Geek-Guy.com

Category: North America

Analyze the latest North American cybersecurity trends, from critical infrastructure protection to evolving threat actor tactics. Get expert insights on regional data security, identity management, and the impact of AI on digital defense across the U.S. and Canada.

Taiwanese operator of Incognito Market sentenced to 30 years over $105M darknet drug ring

A Taiwanese man was sentenced to 30 years for running Incognito Market, a major darknet drug site that sold over $105 million in illegal drugs. Rui-Siang Lin (24) was sentenced to 30 years in prison for running Incognito Market, a major darknet drug marketplace that sold over one ton of narcotics. The Taiwanese man pled…

Think agentic AI is hard to secure today? Just wait a few months

Early experimentation with agentic AI has given CISOs a preview of the possible cybersecurity nightmares ahead. But with autonomous agent adoption expected to soar throughout 2026, CISOs’ lack of visibility into agentic identities, activities, and decision-making is set to get far worse in quick measure. Agentic use will vary by enterprise, but analysts, consultants, and…

Scanning for exposed Anthropic Models, (Mon, Feb 2nd)

Yesterday, a single IP address (%%ip:204.76.203.210%%) scanned a number of our sensors for what looks like an anthropic API node. The IP address is known to be a Tor exit node. The requests are pretty simple: GET /anthropic/v1/models Host: 67.171.182.193:8000 X-Api-Key: password Anthropic-Version: 2023-06-01 It looks like this is scanning for locally hosted Anthropic models,…

Scanning for exposed Anthropic Models, (Mon, Feb 2nd)

Yesterday, a single IP address (%%ip:204.76.203.210%%) scanned a number of our sensors for what looks like an anthropic API node. The IP address is known to be a Tor exit node. The requests are pretty simple: GET /anthropic/v1/models Host: 67.171.182.193:8000 X-Api-Key: password Anthropic-Version: 2023-06-01 It looks like this is scanning for locally hosted Anthropic models,…

The ‘staggering’ cybersecurity weakness that isn’t getting enough focus, according to a top Secret Service official

The internet domain registration system is a major weakness that malicious hackers can exploit, but is often being overlooked, a senior Secret Service official said Thursday. “It is staggering to me that we live in a world where domain registrars and registrars will do bulk registration of various spellings of a major institution’s brand name…

Lawmakers, election officials blast Trump administration after Fulton County raid 

Following a federal raid on Fulton County, Georgia’s Elections Office, lawmakers and state election officials sharply criticized  the Trump administration, accusing the White House of chasing baseless internet conspiracy theories about fraud in the 2020 election. Officials also warned the raid could set a precedent for similar federal actions targeting the 2026 midterm elections. According…

Undressed victims file class action lawsuit against xAI for Grok deepfakes

A class of individuals who say they were victimized by nude or undressed deepfakes generated by Grok have filed a lawsuit against parent company xAI, calling the tool “a generative artificial intelligence chatbot that humiliates and sexually exploits women and girls by undressing them and posing them in sexual positions in deepfake images publicly posted…

Always-on privileged access is pervasive — and fraught with risks

Privileged access management (PAM) has always been about ensuring least privilege. But the nature of enterprise cybersecurity — on top of the complexity of system operations — has prompted far too many users to log in at the highest possible privilege and stay there, even when most of their tasks do not require it. One…

Apple Workers Are Livid That Tim Cook Saw “Melania” Movie Hours After CBP Killed Pretti

Just hours after a U.S. Border Patrol officer gunned down Minneapolis resident Alex Pretti, Apple CEO Tim Cook, donned his tuxedo to attend an exclusive screening of a new documentary about First Lady Melania Trump. A growing number of Apple workers are now internally criticizing Cook and the company’s silence in the face of an…

Initial Stages of Romance Scams [Guest Diary], (Tue, Jan 27th)

[This is a Guest Diary by Fares Azhari, an ISC intern as part of the SANS.edu BACS program] Romance scams are a form of social-engineering fraud that causes both financial and emotional harm. They vary in technique and platform, but most follow the same high-level roadmap: initial contact, relationship building, financial exploitation. In this blog post I focus…

AI needs a course correction, say World Economic Forum speakers

Discussions around artificial intelligence dominated the 2026 World Economic Forum meeting in Davos, Switzerland. Prognosticators said the situation may get worse before it improves. Top executives talked about improved productivity and economic impact with advances in finance, healthcare, and other sectors. But others noted concerns about the unchecked race to superintelligence, warning that AI’s illusions…

Leader of ransomware crew pleads guilty to four-year crime spree

A Russian national pleaded guilty to leading a ransomware conspiracy that targeted at least 50 victims during a four-year period ending in August 2022.  Ianis Aleksandrovich Antropenko began participating in ransomware attacks before moving to the United States, but conducted many of his crimes while living in Florida and California, where he’s been out on…

Researchers find Jordan government used Cellebrite phone-cracking tech against activists

Jordanian authorities used Cellebrite phone-cracking technology to access the devices of domestic activists and human rights defenders and then extract information from them, according to an investigation published Thursday. The nonconsensual access stood in conflict with international human rights treaties that Jordan ratified, the University of Toronto’s Citizen Lab investigation determined, prompting the research organization…

Crooks impersonate LastPass in campaign to harvest master passwords

Password manager LastPass warns of an active phishing campaign impersonating the service to steal users’ master passwords. LastPass warned users about an active phishing campaign that began around January 19, 2026. Attackers impersonate the service with emails claiming urgent maintenance and urge users to back up their password vaults within 24 hours. The messages use…

