Geek-Guy.com

Tag: NEWS

Week in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flaw

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Coinflow CISO on crypto payments security under AI pressure Crypto payment firms sit near the top of the target list for advanced persistent threat groups, and the workload on their security leaders keeps growing. Malcolm Portelli, CISO at Coinflow, runs…

Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension Following TeamPCP’s claim that they’ve breached GitHub’s own private code repositories, the Microsoft-owned company launched an investigation and confirmed the compromise. Earbud sensors can authenticate users by their heartbeat, study…

Week in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploited

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Review: Foundations of Cybersecurity, 2nd edition Jason Andress has refreshed his introductory security text for No Starch Press. He writes in the introduction that the term security now extends past data center servers to cloud resources, mobile devices, the Internet…

Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scams

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Your work apps are quietly handing 19 data points to someone Office work in 2026 relies on mobile apps used alongside personal tools like banking and messaging. Ten widely used workplace apps, including Gmail, Microsoft Teams, Zoom, Slack, and Notion,…

Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: SmokedMeat: Open-source tool shows what attackers do inside CI/CD pipelines Boost Security has released SmokedMeat, an open-source framework that runs attack chains against CI/CD infrastructure so engineering and security teams can see what an attacker would do in their specific…

Entrust Integrates Australia’s Document Verification Service (DVS) to Support AML/CFT-Ready Identity Verification

News Summary: Under Tranche 2 reforms, Australia’s AML/CTF regime will undergo its most significant expansion in nearly two decades.  All reporting entities will need to strengthen identity verification and customer due diligence processes. Entrust Identity Verification unifies Australia DVS checks, biometrics, and AI‑driven fraud controls for all‑in‑one Australia-ready identity verification.

SAP participates in Hannover Messe 2026, showcasing agentic AI-Driven manufacturing and supply chain innovations

COMPANY NEWS: SAP announces its participation in Hannover Messe 2026, the world’s largest industrial trade fair held in Hannover, Germany, from April 20 to 24, to unveil its agentic AI-driven manufacturing and supply chain innovation solutions. Under this year’s theme, Trusted orchestration. Smarter execution, SAP will present its vision for how Business AI is fundamentally…

Klaviyo Strengthens Canva Partnership with Expanded Integration to Help Marketers Build Creative Campaigns Faster

COMPANY NEWS:  Klaviyo, the autonomous B2C CRM, and Canva today announced a deepened commitment to their partnership with an expanded integration that enables marketers to design and streamline full campaigns in Canva and reach consumers wherever they are. Marketers can seamlessly bring their Canva designs into Klaviyo to personalise, refine, and deliver customer experiences at…

Week in review: Acrobat Reader flaw exploited, Claude Mythos offensive capabilities and limits

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Bringing governance and visibility to machine and AI identities In this Help Net Security interview, Archit Lohokare, CEO of AppViewX, explains how the rise of AI marked a turning point where machine and AI agent identities began converging into a…

Ghost breaches: How AI-mediated narratives have become a new threat vector

A company wakes up to a news story claiming it has suffered a major data breach. The details are specific, technical and convincing. But the breach didn’t happen. No systems were compromised. No data was taken. A language model generated the entire story, filling in plausible details from scratch. And before the company can figure…

Week in review: Windows zero-day exploit leaked, Patch Tuesday forecast

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Cloudflare moves up its post-quantum deadline as researchers narrow the path to Q-Day Cloudflare announced it is targeting 2029 to complete post-quantum security across its entire product suite, including post-quantum authentication. The company is following a revised roadmap that Google…

Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploited

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Financial groups lay out a plan to fight AI identity attacks Generative AI tools have brought the cost of deepfake production low enough that criminals and state-sponsored actors now use them routinely against financial institutions. A joint paper from the…

SAP Concur showcases new AI, integrated travel and expense enhancements, and global partnerships at SAP Concur Fusion 2026

COMPANY NEWS: SAP Concur is accelerating the future of travel and expense management with a new wave of AI-powered innovations, expanded global partnerships, and enhanced capabilities unveiled at SAP Concur Fusion 2026. The announcements highlight SAP’s focus on automating workflows, strengthening compliance, and improving employee experiences.

Week in review: NIST updates DNS security guidance, compromised LiteLLM PyPI packages

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: NIST updates its DNS security guidance for the first time in over a decade DNS infrastructure underpins nearly every network connection an organization makes, yet security configurations for it have gone largely unrevised at the federal guidance level for more…

Adactin Launches AFIVE: An Intelligent AI Knowledge Platform Empowering Enterprises with Consistent Data, Reduced Duplication, and Accelerated Decision-Making

COMPANY NEWS:  Adactin, an Australian technology services provider with deep expertise in cloud, AI, and software engineering services, today announced the launch of AFIVE, its next-generation AI-powered knowledge platform designed to transform how organisations access, manage, and leverage information. Built to deliver instant answers and seamless knowledge retrieval, AFIVE enables enterprises to unlock greater productivity…

Week in review: ScreenConnect servers open to attack, exploited Microsoft SharePoint flaw

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What smart factories keep getting wrong about cybersecurity In this Help Net Security interview, Packsize CSO Troy Rydman breaks down the biggest vulnerabilities in smart factory environments today, from IoT devices and legacy systems to human error. He explains how…

Is MacBook Neo the Mac’s iPhone moment?

