Geek-Guy.com

JSP webshells being dropped on unpatched PTC Windchill instances

The US Cybersecurity and Infrastructure Security Agency (CISA) added a vulnerability (CVE-2026-12569) in Windchill and FlexPLM, two product lifecycle management software platforms developed by PTC, to its Known Exploited Vulnerabilities (KEV) catalog. Entries in the KEV catalog don’t contain links to reports of exploitation, but PTC’s advisory keeps getting updated with indicators of compromise and…

Apple’s memory problem is your problem, too

Apple’s ongoing problems with RAM shortages and higher prices won’t be solved anytime soon, because rapidly accelerating demand for high-end AI memory is devouring the consumer electronics industry.  GoPro has already warned it might go out of business — and the scale of the crunch has prompted analysts to call it an “absolute existential crisis” for smaller tech…

Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks

The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel. Acronis Threat Research Unit found active compromises inside Indian government networks, including machines used by senior administrative staff, and worked with 

29th June – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 29th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Polymarket, a large cryptocurrency-based prediction market, has confirmed a supply chain attack after a third-party frontend vendor breach led to malicious JavaScript being injected into its website. Attackers tricked users into approving fraudulent…

Scality Launches Revamped Channel Program

Scality, a provider of data infrastructure software for AI-era storage at scale, is reimagining its partner program to extract greater value, build stronger economics, and provide a clear growth path for resellers and distributors. Scality adapts to new model as partners target cyber resilience and AI demands The Scality Partner Program’s update is a change…

PrivacyHawk Enterprise helps organizations find shadow IT and minimize third-party cyber risk

PrivacyHawk has announced the general availability of PrivacyHawk Enterprise, a solution that identifies and eliminates the shadow IT accounts, abandoned SaaS subscriptions, and forgotten third-party services quietly exposing organizations to breach risk. Every organization has an invisible attack surface. Shadow AI tools. Free trials nobody cancelled. Third-party services still holding employee data from years ago.…

DOJ Seizes 400 Illegal FIFA World Cup Streaming Domains

The U.S. Department of Justice (DOJ) has seized nearly 400 internet domains that were illegally streaming FIFA World Cup 2026 matches. The operation, known as Operation Offsides, targeted websites distributing unauthorized live broadcasts while also highlighting the cybersecurity risks often associated with illegal streaming platforms. According to the DOJ, the seized websites provided unauthorized real-time…

Italian watchdog probes Microsoft as M365 price change looms

Italy’s competition watchdog has opened an investigation into Microsoft over concerns it may not have clearly informed consumers about the integration of Copilot and Designer into Microsoft 365 subscriptions, associated price increases, and automatic upgrades to higher-cost plans. The Italian Competition Authority (AGCM), in a statement to the press, said it had opened an investigation…

236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers

New findings unearthed by Infoblox show that more than 236,000 websites are using investment scam templates built using a legitimate Chinese open-source, cross-platform application development framework called DCloud Uni-App. The templates power bogus cryptocurrency exchanges, multi-language pig-butchering operations, WhatsApp phishing networks, fake gambling platforms, brand-impersonation

StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years

Microsoft shut down the StegoAd campaign, which used 119 malicious Edge extensions, hit 2.6M installs, and ran undetected for two years. Microsoft just shut down one of the more technically clever malicious extension campaigns it’s ever documented. The operation, named StegoAd, ran 119 extensions on the Edge Add-ons store, racked up roughly 2.6 million installs,…

Mozilla warns of indirect prompt injection risk in AI coding agents

A malicious GitHub repository can silently compromise a developer’s machine without containing a single line of malicious code, security researchers at Mozilla’s Zero Day Investigative Network (0DIN) warned. The attack The proof-of-concept attack targets AI-powered coding agents such as Claude Code, and uses indirect prompt injection to manipulate an AI agent into taking harmful actions…

GPT-5.6 gets better at cybersecurity

OpenAI has started rolling out the GPT-5.6 series models in limited preview to a small group of trusted partners through the API and Codex. The series includes Sol as the flagship model, Terra as a balanced option, and Luna as the fastest and most cost-efficient model. The rollout is being coordinated with the U.S. government…

What the post-quantum executive order really demands of CISOs

Post-quantum cryptography didn’t sneak up on the industry.  For years, security teams, standards bodies, hyperscalers, and governments have been pointing at the same horizon: a cryptographically relevant quantum computer will, eventually, dismantle the public-key algorithms underpinning today’s enterprise security. The latest executive order doesn’t introduce a new threat. It codifies what the field has long…

SSU and FBI Uncover Russian Cyber Espionage Operation Against Officials and Military Personnel

Ukraine’s SSU and the FBI Just Confirmed Russian Intelligence Has Been Systematically Hacking Messenger Accounts for Years. The Security Service of Ukraine (SSU), working jointly with the FBI, has formally exposed a sustained Russian intelligence campaign targeting the messaging accounts of government officials, military personnel, politicians, and activists across Ukraine, Europe, and the United States.…

Pax8 Partnership Expands Summit Holdings MSP-aaS Model

Summit Holdings’ MSP-as-a-Service model is expanding its reach through a go-to-market partnership with Pax8, bringing white-labeled service desk, NOC, SOC, and technical operations support to Pax8 partners seeking more scalable delivery models. For Pax8 partners, the model adds access to NOCDOC’s 24/7 operational backbone while allowing MSPs to retain ownership of the customer relationship. According…

A week in security (June 22 – June 28)

Last week on Malwarebytes Labs: Malware steals Chrome session cookies to take over your accounts Beware of “Parcel Expert” job offers: They’re parcel mule scams Update Chrome to patch critical browser security flaws Fake domain renewal emails trick website owners into paying scammers Elite network says it was hacked after members’ personal data was left…

Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts. “This attack avoids the most common npm execution paths through lifecycle scripts, perhaps in an attempt to remain ‘compatible’ with npm v12’s security hardenings,” JFrog…

KDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPs

KDDI Corporation disclosed a breach affecting up to 14.2 million email accounts after attackers exploited a vulnerability in third-party software. KDDI Corporation disclosed a data breach that exposed up to 14.2 million email accounts across six Japanese internet service providers. KDDI Corporation is one of Japan’s largest telecommunications companies. It employs more than 60,000 people…

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 103

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers   A VBScript campaign distributed through WhatsApp deploying RMM software  Lost in relocation: analysis of a new loader distributing CASTLESTEALER  …