Geek Guy

A Vulnerability in Kiteworks EPG (Email Security Gateway) Could Allow for Arbitrary Code Execution

A vulnerability has been discovered in Kiteworks EPG (Email Security Gateway) that could allow for arbitrary code execution. Kiteworks Email Protection Gateway (EPG) is a cloud-based security solution that automates end-to-end encryption, decryption, and policy enforcement for inbound and outbound enterprise emails. A combination of input-handling flaws in publicly reachable endpoints of the Kiteworks Email…

National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations

Collaboration with industry is key to balancing AI security risks and benefits, as well as staying ahead of China and other adversarial nations, National Cyber Director Sean Cairncross said Thursday. The Trump administration is facing pressure from some quarters of Capitol Hill and even some artificial intelligence executives to establish regulations or embrace legislation to…

DeepSeek, Huawei Expand Software Support for Ascend AI Chips

DeepSeek is expanding its work with Huawei, releasing open-source software designed for the Chinese tech company’s Ascend processors. DeepSeek’s Sept. 30 releases and updates extend Ascend support across six open-source projects covering low-level operations needed to build and optimize AI workloads. The release moves their collaboration further into the software layer around AI infrastructure. For…

Give yourself room to be human

Welcome to this week’s edition of the Threat Source newsletter.  Fall is officially here in Maryland, and I can’t be more relieved. I flourish in 50 degree weather, where it feels natural to burrow under blankets, knit sweaters, and listen to an audiobook.  Beyond that, though, can I say that I’m glad fall is here…

Wiz Launches MSP Program for Managed Cloud and AI Security

Managing more cloud security customers can mean more consoles, repeated policy work, and less time to investigate risks. Wiz wants to reduce that overhead for managed service providers. The company announced its Wiz Partner Alliance Managed Service Provider Program on September 28, giving partners centralized customer management, flexible billing, and dedicated support to deliver services…

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the “SC_” markers present in the injected content. Sucuri has described the malware as a “self-healing…

AI policy circles targeted in China-linked phishing operation

A China-aligned cyber espionage group targeted U.S. artificial intelligence policy experts through phishing emails that impersonated prominent officials, economists and an employee of AI company Anthropic, according to research released Thursday by Proofpoint. The campaigns, which the cybersecurity company attributed to a group it calls TA419, sought access to cloud accounts held by people at…

DeepKeep’s AI Lens flags coding agent data leaks and routes destructive commands for approval

DeepKeep has announced AI Lens for Developers, a new extension to the company’s AI usage control and runtime protection modules to secure software developers and their coding agents that can write, modify, and execute code on their behalf. The capability gives security teams policy enforcement, audit visibility, and runtime security over coding agents such as…

Exabeam brings AI-assisted security investigations to data that must stay on-premises

Exabeam has introduced a new wave of capabilities that bring the Agentic SOC to life in the cloud and on-premises environments, combining AI-driven investigation, execution, and governance. Analyst workflows alone can’t keep pace with machine-speed threats or the growing complexity of goal-driven AI agents and autonomous workflows. The future of the SOC is agentic. For…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

RadarFirst helps teams investigate AI bias, data exposure and unintended actions

RadarFirst has announced the general availability of Radar AI Incident Management, a purpose-built solution that helps organizations investigate, manage, and document AI-related incidents. As organizations deploy AI across customer experiences, employee workflows, business operations, and decision-making processes, adverse events can create risks that span privacy, security, legal, compliance, and product teams. Harmful outputs, biased outcomes,…

Threat Coverage Digest: New Malware Reports and 1,100+ Detection Rules

September saw an expansion of detection coverage across network, file, and behavioral activity, providing analysts with additional visibility into suspicious activity. ANY.RUN added 76 behavior signatures, 16 YARA detections, and 1,098 Suricata rules, strengthening coverage across malware activity, suspicious files, and network communications. These updates provide SOC and MSSP teams with additional evidence during investigations,…

AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit

An agentic AI-powered attack that hit the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21 exploited two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system. “Used together, [the two flaws] allowed the attackers to hijack sessions, run code remotely and escalate privileges from the Zammad user to root, in seconds,…

CVE-2026-84782: High-Severity OpenSSL DTLS Flaw Exposes Heap Memory and Enables DoS

