Geek-Guy.com

ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw

Researchers are warning that cybercriminals exploited an Oracle PeopleSoft zero-day vulnerability and potentially infiltrated the networks of more than 100 organizations in an attack spree that largely impacted higher education. Mandiant and Google Threat Intelligence Group said it became aware of the attacks earlier this month as part of its ongoing monitoring of ShinyHunters operations.…

Core Taxonomy of Artificial Intelligence

Core Taxonomy of Artificial Intelligence Machine Learning (ML): The computational foundation of modern AI, focused on developing algorithms that analyze data, detect patterns, and make decisions with minimal human intervention. Sub-branches: Supervised Learning, Unsupervised Learning, Reinforcement Learning, and Deep Learning (Deep Neural Networks). Natural Language Processing (NLP): The domain dedicated to giving machines the ability…

Zero-Days, AI Exploits, and Supply Chain Risks Define This Week in Cybersecurity in June 2026

Major Threats & Vulnerabilities Zero-Days and Exploited CVEs A newly disclosed Microsoft Defender zero-day allows SYSTEM-level access on fully patched Windows 10 and 11 devices. The flaw, caused by a race condition, remains unpatched, and administrators are urged to restrict Defender privileges and monitor for exploitation attempts. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)…

Critical Cybersecurity Updates: 2026-06-12

## Critical Cybersecurity Developments: 2026-06-12 ### Executive Summary This report synthesizes verified breaking developments from trusted industry sources. The following analysis integrates established security frameworks with current threat intelligence. — ### Threat Intelligence Analysis #### 1. Zero-Day Vulnerabilities Recent zero-day vulnerabilities have been identified in enterprise security platforms. These include: – Memory corruption in popular…

Researchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751)

WatchTowr researchers have disclosed a technical analysis and a “Detection Artefact Generator” for CVE-2026-50751, an authentication bypass flaw in Check Point’s Remote Access VPN and Mobile Access, which the vendor confirmed to be actively exploited. The attacks were limited, but with this information now public, a larger wave of opportunistic attacks may be expected. From…

AI-Powered Threat Detection: Balancing Security and Privacy

Artificial Intelligence is revolutionizing cybersecurity threat detection, but it introduces new privacy concerns. Modern AI systems can analyze network traffic patterns, identify malicious behavior, and predict attack vectors in real-time. However, the data required to train these models often includes sensitive user information, raising questions about consent, data retention, and cross-border data transfers. This article…

Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code

Cybersecurity researchers have described what they say is a new class of attack that can trick artificial intelligence (AI) coding agents into running arbitrary code on developer machines. Called Agentjacking by Tenet Security, the attack can be triggered by means of a fake error report crafted using Sentry, an open-source error-tracking and performance-monitoring platform. “The…

CyberCorps is adapting to AI. The budget isn’t keeping up.

The digital battlefield is expanding and changing faster than ever before. Washington must confront mounting threats to critical networks and systems. But there’s one challenge that stands out above the rest: artificial intelligence. The nation’s cyber experts need to be ready to face this new reality. The CyberCorps: Scholarship for Service program is a federal…

Oracle PeopleSoft RCE Flaw Used as Zero-Day in Ongoing ShinyHunters Campaign

ShinyHunters exploited a critical Oracle PeopleSoft zero-day to breach over 100 organizations, mostly universities, before a patch was available. Mandiant and Google’s Threat Intelligence Group published an analysis of an active ShinyHunters campaign on June 11, one day after Oracle finally issued an advisory for the vulnerability being exploited. The gap matters: the activity ran…

Prompt injection breaks today’s AI agents, study warns

Today’s AI web agents have no dependable defenses against prompt injection, according to new research showing that not a single attack scenario was consistently blocked across leading systems powered by GPT‑5 and Gemini. The findings come from StakeBench, a stakeholder-centric benchmark developed by researchers from Nanyang Technological University, ST Engineering, IBM Research, and the University of Illinois…

LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in remote code execution. LangGraph is an open-source framework created by LangChain to build complex, stateful, and multi-agent artificial intelligence (AI) agentic applications. “An SQL injection in LangGraph’s function could

Oracle PeopleSoft zero‑day fuels ShinyHunters extortion spree

A newly disclosed Oracle PeopleSoft zero-day became the weapon of choice in a recent ShinyHunters extortion campaign that primarily targeted universities and other educational institutes. Attackers exploited the critical remote code execution (RCE) flaw in PeopleSoft’s Environment Management component that Oracle started warning customers about on June 10, 2026. In an advisory, the company urged…

AI is exposing the biggest weakness in cybersecurity: We never built a health model. Until now!