In news that will strike a chill to the heart of competing PC makers, Apple has effectively confirmed that demand for its new MacBook Neo is massively exceeding expectations. “Mac just had its best launch week ever for first-time Mac customers,” Apple CEO Tim Cook wrote on X. “We love seeing the enthusiasm!”  Apple also introduced new MacBook…

Training AI Beyond the Known: Milestone Expands Hafnia with Synthetic Data and Training-as-a-Service at NVIDIA GTC

COMPANY NEWS:  At NVIDIA GTC in San Jose, Milestone Systems will showcase major advancements to its suite of AI developer tools coming out of Hafnia. The latest expansion introduces Synthetic Data and a forthcoming Training-as-a-Service (TaaS) offering, enabling developers to train AI models not only for real-world conditions, but also for rare and previously unseen…

Telstra Health introduces Smart Connect to streamline pathology eRequesting for GPs, patients and pathology providers

COMPANY NEWS:  Telstra Health, Australia’s largest digital health technology company, has today launched Smart Connect, a new pathology eRequesting capability within MedicalDirector Clinical, designed to replace manual, paper-based pathology requests with a fully digital workflow. The feature launches with Healius Pathology Network as its first integrated partner.

Week in review: AiTM phishing kit used to hijack AWS accounts, year-long malware campaign targets HR

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Turning expertise into opportunity for women in cybersecurity Speaker diversity in cybersecurity has been a talking point for over a decade, with panels, pledges, and dedicated conference tracks failing to produce change. Stages still skew heavily male, even as women…

Saviynt Taps NEXTGEN, an Exclusive Networks Company, to Accelerate Digital Identity Security in Australia

COMPANY NEWS:    Collaboration strengthens Saviynt’s partner-first strategy as AI-driven identity risk builds across the APJ region Key Highlights: Saviynt will broaden access to AI-ready identity security for organisations navigating growing digital risks NEXTGEN will help scale Saviynt’s partner ecosystem across APJ, enabling faster adoption of identity-centric security in the AI era 

LogicMonitor expands New Zealand investment with new regional infrastructure and ecosystem growth

COMPANY NEWS: LogicMonitor®, the AI-first platform for Autonomous IT, has strengthened its commitment to New Zealand with an expanded investment program to support the country’s rapidly growing digital economy. As organisations across enterprise, government, agribusiness, telecommunications, and managed services accelerate their adoption of cloud and AI, LogicMonitor is deepening its regional presence to meet rising demand for modern, intelligent IT operations.

Week in review: Weaponized OAuth redirection logic delivers malware, Patch Tuesday forecast

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: BlacksmithAI: Open-source AI-powered penetration testing framework BlacksmithAI is an open-source penetration testing framework that uses multiple AI agents to execute different stages of a security assessment lifecycle. BlacksmithAI runs as a hierarchical system in which an orchestrator coordinates task execution…

Radware Announces Another DDoS Industry First – Encrypted Attack Blocking Without SSL Decryption

COMPANY NEWS:  Radware (NASDAQ: RDWR), a global leader in application security and delivery solutions for multi-cloud environments, today announced the availability of its Web DDoS Protection for Encrypted Traffic as a cloud-based service that does not require SSL certificate sharing or traffic decryption. With this release, Radware believes it is the only security provider to…

3 Android theft protection additions you should absolutely activate

BRRRRRRRRRREAKING NEWS, y’all: Despite what the internet’s many misleading headlines may lead you to believe, Android security (gasp!) isn’t actually all that scary. You know that by now, right? Any reasonably recent Android device has layers upon layers of built-in protection. You’ve got mountains of Android security settings standing by and waiting to protect you…

Week in review: Self-spreading npm malware hits developers, Cisco SD-WAN 0-day exploited since 2023

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Identity verification systems are struggling with synthetic fraud Fake and expired IDs keep showing up in routine customer transactions, from alcohol purchases to credit card applications. The problem shows up most often in industries that depend on fast onboarding and…

Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Security at AI speed: The new CISO reality The CISO role has changed significantly over the past decade, but according to John White, EMEA Field CISO, Torq, the most disruptive shift is accountability driven by agentic AI. In this Help…

Week in review: Exploited newly patched BeyondTrust RCE, United Airlines CISO on building resilience

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: United Airlines CISO on building resilience when disruption is inevitable In this Help Net Security interview, Deneen DeFiore, VP and CISO at United Airlines, explains how the company approaches modernization without compromising safety-critical environments, why resilience and continuity matter as…