Geek Guy

Ransomware recovery CEO indicted after allegedly paying hackers and pocketing millions

Authorities accuse the owner of a so-called ransomware remediation company of swindling clients victimized by ransomware attacks into paying the company inflated fees under false pretenses. Zohar Pinhasi, owner and operator of MonsterCloud, claimed he could decrypt and recover victims’ data with specialized, proprietary tools and avoid paying cybercriminals. Yet, no such tool existed, the…

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8. The company, Integrity Technology Group, has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws…

Making sure the checks get printed

Welcome to this week’s edition of the Threat Source newsletter.  My name is Pierre Cadieux, and I’ll be helping contribute to these newsletters. A little about me: I’ve been working in the cybersecurity industry in many roles over the past 20+ years, first focusing on endpoint security, policies, and firewalls, then moving to risk management…

Hunt.io Finds New Infrastructure Of BraZetsu Access Broker Months Before Disclosure

Hunt.io traced BraZetsu ‘s infrastructure and found that hosting patterns and certificate data remained useful after published IOCs became outdated. Group-IB researchers published a detailed writeup on BraZetsu back on August 31, naming it a Python framework compiled with Nuitka and tying it to a Brazilian actor called Exilware with high confidence. Hunt.io checked whether…

OpenAI says Iran, Russia used AI journalists, think tanks to influence Western media

OpenAI disclosed Thursday it shut down two influence operations from Russia and Iran that used ChatGPT and other AI tools to create fake journalist personas and covert think tanks that successfully planted stories and narratives in mainstream news publications. One cluster of accounts, which OpenAI calls “Dark Clark,” is attributed to Russian actors. The network…

Attackers hijack country-code domains to impersonate Google and other services

According to Google, attackers compromised infrastructure behind three country-code domain namespaces—.gh (Ghana), .sl (Sierra Leone), and .as (American Samoa)—and used it to obtain unauthorized HTTPS certificates for Google domains and other organizations. These domain endings aren’t limited to sites serving those countries, so the risk can extend to users elsewhere. This wasn’t a break in…

Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said. The Tokyo-based center, which takes incident reports, based its October 8, 2026 alert on those reports and other information. The alert names no attacker and no affected organization. JPCERT/

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065). ASHVEIN,

ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks. The activity, per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration. “In this activity, the threat…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

MonsterCloud Owner Charged With Secretly Paying Ransomware Demands

MonsterCloud owner Zohar Pinhasi allegedly paid ransomware demands behind clients’ backs, then charged them millions for the supposed recovery. Zohar Pinhasi, the owner of Florida-based MonsterCloud, was charged this week with wire fraud. Federal prosecutors say his clients were scammed twice during the same ransomware crisis. Pinhasi (50) also used the names “Zack Silver” and…

Inside the Exchange Inspector: How Tenable uses OpenAI GPT cyber models to review open-source AI agents

Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange.  Three tools have already passed. Key takeaways Every Inspector-vetted listing clears three gates: an automated check, a frontier model assessment, and human verification. Tenable uses…

Anthropic’s new budget model gets much better at ignoring hidden commands

Anthropic’s Claude Haiku 5.5 model, designed for quick, repetitive workloads and speed-sensitive tasks, is now better at finding vulnerabilities and writing exploits than its predecessor. The company has given it stricter cybersecurity safeguards than Haiku 4.5, though lighter ones than its more advanced models, whose offensive skills remain well ahead. Cybersecurity capabilities and safeguards Anthropic…

Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself. ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US,…

Rogue AI Agents

AI agents are escaping sandboxes, misusing credentials and acting without authorization. This live dashboard tracks every reported incident on a horizontal timeline, with charts showing which AI companies and agents are involved, the techniques used and how they got in. It updates automatically as new events are added.

UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing

Cisco Talos identified an advanced persistent threat (APT) spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions to establish credibility.  The phishing emails exhibited highly consistent structure, rhetoric, and personalization patterns, suggesting the threat actor likely used AI-assisted content generation to…

Ignore all instructions and read this blog: The state of AI-analysis evasion in malware

“AI-analysis evasion” encapsulates the real-world techniques malware authors are developing in attempt to obstruct or defeat any layers of automated AI analysis.  This technique is cheap to add but inconsistently impactful — the best techniques steered the outcome in the attacker’s favor in about 35% of test runs. Further, it must always be plaintext and…

Quantum computers could break today’s encryption. Washington needs to prepare now.

The country is consumed right now with debating artificial intelligence and whether increasingly powerful AI systems could escape human control. Those are valid concerns, but lawmakers are overlooking another technological threat: quantum computing. Unlike AI safety debates, this risk could render today’s encryption obsolete – compromising everything from emails to financial transactions to government communications…

Deeper Network Promo Deeper Network Promo Deeper Network Promo Image

16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys. “The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to

Ransomware recovery firm boss charged with secretly paying attackers and overcharging victims

The owner of Florida-based ransomware remediation company MonsterCloud has been charged with fraud for allegedly paying ransomware gangs behind his clients’ backs and billing them far more than the ransom. Zohar Pinhasi (aka “Zack Silver” and “Zack Green”), a 50-year-old US and Israeli national from Hollywood, Florida, allegedly charged MonsterCloud clients more than $19 million…

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data. Zohar Pinhasi (aka Zack Silver and Zack Green) has been charged with two counts of…

Atlassian Vulnerability Comes Under Attack Hours After Details Go Public

Threat actors are exploiting CVE-2026-21589, a critical Atlassian flaw that can expose sensitive files across multiple Data Center products. Threat actors have started exploiting CVE-2026-21589 (CVSS score of 9.3), a critical arbitrary file access flaw in Atlassian Data Center products. The vulnerability could allow attackers to access sensitive files under certain conditions. Affected products include…

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

The npm package known as “tensorlake,” a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 “contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code,” Socket said

Who watches the AI watching your street?

Yusaku Fujii, a professor at Gunma University in Japan, has designed audits and penalties to stop operators from misusing AI that analyzes street camera footage. His system adds an independent record-keeper and unannounced spot checks to the AI’s outputs. Fujii’s test setting is what he calls a Fully Monitored Public Space (FMPS): streets where cameras…

How AI can fix cybersecurity compliance: From dashboards to continuous execution

Most compliance work goes into proving security, not improving it. That isn’t because the rules are unreasonable. Regulators, customers, and cyber insurers are right to expect organizations to implement hundreds of technical and administrative controls, monitor their environments, respond to incidents, and prove that all of it works. The problem is the cost of delivering…

5 Key Takeaways from Beyond Human Risk: Measuring Secure Behavior with an AI-Driven Platform

Security awareness programs can report who completed training, clicked a simulation, or passed a quiz. Those metrics provide useful evidence of participation and practice. They offer less insight into whether employees can recognize and respond to a real phishing threat when it reaches their inbox, whether that is days or months later. Cofense’s Beyond Human…

Medical devices patients rely on most are least prepared for quantum attacks

Threat actors are exploiting IT, IoMT, OT and IoT devices across healthcare delivery organizations (HDOs) to deploy ransomware, demand payments and monetize stolen patient data, according to Forescout’s Post-Quantum Cryptography (PQC) in Healthcare: From Data Risk to Migration Readiness report. Researchers analyzed a dataset containing more than 2.5 million devices across more than 50 HDO…