For 30 years, cybersecurity has operated like an emergency room. Reactive. Crisis-driven. Always triaging. We are extraordinarily good at it — our detection is faster, our response playbooks are sharper, our incident teams are more capable than they have ever been. When something goes wrong, the modern security organization runs toward the fire with real…

INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator

An INTERPOL-led operation last month resulted in the disruption of Sniper Dz, a decade-long phishing-as-a-service (PhaaS) platform, Group-IB said Thursday. The effort, codenamed Operation Ramz, took place between October 2025 and February 2026, and saw authorities from 13 countries in the Middle East and North Africa (MENA) region making 201 arrests. Included among them was…

Optiv Consulting Targets Secure Agentic AI

Optiv has sold its advisory, consulting, and transformation project-based services business to Vobis Ventures, creating a newly independent Optiv Consulting business focused on helping enterprises securely adopt agentic AI at scale. The deal closed on June 1, with Optiv Consulting initially operating under its current name and serving as Optiv’s priority services partner for the…

Reinvent Launches Managed Security for MSP Partners

Reinvent Telecom has launched MyCloud Managed Security, a fully managed cybersecurity offering built to help MSPs, VARs, and resellers expand into security services without building their own infrastructure. The new service combines Guided Vulnerability Management and Managed XDR to provide continuous monitoring, threat detection and response, asset discovery, endpoint detection and response, SIEM, SOAR, dark…

21,786 Home Cameras, No Password, No Warning

21,786 live cameras stream with zero authentication. Cheap gear is the real risk, webcamXP open 46% of the time. Your home router is the broadcast tower. In May 2026, Mysterium VPN queried a public internet-wide device index to count every camera and recorder that answers the open internet. They found more than three million reachable…

Zebra Repco Rollout Signals ANZ Channel Services Shift

Back in April, Zebra Technologies Corporation, a company specializing in digitizing and automating workflows to deliver intelligent operations, announced that Repco, the largest reseller and supplier in the automotive aftermarket parts sector across Australia and New Zealand (ANZ), had digitized its last-mile delivery operations with Zebra’s TC5 series mobile computers. The deployment highlights a broader…

Pax8 Beyond 2026 Vendors Target MSP AI and Security

At this year’s Pax8 Beyond 2026 conference, vendors across the channel unveiled new products, partnerships, and investments focused on helping managed service providers improve operations and scale more efficiently. Several announcements centered on security, documentation, and service delivery, reflecting the challenges MSPs continue to face as customer expectations rise and operational demands increase.  Read our…

MSP Compliance Services Shift to Continuous Monitoring

As enterprises accelerate AI adoption and face an increasingly complex web of cybersecurity and data protection requirements, managed service providers are finding new opportunities to expand beyond traditional IT support and into continuous compliance services. Brian Harmison, CEO of Corsica Technologies, says customers are no longer looking for occasional audit preparation or checkbox exercises.  Instead,…

Authorities dismantle crypto laundering service that moved €336 million for cybercriminals

An international law enforcement operation has dismantled a cryptocurrency laundering service linked to ransomware groups and other cybercriminals that processed more than €336 million in illicit funds. The domain seizure notice (Source: Europol) Europol said the service, known as AudiA6, is suspected of laundering cryptocurrency obtained through ransomware attacks and other forms of cybercrime between…

‘Harvest now, decipher later’: The quantum threat few are preparing for

Quantum technology may feel far off but certain risks are already with us in the form of “harvest now, decrypt later” — an attack vector in which malicious actors steal data now for a future in which they have access to quantum computational tools capable of breaking encryption deployed by most companies today to protect their data.…

Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs

Authorities in Europe have disrupted AudiA6, a cryptocurrency laundering service used by ransomware gangs and cybercriminal networks. Europol, in a statement issued Thursday, said the dismantling of AudiA6 cut off a “key financial pipeline used to wash hundreds of millions in illicit profits.” The service is estimated to have been used to launder more than…

