Geek-Guy.com

Month: January 2025

Malvertising Scam Uses Fake Google Ads to Hijack Microsoft Advertising Accounts

Cybersecurity researchers have discovered a malvertising campaign that’s targeting Microsoft advertisers with bogus Google ads that aim to take them to phishing pages that are capable of harvesting their credentials. “These malicious ads, appearing on Google Search, are designed to steal the login information of users trying to access Microsoft’s advertising platform,” Jérôme Segura, senior

Backdoor in Chinese-made healthcare monitoring device leaks patient data

US federal agencies have warned that a popular Chinese-made patient monitor device used in medical settings across the US and Europe has a built-in backdoor that leaks patient data to an unauthorized remote server. The backdoor, present also in a rebranded version of the device, also allows the remote server, which appears to belong to…

OpenAI used this subreddit to test AI persuasion

OpenAI used the subreddit, r/ChangeMyView, to create a test for measuring the persuasive abilities of its AI reasoning models. The company revealed this in a system card – a document outlining how an AI system works – that was released along with its new “reasoning” model, o3-mini, on Friday. Millions of Reddit users are members…

Sam Altman believes OpenAI has been on the ‘wrong side of history’ concerning open source

To cap off a day of product releases, OpenAI researchers, engineers, and executives, including OpenAI CEO Sam Altman, answered questions in a wide-ranging Reddit AMA on Friday. OpenAI the company finds itself in a bit of a precarious position. It’s battling the perception that it’s ceding ground in the AI race to Chinese companies like…

MLCommons and Hugging Face team up to release massive speech data set for AI research

MLCommons, a nonprofit AI safety working group, has teamed up with AI dev platform Hugging Face to release one of the world’s largest collections of public domain voice recordings for AI research. The data set, called Unsupervised People’s Speech, contains more than a million hours of audio spanning at least 89 different languages. MLCommons says…

Unlocking the Benefits of Automated Secrets Vaulting

Why Should You Consider Automated Secrets Vaulting? How secure is your organization’s sensitive information within your cloud environment? With rampant digital threats and complex network systems, safeguarding Non-Human Identities (NHIs) and their secret credentials has ascended as a priority for businesses worldwide. This increasing risk calls for robust cybersecurity measures, and automated secrets vaulting aims…

Staying Ahead in Cloud Security: Key Steps

How Can Non-Human Identities Enhance Cloud Security? As advancements in technology take us to the peaks of innovation, the threat landscape also evolves, posing unique challenges to cloud security. So, how do we stay ahead? The answer lies in effective Non-Human Identity (NHI) and Secrets management. NHIs are machine identities that are central to cybersecurity.…

How Secure Rotation Shields Your Digital Assets

Are You Safeguarding Your Non-Human Identities Efficiently? As a cybersecurity specialist, it’s always important to ask, “Am I doing enough to safeguard my non-human identities (NHIs)?” Implementing secure rotation and managing secrets effectively can be the difference between a well-protected system and a compromised one. NHIs, as the term implies, refer to machine identities that…

Video: How DeepSeek And Emerging AI Models Could Impact The IT Channel

It’s been a wile week in the world of AI! DeepSeek went from breaking the mold with its new AI models that the Chinese startup reported were cheaper, faster, and less resource intensive to make by using fewer, sub standard GPU chips. Now, OpenAI accuses the emerging AI leader of copying its models. What does…

Elon Musk is reportedly taking control of the inner workings of US government agencies

People working for, or with, Elon Musk are reportedly taking over the inner workings of multiple government agencies, including the Office of Personnel Management and the Treasury Department. The Washington Post reported Friday that the highest-ranking career official at Treasury is leaving the department after “a clash” with people working for Musk’s so-called Department of…

Guo’s Conviction Partners adds Mike Vernal as GP, raises $230M fund

When in mid-2022 Sarah Guo left Greylock to launch her own AI-focused fund, Conviction Partners, she indicated that she was tagging the word “Partners” to the firm’s name because she would eventually bring on other GPs. Now, more than two years later, Guo is being joined by Mike Vernal, who was a partner at Sequoia…

