Geek-Guy.com

Malware authors subvert AI detection systems

Enterprises that have turned to AI in order to boost their security defenses may have to reconsider their approach. Malware containing code that commands LLM-assisted products to abort their analysis or refuse to implement it is already circulating, according to a post from security company SentinelLabs. SentinelLabs thinks it knows who’s responsible for the malware,…

EU: Microsoft, Amazon cloud services could be classified as gatekeepers

Following a seven-month investigation, the European Commission has reached a preliminary decision that Amazon’s and Microsoft’s cloud platforms — AWS and Azure, respectively — should be classified as “gatekeepers” under the EU’s Digital Markets Act (DMA), Reuters reports. The DMA, also known as the Digital Markets Regulation, aims to limit the market power of dominant…

Cyberattacks pose a ‘threat to life’ in Australia

Australia’s Security Intelligence Organization (ASIO) has uncovered an attack on a critical infrastructure operator’s network. State-sponsored actors had compromised the network and were preparing to sabotage it, according to its director general, Mike Burgess. Other countries face similar cyber-threats to critical infrastructure. It’s impossible to exaggerate the danger that the country is facing from cyberattacks…

Cyberattacks pose a ‘threat to life’ in Australia

Australia’s Security Intelligence Organization (ASIO) has uncovered an attack on a critical infrastructure operator’s network. State-sponsored actors had compromised the network and were preparing to sabotage it, according to its director general, Mike Burgess. Other countries face similar cyber-threats to critical infrastructure. It’s impossible to exaggerate the danger that the country is facing from cyberattacks…

Framewerx CEO on AI’s Next Chapter for MSPs

How can AI help managed service providers reduce repetitive work while improving cybersecurity for small businesses? In this Channel Insider interview, Victoria Durgin speaks with Dan Reid, CEO of Framewerx, about the launch of Neuralwerx—an AI-powered platform designed to automate routine MSP tasks, lower security costs for SMBs, and free IT professionals to focus on…

Comparing Antivirus Software 2026: Avast vs. AVG

This guide is for consumers, freelancers, and small business users comparing Avast and AVG antivirus software in 2026. It evaluates pricing, malware protection, features, customer support, performance, and privacy considerations to help you determine which antivirus solution best fits your needs. Key Points about Avast vs AVG Antivirus in 2026 Avast and AVG provide nearly…

Massive Breaches, AI Risks, and Critical Vulnerabilities Define This Week in Cybersecurity in June 2026

Major Threats & Vulnerabilities Critical Software and Hardware Exploits The FFmpeg PixelSmash vulnerability was disclosed this week, allowing remote code execution (RCE) through malicious video files. The flaw, found in the MagicYUV decoder, can trigger automatically during thumbnail generation. Users are urged to patch immediately and audit systems for exposure. Apple devices were also affected…

8 Best Linux Distros for Forensics & Pentesting in 2026

This guide is for penetration testers, digital forensics investigators, security professionals, and IT administrators looking for the best Linux distributions for cybersecurity in 2026. It compares eight leading Linux distros for ethical hacking, penetration testing, incident response, and digital forensics to help you choose the right platform based on your experience level and security objectives.…

Forget the Apple tax, this is the AI tax

Apple’s decision to raise prices in response to memory cost increases is not unique to the company. If Apple has to do it, everyone else will as well.  Apple announced stiff price increases Thursday — up to 25% in some cases — that extended across most products, including refurbished Macs and iPads (which saw prices increase up to…

23 Top Open Source Penetration Testing Tools in 2026

This guide is for security teams, penetration testers, and IT administrators looking to evaluate the best open-source penetration testing tools in 2026. It compares 23 leading tools across web application security, network scanning, password auditing, exploitation, wireless testing, and other key penetration testing categories to help you choose the right solutions for your environment. Key…

New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

A flaw in the Linux kernel’s traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331, nicknamed “pedit COW,” is an out-of-bounds write in the packet-editing action (act_pedit) that corrupts shared page-cache memory. A public, working exploit appeared within a day of the CVE assignment on June 16. Red Hat rates the flaw as

CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability in question is

Critical open-source projects get a new security framework

Open source software projects are getting a new framework for handling security vulnerabilities as AI shortens the time between flaw discovery and exploitation. The Linux Foundation has launched Akrites, an industry initiative that brings together technology companies, financial institutions, security vendors, AI companies, and open source projects to support the remediation and disclosure of vulnerabilities…

Synology issues critical fix for MailPlus Server vulnerabilities

Synology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. The security update fixes three flaws: CVE-2026-13136, stemming from faulty authorization checks, may allow remote attackers to read or write arbitrary files and conduct denial-of-service (DoS) attacks CVE-2026-13135, caused by improper restriction of…

