Geek Guy

Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks

FortiBleed, a credential compromise campaign targeting Fortinet firewalls and VPN gateways, is an ongoing threat that can lock users out of their Fortinet accounts and also lead to ransomware attacks, the FBI and Secret Service said in an alert published Tuesday. “Affected organizations may find themselves locked out of their systems if threat actors disable accounts…

TD SYNNEX Adds SignWell eSignature Platform for Partners

TD SYNNEX is adding SignWell’s eSignature platform to its U.S. portfolio, giving reseller partners access to SaaS and API-based tools for electronic signatures, document automation, and embedded signing.  The agreement also gives partners access to annual subscriptions, usage-based API plans, partner pricing, and deal registration for qualifying opportunities. TD SYNNEX expands eSignature options for U.S.…

Improving SPIRE security and resiliency with AWS managed services

In cloud-centered environments, establishing trust between workloads is fundamental to securing machine-to-machine communication. Traditional approaches such as API keys, shared secrets, and static service account credentials weren’t designed for the scale and ephemeral nature of cloud workloads. This drives an organizational need to shift from long-term, static credentials to short-lived cryptographic workload identities. Organizations are…

SONiC Adds Lenovo, NADDOD and NEXAI to AI Networking Ecosystem

AI networking depends on coordination across software, switches, silicon, and high-speed connections. Collaboration among those vendors could give channel partners more options for building AI networks, although compatibility, integration, and support still require evaluation. The Software for Open Networking in the Cloud (SONiC) Foundation has announced the addition of Lenovo, NADDOD and Zhanwang (NEXAI) as…

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Cybersecurity researchers have disclosed details of a “human-operated phishing platform” that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. The products, which claim to offer campaign optimization, spend audits, and business-account connections, are designed with one goal in

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing…

Former NSA chief Nakasone says agency overhaul is ‘probably needed’

Former National Security Agency Director Paul Nakasone said a reported broad reorganization of the agency is “probably necessary” as it confronts faster-moving cyberthreats, artificial intelligence and competition with China, but he cautioned that the outcome will depend on how the changes are carried out. Speaking Tuesday at VulnCheck’s ThreatCon1 conference, Nakasone addressed a recent report…

Tanium Unveils New SecOps Capabilities

Tanium has announced new security operations capabilities that give IT and security operators greater detection depth, response options, and AI-native hunting to investigate, contain, and resolve threats faster within live endpoint intelligence. The Tanium Security Operations capabilities are powered by Tanium Atlas, the company’s autonomous operating system that allows customers to build a self-driving SOC…

How to mitigate the risk from AI-generated apps built by your ‘citizen coder’ employees

AI tools let non-technical employees build workplace apps in minutes with natural language prompts. While these AI-generated apps boost productivity, they can create severe security and data risks. As Cybersecurity Awareness Month kicks off, we’re sharing how Tenable adopted a structured governance framework that allows our “citizen coders” to build secure and compliant apps with…

CVE-2026-96940: Microsoft Exchange Vulnerability Allows Unauthorized Mailbox Access

Microsoft has released an out-of-band security update addressing CVE-2026-96940, a high-severity vulnerability in Microsoft Exchange Server that could allow authenticated attackers to access other users’ mailboxes and read sensitive emails and attachments. The flaw carries a CVSS score of 8.8 and affects multiple on-premises Exchange Server versions. The vulnerability comes amid growing security concerns surrounding…

CVE-2026-21589: Critical Atlassian Vulnerability Exposes Sensitive Files Across Eight Products

Atlassian has disclosed CVE-2026-21589, a critical arbitrary file access vulnerability affecting eight widely used Data Center products, including Jira, Confluence, and Bitbucket. The flaw, assigned a CVSS 4.0 score of 9.3, could allow unauthenticated attackers to access sensitive files on vulnerable servers without requiring valid credentials or user interaction. The vulnerability highlights the growing risks…

ASOS “hackers” send push notifications to customers

Thousands of global fashion retailer ASOS customers have received a push notification through the ASOS app this morning alleging that the company has been hacked. The notification, addressed to ASOS’s data protection officer and IT, says: “ASOS HACKED Dear Asos DPO and IT, we have fully compromised ​the Snowflake instance. Engage with us, or we…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely

Microsoft released emergency updates for Exchange Server to fix CVE-2026-96940, a high-severity flaw that can let attackers gain higher privileges. Microsoft has released out-of-band security updates for Exchange Server to fix a high-severity vulnerability tracked as CVE-2026-96940 (CVSS score of 8.8). The flaw is caused by weak authorization and can allow an authenticated attacker to…

Anaconda combines agent swarms with autonomous security testing

Anaconda has announced new capabilities across the Anaconda Platform that pair agentic development with autonomous security testing. The expansion brings agent swarms and autonomous red-team agents together with trusted packages, models, and environments to help builders ship faster and address security weaknesses before production. Builders gain greater choice in the tools and models they use,…

Rogue OpenAI agents made unauthorized Wikipedia edits and millions of requests to Wikimedia

Rogue OpenAI agents made unauthorized edits on Wikimedia wikis and sent millions of automated requests to Wikimedia’s public APIs, traffic that may have contributed to a partial outage of the Wikidata Query Service in May, the Wikimedia Foundation said on Monday. “The Wikimedia Foundation conducted its own investigation to see whether Wikimedia websites had been…

AppViewX targets shadow AI risks with agent discovery and runtime enforcement

AppViewX has expanded capabilities for Agent Identity Security, a solution enabling enterprises to discover every agent, whether sanctioned or shadow; govern their posture and maintain audit-ready activity logs; and monitor and control in real time every action that the agent performs. AppViewX now also issues quantum-resilient agent identities, so trust in every agent holds as…

New Relic adds terminal-based investigation and recovery checks with Ground Truth CLI

