Geek-Guy.com

Month: April 2025

Tesla’s board reportedly sought a successor while Musk wheeled around Washington

According to a new, brow-raising WSJ report, Tesla’s board quietly began searching for Elon Musk’s potential successor about a month ago, approaching executive search firms as the carmaker faced protests, plummeting sales, and shrinking profits while Musk waded into Washington to slash government spending. Board members reportedly met with Musk to express concerns about his…

Microsoft’s most capable new Phi 4 AI model rivals the performance of far larger systems

Microsoft launched several new “open” AI models on Wednesday, the most capable of which is competitive with OpenAI’s o3-mini on at least one benchmark. All of the new pemissively licensed models — Phi 4 mini reasoning, Phi 4 reasoning, and Phi 4 reasoning plus — are “reasoning” models, meaning they’re able to spend more time…

World partners with Tinder, Visa to bring its ID-verifying tech to more places

World, the biometric ID company best known for its eyeball-scanning Orb devices, at an event late on Wednesday announced several partnerships aimed at driving sign-ups and demonstrating the applications of its tech. World is partnering with Match Group, the dating app conglomerate, to verify the IDs of Tinder users in Japan. Via collaborations with Kalshi…

Study accuses LM Arena of helping top AI labs game its benchmark

A new paper from AI lab Cohere, Stanford, MIT, and Ai2 accuses LM Arena, the organization behind the popular crowdsourced AI benchmark Chatbot Arena, of helping a select group of AI companies achieve better leaderboard scores at the expense of rivals. According to the authors, LM Arena allowed some industry-leading AI companies like Meta, OpenAI,…

Microsoft expects some AI capacity constraints this quarter

Microsoft customers could encounter service disruptions when using AI services due to demand outpacing the company’s ability to bring data centers online, an executive warned during the company’s earnings call Microsoft’s EVP and CFO Amy Hood said during the company’s fiscal 2025 third-quarter earnings call Wednesday the company may face AI capacity constraints as early…

Smashing Security podcast #415: Hacking hijinks at the hospital, and WASPI scams

He’s not a pop star, but Jeffrey Bowie is alleged to have toured staff areas of a hospital in Oklahoma, hunting for computers he could install spyware on. We dive into the bizarre case of the man accused of hacking medical networks and then sharing how he did it on LinkedIn. Plus! Move over Nigerian…

North Korean operatives have infiltrated hundreds of Fortune 500 companies

SAN FRANCISCO — North Korean nationals have infiltrated the employee ranks at top global companies more so than previously thought, maintaining a pervasive and potentially widening threat against IT infrastructure and sensitive data. “There are hundreds of Fortune 500 organizations that have hired these North Korean IT workers,” Mandiant Consulting CTO Charles Carmakal said Tuesday…

Alleged ‘Scattered Spider’ Member Extradited to U.S.

A 23-year-old Scottish man thought to be a member of the prolific Scattered Spider cybercrime group was extradited last week from Spain to the United States, where he is facing charges of wire fraud, conspiracy and identity theft. U.S. prosecutors allege Tyler Robert Buchanan and co-conspirators hacked into dozens of companies in the United States…

Threads tops 350M monthly users after adding 30M in the quarter

Instagram Threads, Meta’s X competitor, has now grown to over 350 million monthly active users, CEO Mark Zuckerberg revealed during the company’s Q1 2025 earnings call on Wednesday. That’s an increase of 30 million users since the prior quarter, where Meta reported that Threads had 320 million users. The new figure represents increased growth, as…

Russian APT28 hackers have redoubled efforts during Ukraine war, says French security agency

The war in Ukraine has prompted a resurgence in activity by the notorious Russian APT28/Fancy Bear group, the French ANSSI cybersecurity agency has said. According to a brief report published by the agency this week, Targeting and Compromise of French Entities Using the APT28 Intrusion Set, the group now aggressively targets the networks of government…

Congressional officials wonder how CISA can carry out core mission in face of workforce cuts

SAN FRANCISCO – In her appearance at the RSAC 2025 Conference, Homeland Security Secretary Kristi Noem spoke about getting CISA back to its “core mission” of protecting federal networks and critical infrastructure from cybersecurity threats.  Other cyber policy experts wonder how that is going to unfold with such concentration on cutting CISA’s workforce.  Congressional staffers…

Amazon updates Q Business to let companies build public-facing chatbots

Amazon wants companies to build public-facing chatbots using its Q Business assistant. On Wednesday, the company announced that Q Business, its AWS-hosted AI assistant that can answer questions, provide summaries, and complete tasks, now supports anonymous user access. This effectively means that AWS users can now create Q Business chatbots for websites, support portals, and…

Tariffs could slow replacement of telecom networks, according to industry official

Tariff hikes will drive up prices and make it harder for telecommunications providers to replace networks more vulnerable to Chinese hacker intrusion, an industry official told lawmakers Wednesday. “Tariffs will only raise prices,” David Stehlin, CEO of the Telecommunications Industry Association, told Rep. Darren Soto, D-Fla. While it makes sense to find ways to bring…

BSidesLV24 – Ground Truth – Hacking Things That Think

Author/Presenter: Matthew Canham Our sincere appreciation to BSidesLV, and the Presenters/Authors for publishing their erudite Security BSidesLV24 content. Originating from the conference’s events located at the Tuscany Suites & Casino; and via the organizations YouTube channel. Permalink The post BSidesLV24 – Ground Truth – Hacking Things That Think appeared first on Security Boulevard.

