Connect with us

Infosecurity

The Changing Landscape of Digital Rights Management: From Documents to Policy Servers

Published

on

The Changing Landscape of Digital Rights Management: From Documents to Policy Servers

The role of digital rights management (DRM) has shifted dramatically over the past decade. Once primarily focused on protecting copyrighted media files, DRM tools evolution now centers on securing sensitive corporate data shared across organizations, cloud platforms, and a growing array of devices. This transformation reflects broader changes in how businesses collaborate and how threats emerge in the digital ecosystem.

Today, DRM is no longer just about limiting what users can do with a file. It has become a critical layer in enterprise security strategies, often integrated with identity and access management (IAM) systems to enforce granular policies. As cybercriminals, competitors, and nation-states increasingly target proprietary information, the need for robust, flexible DRM solutions has never been greater.

How DRM Tools Evolution Addresses Modern Security Challenges

The traditional approach to DRM relied on embedding access rights directly into documents. This method, used by older products like WatchDox (now owned by BlackBerry), allowed files to remain usable anywhere but made it difficult to update policies or track usage across distributed networks. If rights changed, a new version had to be issued, and old versions could be recalled—a cumbersome process.

However, the DRM tools evolution has shifted toward policy server architectures. In this model, a central server manages access rights and audit trails in real time. Documents can only be manipulated when users are online, though offline workarounds exist and are becoming less necessary as connectivity improves. This approach offers greater flexibility and security, as policies can be updated instantly without redistributing files.

For organizations seeking to protect sensitive data shared via Microsoft Office 365, Box, or Dropbox, policy server-based DRM provides a centralized way to enforce compliance and prevent unauthorized access.

Key Players in the DRM Tools Evolution

Several vendors are driving the DRM tools evolution with innovative approaches that combine encryption, IAM integration, and cloud compatibility.

Fasoo Enterprise DRM: Agent-Based Policy Enforcement

Fasoo, a South Korea-based vendor, uses a policy server model with client agents installed on endpoints. Its Fasoo Enterprise DRM (FED) solution can be deployed on-premises or hosted on cloud platforms like IBM SoftLayer or Amazon Web Services (AWS). While FED requires agents for full functionality, it offers limited agentless support via browser-based content rendering. The company has found success primarily in Asia and the United States, with limited penetration in Europe.

FinalCode: Cloud-Native DRM with Innate Encryption

FinalCode emerged from stealth in 2014 and offers a cloud-based or on-premises DRM solution with built-in encryption. Its latest release, version 5.11, leverages AWS Key Management Service (KMS) to give data controllers full control over encryption keys. The product also enhances IAM support through SAML and Microsoft Active Directory integration. File owners can grant offline access, though this disables real-time policy changes and audit logging.

Vera: Hybrid DRM for Modern Workflows

Vera, launched in 2015, provides a hybrid DRM platform with innate encryption. It supports both cloud and on-premises deployments, with some customers using a cloud-based policy engine and an on-premises key server. Vera’s biggest use case is securing Microsoft Office 365 deployments, but it also integrates with other cloud storage services. For IAM, Vera partners with Ping Identity, Okta, and Centrify. Its file wrapper technology enables browser-based read-only access without an agent, while full editing requires an agent with specific file support.

Other Notable Solutions

Ionic offers policy-enforced encryption, while Seclore markets itself as an advanced enterprise DRM solution. Both contribute to the ongoing DRM tools evolution by emphasizing security, flexibility, and ease of use.

Integrating DRM with IAM for Stronger Security

One of the most significant trends in the DRM tools evolution is the convergence of DRM and IAM. By linking DRM systems with IAM platforms, organizations can authenticate users and apply policy controls based on roles, locations, or other attributes. This integration simplifies management and enhances security by ensuring only authorized users can access sensitive content.

For example, FinalCode and Vera both support SAML-based IAM integration, allowing companies to leverage existing identity infrastructure. This reduces the need for separate user databases and streamlines policy enforcement across cloud and on-premises environments.

Encryption Key Management: A Growing Complexity

As DRM tools incorporate native encryption, managing encryption keys has become a critical challenge. Vendors like FinalCode use AWS KMS to handle key management, while Vera offers a hybrid approach with an on-premises key server. Proper key management ensures that even if a file is intercepted, it remains unreadable without the correct decryption key.

