Geek-Guy.com

Category: North America

Analyze the latest North American cybersecurity trends, from critical infrastructure protection to evolving threat actor tactics. Get expert insights on regional data security, identity management, and the impact of AI on digital defense across the U.S. and Canada.

Don’t Miss These 2025 PCI SSC Community Meeting Agenda Highlights

We are excited to announce that the full agendas for the PCI SSC 2025 North America, Europe, and Asia-Pacific Community Meetings are now available! Participants can hear directly about the latest advancements in payments, connect with a community of industry colleagues, and explore cutting- edge products and services from our vendors and sponsors.  

Army Secretary forces West Point to rescind appointment given to Easterly

The United States Military Academy abruptly ended the appointment of Jen Easterly to a high-profile academic position in West Point’s Department of Social Sciences, according to a memorandum issued Wednesday by the Secretary of the Army. On Tuesday, the academy announced that Easterly was named as the next Robert F. McDermott Distinguished Chair, a department…

FBI seizes 20 BTC from Chaos Ransomware affiliate targeting Texas firms

FBI Dallas seized 20 BTC from Chaos ransomware affiliate “Hors,” tied to cyberattacks on Texas firms, on April 15, 2025. The FBI division in Dallas seized about 20 Bitcoins on April 15, 2025, from a wallet belonging to a Chaos ransomware affiliate named as “Hors.” The Hors affiliate is responsible for multiple cyberattacks on Texas…

Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure

The notorious cybercrime group known as Scattered Spider is targeting VMware ESXi hypervisors in attacks targeting retail, airline, and transportation sectors in North America. “The group’s core tactics have remained consistent and do not rely on software exploits. Instead, they use a proven playbook centered on phone calls to an IT help desk,” Google’s Mandiant…

Border Patrol Wants Advanced AI to Spy on American Cities

U.S. Customs and Border Protection, flush with billions in new funding, is seeking “advanced AI” technologies to surveil urban residential areas, increasingly sophisticated autonomous systems, and even the ability to see through walls. A CBP presentation for an “Industry Day” summit with private sector vendors, obtained by The Intercept, lays out a detailed wish list…

MuddyWater deploys new DCHSpy variants amid Iran-Israel conflict

Iran-linked APT MuddyWater is deploying new DCHSpy spyware variants to target Android users amid the ongoing conflict with Israel. Lookout researchers observed Iran-linked APT MuddyWater  (aka SeedWorm, TEMP.Zagros, and Static Kitten) is deploying a new version of the DCHSpy Android spyware in the context of the Israel-Iran conflict. The first MuddyWater campaign was observed in late 2017, when the APT group targeted entities in…

Authorities released free decryptor for Phobos and 8base ransomware

Japanese police released a free decryptor for Phobos and 8Base ransomware, letting victims recover files without paying ransom. Japanese authorities released a free decryptor for Phobos and 8Base ransomware, allowing victims to recover files without paying. Japanese police released the free decryptor for ransomware families, which was likely built using intel from a recent gang…

Anne Arundel Dermatology data breach impacts 1.9 million people

Hackers breached Anne Arundel Dermatology systems for three months, potentially exposing personal and health data of 1.9 million people. Anne Arundel Dermatology is a physician-owned and managed dermatology group headquartered in Maryland, founded over 50 years ago. It’s one of the largest dermatology providers in the Mid‑Atlantic and Southeastern United States, operating more than 100…

United Natural Foods loses up to $400M in sales after cyberattack

United Natural Foods said the cyberattack that prompted the food distributor and wholesaler to completely shut down its network last month resulted in lost sales of up to $400 million. Executives, during a business update call Wednesday with analysts and investors, said the financial impact from the attack is largely contained to the current quarter,…

United Natural Foods Expects $400M revenue impact from June cyber attack

United Natural Foods Projects (UNFI) expects a $350–$400M sales hit from a June cyberattack, with $50–$60M in net income impact. United Natural Foods, Inc. (UNFI), the main distributor for Amazon’s Whole Foods, said the June 2025 cyberattack will slash its fiscal 2025 sales by $350 to $400 million. United Natural Foods, Inc. (UNFI) is a Providence, Rhode…

