Geek Guy

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below – CVE-2025-39682 (CVSS score: 9.8) – An improper check for unusual or exceptional conditions vulnerability in the TLS receive path

Druva Adds Ransomware Detection to Cut False Positives

Druva is expanding its cyber recovery portfolio with new ransomware detection and identity resilience capabilities designed to help security teams validate attacks faster, reduce false positives, and identify clean recovery points before restoring data. The company’s new Ransomware Detection capability analyzes backup snapshots for high-risk ransomware behavior and then applies additional forensic validation to determine…

What GTIA’s ASCII Group Acquisition Means for Partners

The Global Technology Industry Association (GTIA) has acquired The ASCII Group, expanding its member community while increasing investment in the programs, resources, and experiences that support IT service providers (ITSPs). The acquisition brings together GTIA’s leadership in research, education, cybersecurity, and industry strategy with The ASCII Group’s business tools and peer-driven community model. “We’ve been…

UltraViolet Cyber Launches Equinox for Detection Gaps

UltraViolet Cyber has launched Equinox, an AI-assisted detection engineering platform designed to identify gaps across customers’ existing security tools and expand mapped threat coverage without adding unnecessary alert volume. Equinox maps customer-specific detection gaps In its official announcement, UltraViolet Cyber highlighted how security teams may have thousands of detections available across their security information and…

StorMagic, Mako Networks Link Edge HCI and SD-WAN

StorMagic and Mako Networks are integrating edge hyperconverged infrastructure with secure SD-WAN in a new partnership aimed at businesses operating across large numbers of distributed locations. The agreement combines StorMagic SvHCI, which provides edge compute, storage, and virtualization, with Mako Networks’ secure SD-WAN and cloud-managed networking platform.  The companies say the integration is designed to…

Brevo Supply-Chain Attack Infected Over 100,000 Websites

A Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over 100,000 sites. Brevo, formerly known as Sendinblue, is a French cloud-based marketing and customer communication platform whose clients include eBay, Louis Vuitton and Michelin. The company was first compromised on September 10, when attackers exploited a vulnerability in its…

Arrow Electronics, Usercentrics Sign EMEA Distribution Deal

Arrow Electronics is expanding its privacy and consent management portfolio through a new distribution agreement with Usercentrics, bringing the company’s Cookiebot CMP to channel partners across eight European markets. The agreement covers Austria, France, Germany, Italy, Portugal, Spain, Switzerland, and the U.K., giving Arrow partners another platform to help customers manage consent requirements and navigate…

MDR vs MXDR vs Managed SOC: Key Differences

The main difference among MDR, MXDR, and a managed SOC lies in scope. MDR provides managed threat detection and response; MXDR correlates detection and response across multiple security domains; and a managed SOC can operate a broader set of security functions, including monitoring, tool administration, detection engineering, reporting, and compliance support. Choosing between them depends…

International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data

North Korean hackers are infiltrating tens of thousands of job seekers’ computer networks by posing as prospective employers, such as artificial intelligence firms, to steal sensitive information and millions of dollars worth of cryptocurrency, U.S. and allied governments warned Friday. The security agencies behind the alert, attributed the group, known as WaterPlum or Contagious Interview,…

A zero-click RCE flaw in AI coding agents could have exposed enterprise systems

Popular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned GitHub Copilot were vulnerable to a zero-click attack that enabled attackers to execute malicious code, even without developer interaction, by swapping a trusted plugin from an online marketplace for a malicious one, potentially giving them a foothold in enterprise…

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed…

Zero-Days, AI Agents, and Massive Data Leaks Define the Week

This week’s cybersecurity landscape combined actively exploited vulnerabilities, AI-assisted attacks, exposed credentials, trusted-channel phishing, and breaches affecting millions of people. Defenders face an increasingly compressed response window as automation accelerates exploitation and compromised infrastructure gives attackers new ways to evade user suspicion. Major Threats & Vulnerabilities Actively Exploited Zero-Days and Critical Flaws WooCommerce plugin exploitation:…

AI Infrastructure Gaps Open New Opportunities for Partners

As enterprises push artificial intelligence projects beyond pilots and into production, infrastructure limitations are becoming harder to ignore—and creating a new opening for channel partners. Dennis Frank, Vice President, EMEA Strategic Partners & Alliances at Hitachi Vantara, spoke with Channel Insider about why storage, data pipelines, and governance are emerging as critical AI bottlenecks, how…

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. “Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a…

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People’s Republic of Korea’s (DPRK) Contagious Interview campaign: BeaverTail and

Sponsor: SACR Sponsored by:
Software Analyst Cyber Research
Deeper Network Promo Image

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. “The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,”

Best MSP Software for 2026: RMM, PSA, Security & More

The best MSP software depends on the services an MSP delivers and the business functions it needs to manage. Most MSP technology stacks combine remote monitoring and management (RMM), professional services automation (PSA), IT service management, help desk, cybersecurity, and backup tools. For 2026, leading MSP software options include Atera and NinjaOne for RMM, HaloPSA…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. “Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses

New infosec products of the week: September 18, 2026

Here’s a look at the most interesting products from the past week, featuring releases from Akuity, Bitsight, Cohesity, Dataminr, Nozomi Networks, and Tuskira. Dataminr uses agentic AI to predict and verify security threats Dataminr has announced Dataminr Advanced for Corporate Security, delivering agentic AI capabilities that give corporate security teams the confidence to protect their…

Sponsor: SACR Sponsored by:
Software Analyst Cyber Research
Deeper Network Promo Image