Geek Guy

Microsoft’s EvilTokens takedown sheds light on state of AI-powered cybercrime

Microsoft has hailed its success in disrupting EvilTokens, an AI-powered a phishing-as-a-service (PhaaS) platform linked to more than 12,000 compromised Microsoft 365 inboxes across more than 10,000 organizations worldwide. Since February 2026, EvilTokens has offered a subscription platform combining account compromise, mailbox analysis, target selection, and fraud preparation. Its dashboard and chatbot centralized access to…

Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects

Volexity researchers spotted another state-aligned Chinese threat group exploiting a triple-link chain of zero-day vulnerabilities across multiple campaigns, the company said in a blog post Monday. The threat group it tracks as UTA0565 exploited the vulnerabilities in Chrome and Microsoft between Sept. 3 and 4 before the defects were disclosed or patched, researchers said. The…

Salesforce, Microsoft Signal New Enterprise AI Shift

Enterprise AI is moving beyond copilots and experimentation toward redesigning how work actually gets done. In this edition of Channel Insider’s Inside the Headlines, we break down two developments pointing toward that shift: Salesforce and Nvidia’s Koa reasoning model for Agentforce CRM workflows, and Microsoft’s Frontier Playbook for enterprise AI transformation. For channel partners, the…

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

Cybersecurity researchers have disclosed details of a malicious npm package named “tw-pkgprobe-7731” that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named “tw-pkgprobe-7731,” was first uploaded to the npm registry in mid-August 2026 by an npm account named “twdepprobe7731.”

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) “at every step of the attack chain.” The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud,…

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is

Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates

A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in

Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud

Microsoft, along with a group of industry partners, disrupted EvilTokens, a short-lived but highly consequential cybercrime platform that investigators linked to more than 12,000 compromised Microsoft customer email inboxes across more than 10,000 organizations globally, the company said Tuesday. Acting on federal court order Sept. 15, Microsoft and partners seized 50 websites the phishing-as-a-service used…

Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk

Chinese artificial intelligence company Z.ai had to disable several features of its ZCode coding assistant this week after a default setting was caught sending users’ local code repositories to Alibaba Cloud servers in China without their consent, raising fresh concerns for enterprises over how AI tools handle sensitive source code. The company apologised and said…

Aviatrix Launches Quantum Harvest and Decrypt Protection Solution

Aviatrix is launching Harvest and Decrypt Protection, a cloud security offering that combines post-quantum encryption with workload communication governance to help enterprises limit both future quantum decryption risk and the paths attackers can use to exfiltrate data today.  The software applies both controls through a single policy and enforcement point across cloud environments. Aviatrix combines…

Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day

The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit BigDiskBuster, it triggers a Denial of Service Vulnerability in Windows Defender Update. The security researcher…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

Ireland Fines Google €403 Million for Violating GDPR Location Rules

Google just got a reminder that location tracking requires more than buried privacy controls. Ireland’s Data Protection Commission slapped Google with a €403 million ($462 million) penalty on Monday, ruling that the search giant broke European Union privacy laws by misleading users and mishandling how it tracked their physical whereabouts. The decision marks the watchdog’s…

The next intellectual property thief may sound like your CEO

Impersonation, phishing and domain-name abuse are the most concerning types of online intellectual property infringement, according to CSC’s The State of Online IP Risk 2026 report. Internet and branded content, online marketplaces and paid search were the channels most frequently targeted. CSC surveyed 300 senior executives specializing in intellectual property law during the second quarter…

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been

CSuite Targets US and EU Organizations with Device-Code Phishing and Remote Access

ANY.RUN researchers investigated CSuite, a phishing and remote-access operation that combines credential theft, Microsoft 365 session hijacking, and the abuse of legitimate management tools. The campaign showed a strong US focus, with 60% of identified victim organizations based in the United States. By blending trusted business services with legitimate remote-access software, CSuite can give attackers…

Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor

Mac security researcher Patrick Wardle says it’s trivial to turn Muse into “the ultimate backdoor.” Increasingly, AI assistants are changing from tools that simply answer questions into agents that can plan tasks, use connected services, and take actions for us. These actions might include booking appointments, filling out forms, creating documents, making purchases, or interacting…

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)

A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated sensitive data from 996 devices across 48 countries, GreyNoise reported on Monday. The affected switches are predominantly located in Italy, the US, Taiwan, South Korea, and a number of EU countries. CVE-2026-7273 exploitation is part of…

North Korean Hackers Hide Mac Backdoors in Fake Terraform Job Tests

A routine Terraform command is becoming an entry point for North Korean hackers targeting developers. TraderTraitor, a DPRK-linked threat actor, is using weaponized infrastructure projects disguised as job interview assignments, with malicious providers that can execute when a candidate runs terraform init. SentinelOne also found the group’s FLATROOF and ROOFDECK macOS backdoors on an Apple…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

A malicious npm package named “indexed-btree” has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls. “Indexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree/indexing utility,” Checkmarx said. “

U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Zyxel GS1900 Series Switches flaw, tracked as CVE-2026-7273 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a stack-based buffer overflow that could allow attackers…

August 2026 Cyber Attacks Statistics

August 2026 statistics report breaks down 218 confirmed cyber incidents by motivation, attack vector, initial access technique, and target sector. Financially motivated Cyber Crime drove more than 4 in 5 attacks, Malware remained the weapon of choice, and Information & Communication infrastructure bore the brunt of targeting across 70 countries.

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. “SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols,” Trellix researchers

Contagious Interview: 30,000 devices infected by a fake job interview

North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview. On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as Contagious Interview.…

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating

Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit

By the second half of 2026, national competent authorities across the EU are actively reviewing NIS2 compliance documentation. Under Article 20(1) of the directive, senior management at essential and important entities can be held personally liable for infringements — a detail that tends to concentrate executive attention. ENISA’s 2025 NIS Investments report found that 34%…

From Payment Plan to Ransomware – Inside a Global Group Attack

By: Iris Suaner, Cofense Phishing Defense Center Highly sophisticated ransomware now targets industries worldwide. Today’s ransomware allows threat actors to infiltrate networks, encrypt confidential data, and hold critical systems hostage until a cryptocurrency ransom is paid. Worse, threat actors often employ “double extortion” techniques by stealing sensitive company data and threatening to publish data publicly…