Geek-Guy.com

Apple scrambles to handle component price hikes

Apple execs are now acknowledging the company is going to need to raises prices to cope with higher component costs, particularly memory. Apple has been battling to avoid doing so, but warned this week that those efforts are “unsustainable.” The price pressure is being felt across the tech industry. Omdia predicts the average selling price (ASP) of smartphones…

Accenture shells out $4.18B on three companies in big industrial cybersecurity push

Accenture announced Thursday it would acquire a majority stake in industrial cybersecurity firm Dragos for $3.25 billion and purchase two smaller security companies outright, essentially making a $4.18 billion bet that defending the IT networks of power grids, pipelines, factories and critical infrastructure sectors will become one of the defining challenges of the AI era.…

Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2

Microsoft has disclosed details of a Windows-based cryptocurrency clipper campaign that has targeted users since February 2026. “The clipper in this campaign relies on Windows Script Host and ActiveX-driven logic to launch a bundled Tor proxy and poll a hidden-service C2 [command-and-control] server,” the Microsoft Defender Security Research Team said in an analysis published Tuesday.…

INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023

Cybersecurity researchers have charted the evolution of INC from an nascent ransomware-as-a-service (RaaS) operation to one of the most prolific cybercrime groups in 2026, claiming no less than 830 victims since August 2023. “The disruption of LockBit and the shutdown of BlackCat created opportunities for INC to expand as affiliates migrated to alternative ransomware operations,”…

F5 Patches Critical NGINX Vulnerabilities Enabling Unauthenticated Code Execution

F5 released emergency updates for critical NGINX flaws (CVE-2026-42530, CVE-2026-42055) that could enable unauthenticated code execution. F5 has issued out-of-band patches for multiple NGINX vulnerabilities, including two critical flaws, respectively tracked as CVE-2026-42530 and CVE-2026-42055 (CVSS 9.2). The bugs affect HTTP modules and can be exploited remotely without authentication to trigger memory corruption, potentially causing…

DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic

Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to conceal command-and-control (C2) traffic inside Microsoft Teams relay infrastructure. According to findings from Broadcom-owned Symantec and Carbon Black, the backdoor was deployed against a major U.S. services firm. The name of the company was

BlackFog Launches ADX Vision Shadow AI Controls for macOS

BlackFog, an anti-data exfiltration (ADX) provider, has announced the general availability of ADX Vision for macOS, extending its shadow AI detection, governance, and prevention platform to Apple endpoints.  With the release, BlackFog said enterprises can apply a single, consistent AI data-loss policy across Windows and macOS environments, helping prevent sensitive data from leaving the organization…

Microsoft working on a fix for RoguePlanet, a flaw that grants full PC control

A publicly available exploit called RoguePlanet can give attackers the highest level of access on Windows systems. Microsoft has confirmed the vulnerability and says it’s working on a security update. RoguePlanet is tracked under CVE-2026-50656, where it’s described as a Microsoft Defender Elevation of Privilege (EoP) vulnerability. In its advisory, Microsoft says: “Microsoft is aware…

eSentire links AI-led penetration testing with MDR through Atlas Preempt

eSentire has announced the launch of Atlas Preempt, a component of the company’s Atlas Platform. Atlas Preempt performs continuous, AI-driven offensive testing against customer environments to identify which exposures attackers can reach and feeds that data into eSentire’s 24/7 Managed Detection and Response (MDR) service. The process includes human oversight and control mechanisms. Atlas Preempt…

Attackers abuse Google Ads, GitLab, and Claude to deliver malware

Threat actors are abusing trusted platforms, including Google Ads, GitLab pages, and Claude’s shared chat feature, to trick users into executing malicious commands on their systems. Disguised as popular AI developer tools, the threat actors used ClickFix social engineering attacks, where victims were tricked into manually executing malicious commands. Typically, this involved copying and pasting…

Lyra Cloud Services Targets Anthropic & AWS AI Use Cases

Lyra Cloud Services has announced a strategic partnership with Anthropic to help organizations adopt and scale enterprise AI capabilities in AWS environments. The partnership expands customer access to Anthropic’s Claude models through Amazon Bedrock, AWS’s managed service for building and scaling generative AI applications.  Partnership targets AI deployment complexity Lyra Cloud Services, Evergreen’s newest addition…

