Geek Guy

DXC Becomes Exclusive Managed Services Provider for Primary’s AI Security Platform

On Aug. 6, DXC announced a strategic partnership with security startup Primary, becoming the exclusive managed services provider for Primary’s AI-native Zero Trust Platform. The joint offering is designed to help enterprises and government agencies govern how AI agents and enterprise AI applications access data, identities, and business systems. The companies are targeting organizations that…

Hackers Target Blackstone, CME and Other Wall Street Firms in Phone-Based Scam

A phone-first data-theft extortion campaign has targeted dozens of major US financial firms over the past month. Ransom-seeking hackers have targeted dozens of major US financial institutions and other businesses in a campaign that relies heavily on phone-based social engineering, according to data from Google and internet intelligence platforms reviewed by Reuters. The targets included…

Cato Networks Adds Agentic AI Threat Prevention

Cato Networks, a converged network and security cloud, has launched Cato Agentic Threat Prevention, a new capability to deploy autonomous agents to predict likely attack paths. Stopping frontier AI adversaries before they advance Introduced at Black Hat USA 2026, the capability also automatically personalizes protections for each customer environment to prevent breaches before AI-assisted attacks…

8×8 Launches Four-Tier Partner Program for Resellers

8×8, Inc., a business communication platform provider, is introducing a new partner program for its direct resell channel that rewards customer retention and expansion. Four-tier structure to align partner and company success The 8×8 partner program features a four-tier structure: Authorized, Silver, Gold, and Platinum. With this structure, direct resellers can earn financial rewards according…

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that’s compatible with the computer’s CPU…

Proofpoint Launches OEM Program for Security Providers

Proofpoint Inc. debuted a new program at Black Hat USA 2026 that makes a portfolio of OEM-ready threat intelligence and detection capabilities available for technology providers, cybersecurity vendors, managed services providers, and platform companies. Accelerating OEM innovation with trusted threat intelligence The Proofpoint OEM Program formalizes and expands the cybersecurity providers’ OEM business. It provides…

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. “UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via…

ConnectWise, SentinelOne Unveil MSP Cybersecurity Strategy

ConnectWise and SentinelOne have unveiled a joint managed cybersecurity strategy aimed at helping MSPs scale threat detection and response through deeper integration of Managed EDR, AI-driven security, and automation. ConnectWise and SentinelOne deepen MSP security collaboration Announced at Black Hat USA 2026, the strategy establishes a framework for deeper collaboration that brings together the AI-driven…

Zero Networks Launches Least Agency Enforcement Capability

Zero Networks, a Zero Trust security solutions provider, announced a new capability at Black Hat USA 2026. This new capability applies the Open Worldwide Application Security Project’s (OWASP) principle of Least Agency to help organizations safely deploy AI agents. Reducing the impact of compromised AI agents The Least Agency Enforcement capability uses identity-based microsegmentation, policy…

Securing your Amazon S3 buckets: Identifying and remediating over-permissioned access

Misconfigured Amazon Simple Storage Service (Amazon S3) buckets can expose your data to unauthorized access. Without proactive review, S3 bucket policies or Access Control Lists (ACLs) configured with broad access may go unnoticed in your environment. In this post, you learn how to identify and fix over-permissioned S3 buckets across your AWS environment, along with…

State Department Wants Palantir’s Advice on Free Speech and “Countering Digital Surveillance”

The Trump administration tapped a surveillance giant with a record of attacking the press to advise the State Department on free speech. Among the partners for the State Department’s new “Freedom Tech Excellence Program” is Palantir, the AI and data integration firm started by right-wing powerbroker Peter Thiel. Under the program, company employees will go…

Hackers Impersonate IT Support to Breach Leading Financial Companies

Hackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies. A hacking campaign operating under names including Redact, Pink, Falcon, and Helix has built credential-stealing websites targeting employees at Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s, among dozens…

Hugging Face Breach: OpenAI Agent Abused Exposed Credentials Across Four Services

An autonomous AI agent powered by a combination of OpenAI models escaped an isolated cyber-capability evaluation environment, reached the public internet, and conducted a multi-stage intrusion into Hugging Face’s systems. The models included GPT-5.6 Sol and a more capable internal research prototype operating with reduced cyber refusals and without the production safeguards normally used to…

AI Agents, Supply Chain Attacks, and Critical Flaws Define the Week in August 2026

This week’s cybersecurity landscape was shaped by rapidly expanding AI risks, attacks on trusted developer workflows, actively exploited enterprise software, and costly data breaches. Research into rogue agents, prompt injection, passkeys, and offensive AI showed why governance must keep pace with deployment, while incidents involving npm, hotel networks, remote monitoring tools, and sensitive public-sector data…

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,

200 accounts compromised in Swiss government’s Microsoft SharePoint breach

Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), compromising the login credentials of around 200 accounts. On July 28, BIT’s security specialists noticed unusual activity on the SharePoint servers. Once the intrusion was confirmed, BIT blocked internet access to the platform and closed the…

Growing Up The Hard Way

Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up — take what you need, pay me back…

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Cybersecurity researchers have called attention to an active “widespread email-driven phishing campaign” that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. “The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors. PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where scanning

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and

Python package security in 2026: How supply chain attacks are targeting your AI development environment

On March 24, 2026, developers building AI applications with LiteLLM — a Python package with 95 million monthly downloads — unknowingly installed malicious code. A threat actor group known as TeamPCP had compromised the PyPI distribution pipeline and pushed malicious versions 1.82.7 and 1.82.8 to the package index. The payload was subtle: a .pth file,…

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, Stagg said the techniques were demonstrated across network infrastructure devices

Human oversight is still critical as AI patching tools miss security risks

AI-generated vulnerability patches still heavily depend on human review, particularly the ones involving security-sensitive code, according to a research. Researchers from 1Password have disclosed an internal evaluation that found AI-generated fixes frequently overlook broader concerns such as architectural intent, business requirements, security implications, and long-term maintainability, despite being syntactically correct. “We studied what happens when…