WRAITH combines BeEF-style browser hooks with blind-XSS capture and a credentialed Page Mirror. Tested locally, with its limits examined.
Category: EN
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code on Database Servers
A newly disclosed PostgreSQL vulnerability, tracked as CVE-2026-6471 and nicknamed PostGREShell, could allow attackers with low-level replication access…
Nscale In $3.5bn Compute Deal For Figure Humanoid Robots
Data centre provider Nscale to supply at least $3.5bn of compute to Figure AI, becomes shareholder in humanoid robot maker
OpenAI Confirms ‘wiki Hijack,’ and Says It’s Working on a Framework for Disclosure Details
OpenAI has confirmed that its AI agents wrote to several internet sites during what it calls the “wiki incident,” also described online as the “wiki…
DPRK-Linked Hackers Backdoor HAProxy Servers to Spy on South Korean Organizations
A previously undocumented Linux espionage toolkit linked with medium confidence to DPRK-aligned threat actors has been used to compromise South Korean…
Berlin Ransomware Leak Exposes State Secrets
Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web. When a…
A week in security (August 31 – September 6)
Last week on Malwarebytes Labs: Stay safe!
MikroTik routers hijacked, Russian data center threats, UK cybercrime losses surge
MikroTik routers hijacked through internet-exposed SSH Russian data centers face new security requirements UK account-hack losses surge thanks to new…
What’s the difference between WAN and LAN?
TLDR. A LAN is a local area network that connects devices in a limited place, like a home, office, or school, while a WAN is…
Magento and Adobe Commerce StyleSmuggler 0-Day RCE Actively Exploited in Attacks
Security researchers have discovered an actively exploited, unauthenticated remote code execution vulnerability affecting installations of Magento Open…
Fake Minecraft Mod Drops Myth Stealer RAT to Steal Passwords and Remotely Control PCs
A trojanized Minecraft optimization mod posing as a companion to the legitimate Lithium project has been used to deploy Myth Stealer 3.2-FIX, a…
Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week
Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from…
ToolHive: The open-source way to run any MCP server securely
ToolHive is an open-source platform that runs Model Context Protocol servers inside containers. An MCP server is the connector that lets an AI client like…
Europol celebrates the International Day of Police Cooperation
On 7 September, Europol is marking the International Day of Police Cooperation together with its partners to recognise the central role our network plays…
Hackers Actively Exploiting MikroTik RouterOS MikroTrick Flaws to Take Full Control of Routers
Threat actors are actively exploiting critical vulnerabilities in MikroTik RouterOS, collectively known as MikroTrick, to compromise internet-exposed…
Critical Telerik UI For ASP.Net Ajax Vulnerability Chain: CVE-2026-13181 to CVE-2026-13184
HOC Shorts A high-severity vulnerability chain in Telerik UI for ASP.NET AJAX (RadAsyncUpload) allows unauthenticated attackers to decrypt…
Weekly Cybersecurity Newsletter Bulletin – CrowdStrike Falcon, Chrome 0-Day, GPT-6 Astra, Dropbox Breach and 20+ Stories
This edition of the weekly cybersecurity newsletter bulletin covers critical zero-day discoveries, nation-state router compromises, emerging autonomous AI…
Hackers Can Use PEEP Chrome Extension to Steal Credentials and Execute Shell Commands
A newly identified Chromium-based post-exploitation toolkit named PEEP can turn Google Chrome and Microsoft Edge into persistent remote-access platforms,…
Zero trust AI agents demand a different kind of security
In this interview, Chris Webber, VP, Product Marketing at Teleport, explains why zero trust principles need to change for AI agents. He covers how agents…
CrowdStrike Launches SafeMind Agentic AI Cybersecurity System Built With NVIDIA Nemotron
CrowdStrike has launched SafeMind, an AI-driven cybersecurity system developed using NVIDIA’s Nemotron models. This new technology is designed as an…
