Geek-Guy.com

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.   Talos has discovered that the actor in this campaign delivers a Python-based remote access tool (RAT) that we track as “Starland RAT” and a command-and-control (C2) memory implant known as the “WLDR agent.” …

Tenable One unifies code risks with enterprise exposure data

Tenable has announced the expansion of the Tenable One Exposure Management Platform, unifying application security risks with all other exposure data. By integrating static code vulnerability data, Tenable One delivers complete, code-to-runtime visibility across the entire attack surface. Security teams have long struggled with a code security problem where vulnerable code reaches production faster than…

Lineation.ai focuses on runtime security for autonomous AI agents

Lineation.ai has announced the public launch of its comprehensive agentic security platform. Delivering a solution at the intersection of GenAI Application Security and Runtime Defense, Lineation introduces a Zero Trust unified control plane and a lightweight endpoint daemon that secures autonomous AI agents directly at execution. As enterprises adopt autonomous AI agents that read sensitive…

Hidden Infrastructure Exposed: ANY.RUN Reveals Hijacked Gov Websites Delivering Malware 

An original threat intelligence investigation uncovering how trusted government infrastructure became an attack channel, placing banking organizations and public-sector systems at risk while revealing previously undocumented infrastructure relationships and actionable mitigation guidance for security leaders.  ANY.RUN analysts have uncovered an active PhantomEnigma campaign abusing compromised government infrastructure and fake police-themed documents to target banking and public-sector organizations in Brazil. Trusted emails and legitimate…

Microsoft makes Windows SSO prompts easier to manage

Microsoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID. Users with personal Microsoft accounts and devices outside policy-managed environments will continue to receive SSO permission prompts. Admin control for SSO prompts in Windows (Surce: Microsoft)…

OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol

OpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery with an aim to fix issues before the tools are deployed widely. “GPT‑Red is a strong red-teamer, and our previous models are highly vulnerable to its prompt injection attacks,” the artificial intelligence (AI) company said. “We use GPT‑Red…

Police dismantle investment fraud ring that stole €100 million a month

Dutch police, working alongside Belgian authorities and Europol, have dismantled a major criminal network accused of operating a global investment fraud scheme through dozens of fraudulent call centers. Investigators estimate the organization generated more than €100 million a month by targeting victims in multiple countries. The group operated around 20 call centers staffed by more…

Top 5 VMware Backup Solutions for 2026

In this post, I will show you the top 5 VMware backup solutions for 2026. Most modern data centers run on virtualised infrastructure, with VMware still the leading platform for running business-critical workloads. But virtualization without a solid backup strategy is a liability waiting to happen.  One hardware failure, ransomware attack or human error can…

The Business Impact of Tampered Telematics Data

Tampered telematics data can cause operational errors, financial losses, safety risks, compliance failures, and unreliable business decisions. One altered telematics entry can send dispatch plans off course, skew fuel and payroll figures, delay maintenance, or weaken evidence during a claim. Integrity failures can interrupt operations, cut into revenue, and damage trust when teams act on…

Flaw surge fuels need for CISOs to rethink vulnerability management

Security experts are calling on enterprises to revise their vulnerability management strategies and move towards “just in time” patching in response the increased pace of vulnerability exploitation. Attackers are turning to AI to increase the rate of vulnerability exploitation and supply chain compromise so that traditional forms of vulnerability management are no longer keeping pace.…

Finance phishing works because it sounds boringly normal

Finance departments process a constant stream of invoices, contracts, payment notices, and procurement emails, making email one of the most common initial access vectors for threat actors. According to Cofense, attackers exploit those workflows with phishing emails that resemble legitimate business correspondence rather than relying on urgency-based lures. Such phishing emails are also likely to…

Micropatches released for Remote Desktop Client Remote Code Execution Vulnerability (CVE-2026-47289)

June 2026 Windows Updates brought a patch for CVE-2026-47289, a remote code execution vulnerability in Remote Desktop Client, allowing a malicious RDP server to cause memory corruption in connecting RDP client, potentially leading to code execution. The vulnerability was found internally by Microsoft engineer Raymond Reskusich. We recreated a POC from the official patch, which…

NPM ecosystem hit with two new supply chain compromises

Attacks targeting developer ecosystems are increasing in frequency and sophistication, with Node.js developers firmly in this week’s crosshairs, as multiple npm packages belonging to the open-source AsyncAPI and Jscrambler Code Integrity were poisoned with malware following compromised development credentials. The incidents highlight the cascading effect of software supply chain attacks in which stolen credentials are…

