Geek-Guy.com

Category: Global Security News

ASUS Confirms Critical Flaw in AiCloud Routers; Users Urged to Update Firmware

ASUS has disclosed a critical security flaw impacting routers with AiCloud enabled that could permit remote attackers to perform unauthorized execution of functions on susceptible devices. The vulnerability, tracked as CVE-2025-2492, has a CVSS score of 9.2 out of a maximum of 10.0. “An improper authentication control vulnerability exists in certain ASUS router firmware series,”

A new kids’ show will come with a crypto wallet when it debuts this fall

A new animated kids’ series expected to premiere this year won’t be headed for a TV network. Or a streaming service. Instead, the founders of production studio We Ghosted Media plan to launch on a decentralized web platform that uses blockchain technology. And yes, a crypto wallet will be involved.  We Ghosted Media — founded by…

Techstars increases startup funding to $220,000, mirroring YC structure

Techstars, a nearly 20-year-old startup accelerator, announced new terms for startups that enter its three-month program. The organization will now invest $220,000, which is $100,000 more than it offered previously, in companies starting with its fall 2025 batch. The capital will be divided into two components. The group is offering companies $20,000 in exchange for…

Stay Reassured with Advanced NHIDR

Can Advanced NHIDR Keep Your Cloud Environment Secure? Enriched with advanced technologies, potential threats also grow in complexity. One such concern circulates around the concept of Non-Human Identities (NHIs) and Secrets Security Management. But, what if there was a way to feel reassured about your security in NHIs? In comes the role of advanced NHIDR—…

Maximizing Data Protection in Healthcare

Understanding the Vitality of Non-Human Identities in Healthcare Data Protection What if you could significantly diminish security risks in your healthcare organization while enhancing operational efficiency? Non-human identities (NHIs) and Secrets Security Management offer the answer to that pressing question. When the dynamics of securing sensitive data continue to evolve, the role of NHIs in…

Securing Secrets: A Path to a Relaxed Audit

Why Is Secrets Security Essential in Today’s Digital Landscape? Is secrets security, also known as Non-Human Identities (NHIs) management, really that important? If you’re searching for a relaxed audit, the answer is a resounding ‘yes’. NHI management is an indispensable facet of modern cybersecurity strategies across various industries, from financial services and healthcare to DevOps…

Staying Ahead with Proactive Secrets Rotation

Why Should Organizations Prioritize Proactive Secrets Rotation? Where digital connectivity is ever-increasing, how can organizations stay one step ahead? One answer lies in proactive secrets rotation – a strategy that is pivotal to maintaining robust cybersecurity health. Not only does this strategy allow companies to prevent unauthorized access to their networks, but it also facilitates…

ChatGPT: Everything you need to know about the AI-powered chatbot

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm since its launch in November 2022. What started as a tool to supercharge productivity through writing essays and code with short text prompts has evolved into a behemoth with 300 million weekly active users. 2024 was a big year for OpenAI, from its partnership…

TechCrunch Mobility: Lyft buys its way into Europe, Kodiak SPACs, and how China’s new ADAS rules might affect Tesla

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Enough with my typical small talk. Let’s jump into the news right away this week. And there’s plenty of it, including Lyft’s entry into Europe, AV startup…

White House replaces covid.gov website with ‘lab leak’ theory

The government-run website covid.gov used to host information about COVID-19 vaccines, testing, and treatment. Now, under President Trump’s purview, the page redirects to a White House website espousing the unproven theory that COVID-19 originated in a Chinese laboratory. The theory, which has been opposed by many virologists, was espoused in a report by House Republicans…

ChatGPT is referring to users by their names unprompted, and some find it ‘creepy’

Some ChatGPT users have noticed a strange phenomenon recently: occasionally, the chatbot refers to them by name as it reasons through problems. That wasn’t the default behavior previously, and several users claim ChatGPT is mentioning their names despite never having been told what to call them. Reviews are mixed. One user, software developer and AI…

BSidesLV24 – Common Ground – One Port to Serve Them All – Google GCP Cloud Shell Abuse

Author/Presenter: Hubert Lin Our sincere appreciation to BSidesLV, and the Presenters/Authors for publishing their erudite Security BSidesLV24 content. Originating from the conference’s events located at the Tuscany Suites & Casino; and via the organizations YouTube channel. Permalink The post BSidesLV24 – Common Ground – One Port to Serve Them All – Google GCP Cloud Shell…

ChatGPT will now use its ‘memory’ to personalize web searches

OpenAI is upgrading ChatGPT’s “memory” again. In a changelog and support pages on OpenAI’s website Thursday, the company quietly announced “Memory with Search,” a feature that lets ChatGPT draw on memories — details from past conversations, such as your favorite foods — to inform queries when the bot searches the web. ChatGPT release notes were…

