Geek Guy

Category: Global Security News

“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI

Actor usage of AI is exploding. By analyzing artifacts left behind, Talos has created a detailed analysis of how we are seeing adversaries leverage the technology to include development, force multiplication, and vulnerability research. Based on the evidence Talos gathered, guardrails did not provide much protection, with most actors able to convince the models to…

How companies could share cyber risks without exposing their secrets

Zero-knowledge proofs could let infrastructure operators answer key security questions without handing over the sensitive data behind their answers. Imagine a major software flaw is discovered in equipment used across pipelines, power plants and telecom networks. The government needs to know as fast as possible which companies are exposed. But answering that question may require…

Joinable Labs unveils Joinable Security for threat intelligence and AI-driven response

Joinable Labs launched Joinable Security, the first domain on the Joinable platform, with two products: Joinable Threat Map, a free utility that lets the security community map, analyze, and share evolving adversary behavior, and Joinable Runbooks, an enterprise platform that turns an organization’s security response documentation into governed knowledge and the agents that act on…

Securonix enhances Unified Defense SIEM with AI agent detection and lower data costs

Securonix has announced expanded cybersecurity cost reduction, expanded Threat Analytics for Microsoft Sentinel, and new Governed AI Agent Detection and Response capabilities. The additions extend the Securonix Unified Defense SIEM platform to help enterprises and managed security providers control data costs, improve detection coverage and response, and govern risks created by enterprise AI adoption. Security…

Legit Security VibeGuard 2.0 brings endpoint security and real-time guardrails to AI coding agents

Legit Security has unveiled VibeGuard 2.0, bringing a new endpoint security capability that seamlessly discovers and integrates with coding agents, secures them and delivers a frictionless developer experience. Launched in Q4 2025, Legit VibeGuard was the solution designed to secure AI-generated code at the moment of creation and place guardrails on coding agents. This latest…

Tanium expands autonomous security across AI, exposure management and SecOps

Tanium has announced a series of new autonomous security capabilities across the Tanium Autonomous IT Platform. Spanning agentic AI, exposure management and security operations, the capabilities empower IT and security operators to stay ahead of an AI-accelerated threat landscape, safely, without losing control. “Tanium is the platform that governs and manages them with Tanium Atlas…

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims’ browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. “The first stage drops a steganographic PNG image into the browser’s cache, retrieves its hidden content, and executes…

Major Cyber Attacks in July 2026: US and EU Organizations Hit by Phishing, RATs, and Stealers

July 2026 showed how trusted business workflows can quickly turn into account takeover, data exposure, fraud, and persistent access. ANY.RUN observed attacks that put cloud accounts, financial processes, sensitive data, and business continuity at risk across the US, Europe, and Brazil. Here are the major attacks from July, the business risks they exposed, and the…

Attackers are crafting malicious AI instruction files to turn your agentic workflows into quiet criminal helpers

AI agents are increasingly being deployed across the enterprise, a rapid adoption that has significantly broadened the organization’s attack surface, turning sharable AI agent resources and configuration files into backdoors, security experts warn. AI-assisted software developers have been increasingly targeted through malicious IDE extensions, rogue MCP servers, and poisoned AI skills, all of which provide…

31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register

Cyberattack exposed data of 31,000 people in Liechtenstein’s beneficial ownership register for companies and foundations. A cyberattack compromised data belonging to about 31,000 people in Liechtenstein’s register of beneficial owners linked to companies, foundations, and trusts. Liechtenstein’s Register of People Behind Companies and Foundations is a government-maintained register of beneficial ownership. Its purpose is to…

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows

Why Campaign-Level Phishing Defense Is the Future of Email Security

Artificial intelligence has fundamentally changed the economics of phishing. Threat actors can now generate convincing emails, rapidly create thousands of unique message variants, rotate infrastructure, and continuously adapt campaigns to evade traditional detection. Instead of sending one malicious email to thousands of recipients, attackers launch coordinated campaigns made up of countless variations that all serve…

Cybersecurity jobs available right now: August 4, 2026

Application Security Engineer Arcadia | USA | Remote – View job details As an Application Security Engineer, you will lead the application vulnerability management process by prioritizing and driving remediation of security findings. You will integrate and automate security tools within CI/CD pipelines, establish a Security Champions program to promote secure development practices, support application…

AI Agent Harnesses Can Change Red Teaming Results 

When organizations evaluate AI agents, they typically compare large language models (LLMs).  However, new research from Lasso suggests another component deserves equal attention: the agent harness. In their study comparing Anthropic’s Claude Agent SDK with the open-source deepagents framework built on LangGraph, researchers held the model, prompt, tools, and attack targets constant while changing only…

BSides 2026: How AI Agents Really Perform in Offensive Security 

The cybersecurity capabilities of large language models (LLMs) are often summarized by a single benchmark score.  However, new research presented at the BSides 2026 conference suggests those scores reveal little about how AI agents actually behave during offensive security tasks.  Rather than focusing solely on benchmark solve rates, researcher Tarun Koyalwar analyzed the decision-making processes…

Coldcard RNG Flaw Linked to Suspected $88.6M Bitcoin Theft

A random number generation flaw in Coldcard firmware may have left thousands of Bitcoin addresses with substantially weakened seeds. Researchers have linked the bug to suspected thefts totaling $88.6 million across 4,585 blockchain addresses, although the connection has not been computationally confirmed for every wallet. The affected firmware generated seeds with reduced entropy, potentially allowing…

Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass

Multiple vulnerabilities have been discovered in SolarWinds Web Help Desk, the most severe of which could allow for authentication bypass. SolarWinds Web Help Desk software grants access to SolarWinds IT support, asset management, and knowledge base operations. A vulnerability in the Web Help Desk could allow an unauthenticated, remote attacker to bypass authentication and gain…

N-able N-central Vulnerability Under Active Exploitation 

A vulnerability in N-able’s N-central remote monitoring and management (RMM) platform is being actively exploited.  The flaw can give attackers unauthenticated administrative access to the N-central console, allowing them to control every endpoint managed through the platform.  “Exploitation is active in the wild; a compromised N-central server can be used to run scripts, push tools,…

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim’s screen. Unit 42 detailed three attack paths against Chrome’s Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest…

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its…

Amazon Links Four npm Supply-Chain Attacks to North Korea’s Sapphire Sleet

A trusted software update can become a malware delivery system when attackers gain control of the account publishing it. Amazon Threat Intelligence has linked four npm supply-chain attacks conducted between March 2025 and March 2026 to Sapphire Sleet, a threat actor associated with North Korea. Based on command-and-control indicators and shared tactics, Amazon assessed the…