Geek-Guy.com

Category: Global Security News

DDoS-Attacken auf deutsche Städte

Hacker haben die Webseiten von mehreren deutschen Städten mit DDoS-Attacken lahmgelegt. Wirestock Creators – shutterstock.com Am 25. April 2025 kämpfte die Stadt Nürnberg mit einem Ausfall ihrer Online-Dienste. Ursache war eine sogenannte DDoS-Attacke (Distributed Denial of Service). Dabei wird eine Website mit Bot-Anfragen überflutet, sodass die Serverkapazitäten überlastet sind. Wie der Bayerische Rundfunk berichtet hatte,…

Hackers hit deportation airline GlobalX, leak flight manifests, and leave an unsubtle message for “Donnie” Trump

GlobalX Airlines, a charter airline being used by the US government for deportation flights, has been attacked by hacktivists who have made off with what they claim are detailed flight records and passenger manifests. Read more in my article for the Hot for Security blog.

CVE funding crisis offers chance for vulnerability remediation rethink

A recent funding crisis involving the Common Vulnerabilities and Exposures (CVE) program sent a wave of panic through the cybersecurity community, raising questions among security professionals about how the potential dissolution of the program would impact their approaches to security triage. The CVE program, which provides a publicly available archive of disclosed vulnerabilities, is highly…

This is your last chance to exhibit at TechCrunch Sessions: AI — don’t miss out

Applications are almost closed, and you have until 11:59 p.m. PT tonight to reserve your exhibitor table at TechCrunch Sessions: AI, our premiere industry event that’s happening at UC Berkeley’s Zellerbach Hall on June 5. Imagine walking into a room filled with 1,200+ investors, founders, enterprise leaders, and journalists — all hunting for the next…

Living Off the Land (LOTL) Attacks: How your tools are used against you?

Introduction A well-known organisation called SolarWinds was attacked in September 2019. In this attack, a hacker used a supply chain attack to inject malicious code into the system. More than 18,000 SolarWinds customers installed Updates containing the dangerous code. Living off the land attacks use legitimate tools to carry out malicious activities. They are particularly…

Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android

Google on Thursday announced it’s rolling out new artificial intelligence (AI)-powered countermeasures to combat scams across Chrome, Search, and Android. The tech giant said it will begin using Gemini Nano, its on-device large language model (LLM), to improve Safe Browsing in Chrome 137 on desktops. “The on-device approach provides instant insight on risky websites and…

What is CTEM? Continuous visibility for identifying real-time threats

What is CTEM? Continuous threat exposure management (CTEM) is a security approach that helps companies to continuously identify and manage threats in their IT environment. The framework shifts the focus from scheduled scans to an event-driven system that assesses risks in real-time and enables immediate action. By using CTEM, companies can better understand where the…

Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell

A China-linked unnamed threat actor dubbed Chaya_004 has been observed exploiting a recently disclosed security flaw in SAP NetWeaver. Forescout Vedere Labs, in a report published Thursday, said it uncovered a malicious infrastructure likely associated with the hacking group weaponizing CVE-2025-31324 (CVSS score: 10.0) since April 29, 2025. CVE-2025-31324 refers to a critical SAP NetWeaver…

Microsoft OneDrive move may facilitate accidental sensitive file exfiltration

Microsoft’s upcoming OneDrive sync change will give enterprise users an easy way to sync both their personal and corporate OneDrive accounts on business devices. But cybersecurity officials do not want to make syncing easier, as it can create lots of security and IT headaches. The rollout was originally scheduled for this weekend (May 11), but…

„CISOs sprechen heute die Sprache des Business“

srcset=”https://b2b-contenthub.com/wp-content/uploads/2025/05/Nick-Godfrey_GoogleCloud_16.jpg?quality=50&strip=all 800w, https://b2b-contenthub.com/wp-content/uploads/2025/05/Nick-Godfrey_GoogleCloud_16.jpg?resize=300%2C168&quality=50&strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2025/05/Nick-Godfrey_GoogleCloud_16.jpg?resize=768%2C432&quality=50&strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/05/Nick-Godfrey_GoogleCloud_16.jpg?resize=150%2C84&quality=50&strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2025/05/Nick-Godfrey_GoogleCloud_16.jpg?resize=640%2C360&quality=50&strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2025/05/Nick-Godfrey_GoogleCloud_16.jpg?resize=444%2C250&quality=50&strip=all 444w” width=”800″ height=”450″ sizes=”(max-width: 800px) 100vw, 800px”>Nick Godfrey, Leiter des Office of the CISO bei Google Cloud Google Cloud Als Senior Director und Leiter des Office of the CISO bei Google Cloud ist es die Aufgabe von Nick Godfrey, das Unternehmen beim Austausch zwischen…

