Geek Guy

NIST and CISA finalize playbook to stop token theft and forgery

NIST and CISA have finalized guidelines to help federal agencies and cloud service providers (CSPs) protect identity and access tokens from forgery, theft, and misuse. The guidance, Protecting Tokens and Assertions from Forgery, Theft, and Misuse (NIST IR 8587), explains how agencies and cloud providers can strengthen key management, token verification, and token lifecycle controls.…

ANY.RUN & SentinelOne: One Workspace, Instant Context for Rapid Response

Speed and clarity are the ultimate advantages for modern SOC teams. The integration of ANY.RUN into SentinelOne delivers exactly that. Instant threat intelligence and interactive sandbox capabilities embedded right where your analysts already work. Let’s look at how this unified workflow eliminates context switching, accelerates incident response, and drives higher ROI by transforming alerts into…

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. “This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution,” Wordfence said. The WordPress security company said it has blocked over

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the…

Corsica Technologies, IDEA Partner on EDI Managed Services

Corsica Technologies and IDEA are partnering to expand adoption of IDEA Exchange by providing electrical distributors and manufacturers access to managed Electronic Data Interchange (EDI) implementation, integration, platform administration, and ongoing technical support.  The partnership targets organizations that lack specialized integration resources but still need to manage ERP changes, new document mappings, eProcurement connections, and…

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76461 this week;…

What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies

A Cybersecurity and Infrastructure Security Agency program that provides tools and capabilities to other agencies has to get speedier so it can push them toward being able to move more quickly themselves, an agency official said Tuesday. “We have to get faster,” said Richard Grabowski, acting branch chief of service delivery and deputy program manager…

Black Hat USA 2026 | The ‘Breaking’ News: The OpenAI–Hugging Face Incident

The ‘Breaking’ News: The OpenAI–Hugging Face Incident – A Technical Reconstruction and Its Implications for AI At this Black Hat USA 2026 talk, OpenAI security engineers and researchers will reconstruct the OpenAI-Hugging Face incident and examine its implications for AI security, cyber resilience, and alignment. Throughout the session, they will share insights that address key…

Architecting resilient authentication with Amazon Cognito multi-Region replication

Your consumer identity and access management (CIAM) system is the foundation of your customer experience. It’s how users sign in, access services, and engage with your applications. As your business scales across geographies, ensuring authentication is always available becomes a core architectural requirement. However, building multi-Region authentication has traditionally required complex custom replication solutions that…

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on…

Gates Foundation Enters Agentic AI Governance With AAIF Board Seat

The organizations shaping agentic AI standards are gaining a philanthropic voice. The Agentic AI Foundation announced that the Gates Foundation has joined as its first philanthropic member. AAIF said the collaboration is intended to bring perspectives from underserved communities into agentic AI development, particularly in agriculture, healthcare, and financial services. For channel partners and technology…

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran’s intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target’s emails and chat messages, take screenshots, and…

Cisco FMC Flaws Give Ransomware and APTs a Path Into Internal Networks

Cisco’s firewall management infrastructure has become an active entry point for ransomware operators and advanced threat actors. Cisco Talos said Sept. 9 that it is tracking three intrusion clusters exploiting two vulnerabilities in Cisco Secure Firewall Management Center (FMC). The campaigns include an advanced persistent threat actor whose tooling overlaps with Russia-linked Sandworm and a…

Operationalizing least privilege: Automate IAM remediation through your CI/CD pipeline

The principle of least privilege is straightforward to articulate but challenging to maintain at scale. When teams first deploy applications to AWS, they often grant broader permissions than strictly necessary; it’s faster to get things working, and the plan is always to tighten permissions later. But later rarely comes. Permissions accumulate, AWS Identity and Access…

Cisco warns customers of actively exploited zero-day in email gateways

Attackers of unknown origins and motivations are exploiting a critical zero-day vulnerability in Cisco Secure Email Gateway, authorities and researchers said Monday. The vulnerability — CVE-2026-76461 —  was exploited before Cisco disclosed and patched the defect Monday and allows unauthenticated, remote attackers to execute commands with root privileges on vulnerable systems. “In practical terms, that…

How to opt out of AI chatbot training

The tech journalists at 404 Media learned that OpenAI is hiring hundreds of contractors to read and review a massive stream of real users’ ChatGPT prompts and responses. “Project Lily” is reportedly a program that asks contractors to score or critique ChatGPT’s answers to improve the chatbot’s quality and behavior. The fact that prompts may…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

Microsoft Warns of Passkey Phishing Attacks: Hackers Are Hijacking Microsoft 365 Accounts