OpenSSL has released security updates addressing 14 vulnerabilities, including a high-severity flaw that could expose sensitive heap memory or crash applications relying on Datagram Transport Layer Security (DTLS). Tracked as CVE-2026-84782, the vulnerability stems from improper handling of handshake message retransmissions and carries a CVSS score of 8.2. Disclosed on September 29, 2026, the issue…

Legit Security extends automated fixes to vulnerable open-source dependencies

Legit Security has announced an expansion of its Agentic Remediation capability to cover vulnerabilities found in open-source dependencies, not just first-party code, enabling development teams to move from vulnerability detection to a verified fix without manual triage. The expansion addresses a growing gap in application security: as AI-generated code accelerates software delivery, most modern codebases…

CVE-2026-76504: Critical Cisco SD-WAN Manager Zero-Day Exploited in the Wild

Cisco has disclosed another actively exploited zero-day vulnerability affecting its Catalyst SD-WAN infrastructure. The latest flaw, tracked as CVE-2026-76504, is a critical authentication bypass in Cisco Catalyst SD-WAN Manager that could enable an unauthenticated remote attacker to gain administrative access to an affected system. The vulnerability carries a CVSS score of 9.8, with Cisco confirming…

Sophos CISO Advantage Gives MSPs New vCISO Opportunity

Sophos has launched CISO Advantage, an AI-enabled cybersecurity offering designed to help organizations assess risk, prioritize remediation, and track security progress while giving MSPs a more structured way to deliver virtual CISO services. The launch comes as more customers look to managed service providers for strategic security leadership. Sophos’ 2026 MSP Perspective Report found that…

Virtuozzo Launches Global Partner Program

Virtuozzo has launched V/Partner, a new global partner program for distributors, resellers, and service providers, adding commercial incentives, training, marketing support, and technical resources as the infrastructure software vendor looks to expand partner-led AI and cloud services.  Partners can resell Virtuozzo, integrate the platform into customer environments, or use it as the foundation for managed…

Armadin raises $255.5 million to expand AI offensive security platform

Armadin has raised $255.5 million in Series B funding co-led by Andreessen Horowitz (a16z) and Accel that brings the company’s valuation to over $2.5 billion. The round includes participation from new investors Bain Capital Ventures (BCV) and Redpoint. Existing investors 8VC, Ballistic Ventures, Google Ventures, In-Q-Tel, Kleiner Perkins, and Menlo Ventures also returned, reflecting their…

Pentagon breach exposes Social Security numbers and military records of millions

The US government is alerting millions of people that their personal information was stolen during a breach of the Pentagon’s personnel records at the Defense Manpower Data Center (DMDC). The DMDC is a central US Department of Defense (DoD) organization that manages personnel records, ID credentials, and benefit entitlements for military and civilian staff, veterans,…

CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with

The Fine Art of Frustrating the Adversary

For Cybersecurity Awareness Month, eight Cisco Talos researchers share practical ways defenders can frustrate adversaries at different stages of an operation. Deception techniques such as honeypot accounts, false infrastructure, and tarpits can slow adversaries down while giving defenders earlier opportunities to detect their activity. Behavioral detections, tighter control of legitimate remote-management tools, and clear boundaries…

U.S. CISA adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Catalyst SD-WAN Manager flaw, tracked as CVE-2026-76504 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability resides in Cisco Catalyst SD-WAN Manager’s…

AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds

DIVD was breached through two Zammad zero-days that let an AI agent reach root in seconds, steal data and pivot to other services before being stopped. The Dutch Institute for Vulnerability Disclosure, a nonprofit organization of volunteer security researchers whose whole job is finding and responsibly disclosing vulnerabilities in other people’s software, just disclosed that…

Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version

Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. “It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense,” Koray Kavukcuoglu,

Sentinel Envelope Plus adds software protection without source code changes

Thales has announced Sentinel Envelope Plus, a new addition to its Sentinel Envelope software protection solution that significantly hardens compiled applications against AI-assisted reverse engineering, automated zero-day vulnerability discovery, and automated exploit generation. Sentinel Envelope Plus applies multiple layers of protection to software applications, without requiring source code changes or any special compilation environments. AI-assisted…

Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory…

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. “Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker

MetaMask Security Incident Prompts Exit of Affected Ethereum Validators

MetaMask on Thursday said it’s responding to what it described as an “ongoing security incident” impacting part of its infrastructure. “We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors,” the software cryptocurrency wallet maker said. “At this time, we have identified no immediate threat to MetaMask wallets.”…