Geek Guy

Category: AI

Explore the latest in Artificial Intelligence at Geek Guy. From deep-dive AI tool reviews to practical tutorials and news, stay ahead of the curve with our expert guides.

News alert: GitGuardian raises $50M to tackle non-human identities crisis, AI agent security gap

NEW YORK, Feb. 11, 2026, CyberNewswire — GitGuardian, a leading secrets and Non-Human Identity (NHI) security platform and #1 app on GitHub Marketplace, today announced a $50 million Series C funding round led by global software investor Insight Partners… (more…)

The post News alert: GitGuardian raises $50M to tackle non-human identities crisis, AI agent security gap first appeared on The Last Watchdog.

First Malicious Outlook Add-In Found Stealing 4,000+ Microsoft Credentials

Cybersecurity researchers have discovered what they said is the first known malicious Microsoft Outlook add-in detected in the wild.
In this unusual supply chain attack detailed by Koi Security, an unknown attacker claimed the domain associated with a now-abandoned legitimate add-in to serve a fake Microsoft login page, stealing over 4,000 credentials in the process. The activity has been

JumpCloud: Most businesses aren’t truly ready for AI

As developers begin using Claude and Codex to help create Mac, iPhone, and iPad apps in Xcode, spare a moment to consider a recent JumpCloud survey that shows most businesses aren’t really ready for AI — though many think they might be.

Among the highlights from the survey:

  • 40% of IT leaders self-assess as mature in their AI practices, yet only 22% meet the rigorous objective standards for leading AI readiness.
  • 90% of leaders see productivity gains from AI, but 74% remain concerned about security risks, specifically around unauthorized data access and AI-generated phishing.
  • 61% of organizations report the use of unsanctioned AI tools, creating significant visibility and governance gaps.
  • 85% of IT leaders agree that secure identity and access management (IAM) is critical for scaling AI safely. (Note that JumpCloud calls itself an AI-powered IT management platform.)

JumpCloud argues that enterprises must deploy IT processes to help protect the identity layer as AI impacts their business, “consolidating identity and access controls for both humans and bots to turn AI from a potential liability into a sustainable engine for growth.”

To support that transition, JumpCloud this week introduced a new investment arm to invest in companies building solutions around AI, security, identity and IT productivity. To an extent, this mirrors competitors in the burgeoning Apple-related IT space (Jamf Ventures, for example) even as it highlights the looming impact AI will have on this side of the market.

One of the first JumpCloud investments, Tofu, uses AI as part of its package of protections against identity fraud during the hiring and onboarding process, an emerging problem for some businesses. You could see Tofu’s tools as indicative of the speed at which AI is evolving. 

Between the thought and the action lies the shadow

People don’t seem prepared for the consequences of the rapid evolution even though business leaders think they are. This gap between perceived preparedness and actual readiness comes after over a decade of rapid digital transformation. That transformation saw the iPhone-driven evolution of mobile business, the collapse of the former hegemonic Microsoft dominance of the enterprise, and an algorithmic assault on some of the principles that underpinned international trade. 

The impact has been felt by every business, and entire business sectors have already been replaced by digitized alternatives. Our century so far has seen an avalanche of change, (remember “1,000 songs in your pocket”?) and enterprise leaders are struggling to keep pace, the JumpCloud survey shows.

Thought leaders have been discussing the need to adopt a new business mindset in which enterprises accept they live in an environment of constant change. These people say creative thinking and a willingness to embrace constant change will be the hallmarks of business success, but when technology moves faster than business leaders, the business environment itself becomes inevitably unstable. 

When it comes to AI deployment, that means confidential data leaks, legal battles as regulators challenge those leaks, and the need to invest in managing digital transformation. 

Faster than progress

AI development is accelerating. New models like GPT-5.3 Codex or Claude Opus 4.6 are insanely powerful and have now evolved something like autonomous discretion. That’s why they can create and iterate application code, which Xcode developers will be exploring now that tools have been made available to them.

