Geek Guy

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. “The attack chain begins with a fake CAPTCHA page and

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows – CVE-2026-65660 (CVSS score: 8.8) – A code injection vulnerability in Microsoft Office SharePoint

Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. “Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems,” said Frank Balonis,…

U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds WordPress flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a WordPress Core flaw, tracked as CVE-2026-87902 (CVSS score of 9.2), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-87902 allows an unauthenticated attacker to make the get_page_template() function include a readable local…

U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-65660 (CVSS score of 8.8) Microsoft SharePoint Code Injection Vulnerability CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow…

Roundcube Webmail Under Attack: 523,000 Instances Exposed Online

Shadowserver is tracking more than 523,000 internet-accessible Roundcube Webmail instances as attackers exploit a high-severity vulnerability that can be abused without authentication. The Canadian Centre for Cyber Security updated its security advisory on Sept. 21 to warn that CVE-2026-48842 is being exploited in the wild. Roundcube originally patched the vulnerability in May, meaning organizations that…

InfraTrust Report Flags Exploited Network Management Flaws

Network management consoles are becoming prime targets as attackers look for one shortcut into entire enterprise environments. Threat actors are increasingly bypassing individual network devices to compromise central management platforms, according to the September edition of Eclypsium’s InfraTrust Pulse report.  Between August 25 and September 17, tracking revealed 158 new security advisories across 17 vendors,…

BrainTrust Launches AI Tools to Improve Enterprise ROI

BrainTrust Partners has launched two AI products aimed at tackling separate barriers to enterprise AI adoption: deciding where AI investments can deliver measurable returns and connecting fragmented business data to support AI agents and automation. The company introduced BrainTrust AI BluePrint Builder, which assesses organizations’ technology environments and business priorities to identify and rank AI…

Akamai Secures $11.6 Billion Deal to Power Anthropic’s AI Workloads

Akamai Technologies has landed one of the largest contracts in its cloud expansion, signing a $11.6 billion computing agreement with Anthropic. The seven-year agreement will see Anthropic tap into Akamai Cloud’s distributed infrastructure and software to support rapidly scaling central processing unit (CPU) workloads. The contract also includes room for an additional $9 billion expansion,…

Multiple Vulnerabilities in ServiceNow’s AI Platform Could Allow for Unauthorized Access

Multiple vulnerabilities have been discovered in ServiceNow’s AI Platform, the most severe of which could allow for unauthorized access. The ServiceNow AI Platform is a unified, cloud-based foundation that integrates artificial intelligence, data, and workflow automation to execute business operations across entire enterprises. Successful exploitation of the most severe of these vulnerabilities could allow for…

Cryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 Million

Bitget says suspected North Korea-linked actors stole $351.6M from hot and warm wallets. Withdrawals were suspended while Mandiant investigates. Cryptocurrency exchange Bitget says suspected North Korea-linked threat actors stole $351.6 million from a limited number of hot and warm wallets. The company detected unauthorized transfers on September 24 and temporarily suspended withdrawals. At 18:31 UTC…

Microsoft’s new Copilot unifies enterprise context for chat and code

Microsoft’s Copilot super-app has arrived, two months after CEO Satya Nadella confirmed it was in development. It combines conversational Chat, the autonomous Cowork agent, a redesigned coding environment named Code, and Autopilot, the persistent agent formerly known as Scout, into a single Copilot experience. The idea is to make those capabilities look less like separate…

LinkedIn adds new checks for fake profiles and work histories

LinkedIn is adding trust and verification features aimed at making fake professional identities, invented work histories, and company impersonation harder to pull off. The company is responding to an environment in which generative AI enables imposters to create an entirely made-up professional persona. It reduces the cost of creating convincing headshots, biographies, résumés, outreach messages,…

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are listed below – actions-cool/issues-helper actions-cool/maintain-one-comment Visiting either of the repositories now shows the message: “Access to this

Zero-Days, AI Agents, and Identity Attacks Define Cybersecurity Week

This week’s security landscape combined actively exploited zero-days, widespread patching gaps, credential-driven attacks, software supply chain threats, and mounting concern over autonomous AI systems. Critical infrastructure and healthcare organizations faced operational risks, major breaches exposed sensitive records, and researchers demonstrated how AI can accelerate both offensive security work and unintended access. Major Threats & Vulnerabilities…

ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer

Attackers hijacked Ukrainian websites to deliver a fake Cloudflare CAPTCHA that installs Psychedelic Stealer and steals browser and crypto credentials. Psychedelic Stealer is being distributed through compromised Ukrainian business websites. Attackers injected hidden iframes into legitimate pages and used them to display a fake Cloudflare verification screen to visitors. The affected sites included a hair-treatment…

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. “Where earlier variants embedded…

ANY.RUN at RootedCON Valencia 2026: Where Cybersecurity Meets the Next Wave of AI

ANY.RUN once again joined the RootedCON community this year, taking part in Rooted Valencia 2026 on September 18. The event brought together cybersecurity professionals, researchers, hackers, and technology enthusiasts from across the global cybersecurity community. For our team, the event became yet another opportunity to meet security professionals, speak with clients, and demonstrate how interactive…