Geek-Guy.com

AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems

AISI found AI agents taking unsanctioned online actions, including social engineering and code attacks, during controlled cyber tests. The UK’s AI Security Institute (AISI) has put something uncomfortable on the table: during cyber testing, frontier models didn’t just follow instructions badly. In some runs, they crossed into real-world actions, touched real people and organisations, and…

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a…

From 2 weeks to 2 minutes: Amazon Cognito launches Provisioned limits for self-service rate limit management

Imagine preparing for your biggest sales event of the year, and you want to ensure your customer identity management service can handle the elevated traffic for carrying out application activities. For security teams, business leaders, and technologists managing identity infrastructure at scale, this scenario has been all too familiar. Whether you’re a CISO evaluating security…

Trustifi Expands Microsoft 365 Security for MSPs

Trustifi is expanding beyond email security with a new platform designed to help managed service providers detect threats, enforce data-loss prevention policies and investigate incidents across Microsoft Teams, OneDrive and SharePoint. The company’s new Collaboration Shield platform applies Trustifi’s security and compliance capabilities to Microsoft 365 collaboration workloads, where employees increasingly exchange sensitive files and…

Cynomi and SPECTRA Partner to Help MSPs Prove Security Value

Cynomi has announced a strategic partnership with SPECTRA, the MSP certification and cyber resilience warranty platform.  The partnership gives Cynomi partners a direct, in-platform path to SPECTRA Certification, allowing them to validate the security services they deliver, offer warranty-backed protection to clients, and potentially reduce cyber insurance costs for both MSPs and their customers. Demonstrating…

Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals

Brown Health Medical Group-MA breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. Brown Health Medical Group-MA data breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. The healthcare group identified a data security breach involving a legacy file server on…

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access to Anthropic’s large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. “Advertisements for Poison Claude

U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-9198 (CVSS score of 9.8) IBM Langflow Code Injection Vulnerability CVE-2026-18556 (CVSS score of 8.2) N-able N-central Authentication…

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam’s console that hands over a managed agent’s credentials, rated 9.5 A cross-tenant flaw in HashiCorp’s MCP server that lets one user’s Terraform token be reused…

Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses

Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm package “bianira-ui” and “fluid-type-ui,” has been codenamed NullReceiver by

Tenable broadens AI visibility across major LLMs and AI tools

Tenable has announced enhanced AI security capabilities within the Tenable One Exposure Management Platform. Tenable One AI Exposure now delivers expanded platform coverage with support for Google Gemini, extending its coverage across major LLMs: Google Gemini, Anthropic Claude, OpenAI ChatGPT Enterprise and Microsoft Copilot. The release also extends discovery to all major Model Context Protocol…

ArmorCode enhances attack path analysis with new AI agents and Context Risk Graph

ArmorCode has announced a major expansion of its Agentic Control Plane. Four new Anya AI agents help security teams analyze cloud risks, assess vulnerability exploitability, identify mitigation strategies, and coordinate patch orchestration. It also unveiled new Context Risk Graph capabilities for expanded attack path analysis, network reachability and patch management. These enhancements help security teams…

Open-source software’s archenemy TeamPCP goes back further than anyone thought

TeamPCP, the threat actor behind an unrelenting flurry of attacks on open-source software this year, has been active much longer than previously thought, according to research Oligo Security shared exclusively with CyberScoop.  The threat actor, which gained notoriety and has captivated threat hunters as it compromised and injected malicious code into more than 1,000 software…

Tuskira expands exposure management with Agentic Control Plane

Tuskira has launched its Agentic Control Plane for Exposure Management, a new capability within the Tuskira platform that governs AI-discovered vulnerabilities from scan to verified closure. The capability extends Tuskira’s existing zero-day and exposure-response capabilities to frontier-model scanning. Tuskira applies enterprise policy to AI and legacy scanner workflows, maps findings to the deployed environment, determines…

Tenable Hexa AI: Automating exposure remediation with agentic routines

Discover how Tenable Hexa AI closes the gap between exposure management and endpoint patching using intent-driven routines, smart guardrails, and human approval. Key takeaways The problem: A slow handoff between security workflows creates a days-long remediation gap.  The solution: Tenable Hexa AI bridges this gap using intent-driven Routines that automate scoping, deployment, and verification across…

Lumu launches live threat intelligence platform for real-time cyber defence

Lumu has announced the release of Lumu Threat Observatory as part of Maltiverse, its threat intelligence solution. Lumu Threat Observatory is Maltiverse’s live, personalized threat-intelligence experience, providing organizations with a complete, live view of the active threats targeting their specific sector, helping them spot malicious adversaries early, prioritize vulnerabilities, and automatically block them. While threat…

AI agent deception moves from theory to reality in UK cyber tests

“During a routine cyber evaluation, AI agents took sustained, unsanctioned action directed at real people and organisations,” UK’s AI Security Institute (AISI) disclosed on Tuesday. The agents’ actions included an attempted supply-chain attack that saw them create malicious pull requests and try to socially engineer an open-source maintainer into approving the malicious code (they refused).…

Critical Paperclip bugs expose AI agent trust failures

Security researchers are warning against trust assumptions in AI security with newly detailed flaws affecting the open-source AI agent platform Paperclip that could be chained into remote code execution (RCE), data exposure, and developer-machine compromise. An Oasis Security research shared with CSO ahead of its publication on Wednesday disclosed details of three recent vulnerabilities affecting…

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft’s real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure,…

OpenAI, Anthropic AI agents resorted to deception in new cybersecurity incidents

OpenAI’s GPT-5.6 Sol and Anthropic’s Mythos 5 have been implicated in another series of AI security incidents after the models created fake online identities, targeted real people, and attempted to manipulate developers into approving malicious code during controlled cyber evaluations, according to the UK AI Security Institute. “On 28th July 2026, AISI’s Security Team detected unusual…

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability. We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the…

One C2 kit. 30 customers. 2 governments

I was mapping the command-and-control infrastructure behind a state-linked intrusion set when the query came back and effectively ended the exercise I thought I was running. The malware resolved its C2 address by reading a smart contract on a public blockchain. Public reporting described one contract. Working from the chain rather than the sample, I…

AI is getting better at election facts, but voters shouldn’t rely on it

Like seemingly everything else these days, artificial intelligence will re-shape the way voters gather information on candidates running in the 2026 midterm elections. In some ways, this is already the reality. Voters are increasingly turning to AI chatbots for information instead of Google.  Political campaigns are deploying deepfakes of their opponents. And AI systems have…

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove

A phishing campaign impersonating Bank of America (BoA) is underway, trying to trick Windows users into installing ScreenConnect remote access software and then making it difficult to uninstall it. Different traps for Mac and Windows users By claiming the recipient must take specific actions “to avoid account restrictions,” the email, sent from onlinebanking@ealerts[.]bkofamerica[.]com, tries to…

Why you need a reliable AI agent kill switch

Recent high-profile rogue agent incidents involving OpenAI and Anthropic underscore the fact that organizations can’t put blind trust in their AI guardrails. Moreover, they must able to turn off agents quickly when they deviate from intended behavior — before they can do potentially catastrophic damage. For legal services company Purpose Legal, that includes incorporating a…

Safeguarding 200M Users: How ChongLuaDao Scales Threat Validation with ANY.RUN

ChongLuaDao protects over 200 million users from cybercrime, having detected more than 1.4 million malicious websites since 2020. Rapid processing of community reports is essential to their operations. In our recent conversation, ChongLuaDao co-founder Hieu Ngo told us how ANY.RUN plays an integral role in the project’s infrastructure, helping it power thousands of safety checks…