Microsoft Defender XDR users may inadvertently overlook command-and-control (C2) traffic when searching for Internet-bound connections due to a specific behavior in how IP addresses are classified. This issue arises from Kusto Query Language (KQL) detections that depend solely on filtering…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data
JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe high‑value AI and ML artifacts across an entire stack. A missing‑authentication bug in the /api/v1/validate/code endpoint…
Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution
Threat actors are actively exploiting CVE-2026-6875, a critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform. This vulnerability allows attackers to escape a restricted server-side script sandbox and execute code without valid credentials. Reports from Defused indicate observed…
AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows
AsyncAPI’s npm ecosystem suffered a coordinated supply chain compromise on July 14, 2026, delivering a Miasma‑associated Node.js backdoor through trusted GitHub Actions–driven release workflows and exposing high‑value developer and CI/CD environments to remote access, credential theft, and further lateral movement.…
Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials
Iran-linked APT42 is escalating its espionage operations with AI-assisted phishing and an expanded TAMECAT backdoor, enabling long-lived access to defense and government identities rather than just endpoints. Recent activity shows tightly integrated social engineering, cloud abuse, and fileless PowerShell tradecraft…
Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell
An ongoing exploitation of two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) devices. These vulnerabilities allowed a threat actor, identified as UTA0533, to gain root-level access, install persistent malware, and deploy the ORANGETAIL Java webshell on vulnerable VPN appliances.…
Abbott Confirms Cyberattack After Unauthorized Access to Cancer Diagnostics Systems
Abbott has disclosed a cybersecurity incident involving unauthorized access to a limited number of internal systems used by its Cancer Diagnostics business. Upon discovering the activity, the company acted swiftly by launching an investigation, engaging external cybersecurity experts, and coordinating…
Critical Gitea Flaw Lets Public-Only Tokens Write to Private Repositories and Trigger Actions Workflows
Gitea administrators are strongly encouraged to upgrade their systems following the discovery of a critical authorization vulnerability. This flaw allows public-only API tokens to modify private pull request branches and potentially trigger Gitea Actions workflows. The vulnerability, tracked as CVE-2026-58443…
AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware
AgentBaiting is the clearest sign yet that AI agents and their capability ecosystems have become a first‑class malware delivery surface, with FakeGit’s 7,600‑repo operation pushing SmartLoader and StealC directly into AI Skills and MCP workflows. By turning agent‑readable READMEs, public…
Linux Kernel Team Publishes 440 CVE Security Advisories Within 24 Hours
The Linux kernel security team published approximately 440,440 CVE advisories over 24 hours, reflecting a significant release of vulnerability records linked to fixes already incorporated into the upstream kernel tree. These notices were distributed through the linux-cve-announce mailing list between…
Fileless Stealer and PureRAT Raid Browser Passwords, Telegram Sessions, and Crypto Wallets
Fileless stealer and PureRAT operators are abusing a WebDAV‑backed “malware delivery lab” to raid browser passwords, Telegram sessions, and cryptocurrency wallets in a campaign that blends fileless info‑stealing with a modular .NET RAT. The incident began with an MDR alert…
European Password Manager Passwork Shares Codebase and Updates With FSTEC-Certified Russian Firm
Passwork Europe, a Spain-based password manager used by European public sector bodies, universities, and private organizations, is facing scrutiny after an investigation led by OCCRP uncovered technical and historical connections to a Russian counterpart certified by Russian state agencies. The…
Bit2Watt Attack Turns AI Data Centers Into Cyber-Physical Threats to Local Power Grids
Bit2Watt is a newly disclosed cyber‑physical attack class that weaponizes AI and GPU workloads in modern data centers to destabilize nearby power grids, turning compute infrastructure itself into a grid‑scale threat surface. Measurements on NVIDIA accelerators show sub‑millisecond power ramps…
Hackers Hide C2 Traffic Inside Telegram While Targeting Middle East Governments
Hackers are increasingly blending malicious traffic with legitimate services, and a newly uncovered campaign shows how far this tactic has evolved. The activity has been attributed to a threat actor with links to East Asia, with researchers uncovering a previously…
HOLLOWGRAPH Malware Turns Microsoft 365 Calendar Events Into Covert Command-and-Control Channels
HOLLOWGRAPH, a Windows malware implant that transforms Microsoft 365 calendar events into a covert command-and-control channel. This malware, which is highly likely linked to the Cavern modular backdoor framework, utilizes the Microsoft Graph API to retrieve tasks from operators and…
Paidwork Data Breach Exposes 23.3 Million Accounts, Banking Data and bcrypt Password Hashes
Gig-economy platform Paidwork has been linked to a significant data breach that affects 23.3 million accounts. This breach, involving an approximately 11GB dataset, was publicly released in July 2026. The incident was added to the Have I Been Pwned (HIBP)…
Hackers Exploit Palo Alto PAN-OS Flaw to Deploy Qilin Ransomware
Hackers are exploiting a high-severity vulnerability in Palo Alto Networks’ PAN-OS to gain initial access to corporate networks and deploy Qilin ransomware. Multiple intrusions investigated in June 2026 began with the exploitation of CVE-2026-0257, an authentication bypass flaw affecting GlobalProtect…
The 12 Best Identity Threat Detection & Response (ITDR) Solutions, Compared and Priced (2026)
Identity is where breaches start, and ITDR pricing is where budgets get confused platform modules, IdP SKUs, E5 bundles, and managed services all claim the same acronym. The value verdict up front: Huntress is the best published-price ITDR for SMBs…
GPT-5.6 Sol Ultra Discovers WordPress Pre-Auth SQL Injection Leading to RCE
A critical vulnerability chain in WordPress, called wp2shell, that allegedly allows unauthenticated attackers to exploit a pre-authentication SQL injection flaw to achieve remote code execution (RCE) on typical WordPress installations running MySQL. Security researcher Adam Kues discovered this vulnerability chain…
TELEPUZ Web Injector Can Steal Cookies, Execute JavaScript, and Replace IBAN Details
A rapidly evolving malware family dubbed TELEPUZ, a modular and lightweight threat that is gaining traction through a ClickFix–VIDAR infection chain. Despite a relatively small command-and-control (C2) footprint, the pace of development and distribution suggests an emerging large-scale operation. The…