For enterprises, this means balancing security with usability. While encryption protects data at rest and in transit, it can complicate sharing and collaboration. Modern DRM solutions address this by automating key rotation and providing granular access controls.

The Future of DRM Tools Evolution

Looking ahead, the DRM tools evolution will continue to be shaped by cloud adoption, mobility, and regulatory requirements. As more organizations move to hybrid work models, DRM must support seamless access across devices while maintaining strict security controls. Policy server architectures are likely to become the standard, offering real-time policy updates and comprehensive audit trails.

For businesses evaluating DRM solutions, focusing on IAM integration, encryption key management, and cross-platform compatibility will be essential. Those that adapt to these trends will be better positioned to protect their intellectual property and comply with evolving data protection laws.

In conclusion, the transformation of DRM from static document protection to dynamic, policy-driven security reflects the broader shift in enterprise IT. As threats grow more sophisticated, investing in advanced DRM tools is no longer optional—it is a necessity for safeguarding sensitive information in a connected world.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

Ransomware Attacks Surge 19% in July After a Quieter Spring

Published

on

ransomware attacks surge

Ransomware Attacks Surge After a Spring Slowdown

Ransomware activity snapped back with a vengeance in July. New data from Comparitech shows a 19% jump in claimed attacks compared to June, making last month the second-busiest of 2026 so far.

The numbers are stark. Researchers tracked 799 claimed ransomware attacks in July — the third-highest monthly total in the past 17 months. That spike follows an unusually quiet stretch from April through June, when activity dipped noticeably.

Finance took the hardest hit, with attacks soaring 71% month-over-month. Technology wasn’t far behind at 62%, while healthcare (46%) and education (44%) also saw sharp increases. US-based organizations felt the pressure too, with attacks up 31% from June.

Major Incidents Show the Damage Ransomware Can Do

Two confirmed attacks stood out for their real-world consequences. US healthcare provider AnMad was forced to close facilities after a breach. In Romania, the government’s land registry agency suffered an attack that wiped an entire database, throwing the country’s real estate market into chaos.

Rebecca Moody, head of data research at Comparitech, put it bluntly: “These attacks highlight how ransomware groups hit organizations in various different ways – taking down key systems, stealing troves of data, and even deleting massive datasets.”

Her advice? Regular backups — and backups of those backups. “Never has it been more important for organisations to ensure they’re carrying out regular backups… so they can reset systems and restore data as quickly as possible if the worst does happen,” she said.

The Gentlemen and Qilin Continue Their Battle for Supremacy

Two ransomware strains continue to dominate the threat landscape. The Gentlemen and Qilin together accounted for 33% of all attacks in July — 135 and 125 claims, respectively.

That’s a continuation of a power struggle that’s been brewing for months. ReliaQuest analysis from earlier this year found The Gentlemen had overtaken Qilin as the most prolific threat actor between March and May 2026.

The gap between these two and everyone else is significant. DragonForce came in third with 41 attacks, followed by INC (36), CRPx0 (33), and SafePay (30).

What This Means for Security Teams

The July numbers are a reminder that ransomware isn’t going anywhere. The lull in spring was temporary — these groups adapt, regroup, and strike when defenses drop.

For organizations in finance, healthcare, and tech, the message is clear: ransomware protection strategies need constant updating. That means patching vulnerabilities, segmenting networks, and testing recovery plans before an incident, not after.

It also means paying attention to who’s actually attacking. The dominance of The Gentlemen and Qilin suggests a consolidation in the ransomware ecosystem — fewer, bigger players with more resources and better tactics.

How to Prepare for the Next Wave

Comparitech’s data points to a few practical steps every organization should take:

  • Maintain offline backups and test restoration procedures regularly
  • Monitor threat intelligence feeds for emerging ransomware groups
  • Implement strict access controls and multi-factor authentication
  • Develop and rehearse an incident response plan specific to ransomware
  • Consider cyber insurance that covers extortion payments and business interruption

The July surge is a warning shot. The spring lull lulled some into complacency — but the attackers never stopped. They were just waiting.

