Geek Guy

Cybersecurity LLM Models — Benchmark Report (2026)

Validated against CYBERSECEVAL 3, Microsoft RCTs, Simbian AI SOC Benchmark | Generated: 2026-09-21 20:16 UTC Key Risk Findings ⚠️ Critical: All tested models show ~18-22% prompt injection susceptibility — guardrails are mandatory. 🔒 Risk Mitigation: Malicious code generation rates: <1% with proper monitoring and Llama Guard 3. ⚖️ Scale vs. Specialization: Larger models (405B) do…

Common Kubernetes Commands & Administrator Functions (cli commands)

Created: 2026-09-21Scope: kubectl commands, administrator functions, multi-cloud platform comparisons Executive Summary Kubernetes administration revolves around the kubectl CLI tool and a set of higher-level management tools. This report documents the most common commands across all resource types, essential administrative workflows, and platform-specific considerations for AWS EKS, GCP GKE, and Azure AKS. Core kubectl Commands by…

AI LLM Inference Costs Report — 2026 Edition

Report Date: September 21, 2026Sources Verified: OpenAI API Docs, Anthropic Pricing, Google Vertex AI, AWS Bedrock, AWS EC2 Self-Hosted benchmarks (public sourced data)Data Currency: All prices verified against live provider pricing pages as of September 2026. Executive Summary Strategic Recommendations 🏆 Best Overall Value: Gemini 1.5 Flash at $0.1875/M blended — approximately half the price…

Only 10% Confident They Can Meet UK Cyber Reporting Rule

Only one in ten UK IT, compliance, and security professionals surveyed by VinciWorks are confident their organizations could meet a proposed 24-hour cyber incident notification requirement as the Cyber Security and Resilience Bill moves through Parliament. The proposed legislation would extend the UK’s existing cyber security regime to managed service providers (MSPs), data centers, and…

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microsoft’s own hardware-compatibility program signs the driver, scored zero detections on VirusTotal…

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto

The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory. The primary targets of the campaign are individual web designers, engineers, and specialists in cryptocurrency,

European AI Firms Warn US Safety Proposals Are ‘Self-Serving’ Market Moats

European AI companies are pushing back on calls to slow frontier model development, warning that some safety requirements could strengthen the position of the companies already leading the market. Mistral and other European developers have challenged proposals from major U.S. AI labs for slower capability growth, coordinated safety standards and stronger independent evaluations. Their concern…

What Is a Value-Added Reseller? How VARs Work & Their Future

A value-added reseller (VAR) is an IT company that resells hardware, software, cloud services, or other technology while adding its own services or expertise. Unlike a basic reseller that primarily sells a product or license, a VAR typically adds value through services such as consulting, configuration, customization, systems integration, implementation, training, cybersecurity, or technical support.…

Agentic AI Pushes SaaS Beyond Per-Seat Pricing

Agentic AI is beginning to change not just how software works, but how vendors charge for it. As autonomous agents take on work once performed by employees, enterprise buyers are increasingly moving beyond traditional per-seat subscriptions and long-term SaaS contracts toward consumption-based pricing, individual actions, or measurable outcomes.  Salesforce, Intercom and Zendesk are already experimenting…

After spending billions, OpenAI still has gaps in its cybersecurity

Two separate reports of security flaws in OpenAI systems highlight how even a company spending billions on developing its own AI-powered cybersecurity testing tools remains vulnerable. In one incident, researchers breached OpenAI systems with the help of a rival AI developer’s tools, while another group of researchers tricked OpenAI’s Codex agent into bypassing its sandbox…

The fake sites using a cheap toolkit to sell $2,000 AI subscriptions

We found more than 100 subscription websites linked through the same toolkit and closely related developer details. Some impersonate existing products, including GPT-6 Astra, DaVinci Resolve, PixAI, and OpenCut. Another uses the name of Omegle, the chat service that shut down in 2023. Others promote unfamiliar brands with little verifiable information about who operates them.…

Transforming Bedrock Guardrails events into OCSF with CloudWatch

Security teams investigating possible AI-related security events need guardrail intervention data alongside their existing security telemetry. When a guardrail identifies or blocks a prompt injection attempt or redacts sensitive data, that intervention carries additional investigative value comparable to a failed sign-in or a network intrusion alert. AWS Bedrock publishes this telemetry to AWS CloudWatch metrics…