Add Punycode to your Threat Hunting Routine, (Tue, Jan 20th)

IDNs or “International Domain Names” have been with us for a while now (see RFC3490[1]). They are (ab)used in many attack scenarios because.. it works! Who can immediately spot the difference between: https://youtube.com/ And: https://youtube.com/ The magic is to replace classic characters by others that look almost the same. In the example above, the letter “o”…

Jordanian national pleads guilty after unknowingly selling FBI agent access to 50 company networks

A 40-year-old Jordanian national pleaded guilty Thursday to operating as an access broker, selling access to at least 50 victim company networks he broke into by exploiting two commercial firewall products in 2023, according to the Justice Department. Feras Khalil Ahmad Albashiti, who lived in the Republic of Georgia at the time, sold an undercover…

Report: Why AI Productivity Gains Disappear into Rework

Workday, an enterprise AI platform, recently released new research that found AI is delivering productivity gains, but organizations aren’t fully capturing its value. Report shows workers find themselves fixing mistakes in AI work too often The Beyond Productivity: Measuring the Real Value of AI report found that employees surveyed are saving meaningful time with AI…

Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain, (Wed, Jan 14th)

Introduction In recent weeks, Lumma Stealer infections have followed a specific pattern in follow-up activity. This pattern adds scheduled tasks for the same action, which increases traffic to the same C2 domain. This diary documents an example from one of these infections on January 14, 2026. Details After Lumma Stealer performs its data exfiltration, the…

Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain, (Wed, Jan 14th)

Introduction In recent weeks, Lumma Stealer infections have followed a specific pattern in follow-up activity. This pattern adds scheduled tasks for the same action, which increases traffic to the same C2 domain. This diary documents an example from one of these infections on January 14, 2026. Details After Lumma Stealer performs its data exfiltration, the…

Microsoft seizes RedVDS infrastructure, disrupts fast-growing cybercrime marketplace

Microsoft announced Wednesday that it worked with international law enforcement to seize infrastructure used to run cybercrime subscription service RedVDS and organized civil actions in the United States and United Kingdom to disrupt its further use.  RedVDS has enabled at least $40 million in fraud losses in the U.S. since March 2025, according to Microsoft.…

Hill warning: Don’t put cyber offense before defense

Amid budding sentiment in the Trump administration and Congress to expand offensive cyber operations, some lawmakers and experts are warning that the United States needs to get its defenses in order before going too far down that road. A House Homeland Security subcommittee on Tuesday examined how to deter foreign cyberattacks, with an emphasis on…

Why Is Everyone Suddenly Talking About Putting Data Centers in Space?

Data centers present sprawling engineering and political problems, with ravenous appetites for land and resources. Building them on Earth has proven problematic enough — so why is everyone suddenly talking about launching them into space? Data centers are giant warehouses for computer chips that run continuously, with up to hundreds of thousands of processors packed…

AI, voting machine conspiracies fill information vacuum around Venezuela operation 

The surprise raid by U.S. armed forces and law enforcement agencies in Caracas, Venezuela had observers around the world scouring social media and news for updates on an operation that saw Venezuelan president Nicholas Maduro and his wife captured and flown to the United States to face criminal charges. The Trump administration initially offered few…

President Trump blocks $2.9M Emcore chip sale over security concerns

Trump ordered the divestment of a $2.9M chip deal, citing U.S. national security risks if HieFo retained control of Emcore ’s technology. President Trump ordered the divestment of a $2.9 million chips deal, citing national security risks tied to HieFo Corp.’s control of Emcore ’s chip technology. HieFo (short for High Efficiency Photonics) is a…

Cryptocurrency Scam Emails and Web Pages As We Enter 2026, (Sun, Jan 4th)

Introduction In October 2025, a work colleague documented a cryptocurrency scam using a fake chatbot. After investigating this, I was able to receive messages from the campaign, and these emails have continued to land in my honeypot account since then. This diary documents the cryptocurrency scam campaign as it continues in 2026. Shown above: My honeypot…

Phishing campaign abuses Google Cloud Application to impersonate legitimate Google emails

Researchers uncovered a phishing campaign abusing Google Cloud Application Integration to send emails posing as legitimate Google messages. Check Point researchers have revealed a phishing campaign that abuses Google Cloud Application Integration to send emails impersonating legitimate Google messages. The attack uses layered redirection with trusted cloud services, user validation checks, and brand impersonation to…

U.S. Federal Communications Commission (FCC) bans foreign-made drones over national security concerns

The FCC announced a ban on drones and critical components made in foreign countries, citing national security concerns. The U.S. Federal Communications Commission (FCC) said it has banned drones and key components manufactured abroad over national security concerns. The U.S. government said drones can improve safety and innovation but also pose security risks if used…

Ukrainian hacker pleads guilty to Nefilim Ransomware attacks in U.S.

Ukrainian Artem Stryzhak (35) pleaded guilty in the U.S. for Nefilim ransomware attacks; he was arrested in Spain in 2024, extradited in April 2025. A 35-year-old Ukrainian, Artem Aleksandrovych Stryzhak (35), pleaded guilty in the U.S. for Nefilim ransomware attacks. The Ukrainian citizen was arrested in Spain in 2024 and extradited to the US in…