Comcast Business SecurityEdge Preferred strengthens security for small businesses

Comcast Business announced SecurityEdge Preferred, its most advanced network-native cybersecurity solution for small businesses. Because SecurityEdge Preferred is built directly into the Comcast Business network, security can be activated in minutes without deploying additional hardware, managing multiple vendors, or maintaining complex security tools. Rather than adding another layer on top of existing infrastructure, it lives…

How to use NIST and ISO frameworks to govern AI agents

Security leaders no longer need convincing that AI agents introduce risk. What’s missing is how to govern them once they move into production and begin operating autonomously across enterprise environments. AI agents already read sensitive documents, invoke internal APIs, trigger workflows, and make decisions that still require human judgment. From a security perspective, the most…

AI sovereignty makes data centers strategic targets for cyber operations

Data centers built for frontier AI draw hundreds of megawatts of electricity and large volumes of cooling water from fixed locations with known addresses. Each one concentrates tens of thousands of graphics processors, liquid cooling systems, and high-density power equipment inside a single building. This physical footprint turns a nation’s AI capability into something an…

Europe’s digital identity wallet gets its first set of standards

People across the European Union already use their phones for banking, travel, and government services. The European Digital Identity Wallet will bring those activities into one application, and the European Telecommunications Standards Institute (ETSI) has released the first standards that support it. What the wallet does The wallet lets EU citizens and residents prove their…

New infosec products of the week: June 12, 2026

Here’s a look at the most interesting products from the past week, featuring releases from AISLE, Drata, Elastic, Filigran, IDnow, and Ridge Security. RidgeBot 7.0 automates Active Directory attack simulations for security validation Ridge Security has announced the release of RidgeBot 7.0, an update to its automated security validation platform that introduces automated Windows Active…

Top 25 Technology Companies by Valuation

Top 25 Technology Companies by Valuation

Here is the list of the top 25 technology companies globally, ranked by their approximate market capitalization (or private valuation) as of mid-2026. This ranking reflects the massive growth in sectors like artificial intelligence, semiconductor manufacturing, and cloud computing. Rank Company Ticker / Status Approximate Valuation 1 NVIDIA NVDA ~$4.96 Trillion 2 Alphabet (Google) GOOG…

Antidetect Browser Technology: The Future of Secure Online Management

In this post, I will talk about the Antidetect Browser technology and the future of secure online management. Online accounts are now part of daily life. Whether someone is managing ads, handling multiple projects, logging into services from different devices, or running automated workflows, they expect one thing: smooth account operation without unnecessary friction. But…

CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch Release

Attackers are exploiting the critical CVE-2026-10520 flaw in Ivanti Sentry, compromising many internet-exposed gateways shortly after patches were released. Threat actors have started exploiting a maximum-severity OS command injection flaw in Ivanti Sentry, tracked as CVE-2026-10520, that allows remote code execution with root privileges. “An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote…

New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets

Two security teams have shown, in separate research published this week, that OpenClaw, the popular self-hosted AI agent, can be driven to run attacker-controlled code or hand over sensitive data through ordinary-looking inputs. Imperva buried instructions inside shared contacts, vCards, and location pins that the agent executed without the victim ever seeing them. Varonis built…

Ticket Scams to Infrastructure Attacks: FIFA World Cup Cyber Risks

One of fútbol’s premier events is about to hit North America this summer with the FIFA World Cup 2026 stretching across the U.S., Canada, and Mexico. The tournament will feature 48 national teams competing to become champions – up from 32 in previous tournaments – across 16 host cities. It will be the first time…

Russian national charged in connection with Void Blizzard espionage campaign

Federal prosecutors have charged a Russian national with conspiracy to commit unauthorized computer access in connection with a sprawling cyber-espionage campaign linked to the Russia-aligned threat group Void Blizzard, according to a criminal complaint filed in federal court this week. Denis Nikolayevich Obrezko, a Russian citizen, is accused of breaking into systems owned by companies…

WWDC: What IT admins need to know

Under-the-hood AI changes and efficiency improvements at the OS layer across Apple’s platforms are certainly the highlights at WWDC 2026. But there have also been significant changes IT admins will need to prepare for, particularly around Declarative Device Management (DDM).  The Intel age is over Apple warned us this was coming, but macOS 27 will not support Intel at all.…