One of Elon Musk’s long-time VCs is suing his former employer after allegedly being fired

Josh Raffaelli, who has long roots as a Silicon Valley investor and has backed a number of Elon Musk companies, is suing his former employer, the massive trillion-dollar AUM Brookfield Asset Management, reports the New York Times.  Much of Raffaelli’s complaint concerns how Brookfield covered pandemic-related real estate losses and alleges the company fired him…

Microsoft employees are banned from using DeepSeek app, president says 

Microsoft employees aren’t allowed to use DeepSeek due to data security and propaganda concerns, Microsoft vice chairman and president Brad Smith said in a Senate hearing today. “At Microsoft we don’t allow our employees to use the DeepSeek app,” Smith said, referring to DeepSeek’s application service (which is available on both desktop and mobile.) Smith…

A timeline of South Korean telco giant SKT’s data breach

In April, South Korea’s telco giant SK Telecom (SKT) was hit by a cyberattack that led to the theft of personal data on approximately 23 million customers, equivalent to almost half of the country’s 52 million residents. At a National Assembly hearing in Seoul on Thursday, SKT chief executive Young-sang Ryu said about 250,000 users…

Ensuring Certainty in NHIs’ Lifecycle Management

What Makes Effective NHIs and Secrets Lifecycle Management So Crucial? The importance of NHIs and Secrets Lifecycle Management in ensuring robust cybersecurity measures is becoming increasingly apparent. Why? It offers certainty and control over automated systems within our ever-growing internet of things (IoT) network. Is managing non-human identities a part of your cybersecurity strategy yet?…

Being Proactive with Your NHIDR Strategy

What Does A Proactive NHIDR Strategy Look Like? A proactive Non-Human Identity and Data Rights (NHIDR) strategy involves anticipating potential threats and challenges instead of waiting for them to occur. It covers facets like security, data privacy, risk management, and compliance. This approach aids in the effective management of machine identities and secrets, reduces the…

Unlock Capabilities with Advanced NHIs Management

Are You Fully Utilizing Advanced NHIs for Secure Management? Emerging from the cornerstones of technology and cybersecurity, Non-Human Identities Management (NHIs) is proving to be a game-changer. This advanced security framework centers around safeguarding the machine identities used – the NHIs. By creating a secure cloud, it bridges the gap between security and R&D teams,…

Aurora co-founder Sterling Anderson is leaving the self-driving truck startup

Sterling Anderson, a veteran of the nascent autonomous vehicle sector and co-founder of Aurora, is resigning just a week after the company launched its commercial self-driving truck service in Texas. Anderson held the chief product officer position at Aurora. The resignation was posted in a regulatory filing along with the company’s first-quarter earnings report. His…

Appfigures: Apple made over $10B from US App Store comissions last year

Over $10 billion — that’s how much revenue Apple’s U.S. App Store raked in last year, according to a new analysis by app intelligence provider Appfigures. The firm’s estimates indicate that U.S. App Store revenue from commissions more than doubled between 2020 and 2024. In 2020, Apple’s share of App Store commissions was approximately $4.76…

How Managed Kubernetes-as-a-Service Unlocks Immediate Value

In this digital-first world, organizations are constantly under pressure to deliver software and services faster, more reliably, and at greater scale. Platform teams, often small but tasked with supporting dozens or even hundreds of engineers, are at the heart of this transformation. For these teams, managed services can become a strategic lever, delivering not just…

ChatGPT’s deep research tool gets a GitHub connector to answer questions about code

OpenAI is enhancing its AI-powered “deep research” feature with the ability to analyze codebases on GitHub. On Thursday, OpenAI announced what it’s calling the first “connector” for ChatGPT deep research, the company’s tool that searches across the web and other sources to compile thorough research reports on a topic. Now, ChatGPT deep research can link…

Sen. Murphy: Trump administration has ‘illegally gutted funding for cybersecurity’

Another top appropriations Democrat criticized budget cuts affecting the Cybersecurity and Infrastructure Security Agency, saying the Trump administration has “illegally gutted funding for cybersecurity.” Connecticut Sen. Chris Murphy, the ranking member on the Senate Appropriations Subcommittee on Homeland Security, made his remarks Thursday to Department of Homeland Security Secretary Kristi Noem at a hearing on…

How SCIM Works: The REST API Powering Modern Identity Provisioning

This article is part of SSOJet’s technical series on identity protocols and standards. For more information on implementing SCIM with SSOJet’s turnkey SSO integration solution, visit our documentation or contact our support team. The post How SCIM Works: The REST API Powering Modern Identity Provisioning appeared first on Security Boulevard.

