Geek-Guy.com

Category: Technology

Stay updated with the latest in technology on Geek-Guy.com. From emerging hardware and software trends to in-depth guides on digital innovation, we explore the tech that shapes our world and the advancements driving the future.

‘Stranger Things’ emerge when OT security is stuck in the past

The final season of “Stranger Things” is upon us, and 1980s nostalgia is at an all-time high. The clunky control panels at Hawkins Lab help set the stage for the show. The unfortunate reality is that similar legacy systems still exist in operational technology (OT) environments today. Just as Hawkins Lab spawned a monstrous compendium…

Elon Musk Had Grok Rewrite Wikipedia. It Calls Hitler “The Führer.”

The Grokipedia encyclopedia logo appears on a smartphone screen reflecting an abstract illustration. Photo: Samuel Boivin/NurPhoto via Getty Images In late October, Elon Musk released a Wikipedia alternative, with pages written by his AI chatbot Grok. Unlike its nearly quarter-century-old namesake, Musk said Grokipedia would strip out the “woke” from Wikipedia, which he previously described as…

Underground AI models promise to be hackers ‘cyber pentesting waifu’ 

As legitimate businesses purchase AI tools from some of the largest companies in the world, cybercriminals are accessing  an increasingly sophisticated underground market for custom LLMs designed to  assist with lower-level hacking tasks. In a report published Tuesday, Palo Alto Networks’ Unit 42 looked at how underground hacking forums advertise and sell custom, jailbroken, and…

New research finds that Claude breaks bad if you teach it to cheat

According to Anthropic, its large language model Claude is designed to be a “harmless” and helpful assistant. But new research released by the company Nov. 21 shows that when Claude is taught to cheat in one area, it becomes broadly malicious and untrustworthy in other areas. The research, conducted by 21 people — including contributors…

The slow rise of SBOMs meets the rapid advance of AI

Open-source components power nearly all modern software, but they’re often buried deep in massive codebases—hiding severe vulnerabilities. For years, software bills of materials (SBOMs) have been the security community’s key tool to shine a light on these hidden risks. Yet, despite government advancements in the US and Europe, SBOM adoption in the private sector remains…

The FBI Wants AI Surveillance Drones With Facial Recognition

The FBI is looking for ways to incorporate artificial intelligence into drones, according to federal procurement documents. On Thursday, the FBI put out the call to potential vendors of AI and machine learning technology to be used in unmanned aerial systems in a so-called “request for information,” where government agencies request companies submit initial information…

NSO Group argues WhatsApp injunction threatens existence, future U.S. government work

NSO Group argued in a court filing this week that the court should pause the permanent injunction preventing it from targeting WhatsApp with its spyware while the company appeals the decision. According to the company, enforcing the injunction would cause irreparable harm to its business and prevent the U.S. government from using its products. Those…

Dozens of groups call for governments to protect encryption 

On Monday, more than 60 digital commerce and trade groups called on governments around the globe to reject efforts or requests to weaken or bypass encryption, saying strong encrypted communications provides critical protections for user privacy, secure data protection and trust that underpin some of society’s most important interactions. “Encryption is a vital tool for…

You Will Never Send Money Digitally Without a Private Company — If the GOP Gets Its Way

Americans who want to transfer money online have options. They can go with services like Venmo and PayPal, make transfers from their personal bank, or do a transaction with stablecoins issued by cryptocurrency companies. All those options have something in common that may not always occur to consumers: The transfers are offered by exclusively by…

China’s ‘autonomous’ AI-powered hacking campaign still required a ton of human work 

Anthropic made headlines Thursday when it released research claiming that a previously unknown Chinese state-sponsored hacking group used the company’s Claude AI generative AI product to breach at least 30 different organizations. According to Anthropic’s report, the threat actor was able to bypass Claude’s security guardrails using two methods: breaking up the work into discrete…

