Geek-Guy.com

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS…

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute…

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities. Anyone who visited a site carrying the affected script on July 27 and…

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could…

South Korea Warns of State-Backed Watering Hole Attacks

South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute) jointly published an advisory warning that a state-backed hacking group is actively targeting South Korean…

Claude published malicious code to the Internet and attacked 3 real companies

Anthropic said its Claude-based security models gained unauthorized access to the sensitive production environments of three outside organizations during internal testing designed to measure the models’ offensive cyber capabilities. The events, which Anthropic revealed Thursday, are the second revelation in 10 days that AI models from the world’s wealthiest providers have trespassed into protected networks,…

Anthropic Says Claude Found New Attacks on HAWK and Reduced-Round AES

AI is beginning to do more than find software vulnerabilities. Anthropic says its Claude Mythos Preview model has now contributed new techniques for analyzing the mathematics behind cryptographic systems. The model developed an improved attack against the post-quantum signature candidate HAWK and accelerated an existing line of attack against a seven-round version of AES-128, according…

Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world

Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world

President Donald Trump blamed Minnesota Friday for the cyberattacks its water systems have suffered in recent days, saying the state was “behind it.” Trump said the state being “incompetent” was the issue, but it wasn’t clear whom he thought actually conducted cyberattacks that U.S. investigators have attributed to Iran — if, perhaps, somehow Minnesota incompetently…

AI Ransomware Raises Stakes for Cyber Recovery

Artificial intelligence is changing ransomware at a pace many enterprises are struggling to match. While most cybersecurity conversations continue to center on preventing attacks, the growing sophistication and speed of AI-enabled ransomware is forcing organizations, and the channel partners that support them, to rethink cyber resilience from the standpoint of recovery. AI expands the ransomware…

HIPAA Security Rule on AWS – Technical Safeguards Implementation and Readiness Guidance

Today, we’re releasing the HIPAA Security Rule on AWS: Technical Safeguards Implementation and Readiness Guidance. This helps covered entities and business associates configure, implement, and evidence compliance with the HIPAA Security Rule Technical Safeguard requirements (45 CFR §164.312) when building healthcare workloads on AWS. The HIPAA Security Rule’s Technical Safeguards (§164.312) define five standards and…

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. These targeted organizations operate across several sectors, such as healthcare, research, government offices,

South Korea Fines KT $37.4M for Failing to Stop Long-Running Network Intrusion

South Korea’s Personal Information Protection Commission (PIPC) has fined KT Corp. 53.9 billion won ($37.4 million) after finding that weak network access controls allowed hackers to expose the personal information of 16,647 mobile customers. The regulator said hackers accessed KT’s wireless network through an unauthorized femtocell, a small base station used to extend mobile coverage,…

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that

Intel 471 Warns of Expanding Software Supply Chain Attacks 

Software supply chain attacks are evolving beyond compromised software packages into attacks targeting the people, identities, and workflows used to build and distribute software.  Intel 471’s report, Poisoned Trust: How Supply Chain Attacks Weaponize Developer Ecosystems, found that threat actors are increasingly targeting developer accounts, CI/CD pipelines, repositories, IDEs, and publishing infrastructure.  By compromising these…

5 Best MDR Services for Businesses and MSPs in 2026

Managed detection and response services give organizations access to 24/7 threat monitoring, investigation, and incident response without requiring them to build a complete security operations center. They combine security technology, automation, and human expertise to help organizations identify and contain threats more efficiently. We evaluated five leading MDR providers for 2026 based on threat coverage,…

Enterprise ERP AI Adoption Outpaces Security Readiness 

Organizations are rapidly embedding artificial intelligence (AI) into enterprise resource planning (ERP) systems, but many cybersecurity leaders remain unconvinced that their organizations are prepared to secure these environments.  According to the 2026 Onapsis State of AI, Security, and ERP report, AI adoption is accelerating across SAP, Oracle, and Salesforce environments even as concerns about security,…

AI-Speed Attacks and Critical Flaws Compress Defenders’ Response Window this Week of July 2026

This week’s cybersecurity landscape was defined by attacks against critical infrastructure, actively exploited enterprise flaws, rapidly expanding AI exposure, and major compromises involving healthcare, energy, financial, and retail data. At the same time, AI agents demonstrated how quickly vulnerabilities can be discovered and weaponized, reinforcing the need for faster patching, stronger identity controls, continuous asset…

Broadcom patches vulnerabilities all over VMware

Broadcom has addresses five vulnerabilities in its VMware product range, three of which have been accorded a “critical” rating. The affected products are: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure CVE-206-59309 affects the VMware Directory Service. According to Broadcom,…

Cybercrime goes subscription: AI, malware and infrastructure on demand

Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These services provide anonymity, plausible deniability, and access to short-lived infrastructure that is difficult to detect, attribute, and disrupt, enabling low-skilled actors to operate at scale, according to the Infoblox 2026 Threat Landscape Report. “Cybercrime…

What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery

An AI-assisted audit found 29 flaws in GlobaLeaks, showing LLMs make large-scale code reviews faster, cheaper, and accessible. GlobaLeaks, a mature whistleblowing platform that had already undergone six independent professional audits over the past thirteen years, was subjected to an LLM-assisted security review that cost roughly USD 3,140 in API calls. The review identified 29…

Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire

A security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years. Fuyao apps ecosystem (Source: Bitsight) According to Bitsight, the operation, named Fuyao, uses preinstalled Android apps, device identity spoofing, AI-generated websites, and residential proxy services to generate advertising revenue without device owners’ knowledge.…

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

An academic study has disclosed a “widespread class” of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user’s network session. The findings have been released by a group of researchers from Singapore’s Nanyang Technological…