Geek-Guy.com

Category: Global Security News

How HHS has strengthened cybersecurity of hospitals and health care systems

Hospitals and health systems across the country are experiencing a significant rise in cyberattacks. These cyber incidents have caused extended disruptions, patient diversion to other facilities, and the cancellation of medical appointments and procedures — all of which undermine patient care and safety. These attacks also expose vulnerabilities in our health care system and degrade…

How to Bring Zero Trust to Wi-Fi Security with a Cloud-based Captive Portal?

Recent data breaches have highlighted the critical need to improve guest Wi-Fi infrastructure security in modern business environments. Organizations face increasing pressure to protect their networks while providing convenient access to visitors, contractors, temporary staff, and employees with BYOD. Implementing secure guest Wi-Fi infrastructure has become essential for authenticating access,

New ‘Sneaky 2FA’ Phishing Kit Targets Microsoft 365 Accounts with 2FA Code Bypass

Cybersecurity researchers have detailed a new adversary-in-the-middle (AitM) phishing kit that’s capable of Microsoft 365 accounts with an aim to steal credentials and two-factor authentication (2FA) codes since at least October 2024. The nascent phishing kit has been dubbed Sneaky 2FA by French cybersecurity company Sekoia, which detected it in the wild in December. Nearly…

Nord Security founders launch Nexos.ai to help enterprises take AI projects from pilot to production

A new AI orchestration startup from the founders of Lithuanian unicorn Nord Security is setting out to help enterprises put their AI projects into production, with an initial focus on bringing greater visibility, security and adaptability to large language models (LLMs). Nexos.ai, as the startup is called, is the handiwork of Tomas Okmanas (pictured above)…

EU’s DORA could further strain cybersecurity skills gap

Efforts spent in achieving compliance with the EU’s Digital Operational Resilience Act (DORA) are likely to pile further pressure on the already strained cybersecurity skills market. DORA, which comes into full effect today, aims to improve the cybersecurity and operational resilience of financial institutions in the EU, including banks, insurance companies, and investment firms. The…

European Privacy Group Sues TikTok and AliExpress for Illicit Data Transfers to China

Austrian privacy non-profit None of Your Business (noyb) has filed complaints accusing companies like TikTok, AliExpress, SHEIN, Temu, WeChat, and Xiaomi of violating data protection regulations in the European Union by unlawfully transferring users’ data to China. The advocacy group is seeking an immediate suspension of such transfers, stating the companies in question cannot shield…

Was ist ein Payload?

Ähnlich wie damals die griechischen Soldaten, die im Inneren des trojanischen Pferdes auf den passenden Zeitpunkt lauerten, werden Payloads zum Beispiel in vermeintlich harmlosen Dateianhängen versteckt und starten ihren Angriff oftmals durch einen Trigger zu einem späteren Zeitpunkt. Foto: wk1003mike – shutterstock.com Der Begriff „Payload“ hat seinen Ursprung im Transportwesen. Dort beschreibt „Nutzlast“ die Menge…

Millions of tunneling hosts are vulnerable to spoofing, DDoS attacks, say researchers

There are more than 4 million vulnerable hosts on the internet that accept unauthenticated traffic, say Belgian researchers, who warn that, unless action is taken by CISOs and network product manufacturers, those hosts can be abused as one-way proxies, enabling an adversary to spoof the source address of packets to permit access to an organization’s…

Apple brings Store app to Indian market

Apple launched its dedicated Apple Store app in India on Friday, deepening its retail presence in the world’s most populous country as the iPhone-maker seeks to capitalize on growing consumer demand. The app, available for download on India’s App Store, lets customers purchase Apple products directly while receiving personalized shopping recommendations, the company said in…

FAA had to divert flights because of SpaceX Starship explosion

The Federal Aviation Administration has told TechCrunch that it had to “briefly” slow and divert a number of aircraft near the area where debris was seen falling after SpaceX’s Starship exploded during a test flight Thursday. Multiple flights could be seen entering holding patterns or completely changing course in the airspace near Puerto Rico shortly…

A Peek Inside the Current State of BitCoin Exchanges

Dear blog readers, In this post I’ll provide some actionable intelligence on the current state of active BitCoin Exchanges landscape with the idea to assist everyone on their way to properly attribute a fraudulent or malicious transaction or to dig a little bit deeper inside the infrastructure and financial infrastructure behind these BitCoin Exchanges. Sample…

SpaceX catches Starship booster a second time, loses ship to an ‘anomaly’ in space

SpaceX caught the Starship rocket’s Super Heavy booster for a second time, after it launched the upper stage into space on Thursday during a seventh test flight of the system. Soon after the successful catch, SpaceX representatives reported the ship was lost after the company lost contact about eight and half minutes into the flight.…

Despite VCs investing $75B in Q4 , it’s still hard for startups to raise money, data proves

After two years of relatively muted investment activity, it seems that VCs are starting to pour capital into startups at pandemic-era levels once again. But a closer look shows that they aren’t really. In the fourth quarter of last year, investors funneled $74.6 billion into US startups, a substantial increase from the average of $42…

