Geek-Guy.com

HIPAA Security Rule on AWS – Technical Safeguards Implementation and Readiness Guidance

Today, we’re releasing the HIPAA Security Rule on AWS: Technical Safeguards Implementation and Readiness Guidance. This helps covered entities and business associates configure, implement, and evidence compliance with the HIPAA Security Rule Technical Safeguard requirements (45 CFR §164.312) when building healthcare workloads on AWS. The HIPAA Security Rule’s Technical Safeguards (§164.312) define five standards and…

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. These targeted organizations operate across several sectors, such as healthcare, research, government offices,

South Korea Fines KT $37.4M for Failing to Stop Long-Running Network Intrusion

South Korea’s Personal Information Protection Commission (PIPC) has fined KT Corp. 53.9 billion won ($37.4 million) after finding that weak network access controls allowed hackers to expose the personal information of 16,647 mobile customers. The regulator said hackers accessed KT’s wireless network through an unauthorized femtocell, a small base station used to extend mobile coverage,…

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that

Intel 471 Warns of Expanding Software Supply Chain Attacks 

Software supply chain attacks are evolving beyond compromised software packages into attacks targeting the people, identities, and workflows used to build and distribute software.  Intel 471’s report, Poisoned Trust: How Supply Chain Attacks Weaponize Developer Ecosystems, found that threat actors are increasingly targeting developer accounts, CI/CD pipelines, repositories, IDEs, and publishing infrastructure.  By compromising these…

5 Best MDR Services for Businesses and MSPs in 2026

Managed detection and response services give organizations access to 24/7 threat monitoring, investigation, and incident response without requiring them to build a complete security operations center. They combine security technology, automation, and human expertise to help organizations identify and contain threats more efficiently. We evaluated five leading MDR providers for 2026 based on threat coverage,…

Enterprise ERP AI Adoption Outpaces Security Readiness 

Organizations are rapidly embedding artificial intelligence (AI) into enterprise resource planning (ERP) systems, but many cybersecurity leaders remain unconvinced that their organizations are prepared to secure these environments.  According to the 2026 Onapsis State of AI, Security, and ERP report, AI adoption is accelerating across SAP, Oracle, and Salesforce environments even as concerns about security,…

AI-Speed Attacks and Critical Flaws Compress Defenders’ Response Window this Week of July 2026

This week’s cybersecurity landscape was defined by attacks against critical infrastructure, actively exploited enterprise flaws, rapidly expanding AI exposure, and major compromises involving healthcare, energy, financial, and retail data. At the same time, AI agents demonstrated how quickly vulnerabilities can be discovered and weaponized, reinforcing the need for faster patching, stronger identity controls, continuous asset…

Broadcom patches vulnerabilities all over VMware

Broadcom has addresses five vulnerabilities in its VMware product range, three of which have been accorded a “critical” rating. The affected products are: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure CVE-206-59309 affects the VMware Directory Service. According to Broadcom,…

Cybercrime goes subscription: AI, malware and infrastructure on demand

Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These services provide anonymity, plausible deniability, and access to short-lived infrastructure that is difficult to detect, attribute, and disrupt, enabling low-skilled actors to operate at scale, according to the Infoblox 2026 Threat Landscape Report. “Cybercrime…

What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery

An AI-assisted audit found 29 flaws in GlobaLeaks, showing LLMs make large-scale code reviews faster, cheaper, and accessible. GlobaLeaks, a mature whistleblowing platform that had already undergone six independent professional audits over the past thirteen years, was subjected to an LLM-assisted security review that cost roughly USD 3,140 in API calls. The review identified 29…

Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire

A security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years. Fuyao apps ecosystem (Source: Bitsight) According to Bitsight, the operation, named Fuyao, uses preinstalled Android apps, device identity spoofing, AI-generated websites, and residential proxy services to generate advertising revenue without device owners’ knowledge.…

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

An academic study has disclosed a “widespread class” of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user’s network session. The findings have been released by a group of researchers from Singapore’s Nanyang Technological…

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Palo Alto Networks’ Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session. The operator, tracked through the aliases knaithe and KnYuan,

