Geek Guy

OpenAI tightens defenses after AI agents breach research environment

Following the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production infrastructure by chaining together multiple weaknesses, OpenAI began strengthening its safety requirements. The weaknesses included previously unknown vulnerabilities and credentials leaked online. OpenAI President Greg Brockman said ChatGPT Work identified 13 security issues on his personal…

Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US

Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle (AiTM) attacks. ANY.RUN research shows that 63.7% of identified victims are in the US, with Technologies, Manufacturing, and Education among the most targeted industries. The operation has generated thousands of compromise events between 2024 and 2026, including stolen…

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by email on August 16 from security@safepal.com, with the subject line “[Important] Your SafePal Order

GitHub restores services after nearly 8-hour outage disrupts Actions, APIs, PRs and Copilot

GitHub has restored services after a nearly eight-hour outage disrupted several of its core developer tools, including Actions, pull requests, APIs, Git operations, Webhooks, and Copilot, impacting software development workflows across its platform. “This incident has been resolved. Thank you for your patience and understanding as we addressed this issue,” the company wrote on its status…

U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Ray-Project Ray vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2025-62593 (CVSS score of 9.4), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2025-62593 is a critical remote code execution (RCE) vulnerability in Ray,…

Synthesized builds Test Data Agent to validate AI agents with production-like data

Synthesized has announced its Test Data Agent, a new agentic infrastructure capability being developed to create and provision the realistic data, business context, and system states enterprises need to validate AI agents safely before production deployment. The Test Data Agent integrates with agent development, evaluation, testing, and orchestration frameworks, providing production-faithful environments for determining whether…

New Mirai-Based Evooo1Bot Botnet Targets Linux Devices

Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai‘s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a…

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than

Google’s open-source HEIR lets AI work with data it can’t see

Google’s researchers and engineers developed the Homomorphic Encryption Intermediate Representation (HEIR) compiler project, an open-source compiler toolchain and development platform for homomorphic encryption. It can convert pre-trained AI models designed to operate on unencrypted data into models that process encrypted inputs. The platform helps application developers, compiler engineers, hardware designers, and cryptography researchers develop privacy-focused…

Attackers turn to AI for help identifying files worth stealing

AI tools are being used by cyber attackers to write malicious code, build tools that harvest credentials, search compromised networks, identify valuable business information, manage technical infrastructure and generate commands during intrusions. Gambit Security researchers examined three unrelated threat actors that show how AI can support different stages of a cyberattack. Across the cases, attackers…

Weekly Update 517: Cyber Ransoms

The current ransomware situation is a bit of a kludge (deep breath): a lot of ransomware (which often doesn’t even involve “ware”, it’s just extortion) is carried out by kids who successfully make a truckload of money but can’t spend it without getting caught and the companies they breach rapidly get piled onto by class…

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score…

SafePal Warns of Phishing Risk After Data Exposure Hits Nearly 40,000 Customers

Nearly 40,000 SafePal customers had their personal and order information exposed after a security flaw allowed unauthorized access to the cryptocurrency wallet provider’s order-tracking system. SafePal said an authorization flaw in a plug-in connected to customer orders allowed outsiders, under certain conditions, to access another customer’s information. The incident affected approximately 39,798 customers who placed…

‘MessiahGPT’ AI Service Promises Ransomware, Phishing Kits, and Malware

Criminal AI tools are increasingly resembling commercial software. Trellix researchers found MessiahGPT openly advertised on BreachForums as an unrestricted AI service for generating ransomware, phishing kits, malware, and social-engineering material. The platform has its own website and Telegram community, although researchers could not independently verify the operator’s claims about the model or its capabilities. The…

Apple Patches iOS and macOS, (Mon, Aug 17th)

Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS. None of the vulnerabilities has been exploited so far. There are a few WebKit vulnerabilities, but no standalone…

Nozomi, Sophos Integrate OT Security Data in Sophos Fusion

Nozomi Networks and Sophos are integrating Nozomi’s OT security intelligence into Sophos Fusion, giving security teams a unified view of threats across IT and operational technology environments.  The partnership connects OT telemetry, asset intelligence, and threat data from Nozomi Networks Vantage with Sophos’ broader cybersecurity platform to support faster detection, investigation, and response. Nozomi Vantage…

SonicWall Launches Simplified Endpoint Protection

SonicWall has launched SonicWall Endpoint Security, a unified endpoint protection platform designed to help managed service providers (MSPs) deliver enterprise-grade security to small and midsize business customers without adding operational complexity.  The offering combines threat protection, automated response, and ransomware recovery, with service tiers built around how MSPs package and manage endpoint security. SonicWall automates…

Clop PTC Windchill Campaign Expands Across Enterprise Environments

A widening Clop extortion campaign has drawn several global enterprises into fresh security scrutiny. Philips confirmed a compromise involving one enterprise server. GE and Shell are investigating related claims as attention turns to activity involving PTC Windchill and FlexPLM environments. Ransom-ISAC has tied attacks against internet-exposed deployments to Clop affiliates. MSPs, MSSPs, and systems integrators…

Philips and GE Investigate Clop Ransomware Data Theft Claims

Philips and General Electric (GE) are investigating incidents after the Clop ransomware group claimed to have stolen data from both companies. The companies are among 43 organizations recently listed on Clop’s data leak site.  These incidents may be connected to attacks targeting internet-exposed PTC Windchill and PTC FlexPLM systems through CVE-2026-12569. “Cl0p’s playbook hasn’t been…

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake’s public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present in .github/workflows/jira_issue.yml, which ran when a

News alert: OpenMatter Network spotlights AI verification at Belgrade Blockchain Week

Melbourne, Fla., August 17, 2026, CyberNewswire — Continuing its effort to build global awareness of the need to move computing from assumption-based trust to cryptographic proof, OpenMatter Network today announced that Head of Operations and Partnerships Chris Biele will play a prominent role at Belgrade Blockchain Week 2026, where he will lead sessions focused on secure…

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the

Updates to your AWS Sign-In experience

Amazon Web Services (AWS) is gradually introducing updates to the AWS Sign-In and sign-up experience to a limited number of customers. We’re sharing these changes so you will know what to expect as we gradually make the updated experience available to more customers. These updates include new options for creating and accessing AWS accounts. To…

LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected

The SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more. Resecurity (USA) estimated the most affected sectors by the “SANDCLOCK” backdoor, which was planted as a result of the code repository compromise. According to cybersecurity experts, LiteLLM / TeamPCP Supply-Chain Attack will have long-lasting consequences. By compromising a…

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engineered threat detection alerts. Key takeaways Storm-0501 demonstrates that cloud-first ransomware groups have shifted from simple endpoint encryption…

LiteLLM Supply-Chain Attack Exposed Credentials Across 2,500 Organizations

A March supply-chain attack involving malicious versions of the LiteLLM Python package may have exposed credentials belonging to more than 2,500 organizations and hundreds of thousands of CI/CD pipelines, according to security researchers. Attackers published two compromised versions of LiteLLM, a widely used AI gateway, after obtaining access to the project’s PyPI account. The malicious…

France’s tax authority admits hackers made off with data on 678,000 individuals

France’s tax authority has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems, saying the intrusion exposed data on 678,000 individuals and professionals. The incident came to light after an alleged attacker using the alias “ZeroBytes” took credit on a cybercrime forum and listed a stolen database for…