Treasury sanctions North Korea over remote IT worker schemes

The U.S. Treasury Department announced sanctions Thursday against two individuals and four entities allegedly involved in generating revenue for North Korea through illicit remote IT workforce operations, the latest salvo in ongoing efforts to disrupt financial streams that support Pyongyang’s weapons programs. The sanctions focus on efforts in which North Korea sent thousands of skilled…

Chinese Innovations Spawn Wave of Toll Phishing Via SMS

Residents across the United States are being inundated with text messages purporting to come from toll road operators like E-ZPass, warning that recipients face fines if a delinquent toll fee remains unpaid. Researchers say the surge in SMS spam coincides with new features added to a popular commercial phishing kit sold in China that makes…

Apple pauses AI notification summaries for news after generating false alerts

Apple is pausing AI notification summaries for news and entertainment apps after facing backlash for generating inaccurate news alerts. In addition, the company is introducing changes to notification summaries as a whole to allow for greater transparency. With the latest round of developer previews for iOS 18.3, iPadOS 18.3, and macOS Sequoia 15.3, Apple is disabling…

Biden cyber executive order gets mostly plaudits, but its fate is uncertain

A sweeping executive order on cybersecurity released Thursday won largely positive reviews, with the main question being its timing — and what will come of it with the executive branch set to be handed over from president to president. Chris Inglis, the former national cyber director for Joe Biden who has served under both Democrats…

Threads might let you add music to your posts in the future

Meta’s Threads is internally prototyping the ability to add music to posts, the company confirmed to TechCrunch. The option to add music to posts is already available on Meta’s other social apps, Instagram and Facebook. It looks like the company is now thinking about bringing the feature to Threads, its X competitor. The feature isn’t…

DEF CON 32 – Signature-Based Detection Using Network Timing

Author/Presenter: Josh Pyorre Our sincere appreciation to DEF CON, and the Authors/Presenters for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel. Permalink The post DEF CON 32 – Signature-Based Detection Using Network Timing appeared first on Security Boulevard.

NVIDIA Partnerships to Boost AI in the Healthcare Industry

Multinational tech giant NVIDIA made a handful of recent announcements that highlight its participation in the AI revolution permeating the healthcare industry.  During a press briefing, Kimberly Powell, Vice President of Healthcare at NVIDIA, broke down NVIDIA’s recent moves in the AI and healthcare space, including collaborating with other entities to enable new products and…

How do you unlock automation within IT security and IT operations?

The proliferation of endpoints in today’s enterprises is outpacing the ability of IT operations and security teams to cost-effectively manage increasingly complex environments.  Already stretched thin, teams face the daunting task of securing vast IT estates with siloed tools, stale data, and other hindrances that create the perfect “imperfect” environment for vulnerabilities. And simply adding…

Nvidia releases more tools and guardrails to nudge enterprises to adopt AI agents

Nvidia is releasing three new NIM microservices, or small independent services that are part of larger applications, to help enterprises bring additional control and safety measures to their AI agents. One of these new NIM services targets content safety and works to prevent an AI agent from generating harmful or biased outputs. Another works to…

Mark Cuban is ready to fund a TikTok alternative built on Bluesky’s AT Protocol

Entrepreneur and investor Mark Cuban is ready to fund a TikTok alternative built on Bluesky’s AT Protocol, he shared in a TikTok video posted on Wednesday. In anticipation of the coming U.S. TikTok ban, which will go through on Sunday unless paused by the Supreme Court, users have been fleeing to other video platforms, including…

Russian Star Blizzard Shifts Tactics to Exploit WhatsApp QR Codes for Credential Harvesting

The Russian threat actor known as Star Blizzard has been linked to a new spear-phishing campaign that targets victims’ WhatsApp accounts, signaling a departure from its longstanding tradecraft in a likely attempt to evade detection. “Star Blizzard’s targets are most commonly related to government or diplomacy (both incumbent and former position holders), defense policy or…

A rising EV startup star snags $100M and Tesla’s win-lose federal funding moment

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Before we move into the news of this week, we have one more roundup of transportation tech at CES 2025. As I noted last week, autonomous vehicle…

TikTok ban poised to be delayed as Trump explores ways to extend deadline

The U.S. ban on TikTok is poised to be delayed as the deadline falls on the MLK Day holiday weekend and President-elect Donald Trump’s incoming administration intends to find a way to extend the deadline, Bloomberg reports. Biden officials see the issue as one for Trump’s incoming administration, as the current administration doesn’t plan to intervene…

Goldman Sachs’ David Solomon tells startups to reconsider going public

Goldman Sachs is one of the biggest investment banker “book runners” for IPOs – where banks are paid many millions of dollars for each listing they underwrite. Yet CEO David Solomon told attendees of the Cisco AI Summit in Palo Alto that startups should reconsider the idea of going public, reports the Financial Times.  Solomon…

