Geek Guy

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below – CVE-2026-63688 (CVSS score: 10.0) – A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an

Heimdal Extends European MSP Security Reach Into DACH With Elovade

Heimdal is expanding its MSP security reach across Germany, Austria, and Switzerland through a broader distribution agreement with Elovade. Under the deal, Elovade will distribute Heimdal’s security platform to partners across the DACH region, extending a relationship the companies already use in other European markets. Regional MSPs will ultimately judge the rollout by how cleanly…

MegazoneCloud, Portal26 Target Shadow AI in Korea

AI and cloud company MegazoneCloud has signed a strategic reseller agreement with Portal26 to bring the U.S. company’s generative AI governance and security platform to enterprise customers in Korea. Under an agreement signed September 28, MegazoneCloud will resell Portal26’s AI Adoption Management Platform and provide technical support, while the companies develop governance and security offerings…

Fal.Con 2026: Comprehensive Market Intelligence Report 2026

eCrime Actor Activity 3. Falcon Guardian — Technical Architecture Deep Dive Core Capabilities Capability Description AI Agent Discovery & Inventory Continuously discovers known and shadow AI agents across Windows, macOS, Linux endpoints. Identifies deployment origin, usage patterns, and security status. Agent Runtime Visibility Connects AI agent behavior directly to Falcon endpoint telemetry; establishes a causal…

A Vulnerability in Fortinet FortiMail Could Allow for Arbitrary Code Execution

A vulnerability has been discovered in Fortinet FortiMail that could allow for arbitrary code execution. Fortinet FortiMail is a secure email gateway that protects organizations from inbound threats including spam, phishing, malware, and business email compromise, while also preventing outbound data loss across physical, virtual, and cloud deployments. Successful exploitation of this vulnerability could allow…

Protected Quick Tunnels: simple accountless authentication for your next dev project

We launched Quick Tunnels in 2021 to give developers an easy way to share their latest service, application, or project running in their local development environment. A lot has changed since then, but the core use case remains the same. Your coding agent has just finished the feature. The dev server is up on localhost:5173, and…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. “We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information,” a spokesperson for the company was quoted as saying. “Our investigation…

BlueVoyant Launches Microsoft ISOC Deployment Service

BlueVoyant has launched a Microsoft Defender XDR ISOC Deployment Service to help organizations prepare their security operations environments for Microsoft’s push toward more integrated, agent-driven security. The service is designed for Microsoft 365 E5 and E7 customers and Microsoft Defender Suite users, with a focus on assessing existing deployments, configuring underlying security technologies, and operationalizing…

EU Cyber Resilience Act ‘completely kills’ manual vulnerability triage

Independent security experts see the EU Cyber Resilience Act (CRA) reshaping international technology markets to emphasize cyber resilience from the ground up, thereby testing the operational capacities of technology vendors whose wares compete in those markets. The EU CRA introduces mandatory reporting within 24 hours for any actively exploited vulnerabilities or severe incidents affecting products…

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

Google has announced a new security measure that limits access to Android’s accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway.…

Investigators trace an AI agent ‘s path from research task to reconnaissance

Asymmetric Security traces rogue OpenAI AI agent activity that probed government sites, accessed staging servers, and evaded sandbox limits. Researchers at Asymmetric Security spent 48 hours over the last weekend reconstructing reported rogue OpenAI AI agent activity that hit the Australian government and other organizations between March and September this year. They worked from public…

Criminal recruiters want people on your payroll

Legitimate employee access can let criminals circumvent security controls that would be difficult to overcome from outside an organization. Routine actions such as information lookups, account resets, transaction approvals and shipment changes can become services sold to criminal customers, according to Intel 471’s Insiders for Hire: Underground Recruitment, Access Claims and Insider-Enabled Services report. A…

U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Fortinet FortiMail flaw, tracked as CVE-2026-104286 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a path traversal vulnerability that can be triggered through…

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. “An improper

Omnissa delivers a peek into the benefits of breaking through enterprise data silos

When Omnissa this week rolled out a new AI governance authority product, Elara, in beta, it delivered a glimpse into the potential of having visibility between the typical enterprise’s data silos, whether they’re in lines of business, disparate geographies, or corporate operational units. “By connecting signals across systems that often operate independently, Elara gives IT…

CISA Certification Explained: Skills, Career Opportunities & CISA Training Options from InfosecTrain

In this post, I will discuss the CISA certification. When an organisation needs to know whether its technology, controls and business systems are doing what they are supposed to, it turns to information systems auditors. ISACA’s Certified Information Systems Auditor certification confirms that a professional has the skills this work demands, and it is recognised…

A Vulnerability in Kiteworks EPG (Email Security Gateway) Could Allow for Arbitrary Code Execution

A vulnerability has been discovered in Kiteworks EPG (Email Security Gateway) that could allow for arbitrary code execution. Kiteworks Email Protection Gateway (EPG) is a cloud-based security solution that automates end-to-end encryption, decryption, and policy enforcement for inbound and outbound enterprise emails. A combination of input-handling flaws in publicly reachable endpoints of the Kiteworks Email…

National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations

Collaboration with industry is key to balancing AI security risks and benefits, as well as staying ahead of China and other adversarial nations, National Cyber Director Sean Cairncross said Thursday. The Trump administration is facing pressure from some quarters of Capitol Hill and even some artificial intelligence executives to establish regulations or embrace legislation to…

DeepSeek, Huawei Expand Software Support for Ascend AI Chips

DeepSeek is expanding its work with Huawei, releasing open-source software designed for the Chinese tech company’s Ascend processors. DeepSeek’s Sept. 30 releases and updates extend Ascend support across six open-source projects covering low-level operations needed to build and optimize AI workloads. The release moves their collaboration further into the software layer around AI infrastructure. For…

Give yourself room to be human

Welcome to this week’s edition of the Threat Source newsletter.  Fall is officially here in Maryland, and I can’t be more relieved. I flourish in 50 degree weather, where it feels natural to burrow under blankets, knit sweaters, and listen to an audiobook.  Beyond that, though, can I say that I’m glad fall is here…