It won’t end with code. You can see the direction of travel for yourself at METR, an organization that tracks how long it takes AI models to complete long tasks. 

Anthropic CEO Dario Amodei tells it like it is when he says AI models “substantially smarter than almost all humans at almost all tasks” could arrive as soon as this year. He also says it might only be a couple of years until AI autonomously builds its own AI successors. 

In the background, the leader of Anthropic’s Safeguards Research Team, Mrinank Sharma, just quit, warning the “world is in peril” from a series of interconnected crises, including AI. Think about that, think about the extent to which you and your business truly meet the standards of AI preparedness, and then consider the challenge it poses to IT decision makers working to keep their heads afloat amid this tsunami of change. 

The gap between perceived and actual readiness is not just a statistic, it is a call to action for every leader. In a world where AI evolves so very quickly, true leadership requires us to prepare for the unknown. The experts say those who manage to stay afloat will be the ones who experiment today, and adapt tomorrow. While you do that, note that AI will be adapting at the very same time and probably faster, and is already in use, sanctioned, or unsanctioned, across your company.

Are you ready? Probably not yet.

Yes, the image to this story was created using AI.

You can follow me on social media! Join me on BlueSky,  LinkedIn, and Mastodon.

Kimwolf Botnet Swamps Anonymity Network I2P

For the past week, the massive “Internet of Things” (IoT) botnet known as Kimwolf has been disrupting The Invisible Internet Project (I2P), a decentralized, encrypted communications network designed to anonymize and secure online communications. I2P users started reporting disruptions in the network around the same time the Kimwolf botmasters began relying on it to evade…

Windows Notepad RCE Flaw Exploits Markdown Files

Microsoft has patched a vulnerability in the modern Windows Notepad app that could allow remote code execution if a user opens a specially crafted Markdown file.  The issue carries a CVSS score of 8.8 and requires user interaction to exploit. The vulnerability “… allows an unauthorized attacker to execute code over a network,” said Microsoft…

Ivanti EPMM exploitation: Researchers warn of “sleeper” webshells

A massive wave of exploitation attempts has followed the disclosure of CVE-2026-1281, a critical pre-authentication Ivanti EPMM vulnerability, the Shadowserver Foundation has warned. Some of it is automated scanning for vulnerable systems, but according to Greynoise and Defused, a suspected initial access broker has been prepping unpatched instances with a “sleeper” webshell for follow-on exploitation…

Reynolds ransomware uses BYOVD to disable security before encryption

Researchers discovered Reynolds ransomware, which uses BYOVD technique to disable security tools and evade detection before encryption. Researchers found a new ransomware, named Reynolds, that implements the Bring Your Own Vulnerable Driver (BYOVD) technique to disable security tools and evade detection before encrypting systems. Broadcom’s cybersecurity researchers initially attributed the attack to Black Basta due…

APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entities

Indian defense sector and government-aligned organizations have been targeted by multiple campaigns that are designed to compromise Windows and Linux environments with remote access trojans capable of stealing sensitive data and ensuring continued access to infected machines.
The campaigns are characterized by the use of malware families like Geta RAT, Ares RAT, and DeskRAT, which are often

Dell Private Cloud Expands Choice with Nutanix Support

Dell Private Cloud now supports Nutanix with external storage flexibility. Organisations can keep the simplicity they love, while gaining the freedom to scale independently. Dell Private Cloud deploying Nutanix combines operational simplicity with architectural freedom, available today. Organisations can pair Nutanix AHV with Dell external storage, scaling compute and storage independently while maintaining familiar tools,…

CodeHunter expands behavioral intent analysis to secure the software supply chain

CodeHunter is expanding its behavioral intent technology beyond traditional malware analysis to address supply chain risk and security decision-making across the software development lifecycle (SDLC). According to a recent Gartner report, “software supply chains transcend organizational boundaries and consist of external entities in addition to internal systems.” Gartner also warns that “improper artifact integrity validation…

