Geek Guy

Category: Global Security News

22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)

[This is a Guest Diary by Daryl Jiminez, an ISC intern as part of the SANS.edu BACS program] Introduction On May 23, 2026, a threat actor successfully authenticated to my Cowrie SSH honeypot using compromised credentials and, within 22 seconds, injected a backdoor SSH key, changed the root password, attempted to clear host-based access restrictions,…

Security validation should begin where attackers begin

Modern attacks increasingly begin with the web application. Customer portals, partner platforms, APIs, external business applications, and AI-powered services have become the front door to the enterprise. The systems organizations build to create value are now the same systems attackers target for initial access. For years, security teams have invested heavily in protecting networks, endpoints,…

UK AI tests found 19 unauthorized agent actions involving Anthropic and OpenAI models

AI agents crossed the line during cyber evaluation. The U.K.’s AI Security Institute (AISI) said it uncovered 19 instances of unsanctioned behavior by AI agents during a cybersecurity evaluation conducted between July 25 and July 28, raising fresh questions about how advanced AI systems behave when given broad autonomy. According to AISI, the incidents occurred…

Microsoft Bug Bounty Payouts Reach $20 Million as Researcher Participation Surges

Microsoft distributed over $20 million across 2,531 eligible reports to 562 security researchers in 64 countries between July 1, 2025, and June 30, 2026. That surpassed the previous year’s $17 million payout to 344 researchers, according to Microsoft. The surge was fueled by an expansion of eligible targets, including open-source dependencies and third-party code, including…

Why security validation must follow the attack path

For years organizations have strengthened their security posture by investing in specialized tools for applications, identities, endpoints, networks, and cloud infrastructure. Those investments remain essential, but the way attackers operate has changed dramatically. Today’s adversaries move laterally, chaining together weaknesses across multiple technologies until they reach their ultimate target. AI is accelerating the pace of…

OpenAI and Anthropic Agents Took 19 Unauthorised Actions During UK Cyber Tests

AI agents from OpenAI and Anthropic took 19 unauthorised actions during UK government cybersecurity tests, including creating fake identities and targeting real developers. The UK AI Security Institute, or AISI, recorded the actions across 10 of 122 evaluation runs involving agents powered by Anthropic’s Mythos 5 and OpenAI’s GPT-5.6-Sol. No real-world harm was identified but…

Lexful Launches AI Documentation Platform for MSPs

Lexful has announced the general availability of its AI-native IT documentation platform, giving managed service providers a new system for organizing operational knowledge and supplying AI tools with more reliable business context. The platform, which officially became generally available on August 3, is designed to automatically capture, structure, and maintain MSP documentation. Lexful positions the…

AI Attacks Are Evolving: TryHackMe Demo Explores Prompt Injection 

Artificial intelligence (AI) is transforming enterprise security, but it is also creating new opportunities for attackers.  From prompt injection and data poisoning to model abuse and AI-assisted phishing, organizations are facing an expanding attack surface that traditional security controls were never designed to address. To help security professionals better understand these risks, Max Robertson, Senior…

Cloudflare Gives AI Agents Wallets to Pay for APIs and Online Content

Cloudflare is giving AI agents persistent identities and programmable wallets that let them pay for APIs, data, and online content. The company introduced Cloudflare Wallets and cloudflare.pay, two services designed to help businesses identify the owners behind AI agents while enabling controlled stablecoin payments. cloudflare.pay serves as the payment layer, allowing AI agents to discover…

Google Anchors $200 Billion AI Financing Push for Anthropic’s TPU Buildout

Google isn’t just selling AI chips anymore; it is helping finance the entire ecosystem that runs them. Google sits at the center of roughly $200 billion in financing arrangements supporting Anthropic’s infrastructure expansion, according to the Financial Times. The network reportedly involves more than $150 billion in Google Tensor Processing Units, along with private-credit firms,…

AWS partners with Anthropic and OpenAI to bring AWS Continuum into developer workflows

Customers have access to models that are continuously getting better with each new generation bringing larger context windows, stronger reasoning, and lower token costs. Getting the strongest AI-powered security will come from tools that combine the most relevant models with deep knowledge of a customer’s specific environment. AWS Continuum for code vulnerabilities (Preview) is built…

GTIA Expands Local Chapters, Giving and AI for Good Work

The Global Technology Industry Association is expanding its efforts to connect channel professionals locally while giving members a larger role in charitable initiatives and responsible artificial intelligence development. The programs, outlined during GTIA’s ChannelCon 2026 conference in San Diego, are part of the association’s broader strategy to combine member services with initiatives designed to benefit…

Oracle SQL Injection Attack Enables Remote Code Execution 

Despite decades of awareness, SQL injection (SQLi) remains an effective technique for cybercriminals.  A recent Huntress investigation demonstrates how a seemingly routine SQL injection attack evolved into full operating system (OS) compromise through the abuse of Oracle database functionality.  Key takeaways of the SQL injection attack A SQL injection vulnerability in a public-facing Java/Tomcat application…

AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems

AISI found AI agents taking unsanctioned online actions, including social engineering and code attacks, during controlled cyber tests. The UK’s AI Security Institute (AISI) has put something uncomfortable on the table: during cyber testing, frontier models didn’t just follow instructions badly. In some runs, they crossed into real-world actions, touched real people and organisations, and…

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a…

From 2 weeks to 2 minutes: Amazon Cognito launches Provisioned limits for self-service rate limit management

Imagine preparing for your biggest sales event of the year, and you want to ensure your customer identity management service can handle the elevated traffic for carrying out application activities. For security teams, business leaders, and technologists managing identity infrastructure at scale, this scenario has been all too familiar. Whether you’re a CISO evaluating security…

Trustifi Expands Microsoft 365 Security for MSPs

Trustifi is expanding beyond email security with a new platform designed to help managed service providers detect threats, enforce data-loss prevention policies and investigate incidents across Microsoft Teams, OneDrive and SharePoint. The company’s new Collaboration Shield platform applies Trustifi’s security and compliance capabilities to Microsoft 365 collaboration workloads, where employees increasingly exchange sensitive files and…

Cynomi and SPECTRA Partner to Help MSPs Prove Security Value

Cynomi has announced a strategic partnership with SPECTRA, the MSP certification and cyber resilience warranty platform.  The partnership gives Cynomi partners a direct, in-platform path to SPECTRA Certification, allowing them to validate the security services they deliver, offer warranty-backed protection to clients, and potentially reduce cyber insurance costs for both MSPs and their customers. Demonstrating…

Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals

Brown Health Medical Group-MA breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. Brown Health Medical Group-MA data breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. The healthcare group identified a data security breach involving a legacy file server on…

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access to Anthropic’s large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. “Advertisements for Poison Claude

U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-9198 (CVSS score of 9.8) IBM Langflow Code Injection Vulnerability CVE-2026-18556 (CVSS score of 8.2) N-able N-central Authentication…

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam’s console that hands over a managed agent’s credentials, rated 9.5 A cross-tenant flaw in HashiCorp’s MCP server that lets one user’s Terraform token be reused…

Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses

Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm package “bianira-ui” and “fluid-type-ui,” has been codenamed NullReceiver by

Tenable broadens AI visibility across major LLMs and AI tools

Tenable has announced enhanced AI security capabilities within the Tenable One Exposure Management Platform. Tenable One AI Exposure now delivers expanded platform coverage with support for Google Gemini, extending its coverage across major LLMs: Google Gemini, Anthropic Claude, OpenAI ChatGPT Enterprise and Microsoft Copilot. The release also extends discovery to all major Model Context Protocol…