Geek Guy

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2025-39682 – Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability CVE-2025-39964 Linux Kernel Race Condition Vulnerability CVE-2026-53266 Linux Kernel…

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor   Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot…

Week in review: Cisco patches exploited email gateway 0-day, Revolut breach

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What we know about the Revolut data breach so far Someone impersonating a government agency, using an email address on that agency’s domain, obtained sensitive customer records from Revolut. The bank confirmed the incident on Saturday, September 12. DeepZero: Open-source…

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. “Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below – CVE-2025-39682 (CVSS score: 9.8) – An improper check for unusual or exceptional conditions vulnerability in the TLS receive path

Sponsor: SACR Sponsored by:
Software Analyst Cyber Research
Deeper Network Promo Image

Druva Adds Ransomware Detection to Cut False Positives

Druva is expanding its cyber recovery portfolio with new ransomware detection and identity resilience capabilities designed to help security teams validate attacks faster, reduce false positives, and identify clean recovery points before restoring data. The company’s new Ransomware Detection capability analyzes backup snapshots for high-risk ransomware behavior and then applies additional forensic validation to determine…

What GTIA’s ASCII Group Acquisition Means for Partners

The Global Technology Industry Association (GTIA) has acquired The ASCII Group, expanding its member community while increasing investment in the programs, resources, and experiences that support IT service providers (ITSPs). The acquisition brings together GTIA’s leadership in research, education, cybersecurity, and industry strategy with The ASCII Group’s business tools and peer-driven community model. “We’ve been…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

UltraViolet Cyber Launches Equinox for Detection Gaps

UltraViolet Cyber has launched Equinox, an AI-assisted detection engineering platform designed to identify gaps across customers’ existing security tools and expand mapped threat coverage without adding unnecessary alert volume. Equinox maps customer-specific detection gaps In its official announcement, UltraViolet Cyber highlighted how security teams may have thousands of detections available across their security information and…

StorMagic, Mako Networks Link Edge HCI and SD-WAN

StorMagic and Mako Networks are integrating edge hyperconverged infrastructure with secure SD-WAN in a new partnership aimed at businesses operating across large numbers of distributed locations. The agreement combines StorMagic SvHCI, which provides edge compute, storage, and virtualization, with Mako Networks’ secure SD-WAN and cloud-managed networking platform.  The companies say the integration is designed to…

Brevo Supply-Chain Attack Infected Over 100,000 Websites

A Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over 100,000 sites. Brevo, formerly known as Sendinblue, is a French cloud-based marketing and customer communication platform whose clients include eBay, Louis Vuitton and Michelin. The company was first compromised on September 10, when attackers exploited a vulnerability in its…

Arrow Electronics, Usercentrics Sign EMEA Distribution Deal

Arrow Electronics is expanding its privacy and consent management portfolio through a new distribution agreement with Usercentrics, bringing the company’s Cookiebot CMP to channel partners across eight European markets. The agreement covers Austria, France, Germany, Italy, Portugal, Spain, Switzerland, and the U.K., giving Arrow partners another platform to help customers manage consent requirements and navigate…

MDR vs MXDR vs Managed SOC: Key Differences

The main difference among MDR, MXDR, and a managed SOC lies in scope. MDR provides managed threat detection and response; MXDR correlates detection and response across multiple security domains; and a managed SOC can operate a broader set of security functions, including monitoring, tool administration, detection engineering, reporting, and compliance support. Choosing between them depends…

International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data

North Korean hackers are infiltrating tens of thousands of job seekers’ computer networks by posing as prospective employers, such as artificial intelligence firms, to steal sensitive information and millions of dollars worth of cryptocurrency, U.S. and allied governments warned Friday. The security agencies behind the alert, attributed the group, known as WaterPlum or Contagious Interview,…

A zero-click RCE flaw in AI coding agents could have exposed enterprise systems

Popular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned GitHub Copilot were vulnerable to a zero-click attack that enabled attackers to execute malicious code, even without developer interaction, by swapping a trusted plugin from an online marketplace for a malicious one, potentially giving them a foothold in enterprise…

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed…

Zero-Days, AI Agents, and Massive Data Leaks Define the Week

This week’s cybersecurity landscape combined actively exploited vulnerabilities, AI-assisted attacks, exposed credentials, trusted-channel phishing, and breaches affecting millions of people. Defenders face an increasingly compressed response window as automation accelerates exploitation and compromised infrastructure gives attackers new ways to evade user suspicion. Major Threats & Vulnerabilities Actively Exploited Zero-Days and Critical Flaws WooCommerce plugin exploitation:…

AI Infrastructure Gaps Open New Opportunities for Partners

As enterprises push artificial intelligence projects beyond pilots and into production, infrastructure limitations are becoming harder to ignore—and creating a new opening for channel partners. Dennis Frank, Vice President, EMEA Strategic Partners & Alliances at Hitachi Vantara, spoke with Channel Insider about why storage, data pipelines, and governance are emerging as critical AI bottlenecks, how…

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. “Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a…

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People’s Republic of Korea’s (DPRK) Contagious Interview campaign: BeaverTail and

Bots with good manners are better at fooling people on social media

Most people can’t tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study. The company analyzed 1,722 participants worldwide, testing their ability to separate human comments from AI-generated ones in a social media setting. Overall, people caught just 40% of…

Sponsor: SACR Sponsored by:
Software Analyst Cyber Research
Deeper Network Promo Image

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. “The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,”