Geek-Guy.com

Category: North America

Analyze the latest North American cybersecurity trends, from critical infrastructure protection to evolving threat actor tactics. Get expert insights on regional data security, identity management, and the impact of AI on digital defense across the U.S. and Canada.

Prosecutors allege incident response pros used ALPHV/BlackCat to commit string of ransomware attacks

Federal prosecutors allege that three cybersecurity professionals, whose job was to help companies respond to ransomware attacks, instead carried out their own ransomware schemes against five U.S. businesses in 2023. Ryan Clifford Goldberg, Kevin Tyler Martin and an unnamed co–conspirator — all U.S. nationals — began using ALPHV, also known as BlackCat, ransomware to attack…

Alleged Jabber Zeus Coder ‘MrICQ’ in U.S. Custody

A Ukrainian man indicted in 2012 for conspiring with a prolific hacking group to steal tens of millions of dollars from U.S. businesses was arrested in Italy and is now in custody in the United States, KrebsOnSecurity has learned. Sources close to the investigation say Yuriy Igorevich Rybtsov, a 41-year-old from the Russia-controlled city of…

Cyber scholarship-for-service students say government has pulled rug on them, potentially burdening them with debt

A landmark program that offers scholarships in exchange for federal service is threatening to saddle students with hundreds of thousands of dollars worth of debt amid hiring freezes and budget cuts, raising questions about the future of an initiative proponents say has helped close the government’s cyber workforce gap. Some CyberCorps: Scholarship for Service participants…

Government watchdog sues DHS over election official’s records

A nonprofit government watchdog group is suing the Department of Homeland Security, alleging that department officials have delayed and denied legitimate public information requests regarding  the hiring of Heather Honey. Honey was hired by DHS earlier this year and given the title “Deputy Assistant Secretary for Elections Integrity,” a change from past administrations, which have…

X-Request-Purpose: Identifying “research” and bug bounty related scans?, (Thu, Oct 30th)

This week, I noticed some new HTTP request headers that I had not seen before: X-Request-Purpose: Research and X-Hackerone-Research: plusultra X-Bugcrowd-Ninja: plusultra X-Bug-Hunter: true The purpose of these headers appears to be to identify them as being sent as part of a bug bounty. Some companies request the use of these headers as part of…

Aisuru Botnet Shifts from DDoS to Residential Proxies

Aisuru, the botnet responsible for a series of record-smashing distributed denial-of-service (DDoS) attacks this year, recently was overhauled to support a more low-key, lucrative and sustainable business: Renting hundreds of thousands of infected Internet of Things (IoT) devices to proxy services that help cybercriminals anonymize their traffic. Experts says a glut of proxies from Aisuru…

F5 asserts limited impact from prolonged nation-state attack on its systems

F5 CEO François Locoh-Donou said on a company earnings call that there were two categories of impact on customers following a nation-state attacker’s long-term, persistent access to its systems: widespread emergency updates to BIG-IP software and hardware, and customers whose configuration data was stolen during the attack. “We were very impressed frankly, with the speed…

Volvo’s recent security breach: 5 tips to speed incident response while preserving forensic integrity

In August 2025, Volvo Group North America disclosed that it had been impacted by a data breach originating in its third-party HR software provider, Miljödata. Although Volvo insisted its internal systems remained untouched, the timeline of detection and disclosure raises questions about forensic readiness and incident-response maturity. Miljödata first detected suspicious activity on August 23,…

National cyber director says U.S. needs to counter Chinese surveillance, push American tech

The United States needs to counter China’s “attempt to export a surveillance state across planet Earth,” and instead push a “clean American tech stack” globally, National Cyber Director Sean Cairncross said Friday. “It’s important that we send that message and engage with not only partners that we have now, but potential partners who are looking…

Infostealer Targeting Android Devices, (Thu, Oct 23rd)

Infostealers landscape exploded in 2024 and they remain a top threat today. If Windows remains a nice target (read: Attackers’ favorite), I spotted an Infostealer targeting Android devices. This sounds logical that attackers pay attention to our beloved mobile devices because all our life is stored on them. The sample that I found (SHA256: 7576cdb835cd81ceb030f89fe5266649ed4a6201547c84da67144f407684a182)…

