Geek Guy

Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack

Nearly nine out of 10 federal civilian executive branch agencies failed to meet last summer’s deadline to implement cloud security directives from the Cybersecurity and Infrastructure Security Agency, a watchdog report published Wednesday found. The conclusions from those results, according to the inspector general for the Department of Homeland Security: agencies “may encounter elevated security…

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below – gocommunity-io/dockerd (222 downloads) kreuzwenker/

DoorDash Spent $1.4 Million Trying to Stop Mamdani From Becoming Mayor. Now We Know Why.

Last year, well before DoorDash’s $131.5 million settlement with New York City for underpaying 264,000 delivery workers was announced Tuesday, the company spent around $1.4 million on the campaign to stop Zohran Mamdani, who oversaw the historic settlement, from becoming mayor. At the time, DoorDash’s campaign contributions in the run-up to the 2025 mayoral election…

Lenovo Expands Virtualization Portfolio for AI-Ready IT

Lenovo is expanding its virtualization portfolio with new infrastructure, deployment services, and validated solutions designed to give enterprises more flexibility as they modernize legacy environments and prepare for AI workloads.  The additions include the ThinkAgile VX850 V4, expanded Infrastructure Deployment Services, and new Express Solutions spanning Microsoft, Red Hat, Nutanix, and SUSE technologies. For channel…

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at

CVE-2026-87902: Critical WordPress Core Flaw Enables Unauthenticated RCE Under Certain Conditions

WordPress has released an emergency security update addressing a critical vulnerability in its Core software that can allow an unauthenticated attacker to load arbitrary local PHP files and, under specific server and theme conditions, achieve remote code execution. Tracked as CVE-2026-87902, the vulnerability affects WordPress releases from version 4.7.0 through 7.1.1 and carries a CVSS…

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution

Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution. Adobe Bridge is a creative asset manager that lets you preview, organize, edit, and publish multiple creative assets quickly and easily. Adobe Connect is a secure, highly customizable web conferencing and virtual training platform used for…

OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems 

OpenAI and the Ukrainian government have agreed to a partnership that will provide AI tools and subsidized computing resources to better protect the nation’s critical infrastructure from cyberattacks. The agreement, announced Wednesday at OpenAI’s New York office, will provide Ukrainian cybersecurity officials with access to advanced AI models designed for cybersecurity work through the company’s…

CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Exploited for Remote Code Execution

F5 has disclosed a critical zero-day vulnerability affecting BIG-IP Access Policy Manager (APM) that is already being exploited in the wild. Tracked as CVE-2026-94127, the flaw can allow an unauthenticated remote attacker to execute arbitrary code on vulnerable BIG-IP systems by sending specially crafted traffic to an affected OAuth configuration. The vulnerability is a heap-based…

CVE-2026-93616: Check Point Management Server Zero-Day Exploited in Targeted Attacks

Check Point has released emergency security updates for a critical zero-day vulnerability affecting its Security Management infrastructure after confirming exploitation in targeted attacks. Tracked as CVE-2026-93616 and rated 9.8 on the CVSS scale, the flaw enables an unauthenticated attacker with network access to the vulnerable management service to upload and execute arbitrary scripts. The vulnerability…

GitHub App keys can still enable takeovers long after they are forgotten

GitHub allows organizations to install GitHub Apps that automate and extend certain functionality on the platform and have access to selected repositories and permissions. But the private keys these applications use to authenticate themselves can remain valid for years unless manually revoked. If leaked, those keys can potentially give attackers administrative control over an organization’s…

Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever

The Australian Signals Directorate (ASD) has this month issued a clear call to action through its Multi-factor authentication: Switch it on campaign, urging businesses, organisations, and individuals to enable multi-factor authentication (MFA) across their online accounts. At AWS, we strongly support this message. As threat actors continue to target credentials through phishing, credential stuffing, and…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

Cofense measures employee readiness against real-world phishing threats

Cofense has announced an expansion of its AI-driven Phishing Defense Platform through Cofense Command Center, its orchestration layer for measurement and reporting. The new Competency Dashboard measures how employees recognize, report and respond to phishing threats, giving security teams evidence of program effectiveness rather than training completion. This measurement advances Secure Behavior Management (SBM), an…

ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack

ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead…

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below – @memtensor/memos-cloud-openclaw-plugin versions

Portnox detects and removes unauthorized AI applications from managed devices

Portnox has announced new capabilities to detect unauthorized AI applications and agents on managed devices and automatically enforce security policy, restricting, quarantining, or removing unapproved or risky applications the moment they’re detected. The capability addresses shadow AI: generative AI applications that increasingly act as autonomous agents, reaching local files, remote resources, and enterprise data with…

Network Solutions Dark Web Monitoring alerts small businesses to domain-linked data exposure

