Geek Guy

Canadian cybersecurity executive arrested in federal extortion case

Federal authorities arrested a Canadian cybersecurity executive Thursday in Pennsylvania on charges of conspiracy of extortion, according to federal court records posted Friday. Edward Dubrovsky, 54, is a former chief operating officer and founder of CYPFER, a firm that helps organizations negotiate with ransomware operators. He is charged with conspiring to threaten the confidentiality of…

Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws

Anthropic on Friday said it’s cutting off live internet access for all its internal evaluations following the discovery of new incidents in which its artificial intelligence (AI) models exhibited misaligned behavior and targeted real websites. The AI company said it identified four broad categories of unintended model actions during evaluations and internal use of Claude…

Okta Oktane 2026 Conference Report

Critical Takeaways, Technologies, Trends, and Case Studies Conference Dates: September 22-24, 2026Location: Caesars Forum, Las Vegas, NevadaAttendance: Over 4,000 attendees Executive Summary Oktane 2026 marked a pivotal moment in enterprise identity security, with Okta’s CEO Todd McKinnon announcing the Blueprint for the Secure Agentic Enterprise and forming the Blueprint Alliance. The conference demonstrated that AI…

Cybersecurity Mergers & Acquisitions Report (Oct 9, 2026)

Global cybersecurity M&A activity reached historic levels through the first three quarters of 2026, driven by demand for AI-native security, identity governance, and operational technology. Strategic platform vendors dominated transaction values, supported by several multi-billion-dollar megadeals and a sharp year-over-year surge in deal volume. Market dynamics shifted as non-cybersecurity buyers in finance, insurance, and data…

US Suspends Green Card Labor Certifications for Microsoft, Adobe, Six IT Firms

Microsoft, Adobe and six major IT services companies face new restrictions on sponsoring foreign employees for permanent residency in the United States. The Trump administration on Thursday suspended the companies from the federal Permanent Labor Certification Program, known as PERM, accusing them of abusing employment-based immigration rules. The affected companies are Cognizant, Infosys, Tata Consultancy…

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. “Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC,” StepSecurity

P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. “Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker’s infrastructure,” iVerify said in a new report published Thursday.…

Ransomware consultant said he would decrypt data, is accused of paying ransoms instead

The owner of a ransomware remediation company is facing trial for defrauding customers. Zohar Pinhasi, also known as “Zack Silver” and “Zack Green,” has been arraigned in New York on wire fraud charges for allegedly defrauding clients of his ransomware remediation company, MonsterCloud. Pinhasi falsely claimed he could recover documents encrypted by ransomware without paying…

Ransomware consultant said he would decrypt data, is accused of paying ransoms instead

The owner of a ransomware remediation company is facing trial for defrauding customers. Zohar Pinhasi, also known as “Zack Silver” and “Zack Green,” has been arraigned in New York on wire fraud charges for allegedly defrauding clients of his ransomware remediation company, MonsterCloud. Pinhasi falsely claimed he could recover documents encrypted by ransomware without paying…

Citrix issues its weekly critical security patch for NetScaler ADC and NetScaler Gateway

For the third week running, Citrix has issued a critical security warning to customers managing their own NetScaler ADC and Netscaler Gateway instances, this time warning of a memory overflow vulnerability enabling denial of service or remote code execution. This week’s vulnerability affects ADC and Gateway when configured as a SAML (Security Assertion Markup Language)…

A Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway Could Allow for Remote Code Execution

A vulnerability has been discovered in Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway that could allow for remote code execution. Citrix NetScaler ADC (Application Delivery Controller) is an enterprise networking platform and traffic management device designed to optimize, secure, and accelerate the delivery of web and cloud applications. Successful exploitation of the…