Westcon-Comstor Brings Meter NaaS to EMEA Channel

Westcon-Comstor has signed a new distribution agreement with Networking-as-a-Service (NaaS) specialist Meter, becoming the vendor’s first distributor in Europe, the Middle East, and Africa (EMEA). The move brings Meter’s full-stack, subscription-based networking platform to Westcon’s regional channel ecosystem, positioning partners to tap into growing demand for consumption-based networking without the need for additional upfront investment.…

Windows Patch Fixes Exploited RasMan DoS Flaw 

Microsoft has patched a vulnerability in the Windows Remote Access Connection Manager (RasMan) service that was being exploited to trigger denial-of-service (DoS) conditions on unpatched systems. If exploited, the flaw can cause the remote access service to crash, potentially interrupting VPN connectivity and affecting remote access for users and administrators. The vulnerability “… allows an…

Kong launches Context Mesh to turn enterprise APIs into agent-ready tools

Kong has announced Kong Context Mesh, a product that automatically discovers enterprise APIs, transforms them into agent-consumable tools, and deploys them with runtime governance. “Organisations have spent years building APIs as the nervous system of the enterprise. Context Mesh allows them to reuse that investment to power agents instead of starting from scratch,” said Marco…

SmartBear Expands Carahsoft Partnership for Public Sector

SmartBear has expanded its partnership with Carahsoft Technology Corp. to strengthen its public sector go-to-market strategy and deepen engagement with the government-focused channel ecosystem, the companies announced Tuesday. The expanded agreement positions Carahsoft as SmartBear’s Master Government Aggregator, giving federal, state, and local agencies simplified access to SmartBear’s software quality and application visibility portfolio through…

Smartsheet Channel Exec on Partners, Platforms, and 2026

As more enterprises look to streamline technology stacks and accomplish more with less, vendors and OEMs are finding themselves in an evolving market focused on bringing integrated solutions to customers through partners. We spoke with Scott Strubel, head of Americas partner sales at Smartsheet, about how market trends influence the ways vendors work with partner…

Dell Makes Annual Updates to Partner Program

Global technology leader Dell Technologies has taken steps to simplify, standardize, and automate how it does business with channel partners in its ecosystem. Dell Technologies focuses on growing its core business and new markets with partners The company states that in 2026, its long-term objectives with partners will focus on growing the core business, expanding…

Why CoreX Acquired InSource’s ServiceNow Unit in 2026

Earlier this year, CoreX announced that it would be acquiring InSource’s ServiceNow business unit to expand ServiceNow delivery capabilities. Companies say deal is a strategic move to scale ServiceNow services The companies involved say the deal will create a single, purpose-built organization to scale with intent, elevate enterprise transformation outcomes, and meet worldwide demand for…

GOP Congress moves to shape election law in Trump’s image

Republicans in Congress are moving ahead with two pieces of legislation this week that would dramatically reshape the nation’s election laws. Together, the SAVE America Act and MEGA Act would shift key voter certification powers to the executive branch,  require stricter proof of citizenship for voter registration, and allow states to more easily access federal…

Digital Gold for Predators: Tenable Expert Warns of AI-Powered “Dark Age” for Romance Scams Ahead of Valentine’s Day

GUEST OPINION:  Romance scams have entered a “dark age,” evolving from disorganised individual actors into a multi-billion-dollar criminal enterprise. According to the US Federal Trade Commission, investment scams, the primary “endgame” for romance fraud, resulted in $5.7 billion in losses in 2024, a figure experts believe is a conservative estimate.

