Geek Guy

Trust and the enticing consultancy offer

Welcome to this week’s edition of the Threat Source newsletter.  In the cybersecurity industry, trust is the invisible currency. Every practitioner carries the implicit trust not to abuse privileged access or knowledge of vulnerabilities in each employment or engagement. This trust is valued by those who require our services, but also by threat actors.  Clumsy…

Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges

Law enforcement has arrested two leaders of a Russian-owned phone hacking company used by Kremlin agencies who allegedly masked its foreign ownership from the U.S. Defense Department, Department of Homeland Security and others to win millions of dollars worth of contracts, the Justice Department announced Wednesday. Lee Reiber of Boise, Idaho, the CEO of Oxygen…

Multiple Vulnerabilities in IBM Concert Software Could Allow for Remote Code Execution

Multiple vulnerabilities have been discovered in IBM Concert Software, the most severe of which could allow for remote code execution. IBM Concert is an agentic IT operations (IT Ops) and resilience platform designed to unify fragmented data, context, and actions across an enterprise’s hybrid cloud and IT environments. Successful exploitation of the most severe of…

Microsoft integrates SOC capabilities with Defender for enterprises

Microsoft 365 E5 and E7 customers can now run security information and event management (SIEM) inside Microsoft Defender at no extra license cost. Microsoft is delivering the capability through the Integrated Security Operations Center (ISOC) in Microsoft Defender, which combines SIEM with Defender’s existing XDR, threat intelligence, automation and AI tools in a single portal.…

Microsoft integrates SOC capabilities with Defender for enterprises

Microsoft 365 E5 and E7 customers can now run security information and event management (SIEM) inside Microsoft Defender at no extra license cost. Microsoft is delivering the capability through the Integrated Security Operations Center (ISOC) in Microsoft Defender, which combines SIEM with Defender’s existing XDR, threat intelligence, automation and AI tools in a single portal.…

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

The “third-party[.]com” domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. “third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays,” Manifold Security’s Head of Research, Ax Sharma, said. “Unlike ‘example[.]com,’ third-party[.]com

Detection Rule Portability

Detection rule portability is the practice of writing and managing threat-detection logic so it moves across SIEM, EDR, and XDR platforms without a full rewrite. What happens to my detection rules when I migrate to a new SIEM platform? Rules written in a platform’s native query language do not travel. SPL stays in Splunk. KQL…

Measuring MITRE ATT&CK detection coverage: what the percentage counts and what it hides

MITRE ATT&CK detection coverage is the ratio of adversary techniques your SOC can detect, validated against the technique set your threat model prioritizes, on the current framework version. A coverage percentage means nothing without its denominator and proof method. Validated coverage counts techniques where a deployed detection rule fires against its required data source, divided…

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. “When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into…

Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks

Two Senate committee leaders are introducing legislation to foster cybersecurity standards for the telecommunications sector nearly two years after the landmark Salt Typhoon campaign was made public. First reported by CyberScoop, Virginia Sen. Mark Warner, the top Democrat on the Intelligence Committee, and Texas Sen. Ted Cruz, the GOP chairman of the Commerce, Science and…

Symphony Risk Intelligence uses AI agents to streamline financial crime investigations

SymphonyAI has introduced Symphony Risk Intelligence (SRI), an enterprise-grade, agent-native platform built to unlock Always-on Compliance. This is a critical shift from periodic to continuous risk and compliance management, in which institutions continuously reassess risk and adapt controls as regulations, threats and business activity change, rather than waiting for the next scheduled review. Current approaches…

On-prem VeloCloud Orchestrator under attack, only some versions patched

A flaw in VeloCloud Orchestrator enables attackers to access the platform organizations use to manage their VeloCloud SD-WAN subscriptions and the edge devices it controls. Arista, which now owns the VeloCloud business, warned customers that a vulnerable configuration exists in on-premises VeloCloud Orchestrator deployments that remote attackers may abuse to access “privileged internal functionality” and…

CVE-2026-94545: Critical Next.js ImageResponse Flaw Enables Remote Code Execution

A critical vulnerability in Next.js could allow remote attackers to execute arbitrary code on vulnerable servers through the framework’s ImageResponse functionality. Tracked as CVE-2026-94545, the flaw affects the Node.js implementation of ImageResponse in next/og and carries a CVSS score of 9.5. Vercel addressed the issue on September 22, 2026, with the release of Next.js 16.3.6.…

OpenAI agent breached Medicare statistics site, then took months to report it

An OpenAI agent didn’t take “no” for an answer when it encountered a government website’s access controls. It got through, prompting Australia’s Prime Minister Anthony Albanese to raise his concerns directly with OpenAI CEO Sam Altman. The BBC reports that an OpenAI agent gained unauthorized access to an Australian government statistics portal while carrying out…

