Geek Guy

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score…

SafePal Warns of Phishing Risk After Data Exposure Hits Nearly 40,000 Customers

Nearly 40,000 SafePal customers had their personal and order information exposed after a security flaw allowed unauthorized access to the cryptocurrency wallet provider’s order-tracking system. SafePal said an authorization flaw in a plug-in connected to customer orders allowed outsiders, under certain conditions, to access another customer’s information. The incident affected approximately 39,798 customers who placed…

‘MessiahGPT’ AI Service Promises Ransomware, Phishing Kits, and Malware

Criminal AI tools are increasingly resembling commercial software. Trellix researchers found MessiahGPT openly advertised on BreachForums as an unrestricted AI service for generating ransomware, phishing kits, malware, and social-engineering material. The platform has its own website and Telegram community, although researchers could not independently verify the operator’s claims about the model or its capabilities. The…

Apple Patches iOS and macOS, (Mon, Aug 17th)

Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS. None of the vulnerabilities has been exploited so far. There are a few WebKit vulnerabilities, but no standalone…

Nozomi, Sophos Integrate OT Security Data in Sophos Fusion

Nozomi Networks and Sophos are integrating Nozomi’s OT security intelligence into Sophos Fusion, giving security teams a unified view of threats across IT and operational technology environments.  The partnership connects OT telemetry, asset intelligence, and threat data from Nozomi Networks Vantage with Sophos’ broader cybersecurity platform to support faster detection, investigation, and response. Nozomi Vantage…

SonicWall Launches Simplified Endpoint Protection

SonicWall has launched SonicWall Endpoint Security, a unified endpoint protection platform designed to help managed service providers (MSPs) deliver enterprise-grade security to small and midsize business customers without adding operational complexity.  The offering combines threat protection, automated response, and ransomware recovery, with service tiers built around how MSPs package and manage endpoint security. SonicWall automates…

Clop PTC Windchill Campaign Expands Across Enterprise Environments

A widening Clop extortion campaign has drawn several global enterprises into fresh security scrutiny. Philips confirmed a compromise involving one enterprise server. GE and Shell are investigating related claims as attention turns to activity involving PTC Windchill and FlexPLM environments. Ransom-ISAC has tied attacks against internet-exposed deployments to Clop affiliates. MSPs, MSSPs, and systems integrators…

Philips and GE Investigate Clop Ransomware Data Theft Claims

Philips and General Electric (GE) are investigating incidents after the Clop ransomware group claimed to have stolen data from both companies. The companies are among 43 organizations recently listed on Clop’s data leak site.  These incidents may be connected to attacks targeting internet-exposed PTC Windchill and PTC FlexPLM systems through CVE-2026-12569. “Cl0p’s playbook hasn’t been…

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake’s public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present in .github/workflows/jira_issue.yml, which ran when a

News alert: OpenMatter Network spotlights AI verification at Belgrade Blockchain Week

Melbourne, Fla., August 17, 2026, CyberNewswire — Continuing its effort to build global awareness of the need to move computing from assumption-based trust to cryptographic proof, OpenMatter Network today announced that Head of Operations and Partnerships Chris Biele will play a prominent role at Belgrade Blockchain Week 2026, where he will lead sessions focused on secure…

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the

Updates to your AWS Sign-In experience

Amazon Web Services (AWS) is gradually introducing updates to the AWS Sign-In and sign-up experience to a limited number of customers. We’re sharing these changes so you will know what to expect as we gradually make the updated experience available to more customers. These updates include new options for creating and accessing AWS accounts. To…

LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected

The SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more. Resecurity (USA) estimated the most affected sectors by the “SANDCLOCK” backdoor, which was planted as a result of the code repository compromise. According to cybersecurity experts, LiteLLM / TeamPCP Supply-Chain Attack will have long-lasting consequences. By compromising a…

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engineered threat detection alerts. Key takeaways Storm-0501 demonstrates that cloud-first ransomware groups have shifted from simple endpoint encryption…

LiteLLM Supply-Chain Attack Exposed Credentials Across 2,500 Organizations

A March supply-chain attack involving malicious versions of the LiteLLM Python package may have exposed credentials belonging to more than 2,500 organizations and hundreds of thousands of CI/CD pipelines, according to security researchers. Attackers published two compromised versions of LiteLLM, a widely used AI gateway, after obtaining access to the project’s PyPI account. The malicious…

France’s tax authority admits hackers made off with data on 678,000 individuals

France’s tax authority has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems, saying the intrusion exposed data on 678,000 individuals and professionals. The incident came to light after an alleged attacker using the alias “ZeroBytes” took credit on a cybercrime forum and listed a stolen database for…

Fortinet expands AI security portfolio with Virtue AI acquisition

Fortinet has acquired Virtue AI, strengthening its broader Security for AI strategy and its vision for securing the agentic enterprise. The acquisition builds on Fortinet’s existing AI security portfolio, which includes the FortiGate Hyperscale Firewall. As organizations deploy AI applications and autonomous agents, their attack surface expands beyond networks, users, endpoints, applications, and cloud workloads.…

17th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupted public services related to illicit-drug monitoring and legal processes. Officials confirmed that some files were…

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

Microsoft Defender’s latest patch bypass shows a familiar problem. A newly disclosed Microsoft Defender flaw called ShieldBreak shows that fixing one attack path doesn’t always close every route to the same result. Microsoft has assigned ShieldBreak the identifier CVE-2026-69414 and confirmed it is an elevation of privilege (EoP) vulnerability in the Microsoft Malware Protection Engine.…

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer

A recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands’ National Cyber Security Centre (NCSC) warns. The vulnerability, tracked as CVE-2026-65400, , let attackers authenticate to macOS Screen Sharing without valid login credentials. Apple fixed the issue with updates…

Zhipu says new coding AI developed advanced cyber skills faster than expected

Chinese AI developer Zhipu has launched GLM-5.3, a new coding-focused AI model that the company says has developed unexpectedly strong cybersecurity capabilities, putting it close to global leading models in vulnerability discovery while remaining behind them on deeper exploitation tasks. Zhipu’s own testing places GLM-5.3 slightly ahead of Anthropic’s Mythos 5 and OpenAI’s GPT-5.6 Sol…

How MCP Servers Can Expose Enterprise Secrets

MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their systems, that exposure can silently become a major gap in MCP server security. The Model Context Protocol (MCP) allows AI agents to…

SafePal breach affects 39,798 customers, data allegedly for sale

Cryptocurrency wallet maker SafePal disclosed a data breach that exposed order information for 39,798 customers, including names, email addresses, shipping addresses, phone numbers and purchase details. The company traced the exposure to an authorization flaw in a plug-in used for order tracking. Under certain conditions, the flaw let one customer view another customer’s order information.…

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. “While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities,…