House hearing will use Stuxnet to search for novel ways to confront OT cyberthreats

Congress is set to revisit Stuxnet — the malware that wreaked havoc on Iran’s nuclear program 15 years ago  — next week in the hopes that the pioneering attack can guide today’s critical infrastructure policy debate, CyberScoop has learned. The House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection will hold a hearing July 22…

Former Army soldier pleads guilty to widespread attack spree linked to AT&T, Snowflake and others

A 21-year-old former Army soldier pleaded guilty Tuesday to charges stemming from a series of attacks and extortion attempts last year on telecommunications companies, including AT&T.  Cameron John Wagenius, who identified himself as “kiberphant0m” and “cyb3rph4nt0m” on online criminal forums, conducted extensive malicious activity for years, including while he was on active duty, the Justice…

French police arrest Russian pro basketball player on behalf of US over ransomware suspicions

At the request of the United States, French police arrested a professional Russian basketball player who had a brief tenure at Penn State over accusations that he was part of a ransomware ring, according to overseas reports. News of the arrest of Daniil Kasatkin came in a court in Paris on Wednesday. His lawyer denied…

US Treasury Department sanctions individuals and entities over illegal IT worker scheme

The US Department of the Treasury’s Office of Foreign Assets Control (OFAC) Tuesday imposed sanctions on two individuals and four companies involved in schemes to provide US companies with illegal remote IT workers whose income would, it said, generate revenue for the Democratic People’s Republic of Korea (DPRK) regime. Song Kum Hyok, described as a…

LevelBlue: Third-Party Management Leading to Security Risks

LevelBlue, a managed security services, strategic consulting, and threat intelligence provider, recently released the Data Accelerator: Software Supply Chain and Cybersecurity report. The research digs into how vulnerable organizations are to the rise in software supply chain attacks.  To learn more about the findings and how businesses should respond, we spoke with Theresa Lanowitz, chief…

Was ist ein Botnet?

Ein Botnetz besteht aus vielen “Zombie”-Rechnern und lässt sich beispielsweise einsetzen, um DDoS-Attacken zu fahren. Das sollten Sie zum Thema wissen.  FOTOKINA | shutterstock.com Kriminelle Hacker suchen stets nach Möglichkeiten, Malware in großem Umfang zu verbreiten oder Distributed-Denial-of-Service (DDoS)-Angriffe zu fahren. Ein Botnet eignet sich dazu besonders gut. Botnet – Definition Ein Botnet ist eine…

Italian authorities arrest Chinese man over Microsoft Exchange Server hack, targeting of COVID-19 researchers

The Justice Department said Tuesday that Italian authorities arrested a Chinese national whom DOJ said was involved in the massive Microsoft Exchange Server hack from 2020 to 2021, an arrest made at the United States’ request. The arrest stems from a nine-count indictment dating back to 2023, which named the arrested man, Xu Zewei, 33,…

Anatsa Android Banking Trojan Hits 90,000 Users with Fake PDF App on Google Play

Cybersecurity researchers have discovered an Android banking malware campaign that has leveraged a trojan named Anatsa to target users in North America using malicious apps published on Google’s official app marketplace. The malware, disguised as a “PDF Update” to a document viewer app, has been caught serving a deceptive overlay when users attempt to access…

Hotter than a GPU in July: some tech jobs skyrocket, unemployment rate slides

US employers added more than 90,000 tech workers in June, pushing the industry’s unemployment rate down from 3.4% to 2.8%, according to a CompTIA analysis of the latest Bureau of Labor Statistics (BLS) data. The Computing Technology Industry Association (CompTIA) reported that tech unemployment remains well below the national average of 4.1%. “Tech employment showed…

Scattered Spider weaves web of social-engineered destruction

In an underworld fueled by infamy and money that leaves a trail of human misery in its wake, the unbound collective colloquially known as Scattered Spider deviates from many norms in cybercrime. The cunning threat group composed of young, native English-speaking people lacks cohesion, is rife with infighting and doesn’t have a data leak site,…

