27 Sep, 2026

Placeholder domain used in dev docs now serves ClickFix attacks

The “third-party.com” domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands. The domain third-party.com has long been used in documentation to represent an arbitrary external website, API, or service, similar to how developers use domains such […]

6 mins read

InfraTrust report warns network management systems under attack

Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. This was reported in the September edition of Eclypsium’s InfraTrust Pulse, a monthly report tracking security advisories affecting network devices, servers, firmware, chips, and other infrastructure. Between August 25 and […]

7 mins read

Rogue external MFA providers can steal passwords during logins

Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users’ passwords during legitimate login attempts. The technique, dubbed TrustSink by Varonis Threat Labs, can work with any provider that relies on this external authentication model, though the researchers demonstrated the attack using Microsoft Entra. Microsoft […]

4 mins read

Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults

Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. The new Windows Age API uses information associated with a Microsoft account and can return age ranges such as under 10, 10-12, 13-15, 16-17, and […]

1 min read

Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks

You’re not alone if you just received an “Apple Threat Notification” saying it detected a “mercenary spyware attack targeted at your iPhone.” Apple confirmed to GeekFeed that it sent a new batch of threat notifications on August 13 to targeted users in 110 countries. Some users on Reddit also reported receiving the alerts, but the feature itself […]

3 mins read

White House taps security firms for offensive hack-back operations

A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations. Signed on Wednesday, the national security presidential memorandum (NSPM) enables the NCC (part of the Homeland Security Task Force) […]

2 mins read

OpenAI releases ChatGPT 5.6 Cyber, but it’s only for approved users

OpenAI has developed a new model called “GPT 5.6 Cyber,” designed for vulnerability research, penetration testing, and incident response. OpenAI says GPT 5.6 Cyber is only available to select companies, including Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group, and SpecterOps. It’s also rolling out to supported security vendors, including Palo Alto Networks, CrowdStrike, Cisco, […]

2 mins read

LexisNexis shuts down services after suspicious activity on servers

LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. The company said it is investigating the incident with assistance from a cybersecurity forensic firm and is rebuilding affected systems in a new environment before bringing the services […]

2 mins read

Google Chrome may soon block New Tab hijacker extensions by default

Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. GeekFeed spotted the protection in a chain of work-in-progress Chromium Gerrit changes. It has not shipped yet, but Google plans to enable it by default once the changes are approved. […]

3 mins read

CISA warns of cyberattacks disrupting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. The agency’s urgent alert comes after hackers disrupted more than 30 community water systems in Minnesota in attacks that started last Sunday and continued through Monday. CISA’s alert […]

3 mins read