The Transformative Role of AI in Cybersecurity

2025 marks a pivotal moment in the integration of artificial intelligence (AI) and cybersecurity. Rapid advancements in AI are not only redefining industries; they are reshaping the cybersecurity landscape in profound ways. Through this evolution, I have noted three primary […] The post The Transformative Role of AI in Cybersecurity appeared first on TechSpective. The…

Anthropic CEO Dario Amodei is trying to duck a deposition in an OpenAI copyright lawsuit

Anthropic CEO Dario Amodei is trying to avoid being deposed in a copyright lawsuit against OpenAI, according to new court filings. In response, lawyers for the plaintiff — the Authors Guild — have filed a motion to compel testimony from Amodei and his Anthropic co-founder, Benjamin Mann. Authors Guild’s lawyers claim that Amodei and Mann,…

Bill requiring federal contractors to have vulnerability disclosure policies gets House redo

Bipartisan legislation to close a loophole in federal cybersecurity standards by requiring vulnerability disclosure policies for government contractors is getting another shot at passage  in this Congress. The Federal Contractor Cybersecurity Vulnerability Reduction Act, a bicameral, bipartisan bill that stalled out last year in the Senate, was reintroduced Friday in the House by Reps. Nancy…

CFPB fines fintech Wise, alleging it charged deceptive fees

The Consumer Financial Protection Bureau (CFPB) has hit UK-based remittance company Wise with about a $2 million fine for what it described as “a series of illegal actions.” Those actions include advertising inaccurate fees and failing to properly disclose exchange rates and other costs, the CFPB alleges. Specifically, the agency claims that the fintech company…

Apple will pay $20M to settle Watch battery swelling suit, ‘denies wrongdoing’

Apple has agreed to pay $20 million to resolve a class-action lawsuit over battery swelling on the Apple Watch. Filed in the U.S. District Court for the Northern District of California in 2019, the suit alleges that the problem affected the first four Apple Watch models. Battery swelling is pretty much what it sounds like:…

DEF CON 32 – An Adversarial Approach To Airline Revenue Management Proving Ground

Authors/Presenters: Craig Lester Our sincere appreciation to DEF CON, and the Authors/Presenters for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel. Permalink The post DEF CON 32 – An Adversarial Approach To Airline Revenue Management Proving Ground appeared…

WhatsApp says it disrupted spyware campaign aimed at reporters, civil society

WhatsApp said Friday that it had disrupted a spyware campaign that targeted 90 people, including journalists and activists. The company tied to the campaign, according to WhatsApp, is Israeli firm Paragon, which last fall signed a $2 million contract with Immigration and Customs Enforcement and recently was purchased by U.S. private equity giant AE International.…

Stablecoins are finding product market fit in emerging markets

Five years ago, SpaceX launched Starlink, which has since grown into its biggest revenue driver, expanding to over 100 countries. But as Starlink scaled, it faced a major hurdle: accepting payments in developing markets, where traditional banking infrastructure is unreliable, slow, and prone to blocking transactions. Many local banks across Africa, Latin America and Asia…

This investor wants you to sign an NDA to build Legos together

Investor, former GitHub CEO, and all around Tech Guy™ Nat Friedman has posted a strangely enticing offer on X. His post reads, “Need volunteers to come to my office in Palo Alto today to construct a 5000 piece Lego set. Will provide pizza. Have to sign NDA. Please DM.” Thanks to the investigative reporting of…

Sam Altman’s ousting from OpenAI has entered the cultural zeitgeist

The lights dimmed as five actors took their places around a table on a makeshift stage in a New York City art gallery turned theater for the night. Wine and water flowed through the intimate space as the house — packed with media — sat to witness the premiere of “Doomers,” Matthew Gasda’s latest play…

FBI, Dutch Police Disrupt ‘Manipulaters’ Phishing Gang

The FBI and authorities in The Netherlands this week seized dozens of servers and domains for a hugely popular spam and malware dissemination service operating out of Pakistan. The proprietors of the service, who use the collective nickname “The Manipulaters,” have been the subject of three stories published here since 2015. The FBI said the…

Microsoft is forming a new unit to study AI’s impacts

Microsoft says that it’s creating a new unit, the Advanced Planning Unit (APU), within its Microsoft AI business division that will help the company understand the societal, health, and work implications of AI the company hopes to build. Microsoft AI, which encompasses Microsoft’s Copilot, Bing, and Edge products, is becoming core to Microsoft’s growth strategy…