LevelBlue: Third-Party Management Leading to Security Risks

LevelBlue, a managed security services, strategic consulting, and threat intelligence provider, recently released the Data Accelerator: Software Supply Chain and Cybersecurity report. The research digs into how vulnerable organizations are to the rise in software supply chain attacks.  To learn more about the findings and how businesses should respond, we spoke with Theresa Lanowitz, chief…

Top FBI cyber official: Salt Typhoon ‘largely contained’ in telecom networks

The Chinese hackers behind the massive telecommunications sector breach are “largely contained” and “dormant” in the networks, “locked into the location they’re in” and “not actively infiltrating information,” the top FBI cyber official told CyberScoop. But Brett Leatherman, new leader of the FBI Cyber division, said in a recent interview that doesn’t mean the hackers,…

Europol Dismantles $540 Million Cryptocurrency Fraud Network, Arrests Five Suspects

Europol on Monday announced the takedown of a cryptocurrency investment fraud ring that laundered €460 million ($540 million) from more than 5,000 victims across the world. The operation, the agency said, was carried out by the Spanish Guardia Civil, along with support from law enforcement authorities from Estonia, France, and the United States. Europol said…

UNFI expects financial hit from cyberattack as recovery continues

Major North American grocery wholesaler United Natural Foods, Inc., has disclosed that the cyberattack it experienced earlier this month would have a “material impact” on its financials for the fourth quarter of fiscal year 2025 as it reported the successful recovery of its core systems, including its electronic ordering and invoice systems, according to BleepingComputer.

Canada bans Hikvision over national security concerns

Canada bans Hikvision over national security concerns, ordering the company to stop operations and barring its tech from government use. Canada ordered Chinese surveillance firm Hikvision to cease all operations in the country, citing national security concerns. Minister Mélanie Joly announced the decision after a security review found vendor’s activities could pose a threat. Canada…

Hacker helped kill FBI sources, witnesses in El Chapo case, according to watchdog report

A hacker working on behalf of the Sinaloa drug cartel infiltrated cameras and phones to track an FBI official in Mexico investigating the drug lord El Chapo, then used data from that surveillance to kill and intimidate potential sources and witnesses the agent was meeting with, a Justice Department watchdog report revealed. An FBI case…

Hacker helped kill FBI sources, witnesses in El Chapo case, according to watchdog report

A hacker working on behalf of the Sinaloa drug cartel infiltrated cameras and phones to track an FBI official in Mexico investigating the drug lord El Chapo, then used data from that surveillance to kill and intimidate potential sources and witnesses the agent was meeting with, a Justice Department watchdog report revealed. An FBI case…

Notorious cybercriminal ‘IntelBroker’ arrested in France, awaits extradition to US

Kai West, a prolific cybercriminal better known for operating under the moniker “IntelBroker,” was arrested in France earlier this year and faces federal charges for allegedly stealing data from more than 40 organizations during a two-year period, the Justice Department said Wednesday.  Federal prosecutors unsealed a four-count indictment charging West, a British national, with conspiracy…

New U.S. Visa Rule Requires Applicants to Set Social Media Account Privacy to Public

The United States Embassy in India has announced that applicants for F, M, and J nonimmigrant visas should make their social media accounts public. The new guideline seeks to help officials verify the identity and eligibility of applicants under U.S. law. The U.S. Embassy said every visa application review is a “national security decision.” “Effective…

Coffee with the Council Podcast: Meet This Year’s North America Community Meeting Keynote Speaker, Reed Timmer

  This episode of Coffee with the Council is brought to you by our podcast sponsor, Feroot. Welcome to our podcast series, Coffee with the Council. I’m Alicia Malone, Director of Communications and Public Relations for the PCI Security Standards Council. Today, I am so excited to bring you a sneak peek interview with PCI…

Coffee with the Council Podcast: Meet This Year’s North America Community Meeting Keynote Speaker, Reed Timmer

  This episode of Coffee with the Council is brought to you by our podcast sponsor, Feroot. Welcome to our podcast series, Coffee with the Council. I’m Alicia Malone, Director of Communications and Public Relations for the PCI Security Standards Council. Today, I am so excited to bring you a sneak peek interview with PCI…