Microsoft adds pay-as-you-go pricing for extra OneDrive storage

Microsoft has added a “pay-as-you-go” option for OneDrive storage, providing an additional way for Microsoft 365 commercial customers to buy extra cloud storage capacity for users. Previously, increasing storage capacity for OneDrive users meant purchasing capacity “packs” for individual accounts, available in 100GB, 500GB, and 1TB through 6TB sizes. With the new consumption-based billing, Microsoft…

OpenAI agent hacking spree widens to Australia, targeting government website

Before the Hugging Face and RubyGems hacks, autonomous OpenAI agents attempted to hack into three other websites, including an Australian government public health website, independent research lab Transluce revealed on Wednesday. “Notably, the tasks the agents were trying to solve were not cyber-related; the agents resorted to hacking tactics while working on ordinary data retrieval…

Gurucul connects AI activity to identity data for faster threat response

Gurucul has announced the general availability of Gurucul AI Risk and Response, bringing behavioral AI to the growing attack surface created as AI moves from assistant to actor. With hundreds of AI detections connecting activity to identity, access, data and broader security telemetry, the solution helps SOC and Insider Risk teams see who or what…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

Airties adds router-level cybersecurity protection for ISPs

Airties has launched new integrated cybersecurity capabilities that enable ISPs to detect and remediate threats to connected homes and small businesses. As part of Airties’ Connectivity Experience Management Platform, these new capabilities turn the router into an additional security layer that safeguards every device on the network, giving ISPs a powerful baseline of protection for…

LatticeFlow AI offers managed risk assessments for enterprise AI systems

LatticeFlow AI has announced the LatticeFlow AI Risk Center, an AI governance managed service that continuously assesses and controls AI risk, giving enterprises the technology, evidence, and expertise to scale AI with confidence and accelerate time to value. AI systems and agentic workflows are moving into production faster than most organizations can build the capabilities…

Meta locks itself out of user data on its AI glasses

Meta is expanding Private Processing to its AI glasses, extending their security protections into cloud data centers. The system runs AI models inside confidential virtual machines (CVMs) designed to prevent Meta from accessing users’ data. Private Processing combines protected hardware, encryption and software verification to secure data during cloud processing and storage. How Private Processing…

Schneider Electric Joins Lenovo 360 Circle for Partners

Lenovo is bringing Schneider Electric’s carbon management tools and decarbonization expertise into Lenovo 360 Circle, giving eligible channel partners new support to measure emissions, identify reduction opportunities, and build practical sustainability roadmaps. Schneider Electric brings decarbonization tools to Lenovo partners As a new ally, Schneider Electric will bring its Decarbonization Champion initiative to the channel,…

Hexnode Synapse Brings Agentic AI Orchestration to MSPs

Hexnode, Mitsogo’s enterprise software division, has unveiled Hexnode Synapse, an agentic AI orchestration layer for IT and security operations designed to turn requests and system events into coordinated, governed, and traceable actions. Hexnode Synapse helps MSPs coordinate service requests, alerts, and events from initiation to resolution across the tools involved. It extends workflows across the…

Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are leaking secrets at approximately twice the rate of human-written ones. Most of the fastest-growing categories of leaked credentials are…

Devolutions Launches Investment Arm for MSP Ecosystem

Devolutions is launching Devolutions Ventures, a new corporate investment arm focused on companies across the IT and managed service provider ecosystem. The initiative will target businesses in areas including secure access, network performance, automation, and other technologies that complement Devolutions’ existing platform. Unlike a traditional acquisition strategy, Devolutions plans to keep portfolio companies independent while…

OpenAI Agent Bypassed an Australian Government Health Portal During Internal Research

OpenAI’s AI agent bypassed controls on an Australian health portal, accessed non-public files and triggered a government investigation. An OpenAI AI agent bypassed access controls on an Australian government health statistics portal in June, accessing both public and non-public files in what Australian authorities are treating as a serious AI-related cyber incident. The case was…

Glassbox Earns Microsoft Financial Services AI Designation

Glassbox has earned Microsoft’s Solutions Partner with certified software designation for financial services AI, giving the digital experience analytics provider a new credential within the Microsoft AI Cloud Partner Program as it expands its Azure-backed AI portfolio. The designation confirms that Glassbox’s software meets Microsoft program requirements and is interoperable with Microsoft Cloud, including Azure.…

Google plans to give Private AI Compute a memory that follows users across devices

Google plans to add private, server-side memory to Private AI Compute, enabling AI assistants to maintain continuity across devices while providing privacy protections normally associated with on-device processing. Private AI Compute is Google’s cloud platform for processing sensitive data with Gemini models in a hardware-isolated environment. It gives AI features access to greater computing power…