CVE-2026-107406: Critical NetScaler ADC and Gateway RCE Vulnerability

Citrix has disclosed CVE-2026-107406, a critical memory overflow vulnerability affecting NetScaler ADC and NetScaler Gateway appliances configured for specific SAML authentication roles. The flaw carries a CVSS v4.0 score of 9.5 and could enable an unauthenticated remote attacker to execute arbitrary code or trigger a denial-of-service condition on vulnerable systems. The vulnerability is particularly significant…

Claude Helps Secure Open Source as Anthropic Offers Free Vulnerability Scanning

Anthropic launches free OSS Scanner, using AI to find open-source vulnerabilities and help maintainers fix bugs before attackers exploit them. Anthropic is launching OSS Scanner, a vulnerability scanner for open-source code that costs nothing for projects to join. It grew directly out of lessons learned running Claude against real-world targets during Project Glasswing. The backdrop…

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as “fixed a bug that could lead to a crash,” with no CVE assigned and…

Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI). “It’s an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing,” Anthropic said. “Projects that join will receive thorough, periodic security scans by our strongest models at no cost.”

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below – CVE-2026-105133 (CVSS v4 score: 5.5) – An improper authentication vulnerability in the checkSysPwd() function in the “com/ahsay/obs/api/ApiStructsAction.java”

Exposed Nvidia GPU monitors can reveal AI infrastructure secrets

A component of Nvidia’s GPU monitoring software that enterprises use to keep tabs on their AI training and inference infrastructure has been vulnerable to denial-of-service (DoS) and information disclosure attacks. The Nvidia DCGM Exporter contains an unauthenticated resource exhaustion vulnerability that could allow remote attackers to crash the monitoring service and potentially disrupt AI workloads…

High-severity NVIDIA vulnerability lets unauthenticated attackers crash GPU monitoring

Hundreds of internet-exposed graphics processing unit (GPU) servers were open to a high-severity flaw in NVIDIA’s DCGM Exporter (CVE-2026-47483) that lets unauthenticated attackers crash the monitoring service and may disrupt AI workloads, according to Lava. Lava reported the flaw to NVIDIA, which rated it 8.2 on the CVSS scale and published a security bulletin on…

Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below – CVE-2015-3306 (CVSS score: 10.0) – An improper access control vulnerability in ProFTPD that could…

The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition

As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The “Horizons of Identity Security” report from SailPoint highlights a critical “velocity paradox,” in which organizations invest in AI-speed business operations while continuing to rely on human-speed security controls,…

ASOS breach update: Hackers stole customer details and shopping searches

The customer data stolen from global fashion retailer ASOS includes more than just names and contact details, raising questions about its early reassurances. As we reported earlier this week, ASOS customers received a push notification through the ASOS app alleging that the company had been hacked. ASOS has confirmed that attackers accessed customer information after tricking…

CVE-2026-107406: Citrix Fixes Critical NetScaler ADC and Gateway Vulnerability

Citrix patched CVE-2026-107406, a critical NetScaler ADC and Gateway flaw that could allow remote code execution or denial-of-service attacks. Citrix has released security updates to fix CVE-2026-107406 (CVSS score of 9.5), a critical flaw affecting NetScaler ADC and NetScaler Gateway that could allow remote code execution or denial-of-service (DoS) under certain conditions. The vulnerability is…

Product showcase: SimpleLogin keeps your email address private with aliases

SimpleLogin is an email alias service from Proton that forwards messages to an existing mailbox. Users create addresses for registrations, purchases, and correspondence, giving them control over where their primary email address is shared. The service is open source and supports self-hosting. Getting started I tried SimpleLogin using a Gmail address. After verification, the dashboard…

CVE-2026-59346: Critical VMware Workstation and Fusion Flaw Enables Guest-to-Host Code Execution

Broadcom has addressed CVE-2026-59346, a critical integer-overflow vulnerability affecting VMware Workstation and VMware Fusion. The flaw carries a CVSS score of 9.3 and can allow an attacker with administrative privileges inside a virtual machine to cross the virtualization boundary and execute code on the underlying host. The issue resides in VMware’s VMXNET3 virtual network adapter…