Geek Guy

Ransomware gangs don’t need control system access to disrupt industrial production

Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to industrial control systems (ICS), according to Dragos. The company identified 1,140 ransomware incidents involving industrial organizations in the second quarter of 2026, up 12% from 1,020 in Q1. The figures come from…

Supply Chain Security: How ANY.RUN Helps US and EU Enterprises Prevent Incidents

Supply chain vulnerabilities represent a growing attack surface for US and EU organizations. With advanced threat tactics on the rise, reducing Mean Time to Detect (MTTD) and Respond (MTTR) is essential. ANY.RUN integrates directly into the SOC workflows as an investigative layer, providing fast malware analysis and threat intelligence to help security teams boost their…

GPT-5.6-Cyber refuses security researchers’ requests far less often

GPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. Model is available only through Daybreak Red, the higher tier of OpenAI’s vetted access program for cybersecurity professionals. “The GPT‑5.6‑Cyber model is trained to improve performance on certain cybersecurity…

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform’s plugins team to temporarily disable their downloads. “Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository,” Wordfence researcher Paolo Tresso said.

Cybersecurity jobs available right now: August 11, 2026

CTI Detection Engineer Department of Parliamentary Services | Australia | Hybrid – View job details As a CTI Detection Engineer, you will lead the detection lifecycle by identifying detection gaps, developing and validating detection logic, deploying and tuning analytics, maintaining cyber threat intelligence workflows, and continuously improving detections to keep pace with evolving adversary tactics,…

OpenAI says Daybreak will expand to offer specialized cyber services 

OpenAI announced Monday  it was expanding access to its frontier models for defensive cybersecurity, detailing different defensive and red-teaming workflows and a new partner program with major cybersecurity product providers. In a pair of blogs posted Monday, OpenAI said it was updating its Daybreak program  – which provides unreleased frontier models to private organizations and…

AWS completes the 2026 Police-Assured Secure Facilities (PASF) audit in Europe (London)

We’re excited to announce that our Europe (London) AWS Region has renewed its accreditation for United Kingdom (UK) Police-Assured Secure Facilities (PASF) for Official-Sensitive data. Since 2017, the Amazon Web Services (AWS) Europe (London) Region has been accredited under the PASF program. This demonstrates our continuous commitment to adhere to the heightened expectations of customers…

U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang

U.S. and South Korean cyber agencies warned Monday about a ransomware-as-a-service outfit, Gunra, that reportedly recruits ethical hackers and penetration testers and benefits from North Korean government-linked hackers’ tools to target government and critical infrastructure organizations. Gunra has gone after sectors such as academia, financial services and insurance, government services and facilities, healthcare, manufacturing and…

DEF CON 34: RovoBlast Exposes Atlassian Rovo Data Risks 

Varonis Threat Labs researchers identified RovoBlast, a vulnerability affecting Atlassian Rovo. The flaw showed how a single crafted link could introduce attacker-controlled instructions into a user’s trusted AI session and potentially expose organizational data. Researchers Dolev Taler and Mark Vaitsman presented the findings at DEF CON 34 after responsibly reporting the vulnerability to Atlassian, which…

Kimi K3 Reached GitHub During Cybersecurity Test, Exposing Sandbox Gap

Moonshot AI’s Kimi K3 accessed the public internet during a controlled cybersecurity evaluation, prompting a dispute over the model’s behavior and the test environment’s configuration. US cybersecurity startup Frontier Security said it discovered the behavior while testing Kimi K3, an open-weight model developed by Chinese AI company Moonshot AI, for defensive cybersecurity tasks. According to…

Royal Navy Cuts Camera Internet Access After Drones Contact Chinese IP

Cameras on Royal Navy drone boats were found contacting a Chinese IP address during a UK Ministry of Defence cybersecurity assessment, prompting officials to cut their internet access. Kraken Technology Group’s K3 Scout vessels used the affected third-party camera subsystem. Unexpected outbound traffic from military hardware has put supplier vetting and device-level security under scrutiny.…

2026 AWS CyberVadis report now available for due diligence on third-party suppliers

We’re excited to announce that Amazon Web Services (AWS) has completed theCyberVadis assessment of its security posture with the highest score (Mature) in all assessed areas. This demonstrates our continued commitment to meet the heightened expectations for cloud service providers. Customers can now use the 2026 AWS CyberVadis report and scorecard to reduce their supplier…

DEF CON 34: 10 Vulnerabilities Put Local AI at Risk 

Local AI offers organizations greater privacy, cost control, and data ownership, but running models locally does not eliminate security risks.  Research presented in connection with DEF CON 34 identified 10 vulnerabilities in llama[.]cpp, a widely adopted inference engine underlying many local AI applications. Key takeaways Researchers identified 10 vulnerabilities in llama[.]cpp, including use-after-free, integer overflow,…