Geek Guy

Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and three that were publicly disclosed prior to the release of the patches. Vulnerabilities of note CVE-2026-68820 is a use-after-free flaw that affects the Windows Ancillary Function Driver for WinSock (AFD.sys) and allows a…

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for…

ConnectSecure helps MSPs automate Microsoft 365 security remediation

ConnectSecure has announced that Microsoft 365 Auto Remediation and AI-powered Training Assessments are now live on the ConnectSecure platform. The capabilities help managed service providers (MSPs) address supported M365 security findings, create and measure assessments, support client training and strengthen security posture from one platform. The launch advances ConnectSecure’s focus on proactive, unified protection for…

4 gaps slowing AI in enterprise SOCs

Artificial intelligence (AI) has quickly become a strategic priority for enterprise security teams. Yet despite growing investment in AI-driven security software, many enterprise SOCs are struggling to translate AI into measurable operational improvements. The issue isn’t whether AI belongs in the SOC. It does. The challenge is that many organizations are approaching AI adoption in…

CBTS brings continuous penetration testing to enterprise security

CBTS has launched Penetration Testing as a Service (PTaaS), combining autonomous penetration testing with security expertise to help organizations continuously identify exploitable risks, validate attack paths, and prioritize remediation as their environments evolve. Cloud environments, SaaS applications, connected systems, third-party relationships and AI systems are expanding enterprise attack surfaces faster than traditional testing cycles can…

Crytica’s RDAi detects OT device tampering from within

Crytica Security has developed a patented solution that delivers rapid, deterministic threat detection for operational technology (OT), protecting the embedded systems and connected devices that underpin critical infrastructure, national security, and healthcare without disrupting operations. The need is becoming increasingly urgent as cybersecurity moves toward machine speed. IBM’s Cost of a Data Breach Report 2026…

Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily

Google Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious websites, helping reduce scams, phishing attempts, and other deceptive content. Abusive notifications (Source: Google) Chrome revokes notification permissions for websites users have not recently interacted with and for sites that Google Safe Browsing identifies as engaging in…

ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch

Chaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day that bypasses the CVE-2026-50656 patch and could enable SYSTEM-level code execution. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a PoC for ShieldBreak, a Microsoft Defender zero-day. The flaw bypasses the patch for CVE-2026-50656 (RoguePlanet), a race condition that…

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential…

Intelligence-Driven SOC: Modernizing Threat Monitoring and Detection Engineering for Ultimate MTTR Reduction

Threat monitoring serves as the vital connective tissue of modern security operations. It ensures that every function from triage to response operates effectively. To meet evolving threat challenges, SOC teams and MSSPs must transition from simple log collection to a proactive, intelligence-driven framework. ANY.RUN’s Threat Intelligence provides the essential solutions to power this transformation across…

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation. “SAP Commerce Cloud…

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePlanet. RoguePlanet has been described

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker…

Can Charter Buses Travel Across State Lines? Complete Guide for Group Trips

In this post, I will answer the question – can charter buses travel across state lines? Traveling with a large group often requires a transportation option that is comfortable, reliable, and cost-effective. Many people planning school trips, corporate events, sports tournaments, family reunions, church outings, or sightseeing tours wonder whether charter buses are allowed to…

Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability

A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases. The hole is in Windows’ Ancillary Function Driver for WinSock (CVE-2026-68820), which, according to Todd Schell, principal product manager at Ivanti,…

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as “critical.”  Microsoft notes that 1 of the vulnerabilities disclosed this month have been exploited in the wild  CVE-2026-68820 is an elevation of privilege vulnerability affecting Windows Ancillary Function Driver for WinSock. A Use After…

Delta Airlines Investigates Rogue Wi-Fi Attack on Flight Carrying DEF CON Attendees 

Passengers on a Delta flight from Las Vegas to Atlanta experienced a disruption when an unauthorized Wi-Fi network prompted the crew to temporarily disable onboard Wi-Fi.  Delta is now investigating the incident, which occurred on Flight 591 carrying passengers returning from the DEF CON 34 cybersecurity conference. “Incidents like this are a reminder that convenience…

Landing Zone Accelerator Independent Assessment Report for C5:2020 now available on AWS Artifact

Organizations operating in Germany and across Europe increasingly need to demonstrate cloud security compliance under the Cloud Computing Compliance Criteria Catalogue (C5:2020), published by Germany’s Federal Office for Information Security (BSI). Last year, we introduced Landing Zone Accelerator on AWS support for digital sovereignty and today we’re announcing the availability of a new independent assessment…

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today. Image: Shutterstock, Mallika Home Studio. August’s overstuffed bundle of patch joy from Microsoft did not eclipse its…

OpenAI Gives Approved Security Providers Access to Advanced Daybreak Cyber Models

Cybersecurity teams can run into an awkward problem with AI. Legitimate defensive work can resemble the same activity a model is trained to restrict. OpenAI is addressing that problem by expanding Daybreak with two access tiers for approved defenders. Blue supports common defensive workflows, while Red provides access to specialized models for advanced, authorized security…

Anthropic to watermark AI-generated content

Anthropic will begin labeling AI-generated content created by Claude, Claude Code, and the company’s API, as well as Claude models via third-party services, according to The Register. Text generated by future Claude models will be given an invisible watermark. According to Anthropic, the watermark is embedded directly into the generated text without affecting its meaning…

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026. “Kimwolf v7 adds an…

Suspected Phishing Sites Use Valid TLS Certificates to Mimic WhatsApp and Instagram

A new phishing campaign is making fake websites look trustworthy by giving them the same HTTPS security signal people usually associate with legitimate sites. Security researchers at Clandestine said they identified newly activated phishing and interface-cloning infrastructure that appears designed to target customers of high-value brands, with a primary focus on WhatsApp and Instagram. According…

CEVA Logistics Breach Triggers Customer Data Alerts Across Europe

A cyberattack at CEVA Logistics is now surfacing in customer notices across Europe. CEVA said the intrusion affected part of its European contract-logistics operation, including eight warehouses. Several clients have since notified customers that information held by CEVA may have been accessed. Client notices are beginning to clarify which organizations and data types were affected.…

OpenAI, Anthropic, and Meta AI Breaches Shared the Same Testing Vendor

A shared security-testing vendor may explain why AI models from OpenAI, Anthropic and Meta all reached systems they were never supposed to access. CNBC reported that the three incidents involved Irregular, an Israeli security firm that evaluates the offensive capabilities of advanced AI models. In the affected tests, configuration weaknesses reportedly gave the models pathways…

Enterprise AI Agent Adoption Hinges on Guardrails, Caylent Finds

Ninety-eight percent of enterprise leaders would allow AI agents to autonomously make changes in production environments, provided the right safeguards are in place, according to Caylent’s newly published 2026 Enterprise Readiness for Agentic Engineering & Autonomous Cloud Operations report. The findings also suggest agentic AI is moving beyond experimentation, with 59.5% of respondents reporting that…

C Spire Earns Three ISO Certifications for Managed Services

C Spire has earned three International Organization for Standardization certifications simultaneously, completing its first audit with zero nonconformities as the managed services provider strengthens its security, service management, and quality standards for customers in regulated industries. These certifications verify that C Spire’s management system “meets rigorous, internationally recognized standards for quality, security, and reliability.” The…