Geek-Guy.com

As White House monitors latest OpenAI incident, Congress eyes an AI ‘kill switch’ for DHS

The White House is monitoring developments after OpenAI revealed earlier this week that one of the company’s AI systems went beyond its intended parameters during a security test and managed to hack into the infrastructure of the AI platform Hugging Face. According to Reuters, presidential technology advisor Michael Kratsios has been briefed on the incident.…

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. “BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet

Coro Hires EMEA, Product and R&D Executives

Cybersecurity vendor Coro has appointed three executives to lead EMEA sales, product strategy, and research and development as the company pursues international and channel growth. New executives take charge of EMEA, product, and R&D Among the hires are: Ingo Schaefer as Vice President of Sales, EMEA Dor Avrahami as Vice President of Product Itzik Schacher…

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync.

Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

Hunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence. Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a live cyber-espionage operation. Instead of recovering malware after the fact, the team found exposed staging servers…

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim’s organization. The vulnerability has been codenamed AgentForger by Zenity Labs. The issue has since been addressed by OpenAI as of…

Top AIs invent same fake PyPl and npm package names

Enterprise software developers continue to be in danger of falling victim to slopsquatting, where AI coding tools hallucinate the existence of nonexistent libraries and hackers create malicious packages in response. The top AI coding tools are remarkably consistent in their hallucinations: Researcher Aleksandr Churilov found the same 127 fake package names generated by five different…

Email threats changed after the Tycoon2FA take-down

Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”. “Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March…

Tycoon2FA takedown reshapes the phishing landscape

Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”. “Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March…

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential

UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations

UAC-0099 delivers malware via a fake Notepad++ plugin after phishing, using a loader that sabotages itself if run without the correct arguments to hinder analysis. CERT-UA published a new advisory attributing a phishing campaign to UAC-0099, a Russia-aligned threat actor active since at least mid-2022 and previously known for exploiting WinRAR vulnerabilities and using phishing…

Microsoft tightens Windows enterprise activation security

Microsoft is making Trusted Platform Module (TPM)-backed attestation a requirement for Windows Key Management Service (KMS), the on-premises service used for Windows volume activation, replacing the software-only trust model with hardware-backed verification to strengthen enterprise activation security. Attestation will become mandatory with the next Windows Server Long-Term Servicing Channel (LTSC) release. How TPM-backed KMS attestation…

US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers

US agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers. The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI) and other U.S. government and international partners published a joint advisory to warn that the Russia-linked APT…

Ingram Micro Partners Embrace Peer Collaboration

Channel partners accustomed to competing for customers, talent, and market share are increasingly turning to one another for help navigating technology shifts and improving their operations. At Ingram Micro’s recent Unplugged event, partners described exchanging technology strategies, leadership lessons, and even stories of failed business decisions with companies that might otherwise be considered competitors.  Those…

Kiteworks and A-LIGN Partner on CMMC Level 2

Kiteworks and A-LIGN have formed a strategic partnership to help Defense Industrial Base (DIB) organizations strengthen sensitive-data controls and prepare for CMMC Level 2 assessments, creating a new compliance-services opportunity for MSPs and MSSPs serving federal contractors. CMMC review creates uncertainty, not a compliance pause The announcement comes as the federal government conducts a 60-day…

Forcepoint Launches New AI Data Security Platform

As enterprises race to adopt generative AI, Forcepoint is introducing a new platform aimed at helping organizations—and the partners supporting them—govern how sensitive data is accessed, shared, and protected.  AI Data Security combines AI governance with data security controls to monitor sanctioned AI applications, shadow AI, and autonomous agents from a single platform. Forcepoint connects…

Keyfactor Expands Partner Program for PQC Services

Keyfactor, a trust infrastructure for AI and machines organization, has announced the expansion of its Global Partner Program. The partner program enhancement enables partners to build new advisory, implementation, and managed services for helping customers modernize digital trust as organizations prepare for the transition to post-quantum cryptography (PQC).  It will equip partners to deliver crypto-agility…

AI Pushes Cloud Advisory Toward Continuous Management

Artificial intelligence is accelerating cloud adoption, infrastructure demand, and spending, forcing enterprises to replace periodic optimization reviews with continuous management.  In this Q&A with Channel Insider, Joaquim Alfaro Camps, global director of cloud advisory and FinOps services at Syntax, explains how the shift is also changing the role of cloud consultants—giving them new tools to…

New infosec products of the week: July 24, 2026

Here’s a look at the most interesting products from the past week, featuring releases from Astelia, Druva, Swimlane, and ThreatDown. Druva brings backup, recovery and governance to AI workloads Druva has announced Druva AI Resilience, a new approach that helps organizations recover, govern, and defend the systems, activity, and context behind AI-powered work. The launch…