CVE-2025-32433: Erlang/OTP SSH Unauthenticated Remote Code Execution Vulnerability

Proof-of-concept code has been released after researchers disclosed a maximum severity remote code execution vulnerability in Erlang/OTP SSH. Successful exploitation could allow for complete takeover of affected devices. Background On April 16, Fabian Bäumer, Marcus Brinkmann, Marcel Maehren, and Jörg Schwenk of the Ruhr University Bochum in Germany disclosed a critical vulnerability in Erlang/OTP SSH…

Chinese Smishing Kit Powers Widespread Toll Fraud Campaign Targeting U.S. Users in 8 States

Cybersecurity researchers are warning of a “widespread and ongoing” SMS phishing campaign that’s been targeting toll road users in the United States for financial theft since mid-October 2024. “The toll road smishing attacks are being carried out by multiple financially motivated threat actors using the smishing kit developed by ‘Wang Duo Yu,’” Cisco Talos researchers…

From Bogotá to the Battlefield: LatAm startups are winning big in TechCrunch Startup Battlefield

For startups around the world, the TechCrunch Startup Battlefield program offers unmatched exposure, credibility, and connections to scale their businesses. TechCrunch has long been committed to spotlighting companies solving real-world problems in scalable and sustainable ways — making it a powerful launchpad for startups both in and outside the U.S. Several Latin American startups have…

BSidesLV24 – Common Ground – Beyond Whack-a-Mole: Scaling Vulnerability Management by Embracing Automation

Author/Presenter: Yotam Perkal Our sincere appreciation to BSidesLV, and the Presenters/Authors for publishing their erudite Security BSidesLV24 content. Originating from the conference’s events located at the Tuscany Suites & Casino; and via the organizations YouTube channel. Permalink The post BSidesLV24 – Common Ground – Beyond Whack-a-Mole: Scaling Vulnerability Management by Embracing Automation appeared first on…

Final day to submit your speaker application and shape the next wave of startups at TechCrunch All Stage

Today’s the day! The application to speak at TechCrunch All Stage closes tonight at 11:59 p.m. PT — this is your final chance to share real-world insights with 1,200+ startup founders and VCs attending the event. Whether you’ve built or backed startups, battled bottlenecks, or cracked the code on growth, the stage is yours. TC…

NetBrain Enhances AI-Driven No-Code Network Automation

NetBrain Technologies, Inc., a no-code automation platform for hybrid network observability, announced new platform enhancements that further integrate agentic AI with intent-based automation to transform network operations. New release brings insights, assessments, and Kubernetes support to users The latest release from NetBrain, Next-Gen 12, enables more AI-driven innovations to enhance real-time observability and continuous network…

Netflix is revamping search with AI to improve discovery

Netflix is building a new search experience aimed at improving the discovery experience, and it’s going to use AI to do it, the company’s CEO Greg Peters said during its first-quarter results conference call. Peters said Netflix is working on “interactive search that’s based on generative technologies” to help people find different titles. Answering an…

Multi-Stage Malware Attack Uses .JSE and PowerShell to Deploy Agent Tesla and XLoader

A new multi-stage attack has been observed delivering malware families like Agent Tesla variants, Remcos RAT, and XLoader. “Attackers increasingly rely on such complex delivery mechanisms to evade detection, bypass traditional sandboxes, and ensure successful payload delivery and execution,” Palo Alto Networks Unit 42 researcher Saqib Khanzada said in a technical write-up of the campaign.…

Unlock the Power of Financial Quantification of Cyber Risk

In today’s complex threat landscape, gut feelings and disparate risk scores are no longer sufficient for effective cyber risk management. Organizations need concrete, data-driven insights to make informed decisions, prioritize security investments, and ultimately, protect their bottom line. This is where cyber risk quantification (CRQ) steps in, offering a powerful lens through which to view…

GFI Software Appoints ADN as Exclusive DACH Distributor

GFI, a provider of AI-powered security and communications solutions for small and medium-sized businesses (SMBs), recently announced that it will extend its strategic partnership with ADN Distribution GmbH by appointing them as the exclusive distributor for the DACH region (Germany, Austria, and Switzerland) across all product lines. Extensive partnership goes even further with new agreement…

GTT’s Sara Seegers on Channel Approach & Meeting Tech Demand

Networking and security as a service provider GTT is tackling increasingly complex challenges across technologies and verticals with an innovative platform experience and a commitment to building a strong global ecosystem. Channel Insider spoke with GTT SVP of Channel and Partner Program, Americas Sara Seegers to learn more about how the company is approaching this…

Experts Uncover New XorDDoS Controller, Infrastructure as Malware Expands to Docker, Linux, IoT

Cybersecurity researchers are warning of continued risks posed by a distributed denial-of-service (DDoS) malware known as XorDDoS, with 71.3 percent of the attacks between November 2023 and February 2025 targeting the United States. “From 2020 to 2023, the XorDDoS trojan has increased significantly in prevalence,” Cisco Talos researcher Joey Chen said in a Thursday analysis. 