Passwords are not the only keys attackers want to Microsoft 365 accounts. They are increasingly targeting the authentication process itself. Microsoft warned Sept. 9 that attackers are using passkey-themed social engineering to trick users and compromise cloud identities. The campaigns can ultimately give attackers access to Microsoft 365 services including Exchange Online, SharePoint, OneDrive, and…

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and…

Just Published: Security Considerations for AI Systems

The PCI Security Standards Council (PCI SSC) has published a new information supplement addressing the security of artificial intelligence (AI) systems. This document covers both security aspects of using AI in payment environments and considerations when securing traditional systems against attacks that utilize AI systems. PCI SSC developed this document in collaboration with industry stakeholders…

CISA Warns of Active GitLab Exploitation as Attackers Target Server Files

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. Tracked as CVE-2026-85706, the path traversal flaw carries a CVSS score of 10.0 and affects self-managed GitLab Community Edition and Enterprise Edition installations. Under certain conditions, it can allow…

CVE-2026-76461: Critical Cisco Secure Email Gateway Zero-Day Enables Root RCE

Cisco has patched CVE-2026-76461, a critical zero-day vulnerability in Secure Email Gateway appliances that is already being exploited in the wild. The flaw carries a CVSS score of 9.8 and enables an unauthenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system simply by sending a specially crafted email through…

Ensono Finds 71% of IT Modernization Projects Over Budget

AI is accelerating enterprise IT modernization, but rising costs and continued reliance on legacy systems are complicating those efforts, according to new Ensono research, which found that 71% of organizations have exceeded their original modernization budgets. The State of IT Modernization Report 2026: Enterprise Reality Check found 54% of decision-makers say AI has accelerated modernization…

NinjaOne Adds Browser Management to IT Operations Platform

NinjaOne is expanding its Unified IT Operations Platform with Browser Management, giving MSPs and enterprise IT teams centralized visibility and control over browser extensions, web access, and policies.  The new capability extends NinjaOne’s endpoint management model into a layer increasingly tied to SaaS, AI tool usage, and browser-based security risk. READ MORE: NinjaOne continues to…

F5 Bot Defense uses real-time risk scoring to detect fraud and abuse

F5 has announced enhancements to F5 Distributed Cloud Bot Defense, introducing new device intelligence capabilities and specialized agentic AI protections. These capabilities bring persistent device context and continuous risk decisioning to application security, giving organizations the real-time agent management designed to help welcome trusted digital interaction while helping stop automated fraud and abuse. These updates…

UltraViolet Cyber Equinox measures detection coverage against MITRE frameworks

UltraViolet Cyber has announced the launch of Equinox, its proprietary detection engineering platform, built and operated by the Threat Intelligence & Detection Engineering (TIDE) team. Equinox maximizes detection coverage across customers’ Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) tooling using AI and automation. Security environments, telemetry and threat frameworks change…

Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture. Key takeaways The Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series covering enterprise IT, cloud,…

Multiple Vulnerabilities in Cisco Secure Email Products Could Allow for Remote Code Execution

Multiple vulnerabilities have been discovered in Cisco Secure Email products, the most severe of which could allow for remote code execution. Cisco Secure Email Gateway (formerly ESA) is an email security appliance that filters spam, malware, and other threats at the mail gateway. Cisco Secure Email and Web Manager (formerly SMA) is a centralized management…

Globalgig expands managed security portfolio to protect enterprise AI

Globalgig has expanded its managed security portfolio to cover enterprise AI, bringing together services that discover, assess, and protect the AI applications, agents, models, and data enterprises are putting into production. The services are delivered through the same managed model that already covers the edge, endpoints, identities, and security operations. Enterprises are adopting AI faster…

Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day

Cisco warns of a critical zero-day in Secure Email Gateway, exploited in the wild to gain root access through malicious emails. Cisco disclosed a critical zero-day, tracked as CVE-2026-76461 (CVSS score of 9.8), affecting Secure Email Gateway appliances. The flaw can be exploited remotely without authentication. Attackers can send specially crafted emails containing malicious SQL…

eBook: Identity-First Threat Intelligence

Attackers increasingly bypass traditional defenses by logging in with credentials that have already been stolen, exposed, or sold on the Dark Web. As infostealer malware accelerates credential theft, organizations need greater visibility into identity risk across Active Directory, IAM, and authentication environments. Download the e-book to explore: How infostealers are reshaping the credential threat landscape…

groundcover Gains Google Cloud GKE Autopilot Approval

Bring-your-own-cloud (BYOC), eBPF and OpenTelemetry (OTel)-native platform, groundcover, is joining the Google Cloud Partner Network as a Select Google Cloud Technology Partner and will now be an approved workload for Google Kubernetes Engine (GKE) Autopilot. groundcover brings observability to GKE Autopilot GKE Autopilot is Google’s fully managed Kubernetes cluster and protects users by only running…