New Relic has announced New Relic Ground Truth CLI augmented with New Relic Autopilot API, bringing headless observability straight to developers and AI agents in their natural workflows. The new command-line interface (CLI) allows teams to investigate production issues, assess recovery criteria, and embed live system evidence into their daily workflows without leaving the terminal.…

NinjaOne RMM Review 2026: Features, Pricing & Pros and Cons

NinjaOne RMM is a cloud-based remote monitoring and management platform designed for managed service providers (MSPs) and internal IT teams managing distributed endpoints. Formerly known as NinjaRMM, the platform combines endpoint monitoring, patch management, automation, scripting, alerting, and remote access in a centralized console.  Our assessment finds NinjaOne particularly well suited to MSPs and IT…

NinjaOne RMM Review 2026: Features, Pricing & Pros and Cons

NinjaOne RMM is a cloud-based remote monitoring and management platform designed for managed service providers (MSPs) and internal IT teams managing distributed endpoints. Formerly known as NinjaRMM, the platform combines endpoint monitoring, patch management, automation, scripting, alerting, and remote access in a centralized console.  Our assessment finds NinjaOne particularly well suited to MSPs and IT…

SailPoint adds AI agent discovery, temporary access and compliance automation

SailPoint has announced significant new capabilities across SailPoint Agentic Fabric (SAF) and SailPoint Human Fabric (SHF), the two purpose-built products of its Identity Security solution, built on SailPoint Atlas. These innovations give enterprises visibility into every hidden AI tool, continuous compliance across human and machine workflows, the replacement of permanent access keys with temporary permissions,…

September Channel M&A: GTIA, Softcat Lead Deal Activity

September delivered another wave of consolidation across the IT channel, with GTIA acquiring The ASCII Group, Softcat striking a $1.05 billion deal for General Datatech, and MSP, cybersecurity and AI providers expanding through acquisitions. The deals spanned managed services, security, cloud infrastructure and AI, underscoring continued pressure on channel companies to add scale, geographic reach…

Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589)

Attackers who know where to look can read files from Atlassian Data Center installations without logging in, the company has warned. About CVE-2026-21589 CVE-2026-21589, a critical arbitrary file access vulnerability with a 9.3 CVSS score, affects all versions of Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo…

New Linux malware turns vulnerable IoT devices into proxy nodes

A new Linux backdoor is turning vulnerable internet-facing devices into remotely controlled proxy nodes, while using the public Session Traversal Utilities for NAT (STUN) infrastructure to blend into normal VoIP and WebRTC traffic. Fortinet’s FortiGuard Labs said it has been tracking the malware, dubbed ClingSTUN, across multiple attacks exploiting known vulnerabilities in routers, IoT devices,…

Here’s how experts think CISA should tell agencies to protect OT

A coalition of cyber firms and critical infrastructure operators on Tuesday spelled out its views on the tasks that the Cybersecurity and Infrastructure Security Agency should assign federal agencies to protect operational technology systems after this summer’s attacks on water utilities. The Operational Technology Cybersecurity Coalition said a CISA binding operational directive (BOD) for OT…

IronChain Ransomware Threatens Businesses with Permanent Data Loss and Costly Downtime

Editor’s note: This research was conducted by Himanshu Anand, an independent cybersecurity researcher (follow Himanshu on X). During Cybersecurity Awareness Month, ransomware remains one of the clearest examples of how a cyber incident can become a business continuity issue. IronChain shows why. It puts business-critical data at risk of permanent loss and can bring operations…

Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies

The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. “The unauthorized bot activities included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and…

Pacing the AI frontier won’t solve agentic cybersecurity’s most urgent problems

When Anthropic CEO Dario Amodei urged other leading AI labs to “pace the frontier” last week, his calls for caution were echoed by other prominent voices in tech. Both Sam Altman and Elon Musk agreed with Amodei’s assessment that pausing AI development was essential to prevent the extinction of the human race. Amodei listed several…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360)

Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges. DSU is a tool used by enterprise IT administrators to apply driver, BIOS, and firmware updates to Dell PowerEdge servers. About CVE-2026-86360 CVE-2026-86360 is a path traversal…

Microsoft’s New Frontier Specialization Opens AI Agent Opportunities for Partners

Less than a week after Microsoft opened its new Frontier Partner specialization, eligible partners can now pursue a designation built around one of the company’s biggest channel priorities: AI agents. The specialization became available Sept. 30 and targets partners that can design, build, deploy, govern, and secure agents across Microsoft’s cloud, productivity, development, and security…

Exclusive Networks Launches ServiceNow Business for EMEA Partners

Exclusive Networks launched a dedicated ServiceNow business on Oct. 1 to support partners across Europe and the Middle East, putting its July distribution agreement into operation. The cybersecurity distributor is targeting two groups with the rollout. Existing ServiceNow partners can use the business to expand into security, while Exclusive Networks partners can add ServiceNow-based workflows…

Ontinue extends ION MXDR with managed dark web monitoring

Ontinue has announced the launch of ION for Dark Web Monitoring (DWM), a new managed add-on service that extends ION MXDR to continuously identify exposed credentials, detect brand impersonation attempts, and uncover emerging external threats before attackers can exploit them. Compromised credentials are traded across criminal forums, lookalike domains are created to impersonate trusted brands,…

Google’s bug bounty pause highlights growing AI vulnerability triage challenge

AI is accelerating the discovery of software vulnerabilities, but it is also creating a new bottleneck for defenders: deciding which machine-generated findings warrant investigation. Google has decided to temporarily stop accepting certain bug bounty submissions after a surge of largely invalid automated reports highlights a growing challenge for security teams as AI-driven vulnerability discovery begins…

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product’s web application root directory. The attacker must already know a file’s exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October…