A recently released proof-of-concept, named FalconFlank, claims to reveal a local privilege escalation vulnerability in the CrowdStrike Falcon Sensor on…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Contagious Interview Operators Move Beyond Git Hooks With Trojanized Mac Applications
North Korea-linked Contagious Interview operators have expanded their developer-targeting malware delivery operation beyond booby-trapped Git hooks and…
Hackers Compromise More Than 14,500 Dahua Security Cameras in Massive Campaign
A large-scale campaign dubbed Operation CameraSwarm compromised at least 14,530 Dahua IP cameras and related surveillance devices in just 35 days.…
LLMjacking Attack Abuses Leaked AWS Credentials to Hijack Amazon Bedrock AI Models
Threat actors are increasingly converting stolen cloud credentials into access to costly generative AI services, a technique known as LLMjacking.…
Fewer attacks, more force: Link11’s European Cyber Report finds new DDoS records for the first half of 2026
Frankfurt am Main, Germany, September 3rd, 2026, CyberNewswire Super-botnets and hijacked cloud servers drive new bandwidth and packet-rate records as…
Fake Acquisition Scam Uses Forged NDAs to Demand €626,000 Corporate Payment.
Threat actors impersonated Gen executives and major consulting firms in a targeted business email compromise-style operation that used forged…
Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems
A malicious ScreenConnect campaign in which rogue remote-access clients do more than provide attackers with hands-on control: modified clients can…
QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes
QR code phishing, widely known as “quishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images…
New $7 SweepLED Gadget Detects Hidden Cameras With 94% Accuracy in 5 Seconds
Researchers have developed SweepLED, a smartphone-based hidden-camera detection system that uses a low-cost LED accessory and computer vision to identify…
Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks
Microsoft will start automatically enabling Memory Integrity protection on eligible Windows devices through quality updates beginning in October 2026.…
HTML-Rendered QR Phishing Evades Image Extraction and OCR-Based Email Scanning
QR-code phishing, commonly known as quishing, is evolving beyond image-based payloads. Threat actors are now rendering scannable QR codes directly from…
Avast Antivirus Zero-Day PoC Lets Attackers Dump SAM Database and Gain SYSTEM Shell
A public proof-of-concept (PoC) repository has revealed a local privilege escalation zero-day vulnerability in GenDigital’s Avast Antivirus. This…
WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover
A high-severity vulnerability affecting over 5 million active WordPress installations could allow unauthenticated attackers to exploit stored SQL…
Sangoma Switchvox RCE Flaw Actively Exploited in Wild via Unauthenticated SQL Injection
Security researchers have reported active exploitation attempts targeting a critical vulnerability in Sangoma Switchvox, allowing unauthenticated…
StreamRAT Abuses Android Accessibility, MediaProjection and HVNC for Full Device Takeover
StreamRAT, a newly identified Android banking trojan distributed through fake free-TV streaming advertisements on Meta and TikTok. The campaign, tracked…
Three HP Easy Start Flaws Let Attackers Gain Root Privileges on macOS
Three high-severity vulnerabilities in HP Easy Start for macOS could allow both local and network-positioned attackers to disrupt the printer software…
Critical Cisco Nexus 9000 Flaw Lets Remote Attackers Execute Code as Root Without Authentication
Cisco has released security updates addressing a critical vulnerability in Nexus 9000 Series switches that could allow unauthenticated remote attackers to…
Ransomware Hackers Can Go From Network Access to Encryption in Less Than 24 Hours
The Gentlemen ransomware-as-a-service operation can move from confirmed access inside a victim network to encryption in under 24 hours. Demonstrating how…
CISA Warns SonicWall SMA1000 Flaws Are Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting SonicWall SMA1000 appliances to its Known…
Spring Ring Campaign Uses Teams Vishing, PowerShell RAT and NTLM Relay Attacks
A coordinated social-engineering operation tracked as Spring Ring abused Microsoft Teams external accounts to impersonate corporate IT help desks,…