Coffee with the Council Podcast: Meet This Year’s North America Community Meeting Keynote Speaker, Reed Timmer

  This episode of Coffee with the Council is brought to you by our podcast sponsor, Feroot. Welcome to our podcast series, Coffee with the Council. I’m Alicia Malone, Director of Communications and Public Relations for the PCI Security Standards Council. Today, I am so excited to bring you a sneak peek interview with PCI…

Coffee with the Council Podcast: Meet This Year’s North America Community Meeting Keynote Speaker, Reed Timmer

  This episode of Coffee with the Council is brought to you by our podcast sponsor, Feroot. Welcome to our podcast series, Coffee with the Council. I’m Alicia Malone, Director of Communications and Public Relations for the PCI Security Standards Council. Today, I am so excited to bring you a sneak peek interview with PCI…

DHS Warns Pro-Iranian Hackers Likely to Target U.S. Networks After Iranian Nuclear Strikes

The United States government has warned of cyber attacks mounted by pro-Iranian groups after it launched airstrikes on Iranian nuclear sites as part of the Iran–Israel war that commenced on June 13, 2025. Stating that the ongoing conflict has created a “heightened threat environment” in the country, the Department of Homeland Security (DHS) said in…

U.S. Offers $10M bounty for info on RedLine malware creator and state hackers

The U.S. offers up to $10M for info on state hackers linked to RedLine malware and its creator, Maxim Rudometov, tied to attacks on U.S. infrastructure. The U.S. Department of State offers a reward of up to $10 million for information nation-state actors linked to the RedLine infostealer and its alleged author, Russian national Maxim…

North America takes the bulk of AI VC investments, despite tough political environment

Despite what some experts have characterized as an environment increasingly hostile to AI R&D, North America continues to receive the bulk of AI venture dollars, according to data from investment tracker PitchBook. Between February and May of this year, VCs poured $69.7 billion into North America-based AI and machine learning startups across 1,528 deals. That’s…

North America takes the bulk of AI VC investments, despite tough political environment

Despite what some experts have characterized as an environment increasingly hostile to AI R&D, North America continues to receive the bulk of AI venture dollars, according to data from investment tracker PitchBook. Between February and May of this year, VCs poured $69.7 billion into North America-based AI and machine learning startups across 1,528 deals. That’s…

North America takes the bulk of AI VC investments, despite tough political environment

Despite what some experts have characterized as an environment increasingly hostile to AI R&D, North America continues to receive the bulk of AI venture dollars, according to data from investment tracker PitchBook. Between February and May of this year, VCs poured $69.7 billion into North America-based AI and machine learning startups across 1,528 deals. That’s…

Experts endorse Sean Cairncross for national cyber director ahead of Senate hearing

President Donald Trump’s pick to serve as national cyber director was endorsed by a collection of cyber experts days before a Senate panel will consider his nomination. The 24 people who signed the letter endorsing Sean Cairncross include former government officials and current industry leaders, many who served in Republican-led administrations but some who also served…

Experts endorse Sean Cairncross for national cyber director ahead of Senate hearing

President Donald Trump’s pick to serve as national cyber director was endorsed by a collection of cyber experts days before a Senate panel will consider his nomination. The 24 people who signed the letter endorsing Sean Cairncross include former government officials and current industry leaders, many who served in Republican-led administrations but some who also served…

Experts endorse Sean Cairncross for national cyber director ahead of Senate hearing

President Donald Trump’s pick to serve as national cyber director was endorsed by a collection of cyber experts days before a Senate panel will consider his nomination. The 24 people who signed the letter endorsing Sean Cairncross include former government officials and current industry leaders, many who served in Republican-led administrations but some who also served…

YARA 4.5.3 Release, (Sun, Jun 1st)

YARA 4.5.3 was released with 5 bugfixes. I want to take this as an opportunity to remind you that YARA is to be replaced with YARA-X, a rewrite in Rust. YARA-X is already powering VirusTotal. Didier Stevens Senior handler blog.DidierStevens.com (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.