Real Estate Giant Redfin Exposed Users’ Personal Info on Listing Contact Forms

Because of a website security snafu, the online real estate platform Redfin made random users’ names, email addresses, and phone numbers available to others who log onto listings. The vulnerability lasted less than a week, the company said. The personal identification information became visible to other users who were viewing real estate listings. The information…

Advocacy group calls on OpenAI to address Sora 2’s deepfake risks

Throughout 2024, OpenAI teased the public release of Sora, its new video generation large language model, capable of creating lifelike visuals out of user prompts. But due to concerns about the tool being used to create realistic disinformation during a  critical U.S. election year, the company delayed its release until after the elections.  Now, a…

Microsoft Patch Tuesday addresses 63 defects, including one actively exploited zero-day

Microsoft addressed 63 vulnerabilities affecting its underlying systems and core products, including one actively exploited zero-day, the company said in its latest monthly security update.  The zero-day vulnerability — CVE-2025-62215 — affects the Windows Kernel and has a CVSS rating of 7.0 due to a high attack complexity, according to Microsoft. Exploitation, which could allow…

What’s left to worry (and not worry) about in the F5 breach aftermath

Researchers aren’t very concerned about the dozens of undisclosed F5 vulnerabilities a nation-state attacker stole during a prolonged attack on F5’s internal systems. Yet, the heist of sensitive intelligence from a widely used vendor’s internal network resembles previous espionage-driven attacks that could pose long-term consequences downstream. F5, which became aware of the attack Aug. 9…

SonicWall pins attack on customer portal to undisclosed nation-state

SonicWall said a state-sponsored threat actor was behind the brute-force attack that exposed firewall configuration files of every customer that used the company’s cloud backup service.  The vendor pinned the responsibility for the attack on an undisclosed nation state Tuesday, after Mandiant concluded its investigation into the incident. SonicWall did not attribute the attack to…

With each cloud outage, calls for government action grow louder 

When a pair of high-profile internet outages took down large chunks of the internet last month, the events briefly brought hundreds of organizations to a near-halt and prevented millions of users from accessing core services for everyday business needs.  From Starbucks to crypto exchanges to the messaging app Signal, the outages rippled across nearly every…

House GOP leaders seek government probe, restrictions on Chinese-made tech

A Commerce Department office should investigate Chinese government-connected products in more than a dozen emerging industries for security threats, a group of House GOP committee leaders said in a letter they released Wednesday. In the missive, the lawmakers said the Office of Information and Communications Technology and Services has the power to both investigate and…

YouTube Quietly Erased More Than 700 Videos Documenting Israeli Human Rights Violations

A documentary featuring mothers surviving Israel’s genocide in Gaza. A video investigation uncovering Israel’s role in the killing of a Palestinian American journalist. Another video revealing Israel’s destruction of Palestinian homes in the occupied West Bank. YouTube surreptitiously deleted all these videos in early October by wiping the accounts that posted them from its website,…

Apple addresses more than 100 vulnerabilities in security updates for iPhones, Macs and iPads

Apple disclosed an exceptionally high number of vulnerabilities in core services and components used across its most popular devices, as the tech giant addressed 105 vulnerabilities in MacOS 26.1 and 56 vulnerabilities with the release of iOS 26.1 and iPadOS 26.1.  The company’s latest security update includes some flaws that affect software spanning iPhones, Macs…

ICE Investigations, Powered by Nvidia

Nvidia, the computing giant that this week became the world’s first $5 trillion company, is powering U.S. Immigration and Customs Enforcement’s investigative division, according to federal records reviewed by The Intercept. This summer, ICE renewed access to software tools for use by Homeland Security Investigations, or HSI, an enforcement division previously tasked with transnational crime…

ICE Plans Cash Rewards for Private Bounty Hunters to Locate and Track Immigrants

U.S. Immigration and Customs Enforcement is considering hiring private bounty hunters to locate immigrants across the country, according to a procurement document reviewed by The Intercept. Under the plan, bounty hunters may receive “monetary bonuses” depending on how successfully they track down their targets — and how many immigrants they then report to ICE. According…

