Geek-Guy.com

Lemongrass Debuts AI-First Model for SAP Modernization

Lemongrass, a specialist in SAP cloud transformation, has unveiled Brightfield, an AI-first modernization model designed to help enterprises realize measurable business value during SAP transformation programs rather than years after go-live. Built on Lemongrass’s LCP AI SaaS Edition (LINK) and delivered through SAP-centric Forward Deployed Engineers (FDEs), Brightfield embeds AI, automation, and Clean Core principles…

New Google Password Manager Attacks Can Hijack Synced Passkeys

Security researchers have uncovered three new attacks that could let malware hijack Google-synced passkeys and take over online accounts from compromised Windows devices. The techniques target Google Password Manager in Chrome and abuse weaknesses in device trust, user verification, re-registration, credential recovery, and passkey synchronization.  Depending on the technique, attackers could bypass verification, authenticate from…

Black Hat 2026: CrowdStrike Threat Hunting Report Findings 

Cyber adversaries are moving faster, exploiting trust instead of brute force, and increasingly combining automation with hands-on operations to evade traditional security controls.  CrowdStrike released its 2026 Threat Hunting report alongside Black Hat 2026.  Its findings show that threat actors are accelerating vulnerability exploitation, abusing artificial intelligence (AI), targeting software supply chains, and shifting toward…

Dem senators criticize Trump administration decisionmaking on AI security risks

The Trump administration’s haphazard and opaque interventions into artificial intelligence security matters could catapult Chinese alternatives into broader acceptance, posing new security risks altogether, a group of Democratic senators wrote to top administration officials Monday. The five senators said that the administration’s handling has alternated between too passive, such as when OpenAI models escaped testing…

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. “Greatness supports AiTM [adversary-in-the-middle] credential and

DEF CON 2026: Flare Launches Free Dark Web Intelligence Training Platform

Flare has launched Darkroom by Flare Academy, a free interactive training platform designed to give cybersecurity professionals practical experience investigating the types of underground environments where cyber threats originate.  The launch coincides with DEF CON 2026, where Flare will also host a live Darkroom event.  Unlike traditional cyber threat intelligence (CTI) training that often relies…

Airlock Digital Unveils Agentic AI Control & Governance to Extend Preventative Endpoint Security

Airlock Digital, a leader in preventative endpoint security, today announced Agentic AI Control & Governance at Black Hat USA 2026. The new capabilities build on application control by providing command- and session-level visibility into trusted AI agent behavior, centralized policy management for trusted applications and AI agents, and real-time governance over what trusted AI agents…

AI developers targeted via trojanized GitHub repositories

Cybercriminals are cloning popular GitHub repositories for AI tools and developer resources to distribute an infostealer, according to Netskope Threat Labs. (Source: Netskope) Netskope came across the campaign while tracking a Windows-based MaaS infostealer, first reported in April 2026, that was spread through the ClickFix social engineering trick. Continuing to follow the operation, the researchers…

GitHub Account Breach Fuels Shai-Hulud npm Supply Chain Attack 

A large-scale software supply chain attack is affecting the JavaScript ecosystem after attackers compromised the GitHub account of a maintainer behind several widely used npm packages.  The incident began on Aug.4, 2026, when malicious code was introduced into packages including keyv, flat-cache, and file-entry-cache, but quickly expanded into a broader Shai-Hulud campaign that has spread…

Sevii APS Module preempts attacks with autonomous cyber defens

Sevii has announced a major expansion of the Sevii Autonomous Defense & Remediation (ADR) platform with the general availability of an Autonomous Preemptive Security (APS) module. The new module complements ADRs autonomous defense against threats, extending the platform to continuously transform customer’s external global and internal environmental cyber intelligence into autonomous hypothesis hunting, exposure validation,…

INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit

INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations. Resecurity disclosed that INC Ransomware has emerged as the dominant threat actor exploiting the recently disclosed SonicWall Secure Mobile Access (SMA) 1000 vulnerabilities. According to the company’s research, the group has accelerated its operations since…