How to Unite Developers, DevOps, and Security Without Slowing Down

5 min readBuilders and protectors don’t have to clash – they just need a common path. The post How to Unite Developers, DevOps, and Security Without Slowing Down appeared first on Aembit. The post How to Unite Developers, DevOps, and Security Without Slowing Down appeared first on Security Boulevard.

Ex-Synapse CEO reportedly trying to raise $100M for his new humanoid robotics venture

Sankaet Pathak’s last startup, fintech Synapse, filed for bankruptcy in 2024 amid issues with partner Evolve Bank & Trust. Tens of millions of dollars in deposits made by consumers, mostly customers of fintechs that worked with Synapse, remain unaccounted for. Yet according to The Information, Pathak is reportedly moving full steam ahead on attempts to…

Social media startup Fizz sues Instacart and Partiful for trademark infringement over new Fizz app

Social media startup Fizz is suing grocery delivery giant Instacart and party planning app Partiful for trademark infringement, the company announced on Thursday. Earlier this week, Instacart launched a new drinks and snack delivery app for parties called Fizz and announced that Partiful had integrated Fizz directly into its platform. Founded in 2020, Fizz is a…

Video: OTAVA CEO TJ Houske on New Scale Computing Partnership, Edge Innovation and Veeam Deal

In this episode of Channel Insider: Partner POV, host Katie Bavoso sits down with returning guest TJ Houske, CEO of OTAVA, to unpack a game-changing new partnership with Scale Computing. This collaboration brings edge computing into OTAVA’s portfolio of offerings for the first time—positioning the company to lead in cloud-to-edge transformation. Watch as TJ shares…

F5 2025 State of Application Strategy Report Reveals Talk Becomes Action as AI Gets to Work

GUEST RESEARCH:  F5 Report Highlights AI-Driven Transformation Amid Operational Complexity 96 per cent of surveyed IT decision-makers have deployed AI models, up from a quarter in 2023 IT leaders are increasingly trusting AI with business-critical tasks from traffic management to cost optimisation, according to the industry’s most comprehensive report on application strategy.

Starlink’s launch in India now a matter of when, not if

Elon Musk’s Starlink has received anticipated state approval in India, opening the door to enter the world’s second-biggest internet market after China — over three years after SpaceX’s previous attempt to launch its satellite-based broadband in the country eventually failed. On Wednesday, the Indian Department of Telecommunications gave its nod to Starlink to start working toward…

Starlink’s launch in India now a matter of when, not if

Elon Musk’s Starlink has received anticipated state approval in India, opening the door to enter the world’s second-biggest internet market after China — over three years after SpaceX’s previous attempt to launch its satellite-based broadband in the country eventually failed. On Wednesday, the Indian Department of Telecommunications gave its nod to Starlink to start working toward…

Starlink’s launch in India now a matter of when, not if

Elon Musk’s Starlink has received anticipated state approval in India, opening the door to enter the world’s second-biggest internet market after China — over three years after SpaceX’s previous attempt to launch its satellite-based broadband in the country eventually failed. On Wednesday, the Indian Department of Telecommunications gave its nod to Starlink to start working toward…

Starlink’s launch in India now a matter of when, not if

Elon Musk’s Starlink has received anticipated state approval in India, opening the door to enter the world’s second-biggest internet market after China — over three years after SpaceX’s previous attempt to launch its satellite-based broadband in the country eventually failed. On Wednesday, the Indian Department of Telecommunications gave its nod to Starlink to start working toward…

Sequoia leads $1.5B tender offer for sales automation startup Clay

It took seven years of hard work for Kareem Amin, co-founder and CEO of sales automation startup Clay, to see the company’s product finally take off in 2022. Since then, the startup has experienced explosive growth, reached a valuation exceeding a billion dollars, and expanded its employee count from low double digits to over 200.…

38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases

Cybersecurity researchers have exposed what they say is an “industrial-scale, global cryptocurrency phishing operation” engineered to steal digital assets from cryptocurrency wallets for several years. The campaign has been codenamed FreeDrain by threat intelligence firms SentinelOne and Validin. “FreeDrain uses SEO manipulation, free-tier web services (like gitbook.io, webflow.io, and github.io

