Geek-Guy.com

Month: February 2025

Microsoft Uncovers Sandworm Subgroup’s Global Cyber Attacks Spanning 15+ Countries

A subgroup within the infamous Russian state-sponsored hacking group known as Sandworm has been attributed to a multi-year initial access operation dubbed BadPilot that stretched across the globe. “This subgroup has conducted globally diverse compromises of Internet-facing infrastructure to enable Seashell Blizzard to persist on high-value targets and support tailored network operations,” the

Trump picks Apple exec to lead transportation safety agency

President Donald Trump has chosen Jonathan Morrison, an Apple executive, to head the National Highway Traffic Safety Administration, per a Senate filing. The nomination will be reviewed and voted on by the Senate Committee on Commerce, Science and Transportation before being sent for a full Senate vote.  If he’s sworn in, Morrison will oversee an…

2023 Russian Hackers Back in News as HPE Discloses Data Exposure Risk

Bizarre and rather dramatically-named hacker organizations are at it again. A Russian hacker group, dubbed Midnight Blizzard (or Cozy Bear), breached HPE and stole the personal data of several employees at the company. Initial breach in 2023 recently flagged for potential information risk HPE actually discovered the breach on December 12, 2023, when they discovered…

DEF CON 32 – Leveraging AI For Smarter Bug Bounties

Authors/Presenters: Diego Jurado & Joel Niemand Sec Noguera Our sincere appreciation to DEF CON, and the Authors/Presenters for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel. Permalink The post DEF CON 32 – Leveraging AI For Smarter Bug…

Suger helps companies list and scale up on cloud marketplaces

When cloud providers like Microsoft Azure and AWS launched cloud software marketplaces a decade ago, it opened up a new sales channel for software-as-a-service (SaaS) companies to get in front of potential enterprise customers. These marketplaces effectively enabled SaaS companies to bypass the traditional, lengthy sales cycles. But rarely is the seller-side experience a walk…

Getting the Most Value out of the OSCP: Pre-Course Prep

The first post in a five-part practical guide series on maximizing the professional, educational, and financial value of the OffSec certification pursuit for a successful career in offensive cybersecurity consulting Disclaimer: All opinions expressed in this article are solely my own. I have reviewed the content to ensure compliance with OffSec’s copyright policies and agreements.…

Halcyon Allies with Pax8 on Ransomware Resilience

Halcyon has recently announced a team up with Pax8 to boost market outreach and fortify businesses against the threat of ransomware through a strategic partnership. Halcyon now available to channel partners on Pax8 marketplace The alliance between the two companies will bring Halcyon’s anti-ransomware platform to Pax8’s cloud marketplace. The partnership is rooted in a…

Halcyon Allies with Pax8 on Ransomware Resilience

Halcyon has recently announced a team up with Pax8 to boost market outreach and fortify businesses against the threat of ransomware through a strategic partnership. Halycon now available to channel partners on Pax8 marketplace The alliance between the two companies will bring Halcyon’s anti-ransomware platform to Pax8’s cloud marketplace. The partnership is rooted in a…

SGNL snags $30M for a new take on ID security based on zero-standing privileges

Security experts often describe identity as the “new perimeter” in the world of security: in the world of cloud services where network assets and apps can range far and wide, the biggest vulnerabilities are often leaked and spoofed log-in credentials.  A startup called SGNL has built a new approach that it believes is better at…

SpotDraft taps AI to help streamline contract management

More and more legal professionals are embracing AI, surveys show. Per a recent poll from legaltech company Clio, 79% of firms used some form of AI for casework last year, up from just 19% in 2023. Despite some skepticism of the tech, in-house counsel has shown an interest, as well, with one survey suggesting that…

Researchers Find New Exploit Bypassing Patched NVIDIA Container Toolkit Vulnerability

Cybersecurity researchers have discovered a bypass for a now-patched security vulnerability in the NVIDIA Container Toolkit that could be exploited to break out of a container’s isolation protections and gain complete access to the underlying host. The new vulnerability is being tracked as CVE-2025-23359 (CVSS score: 8.3). It affects the following versions – NVIDIA Container…

AI-driven manufacturing database Keychain raises $5M for European push

Brands are constantly trying to streamline how they source packaging materials and ingredient suppliers for their products in order to quickly meet consumer demand. However, even today this process can involve some laborious wandering around trade shows. Keychain is an AI-powered platform that aims to quickly connect the consumer packaged goods (CPG) industry with manufacturing…

Don’t use public ASP.NET keys (duh), Microsoft warns

Microsoft Threat Intelligence in December observed a “threat actor” using a publicly available ASP.NET machine key to inject malicious code and fetch the Godzilla post-exploitation framework, a “backdoor” web shell used by intruders to execute commands and manipulate files. The company then identified more than 3,000 publicly disclosed ASP.NET machine keys—i.e., keys that were disclosed in code…

