Geek Guy

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. “Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses

Cisco patches max-severity ISE flaw, the second critical zero-day this week

Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network control and policy enforcement. This is the second zero-day flaw Cisco has been forced to release emergency patches for this week, after fixing a critical vulnerability in its Secure Email Gateway…

Sponsor: SACR Sponsored by:
Software Analyst Cyber Research
Deeper Network Promo Image

Cisco alerts customers to second actively exploited zero-day in as many days

Cisco disclosed its second actively exploited zero-day vulnerability in as many days, presenting its customers with back-to-back threats to address in unrelated products. The latest zero-day — CVE-2026-76460 — has a maximum-severity rating and was exploited before Cisco disclosed and patched the vulnerability Wednesday. The defect in an API of Cisco Identity Services Engine (ISE)…

CVE-2026-76460: Critical Cisco ISE Zero-Day Authentication Bypass Exploited in the Wild

Cisco has released emergency security updates for a maximum-severity vulnerability affecting Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) after confirming active exploitation in the wild. Tracked as CVE-2026-76460 and rated 10.0 on the CVSS scale, the flaw allows an unauthenticated remote attacker to bypass authentication and gain unauthorized access to a vulnerable…

CVE-2026-87886: Acronis Backup Plugin Privilege Escalation Flaw Exploited in Targeted Attacks

Acronis has disclosed a high-severity Linux privilege-escalation vulnerability affecting its Backup integrations for cPanel & WHM and Plesk after detecting exploitation in targeted attacks. Tracked as CVE-2026-87886 and rated 7.8 on the CVSS scale by Acronis, the flaw stems from insecure file permissions and can allow an authenticated attacker with limited privileges to increase their…

Europe’s Biggest AI Data Centers: Where They’re Being Built and How They’ll Be Powered

Europe’s biggest AI data centers are going where the power is. France, Portugal, Finland, and Norway are attracting some of the continent’s largest planned AI campuses as developers seek sufficient electricity, land, connectivity, and cooling to support hundreds of megawatts of computing capacity. The projects show how energy availability is starting to reshape Europe’s traditional…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

Multiple Vulnerabilities in Oracle Products Could Allow for Arbitrary Code Execution

Multiple vulnerabilities have been discovered in Oracle products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs;…

OpenAI admits six new misalignment incidents under new reporting framework

OpenAI has published six new reports detailing AI model misalignment, including instances of hidden instructions, unauthorized communication, and attempts to locate exposed API keys, adding to the evidence that its AI systems bypassed controls during testing. The reports, based on internal evaluations, describe models taking actions beyond defined constraints, including modifying intermediate outputs, interacting with…

SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets

Hunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia. Hunt.io and researcher Guy Yasur have traced a tight cluster of SpiceRAT command‑and‑control servers that predate and extend Bitdefender’s August 2026 SilkParasite report. The work doesn’t dissect malware samples; it maps the network side of the…

Revolut phishing texts appear days after data breach

Only days after Revolut acknowledged that it disclosed sensitive customer records to an unauthorized party, affected customers are receiving phishing texts. However, we don’t know yet if the phishing texts are linked to the breach. The company had accepted fraudulent information requests sent from an email address on a legitimate government agency domain. Through this social engineering attack,…

Sponsor: SACR Sponsored by:
Software Analyst Cyber Research
Deeper Network Promo Image

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

The Iran-linked “hacktivist” persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. “HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading,

Authorities seize popular, long-running DDoS-for-hire service domains

Authorities seized the primary domain and other websites linked to NightmareStresser, one of the longest-running and most popular distributed denial-of-service operations used by cybercriminals globally, the Justice Department said Tuesday.  Cybercriminals of various motivations used the DDoS-for-hire service to launch hundreds of thousands of DDoS attacks or attempted attacks since at least 2022, officials said. …

Splunk Competitive Report

Executive Summary Splunk (Now part of Cisco) is a leading provider of data platform and analytics software, with its flagship product Splunk Enterprise being one of the most mature and feature-rich SIEM (Security Information and Event Management) platforms in the market. The company has evolved from a pure-play security vendor into a comprehensive data analytics…

Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE

Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain and the UAE. In two updates posted September 15, AWS said it can no longer recover customer data and resources stored in its Middle East (Bahrain) region, known as…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys

Cyber deception has long been the domain of well-resourced security teams, but CISA’s latest guidance, titled “Using Cyber Decoys to Strengthen Detection and Response”, is an attempt to try and change that. Why decoys, and why now The core problem CISA is attempting to address is that many organizations are incapable of detecting adversaries who…

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642,…

Druva expands identity resilience with ransomware detection

Druva has announced new capabilities for Druva Identity Resilience alongside the launch of Ransomware Detection, a new feature fueled by a proprietary AI threat pipeline. Powered by Dru MetaGraph, the new offerings use behavioral intelligence and built-in validation to turn suspicious behavior into actionable evidence, definitively confirm impact, and accelerate precise containment and clean recovery.…

Fake MRI Scans Deliver CHOSEN BRICK Spyware to Windows PCs

Medical results are becoming part of a highly targeted malware lure. Iranian state cyber actors are disguising CHOSEN BRICK spyware as MRI files and familiar software to compromise Windows PCs. The UK’s National Cyber Security Centre, the FBI, and the Netherlands’ General Intelligence and Security Service warned Sept. 15, 2026, that the campaign has targeted…

Sponsor: SACR Sponsored by:
Software Analyst Cyber Research
Deeper Network Promo Image

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirmed one more flaw is being targeted: CVE-2026-76460, an authentication bypass bug in an API of Cisco Identity Services Engine (ISE). About CVE-2026-76460 Cisco ISE is an identity-based network access control and policy platform. It checks connecting users’ identity, profiles devices…

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. “SparroWocky is a modular, C++ backdoor,” ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker…

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin’s AI use

Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat. In Japan, The Gentlemen was the most active ransomware group in the first half of 2026. Attackers continue to primarily target small- and medium-sized enterprises, with organizations capitalized at less…