Geek-Guy.com

How to use GitHub safely

GitHub is rapidly becoming the go-to platform for sharing software. Originally built for developers to collaborate on code, it now hosts millions of projects ranging from hobby scripts to widely used applications. That popularity, however, has also made it an attractive delivery platform for cybercriminals. For most home users, GitHub is not something you need…

Claude can now sign into websites with 1Password without exposing your credentials

1Password has introduced 1Password for Claude, a beta integration that lets Anthropic’s AI assistant complete browser tasks requiring authentication without accessing users’ passwords or other secrets. The integration is available to paid Claude subscribers (Pro, Max, Team, and Enterprise) using Claude Desktop on macOS and to 1Password customers on individual, family, and business plans. It…

New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT

Russian-speaking UAT-11795 spreads trojanized Zoom, Webex, and MobaXterm installers to deliver Starland RAT and the WLDR memory-only implant. Cisco Talos researchers published a detailed technical report on July 16 disclosing UAT-11795, a financially motivated, Russian-speaking threat actor that has been running a malware campaign against users in the United States and Europe since at least…

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering. Russian cybersecurity company Kaspersky, which uncovered the activity in February 2026, said it was aimed at government and diplomatic…

U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities (KEV) catalog. The flaws added to the catalog are: CVE-2023-4346 KNX Association KNX Protocol…

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026. The vulnerability in question is CVE-2026-58644 (CVSS score: 9.8), a critical deserialization

New infosec products of the week: July 17, 2026

Here’s a look at the most interesting products from the past week, featuring releases from Cloudflare, Lineation.ai, Nudge Security, and Polygraf AI. Polygraf AI Meeting Guard delivers real-time deepfake detection for enterprise meetings Polygraf AI has announced Meeting Guard, a real-time AI fraud detection solution for enterprise meetings built to detect fraud and protect meeting…

Zoom Patches Critical Account Takeover Vulnerability for Windows 

A critical vulnerability in Zoom’s Windows software could allow an unauthenticated attacker to hijack user accounts over the network.  The latest security release also addresses several high-severity vulnerabilities affecting privilege management and privilege escalation.  “Vulnerability notices create a race between an organization’s endpoint strategy and hackers for control of these attractive high-value targets,” said Romanus…

OAuth Client ID Spoofing Enables Stealthy Cloud Account Enumeration 

Microsoft Entra ID sign-in logs have provided defenders with critical visibility into authentication activity, helping security teams investigate user enumeration, password spraying, and other identity-based attacks.  However, research from Proofpoint shows threat actors are increasingly using a technique called OAuth client ID spoofing to evade common detection methods while identifying valid user accounts and credentials.…

Optro Partner Connect Launches for Global GRC Partners

Optro, an AI-powered governance, risk, and compliance (GRC) intelligence platform, has officially launched its new global partner program: Optro Partner Connect. The program offers partners flexible go-to-market (GTM) opportunities and a comprehensive suite of enablement, certification, technical, and co-marketing support. It also offers a path to expand into new markets, deepen service offerings, and drive…

Optimize365 Joins the Microsoft Marketplace to Help MSPs

Optimize365, an AI-powered multi-tenant M365 security management platform built for managed service providers (MSPs), is now available on the Microsoft Marketplace. Optimize365 will be discoverable and purchasable directly through Microsoft’s partner ecosystem, with co-sell eligibility that lets MSPs and their Microsoft representatives align on joint opportunities. Microsoft Marketplace: Simplifying the purchasing process Channel Insider sat…

Begun, the Patch Wars have

Welcome to this week’s edition of the Threat Source newsletter.  We all knew, to some degree or another, that this summer was going to a hot mess. I don’t mean FIFA drama or record setting heat waves. I mean the slow but steady momentum that AI frontier models were accruing for vulnerability research. If you…

Is Apple bringing chip manufacturing home?

Apple’s recently announced $30 billion multi-year agreement with Broadcom is significant because it means billions of chips for Apple devices will be made in the US, supporting hundreds of jobs.  This is Apple’s biggest US procurement deal so far, but it won’t be the last; when it announced the arrangement, Apple confirmed it is, “working with the administration…

Zoom patches account takeover hole

Zoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.” The issue is especially significant given Zoom’s extensive reach; it reportedly has more than 300 million daily active users, including 470,000 paying business customers. Given that reach, Zoom has been impacted by many…

Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime

Three Russian nationals and a pair of bulletproof hosting providers directly supported a series of attacks on critical infrastructure in 21 states and several countries, according to a 2024 indictment unsealed in federal court Tuesday.  Officials, who have been investigating the trio and their companies since 2019, said the attacks resulted in losses surpassing $62…

Zoom patches account takeover hole

Zoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.” The issue is especially significant given Zoom’s extensive reach; it reportedly has more than 300 million daily active users, including 470,000 paying business customers. Given that reach, Zoom has been impacted by many…

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments. Key Takeaways CISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS…