Geek-Guy.com

Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure

Researchers uncovered the 200,000-device Dysphoria botnet, which uses Ethereum and Solana domains to hide its command servers. QiAnXin XLab, jointly with China’s CNCERT, disclosed Dysphoria, a botnet that has compromised roughly 200,000 devices worldwide and uses Ethereum and Solana blockchain domain names to hide its command infrastructure. The botnet evolved from jackskid and fbot malware…

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic’s released implementation gives an expected end-to-end runtime of about three hours and 42 minutes…

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution

Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution. Adobe Bridge is a powerful asset management tool that allows creative professionals to preview, organize, edit, and publish multiple creative assets efficiently across the Creative Cloud ecosystem. Adobe Format Plugins are software add-ons used by Adobe…

2026 Phase 1a IRAP report is now available on AWS Artifact for Australian customers

Amazon Web Services (AWS) is excited to announce that the latest version of Information Security Registered Assessors Program (IRAP) report (Phase 1a – full assessment) is now available through AWS Artifact. An independent Australian Signals Directorate (ASD) certified IRAP assessor completed the IRAP assessment of AWS in June 2026. The new IRAP report includes four…

News alert: Aembit joins Snowflake to tackle AI security challenge – trusted agent interoperability

SILVER SPRING, Md., July 28, 2026, CyberNewswire – Aembit, the identity and access management company for agentic AI, today announced a new integration with Snowflake, the AI Data Cloud company, designed to reduce identity risk from third-party AI agents. Through this integration with Snowflake, Aembit helps enterprises securely connect, govern, and audit agents across business systems…

LG Launches Financing for Commercial Display Solutions

LG Electronics USA has launched the LG Financing Referral Service, a new program that connects businesses and participating resellers with third-party financing and leasing options for eligible commercial display solutions.  The service is designed to help organizations deploy digital signage and other display technologies with lower upfront costs while giving channel partners greater flexibility to…

AI has become Apple’s latest bug detective

Artificial intelligence is becoming a force multiplier for Apple security research. Apple’s latest 26.5.2 software update includes patches for a record number of bugs — many of them identified by security researchers using AI-assisted tools. A record haul of fixes The numbers tell the story. Apple fixed 87 security vulnerabilities in iOS and iPadOS 26.6, along with an…

AI-assisted security tools are finding more bugs, but the threat level has not changed

AI systems like Anthropic’s Project Glasswing and Microsoft’s MDASH are aiding in the discovery of vulnerabilities, filling the ever-growing pool of defects that defenders have to address before exploitation occurs. Yet, through the first half of 2026, these vulnerabilities were no more or less likely to be exploited than all vulnerabilities disclosed during that period,…

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

A new Mirai-derived botnet called Tengu can use a compromised Linux device’s hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu’s other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force. Tengu supports 25 distributed…

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of the 36,872 internet-exposed server-management interfaces running IPMI, 24,650 have been found to disclose password-derived authentication hashes before login due to

GoTo Exec on AI Services and the Expanding MSP Role

As small and midsize businesses move from experimenting with artificial intelligence to deploying it across everyday workflows, MSPs have an opportunity to become long-term advisors on the infrastructure, security and enablement required to make those investments work. Michael Day, vice president of global partner sales at GoTo, told Channel Insider that partners are increasingly helping…

Zenarmor CEO Outlines Distributed SASE Strategy: Exclusive

Zenarmor, a network security organization, allows partners to deliver omnipresent security that follows users, applications, and data across on-prem, cloud, edge, and remote environments using a single-app, single-stack, single-pass Secure Access Secure Edge (SASE) platform. The organization is changing how SASE is delivered through the channel, offering a distributed, partner-operated SASE delivery model. In an…

A Vulnerability in VeloCloud Orchestrator (VCO) On-Prem Could Allow for Remote Code Execution

A vulnerability has been discovered in VeloCloud Orchestrator (VCO) On-Prem that could allow for remote code execution. VeloCloud Orchestrator is a centralized management platform used to configure, provision, monitor, and troubleshoot software-defined wide area networks (SD-WAN) and SASE components across enterprise edges and gateways. Successful exploitation of this vulnerability may allow a remote attacker to…

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog’s software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes…

Bugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validation

Bugcrowd unveils Savant Pathseeker, the first solution in its Agentic Offensive Testing line. Savant Pathseeker gives security teams the speed and scale to test every external web application and API continuously, not just the assets that make it onto the pentest schedule, while providing the evidence to prove that the findings are genuinely exploitable. Security…