Lanch bags $27M for a social media-skewed take on fast food

E-commerce startups built around food continue to gobble up funding as investors look for sticky consumer concepts that can scale without breaking the bank. On Wednesday, Germany’s Lanch — which taps social media and influencers to develop popular food brands alongside retail networks for distributing them — closed funding of €26 million ($27 million) to…

WatchGuard to Join AWS ISV Accelerate Program

WatchGuard, a unified cybersecurity vendor, is joining the Amazon Web Services (AWS) Independent Software Vendor (ISV) Accelerate Program, a co-sell program for AWS Partners that provides software solutions that run on or integrate with AWS and helps drive new business by connecting participating ISVs with the AWS Sales arm. WatchGuard latest of many to join…

Other World Computing and ARCHIWARE Partner on Collaborative Workflows

Other World Computing (OWC) is partnering with ARCHIWARE, a data management software provider, to deliver seamless shared storage, cloning, backup, and archiving for collaborative workflows. Collaboration addresses asset management needs for creatives OWC, an organization that delivers storage, docks, and memory card solutions to empower professionals in video and audio production, photography, and business with…

Ermittler zerschlagen Ransomware-Gruppierung 8Base

Die Gruppierung 8Base nutzte die Ransomware „Phobos“ und agierte weltweit als höchst professionelle kriminelle Organisation. In Deutschland fanden 365 Phobos-Angriffe statt. Gorodenkoff – shutterstock.com Ermittlern aus Bayern ist es zusammen mit internationalen Partnern gelungen, mehrere mutmaßliche Mitglieder einer Gruppe von Cyberkriminellen festzunehmen. Vier führende Köpfe der Gruppierung mit dem Namen 8Base seien in Thailand festgenommen…

Nozomi Networks welcomes Schneider Electric to its MSSP Elite Partner Program to deliver Advanced Managed Security Services worldwide

New Full-Scale, Industrial-Focused Security Management Service Designed to Safeguard the Most Complex Operational Environment COMPANY NEWS: Nozomi Networks, the leader in OT and IoT security, announced today that Schneider Electric, the leader in the digital transformation of energy management and automation, has joined its MSSP Elite Partner Program to deliver best-of-breed Managed Security Services (MSS)…

EU abandons ePrivacy, AI liability reforms, as bloc shifts focus to competitiveness & data access for AI

A long stalled bid to beef up European Union rules around online tracking technologies — and put penalties on a similar footing to the bloc’s data protection framework, GDPR, which allows for fines of up to 4% of annual turnover for breaches — has been withdrawn by the Commission after co-legislators failed to reach agreement…

No-code app builder Softr expands beyond Airtable databases

If you’re working for a small company and want to build a client portal or an internal tool, it can be difficult to find the budget and resources to allocate a developer to that small project. That’s why more than 600,000 people, including project managers, HR employees and marketing people, have been trying Softr’s no-code…

Hacker allegedly puts massive OmniGPT breach data for sale on the dark web

Popular AI rip-off OmniGPT, which provides access to multiple AI models including ChatGPT-4, Claude 3.5, Gemini, and Midjourney, has allegedly suffered a massive breach, exposing personal data belonging to over 30,000 users. On Monday, a BreachForums user “Gloomer” reportedly made a post, offering samples of the allegedly stolen data. “This leak contains all messages between…

A woman in China sued Tesla after complaining of faulty brakes — now she’s paying Tesla $23K

As per an investigation by the Associated Press (AP), Tesla has won a defamation lawsuit against one individual called Zhang Yazhou, who in February 2021 was a passenger in a Tesla Model 3 car that allegedly crashed due to faulty brakes, resulting in a four-day hospital stay for both her parents. Following the accident, Zhang…

DeepSeek erfasst Tastatureingabemuster

Selbst Tastatureingaben in der DeepSeek App können womöglich mitgelesen werden, bevor sie abgeschickt werden. Mojahid Mottakin – shutterstock.com Behörden und Cybersicherheitsfachleute haben gravierende Sicherheitsbedenken gegen die chinesische KI DeepSeek. Dabei geht es um mehrere Punkte: die offenkundig sehr weitreichende Speicherung von Nutzerdaten, die mögliche Manipulierbarkeit der Anwendung für kriminelle Zwecke und die Frage, inwieweit der…