Canada Fines Cybercrime Friendly Cryptomus $176M

Financial regulators in Canada this week levied $176 million in fines against Cryptomus, a digital payments platform that supports dozens of Russian cryptocurrency exchanges and websites hawking cybercrime services. The penalties for violating Canada’s anti money-laundering laws come ten months after KrebsOnSecurity noted that Cryptomus’s Vancouver street address was home to dozens of foreign currency…

Sendmarc appoints Dan Levinson as Customer Success Director in North America

Sendmarc has announced the appointment of Dan Levinson as Customer Success Director – North America, furthering the company’s regional expansion and commitment to providing expert, locally aligned support to organizations across the continent. Levinson will lead the development of customer success programs that help businesses strengthen their email security and achieve full compliance with Domain-based…

Robocalling task force bill advances in Senate

The federal government is shut down and the House remains out of session, but work in the Senate continues, as a bipartisan bill designed to crack down on overseas robocalls  advanced through a key committee Tuesday. The Foreign Robocall Elimination Act, sponsored by Sens. Ted Budd, R-N.C., and Peter Welch, D-Vt., would create a new…

Dataminr to acquire cybersecurity firm ThreatConnect for $290 million

Dataminr, a New York-based company specializing in real-time threat intelligence, announced plans Tuesday to acquire ThreatConnect, a cybersecurity threat intelligence provider, for $290 million. The acquisition will combine Dataminr’s AI-powered analysis of public data with ThreatConnect’s internal threat management capabilities, creating what the companies describe as “Client-Tailored intelligence” that adapts to individual customer needs. The…

AI-enabled ransomware attacks: CISO’s top security concern — with good reason

As ransomware attacks accelerate in speed and sophistication, 38% of security leaders rank AI-enabled ransomware as their top concern — the most frequently cited worry about AI-related security issues according to CSO’s new 2025 Security Priorities study. That concern appears to already be well founded, as a second study released today, CrowdStrike’s 2025 State of…

Tykit Analysis: New Phishing Kit Stealing Hundreds of Microsoft Accounts in Finance & Construction 

Not long ago we reported a spike in phishing attacks that use an SVG file as the delivery vector. One striking detail was how the SVG embeds JavaScript that rebuilds the payload with XOR and then executes it directly via eval() to redirect victims to a phishing page.  A quick look at the indicators we…

Cork Report Asserts Need for Shift to Next-Gen IT Services

Cork Protection recently released its “SMB Cyber Defense 2026: Expert Strategies for Staying Ahead of Threat Actors” report, compiling market research and industry expertise with advice for MSPs and other providers seeking to build the next evolution of their business. We spoke with Cork Protection CEO Dan Candee about the report and how he plans…

FedRAMP Continuous Monitoring: Strategies for Ongoing Compliance

Here, we will address FedRAMP’s continuous Monitoring, and I will reveal the strategies for ongoing compliance. In today’s interconnected digital landscape, the security of sensitive information is paramount. For organizations handling government data in the United States, compliance with the Federal Risk and Authorization Management Program (FedRAMP) is not just a one-time task but an…

WatchGuard Introduces Endpoint Security Prime

WatchGuard Technologies, a provider of unified cybersecurity, recently announced the launch of Endpoint Security Prime (Prime), a new package designed for endpoint protection. AI-powered EDR and antivirus protection meet next-gen security demand Endpoint Security Prime combines complete, AI-powered endpoint detection and response (EDR) with next-generation antivirus (NGAV), reducing attack surfaces and stopping threats in real…

Researchers warn of widespread RDP attacks by 100K-node botnet

A botnet of 100K+ IPs from multiple countries is attacking U.S. RDP services in a campaign active since October 8. GreyNoise researchers uncovered a large-scale botnet that is targeting Remote Desktop Protocol (RDP) services in the United States starting on October 8. The company discovered the botnet after detecting an unusual spike in Brazilian IP…

House Dems seek info about ICE spyware contract, wary of potential abuses

Three House Democrats questioned the Department of Homeland Security on Monday over a reported Immigration and Customs Enforcement contract with a spyware provider that they warn potentially “threatens Americans’ freedom of movement and freedom of speech.” Their letter follows publication of a notice that ICE had lifted a stop-work order on a $2 million deal…

House Dems seek info about ICE spyware contract, wary of potential abuses

Three House Democrats questioned the Department of Homeland Security on Monday over a reported Immigration and Customs Enforcement contract with a spyware provider that they warn potentially “threatens Americans’ freedom of movement and freedom of speech.” Their letter follows publication of a notice that ICE had lifted a stop-work order on a $2 million deal…

