Geek-Guy.com

Palo Alto Warns of Exploitation of VPN Bypass Exploits (CVE-2026-0257) in PAN-OS Flaw

Palo Alto Networks warns that attackers are actively exploiting CVE-2026-0257, a PAN-OS flaw that lets unauthorized users bypass authentication and establish VPN connections. Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, a PAN-OS authentication bypass vulnerability affecting GlobalProtect portals and gateways. Palo Alto Networks addressed the vulnerability on May 13. Two weeks later, cybersecurity firm Rapid7…

152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic

Cybersecurity researchers have discovered a network of 152 Google Chrome extensions that act as new tab live wallpaper add-ons to distribute a potentially unwanted program (PUP) family. The cluster spans 38 separate Chrome Web Store publisher accounts and three brand backends: tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com. They have been collectively installed 105,000 times. The

PhishLumos: Exposing phishing campaigns that evade detection by hiding content

Phishing remains one of the most stubbornly persistent threats in cybersecurity: humans are tired, distracted, trusting, and susceptible to urgency and authority in ways that no amount of awareness training can completely overcome. The security community has largely accepted this reality and shifted focus toward automated detection systems that can intercept and block phishing threats…

Modat enhances Magnify with Passive DNS for faster threat hunting and infrastructure analysis

Modat has launched native Passive DNS intelligence in Magnify, its internet intelligence platform, unifying IP, device fingerprint, certificate, and passive DNS into a single pivot-driven investigation flow. Threat intelligence, threat hunting, exposure management, fraud and Security teams have long been forced to stitch together evidence across multiple tools and datapoints. Magnify eliminates that gap, building…

Microsoft’s workplace check-in via Wi-Fi tracks who’s in the office, and not everyone’s happy

Microsoft is rolling out workplace check-in via Wi-Fi for Teams and Microsoft Places. Connect to your office network and your in-office presence updates automatically, no manual status change needed. Microsoft says the signal isn’t stored as location history, and that you can configure your own settings. Here’s the catch. Your employer enables the feature at…

LTM’s BlueVerse for iRun applies agentic AI to managed IT operations

LTM has announced the launch of BlueVerse for iRun, an AI-native managed services offering designed to transform IT operations into a resilient, intelligent, and outcome-driven function. As enterprise environments grow more complex, spanning hybrid cloud, SaaS, and AI-driven ecosystems, managed services models are increasingly constrained by siloed teams, static processes, and effort-led scaling. BlueVerse for…

Governing the ghost workforce

Every enterprise security team is fighting a workforce problem they cannot see on any org chart. Bots, service accounts, API keys, OAuth tokens, machine certificates — non-human identities now outnumber human ones in most large organisations, often by a factor of ten to one. They authenticate constantly, operate across every environment, and when forgotten, they…

Supply Chain Attack Hits Popular WordPress Plugins Through Awesome Motive CDN

Attackers compromised Awesome Motive CDN files, backdooring WordPress sites running OptinMonster, TrustPulse, and PushEngage. Sansec researchers discovered an active supply chain attack hitting WordPress sites running OptinMonster, TrustPulse, and PushEngage, three plugins operated by Awesome Motive, one of the largest WordPress plugin companies in the world. The malicious JavaScript wasn’t sitting on any victim’s server.…

AWS Partners Rethink Software for Agentic AI Era

AWS technology partners are rearchitecting products around agentic AI as enterprise customers demand more flexible, outcome-driven software experiences. In three interviews with Channel Insider, leaders from AWS, Zendesk, and Dynatrace described a market moving beyond early AI pilots and into production-grade deployments, where customers expect agents to support workflows, resolve issues, optimize systems, and integrate…

A week in security (June 8 – June 14)

Last week on Malwarebytes Labs: Stolen iPhones could soon be worth a lot less to thieves Fake verification pages are stealing Steam accounts from players Google can be liable for false AI Overviews, court rules VRChat says reported data breach never happened Children’s phones must block nude images by September, UK says Free Spotify Premium…

Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts

Cybersecurity researchers have disclosed details of fraudulent activity targeting users across the Middle East and North Africa by employing various fraudulent Facebook accounts impersonating politicians, public figures, and trusted organizations. “These accounts promoted fake offers, including free mobile internet packages, financial compensation, and government subsidy programs,” Group-IB

Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

Palo Alto Networks has revealed that it has observed “active exploitation” of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited…

Open-source CI/CD abuse detector guards against stolen credential attacks

CI/CD Abuse Detector is an open-source project that uses a large language model to flag suspicious changes to continuous integration and continuous deployment pipelines, workflows, and automation configurations. The repository contains drop-in templates for GitHub Actions, GitLab CI, and Azure DevOps. The project targets a common attack chain in software supply chain compromises. Stolen developer…

Weekly Update 508

Light switches. How on earth is it so hard to find decent light switches?! It sounds ridiculous until you actually spend enough time looking for ones that meet two simple criteria: Aren’t stateful (switch is up or down, has to be push-button) Looks good Now, I’m conscious that this is also very likely an Australian…