North Korean actors blend ClickFix with new macOS backdoors in Crypto campaign

A financially motivated threat actor tracked as UNC1609 is using a ClickFix-style social engineering campaign to deploy multiple macOS malware families against crypto-focused organizations. According to new research from Google Cloud’s Mandiant, the activity recently targeted an employee at a company operating in the cryptocurrency and decentralized finance (DeFi) sector. The researchers said that the…

CISO Spotlight: Craig Riddell on Curiosity, Translation, and Why API Security is the New Business Imperative

It’s an unusually cold winter morning in Houston, and Craig Riddell is settling into his new role as Wallarm’s Global Field CISO. It’s a position that suits him down to the ground, blending technical depth, empathy, business acumen, and, what Craig believes, the most underrated skill in cybersecurity: curiosity.  Like so many of us, Craig…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

Model Context Protocol: Security Risks & Mitigations

AI adoption is moving fast, shifting from pilot projects to the infrastructure-level, day-to-day practice. The budget curve reflects that shift. Gartner expects worldwide AI spending to reach $2.52T in 2026, a 44% year-over-year increase. At the same time, AI cybersecurity spending is expected to grow by more than 90% in 2026, a clear signal that…

That “summarize with AI” button might be manipulating you

Microsoft security researchers discovered a growing trend of AI memory poisoning attacks used for promotional purposes, referred to as AI Recommendation Poisoning. The MITRE ATLAS knowledge base classifies this behavior as AML.T0080: Memory Poisoning. The activity focuses on shaping future recommendations by inserting prompts that cause an assistant to treat specific companies, websites, or services…

Exposed Training Open the Door for Crypto-Mining in Fortune 500 Cloud Environments

Intentionally vulnerable training applications are widely used for security education, internal testing, and product demonstrations. Tools such as OWASP Juice Shop, DVWA, Hackazon, and bWAPP are designed to be insecure by default, making them useful for learning how common attack techniques work in controlled environments. The issue is not the applications themselves, but how they…

Google Search introduces new ways to remove sensitive personal information and explicit images

Google expanded its “Results about you” tool to give users more control over sensitive personal information and added a way to request removal of non-consensual explicit images from Search. Manage and limit sensitive personal information in Search Users can request the removal of Search results that contain sensitive personal information, such as driver’s license numbers,…

EU clears Google’s $32B Wiz acquisition, intensifying cloud security competition

Google has secured unconditional EU antitrust approval for its $32 billion acquisition of cloud security firm Wiz, clearing a major regulatory hurdle and paving the way for one of the largest cybersecurity acquisitions to date.   The decision removes a key uncertainty for enterprise customers and positions Google Cloud to aggressively expand its security portfolio…

How Digital Training Programs Support Skills in Healthcare Settings

In this post, I will show you how digital training programs support skills in healthcare settings. Healthcare workers should keep updating their information to provide safe and effective care. In such environments, digital training programs have emerged as a critical component of the skill development strategy. Frequent learning opportunities allow staff to build familiarity and…

SSHStalker Botnet Uses IRC C2 to Control Linux Systems via Legacy Kernel Exploits

Cybersecurity researchers have disclosed details of a new botnet operation called SSHStalker that relies on the Internet Relay Chat (IRC) communication protocol for command-and-control (C2) purposes. “The toolset blends stealth helpers with legacy-era Linux exploitation: Alongside log cleaners (utmp/wtmp/lastlog tampering) and rootkit-class artifacts, the actor keeps a large back-catalog of

SSHStalker botnet targets Linux servers with legacy exploits and SSH scanning

A new Linux botnet, SSHStalker, has infected about 7,000 systems using old 2009-era exploits, IRC bots, and mass-scanning malware. Flare researchers uncovered a previously undocumented Linux botnet dubbed SSHStalker, observed via SSH honeypots over two months. Researchers ran an SSH honeypot with weak credentials starting in early 2026 and spotted a set of intrusions unlike…

The hard part of purple teaming starts after detection

In my recent articles for CSO, I’ve talked about the limits of current SOC models and the importance of rehearsal. This time, I want to focus on something that’s becoming increasingly clear: purple teaming has lost its depth. We’ve turned one of the most powerful tools for resilience into a transactional exercise that feels reassuring…