House Dems seek info about ICE spyware contract, wary of potential abuses

Three House Democrats questioned the Department of Homeland Security on Monday over a reported Immigration and Customs Enforcement contract with a spyware provider that they warn potentially “threatens Americans’ freedom of movement and freedom of speech.” Their letter follows publication of a notice that ICE had lifted a stop-work order on a $2 million deal…

House Dems seek info about ICE spyware contract, wary of potential abuses

Three House Democrats questioned the Department of Homeland Security on Monday over a reported Immigration and Customs Enforcement contract with a spyware provider that they warn potentially “threatens Americans’ freedom of movement and freedom of speech.” Their letter follows publication of a notice that ICE had lifted a stop-work order on a $2 million deal…

House Dems seek info about ICE spyware contract, wary of potential abuses

Three House Democrats questioned the Department of Homeland Security on Monday over a reported Immigration and Customs Enforcement contract with a spyware provider that they warn potentially “threatens Americans’ freedom of movement and freedom of speech.” Their letter follows publication of a notice that ICE had lifted a stop-work order on a $2 million deal…

FunkSec’s FunkLocker: How AI Is Powering the Next Wave of Ransomware 

Editor’s note: The current article is authored by Mauro Eldritch, offensive security expert and threat intelligence analyst. You can find Mauro on X.  AI is part of our lives whether we like it or not. Even if you are not quite a fan, or not a user at all, you probably came across multiple AI-generated avatars, pictures,…

Google Secretly Handed ICE Data About Pro-Palestine Student Activist

Even before immigration authorities began rounding up international students who had spoken out about Israel’s war on Gaza earlier this spring, there was a sense of fear among campus activists. Two graduate students at Cornell University — Momodou Taal and Amandla Thomas-Johnson — were so worried they would be targeted that they fled their dorms…

Google Secretly Handed ICE Data About Pro-Palestine Student Activist

Even before immigration authorities began rounding up international students who had spoken out about Israel’s war on Gaza earlier this spring, there was a sense of fear among campus activists. Two graduate students at Cornell University — Momodou Taal and Amandla Thomas-Johnson — were so worried they would be targeted that they fled their dorms…

Google Secretly Handed ICE Data About Pro-Palestine Student Activist

Even before immigration authorities began rounding up international students who had spoken out about Israel’s war on Gaza earlier this spring, there was a sense of fear among campus activists. Two graduate students at Cornell University — Momodou Taal and Amandla Thomas-Johnson — were so worried they would be targeted that they fled their dorms…

Google Secretly Handed ICE Data About Pro-Palestine Student Activist

Even before immigration authorities began rounding up international students who had spoken out about Israel’s war on Gaza earlier this spring, there was a sense of fear among campus activists. Two graduate students at Cornell University — Momodou Taal and Amandla Thomas-Johnson — were so worried they would be targeted that they fled their dorms…

Google Secretly Handed ICE Data About Pro-Palestine Student Activist

Even before immigration authorities began rounding up international students who had spoken out about Israel’s war on Gaza earlier this spring, there was a sense of fear among campus activists. Two graduate students at Cornell University — Momodou Taal and Amandla Thomas-Johnson — were so worried they would be targeted that they fled their dorms…

Kosovo man pleads guilty to running online criminal marketplace BlackDB

Kosovo man Liridon Masurica pleaded guilty to running the cybercrime marketplace BlackDB. He was arrested in 2024. Kosovo citizen Liridon Masurica (33) of Gjilan, aka @blackdb, pleaded guilty to running the BlackDB cybercrime market. Kosovo police arrested Masurica on December 12, 2024 and he was extradited to the US. The online criminal marketplace BlackDB.cc has…

Arms Cyber Launches Partner Program in North America

Cybersecurity firm Arms Cyber has launched its Shield Partner Program, an initiative designed to empower North American reseller partners to deliver preemptive cyber defense solutions, moving beyond the reactive approach of legacy systems.  Shifting from reactive to preemptive security In its official press release, Arms Cyber cited a Gartner forecast predicting that preemptive cybersecurity solutions…