DeepSeek: Everything you need to know about the AI chatbot app

DeepSeek has gone viral. Chinese AI lab DeepSeek broke into the mainstream consciousness this week after its chatbot app rose to the top of the Apple App Store charts (and Google Play, as well). DeepSeek’s AI models, which were trained using compute-efficient techniques, have led Wall Street analysts — and technologists — to question whether the U.S. can maintain its…

Custom feed builder Graze is building a business on Bluesky, and investors are paying attention

A startup called Graze, which lets you build your own feeds for the Bluesky social network, has caught investors’ attention. In addition to offering tools to easily build, customize, publish, and manage Bluesky feeds, Graze will soon allow feed creators to monetize their efforts with advertising, sponsored posts, and subscriptions. In other words, Graze has…

AI startup Perplexity sued for alleged trademark infringement

Perplexity, the venture-backed startup building AI-powered search products, has been sued in federal court for allegedly violating another company’s trademark. In a complaint filed Thursday in the U.S. District Court for the Northern District of California, attorneys representing a company called Perplexity Solved Solutions accuse Perplexity of infringing on its trademark rights by using the…

DeepSeek AI Disrupts Industry with Low-Cost, High-Performance Model

The American AI market was recently rattled by the emergence of a Chinese competitor that’s cost-efficient and matches the performance of OpenAI’s o1 model on several math and reasoning metrics.  The new AI model, created by Hangzhou-based startup DeepSeek, has supposedly surpassed Meta as the leading purveyor of open-source AI tools. The company’s R1 model…

Backed by Mayo Clinic, Nutrix’s hardware monitors worker stress

Stress isn’t just bad for you — it’s also bad for your employer. Factoring in absenteeism, diminished productivity, turnover, medical costs, and accidents, the non-profit American Institute of Stress estimates that workplace stress costs U.S. businesses over $300 billion annually. One way to measure stress is by monitoring cortisol levels. Even influencers know this, with…

Big Early Moves In 2024 A/NZ Channel Consolidation

Major consolidation moves are already shaping the Australian and New Zealand channel landscape in early 2025, with multiple acquisition talks and competing takeover bids highlighting the sector’s dynamic nature. AUCyber pursuit heats up, then cools as Brennan IT withdraws The first big acquisition tussle is centered around ASX-listed cyber security company AUCyber. Melbourne-based digital services…

TechCrunch Disrupt 2025: Last 24 hours for 2-for-1 Pass

Final hours for 2-for-1 Passes! One of the best Super Early Bird Deals for TechCrunch Disrupt 2025 will be wrapping up in just 24 hours for the rest of the year. The 2-for-1 Pass lets you bring a friend, colleague, or business partner, for nearly free. Buy one pass at the Super Early Bird rate…

Flexera Acquires NetApp’s FinOps Business to Expand CLM

Technology spend and risk management company Flexera is boosting its FinOps portfolio by acquiring the FinOps Business arm from NetApp, Inc., an intelligent data infrastructure company, as part of its broader 2025 strategy. Flexera aims to strengthen its FinOps offerings Spot by NetApp FinOps will help strengthen Flexera’s ability to better serve customers and partners…

Radix and Celanese to Collaborate with Cognite on AI-Powered Solution

Global technology solutions company Radix and global chemical and specialty material company, Celanese, have announced a collaboration with Cognite, a provider of data and AI technology for specialized industry use cases. The three companies have created JO.AI, a generative AI-powered solution aimed at improving operations in asset-intensive industries. New solution promises gains in efficiency and…

Barracuda Introduces Updates to Email Protection Solution

Barracuda Networks, Inc. recently announced advancements to Barracuda Email Protection, a solution that provides AI-powered protection against advanced threats. Email security enhancements target complex threats The updates to the email protection solution include flexible deployment options, enhanced security capabilities, and more advancements to make it easier for organizations of varying sizes and IT environments to…

VMware offers fixes to severe vulnerabilities in VMware Aria

VMware has fixed multiple high-severity vulnerabilities affecting its cloud management platform (CMP), VMware Aria, which could allow attackers to steal sensitive credentials from the virtualization giant’s IT management and logging solutions. Parent company Broadcom, in an advisory issued on Thursday, revealed that two out of five recently disclosed vulnerabilities are “high severity” information disclosure flaws…

