Geek Guy

DataGrout helps enterprises control AI usage, governance and LLM costs

SelectHub has announced the launch of DataGrout, its specialized AI research lab introducing an LLM inference optimization platform and AI governance solution for enterprises. DataGrout’s mission is to drive token reduction for agentic workflows, chatbots and AI tools, while equipping IT and FinOps leadership with a policy-driven, auditable LLM payload and cost monitoring system to…

AI agents wage near-autonomous cyberattack on Asian government networks

Autonomous AI agents built on open-source frameworks breached Taiwanese government systems, compromised credentials, and probed a nuclear safety agency in a multi-day cyberattack that researchers say signals a new phase in AI-enabled operations. The campaign unfolded over four days in early July, during which multiple AI agents operated in parallel to map networks, identify vulnerabilities,…

Frontier Technologies, MSP Hub Form Secure Cloud Alliance

Frontier Technologies and MSP Hub Technologies have formed a strategic alliance combining Frontier’s federal contracting and CMMC capabilities with MSP Hub’s Microsoft licensing, cloud, and managed services operations for government and regulated customers. Managed services and federal contracting expertise in one model This partnership will deliver a fully integrated model that combines Frontier’s federal contracting…

A10 Networks introduces AI Gateway to secure and manage enterprise AI

A10 Networks has announced the general availability of the A10 AI Gateway, a centralized, intelligent control plane that gives organizations unified routing, cost management, and governance across every AI agent, application and large language model (LLM) they use. As AI adoption accelerates, developers are increasingly building agents and embedding AI into applications and business systems,…

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)

Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. About CVE-2026-55040 Tracked as CVE-2026-55040, the vulnerability was patched by Microsoft as part of its July 2026 Patch Tuesday updates. “The authentication feature could be bypassed as this vulnerability allows impersonation,” Microsoft said. “Exploiting this…

The State of Ransomware Q2 2026

For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Research shows that picture starting to shift. The leaders are still winning, but…

Trump administration opens door to private-sector cyber offensives

The Trump administration is opening the door for vetted US companies to conduct cyber operations against foreign cybercriminal organizations under federal supervision, giving the private sector a more direct role in disrupting cyber-enabled crime. A presidential memorandum issued on August 12 directs the National Coordination Center to create a program authorizing participating companies to conduct…

It took $58 to break Microsoft’s SCCM, but a patch made it harder

Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment. Enterprises use Microsoft System Center Configuration Manager (SCCM) to deploy operating systems, manage patches, distribute software, and monitor compliance across…

It took $58 to break Microsoft’s SCCM, but a patch made it harder

Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment. Enterprises use Microsoft System Center Configuration Manager (SCCM) to deploy operating systems, manage patches, distribute software, and monitor compliance across…

Trump turns to private sector in offensive hacking operations memo

President Donald Trump signed a national security memorandum Wednesday that lays the groundwork for private sector companies to take a larger role in helping law enforcement carry out offensive hacking operations against transnational criminal organizations. The White House said sustained fraud and other cyber-enabled campaigns from transnational criminal organizations (TCOs) warranted the memo, and cited…

Searchlight Cyber combines exposure and threat intelligence in new PTEM platform

Searchlight Cyber has launched its Preemptive Threat Exposure Management (PTEM) platform, combining exposure visibility with real-world attacker intelligence to help organizations prioritize and reduce the exposures most likely to be exploited. Security for the real-time era For decades, security teams have relied on a critical advantage: time. Organizations could identify vulnerabilities, investigate threats and respond…

Dissecting the JWR phishing framework

Cisco Talos recently identified an undocumented phishing framework, internally branded “JWR” by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.  The client engine of the JWR phishing framework is a real-time, operator-driven system that, rather than merely logging form submissions like a static credential-stealing page, keeps an AES-CTR encrypted WebSocket open to the threat actor…

July 2026 Cyber Attacks Statistics

July 2026 saw 188 confirmed cyber attacks across 69 countries, with financially motivated Cyber Crime driving three in four incidents. Malware remained attackers’ weapon of choice, exposed public-facing applications were the most common way in, and Information & Communication infrastructure absorbed the heaviest share of targeting. Here’s the full breakdown of who attacked, how, and…

SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit

Attackers are exploiting SharePoint flaw CVE-2026-55040 after a public PoC was released, allowing unauthenticated users to impersonate administrators. Attackers started exploiting CVE-2026-55040 (CVSS score of 9.1), a critical SharePoint authentication bypass patched in July, within days of Rapid7 releasing a public proof-of-concept on August 12. The vulnerability allows an unauthenticated attacker impersonate any SharePoint user…

LevelBlue Named SentinelOne Wayfinder Remediation Partner

LevelBlue has been named SentinelOne’s premier remediation partner for Wayfinder Frontier AI Services, expanding the companies’ relationship as organizations grapple with a growing challenge: finding vulnerabilities with AI is becoming faster, but fixing those vulnerabilities at scale remains difficult. For MSPs and other security service providers, the partnership reflects a broader opportunity emerging around AI-driven…

Schneider Electric Launches Multi-Chemistry APC Smart-UPS

Schneider Electric has launched a new generation of its APC Smart-UPS designed to support multiple battery chemistries, giving channel partners a more flexible platform for helping customers modernize backup power across distributed IT and edge environments.  Standardized platform across every battery type The new Smart-UPS runs on valve-regulated lead-acid (VRLA) or lithium-ion batteries and supports…

Storm-1175 Replaces Medusa With New StormEncryptor Ransomware

Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor. The group previously relied on Medusa ransomware. StormEncryptor is written in C++ and encrypts files and adds the .encrypted extension, then…

MSP Credential Security Gaps Raise Multi-Client Breach Risk

MSPs’ access to credentials across dozens or even hundreds of customer environments can turn a single compromised login into a multi-client security incident, putting credential management, technician access and offboarding practices under growing scrutiny. Chris Skipworth, CEO of MSP-focused password management provider Passpack, spoke with Channel Insider about where credential security breaks down inside MSPs,…

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)

A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog and needs to be remediated by US civilian federal agencies by August 14, 2026. Details about the attacks are currently under wraps. Cisco…

North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job

Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls. Check Point Research has uncovered a new wave of Operation Dream Job, the long-running North Korean campaign that lures defense and aerospace professionals with convincing fake job offers. This iteration is more dangerous than previous…

DDoS attacks hit record scale as 1 Tbps+ campaigns become more common

DDoS attacks grew in scale during the first half of 2026, bringing larger traffic floods, shorter attack durations, and increasingly automated campaigns. Cloudflare’s H1 2026 DDoS Threat Report shows threat actors relying on multi-vector techniques and large-scale network-layer attacks to disrupt online services across multiple industries. L3/4 attack-size distribution (bitrate), H1 2026 (Source: Cloudflare) Network-layer…