Geek-Guy.com

20 open-source cybersecurity tools to keep your team ready for anything

AI is changing how security teams find vulnerabilities, analyze code, test applications, and protect infrastructure. Developers are building tools to secure AI systems themselves, from coding agents and memory protection to model exposure discovery. This roundup covers recent open-source releases for vulnerability research, application security testing, container security, endpoint protection, AI security, and penetration testing.…

Modern Digital Security Practices Using Octo Browser

In this post, I will discuss the modern digital security practices using Octo Browser. Online security is no longer just about strong passwords and antivirus software. Today, websites and apps “recognize” you using many subtle signals—device behavior, browser characteristics, network patterns, and even timing patterns. If you understand how these signals work, you can protect…

Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets

Attackers are exploiting a critical Gitea flaw (CVE-2026-20896) that bypasses authentication with a single HTTP header, exposing repositories and sensitive data. Sysdig researchers warn that attackers are actively exploiting a critical authentication bypass flaw, tracked as CVE-2026-20896 (CVSS score of 9.8), which affects Gitea official Docker images before version 1.26.3. “CVE-2026-20896 exploited 13 days after…

Spanish Police Arrest Man Linked to CARR, Z-Pentest, and NoName057(16)

Spain arrested a suspected CARR and Z-Pentest collaborator in an FBI-led probe for aiding pro-Russian hackers, coordinating attacks, and using crypto. Spanish National Police arrested a man in Palencia last March on charges of membership in and collaboration with a terrorist organization, glorifying terrorism, and computer damage. The investigation, carried out jointly with the FBI,…

Enforce zero data retention on Amazon Bedrock with Bedrock Projects and service control policies

With the introduction of models that require data sharing with third-party providers—such as Claude Fable 5—organizations need a way to centrally enforce data retention policies. Amazon Bedrock gives you control over whether your prompts and model outputs are retained after an inference request completes. You might need a way to enforce your retention settings across…

Barracuda Acquires IAM Provider Evo Security

Cyber resilience platform, Barracuda, has announced the acquisition of Evo Security, an identity and access management (IAM) provider for MSPs. The move is set to expand the organization’s BarracudaONE platform, which provides cyber resilience across email, data, applications, networks, and managed XDR in an open ecosystem. BarracudaONE expands across PAM, identity, and security response By…

BeyondTrust Patches Authentication Bypass Vulnerabilities 

BeyondTrust is urging self-hosted customers to patch multiple vulnerabilities affecting its Remote Support (RS) and Privileged Remote Access (PRA) platforms.  Two of the vulnerabilities are critical authentication bypass flaws that could allow unauthorized users to gain access to vulnerable systems under specific configurations.  Key Takeaways of the BeyondTrust Vulnerabilities BeyondTrust patched four vulnerabilities affecting RS…

Barracuda adds PAM and identity protection with Evo Security acquisition

Barracuda Networks has acquired Evo Security. The acquisition expands the BarracudaONE platform’s identity security capabilities by adding privileged access management (PAM), access control, identity protection, and identity threat detection and response. By combining Evo Security’s identity solutions with Barracuda’s existing identity-driven controls, BarracudaONE delivers a unified, end-to-end identity security architecture through a single platform, precisely…

Fake Netflix, Coca-Cola, and FIFA job scams target marketers

Attackers are impersonating major companies and recruiters to target marketing professionals, using trusted services and browser tricks to make the scam look legitimate. A BleepingComputer article detailing the campaign found at least 34 domains impersonating high-value companies, including Netflix, Coca-Cola, Adidas, and FIFA. The lure is a fake job interview or scheduling request from a…

CyberProof Agentic MXDR Service brings AI agents to managed detection and response

CyberProof has announced the launch of the CyberProof Agentic MXDR Service which connects AI agents with human expertise and presents quantifiable security outcomes with CyberProof’s Reveal360. CyberProof modernizes managed detection and response by shifting security operations from manual workflows to a human-governed system of expert AI agents. The service streamlines the typically siloed functions of…

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants

Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intelligence (AI) platform, that could result in cross-tenant compromise. The one-click vulnerability has been codenamed WriteOut by the Sand Security Research team. “An outsider could go from having no access to taking over any Writer AI