Emerging Ransomware BQTLock & GREENBLOOD Disrupt Businesses in Minutes 

How long would it take your team to realize ransomware is already running?  The newly identified ransomware families are already causing real business disruption. These threats can disrupt operations fast while also reducing visibility through stealth or cleanup activity, shrinking the time teams have to detect and contain the attack.  Here’s what you should know about BQTLock and GREENBLOOD, and how your team can detect and contain them before…

U.S. CISA adds Microsoft Office and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Office and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Microsoft Office and Microsoft Windows flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: CVE-2026-21510 Microsoft Windows Shell Protection Mechanism Failure…

CISOs must separate signal from noise as CVE volume soars

In 2026, the cybersecurity industry is expected to cross a threshold it has never reached before: More than 50,000 publicly disclosed software vulnerabilities in a single year. According to a new forecast from the Forum of Incident Response and Security Teams (FIRST), the median projection for 2026 is roughly 59,000 Common Vulnerabilities and Exposures (CVEs).…

North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations

The North Korea-linked threat actor known as UNC1069 has been observed targeting the cryptocurrency sector to steal sensitive data from Windows and macOS systems with the ultimate goal of facilitating financial theft. “The intrusion relied on a social engineering scheme involving a compromised Telegram account, a fake Zoom meeting, a ClickFix infection vector, and reported…

Vorgetäuschte PDFs bergen neue Gefahren

loading=”lazy” width=”400px”>Cyberkriminelle verschicken ihre Malware als PDF-Dateien getarnt. IDG Der Security-Anbieter Malwarebytes hat kürzlich vor einer besonders perfiden Phishing-Kampagne gewarnt. Die Angreifer tarnen dabei ihre Malware als gewöhnliches PDF-Dokument. Mitarbeiter sind es gewohnt, Bestellungen oder Rechnungen im PDF-Format zu erhalten. Daher ist es sehr wahrscheinlich, dass die schädlichen Dateien geöffnet werden. Klickt ein Mitarbeiter auf…

Cisco enhances security for enterprise AI adoption

Cisco announced a suite of capabilities to help enterprises adopt agentic AI with confidence, combining agent protection, interaction governance, and resilient connectivity for AI-driven workflows. As organizations move from AI assistants to autonomous agents that use tools and data across hybrid environments, security teams need to strengthen agentic defenses, govern agent interactions with enterprise systems…

Groupe Rocher CISO on strengthening a modern retail cybersecurity strategy

Global retail and beauty brands manage a unique cybersecurity balancing act. They depend on consumer trust, massive volumes of personal data, and a sprawling network of vendors, while also managing thousands of physical locations and dynamic digital growth. In this Help Net Security interview, Jérôme Etienne, Group CISO, Groupe Rocher shares practical insights on closing…

Trellix SecondSight identifies subtle indicators of an active breach

Trellix announced Trellix SecondSight, a threat hunting service designed to proactively identify low-noise advanced threats often undetected, reducing organizational risk for Trellix customers. “Threat actors’ use of AI has significantly increased alert fatigue for security analysts,” said John Fokker, VP Threat Intelligence Strategy, Trellix. “While automated systems flag high-level alerts, they often miss subtle, low-noise…

Zen-AI-Pentest: Open-source AI-powered penetration testing framework

Zen-AI-Pentest provides an open-source framework for scanning and exercising systems using a combination of autonomous agents and standard security utilities. The project aims to let users run an orchestrated sequence of reconnaissance, vulnerability scanning, exploitation, and reporting using AI guidance and industry tools like Nmap and Metasploit. It is written to support command line, API,…

Product showcase: PCAPdroid analyzes Android app network activity

PCAPdroid is a free, open-source Android app that allows inspection of network traffic. Installation is straightforward and does not require creating an account. To begin capturing traffic, a VPN request must be accepted, which allows the app to monitor network activity. Once permission is granted, tapping the play button starts PCAPdroid, which then runs in…

