Security researchers have recently disclosed a new enterprise AI attack technique known as Workflow Identity Hijacking. This method enables external…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
Threat actors are increasingly using ClickFix social-engineering lures and search-engine malvertising to deploy MacSync Stealer, a macOS-focused…
Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
Threat actors targeting organizations across Latin America are increasingly embedding commercial large language models (LLMs) into intrusion workflows,…
Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
Threat intelligence firm GreyNoise has identified an AI-driven intrusion campaign, likely orchestrated by a Russian-speaking threat actor, that…
China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
Researcher has discovered a rapidly spreading exploit kit called BlueMoon, which combines vulnerabilities in the Chrome browser with a Windows kernel…
Anthropic Claude AI Models Attack Real Systems During Misconfigured Cybersecurity Tests
Anthropic has reported four cybersecurity evaluation incidents in which pre-release Claude AI models gained unauthorized access to real third-party…
Hackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential-Stealing Malware
A multi-stage malware operation that combines fake Google CAPTCHA prompts, WebDAV-hosted DLL execution, malicious Cloudflare Workers and BNB Smart Chain…
FortiPAM Chrome Extension Vulnerability Lets Malicious Sites Control Browser Proxy and Record Tabs
A critical vulnerability has been identified in the Fortinet FortiPAM Chrome extension that could allow a malicious website to manipulate browser proxy…
SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise
Austin, Texas / USA, September 9th, 2026, CyberNewswire Ninety-five percent of organizations believe they have visibility into their AI and machine…
Iran-Linked Hackers Use Fake LinkedIn Job Offers to Deploy NodeRabbit and PollCat RATs
Iran-linked cyberespionage group Mirage Kitten is targeting software engineers with fake recruiter outreach on LinkedIn and job-search platforms. Using…
Critical ArangoDB Bugs Expose Entire Databases and Enable Remote Code Execution as Root
Two critical ArangoDB vulnerabilities can allow unauthenticated attackers to access protected database APIs and, after obtaining valid database access,…
Critical MapLibre GL JS Vulnerability Enables Zero-Click XSS Attacks
MapLibre GL JS users are advised to upgrade their software following the disclosure of an XSS vulnerability, identified as CVE-2026-85061 and documented…
GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GoldFactory has expanded the evasion capabilities of its Gigabud Android banking trojan by deploying Vwork, a weaponized fork of the open-source Shelter…
Windows BitLocker Flaw Lets Attackers Execute Code on Vulnerable Systems
Microsoft disclosed CVE-2026-69449, an Important-severity vulnerability in Windows BitLocker. This issue is classified as a heap-based buffer overflow…
ChatGPT Flaw Could Let Attackers Steal Gmail Data Across User Accounts
Security researchers have revealed a recently patched flaw in ChatGPT’s isolation system that could have allowed attackers to access data from a victim’s…
Hackers Weaponize Agentic AI to Automate Reconnaissance, Exploitation and Post-Exploitation
Threat actors are increasingly operationalizing agentic artificial intelligence to compress cyberattack timelines, automating reconnaissance,…
Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT
Threat actors are actively exploiting a critical vulnerability in FortiGate to deploy PivotC2, a Node. js-based remote access trojan (RAT) designed for…
Windows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM
A newly published proof-of-concept (PoC) called ShieldCrash reveals an unpatched vulnerability in Microsoft Defender that allows a local attacker to gain…
DeepSeek, Alibaba and Chinese AI Firms Extract Billions of Tokens From U.S. AI Models
U.S. intelligence and cybersecurity agencies have accused six China-based AI companies including DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI…
The 12 Best Managed XDR Services, Compared and Priced
Best value overall: Bitdefender — competent managed XDR at pricing that mid-market organizations can approve, which most of this list cannot claim. Best…