U.S. CISA adds Cisco and PTC Windchill and FlexPLM flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco and PTC Windchill and FlexPLM flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Cisco and PTC Windchill and FlexPLM flaws to its Known Exploited Vulnerabilities (KEV) catalog. The two flaws added to the catalog are: CVE-2026-12569 (CVSS score of 9.3)…

Why SpaceX is the McDonald’s of AI

Have you seen “The Founder”? It’s the story of McDonald’s and how Ray Kroc (played by Michael Keaton) transformed the company from a local burger joint to a global landlord. According to the movie, Kroc’s accountant gave him the revelation: “You’re not in the burger business. You’re in the real estate business.” When brothers Richard…

Ransomware gangs find Europe’s weakest link in third-party suppliers

Ransomware attacks against European organizations increased during the first months of 2026, with third-party suppliers becoming a major entry point for attackers. Black Kite examined 2,066 ransomware incidents across 31 countries between January 2025 and April 2026 in its 2026 European Cyber Risk Report. Country distribution of ransomware attacks (Source: Black Kite) “Three forces are…

UK AI Adoption Raises Security and Compliance Risks

As AI adoption accelerates across UK businesses, security and compliance teams are working to align deployments with GDPR requirements and new government cybersecurity guidance.  Regulators and industry bodies warn that widespread use of unapproved AI tools and third-party platforms is creating governance and data security risks that many organizations are only beginning to address. UK…

Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials

Mirage2FA, a phishing kit that combines short-lived HTML smuggling with obfuscated JavaScript loaders to deliver fake Microsoft 365 login pages and steal credentials during MFA prompts, has been identified by researchers at Fortra. Fortra based its analysis on a suspicious HTML and JavaScript attachment delivered by email, supporting DNS data, and the second-stage phishing page.…

Mystery hackers use novel SharkLoader dropper against governments, software devs

Kaspersky researchers have uncovered a previously unknown cyberattack campaign that has compromised government organizations and software development companies in multiple countries. They first stumbled onto the campaign while investigating an attack on a diplomatic organization in Indonesia. What initially looked like an isolated incident revealed a global operation they’ve dubbed StrikeShark, due to the attackers’…

Why AI is Driving Renewed Demand for Private and Hybrid Cloud

For years, enterprise cloud conversations centered on migrating workloads to public cloud platforms. At HPE Discover 2026, however, executives and partners painted a different picture: artificial intelligence is accelerating demand for private and hybrid cloud environments rather than replacing them. “The single most powerful hybrid workload is AI,” Jim O’Dorisio, senior vice president and general…

How Smart Sensors Improve Modern Security Systems

In this post, I will show you how smart sensors improve modern security systems. Modern security systems need more than cameras and alarms. Businesses now manage risks across entrances, restrooms, storage rooms, shared offices, warehouses, parking areas, schools, healthcare spaces, and public facilities. Smart sensors improve security by detecting conditions that traditional systems may miss.…

SIM-swapping gang busted in international police operation

Officers from Poland’s Central Bureau for Combating Cybercrime (CBZC) arrested four suspected members of an organized cybercrime group accused of SIM swap attacks, cryptocurrency theft, and money laundering. The operation involved agents from the U.S. Federal Bureau of Investigation (FBI) and Homeland Security Investigations (HSI). The investigation is being supervised by the Regional Prosecutor’s Office…

ZeroTier Quantum RC2 brings post-quantum security closer to general availability

ZeroTier has announced the release candidate 2 (RC2) for ZeroTier Quantum, its end-to-end quantum-secure networking platform. This milestone marks the final testing phase, positioning the platform one step away from general availability (GA). ZeroTier Quantum addresses the looming threat quantum computing poses to traditional encryption by meeting the NIST and NSA’s highest CNSA 2.0 standards,…

Google Details Turla’s New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that has been deployed against government and military organizations in Ukraine, and entities that have an interest in Italian foreign policy. Describing the Windows backdoor as continually developed by the hacking group, Google Threat Intelligence Group…

Modelplane: Open-source control plane for AI inference

Organizations that run open-weight models on hardware they own operate GPU fleets spread across clouds, neoclouds, and on-premise data centers. Each fleet handles model placement, replica scaling, infrastructure provisioning, weight distribution, and traffic routing. Teams have built this coordination layer by hand, one operator at a time. Upbound, the company behind the Crossplane project, released…

New infosec products of the month: June 2026

Here’s a look at the most interesting products from the past month, featuring releases from AISLE, Asimily, Blue Planet, depthfirst, Diligent, Drata, Elastic, Filigran, Flip, Hyland, IDnow, Legit Security, MazeBolt, Noma, Qodo, Ridge Security, Tigera, and WitnessAI. Asimily turns device risk into automated network policy Asimily has launched Segmentation Orchestration, enabling connected-device risk intelligence to…