Continue Reading

Infosecurity

Chinese telecoms keep a quiet US foothold despite Salt Typhoon ties, House panel finds

Published

on

Chinese telecoms US presence

A 49-page report, a subpoena fight, and a stubborn question

Three Chinese state-owned telecom giants still have a quiet but real presence inside America’s internet backbone, years after federal regulators pulled their licenses over cybersecurity fears. That’s the blunt conclusion of a new bipartisan investigation from the House Select Committee on China, released Tuesday.

The 49-page report focuses on China Mobile, China Unicom, and China Telecom — companies that lost or were denied Section 214 authorization by the FCC between 2019 and 2022. That authority is what lets foreign carriers provide international telecommunications services in the U.S. Losing it was supposed to be a near-fatal blow.

It wasn’t.

Committee investigators subpoenaed all three firms, conducted eight interviews with company officials in September 2025, and pored over technical data tied to the Salt Typhoon hacking campaign, which breached at least nine U.S. telecom companies. Their finding: the license revocations limited what these carriers could do, but never forced them to pull equipment out of American networks or sever business ties with U.S. partners.

What the FCC actions actually accomplished

The report gives the FCC credit for moving against the carriers. But it argues the agency’s actions left a glaring loophole: nothing required the companies to shut down physical operations or dismantle hardware already sitting inside U.S. infrastructure.

Instead, all three “quietly obtained or retained hardware, interconnection agreements, and data center footholds that served as their ‘trusted’ backdoors,” the report states. They pivoted into less-regulated network services — managing VPNs, brokering third-party equipment, renting space at U.S. facilities, and routing customer data across the globe.

In other words, they rebuilt their U.S. businesses around services that sit outside the core Section 214 framework. The committee says that preserved their operational footing at critical nodes of the U.S. internet.

Ownership chains that lead straight to Beijing

The investigation traces each company’s corporate structure upward. Every one of them sits at the bottom of an ownership chain running through Hong Kong and offshore holding companies to a Chinese state-owned enterprise, all overseen by China’s State-owned Assets Supervision and Administration Commission (SASAC).

The committee’s conclusion is blunt: none of these firms are independent from their parent companies, and those parents have deep ties to the Chinese government. The report also notes that Chinese-manufactured equipment from firms subject to PRC legal obligations — which can compel cooperation with state security services — is still running inside U.S. networks.

Chairman John Moolenaar (R-MI) put it in stark terms. “These companies are a threat to all of us,” he said in a statement. “They poison the domestic cyber infrastructure we rely on.”

Salt Typhoon links and a decade of routing incidents

The report doesn’t stop at structural analysis. It connects the three carriers to a string of cybersecurity incidents stretching back years.

China Telecom and other state-backed carriers were tied to several large-scale internet routing incidents where U.S. government and private-sector traffic was misrouted to PRC-controlled networks. Some may have been accidents. But the Justice Department and other agencies concluded that multiple incidents were intended to expose data to interception or alteration, according to the study.

On Salt Typhoon specifically, the committee stopped short of saying China Mobile directly participated. But it found technical data tying the hacking incidents to the company’s infrastructure.

China Unicom’s links are more concrete. The report says the company has verified connections to Integrity Tech, a firm sanctioned by the U.S. and accused of direct involvement in state-sponsored hacking. China Unicom is also a corporate partner of i-SOON, another Chinese cybersecurity company the U.S. government has accused of running hacking campaigns.

Interviews that went nowhere

The committee’s outreach to the companies themselves didn’t exactly yield candor. Officials initially didn’t respond to voluntary requests, and the Chinese government condemned the subpoenas outright.

When interviews finally happened in September 2025, results were mixed. Some officials answered questions. Others refused to acknowledge even basic facts about their employers. None of those interviewed would admit to reading news reports about the Salt Typhoon incidents.

That’s a remarkable detail, and the committee clearly intends it as one.

What Congress should do next

The report lands with a set of recommendations aimed at closing the gaps the FCC couldn’t. It urges Congress to expand the FCC’s authority to limit these companies’ operations, and to force a “rip-and-replace” of technology from China Mobile, China Unicom, and China Telecom wherever it remains in U.S. networks.