Rivian’s reportedly sitting on a stockpile of tariff-free batteries

Rivian built up a stockpile of batteries for its trucks, SUVs, and commercial vans before and after the election of Donald Trump, a strategy used to soften the blow of the president’s tariffs, according to Bloomberg News. The company apparently bought an undisclosed number of lithium iron phosphate batteries from Chinese firm Gotion before the…

Trump’s Auto Tariff Relief “Helps Tesla a Lot” — Leaving Other Carmakers Behind

Donald Trump’s latest adjustment to automobile tariffs were billed as relief for the Big Three carmakers, but a leading analyst said Wednesday that Elon Musk’s Tesla will benefit most while others will be stuck “in quicksand” — potentially creating a slight advantage for a company whose CEO donated nearly $300 million to Trump and other…

Gruve.ai promises software-like margins for AI tech consulting, disrupting decades-old Industry

Companies of all sizes are recognizing the game-changing possibilities of AI. Despite the excitement about the new technology, most of their pilot projects don’t make it into production. Gruve.ai, a startup founded by the team behind Rahi Systems aims to help enterprises get AI solutions out of testing phase and into real-world application by using…

Orb, a new app by Ookla’s ex-CEO, offers a broader picture of your internet connection

Since it launched nearly 20 years ago, Speedtest.net has been one of the most popular tools used to measure internet speeds. However, Doug Suttles, the founder and former CEO of Ookla, the network testing company behind Speedtest, felt that just measuring speed was not enough to tell people all they wanted to know about their…

Anthropic suggests tweaks to proposed U.S. AI chip export controls

Anthropic agrees with the U.S. government that implementing robust export controls on domestic-made AI chips will help the U.S. compete in the AI race against China. But the company is suggesting a few tweaks to the proposed restrictions. Anthropic released a blog post on Wednesday stating that the company “strongly supports” the U.S. Department of…

Social Agent’s new app lets you book a photographer within 30 minutes

There’s an unspoken pressure nowadays to share all your special moments online, whether it be birthdays, graduations, or engagements.  However, not everyone has the skills to take high-quality pictures, and often, people find themselves too distracted to snap the perfect shot. While hiring a professional photographer is an option, it may not always be feasible…

Duolingo launches 148 courses created with AI after sharing plans to replace contractors with AI

Duolingo is introducing 148 new language courses that were created with generative AI, the company announced on Wednesday. The launch comes as Duolingo has been facing backlash this week after sharing that it was going to replace contractors with AI and become an “AI-first” company. The company says the launch of the new courses doubles…

BSidesLV24 – Ground Truth – Looking For Smoke Signals In Financial Statements, For Cyber

Author/Presenter: Brandon Pinzon Our sincere appreciation to BSidesLV, and the Presenters/Authors for publishing their erudite Security BSidesLV24 content. Originating from the conference’s events located at the Tuscany Suites & Casino; and via the organizations YouTube channel. Permalink The post BSidesLV24 – Ground Truth – Looking For Smoke Signals In Financial Statements, For Cyber appeared first…

Cast your vote: Help shape the TechCrunch All Stage agenda

TechCrunch All Stage is just around the corner — and you get to help shape the agenda.  From a competitive pool of applicants, two of the six visionary finalists are one step away from leading a roundtable session on July 15 at SoWa Power Station in Boston. Your vote determines who makes it. Audience Choice…

Side Event submission deadline extended for TechCrunch Sessions: AI

Did you miss your chance to apply for a Side Event at “TechCrunch Sessions: AI Week?” Don’t worry – we’ve extended the deadline by three more days! You now have until May 2 at 11:59 p.m. PT to submit your proposal. This is your opportunity to connect with attendees of TC Sessions: AI and the…

Wikipedia says it will use AI, but not to replace human volunteers

Wikipedia on Wednesday revealed its new AI strategy for the next three years — and it’s not replacing the Wikipedia community of editors and volunteers with artificial intelligence, thankfully. Instead, Wikipedia says it will use AI to build new features that “remove technical barriers,” allowing editors, moderators, and patrollers tools that allow them to accomplish what they need…

Revived CryptoJS library is a crypto stealer in disguise

An illicit npm package called ‘crypto-encrypt-ts‘ may appear to revive the unmaintained but vastly popular CryptoJS library, but what it actually does is peek into your crypto wallet and exfiltrate your secrets to threat actors. The post Revived CryptoJS library is a crypto stealer in disguise appeared first on Security Boulevard.