Arms Cyber Launches Partner Program in North America

Cybersecurity firm Arms Cyber has launched its Shield Partner Program, an initiative designed to empower North American reseller partners to deliver preemptive cyber defense solutions, moving beyond the reactive approach of legacy systems.  Shifting from reactive to preemptive security In its official press release, Arms Cyber cited a Gartner forecast predicting that preemptive cybersecurity solutions…

KillSec Ransomware is Attacking Healthcare Institutions in Brazil

KillSec Ransomware claimed responsibility for a cyberattack on MedicSolution, a software solutions provider for the healthcare industry in Brazil. The KillSec Ransomware group has threatened to leak sensitive data unless negotiations are initiated promptly. According to threat intelligence reporting by Resecurity, the root cause of the incident – data exfiltration from insecure AWS S3 bucket.…

KillSec Ransomware is Attacking Healthcare Institutions in Brazil

KillSec Ransomware claimed responsibility for a cyberattack on MedicSolution, a software solutions provider for the healthcare industry in Brazil. The KillSec Ransomware group has threatened to leak sensitive data unless negotiations are initiated promptly. According to threat intelligence reporting by Resecurity, the root cause of the incident – data exfiltration from insecure AWS S3 bucket.…

Critical infrastructure security tech needs to be as good as our smartphones, top NSC cyber official says

The top cyber official at the National Security Council said Tuesday that he’s dismayed by the lag in security technology embedded in critical infrastructure, saying it pales in comparison to the tech in modern smartphones. “I worry a lot about critical infrastructure cybersecurity,” Alexei Bulazel said at the Billington Cybersecurity Summit. “I also think about…

U.S. indicts Ukrainian national for hundreds of ransomware attacks using multiple variants

The Department of Justice unsealed an indictment against a Ukrainian national alleged to be central to a ransomware campaign affecting hundreds of companies worldwide.  Volodymyr Viktorovych Tymoshchuk, known online as “deadforz,” “Boba,” “msfv,” and “farnetwork,” is accused of developing and deploying ransomware variants Nefilim, LockerGoga, and MegaCortex, all of which have been used in attacks…

OneTrust Research & Product Updates Show Need for AI Governance

AI governance platform provider, OneTrust, recently released new survey results that found significant gaps when it comes to AI governance and risk in the enterprise. Additionally, the organization announced some new product updates, including AI agents, privacy automation discovery, and continuous synchronization of AI projects between OneTrust and Databricks. OneTrust’s 2025 AI-Ready Governance Report OneTrust’s…

Treasury Department targets Southeast Asia scam hubs with sanctions

Federal authorities on Monday imposed sanctions on 19 people and organizations allegedly involved in major cyberscam hubs in Burma and Cambodia. “Criminal actors across Southeast Asia have increasingly exploited the vulnerabilities of Americans online,” Secretary of State Marco Rubio said in a statement. “In 2024, Americans lost at least $10 billion to scam operations in…

Supreme Court blocks FTC commissioner Slaughter’s reinstatement

Rebecca Slaughter’s return-to-work orders have been put on hold for the second time this year, after the U.S. Supreme Court stepped in to block a lower court ruling that ordered her reinstatement at the Federal Trade Commission. Last week a lower court ruled that Slaughter had been illegally fired by President Donald Trump, citing a…

Sendmarc appoints Rob Bowker as North American Region Lead

Veteran email security leader to expand MSP and VAR partnerships and accelerate DMARC adoption.  Sendmarc today announced the appointment of Rob Bowker as North American Region Lead. Bowker will oversee regional expansion with a focus on growing the Managed Service Provider (MSP) partner community, developing strategic Value-Added Reseller (VAR) partnerships, and broadening the enterprise customer…

Court rules ‘fired’ FTC commissioners be reinstated — again

For the second time, a court has ruled that President Donald Trump’s attempted firing of Federal Trade Commission members Rebecca Slaughter and Alvaro Bedoya was illegal and ordered the agency to reinstate the commissioners. By law, the FTC governs by a bipartisan 3-2 split, with the president’s party getting an extra seat and controlling the…

Trump administration setting the stage for elections power grab, voting rights group warns

Election officials should brace for direct attacks from the Trump administration and its state GOP allies on the integrity of U.S. elections — and plan for the possibility that federal agencies once charged with protecting elections will leverage their authorities to interfere in the process, a voting rights nonprofit warned. In a report released Wednesday,…