OpenAI releases ‘Aardvark’ security and patching model 

A new security-focused AI model released Thursday by OpenAI aims to automate bug hunting, patching and remediation. The model, powered by ChatGPT-5 and given the name Aardvark, has been used internally at OpenAI and among external partners. Currently offered in an invite-only Beta, it’s designed to continuously scan source code repositories to find known vulnerabilities…

CISA, NSA offer guidance to better protect Microsoft Exchange Servers

Cybersecurity experts from multiple federal agencies released guidance to help organizations bolster their defenses against attacks on on-premises Microsoft Exchange Servers, resurfacing and building upon previously shared advice that generally applies to most technology. The Cybersecurity and Infrastructure Security Agency said the security blueprint for Microsoft Exchange Server is a follow-up effort to an emergency…

Ex-L3Harris exec pleads guilty to selling zero-day exploits to Russian broker

An ex-L3 Harris executive pleaded guilty to two counts of theft of trade secrets Wednesday, admitting to selling eight zero-day exploits to a Russian broker in exchange for millions of dollars.  Peter Williams, 39, pleaded guilty in the District Court of the District of Columbia to two counts of theft of trade secrets. Court records…

F5 asserts limited impact from prolonged nation-state attack on its systems

F5 CEO François Locoh-Donou said on a company earnings call that there were two categories of impact on customers following a nation-state attacker’s long-term, persistent access to its systems: widespread emergency updates to BIG-IP software and hardware, and customers whose configuration data was stolen during the attack. “We were very impressed frankly, with the speed…

Exclusive: OpenAI’s Atlas browser — and others — can be tricked by manipulated web content

As AI browser agents enter the market promising to help people shop, hire employees  or assist with other online tasks, security researchers are warning that the information these programs collect from the internet can be manipulated and corrupted without anyone ever realizing it. In new research shared exclusively with CyberScoop, AI cybersecurity firm SPLX highlighted…

As Israel Bombed Gaza, Amazon Did Business With Its Bomb-Makers

Amazon sold cloud-computing services to two Israeli weapons manufacturers whose munitions helped devastate Gaza, according to internal company materials obtained by The Intercept. Amazon Web Services has furnished the Israeli government — including its military and intelligence agencies — with a suite of state-of-the-art data processing and storage services since 2021 as part of its…

Robocalling task force bill advances in Senate

The federal government is shut down and the House remains out of session, but work in the Senate continues, as a bipartisan bill designed to crack down on overseas robocalls  advanced through a key committee Tuesday. The Foreign Robocall Elimination Act, sponsored by Sens. Ted Budd, R-N.C., and Peter Welch, D-Vt., would create a new…

Researchers uncover remote code execution flaw in abandoned Rust code library

Security specialists at Edera discovered and disclosed a high-severity vulnerability in an early and since-abandoned code for an open-source async tar archive library for the Rust programming language.  Researchers warned that potential exploitation, which allows for remote code execution, could bear major impacts due to widespread forking and a lack of visibility into the code’s…

Apple and Google challenged by parents’ rights coalition on youth privacy protections

A nonprofit organization has filed a formal complaint with the Federal Trade Commission, claiming Google’s business practices around children and teenagers violates U.S. privacy laws and constitutes unfair and deceptive practices. The complaint, filed by the Digital Childhood Institute, lays out five core claims against the tech giant: that it “knowingly” markets adult-themed or age-restricted…

SonicWall admits attacker accessed all customer firewall configurations stored on cloud portal

A brute-force attack exposed firewall configuration files of every SonicWall customer who used the company’s cloud backup service, the besieged vendor said Wednesday. An investigation aided by Mandiant confirmed the totality of compromise that occurred when unidentified attackers hit a customer-facing system of SonicWall controls. The company previously said less than 5% of its firewall…

OpenAI: Threat actors use us to be efficient, not make new tools

A long-running theme in the use of adversarial AI since the advent of large language models has been the automation and enhancement of well-established hacking methods, rather than the creation of new ones.   That remains the case for much of OpenAI’s October threat report, which highlights how government agencies and the cybercriminal underground are opting…

