Geek-Guy.com

The Odyssey piracy scams surface hours after its theatrical debut

Christopher Nolan’s The Odyssey had barely reached theaters before scammers began targeting people searching for pirated copies, according to Malwarebytes. Within hours of the film’s release, researchers found two separate scams running on cloned piracy sites: fake browser warnings and Windows executables disguised as movie downloads. “Neither scam has anything to do with the movie…

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV. What makes it…

2026 ISO and CSA STAR certificates are now available with two additional services

Amazon Web Services (AWS) successfully completed an onboarding audit with no findings for ISO 9001:2015, 27001:2022, 27017:2015, 27018:2019, 27701:2019, 20000-1:2018, and 22301:2019, and Cloud Security Alliance (CSA) STAR Cloud Controls Matrix (CCM) v4.0. EY Certify Point auditors conducted the audit and reissued the certificates on May 31, 2026. The objective of the audit was to…

Hugging Face Discloses Autonomous AI Agent Attack 

Hugging Face disclosed that attackers breached its production infrastructure using an autonomous AI agent attack.  The attackers gained access to internal datasets and credentials by exploiting vulnerabilities in the company’s data-processing pipeline.  While the investigation is ongoing, the company said it has found no evidence that public-facing models, datasets, or Spaces were modified, and its…

Scale Computing Brings AMD CPUs to SC//HyperCore 9.7

Scale Computing, an edge computing and network solutions provider, is expanding deployment options for its edge solutions to include support for AMD EPYC and AMD Ryzen AI processors. SC//HyperCore now supports AMD CPU infrastructure Scale Computing’s SC//HyperCore virtualization suite version 9.7 adds support for AMD CPU-based infrastructure, expanding support for customers and partners and providing…

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic,…

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)

Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection vulnerability that lets unauthenticated attackers escape ServiceNow’s script sandbox and execute code remotely on…

Healthcare giant Abbott probes two cyber incidents amid extortion claims

Abbott Laboratories, one of the world’s largest healthcare and medical device companies, is investigating two apparently unrelated cyber incidents after confirming unauthorized access to internal systems. While Abbott says there has been no impact on manufacturing, laboratory operations, or patient care, cybercriminal groups ShinyHunters and ShadowByt3$ claim the breaches were far more extensive. Those claims…

Mitel’s Ben Macdonald Outlines Partner Growth Strategy

Mitel’s new global channel leader says hybrid communications, AI, and stronger partner alignment represent the company’s biggest opportunities for growth as organizations continue modernizing their collaboration environments. Ben Macdonald, who joined Mitel in June as Vice President of Global Channel Go-to-Market, told Channel Insider he plans to focus on simplifying the partner experience while using…

WordPress Remote Code Execution Flaws Get Public Exploits 

Organizations running WordPress should prioritize installing the latest WordPress security update after public proof-of-concept (PoC) exploits were released for WordPress vulnerabilities that can be chained to achieve remote code execution (RCE).  “This is going to hurt. WordPress runs on hundreds of millions of websites globally. Some of those will be auto-patched by their hosting providers,…

wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating. Key takeaways: Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve…

Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage

Dutch intelligence says Russia hacks IP cameras to monitor NATO military logistics and weapons shipments to Ukraine. The Netherlands’ AIVD and MIVD, the civilian and military intelligence services, published a joint advisory on July 10 confirming that at least one Russian intelligence service is systematically compromising internet-connected IP cameras across the Netherlands, other EU and…

Italy fines WINDTRE €1.7 million over security flaws behind two data breaches

Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE €1.7 million over “serious data security shortcomings” that let hackers breach its systems twice and exfiltrate personal data belonging to more than 365,000 customers. The regulator opened its investigation after WINDTRE, one of Italy’s major telecom operators, reported two separate data…

Radware Introduces New DefensePro X Protection

Radware, a provider of AI and application security and delivery solutions for multi-cloud environments, has announced a new cloud-augmented protection architecture for DefensePro X, which protects against distributed denial-of-service attacks (DDoS). The new architecture will extend the platform with AI-powered cloud algorithms while keeping traffic inspection and mitigation on-premises. For channel partners, including Radware’s MSSP…

A Vulnerability Chain in WordPress Core Could Allow for Remote Code Execution

A vulnerability chain has been discovered in WordPress Core that could allow for remote code execution. WordPress is an open-source content management system (CMS) used to design, build, and publish personal and commercial websites. Successful exploitation of vulnerability chain could allow for remote code execution in the context of the affected service account. Depending on…

Patch now: WordPress REST API bug allows remote code execution

Organizations running recent versions of WordPress are being asked to patch a newly detailed pre-authentication remote code execution (RCE) vulnerability affecting the platform’s built-in REST Batch API. The flaw, dubbed wp2shell, enables attackers to execute arbitrary code against a default WordPress installation without requiring plugins, authentication, or special configuration. Adam Kues of Searchlight Cyber first…

20th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information,…

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands’ civilian and…

Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding

We have detected several campaigns using fake downloads of games, mods, cracks, and software to spread RenPy Loader. Once installed, the loader starts a complex, multi-stage infection chain that abuses MSBuild and the EtherHiding technique before ultimately delivering Amatera Stealer. Amatera is an infostealer—a type of malware designed to steal sensitive information from an infected…

Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!

7-Zip fixed a vulnerability that could let attackers run code by tricking users into opening malicious XZ-compressed archive files. 7-Zip released version 26.02 to address a remote code execution vulnerability in its handling of XZ-compressed data. The flaw, discovered by researcher Landon Peng, can be triggered through a specially crafted archive. If a user opens…

CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers

F5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests. F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticated attacker to trigger a heap buffer overflow using specially crafted HTTP requests. “heap…

Channel Partners Shift Vendors as Hardware Risks Rise

A new Westcon-Comstor survey found that 87% of channel partners are changing how they plan, procure, and deliver IT infrastructure projects as hardware price volatility and supply constraints continue to disrupt customer deployments.  The findings suggest partners are increasingly turning to capacity planning, accelerated purchasing, and vendor changes to keep projects on schedule despite ongoing…

AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign

Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials. Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can build, share, and deploy machine learning and generative AI models. Hugging Face disclosed that an…

Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances

Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available. Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks…

A week in security (July 13 – July 19)

Last week on Malwarebytes Labs: Shark vacuum flaw exposes cameras, home maps and Wi-Fi passwords How to use GitHub safely The backlash against Flock cameras is spreading Security updates available for Adobe, Chrome, Firefox, VMWare, and Zoom Samsung backs down on threat to delete health data Claude for Chrome flaw could let rogue extensions access…

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform

Out-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that many researchers assemble on their own. A new open-source project from Microsoft supplies that infrastructure in a package meant to run inside a private environment. Dusseldorf is an out-of-band application security…

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below – git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) – Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4)…

Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security

ZoneAlarm Mobile Security is a security app from Check Point designed to protect mobile devices against phishing, malicious websites, unsafe networks, and fraudulent links. It is available for iPhone, iPad, Android, and can run on Apple silicon Macs through the App Store. Getting started The onboarding process begins with a request for notification permissions, followed…

Nearly half of open-source AI projects never reach production

Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles as model capability improves. Open source AI in 2026, in four numbers. (Source: Mozilla) “Without investment…