Geek-Guy.com

AISI, OpenAI report more ‘unsanctioned’ model hacks

The UK’s AI Security Institute said that their AI research system took “unsanctioned” actions over the internet to engage in “sustained, potentially harmful activity directed at real people.” According to a blog post and technical report released Tuesday, the organization noticed “unusual data transfers” leaving their research systems through the pseudo-anonymous Tor network on July…

Microsoft Warns Russian Hackers Use Hotel Wi-Fi to Steal Credentials

Connecting a work laptop to hotel Wi-Fi could expose corporate credentials and sensitive data. Microsoft has uncovered a Russian state-backed campaign that uses compromised hospitality networks to target travelers. Tracked as CaptiveCrunch, the campaign has affected networks in several countries since early May 2026. Malicious prompts appear during the normal connection process, allowing them to…

SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency

Swiss Federal IT Agency FOITT says attackers exploited SharePoint flaws to compromise about 200 accounts. Servers are being rebuilt as investigations continue. Switzerland’s Federal Office for Information Technology and Communications, known as BIT or FOITT, disclosed that unknown attackers had compromised approximately 200 accounts on its on-premises SharePoint servers. The FOITT said the unknown attackers…

China Tightens Chip Design Rules, Raises Bar for IP Protection

Beijing is strengthening legal protections around the blueprints at the heart of semiconductor development. China has revised its regulations covering integrated circuit (IC) layout designs, introducing stricter registration standards, stronger enforcement tools, and tougher penalties for infringement as it seeks to safeguard domestic semiconductor innovation. The updated rules, signed by Premier Li Qiang on July…

Lemongrass Debuts AI-First Model for SAP Modernization

Lemongrass, a specialist in SAP cloud transformation, has unveiled Brightfield, an AI-first modernization model designed to help enterprises realize measurable business value during SAP transformation programs rather than years after go-live. Built on Lemongrass’s LCP AI SaaS Edition (LINK) and delivered through SAP-centric Forward Deployed Engineers (FDEs), Brightfield embeds AI, automation, and Clean Core principles…

New Google Password Manager Attacks Can Hijack Synced Passkeys

Security researchers have uncovered three new attacks that could let malware hijack Google-synced passkeys and take over online accounts from compromised Windows devices. The techniques target Google Password Manager in Chrome and abuse weaknesses in device trust, user verification, re-registration, credential recovery, and passkey synchronization.  Depending on the technique, attackers could bypass verification, authenticate from…

Black Hat 2026: CrowdStrike Threat Hunting Report Findings 

Cyber adversaries are moving faster, exploiting trust instead of brute force, and increasingly combining automation with hands-on operations to evade traditional security controls.  CrowdStrike released its 2026 Threat Hunting report alongside Black Hat 2026.  Its findings show that threat actors are accelerating vulnerability exploitation, abusing artificial intelligence (AI), targeting software supply chains, and shifting toward…

Dem senators criticize Trump administration decisionmaking on AI security risks

The Trump administration’s haphazard and opaque interventions into artificial intelligence security matters could catapult Chinese alternatives into broader acceptance, posing new security risks altogether, a group of Democratic senators wrote to top administration officials Monday. The five senators said that the administration’s handling has alternated between too passive, such as when OpenAI models escaped testing…

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. “Greatness supports AiTM [adversary-in-the-middle] credential and

DEF CON 2026: Flare Launches Free Dark Web Intelligence Training Platform

Flare has launched Darkroom by Flare Academy, a free interactive training platform designed to give cybersecurity professionals practical experience investigating the types of underground environments where cyber threats originate.  The launch coincides with DEF CON 2026, where Flare will also host a live Darkroom event.  Unlike traditional cyber threat intelligence (CTI) training that often relies…

Airlock Digital Unveils Agentic AI Control & Governance to Extend Preventative Endpoint Security

Airlock Digital, a leader in preventative endpoint security, today announced Agentic AI Control & Governance at Black Hat USA 2026. The new capabilities build on application control by providing command- and session-level visibility into trusted AI agent behavior, centralized policy management for trusted applications and AI agents, and real-time governance over what trusted AI agents…

AI developers targeted via trojanized GitHub repositories

Cybercriminals are cloning popular GitHub repositories for AI tools and developer resources to distribute an infostealer, according to Netskope Threat Labs. (Source: Netskope) Netskope came across the campaign while tracking a Windows-based MaaS infostealer, first reported in April 2026, that was spread through the ClickFix social engineering trick. Continuing to follow the operation, the researchers…

GitHub Account Breach Fuels Shai-Hulud npm Supply Chain Attack 

A large-scale software supply chain attack is affecting the JavaScript ecosystem after attackers compromised the GitHub account of a maintainer behind several widely used npm packages.  The incident began on Aug.4, 2026, when malicious code was introduced into packages including keyv, flat-cache, and file-entry-cache, but quickly expanded into a broader Shai-Hulud campaign that has spread…

Sevii APS Module preempts attacks with autonomous cyber defens

Sevii has announced a major expansion of the Sevii Autonomous Defense & Remediation (ADR) platform with the general availability of an Autonomous Preemptive Security (APS) module. The new module complements ADRs autonomous defense against threats, extending the platform to continuously transform customer’s external global and internal environmental cyber intelligence into autonomous hypothesis hunting, exposure validation,…

INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit

INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations. Resecurity disclosed that INC Ransomware has emerged as the dominant threat actor exploiting the recently disclosed SonicWall Secure Mobile Access (SMA) 1000 vulnerabilities. According to the company’s research, the group has accelerated its operations since…

ServiceNow organizes autonomous security around six solution areas

ServiceNow has announced an acceleration of its Autonomous Security vision with six unified solutions that help deliver prevention-first, AI-native cyber defense across unified exposure management, continuous vulnerability detection, cyber-physical security, identity and access security, and agentic incident response, and cyber risk and compliance. With new AI Specialists that complete security workflows autonomously, including the Vulnerability…

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later…

Snyk unveils continuous AI pentesting and agent red teaming

Snyk has announced the general availability of Evo Continuous Offensive Security (COS), enabling security teams to continuously test applications with autonomous, AI-powered pentesting and AI agent red teaming while providing validated proof of what attackers could actually exploit. AI is accelerating software release cycles while rapidly expanding the exposed attack surface, which now spans architectural…

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKE#SCREEN by Securonix Threat

CVE-2026-18577: N-able N-central Authentication Bypass Lets Attackers Reach Managed Endpoints

N-able has released an emergency hotfix for an actively exploited authentication bypass in N-central, a remote monitoring and management platform widely used by managed service providers and internal IT teams. The flaw allows a remote, unauthenticated attacker to obtain administrative access to vulnerable N-central servers and use the platform’s legitimate management capabilities to reach downstream…

AvePoint Launches Kinetic Classification for AI Security

AvePoint has launched a new continuous data classification capability designed to help organizations identify sensitive information as files, permissions, and AI usage change over time. The company’s Kinetic Classification feature repeatedly reassesses enterprise data rather than relying on static labels, while new Rapid Recovery capabilities use that intelligence to help organizations prioritize which systems and…

RapidFort Runtime brings continuous CVE monitoring and tamper detection

RapidFort has launched RapidFort Runtime, a real-time security solution that extends RapidFort’s SSCS capabilities into live production environments. The offerings provide end-to-end continuous threat elimination, from curated, independently malware-scanned open-source software before deployment to continuous CVE monitoring and tamper detection in production. RapidFort Runtime operates inside an organization’s production environment continuously monitoring deployed software, detecting…

Black Hat 2026: Improving CISO to Board Cyber Risk Reporting 

Cybersecurity has become a standing agenda item in boardrooms, yet many chief information security officers (CISOs) still struggle to communicate cyber risk in a way that enables informed business decisions.  According to Pulse Security’s The CISO-Board Communication Gap report, released during Black Hat 2026, the challenge is not simply improving presentations.  Instead, the research suggests…

Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)

This morning, I noticed specific sources “hunting” for vulnerabilities in URLs that I haven’t noticed before. All of these URLs appear to be associated with diagnostic tools: URL Count Vulnerability / 1 (simple recon for index page) /apply.cgi 20 CVE-2024-12856 Four-Faith router command injection /cgi-bin/adv_ping.cgi 20 ? /cgi-bin/diagnostic.cgi 20 CVE-2013-7179 Seowon Intech WiMAX SWU-9100 mobile…

Critical Azure Cosmos DB flaw threatened cross-tenant database takeover

A critical vulnerability in Microsoft Azure’s Cosmos DB database service could have enabled attackers to escape the platform’s Gremlin query sandbox, execute code on shared infrastructure, and ultimately gain access to any customer’s database, including data stores used by Microsoft services such as Entra ID, Teams, and Copilot, according to research published by cloud security…

The top cybersecurity product announcements from Black Hat 2026

Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products. Vendors are increasingly packaging AI into operational workflows, while pairing automation with governance, exposure management, and recovery capabilities aimed at making autonomous security more practical for enterprise environments.…

RapidFort Runtime Extends Software Supply Chain Security

RapidFort has launched RapidFort Runtime, a security platform designed to extend software supply chain protection beyond development and into live production environments. RapidFort extends security monitoring into production The solution, RapidFort Runtime, creates an end-to-end continuous threat elimination solution from curated, independently malware-scanned open-source software before deployment to continuous CVE monitoring and tamper detection in…

Google ADK flaws reveal what happens when AI agents trust the wrong message

Security flaws in automated workflows in the GitHub repository for Google’s Agent Development Kit for Python could allow public-facing AI agents to trigger more privileged automation, opening one path to manipulate pull-request reviews and another to expose credentials, according to a report from Pillar Security. The first attack path involved a triage agent that analyzed…

When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted

The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break. Security teams have long estimated risk by ranking attacker sophistication. Nation-state actors sat at one end. Organized criminal groups followed. Inexperienced attackers, dismissed as “script kiddies,” sat at the other end, running public

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent. The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so…

U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a N-able N-central flaw, tracked as CVE-2026-18577 (CVSS score of 8.2), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-18577 (CVSS 8.2) is an authentication bypass flaw caused by an…

Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware

Midnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at places like hotels and conference centers, according to new findings from Microsoft Threat Intelligence. Overview of the CaptiveCrunch attack flow (Source: Microsoft) Microsoft named the campaign CaptiveCrunch and identified two malware strains…

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database’s root context, crossing the privilege boundary between a cPanel account and the server’s administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The database bug is tracked as CVE-2026-58048 (CVSS…