It also calls for more funding for federal agencies to hire technical experts who actually understand cyber threats at the network level — a recurring weakness in government cybersecurity hiring.

Rep. Ro Khanna (D-CA), the committee’s ranking member, framed the stakes in terms of data protection. The report, he said, highlights the need for Congress to “address risks to Americans’ data and ensure that the agencies responsible for securing our communications networks have the resources they need to respond to potential threats.”

The question now is whether the FCC’s next move will be stronger — or whether the carriers will find yet another way to stay embedded. For more on how these threats evolve, see our analysis of state-sponsored cyberattack trends and telecom network security best practices.

Continue Reading

Infosecurity

Cloud and SaaS Environments Have Become the Hottest Targets for Attackers

Published

on

cloud and SaaS environments

Why Cloud and SaaS Environments Are Under Siege

The first half of 2026 has made one thing painfully clear: cloud and SaaS environments are now the primary playground for cybercriminals. That’s the central finding from Darktrace‘s latest threat report, published on August 3.

The shift didn’t happen overnight. Throughout 2025, attackers gradually moved away from traditional malware and vulnerability exploitation. Instead, they zeroed in on one thing: identities. But the game has changed again. In H1 2026, the focus has expanded beyond simple account credentials to email authentication, cloud entitlements, software supply chains, AI gateways, remote admin tools, and non-human identities.

The result? Trust itself has become the attack surface.

A Single Compromised SaaS Account Can Wreak Havoc

Darktrace highlighted a case where one compromised SaaS account triggered malicious activity across email, SaaS, and network layers simultaneously. Attackers changed inbox rules and launched phishing campaigns. Individually, none of these actions looked suspicious. Together, they spelled a clear intrusion.

That’s the scary part. These attacks are designed to fly under the radar, blending in with normal user behavior.

Supply Chain Attacks: Hijacking Trusted Infrastructure

The report also detailed how attackers are exploiting trusted digital supply chain infrastructure. In April, threat actors hijacked Axios — a JavaScript library downloaded over 100 million times weekly — to distribute remote access trojans (RATs). Axios is a dependency in countless developer environments and CI/CD pipelines, making it a perfect delivery vehicle.

Blockchain infrastructure hasn’t been spared either. Researchers observed attackers abusing legitimate blockchain services to spread infostealers like AMOS and Phexia. These platforms often serve users with limited security resources, giving malicious actors access to a much wider victim base.

“Increasingly, attackers do not need to bypass trust controls in these environments; they inherit them through compromised identities, delegated access, and legitimate administration tools,” the researchers noted.

Email Attacks Get Smarter, Not Louder

Email-based attacks are evolving too, but not in the way you might expect. The focus has shifted from quantity to quality.

Around two-thirds of phishing emails in H1 2026 passed DMARC validation protocols. That’s a sobering stat — it means authentication alone can no longer protect your inbox.

  • 37% of phishing attacks contained a high volume of text, up from 32% in H1 2025
  • 39% featured novel social engineering techniques
  • VIP users were targeted in 25% of observed attacks

These numbers paint a picture of attackers customizing their campaigns for specific targets. They’re doing their homework, and it shows.

ClickFix social engineering — a technique that tricks users into running malicious code themselves — continued its run from 2025 as a common vector.

AI Is Expanding the Attack Surface

The rise of AI in enterprise environments has opened new doors for attackers, and they’re walking right through them.

One notable example: AI-generated malware exploiting the React2Shell vulnerability. An attacker used a large language model to produce working exploit code and deployed it at scale. No manual coding required.

Then there’s JadePuffer, the world’s first fully AI-generated ransomware campaign, highlighted by researchers in July. An agentic threat actor exploited a vulnerability in an internet-facing server before launching a fully automated ransomware attack.

“AI is accelerating the path from vulnerability disclosure to operational exploitation,” the Darktrace researchers wrote.

What This Means for Your Security Strategy

If you’re still treating cloud and SaaS environments as secondary concerns, it’s time to rethink. The attackers have already made their move.

Focus on identity protection, monitor for anomalous behavior across all layers, and don’t rely solely on authentication protocols. The threat landscape has shifted — your defenses need to shift with it.

Continue Reading

Trending