Geek-Guy.com

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,

Apple preps for a wearable AI revolution

This fall, with watchOS 27, Apple Watch will finally get access to Siri AI with a software update that turns your wrist into the most widely-used wearable AI platform on Earth. That’s not hyperbole. Siri AI on Apple Watch is arguably the most important feature to this year’s watchOS update. Though it didn’t get much attention at WWDC, the update also offers…

Cellhire Expands Channel Team with Four New Hires

Cellhire has expanded its channel and business development teams with four new hires as the mobile and IoT connectivity provider looks to grow its reseller network and strengthen partner support. The UK-based company provides managed mobile connectivity, IoT connectivity, eSIM services, and temporary connectivity solutions for enterprises, channel partners, and organizations supporting remote workforces, large-scale…

Coffee with the Council Podcast: Meet This Year’s Asia-Pacific Community Meeting Keynote Speaker, CJ Meadows

  Welcome to our podcast series, Coffee with the Council. I’m Alicia Malone, Director of Communications and Public Relations for the PCI Security Standards Council. Today, I’m excited to bring you a preview of our 2026 Asia-Pacific Community Meeting keynote speaker, Dr. CJ Meadows. CJ is a globally recognized innovation and leadership expert whose work…

Huntress warns about attack spree that hit 30 SonicWall customers in 2 days

Huntress researchers spotted an active and ongoing series of attacks targeting SonicWall VPN and firewall accounts, which compromised 30 organizations in less than two days, the company said in a threat advisory Tuesday. The credential stuffing campaign started Saturday and grew rapidly, ultimately compromising 92 unique user accounts during the next 41 hours, according to…

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security’s

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. “A malicious actor with network…

MCBS Healthcare Data Breach Affects 1.26 Million People

A cyberattack on a medical billing company has potentially exposed information belonging to more than 1.26 million people, underscoring that healthcare’s biggest security risks often lie outside the hospital. Medical Computer Business Services (MCBS), a US software vendor for healthcare providers, disclosed that attackers gained unauthorized access to its network between September 22 and 26,…

Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline

A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls. Braham’s water plant went offline, and the city asked residents to…

Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies

Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution

Broadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine. Broadcom has released patches to address five vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion, including three rated critical. The most severe, tracked as CVE-2026-47876 (CVSSv3 base score of 9.3), is a…

ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility

Research from Aryon reveals that each year, 3,731,699 short-lived cloud resources containing highly sensitive information are publicly exposed. This impacts any organization using AWS services that support public sharing. These exposures often last only minutes or hours, too briefly for periodically scanning CSPM and CNAPP platforms to detect, yet long enough for attackers to discover and…

DefensX Unveils AI Browser Security Features for MSPs and SMBs

DefensX has expanded its browser security platform with new AI governance capabilities designed to help managed service providers secure AI adoption among small and midsize businesses. The update includes an AI Cloud Connector that isolates browser-based AI traffic and helps organizations enforce data protection and compliance policies. DefensX announced the expansion alongside a growth investment…

Delinea AI Agent Security Adds Runtime Authorization

Identity security provider Delinea has introduced runtime authorization capabilities designed to control what AI agents can do after they connect to sensitive enterprise systems. The Delinea Platform evaluates individual tool calls, commands, and database queries as they occur, allowing organizations to approve, block, or escalate agent actions instead of relying solely on authentication at the…

OpenAI rogue AI agent’s attack expanded beyond Hugging Face

The autonomous AI agent that escaped during OpenAI testing exploited weaknesses across a customer workload, a third-party cloud platform, and Hugging Face’s production environment before being contained, according to new technical disclosures that provide the clearest picture yet of one of the first publicly documented AI-driven intrusion chains. Hugging Face’s technical timeline identifies Modal as…

MIND AI DLP Agents automate DLP classification, investigations and remediation

MIND has announced MIND AI DLP Agents with capabilities focused on classification, investigation, policies, remediation and exception management. MIND also includes a Model Context Protocol (MCP) interface that enables security teams to direct data security work through any MCP-connected client using natural language. AI has fundamentally changed the speed and scale at which sensitive data…

Contrast CVE Shield aims to protect applications while security teams deploy patches

Contrast Security has announced Contrast CVE Shield, designed to help organisations defend against the growing number of exploits generated with advanced AI models such as Claude Mythos. Contrast CVE Shield runs inside the application, where it detects, monitors and blocks attempts to exploit known vulnerabilities. Applications continue to function normally while security teams gain visibility…

Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity

The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law. The principal security agency said the instant messaging platform “failed to remove numerous channels, chats, and bots on the platform…

Cloudflare reveals what’s behind major internet outages

Storms, earthquakes, and infrastructure failures disrupted internet access throughout the second quarter, while governments deliberately shut networks down, according to Cloudflare’s latest Internet Disruption Summary. Based on Cloudflare Radar traffic data, the report covers internet disruptions recorded between April and June 2026. Governments switching access on and off Iran began restoring nationwide internet access on…

OpenAI’s rogue AI agent shows why we need federal rules for autonomous systems

Months before the Hugging Face breach, Emergence AI published research that investigative journalist Ronan Farrow made public. Ten autonomous AI agents operated across five virtual environments for fifteen days without human intervention. Much of the attention focused on Grok 4.1 turning violent and Gemini 3 Flash committing 683 crimes. What mattered more went unnoticed: Anthropic’s…

It’s easier to steal cargo than toothpaste

Our cybersecurity world can get quite interesting and even close to science fiction sometimes. No, it’s not AI this time, but something movie-worthy nevertheless. Picture scenes from known heist-themed movies such as “Ocean’s Eleven” or “Mission: Impossible”. Real-world equivalent scenarios like these are happening in front of your eyes and you might not even know…

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that

FortiGate 1200G brings FortiSASE Outpost to customer-controlled environments

Fortinet has announced the FortiGate 1200G series, the newest addition to the FortiGate G series with FortiSASE Outpost, which brings cloud-delivered security services into customer-controlled environments. By combining high-performance threat protection, connectivity, hardware-rooted platform security, and cloud-delivered security capabilities, the solution gives organizations the flexibility to enforce security where it makes the most business sense.…