OpenAI: Threat actors use us to be efficient, not make new tools

A long-running theme in the use of adversarial AI since the advent of large language models has been the automation and enhancement of well-established hacking methods, rather than the creation of new ones.   That remains the case for much of OpenAI’s October threat report, which highlights how government agencies and the cybercriminal underground are opting…

OpenAI: Threat actors use us to be efficient, not make new tools

A long-running theme in the use of adversarial AI since the advent of large language models has been the automation and enhancement of well-established hacking methods, rather than the creation of new ones.   That remains the case for much of OpenAI’s October threat report, which highlights how government agencies and the cybercriminal underground are opting…

OpenAI: Threat actors use us to be efficient, not make new tools

A long-running theme in the use of adversarial AI since the advent of large language models has been the automation and enhancement of well-established hacking methods, rather than the creation of new ones.   That remains the case for much of OpenAI’s October threat report, which highlights how government agencies and the cybercriminal underground are opting…

OpenAI: Threat actors use us to be efficient, not make new tools

A long-running theme in the use of adversarial AI since the advent of large language models has been the automation and enhancement of well-established hacking methods, rather than the creation of new ones.   That remains the case for much of OpenAI’s October threat report, which highlights how government agencies and the cybercriminal underground are opting…

House Dems seek info about ICE spyware contract, wary of potential abuses

Three House Democrats questioned the Department of Homeland Security on Monday over a reported Immigration and Customs Enforcement contract with a spyware provider that they warn potentially “threatens Americans’ freedom of movement and freedom of speech.” Their letter follows publication of a notice that ICE had lifted a stop-work order on a $2 million deal…

House Dems seek info about ICE spyware contract, wary of potential abuses

Three House Democrats questioned the Department of Homeland Security on Monday over a reported Immigration and Customs Enforcement contract with a spyware provider that they warn potentially “threatens Americans’ freedom of movement and freedom of speech.” Their letter follows publication of a notice that ICE had lifted a stop-work order on a $2 million deal…

House Dems seek info about ICE spyware contract, wary of potential abuses

Three House Democrats questioned the Department of Homeland Security on Monday over a reported Immigration and Customs Enforcement contract with a spyware provider that they warn potentially “threatens Americans’ freedom of movement and freedom of speech.” Their letter follows publication of a notice that ICE had lifted a stop-work order on a $2 million deal…

House Dems seek info about ICE spyware contract, wary of potential abuses

Three House Democrats questioned the Department of Homeland Security on Monday over a reported Immigration and Customs Enforcement contract with a spyware provider that they warn potentially “threatens Americans’ freedom of movement and freedom of speech.” Their letter follows publication of a notice that ICE had lifted a stop-work order on a $2 million deal…

House Dems seek info about ICE spyware contract, wary of potential abuses

Three House Democrats questioned the Department of Homeland Security on Monday over a reported Immigration and Customs Enforcement contract with a spyware provider that they warn potentially “threatens Americans’ freedom of movement and freedom of speech.” Their letter follows publication of a notice that ICE had lifted a stop-work order on a $2 million deal…

Potential EU law sparks global concerns over end-to-end encryption for messaging apps 

Tech experts and companies offering encrypted messaging services are warning that  pending European regulation, which would grant governments broad authority to scan messages and content on personal devices for criminal activity, could spell “the end” of privacy in Europe. The European Union will vote Oct. 14 on a legislative proposal from the Danish Presidency known…

Potential EU law sparks global concerns over end-to-end encryption for messaging apps 

Tech experts and companies offering encrypted messaging services are warning that  pending European regulation, which would grant governments broad authority to scan messages and content on personal devices for criminal activity, could spell “the end” of privacy in Europe. The European Union will vote Oct. 14 on a legislative proposal from the Danish Presidency known…

Potential EU law sparks global concerns over end-to-end encryption for messaging apps 