Security teams are paying for sprawl in more ways than one

Most enterprises run security programs across sprawling environments that include mobile devices, SaaS applications, cloud infrastructure, and telecom networks. Spend control in these areas often sits outside the security organization, even when the operational consequences land directly on security teams. Tangoe’s 2026 Trends & Savings Recommendations Report connects these cost domains to recurring governance failures…

Microsoft to roll out a ‘consent first’ model to protect Windows

Windows serves as the backbone of enterprises around the world, powering more than a billion devices and supporting millions of apps. However Microsoft acknowledges that apps are increasingly going rogue, overriding settings, installing additional components, or altering critical Windows capabilities without user awareness or approval. In response, the tech giant plans to roll out what…

February 2026 Patch Tuesday: Six new and actively exploited Microsoft vulnerabilities addressed

Microsoft highlighted six new and actively exploited vulnerabilities among the 60 fixes issued in today’s February Patch Tuesday releases. However, Tyler Reguly, associate director of security R&D at Fortra, says there’s good news: The issues are easy to resolve with regular Microsoft patches for Windows and Office, and none require any post patch configuration steps.…

Telstra’s Spectrum Warning: The Real Cost of Policy Trade-Offs

When Telstra talks about “cost trade-offs,” it’s not idle commentary. It’s a signal to regulators, policymakers – and consumers. The telco’s latest comments around spectrum licence obligations, administered by the Australian Communications and Media Authority (ACMA), have reignited a familiar debate: how do you balance public interest requirements with the commercial realities of building and…

Telstra’s Spectrum Warning: The Real Cost of Policy Trade-Offs

When Telstra talks about “cost trade-offs,” it’s not idle commentary. It’s a signal to regulators, policymakers – and consumers. The telco’s latest comments around spectrum licence obligations, administered by the Australian Communications and Media Authority (ACMA), have reignited a familiar debate: how do you balance public interest requirements with the commercial realities of building and…

Telstra’s plan to move up to 209 roles offshore as part of its AI joint venture with Accenture deserves more than a passing glance

This isn’t just another line in a restructuring update. It goes to the heart of how and where Australia builds its digital future. Let’s be clear: global partnerships are not new, and they’re not inherently bad. India is a powerhouse in IT services and AI talent. Accenture operates at enormous global scale. From a cost…

Telstra’s plan to move up to 209 roles offshore as part of its AI joint venture with Accenture deserves more than a passing glance

This isn’t just another line in a restructuring update. It goes to the heart of how and where Australia builds its digital future. Let’s be clear: global partnerships are not new, and they’re not inherently bad. India is a powerhouse in IT services and AI talent. Accenture operates at enormous global scale. From a cost…

BeyondTrust fixes critical RCE flaw in remote access tools

Companies using self-hosted versions of BeyondTrust Remote Support (RS) or Privileged Remote Access (PRA) should deploy patches for a critical vulnerability that allows attacks to execute OS commands without authentication. “Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption,” BeyondTrust said in…

Microsoft Patch Tuesday security updates for February 2026 fix six actively exploited zero-days

Microsoft Patch Tuesday security updates for February 2026 fix six actively exploited zero-day vulnerabilities. Microsoft Patch Tuesday security updates for February 2026 fix 58 new security flaws across Windows, Office, Azure, Edge, Exchange, Hyper-V, WSL, and other components, rising to 62 CVEs when third-party updates are included. Five vulnerabilities are Critical, two Moderate, and most…

Patch Tuesday, February 2026 Edition

Microsoft today released updates to fix more than 50 security holes in its Windows operating systems and other software, including patches for a whopping six “zero-day” vulnerabilities that attackers are already exploiting in the wild. Zero-day #1 this month is CVE-2026-21510, a security feature bypass vulnerability in Windows Shell wherein a single click on a…

