Geek Guy

How AI Is Changing the MSP Business

AI is changing more than the technology MSPs deploy. It’s reshaping how providers demonstrate value, build services, work with customers, and differentiate their businesses. In this episode of Channel Insider: Partner POV, Victoria Durgin sits down with Peter Fidler, president and founding partner of WCA Technologies, to discuss what AI adoption looks like inside an…

Major rules for federal contractors handling sensitive data are nearing the finish line

Federal government contractors that handle sensitive information could soon face a “sea change” in rules about how they protect that information and report when it has been part of a breach. Pending federal regulations on the handling of “controlled unclassified information,” or CUI, a category of sensitive data that falls short of classified — including…

Microsoft, Adobe, Apple, and Foxit vulnerabilities

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy.  For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets…

Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google’s own systems were not breached, but any domain ending in .gh (Ghana), .sl (Sierra Leone) or .as (American Samoa) was put at risk. With such a certificate, an attacker could pose as the real…

Meta Joins Walmart, Shopify, Stripe to Back New AI Agent Standard for Business

Meta is joining Walmart, Shopify, Stripe, and other major technology and commerce companies to establish common rules for how personal AI agents interact with businesses. The companies are backing the Personal Agent Protocol, an open standard being developed by Meta and enterprise AI startup Sierra with Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart. The framework…

Coffee with the Council Podcast: PCI SSC Introduces Key Management and Operations (KMO) Standard v1.0

  Welcome to our podcast series, Coffee with the Council. I’m Alicia Malone, Director of Communications and Public Relations for the PCI Security Standards Council. Recently, the Council published its newest standard, the Key Management and Operations, or KMO Standard. But what exactly is KMO, and how does it fit into the Council’s portfolio of…

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet. The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including

Scans for Atlassian vulnerablity (CVE-2026-21589), (Wed, Oct 7th)

On October 5th, Atlassian published patches for multiple products to fix an “Arbitrary File Access” vulnerability [CVE-2026-21589]. An attacker can read arbitrary files in the web application’s directory, potentially exposing sensitive information such as configuration files. This directory traversal vulnerability is a little bit different from the textbook case. Atlassian products replace slashes with the pattern…

Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589)

One day after Atlassian released patches fixing a critical arbitrary file access vulnerability (CVE-2026-21589) in its self-managed Data Center products, and a few hours after watchTowr researchers published a technical rundown of the flaw, attackers have been spotted attempting to exploit it. CVE-2026-21589 PoC in action (Source: watchTowr) “Exploitation attempts have now started to hit…

Gremlin Foresight AI finds system weaknesses and verifies the fixes

Gremlin has announced the general availability of Gremlin Foresight AI. Following a successful beta, Gremlin Foresight AI has proven it can identify and address reliability risks before they become incidents, helping engineering teams move at AI speed without compromising the resilience of mission-critical production systems. “AI-driven development means shipping code at 10X velocity; it also…

Cisco Webex Adds AI Agents, RoomOS 27 and CX Tools

Cisco is expanding Webex with collaborative AI agents designed to work across applications, manage longer-running tasks, and support employees beyond traditional prompt-based assistants. Announced at WebexOne 2026, the updates extend Cisco’s agentic AI strategy across collaboration, physical workplaces, and customer experience. They include new Webex AI agents, Intelligent Workplace Experiences, RoomOS 27, and Dialog, an…

FortiBleed hit 86,000 firewalls by exploiting something nobody can patch away

FBI and Secret Service warn FortiBleed, a credential-harvesting campaign against Fortinet firewalls, has compromised 86,644 devices and is locking out admins. The FBI and the U.S. Secret Service issued a joint advisory about FortiBleed, and the headline number alone is worth sitting with: more than 86,644 compromised Fortinet FortiGate devices across 194 countries, according to…

FortiBleed is still active, with attackers locking admins out of Fortinet firewalls

Some organizations hit by the FortiBleed campaign have been locked out of their own Fortinet firewalls, according to a joint FBI and U.S. Secret Service advisory. FortiBleed targets internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. The advisory cites SOCRadar, which has verified more than 86,644 compromised devices in 194 countries. “Based on initial responses,…

Vijil DART tests AI agents for security flaws and policy violations

Vijil has released Diamond Adaptive Red Teaming for Agents (DART), an automated testing system that finds security vulnerabilities and policy violations in enterprise AI agents. DART employs multiple adversarial agents of its own to probe the target’s defenses with multi-turn attacks that learn and adapt tactics across turns, episodes, and engagements. Using DART, AI developers…

