Geek Guy

Picus Blue Report Reveals Persistent Detection Gaps 

According to Picus’s Blue Report 2026, enterprise cybersecurity defenses improved in 2026.  However, organizations continue to struggle with detecting stealthy attacker behavior and converting security telemetry into actionable alerts.  The report analyzed more than 338 million simulated attacks conducted in Picus customer environments between January and June 2026.  Picus measured how effectively existing security controls…

A Vulnerability in Zoom Clients Could Allow for Remote Code Execution

A vulnerability has been discovered in Zoom Clients that could allow for remote code execution. Zoom is a cloud-based communications platform that allows users to connect via video, audio, chat, and content sharing. Successful exploitation could allow an attacker to target meeting participants, execute code without user interaction, steal data, activate cameras or microphones, and…

Veracode Finds AI-Generated Code Still Struggles With Security 

Generative artificial intelligence (GenAI) has rapidly changed software development by allowing developers to generate functional code faster and at greater scale.  However, Veracode’s 2026 GenAI Code Security Report reveals a disconnect between improvements in AI coding capability and improvements in security.  Although modern large language models (LLMs) can produce syntactically correct code almost perfectly, their…

“Zoomsday” flaws could let one Zoom participant attack another

Researchers have found three vulnerabilities in the popular Zoom meeting platform that could let one meeting participant attack another through malicious collaboration data. The vulnerabilities, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, affect the code Zoom uses to process annotation data shared during meetings. The researchers named the set of flaws “Zoomsday.” Affected applications are: Zoom…

Patch Tuesday: Update now to fix 421 flaws, including three zero-days

Microsoft’s August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical. One Windows vulnerability has been exploited in the wild by the Lazarus group to gain SYSTEM privileges. The August update is smaller than July’s record-breaking release, but it’s still among Microsoft’s largest Patch Tuesday batches. More importantly, it includes several flaws likely…

Signal’s new security feature checks if your encrypted chats were tampered with

Signal has introduced a feature called automatic key verification, giving users a new way to confirm that nobody has secretly interfered with their encrypted chats. “Signal is always end-to-end encrypted, and automatic key verification provides an additional, streamlined way to confirm that there’s no unexpected party between you and the other ‘end’ of an end-to-end…

ScienceLogic delivers secure AI deployment and smarter IT operations with Skylar AI 2.5

ScienceLogic has announced Skylar AI 2.5, expanding secure deployment options for organizations with stringent security, sovereignty, and compliance requirements, while introducing enhancements that strengthen AI performance, operational intelligence, and enterprise integrations. The release further improves AI accuracy, platform performance, and natural language user experience across the ScienceLogic AI Platform. Serving as the intelligence layer of…

Deloitte strengthens AI governance to support trusted enterprise adoption

Deloitte has expanded AI Controls and Assurance services and solutions designed to help organizations confidently adopt, scale and govern AI across the enterprise. From early exploration to enterprise deployment, Deloitte’s enhanced services provide end-to-end support across the AI lifecycle, combining advisory and assurance services across governance frameworks and AI-enabled transformation to help organizations manage risk…

CVE-2026-68820: Actively Exploited Windows AFD.sys Zero-Day Enables SYSTEM Privilege Escalation

Microsoft’s August 2026 Patch Tuesday addresses hundreds of security vulnerabilities, but one issue stands out because attackers were already exploiting it before a fix became available. CVE-2026-68820 is a high-severity elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock, or AFD.sys, that can allow a local attacker to escalate privileges to SYSTEM. The flaw…

7 Best SIEM Tools & Software for 2026

Security information and event management (SIEM) solutions help organizations collect and analyze data across IT and cybersecurity systems to detect threats, investigate suspicious activity, and manage security risks. The best SIEM solutions also support real-time monitoring, compliance requirements, and faster incident response by giving security teams greater visibility into their environments. To help you find…

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models’ Reasoning

A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the providers’ reasoning APIs, where a block created in one session could be replayed…

Fake CCleaner downloads turn Chrome into a credential-stealing surveillance tool

A convincing fake version of the widely used CCleaner utility is being used to deliver a multi-stage Windows malware that ultimately abuses Google Chrome for credential theft and surveillance. Researchers from Malwarebytes found the campaign distributing a malicious Chrome extension called GhostDesk, which can capture credentials, cookies, keystrokes, and screenshots while also allowing attackers to…