No-Contract Internet Plans Georgia Comparison: Speed, Price & Fees Side-by-Side

In this post, I will discuss the no-contract Internet plans Georgia comparison. Also, I will talk about their speed, price & fees side-by-side. Georgia internet shoppers can finally skip the fine print. About 52 percent of the state already sits on fiber lines, and 5G fixed-wireless is filling most remaining gaps, according to BroadbandNow Georgia…

AI chatbots are worse than search engines for medical advice

There is a clear gap between the theoretical medical knowledge of large language models (LLMs) and their practical usefulness for patients, according not a new study from the Oxford Internet Institute and the Nuffield Department of Primary Care Health Sciences at the University of Oxford. The research, conducted in collaboration with MLCommons and other institutions,…

Global Group ransomware gang running new campaign using Windows shortcut files

When Microsoft patched a vulnerability last summer that allowed threat actors to use Windows’ shortcut (.lnk) files in exploits, defenders might have hoped use of this tactic would decline. They were wrong. According to researchers at Forcepoint, a new high-volume phishing campaign spreading the Global Group ransomware has been detected that hopes to sucker employees…

Video: How Netskope and Optiv Fight Shadow AI

As organizations race to modernize cloud environments and adopt AI, security and governance can’t be an afterthought. In this episode of Partner POV, Katie Bavoso sits down with Netskope and Optiv to explore how a deep partner-led approach helps customers securely adopt cloud and AI technologies at scale. Joe Green of Netskope and Paul Herrmann…

Microsoft Patch Tuesday matches last year’s zero-day high with six actively exploited vulnerabilities

Microsoft’s latest security update is littered with zero-day vulnerabilities, actively exploited defects that account for more than 10% of the total CVEs the vendor addressed in this month’s Patch Tuesday update. The vendor addressed 59 vulnerabilities affecting its various products for business operations and underlying systems, including six defects that were actively exploited prior to…

FortiOS Authentication Bypass Exposes VPN and SSO Deployments

Fortinet has disclosed an authentication bypass vulnerability in FortiOS.  Under certain configurations, the flaw could allow attackers to bypass LDAP-based authentication controls and gain unauthorized access to protected enterprise networks. The vulnerability “… may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, under specific LDAP server configuration,” said Fortinet…

FortiSandbox XSS Vulnerability Allows Remote Command Execution

Fortinet has disclosed a vulnerability in its FortiSandbox platform that could allow unauthenticated attackers to execute arbitrary commands.  The issue involves a cross-site scripting (XSS) flaw in the FortiSandbox web interface that may lead to elevated access if exploited. The vulnerability “… may allow an unauthenticated attacker to execute commands via crafted requests,” said Fortinet…

Microsoft Patch Tuesday – January 2026, (Tue, Feb 10th)

Today’s patch Tuesday addresses 59 different vulnerabilities (plus two Chromium vulnerabilities affecting Microsoft Edge). While this is a lower-than-normal number, this includes six vulnerabilities that are already exploited. Three vulnerabilities have already been exploited and made public. In addition, five critical vulnerabilities are included in this patch Tuesday. Vulnerabilities of Interest: The three already exploited…

Picus Red Report 2026 Shows Attackers Favor Stealth Over Disruption

Cyber attackers are quietly changing how they operate — and the latest Picus Red Report shows that disruption is no longer the goal.  Rather than encrypting systems or triggering immediate disruption, Picus Security found that adversaries are prioritizing stealth, persistence, and long-term access within enterprise environments.  “The 2026 Red Report confirms that the era of…

DPRK Operatives Impersonate Professionals on LinkedIn to Infiltrate Companies

The information technology (IT) workers associated with the Democratic People’s Republic of Korea (DPRK) are now applying to remote positions using real LinkedIn accounts of individuals they’re impersonating, marking a new escalation of the fraudulent scheme. “These profiles often have verified workplace emails and identity badges, which DPRK operatives hope will make their fraudulent