When AI moves beyond human oversight: The cybersecurity risks of self-sustaining systems

Artificial intelligence is no longer just a tool executing predefined commands, it is increasingly capable of modifying itself, rewriting its own parameters, and evolving based on real-time feedback. This self-sustaining capability, sometimes referred to as autopoiesis, allows AI systems to adapt dynamically to their environments, making them more efficient but also far less predictable. For cybersecurity…

CVE-2025-24054 Under Active Attack—Steals NTLM Credentials on File Download

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a medium-severity security flaw impacting Microsoft Windows to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, assigned the CVE identifier CVE-2025-24054 (CVSS score: 6.5), is a Windows New Technology LAN Manager (NTLM) hash disclosure

OpenAI pursued Cursor maker before entering into talks to buy Windsurf for $3B

When news broke that OpenAI was in talks to acquire AI coding company Windsurf for $3 billion, one of the first questions on the mind of anyone following the space was likely: “Why not buy Cursor creator Anysphere instead?” After all, OpenAI Startup Fund has been an investor in Anysphere, the maker of Cursor, since the…

Will politicization of security clearances make US cybersecurity firms radioactive?

With the US government now tying security clearances to the support of specific political positions, many in the security community fear it may tar US vendors with the same brush as their Russian and Chinese counterparts. Will enterprise CISOs now have to worry about whether they can rely on American threat intel? More broadly, will…

The Future of SSL Certificate Management: Adapting to Shortened Renewal Periods

The industry is evolving yet again. With the CA/Browser Forum’s recent decision to reduce the maximum SSL/TLS certificate lifecycle to 47 days by 2029, the way organizations manage their certificates is going to change significantly—and sooner than most realize. This update builds on the trend of strengthening web security by minimizing risks associated with stale…

Video: How The 20 MSP is Scaling Without Private Equity

In this episode of Channel Insider: Partner POV, host Katie Bavoso chats with Tim and Crystal Conkle, the married power duo leading The 20 MSP—the largest founder-owned MSP platform in the U.S., according to Tim, the CEO, with 38+ successful acquisitions and zero private equity backing. Learn how The 20 MSP is revolutionizing the managed…

Ramp is trying to get the US government as a customer after seeing a tweet from DOGE

Expense management startup Ramp is being considered for a charge card pilot program by the U.S. government’s General Services Administration, the company confirmed to TechCrunch on Thursday. The government’s internal expense card program, dubbed SmartPay, is a $700 billion program. It is estimated that the charge card pilot program contract for which Ramp is being…

Securing Cloud Data: A Relief for CFOs

Are Interactions in Your Digital Environment Truly Secure? Cybersecurity has grown beyond the protection of human accounts alone. Increasingly, the focus is on securing machine-based interactions, such as APIs and service accounts, that occur billions of times a day. Non-Human Identities (NHIs) and Secrets Security Management has emerged to be a pivotal strategy in securing…

How to Ensure Security in Cloud Compliance

Why is Cloud Security of Paramount Importance? It’s a well-acknowledged fact, isn’t it, that our reliance on cloud services has significantly increased in the past few years? According to data from Dell Technologies, almost every organization, regardless of size and industry, has adopted some form of cloud storage or applications. This shift has prompted many…

OpenAI launches Flex processing for cheaper, slower AI tasks

In a bid to more aggressively compete with rival AI companies like Google, OpenAI is launching Flex processing, an API option that provides lower AI model usage prices in exchange for slower response times and “occasional resource unavailability.” Flex processing, which is available in beta for OpenAI’s recently released o3 and o4-mini reasoning models, is…

IFS attracts AUD 26.6 billion Valuation as Demand for Industrial AI Soars

• Hg increases its stake in enterprise software provider IFS and becomes co-control shareholder alongside EQT, while existing minority shareholder TA Associates remains invested• New investors in this transaction include a wholly-owned subsidiary of the Abu Dhabi Investment Authority (“ADIA”) and the Canada Pension Plan Investment Board (“CPP Investments”)• IFS continues to perform strongly, having…

As the trade war escalates, Hence launches an AI ‘advisor’ to help companies manage risk

