Geek-Guy.com

Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials

The Security Service of Ukraine (SSU) said it, together with the U.S. Federal Bureau of Investigation (FBI), uncovered a long-running campaign orchestrated by Russian intelligence services to break into the messaging accounts of government officials, military personnel, politicians, and activists in Ukraine, Europe, and the U.S. The systematic cyber attacks aimed at stealing sensitive

New FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access Messages

FBI warns Russian spies now target Signal Backup Recovery Keys, enabling access to message history and long-term account takeover. The FBI and CISA updated their March 2026 warning about Russian intelligence phishing campaigns, and the new advisory adds a detail that wasn’t in the original: the operators have shifted their primary objective from stealing verification…

Hospitality Sector Hit by Phishing Campaign Using Fake Guest Complaint Emails

Microsoft warns of a phishing campaign targeting the hospitality sector with fake guest emails that install TonRAT using resilient persistence. Microsoft Threat Intelligence published a detailed analysis on an ongoing hacking campaign against hospitality organizations that has been running since April 2026. The targets are specific: device names observed across compromised environments include strings like…

Hackers exploit critical PTC Windchill PLM software flaw

Hackers are exploiting a critical vulnerability recently patched in PTC Windchill and FlexPLM, two product lifecycle management solutions used by organizations across a range of industries, including defense, aerospace, automotive, medical, electronics, industrial machinery, and consumer goods. The vulnerability, tracked as CVE-2026-12569, is an unsafe deserialization flaw that enables remote code execution. It’s located in…

Weak Access Controls Leave Enterprise Networks at Risk 

Many successful cyberattacks still exploit exposed services, weak credentials, and inadequate access controls.  Recent findings from Barracuda Managed XDR highlight how attackers continue to exploit these gaps to deploy malware, compromise remote access infrastructure, and establish persistent footholds within enterprise environments. Key Takeaways Weak credentials, exposed remote services, and insufficient access controls continue to provide…

SOC 2 Compliance Is Reshaping Enterprise Procurement 

Security and compliance have become increasingly important factors in enterprise purchasing decisions.  While SOC 2 compliance was once viewed as a differentiator, many organizations now expect vendors to demonstrate independently validated security controls before advancing through procurement.  According to Aaron Puckett, Executive Vice President of Managed Services Group, the next phase of vendor evaluation will…

New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks

A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts. Kaspersky, which is tracking the activity under the moniker StrikeShark, said the campaign has targeted a diplomatic organization in Indonesia, government organizations in Taiwan,

APAC MSPs Move Beyond IT Support as AI Adoption Grows

Managed service providers (MSPs) in the Asia Pacific (APAC) region are playing a larger role as organizations accelerate AI adoption and digital transformation. With AI investment, cloud adoption, and infrastructure expansion continuing to grow, APAC is emerging as one of the world’s leading technology markets. These developments are creating new opportunities, while also raising expectations…

Chinese APT CL-STA-1062 Expands Attacks on Southeast Asian Critical Infrastructure With Custom Malware

Chinese-speaking APT CL-STA-1062 targeted Southeast Asian government and energy networks open-source tools, and a new TinyRCT backdoor. Palo Alto Networks Unit 42 researchers published a detailed report on a Chinese-speaking threat actor, tracked as CL-STA-1062, that has been running persistent operations across East Asia since at least March 2022 and shifted focus to Southeast Asian…

GEO Poisoning Can Manipulate AI-Generated Answers 

As organizations increasingly rely on AI assistants for research and decision-making, attackers may have a new way to influence AI-generated answers without compromising the underlying models.  New research from Lasso Security demonstrates that generative engine optimization (GEO) — the practice of optimizing content for inclusion in AI-generated responses — can be manipulated to promote false…

Malware authors subvert AI detection systems

Enterprises that have turned to AI in order to boost their security defenses may have to reconsider their approach. Malware containing code that commands LLM-assisted products to abort their analysis or refuse to implement it is already circulating, according to a post from security company SentinelLabs. SentinelLabs thinks it knows who’s responsible for the malware,…

Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign

A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia. The activity, particularly aimed at state-owned enterprises in the energy and government sectors, has been attributed to a threat actor called CL-STA-1062, which…

Chinese Development Framework Linked to Global Scam Infrastructure

A new Infoblox Threat Intel report reveals that the legitimate DCloud Uni-App framework has become a foundation for a global online scam ecosystem.  Researchers identified more than 236,000 scam domains built with DCloud Uni-App, including fake crypto exchanges, phishing sites, gambling platforms, and investment scams.   Key Takeaways Researchers linked more than 236,000 scam domains to…

EU: Microsoft, Amazon cloud services could be classified as gatekeepers

Following a seven-month investigation, the European Commission has reached a preliminary decision that Amazon’s and Microsoft’s cloud platforms — AWS and Azure, respectively — should be classified as “gatekeepers” under the EU’s Digital Markets Act (DMA), Reuters reports. The DMA, also known as the Digital Markets Regulation, aims to limit the market power of dominant…

Cyberattacks pose a ‘threat to life’ in Australia

Australia’s Security Intelligence Organization (ASIO) has uncovered an attack on a critical infrastructure operator’s network. State-sponsored actors had compromised the network and were preparing to sabotage it, according to its director general, Mike Burgess. Other countries face similar cyber-threats to critical infrastructure. It’s impossible to exaggerate the danger that the country is facing from cyberattacks…

Cyberattacks pose a ‘threat to life’ in Australia

Australia’s Security Intelligence Organization (ASIO) has uncovered an attack on a critical infrastructure operator’s network. State-sponsored actors had compromised the network and were preparing to sabotage it, according to its director general, Mike Burgess. Other countries face similar cyber-threats to critical infrastructure. It’s impossible to exaggerate the danger that the country is facing from cyberattacks…

Framewerx CEO on AI’s Next Chapter for MSPs

How can AI help managed service providers reduce repetitive work while improving cybersecurity for small businesses? In this Channel Insider interview, Victoria Durgin speaks with Dan Reid, CEO of Framewerx, about the launch of Neuralwerx—an AI-powered platform designed to automate routine MSP tasks, lower security costs for SMBs, and free IT professionals to focus on…