ServiceNow organizes autonomous security around six solution areas

ServiceNow has announced an acceleration of its Autonomous Security vision with six unified solutions that help deliver prevention-first, AI-native cyber defense across unified exposure management, continuous vulnerability detection, cyber-physical security, identity and access security, and agentic incident response, and cyber risk and compliance. With new AI Specialists that complete security workflows autonomously, including the Vulnerability…

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later…

Snyk unveils continuous AI pentesting and agent red teaming

Snyk has announced the general availability of Evo Continuous Offensive Security (COS), enabling security teams to continuously test applications with autonomous, AI-powered pentesting and AI agent red teaming while providing validated proof of what attackers could actually exploit. AI is accelerating software release cycles while rapidly expanding the exposed attack surface, which now spans architectural…

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKE#SCREEN by Securonix Threat

CVE-2026-18577: N-able N-central Authentication Bypass Lets Attackers Reach Managed Endpoints

N-able has released an emergency hotfix for an actively exploited authentication bypass in N-central, a remote monitoring and management platform widely used by managed service providers and internal IT teams. The flaw allows a remote, unauthenticated attacker to obtain administrative access to vulnerable N-central servers and use the platform’s legitimate management capabilities to reach downstream…

AvePoint Launches Kinetic Classification for AI Security

AvePoint has launched a new continuous data classification capability designed to help organizations identify sensitive information as files, permissions, and AI usage change over time. The company’s Kinetic Classification feature repeatedly reassesses enterprise data rather than relying on static labels, while new Rapid Recovery capabilities use that intelligence to help organizations prioritize which systems and…

RapidFort Runtime brings continuous CVE monitoring and tamper detection

RapidFort has launched RapidFort Runtime, a real-time security solution that extends RapidFort’s SSCS capabilities into live production environments. The offerings provide end-to-end continuous threat elimination, from curated, independently malware-scanned open-source software before deployment to continuous CVE monitoring and tamper detection in production. RapidFort Runtime operates inside an organization’s production environment continuously monitoring deployed software, detecting…

Black Hat 2026: Improving CISO to Board Cyber Risk Reporting 

Cybersecurity has become a standing agenda item in boardrooms, yet many chief information security officers (CISOs) still struggle to communicate cyber risk in a way that enables informed business decisions.  According to Pulse Security’s The CISO-Board Communication Gap report, released during Black Hat 2026, the challenge is not simply improving presentations.  Instead, the research suggests…

Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)

This morning, I noticed specific sources “hunting” for vulnerabilities in URLs that I haven’t noticed before. All of these URLs appear to be associated with diagnostic tools: URL Count Vulnerability / 1 (simple recon for index page) /apply.cgi 20 CVE-2024-12856 Four-Faith router command injection /cgi-bin/adv_ping.cgi 20 ? /cgi-bin/diagnostic.cgi 20 CVE-2013-7179 Seowon Intech WiMAX SWU-9100 mobile…

Critical Azure Cosmos DB flaw threatened cross-tenant database takeover

A critical vulnerability in Microsoft Azure’s Cosmos DB database service could have enabled attackers to escape the platform’s Gremlin query sandbox, execute code on shared infrastructure, and ultimately gain access to any customer’s database, including data stores used by Microsoft services such as Entra ID, Teams, and Copilot, according to research published by cloud security…

The top cybersecurity product announcements from Black Hat 2026

Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products. Vendors are increasingly packaging AI into operational workflows, while pairing automation with governance, exposure management, and recovery capabilities aimed at making autonomous security more practical for enterprise environments.…

RapidFort Runtime Extends Software Supply Chain Security

RapidFort has launched RapidFort Runtime, a security platform designed to extend software supply chain protection beyond development and into live production environments. RapidFort extends security monitoring into production The solution, RapidFort Runtime, creates an end-to-end continuous threat elimination solution from curated, independently malware-scanned open-source software before deployment to continuous CVE monitoring and tamper detection in…

Google ADK flaws reveal what happens when AI agents trust the wrong message

Security flaws in automated workflows in the GitHub repository for Google’s Agent Development Kit for Python could allow public-facing AI agents to trigger more privileged automation, opening one path to manipulate pull-request reviews and another to expose credentials, according to a report from Pillar Security. The first attack path involved a triage agent that analyzed…