RabbitMQ Vulnerabilities Could Enable Unauthenticated Broker Takeover 

Miggo researchers discovered two vulnerabilities that could allow attackers to seize control of vulnerable message brokers or expose data across shared environments.  While there is no evidence either vulnerability has been exploited in the wild, organizations running affected RabbitMQ versions should prioritize applying the available patches.  Key Takeaways of the RabbitMQ Vulnerabilities Two RabbitMQ vulnerabilities…

US and allied Governments’ Recommendations: Securing Network Devices Against Russian APT Groups

US and allies warn of Russian APT groups targeting routers and network devices to compromise critical infrastructure worldwide. The US and allied governments warn that Russian state-sponsored APT groups are scanning and exploiting poorly secured network devices, especially routers, to access critical infrastructure. Groups linked to FSB Center 16, including Berserk Bear, Energetic Bear, Ghost…

SonicWall customers under threat as attackers exploit 2 zero-days

SonicWall customers are attempting to dodge another security challenge as attackers are exploiting a pair of zero-day vulnerabilities that have been confirmed by the vendor.  The company publicly disclosed the vulnerabilities — CVE-2026-15409 and CVE-2026-15410 — in a security advisory Tuesday. SonicWall credited an employee with discovering the defects, but it hasn’t said when the…

TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development

Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results. “While the AI complied with their request to generate botnet code, it included a safety disclaimer that the…

Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed

Democratic senators pressed President Donald Trump’s pick for director of national intelligence on questions of election security and integrity Wednesday, but they didn’t leave his nomination hearing satisfied with the answers. As is typical for Trump administration nominees, Jay Clayton wouldn’t answer definitively at his Senate Intelligence Committee confirmation hearing whether Joe Biden won the…

CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild

SonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution. Key takeaways CVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities that may have been chained together to allow for code execution on SonicWall SMA1000 series appliances.  Zero-day exploitation…

Chaotic Eclipse Unveils LegacyHive Exploit Affecting Fully Patched Windows Systems

LegacyHive PoC exposes a Windows Privilege Escalation flaw affecting fully patched Windows desktop and server systems. Just hours after Microsoft’s July 2026 Patch Tuesday, security researcher Nightmare Eclipse, also known as Chaotic Eclipse, published a new Windows zero-day proof-of-concept called LegacyHive. This time, the target is the Windows User Profile Service (ProfSvc), and unlike the…

centrexIT Finds Common Ground with Coalition on MDR

Cyber insurers and managed service providers have long debated where insurance ends and cybersecurity services begin. As insurers expand into offerings such as managed detection and response (MDR), many MSPs have questioned whether those moves create channel conflict or create new opportunities to improve customer security. Josh Hohbein, manager of cybersecurity and automation at centrexIT,…

Apple’s OpenAI lawsuit: The lunacy of trying to limit what ex-employees can tell future employers

When Apple sued OpenAI last week, the argument it made was that former employees had stolen Apple data and then used it to benefit OpenAI.  The technical details — an employee used “a rare, previously unknown authentication bug to access Apple’s shared network folders” — are interesting. But the larger story is Apple’s ridiculous attempt…

News alert: Pulse Security launches with $8 million for AI platform to modernize CISO operations

SAN FRANCISCO, July 15, 2026, CyberNewswire – Backed by Foundation Capital and Zetta Venture Partners with $8M in seed funding, Pulse Security delivers the program intelligence and agentic infrastructure that security leaders have been missing. Pulse Security AI launched from stealth today to solve a problem the security industry has spent decades ignoring: giving the leader…

News alert: Insignary’s on-demand SBOM verification boosts software supply chain security

TORONTO, July 15, 2026, CyberNewswire – According to Insignary Inc., a leader in software supply chain security and binary software composition analysis (SCA), most organizations cannot independently verify what is actually inside the software they deploy — because traditional SCA tools read what software claims to contain, not what it actually contains. Today, the company…

Understanding Claude Tag’s access model in Slack and how to configure it securely

Anthropic’s new AI agent for Slack acts under an admin-configured access bundle rather than each user’s own credentials. Here’s how that model works, what admins should understand and how to securely configure it. Key takeaways Claude Tag, Anthropic’s newly launched AI agent for Slack, acts on connected services using shared credentials an admin configures for…

LabubaRAT malware infiltrates Windows systems while posing as NVIDIA software

LabubaRAT, a previously undocumented Rust-based remote access tool (RAT) masquerading as NVIDIA software that enables post-compromise operations on Windows systems, has been uncovered by Blackpoint Cyber. According to researchers, LabubaRAT creates “a reusable foothold for hands-on activity.” Once deployed, it can profile the host, identify installed security tools, receive operator commands, transfer files, capture screenshots,…