Fake Flash Player installs AtlasRAT

Researchers have described a campaign that delivers a remote access Trojan (RAT) called AtlasRAT through a fake Flash Player installer. People still go looking for “Flash player” because a surprising amount of content and software was built around Flash and never properly migrated. Users often just want a quick way to get those old sites,…

JetBrains says a crafted HTTP request could break TeamCity

JetBrains is warning of a critical security vulnerability in its TeamCity DevOps platform that could allow unauthenticated attackers to execute arbitrary operating system commands on vulnerable servers. “If exploited, this vulnerability may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary commands,“ the company said in…

Anthropic’s Claude breached three companies during security tests

Anthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure follows OpenAI’s July 21 announcement that some of its models had escaped an isolated testing environment by exploiting a previously unknown vulnerability and reached the systems of Hugging Face, the open-source machine…

After OpenAI, Anthropic finds Claude breached three organizations during cyber tests

Less than two weeks after OpenAI disclosed that an experimental AI model breached Hugging Face during a cybersecurity evaluation, Anthropic has revealed that its own review uncovered three incidents in which Claude models gained unauthorized access to the production infrastructure of three organizations during similar testing. Anthropic said it launched the review after OpenAI disclosed…

Anthropic Finds Claude Breached Real Companies During Security Evaluations

Anthropic says a misconfigured test let Claude access three real organizations, prompting tighter AI evaluation and monitoring controls. Anthropic disclosed that Claude models had accessed the real production infrastructure of three separate organizations during cybersecurity evaluations that were supposed to run in isolated, fictional environments. The company found the incidents after reviewing 141,006 evaluation runs…

Horizon3.ai expands NodeZero with automated web application attack path testing

Horizon3.ai has expanded its NodeZero platform with AI-powered web application pentesting. The platform can now autonomously test web applications and identify attack paths that chain application vulnerabilities, credential theft, lateral movement, cloud access, and data exposure. Web applications have never been more exposed or more critical to secure. The rapid deployment of “vibe-coded” applications built…

AttackIQ targets CTEM execution with AVA Agentic OS

AttackIQ has announced AVA Agentic OS, an agentic operating system designed to operationalize Continuous Threat Exposure Management. CTEM has emerged as the strategic framework for managing cyber risk, yet many organizations continue to struggle to operationalize CTEM across fragmented security technologies, disconnected workflows, and manual processes. Security teams have invested heavily in tools that identify…

Resecurity expands threat intelligence integration ecosystem with IBM QRadar

Resecurity has announced the availability of native integration with IBM QRadar SIEM, a widely used Security Information and Event Management (SIEM) platform used by the leading Fortune 100 corporations worldwide. The plugin is available for activation via IBM Application Exchange. The integration leverages open standards STIX and TAXII (including version 2.1) to ingest, normalize, and…

SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign

SilverFox targeted a Japanese manufacturer with new DLL sideloading techniques, kernel drivers, and resilient ValleyRAT persistence mechanisms. Cato CTRL documented a new SilverFox campaign targeting a Japanese industrial manufacturer. The attack chain adds two previously undocumented DLL-sideloading hosts, two kernel drivers not previously associated with SilverFox, and a dual-layer recovery architecture that keeps ValleyRAT running…

News alert: OpenMatter proposes verification architecture for securing autonomous AI systems

MELBOURNE, Fla., July 30, 2026, CyberNewswire – The growing number of high-profile AI security incidents making headlines around the world are not simply cybersecurity failures. They are architectural failures, according to OpenMatter Network Co-Founder and CEO Renee Davis. “Recent incidents involving increasingly autonomous AI systems – including OpenAI’s widely reported cyber evaluation that resulted in…

Companies push AI, sysadmins keep it on a short leash

In 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response within two years. Action1’s 2026 Survey Report: AI Impact on Sysadmins found that those expectations proved overly optimistic. The largest shortfalls appeared in high-impact operational and security functions, where AI needs to understand business context, system dependencies, risk,…

New infosec products of the week: July 31, 2026

Here’s a look at the most interesting products from the past week, featuring releases from BlackCloak, Contrast Security, Dropzone AI, PortSwigger, Realm Security, Reco, Root Evidence, and ZeroFox. BlackCloak extends deepfake protection to the executive’s trusted circle Deepfakes have made one of our oldest assumptions unreliable: that you can trust a familiar face or voice.…