FortiBleed campaign exposes 75,000 Fortinet firewalls worldwide

A massive credential-compromise campaign dubbed “Fortibleed” has been found to expose tens of thousands of Fortinet devices worldwide, with researchers warning of persistent attacker access to affected enterprise environments. The campaign was first flagged by security researcher Volodymyr Diachenko, who posted on LinkedIn about finding an attacker-controlled list of potentially working FortiGate passwords collected “through…

New CISO appointments 2026

The upper ranks of corporate security are seeing a high rate of change as companies try to adapt to the evolving threat landscape. Many companies are hiring a chief security officer (CSO) or chief information security officer (CISO) for the first time to support a deeper commitment to information security. Follow this column to keep…

Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model

Analysis tools do not need AI built in to support agentic workflows; they simply need to expose their data through an external scripting interface.  Even traditional graphical user interface (GUI) applications can be made AI-accessible by publishing their internal object models, allowing agents to query and automate analysis without modifying the core application.  This approach can often be implemented…

Microsoft Confirms RoguePlanet Zero-Day in Defender, Patch Under Development

Microsoft confirmed the RoguePlanet Defender zero-day (CVE-2026-50656), a privilege escalation flaw, and is developing a security patch. Microsoft has acknowledged the RoguePlanet zero-day affecting Microsoft Defender, tracked as CVE-2026-50656 (CVSS score of 7.8). The vulnerability allows privilege escalation through the Microsoft Malware Protection Engine. The company stated it is aware of the issue and is…

GentleKiller targets more than 400 security processes across 48 products

Most ransomware operations leave the work of disabling endpoint security software to their affiliates. The ransomware-as-a-service gang Gentlemen runs a different model. Its operators develop and maintain a set of tools for shutting down endpoint detection and response (EDR) products, then provide these tools directly to the affiliates who rent the gang’s encryptors. An internal…

Cybersecurity was built for predictable systems. AI changes the rules

Every major technology shift changes cybersecurity. I’ve spent much of my career working through major technology transitions, from the rise of the commercial internet to mobile and cloud computing. Each shift created new opportunities for innovation, but it also created new security problems organizations weren’t fully prepared for. AI may resemble previous technology shifts in…

Barracuda introduces AI-powered email security with automated threat response

Barracuda Networks has unveiled Barracuda Integrated Email Protection, an Integrated Cloud Email Security (ICES) solution delivering protection against evolving AI-driven threats. Powered by AI, the solution continuously and autonomously detects and remediates threats across the attack lifecycle, explains Microsoft 365 and Google Workspace verdicts and enables rapid post-delivery message clawback. Built on BarracudaONE platform telemetry…

New 42Crunch plugin helps developers find and fix API vulnerabilities in GitHub Copilot

42Crunch has announced the availability of the 42Crunch API Security Testing Plugin for GitHub Copilot. This latest advance enables developers to continuously audit, test, remediate and validate API security vulnerabilities directly within AI-assisted development workflows. Organizations are struggling to secure their growing API landscape in the face of increasing attacks, with AI’s heavy reliance on…

Blue Planet helps service providers reduce risk with unified network change governance

Blue Planet is closing the governance gap in network operations by unveiling Blue Planet Configuration and Change Management (CCM), unifying device configuration, change, and lifecycle management across multi-vendor networks. Backed by Blue Planet’s deep Operations Support System (OSS) expertise, CCM replaces fragmented tools and manual processes with AI-driven workflows to reduce risk, prevent outages, and…

How security teams are getting credential visibility into developer endpoints

As we noted in our earlier analysis, attackers already know secrets are on your developers’ machines, the only question is whether security teams do. The supply chain attack calendar of 2026 has been relentless. Megalodon backdoored 5,500 GitHub repositories in six hours. TrapDoor spread across npm, PyPI, and Crates.io simultaneously, planting persistence inside AI coding…

5 Key Takeaways from Inside the Shape-Shifting Inbox: A Modern Playbook for Security Leaders

Artificial intelligence is accelerating one of the most significant shifts the cybersecurity industry has seen in years. During Cofense’s webinar, Inside the Shape-Shifting Inbox: A Modern Playbook for Security Leaders, CEO Marc Olsen and Board Advisor George Gerchow explored how AI is transforming phishing from a high-effort, tactical attack into a highly scalable, adaptive business…