Akira attackers used Safe Mode to disable EDR before deploying ransomware, but memory issues caused the encryptor to fail. An Akira ransomware affiliate…
GeoServer Pre-Auth SQL Injection Flaw Lets Attackers Gain Remote Code Execution
A newly disclosed SQL injection vulnerability in GeoServer allows remote attackers to execute operating system commands on backend PostgreSQL hosts under…
Evooo1Bot Linux Botnet Uses 16 DDoS Methods and SOCKS5 Proxies to Hijack Edge Devices
A newly tracked Linux botnet is turning exposed edge devices into tools for disruption, remote access, and traffic relaying. Evooo1Bot is the threat that…
SAP Commerce flaw exploited, Mirai boosts capabilities, Shell investigates breach
Max severity SAP Commerce Cloud flaw now targeted in attacks New Mirai variant adds stealth capabilities to botnet code Shell investigates potential…
ChainDrop npm Worm Poisons 444 Packages Through GitHub Actions and Trusted Publishing
ChainDrop has made an npm package compromise a warning about developer machines. The self-propagating campaign poisoned 444 packages and more than 1,300…
A week in security (August 10 – August 16)
A list of topics we covered in the week of August 10 to August 16 of 2026
Fake Web3 Interview Uses Signed ClickOnce to Deploy NeedleStealer and hVNC RAT
Fake job interviews are again being used to breach cryptocurrency teams. In a documented case, a convincing Web3 recruitment process led a Windows user to…
Black Hat and DEF CON are AI conferences now, too
On this week’s episode of The Reg’s Kettle podcast, we revisit ‘hacker summer camp,’ where the hottest topic was … sigh… agentic AI
12 KB Windows Backdoor Hides C2 Domain in desktop.ini Whitespace to Evade Detection
A newly documented Windows backdoor shows how little code an attacker needs to stay hidden. The 12 KB implant was found on one corporate workstation,…
ChainDrop Publishes Initial Malware Without Stealing a Long-Lived npm Token
The ChainDrop campaign has exposed a gap in modern software supply-chain defenses: malware no longer needs a durable npm publishing token or even an npm…
Safepal Confirm Hackers Gained Access to Customer Order Information
SafePal has confirmed a security incident in which unauthorized parties accessed customer order information through a flaw in an order-tracking plug-in.…
Weekly Recap! – Top 50 Biggest Cybersecurity Stories of the Week: Apple Spyware, Zoom Zero-Click RCE, VMware vCenter Exploits, Microsoft Patch Day & More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from…
Fortune 500 Companies Hit in Azure Data Theft Campaign
A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations.
IT Security News Hourly Summary 2026-08-17 09h : 6 posts
6 posts published in the last hour 06:31Evooo1Bot Turns Compromised Routers Into DDoS Bots and Anonymous Proxy Nodes 06:02The OWASP LLM Top 10 Was the Warm-Up: What Comes Next 06:0212 KB Backdoor Masquerades as Realtek Software and Hides C2 in…
Evooo1Bot Turns Compromised Routers Into DDoS Bots and Anonymous Proxy Nodes
A newly identified Linux botnet dubbed Evooo1Bot is targeting vulnerable internet-facing routers, edge appliances, cameras, and enterprise systems,…
The OWASP LLM Top 10 Was the Warm-Up: What Comes Next
When the OWASP Top 10 for LLM Applications arrived, it did the industry a real service. It gave security teams a stable, vendor-neutral vocabulary for a…
12 KB Backdoor Masquerades as Realtek Software and Hides C2 in Windows Whitespace
A compact, custom-built Windows backdoor that impersonates Realtek software, persists through WMI, and conceals its command-and-control address inside…
Windows 11’s strongest security defenses can be bypassed without a screwdriver
Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without…
MessiahGPT Unrestricted AI Model Lets Hackers Generate Ransomware and Phishing Kits
A newly surfaced criminal AI service named MessiahGPT is being marketed on BreachForums as an unrestricted offensive model capable of generating…
IT Security News Hourly Summary 2026-08-17 08h : 7 posts
7 posts published in the last hour 05:31China Z.ai Benchmarks GLM-5.3 Against Anthropic Mythos 5 in Cyber Defense Tests 05:31Shell Investigates Data Breach After Cl0p Ransomware Claims Theft of 89GB Corporate Data 05:31Hazmat: Open-source containment for AI agents 05:31Critical SAP…
China Z.ai Benchmarks GLM-5.3 Against Anthropic Mythos 5 in Cyber Defense Tests
Chinese AI startup Z.ai officially benchmarked its open-weights model, GLM-5.3, claiming its software vulnerability detection capabilities match—and…
Shell Investigates Data Breach After Cl0p Ransomware Claims Theft of 89GB Corporate Data
Shell has launched a cybersecurity investigation following claims by the Cl0p ransomware operation that it stole 89GB of corporate information from the…
Hazmat: Open-source containment for AI agents
Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code,…
Critical SAP Commerce Cloud RCE Vulnerability Actively Exploited in the Wild
Defused, a threat intelligence provider, reported exploitation attempts targeting CVE-2026-58231, a critical unauthenticated remote code execution…