Geek Guy

16-31 August 2026 Cyber Attacks Timeline

The second half of August 2026 brought 110 confirmed cyber incidents, with Cyber Crime once again the dominant motivation at 78% of attacks. Malware remained the weapon of choice, exploitation of public-facing applications (T1190) continued to lead initial access, and Information & Communication emerged as the hardest-hit sector. This timeline breaks down the period by…

Enterprise Threat Intelligence Buying Guide: How to Choose the Right Solution

Choosing an enterprise threat intelligence solution is about more than just data volume or integrations. The right provider should deliver relevant intelligence, fit existing workflows, and help security teams investigate threats faster. While SOCs may prioritize rapid investigation and enrichment at scale, MSSPs may focus more on multi-tenancy and customer separation. This enterprise threat intelligence…

The Blueprint for Operational Resilience: Navigating the Post-CPS 230 Reality

In this post, I will give you the blueprint for operational resilience by navigating the Post-CPS 230 reality. Data-breach notifications in Australia hit an all-time high in 2025, with a significant majority stemming from malicious attacks. In parallel, the Australian Prudential Regulation Authority’s (APRA) CPS 230 Operational Risk Management standard officially took effect in July…

Riverbed NPM 360 uses AI to predict and prevent network disruptions

Riverbed has announced new Riverbed intelligent network observability solutions that combine 360-degree network visibility with agentic AI to help network operations teams accelerate troubleshooting, identify root causes, predict emerging issues and increasingly prevent disruptions before they impact users. The new Riverbed Network 360 offerings natively integrate the powerful agentic AI capabilities of Riverbed IQ and…

Tuskira Vector brings autonomous red teaming to attack surface validation

Tuskira has announced Vector, its autonomous red teaming agentic capability, which identifies an organization’s exploitable attack surface by simulating what an attacker can do from outside it. Tuskira validates every external finding against the organization’s deployed compensating controls, the internal risks already reported by its security tools, and the architecture of its application and infrastructure…

AI is adding to the review load on open-source projects, many of them thinly funded

AI coding tools are making open source software harder to maintain and secure, according to six authors writing for the Association for Computing Machinery’s Technology Policy Council, among them Simson Garfinkel and Josiah Dykstra. The tools write code and find security flaws quickly. The maintainers who decide what enters a project’s official release still have…

The world must establish red lines for autonomous AI weapons

AI is transforming warfare and international conflict. Autonomous weapon systems pose a genuine threat to civilians. The war in Ukraine has become a proving ground for weapons that can navigate, identify targets, resist electronic countermeasures, and pursue and engage targets autonomously without the need for human control. That evolution should concern technology professionals, regulators, policymakers,…

Salesforce Debuts Koa, a CRM Reasoning Model Built on Nvidia’s Nemotron

Yesterday, Salesforce and Nvidia announced Koa, Salesforce’s first CRM reasoning model for Agentforce. Built on Nvidia’s post-training Nemotron 3 Super, Koa is designed to handle multistep CRM tasks such as updating sales opportunities, routing support cases, and scheduling follow-ups. Salesforce built the model using a proprietary synthetic dataset based on nearly three decades of CRM…

Salesforce Global Outage Hits Customers on Second Day of Dreamforce

Salesforce’s biggest annual conference was in full swing when customers around the world began struggling to access parts of its cloud platform. The Sept. 16 outage, which struck on the second day of Dreamforce 2026, affected Salesforce instances across multiple regions. Customers experienced severe delays, intermittent errors, and service outages as engineers investigated issues with…

CISA promotes a fresh way to deter cyberattackers: Lie to them

For the first time, the Cybersecurity and Infrastructure Security Agency is advising critical infrastructure owners and operators on how to set up phony systems, accounts and data to deceive would-be hackers into being distracted and discovered. The Wednesday guidance, “Using Cyber Decoys to Strengthen Detection and Response,” arose from internal discussions with CISA’s threat hunters…

BambooToken: The Malware That Speaks MQTT to Stay Under the Radar

Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietly control infected Windows and Linux machines. Most malware connects directly to a command-and-control…

LinkedIn fights for the right to tell customers when the feds want their data

Microsoft’s top lawyer argued Tuesday that legislators “must make secrecy [orders] the exception” in government subpoenas demanding information about LinkedIn users. LinkedIn, which is owned by Microsoft, is fighting what it calls overly broad subpoena demands from the US government, which sometimes come with secrecy orders that prevent LinkedIn from alerting customers whose information is…

LinkedIn fights for the right to tell customers when the feds want their data

Microsoft’s top lawyer argued Tuesday that legislators “must make secrecy [orders] the exception” in government subpoenas demanding information about LinkedIn users. LinkedIn, which is owned by Microsoft, is fighting what it calls overly broad subpoena demands from the US government, which sometimes come with secrecy orders that prevent LinkedIn from alerting customers whose information is…

Data Broker Radaris Loses Domains in Privacy Fight

The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

Oracle’s September patches put Fusion Middleware back in the hot seat

Oracle’s September 2026 Critical Security Patch Update has arrived with 673 new security patches spanning 17 Oracle product families, with Oracle E-Business Suite accounting for the largest share at 159 patches, followed by Fusion Middleware with 153. Of these, 19 E-Business Suite vulnerabilities and 78 Fusion Middleware vulnerabilities can be remotely exploited without authentication. Other…

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension. Once the extension was installed, it could access each product’s built-in AI with a single click. On…

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. Before the repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted. The worm stole repository secrets and source code for the

Revolut Data Leak May Trace Back to Compromised Italian Government Accounts

A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers. The Revolut data exposure may be part of a much broader cyber incident involving compromised Italian government infrastructure. Revolut has confirmed that its systems were not breached. Instead,…