23 Sep, 2026

Threat actors downgrade FIDO2 MFA auth in PoisonSeed phishing attack

A PoisonSeed phishing campaign is bypassing FIDO2 security key protections by abusing the cross-device sign-in feature in WebAuthn to trick users into approving login authentication requests from fake company portals. The PoisonSeed threat actors are known to employ large-volume phishing attacks for financial fraud. In the past, distributing emails containing crypto seed phrases used to drain cryptocurrency wallets. In […]

3 mins read

Popular npm linter packages hijacked via phishing to drop malware

Popular JavaScript libraries were hijacked this week and turned into malware droppers, in a supply chain attack achieved via targeted phishing and credential theft. The npm package eslint-config-prettier, downloaded over 30 million times weekly, was compromised after its maintainer fell victim to a phishing attack. Other packages, namely eslint-plugin-prettier, synckit, @pkgr/core, and napi-postinstall from the same maintainer, were also targeted. The attacker(s) used stolen […]

4 mins read

ChatGPT”s GPT-5-reasoning-alpha model spotted ahead of launch

GPT-5 might be just a few days or weeks away, as we’ve spotted references to a new model called gpt-5-reasoning-alpha-2025-07-13. As spotted on X, OpenAI is testing a model called “gpt-5-reasoning-alpha-2025-07-13.” This model was finalised on the 13th of July, and it appears to be the final round of testing. “Models: openai/gpt-5-reasoning-alpha-2025-07-13: reasoning_effort: high,” one of the […]

1 min read

OpenAI, Anthropic, Google may disrupt education market with new AI tools

AI companies could soon disrupt the education market with their new AI-based learning tools for students. GeekFeed recently reported that OpenAI is working on a Study Together feature for ChatGPT. This would allow ChatGPT to teach students a wide range of topics and then offer quizzes. The idea is to create an engaging and interactive “study together” experience […]

1 min read

New CrushFTP zero-day exploited in attacks to hijack servers

CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers. CrushFTP is an enterprise file transfer server used by organizations to securely share and manage files over FTP, SFTP, HTTP/S, and other protocols. According to CrushFTP, threat […]

3 mins read

Arch Linux pulls AUR packages that installed Chaos RAT malware

Arch Linux has pulled three malicious packages uploaded to the Arch User Repository (AUR) were used to install the CHAOS remote access trojan (RAT) on Linux devices. The packages were named “librewolf-fix-bin”, “firefox-patch-bin”, and “zen-browser-patched-bin,” and were uploaded by the same user, “danikpapas,” on July 16. The packages were removed two days later by the […]

3 mins read

UK ties GRU to stealthy Microsoft 365 credential-stealing malware

The UK National Cyber Security Centre (NCSC) has formally attributed ‘Authentic Antics’ espionage malware attacks to APT28 (Fancy Bear), a threat actor already linked to Russia’s military intelligence service (GRU). The NCSC revealed in a detailed technical analysis of the Authentic Antics malware dated May 6th that it is stealing credentials and OAuth 2.0 tokens that […]

3 mins read

Microsoft mistakenly tags Windows Firewall error log bug as fixed

Microsoft has mistakenly tagged an ongoing Windows Firewall error message bug as fixed in recent updates, stating that they are still working on a resolution. Earlier this month, Microsoft warned that, starting with the June 2025 Windows 11 preview update, users would see Windows Firewall errors in the Event Viewer. These events would be labeled as event […]

1 min read

New ChatGPT o3-alpha model hints at coding upgrade

ChatGPT’s o3 is OpenAI’s best model to date because it features reasoning, and it might get even better in the next update. As spotted on X, OpenAI is testing a new “Alpha” variant of the o3 model, which has significant coding-related improvements. In our tests, GeekFeed observed that o3-alpha is better than o3 in designing web pages, even […]

1 min read

Russian alcohol retailer WineLab closes stores after ransomware attack

WineLab, the retail store of the largest alcohol company in Russia, has closed its stores following a cyberattack that is impacting its operations and causing purchase problems to its customers. Its parent company, Novabev Group, informed earlier this week that hackers had breached its IT systems. “On July 14, the group was subjected to an […]

2 mins read