President Donald Trump’s tariffs have underscored the increasing geopolitical risk that almost all businesses now face. As the situation continues to shift with Trump’s unpredictable deal-making, it’s also becoming clear how challenging it is for companies, nonprofits, consultants, and lawyers to keep up with the rapid day-to-day changes. “We are drowning in trade updates every…

Chinese shopping app Taobao joins DHgate in Top 5 on US App Store

The Chinese e-commerce marketplace app DHgate, which is now the No. 2 free iPhone app in the U.S., isn’t the only one that’s oddly benefiting from President Trump’s tariffs on U.S. imports from China. Another Chinese shopping app, Taobao, has now also entered the Top 5 as of Thursday. U.S. consumers began flocking to these…

AI Is Redefining Tech Infrastructure Priorities: Seagate Report Calls for Balance Between Cost and Carbon

Urges data centre ecosystem to shift from fragmented efforts to a unified sustainability approach COMPANY NEWS: Seagate Technology Holdings plc (NASDAQ: STX), a leader in mass-capacity data storage, today released the Decarbonizing Data report, its latest global report based on a commissioned survey, highlighting the growing sustainability challenges facing data centres as enterprises scale to…

BSidesLV24 – Common Ground – Security for AI Basics – Not by ChatGPT

Author/Presenter: Chloé Messdaghi Our sincere appreciation to BSidesLV, and the Presenters/Authors for publishing their erudite Security BSidesLV24 content. Originating from the conference’s events located at the Tuscany Suites & Casino; and via the organizations YouTube channel. Permalink The post BSidesLV24 – Common Ground – Security for AI Basics – Not by ChatGPT appeared first on…

Google’s latest AI model report lacks key safety details, experts say

On Thursday, weeks after launching its most powerful AI model yet, Gemini 2.5 Pro, Google published a technical report showing the results of its internal safety evaluations. However, the report is light on the details, experts say, making it difficult to determine which risks the model might pose. Technical reports provide useful — and unflattering,…

Automakers selling cars in China banned from using ‘autonomous driving’ in ads

China is cracking down on how automakers advertise driver assistance features, banning terms like “autonomous driving,” “self-driving,” and “smart driving,” Reuters reported, citing a transcript of a meeting between the government and industry representatives. The updated rule will also prohibit automakers from rolling out improvements via software updates to advanced driving assistance systems in vehicles…

CSP FY: A Magecart Attack That Dodges Policy—and Makes a Joke While Doing It

by Source Defense When attackers are clever enough to name their cookie “csp_f_y,” you know they’re not just exfiltrating data—they’re mocking your defenses. In a recent attack spotted by the Source Defense Cyber Research team, a compromised first-party script on a payment page stored sensitive data in a cookie named csp_f_y. The exfiltration didn’t happen…

AI benchmarking platform Chatbot Arena forms a new company

Chatbot Arena, the crowdsourced benchmarking project major AI labs rely on to test and market their AI models, is forming a company called Arena Intelligence Inc., reports Bloomberg. In a blog post published Thursday, Chatbot Arena said that the company will “give [it] the resources to improve [its platform] significantly over what it is today.”…

HubSpot and TikTok Partner to turn Engaged Audiences into Loyal Customers

Available now in Australia, the CRM partnership supercharges B2B lead generation COMPANY NEWS: HubSpot and TikTok have today announced a partnership to make community-based customer acquisition easier than ever for B2B brands. With a new integration designed to easily capture leads from TikTok directly in HubSpot, B2B businesses will benefit from the combined power of…

House investigation into DeepSeek teases out funding, security realities around Chinese AI tool

A House panel has concluded that the U.S. government should double down on export controls and other tools to slow down the progress of Chinese AI companies like DeepSeek, while also preparing for a future where those efforts fail. In a report released Wednesday, the House Select Committee on the Chinese Communist Party further fleshes…

Time to Migrate from On-Prem to Cloud? What You Need to Know

Migrating from on-premises infrastructure to the cloud is an important step for any business seeking to modernize operations, improve scalability, and (potentially) reduce costs. Using Amazon Elastic Kubernetes Service (EKS), Microsoft Azure Kubernetes Service (AKS), and Google Kubernetes Engine (GKE) and the 7 Rs migration framework can help you streamline this transition. Let’s look at…

Instagram’s new Blend feature creates a custom reels feed for you and your friends

Instagram on Thursday announced that it’s rolling out Blend, a new feature that lets you create a custom, personalized reels feed for you and your friends. Blends are invite-only and can be created with a singular friend or with a group chat. The custom feeds are refreshed with new content each day. The launch doesn’t…

WordPress Appliance - Powered by TurnKey Linux