When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted

The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break. Security teams have long estimated risk by ranking attacker sophistication. Nation-state actors sat at one end. Organized criminal groups followed. Inexperienced attackers, dismissed as “script kiddies,” sat at the other end, running public

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent. The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so…

U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a N-able N-central flaw, tracked as CVE-2026-18577 (CVSS score of 8.2), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-18577 (CVSS 8.2) is an authentication bypass flaw caused by an…

Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware

Midnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at places like hotels and conference centers, according to new findings from Microsoft Threat Intelligence. Overview of the CaptiveCrunch attack flow (Source: Microsoft) Microsoft named the campaign CaptiveCrunch and identified two malware strains…

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database’s root context, crossing the privilege boundary between a cPanel account and the server’s administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The database bug is tracked as CVE-2026-58048 (CVSS…

Indusface SwyftComply AI enables autonomous virtual patching for AI-discovered flaws

Indusface has announced SwyftComply AI, an autonomous vulnerability remediation solution that virtually patches vulnerabilities surfaced by AI-assisted pentesting. Artificial intelligence has changed the economics of application security. AI-powered security agents now uncover exponentially more vulnerabilities than ever before. Yet remediation has not accelerated. Security teams are overwhelmed by findings while remediation remains constrained by engineering…

ESET introduces new AI capabilities for autonomous agent security

ESET is expanding its AI capabilities across threat detection, investigations, threat protection, and security operations, delivering added value to customers through built-in innovations rather than separate add-on solutions. “AI is a new class of actor inside the company – reading, writing, making decisions and executing. As such, it deserves the same security attention as users…

“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI

Actor usage of AI is exploding. By analyzing artifacts left behind, Talos has created a detailed analysis of how we are seeing adversaries leverage the technology to include development, force multiplication, and vulnerability research. Based on the evidence Talos gathered, guardrails did not provide much protection, with most actors able to convince the models to…

How companies could share cyber risks without exposing their secrets

Zero-knowledge proofs could let infrastructure operators answer key security questions without handing over the sensitive data behind their answers. Imagine a major software flaw is discovered in equipment used across pipelines, power plants and telecom networks. The government needs to know as fast as possible which companies are exposed. But answering that question may require…

Joinable Labs unveils Joinable Security for threat intelligence and AI-driven response

Joinable Labs launched Joinable Security, the first domain on the Joinable platform, with two products: Joinable Threat Map, a free utility that lets the security community map, analyze, and share evolving adversary behavior, and Joinable Runbooks, an enterprise platform that turns an organization’s security response documentation into governed knowledge and the agents that act on…

Securonix enhances Unified Defense SIEM with AI agent detection and lower data costs

Securonix has announced expanded cybersecurity cost reduction, expanded Threat Analytics for Microsoft Sentinel, and new Governed AI Agent Detection and Response capabilities. The additions extend the Securonix Unified Defense SIEM platform to help enterprises and managed security providers control data costs, improve detection coverage and response, and govern risks created by enterprise AI adoption. Security…

Legit Security VibeGuard 2.0 brings endpoint security and real-time guardrails to AI coding agents

Legit Security has unveiled VibeGuard 2.0, bringing a new endpoint security capability that seamlessly discovers and integrates with coding agents, secures them and delivers a frictionless developer experience. Launched in Q4 2025, Legit VibeGuard was the solution designed to secure AI-generated code at the moment of creation and place guardrails on coding agents. This latest…

Tanium expands autonomous security across AI, exposure management and SecOps

Tanium has announced a series of new autonomous security capabilities across the Tanium Autonomous IT Platform. Spanning agentic AI, exposure management and security operations, the capabilities empower IT and security operators to stay ahead of an AI-accelerated threat landscape, safely, without losing control. “Tanium is the platform that governs and manages them with Tanium Atlas…

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims’ browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. “The first stage drops a steganographic PNG image into the browser’s cache, retrieves its hidden content, and executes…