Geek-Guy.com

Micropatches released for Desktop Window Manager Elevation of Privilege Vulnerability (CVE-2026-20871)

January 2026 Windows Updates brought a patch for CVE-2026-20871, a local privilege escalation vulnerability in Desktop Window Manager, allowing a local unprivileged attacker to execute arbitrary code as System. The vulnerability was anonymously reported to Microsoft through Trend Zero Day Initiative, but the official patch was reverse engineered and turned into a proof-of-concept by Joe…

Best Performing Models for OpenClaw, (Claudebot, Moltbot) & Hermes Agent

Editors Choice (Local): Qwen3_5-9B-DeepSeek-V4-Flash-Q4_K_M Model Name Developer Context Window Hardware Requirements Primary Use Case Estimated Monthly Cost Performance Rating (Inferred) Claude Opus 4.5 Anthropic Long-context (standard benchmark) Cloud-based / Managed Agentic reasoning, complex planning, high-stakes coding, proactive assistant $180 – $750 Benchmark / SOTA Reasoning GPT-5.2 (Codex) OpenAI 400,000 Cloud-based / Managed High-stakes software architecture,…

Top 10 Hall Effect Keyboards of 2026: Comprehensive Review & Buying Guide

Top 10 Hall Effect Keyboards of 2026: Comprehensive Review & Buying Guide

Report Date: July 12, 2026  Data Validated: All prices, specs, reviews, and availability confirmed as current 2026 Executive Summary Hall Effect magnetic switch keyboards have revolutionized the gaming and productivity peripheral market in 2026. These keyboards feature magnetic sensors that detect actuation at any point between 0.1mm and 3.8mm, enabling Rapid Trigger technology that eliminates the…

Progress Told ShareFile Customers to Pull the Plug on Their Servers. Here’s What We Know.

Progress urged ShareFile Storage Zone customers to shut down internet-facing servers immediately over a credible security threat under investigation. Progress Software sent an urgent email to ShareFile customers the evening of July 10 with a subject line that left no room for ambiguity: “Service Disruption. Immediate Action Required.” The company told customers running Storage Zone…

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 105

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux   Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom Capabilities Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign   RedWing: A…

Company That Bragged It Could Track U.S. Spies Hired to Investigate “Havana Syndrome”

The U.S. military inquiry into the so-called Havana syndrome, the mysterious illness claimed by a litany of American intelligence officers, is tapping a controversial contractor: a private surveillance firm that once boasted of its ability to stalk American intelligence officers. Documents obtained by The Intercept through a Freedom of Information Act request reveal that technology…

U.S. CISA adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities (KEV) catalog. The flaws added to the catalog are: CVE-2026-48939 (CVSS score of 10.0) iCagenda Unrestricted Upload of File…

Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns

Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between February 2024 and April 2026. “At Balochistan Police, the compromised assets included servers hosting web applications that manage police and citizen data, such as criminal and

‘Rotten to its core’ — Apple files an explosive lawsuit against OpenAI

Apple surprised the tech industry after financial markets closed Friday with news the company has sued OpenAI, alleging theft of trade secrets for ChatGPT hardware. The lawsuit particularly targets some senior ex-Apple employees now working at OpenAI. Apple’s suit names two former employees — Chang Liu and Tang Tan, former vice president for product design, iPhone and…

Apple is prepping for life after the AI gold rush

Consumer electronics prices are shooting up. Energy prices are increasing fast. Even water bills are climbing. For a technology that promises “efficiency,” the ongoing AI gold rush seems to be taking things away, much like the proverbial gift that keeps on grabbing. With hundreds of billions in AI investment already racked up for 2026, it’s important to remember the entire…

WP-SHELLSTORM Exposed: Hackers Backdoored Thousands of WordPress Websites 

A simple operational mistake by a cybercrime group has provided researchers with an inside look at how large-scale website compromises are conducted. According to research from SOCRadar, an internet-exposed server belonging to a threat group tracked as WP-SHELLSTORM remained publicly accessible for approximately three weeks.  “WP-SHELLSTORM is industrialized cybercrime made visible because someone left a…

Structured Expands AI Partner Marketing Platform

Structured has expanded its AI-native partner marketing platform with nearly 60 new capabilities spanning AI-powered analytics, campaign automation, enterprise integrations, and pipeline reporting, marking its first major product update roughly 100 days after the platform’s launch. The updates introduce AI agents that answer campaign performance questions in natural language, deeper integrations with Salesforce and Adobe…

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Unknown threat actors compromised the Injective Labs SDK project’s GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was

URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a “credible external security threat.” The company has temporarily disabled access to the affected accounts, a step it says it took “out of an abundance of caution” while…