Top 5 AI-Powered Social Engineering Attacks

Social engineering has long been an effective tactic because of how it focuses on human vulnerabilities. There’s no brute-force ‘spray and pray’ password guessing. No scouring systems for unpatched software. Instead, it simply relies on manipulating emotions such as trust, fear, and respect for authority, usually with the goal of gaining access to sensitive information…

US nonprofit healthcare provider says hackers stole medical and personal data of 1M+ patients

Community Health Center (CHC), a Connecticut-based nonprofit healthcare provider, has confirmed that hackers accessed the sensitive data of more than a million patients. In a filing with Maine’s attorney general on Thursday, CHC said it detected suspicious activity on its network on 2 January and determined that a “skilled criminal hacker” had accessed its network…

The push for 47-day certificates: a win for digital security and trust

By 2028, SSL/TLS certificate lifecycles may be cut down to just 47 days – a dramatic shift from the current 398-day maximum. Apple’s recent ballot submission to the CA/Browser Forum proposes this change, and it’s gaining traction among industry leaders, including Sectigo. While some enterprises may see this as an operational burden, the reality is…

Apple Intelligence will support more languages from April

Apple’s AI suite, Apple Intelligence, will soon be available in French, German, Italian, Portuguese, Spanish, Japanese, Korean, and simplified Chinese, along with localized English versions for India and Singapore. During the company’s Q4 2024 quarterly results call on Thursday, CEO Tim Cook said that the company will roll out support for these additional languages in…

Behörden schalten große Cybercrime-Foren ab

Die weltweit größte Handelsplattformen für Cybercrime im Internet ist offline. Cheryl-Annette Parker – shutterstock.com Die Generalstaatsanwaltschaft Frankfurt am Main und das Bundeskriminalamt haben zwei Cybercrime-Foren mit Millionen Nutzern abgeschaltet. Nach Angaben der Behörden handelte es sich um die weltweit größten Handelsplattformen für Cybercrime im Internet. Mehr als zehn Millionen Nutzer sollen auf den Plattformen “nulled.to”…

In another challenging year for startups, higher valuations and revenue give reason for hope

Welcome to Startups Weekly — your weekly recap of everything you can’t miss from the world of startups. Want it in your inbox every Friday? Sign up here. The aftermath of DeepSeek’s launch was arguably the biggest tech story of the week, especially for anyone keeping a close eye on public markets. But private companies,…

How law enforcement agents gain access to encrypted devices

Accessing data on encrypted devices might seem like something out of a hacker or spy movie, but for law enforcement, it’s a very real challenge. The issue is of relevance to CISOs and other security professionals because workers on sales trips or attending conferences overseas might face demands to decrypt devices and present their contents…

Broadcom Patches VMware Aria Flaws – Exploits May Lead to Credential Theft

Broadcom has released security updates to patch five security flaws impacting VMware Aria Operations and Aria Operations for Logs, warning customers that attackers could exploit them to gain elevated access or obtain sensitive information. The list of identified flaws, which impact versions 8.x of the software, is below – CVE-2025-22218 (CVSS score: 8.5) – A…

Bedrohungs-Monitoring: Die 10 besten Tools zur Darknet-Überwachung

Lesen Sie, worauf es beim Darknet-Monitoring ankommt und welche Tools dafür am besten geeignet sind. Foto: sashk0 – shutterstock.com Das Dark Web ist ein Ort, von dem jeder CISO hofft, dass die Daten seines Unternehmens dort nicht landen. Es besteht aus Websites, die von gängigen Suchmaschinen wie Google nicht indiziert werden. Dieser dunkle Teil des…

Exploring the Latest Trends and Threats in Cybersecurity: A Deep Dive for Geeks

In an era where digital transformation accelerates at an unprecedented pace, the landscape of cybersecurity evolves in tandem, presenting both challenges and opportunities for IT professionals and enthusiasts. From sophisticated data breaches to the implementation of zero trust security models, understanding the nuances of these developments is crucial. This article aims to dissect the latest…

WordPress Appliance - Powered by TurnKey Linux