Tech experts and companies offering encrypted messaging services are warning that  pending European regulation, which would grant governments broad authority to scan messages and content on personal devices for criminal activity, could spell “the end” of privacy in Europe. The European Union will vote Oct. 14 on a legislative proposal from the Danish Presidency known…

Potential EU law sparks global concerns over end-to-end encryption for messaging apps 

Tech experts and companies offering encrypted messaging services are warning that  pending European regulation, which would grant governments broad authority to scan messages and content on personal devices for criminal activity, could spell “the end” of privacy in Europe. The European Union will vote Oct. 14 on a legislative proposal from the Danish Presidency known…

Potential EU law sparks global concerns over end-to-end encryption for messaging apps 

Tech experts and companies offering encrypted messaging services are warning that  pending European regulation, which would grant governments broad authority to scan messages and content on personal devices for criminal activity, could spell “the end” of privacy in Europe. The European Union will vote Oct. 14 on a legislative proposal from the Danish Presidency known…

Security leaders at Okta and Zscaler share lessons from Salesloft Drift attacks

When security researchers issued warnings about the Salesloft Drift issues last month, two prominent cybersecurity companies found themselves facing the same threat — but their stories ended up unfolding in different ways.  Okta and Zscaler, among the larger players in the identity management space, were among the more than 700 Drift customers targeted in what…

Security leaders at Okta and Zscaler share lessons from Salesloft Drift attacks

When security researchers issued warnings about the Salesloft Drift issues last month, two prominent cybersecurity companies found themselves facing the same threat — but their stories ended up unfolding in different ways.  Okta and Zscaler, among the larger players in the identity management space, were among the more than 700 Drift customers targeted in what…

Security leaders at Okta and Zscaler share lessons from Salesloft Drift attacks

When security researchers issued warnings about the Salesloft Drift issues last month, two prominent cybersecurity companies found themselves facing the same threat — but their stories ended up unfolding in different ways.  Okta and Zscaler, among the larger players in the identity management space, were among the more than 700 Drift customers targeted in what…

Security leaders at Okta and Zscaler share lessons from Salesloft Drift attacks

When security researchers issued warnings about the Salesloft Drift issues last month, two prominent cybersecurity companies found themselves facing the same threat — but their stories ended up unfolding in different ways.  Okta and Zscaler, among the larger players in the identity management space, were among the more than 700 Drift customers targeted in what…

Security leaders at Okta and Zscaler share lessons from Salesloft Drift attacks

When security researchers issued warnings about the Salesloft Drift issues last month, two prominent cybersecurity companies found themselves facing the same threat — but their stories ended up unfolding in different ways.  Okta and Zscaler, among the larger players in the identity management space, were among the more than 700 Drift customers targeted in what…

Videos of Charlie Kirk’s Murder Are Still on Social Media — and That’s No Accident

Charlie Kirk hands out hats before he was shot and killed during an event at Utah Valley University in Orem, Utah, on Sept. 10, 2025.  Photo: Tess Crowley/The Deseret News via AP After Charlie Kirk was murdered at Utah Valley University, graphic videos of the right-wing provocateur’s assassination went viral on every major social media…

Videos of Charlie Kirk’s Murder Are Still on Social Media — and That’s No Accident

Charlie Kirk hands out hats before he was shot and killed during an event at Utah Valley University in Orem, Utah, on Sept. 10, 2025.  Photo: Tess Crowley/The Deseret News via AP After Charlie Kirk was murdered at Utah Valley University, graphic videos of the right-wing provocateur’s assassination went viral on every major social media…

Videos of Charlie Kirk’s Murder Are Still on Social Media — and That’s No Accident

Charlie Kirk hands out hats before he was shot and killed during an event at Utah Valley University in Orem, Utah, on Sept. 10, 2025.  Photo: Tess Crowley/The Deseret News via AP After Charlie Kirk was murdered at Utah Valley University, graphic videos of the right-wing provocateur’s assassination went viral on every major social media…

Videos of Charlie Kirk’s Murder Are Still on Social Media — and That’s No Accident

