A newly disclosed cluster of Microsoft SharePoint Server vulnerabilities is actively being exploited in the wild, allowing attackers to convert a single crafted web request into full remote code execution and long-term persistence across enterprise environments. Security updates released in…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier
Microsoft will stop delivering feature updates, bug fixes, and security patches for the OneDrive sync app on systems running Windows version 21H2 and earlier on August 15, 2026. This change was announced in the Microsoft 365 Message Center notification MC1426708…
LG Monitors Silently Install McAfee Adware on Windows PCs With Full System Access
Concerns have arisen regarding LG monitors that reportedly trigger the silent installation of an LG companion application on Windows PCs. This installation is followed by promotional prompts for a McAfee security trial, raising issues related to device-software delivery mechanisms, user…
Microsoft Releases Emergency Windows 11 Update to Fix Intel IPF Driver Performance Issues
Microsoft has released KB5121767, an out-of-band (OOB) cumulative update for Windows 11 versions 22H2 and 21H2. This update addresses a system performance issue related to the Intel Innovation Platform Framework (Intel IPF) drivers. The update was made available on July…
U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million
U.S. federal prosecutors have unsealed a sweeping indictment charging three Russian nationals and two St. Petersburg–based companies for operating a global “bulletproof hosting” infrastructure. That enabled widespread cyberattacks against critical sectors, causing losses exceeding $62 million across at least 21…
GoldenEyeDog Threat Group Behind DigiCert Code-Signing Certificate Attack
GoldenEyeDog, a Chinese cybercrime group increasingly tracked as an advanced threat cluster, has been linked to a sophisticated intrusion into DigiCert that enabled the theft and abuse of legitimate code-signing certificates. The group has been active since at least 2015…
Weekly Cybersecurity Newsletter – The 50 Biggest Cybersecurity Stories – Microsoft Patch, AI Attack, Exploits Releases, Data Breaches & More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 40 most important stories from July 13–17, 2026. What a week: Microsoft shattered records with 570 vulnerabilities patched in a single Patch Tuesday,…
PENTDEM AI Pentesting Daemon Uses 34 Security Tools to Automate WAF Bypass and Attack Chains
PENTDEM is an open-source autonomous AI pentesting daemon that integrates 34 security tools with LLM-directed analysis to automate various tasks, including reconnaissance, vulnerability discovery, evidence validation, Web Application Firewall (WAF) fingerprinting, and multi-stage attack-path modeling. This Python-based project is designed…
Furtex Linux Toolkit Uses io_uring and eBPF to Bypass EDR and Falco Detection
A newly published Linux toolkit named Furtex showcases a wide range of concepts related to post-exploitation, persistence, data access, and monitoring evasion. It is built around io_uring, eBPF, BPF maps, and raw system calls. The project includes over 100 tools…
North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images
A sophisticated North Korean threat campaign dubbed “Contagious Interview” has resurfaced with new delivery techniques, leveraging weaponized SVG image files to deploy the OTTERCOOKIE malware while coinciding with a separate supply chain intrusion targeting the Ruby ecosystem. Security researchers tracking…
Kimai Docker Vulnerability Exposes Default APP_SECRET, Enabling Account Takeover
Kimai users who are running the official Docker image are strongly urged to update their installations after a critical vulnerability, tracked as CVE-2026-52824 and GHSA-jr9p-4h4j-6c58, was discovered. This vulnerability exposes installations to the risk of account takeover due to a…
Hugging Face Security Breach Exposes Internal Datasets, Credentials, and Tokens
Hugging Face has disclosed a security incident involving unauthorized access to certain parts of its production infrastructure, affecting a limited set of internal datasets and several service credentials. The AI platform made this disclosure on July 16, 2026, noting that…
Critical WordPress Core Flaw Lets Anonymous Hackers Gain Remote Code Execution
A newly disclosed a pre-authentication remote code execution (RCE) vulnerability in WordPress Core, dubbed “wp2shell,” that requires no authentication and affects stock WordPress installations with zero plugins installed. Given that WordPress powers an estimated 500 million websites globally. The flaw…
EY Data Breach – Hackers Access Third-Party IT Support Platform and Steal Client Tax Documents
Ernst & Young LLP (EY) has confirmed a data security incident in which an unauthorized third party breached a third-party IT service management platform used by its tax practice, exfiltrating documents containing client personal and financial information. The Big Four…
OpenSSL DoS Vulnerability Lets Remote Attackers Exhaust Server Memory With an 11-Byte Payload
A newly disclosed vulnerability reminds us how deeply our digital infrastructure relies on foundational libraries. The Okta Red Team recently discovered “HollowByte,” a Denial of Service (DoS) flaw in OpenSSL that allows a remote, unauthenticated attacker to force a server…
Citrix Secure Access Client Flaw Lets Low-Privileged Windows Users Gain SYSTEM Privileges
Cloud Software Group has issued a High-severity security bulletin (CTX696734) disclosing two vulnerabilities in the Citrix Secure Access Client for Windows and the Citrix Endpoint Analysis Client for Windows. The more serious of the two, tracked as CVE-2026-53565, allows a…
New Starland RAT Steals Browser Credentials and Scans for Over 40 Crypto Wallets
A financially motivated, Russian-speaking threat actor tracked as UAT-11795, orchestrating a large-scale campaign since at least June 2025. A sophisticated Python-based remote access trojan dubbed “Starland RAT,” alongside a stealthy in-memory PowerShell implant known as the “WLDR agent.” The operation…
Hackers Hide Lua Loaders in Fake TTF Files to Deploy Remcos, XWorm, and Agent Tesla
Hackers are increasingly abusing trusted file formats and lightweight scripting environments to evade detection, with a newly observed campaign leveraging Lua-based loaders. Disguised as TrueType (.ttf) font files to deploy commodity malware, including Remcos RAT, Agent Tesla, XWorm, and Snake…
LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives
A newly disclosed Windows local privilege-escalation vulnerability, dubbed LegacyHive, could allow a standard user to load and modify the per-user registry classes hive of an administrator account. The proof-of-concept (PoC), published by researcher NightmareEclipse under the MSNightmare/LegacyHive GitHub repository, abuses…
AWS Billing Bug Displays Trillion-Dollar Cost Estimates to Cloud Customers
Amazon Web Services (AWS) is currently investigating a significant billing issue affecting its Cost Explorer tool. This problem caused some cloud customers to see alarmingly inflated cost estimates, with figures reportedly reaching into the trillions of dollars. AWS Support acknowledged…