Jeder fünfte CISO vertuscht Compliance-Probleme

Compliance-Verfehlungen unter den Teppich zu kehren, sollte sich für CISOs falsch anfühlen. Roman Samborskyi | shutterstock.com CISOs befinden sich zunehmend in der Zwickmühle, wenn es darum geht, eine gesunde Balance zwischen Loyalität zu ihrer Organisation und ihren rechtlichen Verantwortlichkeiten zu finden. Zumindest legt das eine aktuelle Studie des Sicherheitsanbieter Splunk nahe, in deren Rahmen 600…

Beyond the paycheck: What cybersecurity professionals really want

The cybersecurity industry is facing an unprecedented challenge: retaining skilled professionals in the midst of an ever-expanding threat landscape and a significant skills shortage. Organizations are finding themselves in fierce competition to attract and hold onto cybersecurity talent, and failing to do so can have dire consequences. According to recent research by Forrester, neglecting staff…

Tabby doubles valuation to $3.3B in $160M funding as it looks beyond BNPL and plans IPO

Consumer demand for credit options varies across regions, and for fintechs, understanding these differences is key to survival. In developed markets, where credit cards are common, consumers often view buy now, pay later (BNPL) offerings positively because of their flexible installment options. But in emerging markets like the Middle East, where credit card penetration is…

UK monitoring group to classify cyber incidents on earthquake-like scale

A UK body backed by the cyber insurance industry is seeking to establish a framework to classify the severity of cyber incidents affecting UK organisations. The Cyber Monitoring Centre (CMC) — an independent nonprofit organisation launched last week — aims to create a standardised scale for measuring the impact of cyber incidents from one (least…

Ivanti Patches Critical Flaws in Connect Secure and Policy Secure – Update Now

Ivanti has released security updates to address multiple security flaws impacting Connect Secure (ICS), Policy Secure (IPS), and Cloud Services Application (CSA) that could be exploited to achieve arbitrary code execution. The list of vulnerabilities is below – CVE-2024-38657 (CVSS score: 9.1) – External control of a file name in Ivanti Connect Secure before version…

Microsoft Patch Tuesday, February 2025 Edition

Microsoft today issued security updates to fix at least 56 vulnerabilities in its Windows operating systems and supported software, including two zero-day flaws that are being actively exploited. All supported Windows operating systems will receive an update this month for a buffer overflow vulnerability that carries the catchy name CVE-2025-21418. This patch should be a…

Trump picks Sean Cairncross for national cyber director

President Donald Trump has selected Sean Cairncross — a former White House and Republican National Committee official and the former CEO of the Millennium Challenge Corporation, a federal foreign aid agency — to be his national cyber director. Cairncross hasn’t held any major cyber-related positions, but during his time in the Trump White House as…

February Patch Tuesday: CISOs should act now on two actively exploited Windows Server vulnerabilities

CISOs should make sure that two actively exploited vulnerabilities in Windows are addressed as part of their staff’s February Patch Tuesday efforts. They are: CVE 2025-21391, a Windows Storage escalation of privilege vulnerability that, if exploited, could allow an attacker to delete – but not read — targeted files on a system. While this wouldn’t…

U.S. adversaries increasingly turning to cybercriminals and their malware for help

Governments of the United States’ chief adversaries in cyberspace, especially Russia, have increasingly been relying on cybercriminals and their tools to advance their goals, according to a Google report published Tuesday. There’s long been overlap between government and criminal cyber operators, but governments are now enjoying the benefits of collaboration and borrowing more — both…

Product Update | Cloud Monitor + Content Filter

NEW! In Cloud Monitor: Policy Enhancements We’re thrilled to introduce our latest Cloud Monitor policy updates! We designed these enhancements to make it easier than ever for administrators to keep students safe and secure in the classroom. With smarter alerting and automation, identifying and addressing violations now takes less manual effort, allowing you to stay…

Founders Fund is about to close another $3B fund

Founders Fund is on track to conclude fundraising of its third growth fund at the end of March, according to people close to the firm. The Peter Thiel-founded outfit is raising $3 billion, a source told TechCrunch and  Axios also reported. The fund, which is intended primarily for additional investments in its successful late-stage portfolio…

Authorities seize Phobos and 8Base ransomware servers, arrest 4 suspects

Law enforcement agencies from 14 countries collaborated in an investigation against the related Phobos and 8Base ransomware operations, arresting four suspects and seizing 27 servers, including the data leak and ransom negotiation websites. On Tuesday, the US Department of Justice also announced indictments against two Russian nationals who operated the “8Base” and “Affiliate 2803” affiliate…

Microsoft fixes 63 vulnerabilities, including 2 zero-days

Microsoft patched 63 vulnerabilities affecting some of its underlying systems and core products, the company said in its latest security update Tuesday, including Microsoft Excel, Microsoft Office, Windows CoreMessaging and Windows Storage. More than two-thirds of the vulnerabilities covered in the update are high-severity flaws on the CVSS scale. Vulnerabilities with high-severity base scores run…