Redefining Workforce Management: Empowering the Frontline in a Post-Pandemic Era

GUEST RESEARCH:  The pandemic catalysed a seismic shift in the expectations employees have of their workplaces—especially those on the front lines. Once celebrated as the backbone of our transport, hospitality, and services (THS) sectors, frontline workers are now rightfully demanding more than just a regular salary. They want engagement, flexibility, and purpose—and they want tools…

Weaponizing Facebook Ads: Inside the Multi-Stage Malware Campaign Exploiting Cryptocurrency Brands

GUEST RESEARCH:  A persistent malvertising campaign is plaguing Facebook, leveraging the reputations of well-known cryptocurrency exchanges to lure victims into a maze of malware. Since Bitdefender Labs started investigating, this evolving threat has posed a serious risk by deploying cleverly disguised front-end scripts and custom payloads on users’ devices, all under the guise of legitimate…

OpenAI launches a data residency program in Asia

OpenAI is introducing a new data residency program in Asia, the company announced Thursday, following the rollout of its data residency program in Europe in February. The new program, which is available for OpenAI’s ChatGPT Enterprise, ChatGPT Edu, and the OpenAI API, aims to help Asia-based organizations meet local data sovereignty requirements while using the…

OpenAI launches a data residency program in Asia

OpenAI is introducing a new data residency program in Asia, the company announced Thursday, following the rollout of its data residency program in Europe in February. The new program, which is available for OpenAI’s ChatGPT Enterprise, ChatGPT Edu, and the OpenAI API, aims to help Asia-based organizations meet local data sovereignty requirements while using the…

OpenAI launches a data residency program in Asia

OpenAI is introducing a new data residency program in Asia, the company announced Thursday, following the rollout of its data residency program in Europe in February. The new program, which is available for OpenAI’s ChatGPT Enterprise, ChatGPT Edu, and the OpenAI API, aims to help Asia-based organizations meet local data sovereignty requirements while using the…

OpenAI launches a data residency program in Asia

OpenAI is introducing a new data residency program in Asia, the company announced Thursday, following the rollout of its data residency program in Europe in February. The new program, which is available for OpenAI’s ChatGPT Enterprise, ChatGPT Edu, and the OpenAI API, aims to help Asia-based organizations meet local data sovereignty requirements while using the…

OpenAI launches a data residency program in Asia

OpenAI is introducing a new data residency program in Asia, the company announced Thursday, following the rollout of its data residency program in Europe in February. The new program, which is available for OpenAI’s ChatGPT Enterprise, ChatGPT Edu, and the OpenAI API, aims to help Asia-based organizations meet local data sovereignty requirements while using the…

OpenAI launches a data residency program in Asia

OpenAI is introducing a new data residency program in Asia, the company announced Thursday, following the rollout of its data residency program in Europe in February. The new program, which is available for OpenAI’s ChatGPT Enterprise, ChatGPT Edu, and the OpenAI API, aims to help Asia-based organizations meet local data sovereignty requirements while using the…

OpenAI launches a data residency program in Asia

OpenAI is introducing a new data residency program in Asia, the company announced Thursday, following the rollout of its data residency program in Europe in February. The new program, which is available for OpenAI’s ChatGPT Enterprise, ChatGPT Edu, and the OpenAI API, aims to help Asia-based organizations meet local data sovereignty requirements while using the…

Indirect prompt injection attacks target common LLM data sources

While the shortest distance between two points is a straight line, a straight-line attack on a large language model isn’t always the most efficient — and least noisy — way to get the LLM to do bad things. That’s why malicious actors have been turning to indirect prompt injection attacks on LLMs. The post Indirect…

SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root

SonicWall has released patches to address three security flaws affecting SMA 100 Secure Mobile Access (SMA) appliances that could be fashioned to result in remote code execution. The vulnerabilities are listed below – CVE-2025-32819 (CVSS score: 8.8) – A vulnerability in SMA100 allows a remote authenticated attacker with SSL-VPN user privileges to bypass the path…

Democrats Woke Up to Trump’s Crypto Grift. Will They Stop Other Scammers?

Cryptocurrency legislation once seemed to be the rare issue that could draw bipartisan support in Donald Trump’s Washington, thanks to the industry’s prolific donations on both sides of the aisle. Then Trump and his family attempted to monetize the presidency through a meme coin and a $2 billion crypto deal involving an Abu Dhabi-backed venture…