Apple, Google agree to app store changes in the UK

Under pressure from UK regulators, Apple and Google have reached an agreement to change how they operate their app stores in the UK, the Competition and Markets Authority (CMA) announced on Tuesday. The agreement means both companies will not discriminate against apps that compete with their own apps and services. They pledged to be more transparent…

Reco Raises $30M Series B to Address AI SaaS Security Risks

Reco, a New York-based security vendor focused on AI-driven SaaS environments, has raised $30 million in Series B funding, bringing its total capital raised to $85 million.  The round was led by Zeev Ventures and included participation from existing investors Insight Partners, boldstart ventures, and Angular Ventures, along with new strategic backers Workday Ventures, TIAA…

SpecterOps Unveils BloodHound Scentry, Expanding Identity APM

SpecterOps, the pioneer behind identity Attack Path Management (APM), has introduced BloodHound Scentry, a new service designed to help customers accelerate their APM practice and reduce identity risk.  Protecting an organization’s critical assets According to the company, BloodHound Scentry combines the capabilities of BloodHound Enterprise with the tradecraft of SpecterOps experts to provide tailored guidance…

Stop comparing safety and cybersecurity, they have very little in common

Nearly a year ago, we hosted Dug Song, the legendary founder of Duo Security, on Inside the Network. During that conversation, Dug shared a powerful analogy that has stuck with me. He explained that in aviation, a plane crashes the same way only once, or maybe twice. Whenever it happens, we get to the bottom…

SolarWinds WHD zero-days from January are under attack

SolarWinds Web Help Desk (WHD) is under attack, with recent incidents exploiting a chain of zero-day and patched vulnerabilities dating back to late 2025, an analysis of customer reports by security company Huntress has found. Until now, it has been unclear which combination of recent WHD vulnerabilities were behind a series of compromises of customer…

After major Poland energy grid cyberattack, CISA issues warning to U.S. audience

A recent attempt at a destructive cyberattack on Poland’s power grid has prompted the Cybersecurity and Infrastructure Security Agency to publish a warning for U.S. critical infrastructure owners and operators. Tuesday’s alert follows a Jan. 30 report from Poland’s Computer Emergency Response Team concluded the December attack overlapped significantly with infrastructure used by a Russian…

CVE-2026-21643: Critical FortiClient EMS Vulnerability Enables Unauthenticated Remote Code Execution

Shortly after our recent coverage of high-impact FortiOS SSO zero-day exploitation (CVE-2026-24858), defenders are facing another urgent patching priority in the Fortinet ecosystem. On February 6, Fortinet released a fix for a critical SQL injection flaw that can be triggered remotely and doesn’t require authentication, potentially leading to unauthorized code or command execution.  Although there…

Bing Ads Abused to Deliver Azure-Hosted Tech Support Scams

A recently identified scam campaign is using Bing search advertisements and Microsoft Azure infrastructure to redirect users to fraudulent tech support pages, demonstrating how legitimate platforms can be misused for social engineering activity.  “The tech support scam campaign had a significant initial impact, affecting users across 48 different organizations in the U.S. within a short…

Singapore telcos breached in China-linked cyber espionage campaign

Singapore’s four major telecommunications companies were hit by a coordinated cyber espionage campaign last year, the country’s Cyber Security Agency (CSA) has revealed. An advanced persistent threat group known as UNC3886 has probed deep into the networks of M1, SIMBA Telecom, Singtel, and StarHub, spurring Singapore’s security agencies to mount a large cyber defence operation.…

ZeroDayRAT spyware grants attackers total access to mobile devices

ZeroDayRAT is a commercial mobile spyware that grants full remote access to Android and iOS devices for spying and data theft. ZeroDayRAT is a newly discovered commercial mobile spyware toolkit that gives attackers full control over Android and iOS devices. It supports live camera access, keylogging, and theft of banking and crypto data. First spotted…