Prescient Security adds attack surface management to Cait, broadens AI-assisted pentesting

Prescient Security has announced a series of capability expansions to Cait (Cacilian AI), its continuous AI-assisted penetration testing service. The updates which will roll out through summer 2026 add attack surface management (ASM), new asset testing types and expanded environment support, extending Cait’s reach well beyond its initial web application focus. The announcements follow Cait’s…

SpecterOps brings AWS attack path management and AI to hybrid identity security

SpecterOps has announced new capabilities built to give defenders a dynamic understanding of how adversaries traverse their hybrid environment and the ability to proactively eliminate pathways before they can be abused. BloodHound Enterprise adds support for Amazon Web Services and Microsoft Entra Agent ID, expanding the reach of attack path management. A new purpose-built AI…

Team Cymru unveils Pure Signal Command for AI-powered threat intelligence and incident response

Team Cymru has announced Pure Signal Command, the connected operating environment for analysts, security teams, applications, and AI agents to access and act on Team Cymru’s internet infrastructure intelligence. Command unlocks Team Cymru’s globally observed threat intelligence data by connecting telemetry, investigative and attack surface management capabilities, expert analysis, and machine-native access within a common…

Shared Claude chats were searchable on Google

Reddit users found that by using a specific Google search query, it was possible to find Claude conversations that users had shared. This exposed sensitive material, including crypto wallet keys, names, addresses, work notes, and even erotic or otherwise policy-violating chats. Fortune says Anthropic appears to have fixed the Google indexing issue, but the shared…

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket…

JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover

JetBrains patched a critical TeamCity flaw (CVE-2026-63077) enabling unauthenticated code execution on affected on-premise servers. JetBrains has released security updates for TeamCity On-Premises after discovering a critical vulnerability, tracked as CVE-2026-63077 (CVSS score of 9.8). The flaw could allow unauthenticated attackers to execute arbitrary commands on affected servers. All on-premise versions are impacted, while TeamCity…

Anthropic rejects open-weight AI bans, calls for China chip controls and safety tests

Anthropic CEO Dario Amodei has argued that policymakers should keep lower-risk open-weight AI accessible while placing stricter safeguards around frontier systems, including mandatory testing and limits on China’s access to advanced computing and model capabilities. In a post outlining Anthropic’s position, Amodei said broad restrictions, including bans on Chinese open-weight models used by US businesses,…

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)

JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible. “For those who are unable to do so, we have released a security patch plugin,” noted Daniel Gallo, Solutions Engineering Lead at JetBrains. TeamCity as a possible target JetBrains TeamCity is a widely…

AI Agents, Trust Abuse, and Breaches Define Cybersecurity News this Week of July 2026

This week’s cybersecurity landscape was shaped by autonomous AI attacks, prompt injection, evasive malware, software supply-chain weaknesses, identity abuse, and several large data exposures. Researchers also highlighted how trusted credentials, legitimate administrative tools, and familiar brands are increasingly being turned against enterprises. Major Threats & Vulnerabilities Autonomous AI Agents and Development Workflows OpenAI agents demonstrate…

IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains

Phishing was the primary means of gaining initial access this quarter, appearing in over half of all Cisco Talos Incident Response (Talos IR) engagements – an increase from approximately a third of engagements last quarter. Attackers continued to innovate their delivery methods to evade defenses, deploying QR code-embedded PDFs to bypass traditional email gateways and…

New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide

Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns. Proofpoint’s research team traced a wave of income-tax-themed lures targeting Indian taxpayers, tax professionals, and corporate finance teams back to a crypter service called Cruciferra, and the tool turns out to be shared infrastructure used across multiple unrelated criminal…

Building Resilience Against AiTM Phishing: What SOC Leaders Should Know

Email gateways, endpoint controls, and file-centric sandboxing remain essential layers of defense. But many of today’s phishing attacks unfold in ways they weren’t designed to fully expose.  How do you build resilience against modern phishing if it has outgrown your SOC’s investigation workflows? Rethinking Phishing Investigations in Modern SOCs  While initial investigation workflows were designed around malicious files and processes,…

5 Best EDR Tools for MSPs and Businesses in 2026

As ransomware, zero-day exploits, and identity-based attacks continue to evolve, businesses need more than basic endpoint protection. EDR tools help security teams identify suspicious activity, investigate incidents, and contain threats before they spread.  In this guide, we compare the best EDR tools for 2026 based on their detection and response capabilities, pricing, integrations, and suitability…

U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the KeV catalog: CVE-2025-68686 (CVSS score of…

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have…