Critical Cybersecurity Updates: 2026-06-14

## Critical Cybersecurity Developments: 2026-06-14 ### Executive Summary This report synthesizes verified breaking developments from trusted industry sources and real-time threat intelligence feeds. The following analysis integrates live search results with established security frameworks. — ### Live Search Results Analysis Based on current intelligence, the following threat vectors are active: #### 1. Emerging Threat Vectors…

Comprehensive Report: Latest Malware Threats – Technical Analysis, TTPs, Tools, and Procedures (June 2026)

Comprehensive Report: Latest Malware Threats – Technical Analysis, TTPs, Tools, and Procedures

Executive Summary This report provides a detailed technical analysis of the most significant malware threats observed in 2026, including ransomware operations, nation-state threat actors, and emerging attack methodologies. The analysis covers Tactics, Techniques, and Procedures (TTPs), attacker tools, operational procedures, and provides citations to authoritative threat intelligence sources. Akira Ransomware (Punk Spider / Halcyon) OverviewAkira…

2026 Internet, IT & Cybersecurity Adoption Survey Report

��

Date: June 2026 Scope: Global cybersecurity adoption rates across all domains, stacks, and markets based on 2026 survey data from Gartner, Forrester, Ponemon, Cisco, Microsoft, Fortinet, World Economic Forum, and other leading research organizations. Executive Summary 2026 marks a pivotal year for cybersecurity adoption, with global cybersecurity spending reaching $240-244 billion (12.5-13.3% YoY growth) and $300…

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 101

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter IronWorm: Shai-Hulud’s rustier cousin Trojanized ai-sdk-ollama Delivers Miasma, a Self-Replicating npm Worm via binding.gyp  Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO  Using AI Agents to Analyze Malware on REMnux   The Miasma…

Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: DockSec: Open-source AI-powered Docker security scanner DockSec is an OWASP Incubator Project that combines three container security scanners with a language-model layer for explanation and remediation. Created by Advait Patel, the Python tool runs Trivy, Hadolint, and Docker Scout against…

Ukrainian Extradited from Ireland Pleads Guilty Over Role in Conti Ransomware Scheme

Ukrainian national Oleksii Lytvynenko pleaded guilty in the U.S. for his role in Conti ransomware attacks targeting victims worldwide. Oleksii Oleksiyovych Lytvynenko (44), a Ukrainian national extradited from Ireland to the U.S., has pleaded guilty to conspiracy to commit wire fraud for his involvement in the Conti ransomware operation. Prosecutors said he helped conduct attacks…

Anthropic disables new models after government calls them a national security concern

The U.S. government on Friday ordered Anthropic to immediately suspend foreign access to Fable 5 and Mythos 5, its two most advanced artificial intelligence models, citing national security concerns tied to a reported method of bypassing the models’ safety restrictions.  The directive, issued late Friday afternoon by Secretary of Commerce Howard Lutnick in a letter…

Critical Cybersecurity Updates: 2026-06-13

## Critical Cybersecurity Developments: 2026-06-13 ### Executive Summary This report synthesizes verified breaking developments from trusted industry sources and real-time threat intelligence feeds. The following analysis integrates live search results with established security frameworks. — ### Live Search Results Analysis Based on current intelligence, the following threat vectors are active: #### 1. Emerging Threat Vectors…

Washington Pulled the Plug on Anthropic ‘s Fable 5 and Mythos 5 models. The Rest of the World Is Watching.

Anthropic disputes restrictions on Mythos 5 and Fable 5, arguing the decision lacks transparency and isn’t based on clear technical evidence. On Friday June 12 at 5:21pm ET, Anthropic received a letter from the US Commerce Department, signed by Commerce Secretary Howard Lutnick and drafted with officials from the Bureau of Industry and Security. The…

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system. “In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user could create or…

U.S. CISA adds Oracle PeopleSoft Enterprise PeopleTools flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle PeopleSoft Enterprise PeopleTools flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Oracle PeopleSoft Enterprise PeopleTools flaw, tracked as CVE-2026-35273 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. Oracle PeopleSoft Enterprise PeopleTools is the underlying technology platform…

Hacker Culture: A Comprehensive Report

Hacker Culture: A Comprehensive Report

Executive Summary Hacker culture emerged from the academic and technical communities of the 1960s, evolving through distinct phases shaped by technological revolution, cultural revolution, and the white/black/gray hat split. This report synthesizes the timeline, key events, cultural evolution, and the ongoing revolution from curiosity-driven exploration to organized cyber operations. Table of Contents 1. Origins and…

The Meaning of Life: Variations and Statistics

Executive Summary The question “What is the meaning of life?” has been explored across religious, philosophical, scientific, and secular traditions. This report synthesizes research findings, philosophical frameworks, and statistical data from global surveys to present the major variations in how different cultures and individuals define life’s purpose. Table of Contents Religious Traditions Major Religious Frameworks…