Microsoft catches Russian state-sponsored hackers shifting tactics to WhatsApp

The cat-and-mouse game between state-sponsored Russian hackers and one of the world’s biggest technology companies has continued into 2025.  Microsoft’s threat intelligence team published research Thursday examining how a state-sponsored Russian threat actor group, known as Star Blizzard, has altered its longstanding attack strategies to target WhatsApp accounts. This attack vector is a significant change…

This MIT spinout wants to spool hair-thin fibers into patients’ brains

You can’t start a company without a healthy dose of daring, and that’s certainly the case with NeuroBionics. The MIT-spinout thinks it could one day improve the lives of millions of people who live with neurological conditions like depression, epilepsy and Parkinson’s disease.  Famed investor Steve Jurvetson of Future Ventures said that if everything goes…

Symbotic set to take over Walmart’s robotics business

Walmart and Symbotic announced a deal Tuesday that would find the Massachusetts robotics firm taking control of the mega-retailer’s automation business. Symbotic is paying $200 million in cash for the program, plus up to $350 million in “additional contingent consideration,” depending on how the deal shakes out. The relationship is more partnership than straight acquisition,…

Netradyne snags $90M at $1.25B valuation to expand smart dashcams for commercial fleets

Distracted driving is a leading cause of car crashes — and rising auto insurance premiums, which are expected to increase in 2025. For commercial fleets, that’s an expensive challenge to navigate. But for California-based startup Netradyne, it’s a tailwind.  Netradyne provides fleet owners, including big names like Amazon, with AI-enabled dashcams that collect vehicle data…

Teal Health raises $10M to create at-home cervical cancer screenings

The process of getting screened for cervical cancer is quite intimidating. It’s the once-a-year, sometimes life-changing treatment, that involves the bright lights of a doctor’s office and an uncomfortable insertion that always seems to last too long.   It’s no wonder why Kara Egan and Dr. Avnesh Thakor saw the potential to make this process more…

NVIDIA Announces NIM Microservices for NeMo Guardrails to Secure AI Agents

NVIDIA recently announced the availability of new microservice programs aimed at enabling organizations to embrace agentic AI without sacrificing security or latency.  New NIM programs bring guardrails across content, access, and more The added microservices are a new component of NVIDIA’s pre-existing NeMo Guardrails, part of the NeMo platform built for curating, customizing, and guardrailing…

TikTok CEO plans to attend Trump inauguration

As TikTok’s fate hangs in the balance, TikTok CEO, Shou Chew, is planning to attend President-elect Donald Trump’s inauguration on Monday, The New York Times reports. The executive will join Mark Zuckerberg, Jeff Bezos, and Elon Musk on the dais, which is where former presidents and important guests are traditionally seated. Although Trump initiated calls…

A CISA secure-by-design guru makes the case for the future of the initiative

One of the chief architects of the Cybersecurity and Infrastructure Security Agency campaign to get software developers to design their products with security in mind said he believes it could be one of the best tools the Trump administration has to counter China. Jack Cable, who is departing his role as senior technical adviser Thursday,…

Bipartisan cloud study recommends speeding federal adoption, or remain vulnerable on cyber

Slow adoption of cloud technologies poses a cybersecurity hazard for federal agencies, which will require an overhaul of contracting, regulatory and budgeting procedures to fix, a bipartisan think tank report that will be released Thursday concludes. Led by veterans of both the first Trump administration and Biden administration as well as lawmakers from both parties,…

International agierende Internetbetrüger geschnappt

Insgesamt waren ca. 150 Polizeikräfte – davon 10 Polizeibeamte des Nürnberger Kriminalfachdezernats 5 – und zwei Staatsanwältinnen sowie zwei IT-Forensiker der ZCB in Deutschland, Rumänien und Österreich im Einsatz. m.mphoto – shutterstock.com Die Kripo Nürnberg und die bayerische Zentralstelle Cybercrime melden einen Erfolg im Kampf gegen die organisierte Internet-Kriminalität. Den fünf Tatverdächtigen werden zahlreiche Fälle…

Fortinet firewalls hit with new zero-day attack, older data leak

GUEST OPINION:   Rapid7 is investigating two separate events affecting Fortinet firewall customers: Zero-day exploitation of CVE-2024-55591, an authentication bypass vulnerability in FortiOS and FortiProxy disclosed earlier this week. Successful exploitation could allow remote attackers to gain super-admin privileges via crafted requests to the Node.js websocket module. A January 15, 2025, dark web post from a threat…

ISPT’s future focused office buildings ‘lead the way’ with 5G indoor mobile connectivity

By Peggy Renders, Chief Customer Officer for Telstra Enterprise: ISPT and Telstra have announced that they are transforming office connectivity with 5G DAS tech, ensuring reliable, high-speed coverage in lifts, carparks, and more – with the first deployment in Sydney’s new Tech Central precinct, Sydney, with other sites on the radar.

Dub.co is an open-source URL shortener and link attribution engine packed into one

In the last few weeks, PayPal-owned Honey, which claims to find you the best coupon codes for a deal, has been at the center of controversy. Allegedly, the tool sneakily earned affiliate money by changing attributes of product links creators posted on their videos. At the center of it, the problem was how affiliate links…

WordPress Appliance - Powered by TurnKey Linux