Geek Guy

MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

The U.K.’s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing’s state security service. In a “Security Service Espionage Alert” issued on September 30, 2026, MI5 said the “primary purpose of the China General Technology Research Institute (CGTRI) 中国通用技术研究院 is…

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. “In the

The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale. This report examines how core areas of

U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-102489 (CVSS score of 9.4) Zammad GmbH Zammad Session Fixation Vulnerability CVE-2026-102490 (CVSS score of 9.4) Zammad GmbH Zammad Improper…

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below – CVE-2026-63688 (CVSS score: 10.0) – A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an

Heimdal Extends European MSP Security Reach Into DACH With Elovade

Heimdal is expanding its MSP security reach across Germany, Austria, and Switzerland through a broader distribution agreement with Elovade. Under the deal, Elovade will distribute Heimdal’s security platform to partners across the DACH region, extending a relationship the companies already use in other European markets. Regional MSPs will ultimately judge the rollout by how cleanly…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

MegazoneCloud, Portal26 Target Shadow AI in Korea

AI and cloud company MegazoneCloud has signed a strategic reseller agreement with Portal26 to bring the U.S. company’s generative AI governance and security platform to enterprise customers in Korea. Under an agreement signed September 28, MegazoneCloud will resell Portal26’s AI Adoption Management Platform and provide technical support, while the companies develop governance and security offerings…

Fal.Con 2026: Comprehensive Market Intelligence Report 2026

eCrime Actor Activity 3. Falcon Guardian — Technical Architecture Deep Dive Core Capabilities Capability Description AI Agent Discovery & Inventory Continuously discovers known and shadow AI agents across Windows, macOS, Linux endpoints. Identifies deployment origin, usage patterns, and security status. Agent Runtime Visibility Connects AI agent behavior directly to Falcon endpoint telemetry; establishes a causal…

A Vulnerability in Fortinet FortiMail Could Allow for Arbitrary Code Execution

A vulnerability has been discovered in Fortinet FortiMail that could allow for arbitrary code execution. Fortinet FortiMail is a secure email gateway that protects organizations from inbound threats including spam, phishing, malware, and business email compromise, while also preventing outbound data loss across physical, virtual, and cloud deployments. Successful exploitation of this vulnerability could allow…

OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. “We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information,” a spokesperson for the company was quoted as saying. “Our investigation…

BlueVoyant Launches Microsoft ISOC Deployment Service

BlueVoyant has launched a Microsoft Defender XDR ISOC Deployment Service to help organizations prepare their security operations environments for Microsoft’s push toward more integrated, agent-driven security. The service is designed for Microsoft 365 E5 and E7 customers and Microsoft Defender Suite users, with a focus on assessing existing deployments, configuring underlying security technologies, and operationalizing…

EU Cyber Resilience Act ‘completely kills’ manual vulnerability triage

Independent security experts see the EU Cyber Resilience Act (CRA) reshaping international technology markets to emphasize cyber resilience from the ground up, thereby testing the operational capacities of technology vendors whose wares compete in those markets. The EU CRA introduces mandatory reporting within 24 hours for any actively exploited vulnerabilities or severe incidents affecting products…

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

Google has announced a new security measure that limits access to Android’s accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway.…

Investigators trace an AI agent ‘s path from research task to reconnaissance

Asymmetric Security traces rogue OpenAI AI agent activity that probed government sites, accessed staging servers, and evaded sandbox limits. Researchers at Asymmetric Security spent 48 hours over the last weekend reconstructing reported rogue OpenAI AI agent activity that hit the Australian government and other organizations between March and September this year. They worked from public…

Criminal recruiters want people on your payroll

Legitimate employee access can let criminals circumvent security controls that would be difficult to overcome from outside an organization. Routine actions such as information lookups, account resets, transaction approvals and shipment changes can become services sold to criminal customers, according to Intel 471’s Insiders for Hire: Underground Recruitment, Access Claims and Insider-Enabled Services report. A…

U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Fortinet FortiMail flaw, tracked as CVE-2026-104286 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a path traversal vulnerability that can be triggered through…

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. “An improper

Omnissa delivers a peek into the benefits of breaking through enterprise data silos

When Omnissa this week rolled out a new AI governance authority product, Elara, in beta, it delivered a glimpse into the potential of having visibility between the typical enterprise’s data silos, whether they’re in lines of business, disparate geographies, or corporate operational units. “By connecting signals across systems that often operate independently, Elara gives IT…