TransUnion discloses a data breach impacting over 4.4 million customers

TransUnion reported a data breach in which threat actors accessed personal information of over 4.4 million customers. TransUnion disclosed a data breach that impacted more than 4,461,511 customers. The company is one of the three major credit reporting agencies in the United States (alongside Experian and Equifax). It collects and maintains credit information on consumers…

TransUnion discloses a data breach impacting over 4.4 million customers

TransUnion reported a data breach in which threat actors accessed personal information of over 4.4 million customers. TransUnion disclosed a data breach that impacted more than 4,461,511 customers. The company is one of the three major credit reporting agencies in the United States (alongside Experian and Equifax). It collects and maintains credit information on consumers…

TransUnion discloses a data breach impacting over 4.4 million customers

TransUnion reported a data breach in which threat actors accessed personal information of over 4.4 million customers. TransUnion disclosed a data breach that impacted more than 4,461,511 customers. The company is one of the three major credit reporting agencies in the United States (alongside Experian and Equifax). It collects and maintains credit information on consumers…

TransUnion discloses a data breach impacting over 4.4 million customers

TransUnion reported a data breach in which threat actors accessed personal information of over 4.4 million customers. TransUnion disclosed a data breach that impacted more than 4,461,511 customers. The company is one of the three major credit reporting agencies in the United States (alongside Experian and Equifax). It collects and maintains credit information on consumers…

Treasury sanctions North Korea IT worker scheme facilitators and front organizations

The Treasury Department on Wednesday expanded efforts to disrupt the pervasive North Korean technical worker scheme by imposing sanctions on people and organizations serving as facilitators and fronts for the country’s years-long conspiracy effort to defraud businesses and earn money despite international sanctions.  Vitaly Sergeyevich Andreyev, Kim Ung Sun, Shenyang Geumpungri Network Technology and Korea…

Google previews cyber ‘disruption unit’ as U.S. government, industry weigh going heavier on offense

Google says it is starting a cyber “disruption unit,” a development that arrives in a potentially shifting U.S. landscape toward more offensive-oriented approaches in cyberspace. But the contours of that larger shift are still unclear, and whether or to what extent it’s even possible. While there’s some momentum in policymaking and industry circles to put…

Whistleblower: DOGE put Social Security database covering 300 million Americans on insecure cloud

The Elon Musk–founded Department of Government Efficiency (DOGE) uploaded to an insecure Amazon Web Services server a copy of Americans’ Social Security data, risking the security of critical personal information for more than 300 million people, according to a protected whistleblower disclosure to the US Office of Special Counsel and congressional committees filed by the Government Accountability Project.…

Sneak Peek: 2025 North America Community Meeting Speakers

The countdown is on for this year’s North America Community Meeting! We’re thrilled to share an early look at some of the exceptional sessions coming your way in Fort Worth, Texas, September 16–18. Get ready for insights, innovation, and inspiration! This year promises expertly crafted sessions that are imperative to securing payments worldwide. Register now…

Sneak Peek: 2025 North America Community Meeting Speakers

The countdown is on for this year’s North America Community Meeting! We’re thrilled to share an early look at some of the exceptional sessions coming your way in Fort Worth, Texas, September 16–18. Get ready for insights, innovation, and inspiration! This year promises expertly crafted sessions that are imperative to securing payments worldwide. Register now…

Sneak Peek: 2025 North America Community Meeting Speakers

The countdown is on for this year’s North America Community Meeting! We’re thrilled to share an early look at some of the exceptional sessions coming your way in Fort Worth, Texas, September 16–18. Get ready for insights, innovation, and inspiration! This year promises expertly crafted sessions that are imperative to securing payments worldwide. Register now…

Don’t Miss These 2025 PCI SSC Community Meeting Agenda Highlights

We are excited to announce that the full agendas for the PCI SSC 2025 North America, Europe, and Asia-Pacific Community Meetings are now available! Participants can hear directly about the latest advancements in payments, connect with a community of industry colleagues, and explore cutting- edge products and services from our vendors and sponsors.  

Don’t Miss These 2025 PCI SSC Community Meeting Agenda Highlights

We are excited to announce that the full agendas for the PCI SSC 2025 North America, Europe, and Asia-Pacific Community Meetings are now available! Participants can hear directly about the latest advancements in payments, connect with a community of industry colleagues, and explore cutting- edge products and services from our vendors and sponsors.