Malicious HEIF Upload Reached OpenAI’s Internal GitHub, Researchers Reveal

Researchers have disclosed how a malicious HEIF image uploaded to OpenAI’s public community forum ultimately opened a path to the company’s internal GitHub environment. Hacktron published the full attack chain on September 13, detailing a July 25 compromise of OpenAI’s Discourse-hosted forum that researchers chained with a separate single sign-on flaw. The group gained access…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

Top 10 WiFi Routers & Mesh Systems — September 2026

Report Date: September 21, 2026Data Sources: Amazon Best Sellers, PCMag Reviews, Tom’s Hardware, RTINGS.com, WiredMarket Context: Wi-Fi 7 adoption accelerating; multi-gigabit support now mainstream; AI-driven networking features standard on mid-tier products Executive Summary The September 2026 router market shows strong consolidation around Wi-Fi 7 (802.11be) as the dominant technology, with Wi-Fi 6E holding a budget…

New npm malware finds a way around install script defenses

Blocking suspicious install scripts may no longer be enough to mitigate threats from malicious JavaScript dependencies used in software supply-chain attacks. Security researchers at Checkmarx are warning of attackers using a malicious package called “indexed-btree” to impersonate the legitimate sorted-btree library, to spread malware hidden in the package’s normal runtime code. The campaign abandons the…

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor “automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files

Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and then stays put to grab each new or edited document. The same malware steals saved Wi-Fi passwords and clipboard text, takes screenshots, and runs whatever command its operators send. Akshay Gaikwad and Aaron…

Orchid Security Introduces AI Agent Readiness Controls Featuring Continuous Identity Monitoring and Kill-Switch Capabilities

Readiness tagging for AI, always-on observability, and coordinated kill switches at the application layer give enterprises a defensible route to scaling agents while keeping authority in human hands. New York, London – September 15, 2026 – Orchid Security, which unlocks safe AI adoption by solving identity at its core, today unveiled a set of AI…

ChainScript: the RAT that hides its command server inside a blockchain contract

Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server. Blackpoint’s Adversary Pursuit Group was chasing a ClickFix campaign spreading an unknown RAT namend ChainScript. The malicious code is a previously undocumented Node.js remote access trojan that hides its command server on a public blockchain. The…

ShinyHunters hacks rival extortion gang and takes over its dark web site

Reportedly, the ShinyHunters extortion group breached the leak site of one of its competitors, the Clop ransomware gang. ShinyHunters is a financially motivated cybercrime and extortion group active since 2019. It is known for stealing large volumes of data and pressuring victims to pay, rather than necessarily deploying ransomware. One recent high-profile organization targeted by…

Hackers exploit Gyazo server flaw to steal 23.6 million user records

Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in its image upload server, stealing approximately 23.62 million user records and metadata tied to hundreds of millions of images. Gyazo is a cloud-based screenshot and screen-recording service that uploads users’ captures automatically and generates…

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. “ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software,” Blackpoint Adversary Pursuit Group (APG)

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based “much smaller organization” in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks. Cybersecurity company SentinelOne, which disclosed details of the activity, said it involved the…

Product showcase: Helmit alerts parents when online conversations show signs of trouble

Helmit is a parental control app that combines AI-powered social media monitoring with screen time management, web filtering, location tracking, and safety alerts. It identifies potentially concerning interactions and surface the messages associated with an alert. Helmit is available on iOS, Android, macOS, and Windows. Parents can create profiles for their children and connect supported…

AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor

Forty percent of large companies had an AI-related compliance or governance issue in the past 12 months, according to 1,000 senior IT, operations, and transformation leaders surveyed by Sapio Research. Those leaders said process-related problems contributed to 84 percent of the incidents. The researchers trace the exposure to workflows designed around people. Approvals, handoffs, and…

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2025-39682 – Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability CVE-2025-39964 Linux Kernel Race Condition Vulnerability CVE-2026-53266 Linux Kernel…

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor   Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot…

Week in review: Cisco patches exploited email gateway 0-day, Revolut breach

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What we know about the Revolut data breach so far Someone impersonating a government agency, using an email address on that agency’s domain, obtained sensitive customer records from Revolut. The bank confirmed the incident on Saturday, September 12. DeepZero: Open-source…