Geek-Guy.com

The Validation Stage of CTEM: Proving Which Exposures Attackers Can Actually Exploit

The validation phase of continuous threat exposure management (CTEM) determines whether an attack could succeed in your particular environment. Your teams get proof of attack viability and can concentrate remediation efforts on exploitable exposures, not scoring severity. The 2026 Verizon Data Breach Investigation Report revealed that exploiting vulnerabilities was the most popular initial access vector,…

U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the KeV catalog: CVE-2026-16232 (CVSS score of 9.3) Check Point SmartConsole…

Russian TA488 Exploits Zimbra CVE-2025-66376 to Target Government Mail Servers 

Russian-aligned TA488 exploited Zimbra flaw CVE-2025-66376 for at least five months using a half-click attack triggered when victims opened or previewed a malicious email.  The campaign targeted Ukrainian and U.S. government, defense, and scientific organizations, allowing attackers to steal sensitive emails and maintain persistent access to compromised mail servers.  “What’s interesting here is that more…

4 ways AI-driven defense is rewriting the cybersecurity playbook

The cybersecurity landscape has evolved beyond human scale. Today’s adversaries have replaced predictable, manual playbooks with machine-generated attack chains that can breach traditional controls in seconds. To bridge the gap, organizations must move past legacy, reactive controls and embrace a fundamentally different, AI-driven architecture: Agentic Endpoint Security (AES).  AES represents a paradigm shift, moving security…

Don’t swing at everything

Welcome to this week’s edition of the Threat Source newsletter.  Lately I’ve found myself thinking a lot about the Australian TV series Mr. Inbetween (IMDb 8.7/10) — not because I’m a hitman for hire, but because I literally feel in-between. Specifically, in-between what I’d call the “pre-Mythos” and “post-Mythos” eras. We’ve crossed a capability threshold,…

Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries

A Russian state-sponsored threat group has been stealing sensitive data from governments and commercial organizations since July 2025 via a novel exploit in popular Linux-based enterprise software, U.S. authorities and cyber officials from more than a dozen other countries warned in a joint cybersecurity advisory Thursday. Laundry Bear’s most recent espionage campaign involves the exploitation…

Enterprise security at machine speed: AWS Black Hat 2026 preview

Black Hat 2026 (Aug 1-6, 2026) brings together over 22,000 security practitioners, researchers, and CISOs who build, break, and defend enterprise infrastructure. They’re security professionals who push the limits of offensive and defensive security and demand proof over promises. As frontier security models like Mythos reshape the enterprise landscape, they need security that operates at…

OpenAI Presence Brings Governance to Enterprise AI Agents

OpenAI has introduced OpenAI Presence, a managed enterprise platform designed to help organizations build, deploy, monitor, and continuously improve governed AI agents for business-critical workflows.  Available initially through a limited general availability program, the platform reflects a growing shift in enterprise AI from simply providing large language models to helping customers operate AI agents safely…

CVE-2026-64600: RefluXFS Linux Kernel Flaw Can Lead to Root Privilege Escalation

Linux local privilege escalation bugs remain especially dangerous when they turn an ordinary user foothold into full root access. CVE-2026-64600, also referred to as the RefluXFS vulnerability and the RefluXFS Linux Kernel Vulnerability, is a race condition in the Linux kernel’s XFS copy-on-write path that allows an unprivileged local attacker to overwrite protected files on…

Swimlane Launches AI SOC Platform for MSSPs

Swimlane, an agentic AI automation provider, has launched Swimlane AI SOC for MSSPs, a platform designed to help managed security service providers (MSSPs) build AI-powered security operations centers without competing for their customers. Swimlane positions AI SOC as an MSSP-owned platform According to Swimlane, the new offering addresses a growing trend of AI SOC providers…

Cobalt adds Autonomous Pentest to scale application security testing

Cobalt has introduced Cobalt Autonomous Pentest, a new offering that enables continuous offensive security across an organization’s application portfolio by delivering actionable penetration testing results in as little as 24 hours. AI-assisted development enables organizations to ship software faster than ever, while attackers are using AI to automate reconnaissance and accelerate exploitation. Pentesting performed quarterly…

Cato Networks integrates SASE with CrowdStrike Falcon

Cato Networks and CrowdStrike have integrated their security platforms to unify network and endpoint telemetry, giving customers a more streamlined way to investigate threats while creating new managed security and consolidation opportunities for channel partners. Cato and CrowdStrike connect network and endpoint data This unified integration will help security teams unify network and endpoint visibility,…

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region; it was offline by the…

Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability Hunting

Google DeepMind unveiled Gemini 3.5 Flash Cyber, an AI model for vulnerability discovery and patching, available only to governments and trusted partners. Google DeepMind announced Gemini 3.5 Flash Cyber on Tuesday, a security-focused AI model built on top of the existing 3.5 Flash architecture and designed specifically to find, validate, and patch software vulnerabilities. It…

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. The activity involves malicious Packagist development versions spanning 10 packages associated with a legitimate PHP and DevOps developer, dinushchathurya, between July 12 and 13,

Months-long breach exposes South Korean diplomats’ personal data

South Korea’s Foreign Ministry has disclosed that attackers breached the Korea National Diplomatic Academy’s online education system, compromising personal data belonging to current and former ministry staff and diplomats stationed abroad. The Korea National Diplomatic Academy launched the online training platform in 2022 to support remote learning during the COVID-19 pandemic. Since then, it has…

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)

Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls). “An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes…

10 Best Threat Intelligence Feeds for SOCs and MSSPs in 2026

Threat intelligence feeds give SOCs and MSSPs the data they need to detect malicious activity, enrich alerts, investigate threats, and respond faster. Depending on the platform, this may include malicious IPs, domains, URLs, file hashes, malware behavior, threat actor activity, vulnerabilities, phishing infrastructure, and geopolitical risk.  This guide covers several commercial and open-source threat intelligence solutions used…

Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel

Cisco Talos has discovered a new Rust-based remote access trojan (RAT) we call “msaRAT” attributed to the Chaos ransomware group. The name is derived from the binding names found in the binary: “msaOpen,” “msaClose,” “msaError,” and “msaMessage”. msaRAT is implemented using the Tokio asynchronous runtime, with primary capabilities of browser-leveraged remote code execution and covert…

ANCHOR-CI could fix 20 years of broken government-industry collaboration

On July 1, the Cybersecurity and Infrastructure Security Agency (CISA) published a seven-page notice in the Federal Register that could fundamentally change how the U.S. government works with private companies to protect critical infrastructure from cyber threats and natural disasters. The notice, “Establishment of the Alliance of National Councils for Homeland Operational Resilience – Critical…