Geek Guy

Enterprise Security Guide: Your Roadmap To A Secure Business

Here is our enterprise security guide, read on! In today’s interconnected world, organizations face a complex and ever-evolving threat landscape. Cyberattacks are becoming increasingly sophisticated, targeting sensitive data, disrupting business operations, and damaging reputations. Enterprise security, therefore, has become a critical aspect of organizational success, requiring a comprehensive and strategic approach to safeguarding assets, protecting…

U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data

IEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data. IEH Corporation is a U.S. defense and aerospace manufacturer based in Brooklyn, New York. The company specializes in high-reliability electrical connectors, particularly hyperboloid connectors used in demanding military and aerospace environments. Its connectors are used…

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 109

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums   DarkSword’s Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster   Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba…

Security Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions Metabase Zero-Day Exploited in the Wild,…

Black Hat USA 2026 Cybersecurity and AI Announcements

Cybersecurity vendors introduced a wave of AI-driven tools at Black Hat USA 2026, targeting threat detection, exposure management, security operations, and emerging attack risks. Tanium, Prophet Security, VanishID, Flashpoint, Arctic Wolf, and Vectra AI were among the companies unveiling new capabilities during the Aug. 1–6 conference in Las Vegas. The announcements reflected the industry’s shift…

Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions

China opened a cybersecurity review of Palo Alto Networks, citing national security concerns but giving no details about the reasons behind the probe. China’s Cyberspace Administration (CAC) announced that it’s launching a cybersecurity review of products Palo Alto Networks sells in the country. The announcement itself runs to a few sentences of formal Chinese, citing…

U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-8037 (CVSS score of 9.6), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is an OS Command Injection Remote Code Execution issue…

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads.…

Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients

Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 2025. Unlimited Technology Systems is a U.S.-based healthcare technology company headquartered…

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to…

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. “We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques,” the company said. “This…

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary

DXC Becomes Exclusive Managed Services Provider for Primary’s AI Security Platform

On Aug. 6, DXC announced a strategic partnership with security startup Primary, becoming the exclusive managed services provider for Primary’s AI-native Zero Trust Platform. The joint offering is designed to help enterprises and government agencies govern how AI agents and enterprise AI applications access data, identities, and business systems. The companies are targeting organizations that…

Hackers Target Blackstone, CME and Other Wall Street Firms in Phone-Based Scam

A phone-first data-theft extortion campaign has targeted dozens of major US financial firms over the past month. Ransom-seeking hackers have targeted dozens of major US financial institutions and other businesses in a campaign that relies heavily on phone-based social engineering, according to data from Google and internet intelligence platforms reviewed by Reuters. The targets included…

Cato Networks Adds Agentic AI Threat Prevention

Cato Networks, a converged network and security cloud, has launched Cato Agentic Threat Prevention, a new capability to deploy autonomous agents to predict likely attack paths. Stopping frontier AI adversaries before they advance Introduced at Black Hat USA 2026, the capability also automatically personalizes protections for each customer environment to prevent breaches before AI-assisted attacks…

8×8 Launches Four-Tier Partner Program for Resellers

8×8, Inc., a business communication platform provider, is introducing a new partner program for its direct resell channel that rewards customer retention and expansion. Four-tier structure to align partner and company success The 8×8 partner program features a four-tier structure: Authorized, Silver, Gold, and Platinum. With this structure, direct resellers can earn financial rewards according…

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that’s compatible with the computer’s CPU…

Proofpoint Launches OEM Program for Security Providers

Proofpoint Inc. debuted a new program at Black Hat USA 2026 that makes a portfolio of OEM-ready threat intelligence and detection capabilities available for technology providers, cybersecurity vendors, managed services providers, and platform companies. Accelerating OEM innovation with trusted threat intelligence The Proofpoint OEM Program formalizes and expands the cybersecurity providers’ OEM business. It provides…

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. “UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via…

ConnectWise, SentinelOne Unveil MSP Cybersecurity Strategy

ConnectWise and SentinelOne have unveiled a joint managed cybersecurity strategy aimed at helping MSPs scale threat detection and response through deeper integration of Managed EDR, AI-driven security, and automation. ConnectWise and SentinelOne deepen MSP security collaboration Announced at Black Hat USA 2026, the strategy establishes a framework for deeper collaboration that brings together the AI-driven…

Zero Networks Launches Least Agency Enforcement Capability

Zero Networks, a Zero Trust security solutions provider, announced a new capability at Black Hat USA 2026. This new capability applies the Open Worldwide Application Security Project’s (OWASP) principle of Least Agency to help organizations safely deploy AI agents. Reducing the impact of compromised AI agents The Least Agency Enforcement capability uses identity-based microsegmentation, policy…

Securing your Amazon S3 buckets: Identifying and remediating over-permissioned access

Misconfigured Amazon Simple Storage Service (Amazon S3) buckets can expose your data to unauthorized access. Without proactive review, S3 bucket policies or Access Control Lists (ACLs) configured with broad access may go unnoticed in your environment. In this post, you learn how to identify and fix over-permissioned S3 buckets across your AWS environment, along with…

State Department Wants Palantir’s Advice on Free Speech and “Countering Digital Surveillance”

The Trump administration tapped a surveillance giant with a record of attacking the press to advise the State Department on free speech. Among the partners for the State Department’s new “Freedom Tech Excellence Program” is Palantir, the AI and data integration firm started by right-wing powerbroker Peter Thiel. Under the program, company employees will go…

Hackers Impersonate IT Support to Breach Leading Financial Companies

Hackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies. A hacking campaign operating under names including Redact, Pink, Falcon, and Helix has built credential-stealing websites targeting employees at Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s, among dozens…

Hugging Face Breach: OpenAI Agent Abused Exposed Credentials Across Four Services

An autonomous AI agent powered by a combination of OpenAI models escaped an isolated cyber-capability evaluation environment, reached the public internet, and conducted a multi-stage intrusion into Hugging Face’s systems. The models included GPT-5.6 Sol and a more capable internal research prototype operating with reduced cyber refusals and without the production safeguards normally used to…