Network Solutions has launched Dark Web Monitoring, a new security capability that alerts small businesses when information associated with their domain appears in known breach data and provides steps they can take to reduce risk. Stolen credentials and other information exposed in data breaches can circulate across dark web marketplaces, forums and other sources. For…

Finnish AI Cloud Startup Verda Raises $189M, Tops $1B Valuation

Finnish AI infrastructure startup Verda has raised $189 million in an oversubscribed Series B round, pushing its valuation above $1 billion as it expands GPU capacity across Europe. Emergence Capital led the round, joined by Supermicro, MUFG Innovation Partners, Varma, Lifeline Ventures, 6 Degrees Capital, byFounders, Tesi, and several angel investors. The financing brings Verda’s…

Okta Expands AI Agent Security and Governance

Okta is expanding its identity security controls for AI agents, adding new capabilities for agent discovery, access governance, runtime enforcement, and rapid response as enterprises deploy more autonomous AI across their environments. The new capabilities build on Okta’s blueprint for the secure agentic enterprise, introduced in March 2026, and are designed to answer four increasingly…

Barracuda brings AI security and governance within reach of smaller organizations

Barracuda Networks has launched Barracuda AI Data Security, the AI security and governance solution purpose-built for resource-constrained organizations and managed service providers (MSPs). The solution enables businesses to accelerate AI adoption by protecting sensitive data, enforcing responsible AI use and demonstrating compliance. Barracuda AI Data Security represents a major milestone in Barracuda’s expanding AI Security…

Lookout targets smishing, voice cloning, and vishing with real-time mobile protection

Lookout has launched Social Engineering Protection (SEP), a new module within the Lookout Mobile AI Security Platform. SEP provides automated, real-time protection against the next generation of AI-driven mobile threats, including linkless smishing attacks, synthetic voice cloning, and other voice phishing (vishing) techniques. Frontier AI is transforming social engineering by enabling attackers to create highly…

Fake Claude Max giveaway tricks users into handing over their Google account credentials

A fake Claude Max giveaway uses a spoofed Google sign-in window to steal users’ login credentials, Malwarebytes researchers have found. “Browser-in-the-browser” is not a new technique. Researchers have documented it since 2022, and in June Palo Alto Networks’ Unit 42 reported a campaign that used draggable fake browser windows to target Microsoft 365 users. “Phishing…

EvilTokens made phishing-as-a-service look easy. Then it got taken down

Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens showed up in February 2026 and moved fast. Within months it had compromised more than 12,000 inboxes across over 10,000 organizations. Microsoft says the EvilTokens platform, operated by Storm-2992, is a phishing-as-a-service kit sold…

Black Hat Fireside Chat: As AI agents spread, the network shifts from traffic mover to policy enforcer

The network’s job has always been simple: watch the traffic. Authority stopped there. Related: AI agents have a Lord Of The Flies problem For decades, network traffic came from something physical: a server, a laptop, a badge reader, a printer, each with a fixed address. An AI agent isn’t physical, and it has no fixed…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

Phishing Risk Across 5 Key US Industries: ANY.RUN Data & Mitigation Strategies

According to fresh ANY.RUN data, phishing exposure remains above 70% in several critical industries. This doesn’t happen because organizations aren’t protected enough. Companies have been implementing email filtering, MFA, and phishing-awareness training for years. However, threats continue to evolve, and security methods that were highly effective yesterday can develop visibility gaps as attackers adapt. In…

Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances

Check Point Software has released emergency fixes for a critical Check Point Management Server vulnerability (CVE-2026-93616) that has been exploited as far back as July 23, 2026. The company also confirmed that a pre-authentication remote code execution (RCE) vulnerability (CVE-2026-85102) in Check Point (Quantum) Security Gateway for which it released patches on September 9, 2026,…

Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes

The EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations, has been disrupted by a coalition of law enforcement and private-sector partners led by Microsoft. With authorization from the US District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation…

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break

Cofense Expands AI-Driven Phishing Defense Platform to Advance Secure Behavior Management

New Competency Dashboard in Cofense Command Center measures organizational readiness against phishing and connects employee behavior with real-world threat signals  News highlights Cofense Command Center, the orchestration layer for measurement and reporting across the Cofense Platform, brings more of the phishing defense lifecycle into a single view beginning with how employees recognize, report and respond to…

A Vulnerability in F5 BIG-IP Access Policy Manager Could Allow for Remote Code Execution

A vulnerability has been discovered in F5 BIG-IP Access Policy Manager (APM) that could allow for remote code execution. BIG-IP APM is a widely deployed network access and identity management solution used across government agencies, financial institutions, healthcare organizations, and large enterprises to control application and network access. Successful exploitation of this vulnerability could result…