Apple Maps plans to show ‘Gulf of America,’ following Google

Apple Maps will soon rename the Gulf of Mexico to the Gulf of America, following similar changes made by Google this week, in order to comply with U.S. President Donald Trump’s executive order that officially changed the name. U.S.-based Apple users may see the “Gulf of America” as soon as Tuesday, according to Bloomberg, and…

ChatGPT may not be as power-hungry as once assumed

ChatGPT, OpenAI’s chatbot platform, may not be as power-hungry as once assumed. But its appetite largely depends on how ChatGPT is being used, and the AI models that are answering the queries, according to a new study. A recent analysis by Epoch AI, a nonprofit AI research institute, attempted to calculate how much energy a…

Amazon tests sending customers directly to brands’ websites when it doesn’t stock their products

Remember that Christmas movie “Miracle on 34th Street,” where Macy’s in-store Santa, Kris Kringle, sends a frazzled shopper to a competitor’s store to find the Christmas present her son wanted because Macy’s was out of stock? Now, Amazon is doing the same thing online. The retailer announced on Tuesday the test of a new Amazon…

How to delete Facebook, Instagram, and Threads

In the wake of Meta’s decision to remove its third-party fact-checking system and loosen content moderation policies, Google searches on how to delete Facebook, Instagram, and Threads have been on the rise. People who are angry with the decision accuse Meta CEO Mark Zuckerberg of cozying up to the Trump administration at the expense of…

Google’s I/O developer conference set for May 20-21

Google Tuesday confirmed that its annual developer conference is set for May 20-21, 2025. The event will be held at the usual spot, Mountain View’s Shoreline Amphitheater, a few minutes — depending on traffic — from Google HQ. The two-day event is a mix of both public- and developer-facing content. CEO Sundar Pichai will kick…

Microsoft powers AI ambitions with 400 MW solar purchase

Microsoft has added another 389 megawatts of renewable power to its portfolio as the tech giant scrambles to meet the power demands required to match its AI ambitions.  The additional renewable power spans three solar projects developed by EDP Renewables North America — two in southern Illinois and one outside Austin, Texas. Microsoft is buying…

Shopify took down Kanye’s swastika T-shirt shop, but another antisemitic storefront still operates

Shopify took down Kanye West’s online store after the musician sold T-shirts with the swastika symbol. West, who also goes by Ye, advertised his online store in a Super Bowl commercial on Sunday, directing viewers to his website, where the only item listed was the swastika T-shirt. Though Shopify removed a policy banning sellers from…

Google says it removed cultural events from its calender last year

Google has removed events such as Black History Month and Pride Month from being listed on the calendar by default.  Other events that were removed from the default calendar include Jewish Heritage, Indigenous People Month, Holocaust Remembrance Day, and Hispanic Heritage Month.  Google spokesperson Madison Cushman Veld confirmed the changes to TechCrunch, saying that in…

Anduril takes control of Microsoft’s $22B VR military headset program

The Army has granted upstart weapons maker Anduril control of one of its highest-profile and long-troubled projects known as the Integrated Visual Augmentation System, founder Palmer Luckey announced in a blog post Tuesday. IVAS was initially awarded to Microsoft in 2018 to develop augmented reality headsets for soldiers based on a ruggedized version of Hololens.…

Bipartisan Senate bill would strengthen cybercrime penalties

Cybercrimes could be punished more harshly under a new bill from a pair of senators that seeks to amend U.S. criminal code on computer fraud. The Cyber Conspiracy Modernization Act from Sens. Mike Rounds, R-S.D., and Kirsten Gillibrand, D-N.Y., would modify the Computer Fraud and Abuse Act (CFAA) to establish a specific penalty for conspiracy…

Tumblr to join the fediverse after WordPress migration completes

Since 2022, blogging site Tumblr has been teasing its plans to integrate with the fediverse — the open social web powered by the protocol ActivityPub also used by Mastodon, Threads, Flipboard, and others. Now, the Automattic-owned blogging platform is sharing more information about when and how that integration could actually happen. As it turns out,…

How Musk’s $97.4B bid could gum up OpenAI’s for-profit conversion

On Monday, Elon Musk, the world’s richest man, offered to buy the nonprofit that effectively governs OpenAI for $97.4 billion. The unsolicited buyout would be financed by Musk’s AI company, xAI, and a consortium of outside investors, per a letter sent to California and Delaware’s attorneys general. OpenAI CEO Sam Altman quickly dismissed Musk’s bid,…

WordPress Appliance - Powered by TurnKey Linux