Charlie Kirk hands out hats before he was shot and killed during an event at Utah Valley University in Orem, Utah, on Sept. 10, 2025.  Photo: Tess Crowley/The Deseret News via AP After Charlie Kirk was murdered at Utah Valley University, graphic videos of the right-wing provocateur’s assassination went viral on every major social media…

Videos of Charlie Kirk’s Murder Are Still on Social Media — and That’s No Accident

Charlie Kirk hands out hats before he was shot and killed during an event at Utah Valley University in Orem, Utah, on Sept. 10, 2025.  Photo: Tess Crowley/The Deseret News via AP After Charlie Kirk was murdered at Utah Valley University, graphic videos of the right-wing provocateur’s assassination went viral on every major social media…

Google Secretly Handed ICE Data About Pro-Palestine Student Activist

Even before immigration authorities began rounding up international students who had spoken out about Israel’s war on Gaza earlier this spring, there was a sense of fear among campus activists. Two graduate students at Cornell University — Momodou Taal and Amandla Thomas-Johnson — were so worried they would be targeted that they fled their dorms…

Google Secretly Handed ICE Data About Pro-Palestine Student Activist

Even before immigration authorities began rounding up international students who had spoken out about Israel’s war on Gaza earlier this spring, there was a sense of fear among campus activists. Two graduate students at Cornell University — Momodou Taal and Amandla Thomas-Johnson — were so worried they would be targeted that they fled their dorms…

Google Secretly Handed ICE Data About Pro-Palestine Student Activist

Even before immigration authorities began rounding up international students who had spoken out about Israel’s war on Gaza earlier this spring, there was a sense of fear among campus activists. Two graduate students at Cornell University — Momodou Taal and Amandla Thomas-Johnson — were so worried they would be targeted that they fled their dorms…

Google Secretly Handed ICE Data About Pro-Palestine Student Activist

Even before immigration authorities began rounding up international students who had spoken out about Israel’s war on Gaza earlier this spring, there was a sense of fear among campus activists. Two graduate students at Cornell University — Momodou Taal and Amandla Thomas-Johnson — were so worried they would be targeted that they fled their dorms…

Google Secretly Handed ICE Data About Pro-Palestine Student Activist

Even before immigration authorities began rounding up international students who had spoken out about Israel’s war on Gaza earlier this spring, there was a sense of fear among campus activists. Two graduate students at Cornell University — Momodou Taal and Amandla Thomas-Johnson — were so worried they would be targeted that they fled their dorms…

Proton Mail Suspended Journalist Accounts at Request of Cybersecurity Agency

The company behind the Proton Mail email service, Proton, describes itself as a “neutral and safe haven for your personal data, committed to defending your freedom.” But last month, Proton disabled email accounts belonging to journalists reporting on security breaches of various South Korean government computer systems following a complaint by an unspecified cybersecurity agency.…

Wyden calls on FTC to investigate Microsoft for ‘gross cybersecurity negligence’ in protecting critical infrastructure

Sen. Ron Wyden, D-Ore., on Wednesday called for the Federal Trade Commission to investigate Microsoft, saying the company’s default configurations are leaving customers vulnerable and contributing to ransomware, hacking and other threats. That includes the 2024 Ascension hospital ransomware attack, which resulted in the theft of personal data, medical data, payment information, insurance information and…

Salesloft Drift security incident started with undetected GitHub access

Salesloft pinned the root cause of the Drift supply-chain attacks to a threat group gaining access to its GitHub account as far back as March, the company said in an update Saturday.  During a 10-day period in mid-August, the threat group compromised and stole data from hundreds of organizations.  The threat group, which Google tracks…

AI can help track an ever-growing body of vulnerabilities, CISA official says

Artificial intelligence could be a key tool for helping organizations keep track of an ever-expanding catalog of identified software flaws, a top official at the Cybersecurity and Infrastructure Security Agency said Thursday. CISA sponsors the Common Vulnerabilities and Exposures (CVE) program, which publishes standardized data about known cyber vulnerabilities. The number of vulnerabilities the CVE…