Edgescan Atomic validates attack paths with controlled AI testing

Edgescan announced the launch of Edgescan Atomic, an autonomous penetration-testing capability built on agentic AI and Edgescan’s existing security intelligence. Edgescan Atomic can run on top of Edgescan’s existing continuous security platform or run as a stand along Agentic Penetration Testing solution. Organizations need confidence that they are safe from AI-powered cyber-attacks. Edgescan Atomic is…

Trustero automates vendor document reviews with human approval

Trustero has announced the launch of Trustero Third-Party Risk Management (TPRM). TPRM extends Trustero’s AI engine beyond a company’s own compliance program to the vendors and partners it depends on. Instead of collecting and reading vendor documentation, teams review and approve a recommended risk determination. Vendor risk management is largely a logistics problem: chasing attestations,…

Hoxhunt expands Respond to automate phishing investigations and email removal

Hoxhunt has announced expanded capabilities for Hoxhunt Respond, its email incident response automation platform for security operations teams. Respond can reduce phishing tickets requiring analyst attention by up to 99% and remediate confirmed malicious campaigns in under one minute. Effective phishing training creates a valuable result: employees recognize and report more real threats. It also…

Tanium adds endpoint behavior detection and AI-assisted threat hunting

Tanium has relaunched Tanium Security Operations to address AI-assisted attacks in which adversaries use legitimate administrative tools to blend into normal activity and spread across endpoints. The platform is designed to detect this behavior, support response across affected endpoints and help analysts investigate threats. With AI, attackers no longer need malware that a scanner can…

Dell AI Data Platform Adds Agentic AI, GPU Capabilities

Dell Technologies is expanding its AI Data Platform with new enterprise context, GPU acceleration, and managed infrastructure capabilities to help organizations move AI workloads from pilot projects into production. The updates include a Unified Semantic Layer, Enterprise Knowledge Graph, and knowledge agents designed to give AI systems governed business context, alongside NVIDIA-accelerated data processing, a…

FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. “The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software

Hackers hijack three country-code domain registries, obtain HTTPS certificates for Google domains

Attackers who took control of three country-code top-level domains (ccTLDs) used that access to obtain HTTPS certificates for several Google domains and for domains run by other large organizations, Google disclosed on Tuesday. Attackers compromised the third-party operators of the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) ccTLDs, putting every domain under those…

SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255)

SonicWall has patched four vulnerabilities in its popular Secure Mobile Access (SMA) 1000 series of appliances, including one (CVE-2026-102255) that could allow remote unauthenticated attackers “to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.” “There is currently no evidence any of the vulnerabilities addressed in this…

Another ShinyHunters suspect arrested

The net is tightening around the Shiny Hunters cybercrime group following the reported arrest of a second member. On Saturday, Reuters said that 16 year-old Saif al-Din Khader had been arrested in Jordan and was in FBI custody. This follows the arrest earlier in September of another member in the Netherlands. Third party reports named…

One breach, please, and make no mistakes

For some time now, the cybersecurity community has seen examples of autonomous agents, built inside AI labs, attacking public infrastructure (to name a few, Hugging Face, DSEWiki, and RubyGems). Of course, frontier labs have built-in security to prevent these attacks from occurring, but every now and then, the training or prompting appears to be insufficient…

September 2026 Cyber Attacks Statistics

September 2026 recorded 182 cyber incidents, and Cyber Crime drove roughly three in four of them (73.9%). Malware was the top attack vector at 27.8%, exploitation of public-facing applications led initial access at 28.9%, and Information & Communication was the most targeted sector. Explore the full statistics, from the daily trend to the geographic distribution.

Anthropic loosens Claude’s cyber restrictions for verified defenders

Anthropic expanded its Cyber Verification Program (CVP), giving approved security professionals access to advanced Claude capabilities with fewer automated blocks on work such as malware analysis and vulnerability testing. Three tiers for cybersecurity work The program now has three tiers based on the scope of applicants’ cybersecurity work. The expansion combines CVP and Project Glasswing…

Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

Anthropic on Tuesday said it’s expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional

100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer). The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not…

From Guest Complaints to Malware: Blockchain Abuse Targets Hotels

By: Kahng An, Intelligence Team Cofense Intelligence has been tracking a series of email campaigns that target the accommodation industry with fake guest complaints or reviews that deliver blockchain technology-abusing malware. These emails appear to likely be a continuation of a prior series of predominantly Booking.com-spoofing emails that were seen delivering various remote access trojans…