Nuvo, a network for B2B trade, has nabbed $34M from Sequoia and Spark Capital

Nuvo, a company that has built a social-like platform to facilitate easier purchasing of physical goods between businesses, has raised a $34 million Series A from Sequoia Capital and Spark Capital, it tells TechCrunch exclusively. The San Francisco-based startup previously raised $11 million in an undisclosed seed round led by Founders Fund and Index Ventures…

5 days left: $210 ticket discount and 50% off on the second for TechCrunch Sessions AI

You’ve got just 5 days to save up to $210 — plus 50% off your +1 — and get inside the minds of AI’s biggest voices at TechCrunch Sessions: AI. Imagine hearing firsthand from Anthropic’s Jared Kaplan, OpenAI’s startup team, and top voices from firms like Khosla Ventures — all in one day. June 5…

Supio, an AI-powered legal analysis platform, lands $60M

Supio, a startup that uses AI to automate data collection and analysis for legal teams, has raised $60 million in a funding round led by Sapphire Ventures with participation from Mayfield and Thomson Reuters Ventures. The new capital, which brings Supio’s total raised to $91 million, will be put toward growth, hiring, and go-to-market efforts,…

HPE adds ‘digital circuit breaker’ to protect GreenLake customers

HPE has introduced new security features for its Aruba Networking and GreenLake platforms to enhance cloud and network security in hybrid IT environments. The updates, announced at the RSA 2025 conference, include an AI-driven policy engine for network access control, tighter integration between Aruba Central and HPE OpsRamp for unified visibility, and real-time threat response…

Cast AI raises $108M to get the max out of AI, Kubernetes and other workloads

The crush of traffic going into training and running AI has quickly turned into a major cost and resource headache for organisations. Today, Cast AI — a startup building tools to ease and optimise AI and other workloads with automation — is raising a major round of funding on the back of its strong growth…

AI sales tax startup Kintsugi had doubled its valuation in 6 months

Kintsugi, a Silicon Valley-based startup that helps companies offload and automate their sales tax compliance, has raised $18 million in new funding led by global indirect tax technology solution provider Vertex. The startup plans to enable more small and medium businesses to use its AI-enabled capabilities for tax calculations and filings. The ongoing growth of…

Kritische Zero-Day-Schwachstelle in SAP NetWeaver

width=”1888″ height=”1062″ sizes=”(max-width: 1888px) 100vw, 1888px”>Hacker könnten über eine Schwachstelle im NetWeaver auf SAP-Systeme zugreifen, Schadcode einschleusen und so die Kontrolle übernehmen. TenPixels – shutterstock.com Angreifer nutzen seit dem 21. April 2025 eine kritische Zero-Day-Schwachstelle in der Visual Composer-Komponente des SAP NetWeaver Application Server aus. SAP hat bereits einen Out-of-Band-Fix veröffentlicht, der über das Support-Portal…

Cybercriminals intensify hunt for exposed Git secrets

Git configuration files exposed in public repositories are being aggressively dug up and looked into by threat actors to reveal sensitive secrets and authentication tokens unintentionally left behind in Git projects. A GreyNoise observation recorded a significant spike in search attempts for exposed Git configuration files between April 20 and April 21. “While the crawling…

[Free Webinar] Guide to Securing Your Entire Identity Lifecycle Against AI-Powered Threats

How Many Gaps Are Hiding in Your Identity System? It’s not just about logins anymore. Today’s attackers don’t need to “hack” in—they can trick their way in. Deepfakes, impersonation scams, and AI-powered social engineering are helping them bypass traditional defenses and slip through unnoticed. Once inside, they can take over accounts, move laterally, and cause…

Chinese Hackers Abuse IPv6 SLAAC for AitM Attacks via Spellbinder Lateral Movement Tool

A China-aligned advanced persistent threat (APT) group called TheWizards has been linked to a lateral movement tool called Spellbinder that can facilitate adversary-in-the-middle (AitM) attacks. “Spellbinder enables adversary-in-the-middle (AitM) attacks, through IPv6 stateless address autoconfiguration (SLAAC) spoofing, to move laterally in the compromised network, intercepting packets and

U.S. Companies Honed Their Surveillance Tech in Israel. Now It’s Coming Home.

Illustration: The Intercept In partnership with Rita Murad, a 21-year-old Palestinian citizen of Israel and student at the Technion Israel Institute of Technology, was arrested by Israeli authorities in November 2023 after sharing three Instagram stories on the morning of October 7. The images included a picture of a bulldozer breaking through the border fence in Gaza…

Nebulous Mantis Targets NATO-Linked Entities with Multi-Stage Malware Attacks

Cybersecurity researchers have shed light on a Russian-speaking cyber espionage group called Nebulous Mantis that has deployed a remote access trojan called RomCom RAT since mid-2022. RomCom “employs advanced evasion techniques, including living-off-the-land (LOTL) tactics and encrypted command and control (C2) communications, while continuously evolving its infrastructure – leveraging

RansomHub Went Dark April 1; Affiliates Fled to Qilin, DragonForce Claimed Control

Cybersecurity researchers have revealed that RansomHub’s online infrastructure has “inexplicably” gone offline as of April 1, 2025, prompting concerns among affiliates of the ransomware-as-a-service (RaaS) operation. Singaporean cybersecurity company Group-IB said that this may have caused affiliates to migrate to Qilin, given that “disclosures on its DLS [data leak site] have doubled since