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below – CVE-2026-48362 (CVSS score: 10.0) – An operating system command injection vulnerability in ColdFusion that could

Zaelab Joins Anthropic as Enterprise AI Delivery Partner

Zaelab, a digital consultancy for complex enterprises modernizing CX and revenue operations, has been selected by Anthropic as a delivery partner to help enterprises turn AI pilots into production-ready solutions. Zaelab targets the AI pilot-to-production gap This combination will bring together Zaelab’s enterprise delivery experience with Anthropic’s Claude models, helping organizations move AI from proof…

OpenAI Launches GPT-5.6-Cyber for Advanced Defensive Security Testing

OpenAI has released GPT-5.6-Cyber, a cybersecurity-specific model designed to handle advanced defensive work that general-purpose models often refuse, including exploit validation, vulnerability research, and exploit-chain development. The model is available through Daybreak Red, a restricted access tier for vetted defenders conducting authorized security testing. In OpenAI’s internal testing, GPT-5.6-Cyber completed 95% of advanced cyber requests,…

Pipefy: AI Governance Expands the Channel Partner Role

As enterprises accelerate AI adoption, fragmented tools, inconsistent governance, and disconnected workflows are creating new operational challenges—and expanding the role of channel partners. Sandro Guedes, global director of partnerships at Pipefy, said partners are increasingly being called on not just to sell AI technologies, but to help customers integrate them, establish governance, and drive adoption…

Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and three that were publicly disclosed prior to the release of the patches. Vulnerabilities of note CVE-2026-68820 is a use-after-free flaw that affects the Windows Ancillary Function Driver for WinSock (AFD.sys) and allows a…

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for…

ConnectSecure helps MSPs automate Microsoft 365 security remediation

ConnectSecure has announced that Microsoft 365 Auto Remediation and AI-powered Training Assessments are now live on the ConnectSecure platform. The capabilities help managed service providers (MSPs) address supported M365 security findings, create and measure assessments, support client training and strengthen security posture from one platform. The launch advances ConnectSecure’s focus on proactive, unified protection for…

4 gaps slowing AI in enterprise SOCs

Artificial intelligence (AI) has quickly become a strategic priority for enterprise security teams. Yet despite growing investment in AI-driven security software, many enterprise SOCs are struggling to translate AI into measurable operational improvements. The issue isn’t whether AI belongs in the SOC. It does. The challenge is that many organizations are approaching AI adoption in…

CBTS brings continuous penetration testing to enterprise security

CBTS has launched Penetration Testing as a Service (PTaaS), combining autonomous penetration testing with security expertise to help organizations continuously identify exploitable risks, validate attack paths, and prioritize remediation as their environments evolve. Cloud environments, SaaS applications, connected systems, third-party relationships and AI systems are expanding enterprise attack surfaces faster than traditional testing cycles can…

Crytica’s RDAi detects OT device tampering from within

Crytica Security has developed a patented solution that delivers rapid, deterministic threat detection for operational technology (OT), protecting the embedded systems and connected devices that underpin critical infrastructure, national security, and healthcare without disrupting operations. The need is becoming increasingly urgent as cybersecurity moves toward machine speed. IBM’s Cost of a Data Breach Report 2026…

Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily

Google Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious websites, helping reduce scams, phishing attempts, and other deceptive content. Abusive notifications (Source: Google) Chrome revokes notification permissions for websites users have not recently interacted with and for sites that Google Safe Browsing identifies as engaging in…

ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch

Chaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day that bypasses the CVE-2026-50656 patch and could enable SYSTEM-level code execution. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a PoC for ShieldBreak, a Microsoft Defender zero-day. The flaw bypasses the patch for CVE-2026-50656 (RoguePlanet), a race condition that…

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential…

Intelligence-Driven SOC: Modernizing Threat Monitoring and Detection Engineering for Ultimate MTTR Reduction

Threat monitoring serves as the vital connective tissue of modern security operations. It ensures that every function from triage to response operates effectively. To meet evolving threat challenges, SOC teams and MSSPs must transition from simple log collection to a proactive, intelligence-driven framework. ANY.RUN’s Threat Intelligence provides the essential solutions to power this transformation across…