A Chinese-speaking cybercrime cluster linked to the Earth Berberoka threat actor has compromised Brazilian government and educational web servers to…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
GitSpawn Flaw Enables Arbitrary Code Execution in Claude Code, Codex, Cursor and Grok
A newly disclosed vulnerability class, named GitSpawn, reveals a serious weakness in AI coding agents that automatically execute Git commands to…
Claude AI Can Now Control macOS and Windows Computers to Click, Type and Open Apps
Anthropic has enhanced Claude’s desktop automation capabilities, enabling the AI assistant to operate directly on macOS and Windows computers through…
Google Unveils Gemini 3.8 Flash Cyber for Autonomous Vulnerability Discovery and Automated Patching
Google has introduced Gemini 3.8 Flash Cyber, a specialized AI model focused on cybersecurity. This model is designed to autonomously identify software…
Threat Intelligence: Definition, Benefits, and Use Cases
Security teams rarely struggle because they lack data. More often, the challenge is deciding which signals actually deserve attention. Modern security…
Singularity Rootkit Bypasses Elastic Defend eBPF Module Load Detection
Security researcher has disclosed a technique used by the Singularity Linux rootkit to evade Elastic Defend by suppressing module-load telemetry to avoid…
255 Fake Accounts Used to Send Malicious Excel Files to 80,000 Freelancers
A Russian national has been extradited to the United States to face charges over an alleged phishing operation that used 255 fake accounts on a freelance…
Firefox for iPhone Adds Built-In Ad Blocker to Block Third-Party Ads and Trackers
Mozilla has introduced a built-in ad blocker for Firefox on iOS, providing iPhone users with a native option to block many third-party advertisements and…
Claude AI Develops Working RCE Exploit Against WAGO PLC With Researcher Assistance
Researchers have demonstrated that Anthropic’s Claude AI can assist in porting a remote code execution exploit between vulnerable models of WAGO…
Hackers Exploit LiteLLM Admin API Flaw to Turn Read-Only Access Into Full Server Takeover
Attackers are actively exploiting a critical authorization flaw in LiteLLM’s administrative API. This vulnerability allows low-privileged, read-only users…
Palo Alto Networks Acquires Console to Add Agentic AI Workflows to Cortex
Palo Alto Networks has acquired Console, an AI-native platform designed to enable agentic workflows across enterprise operations. This acquisition expands…
The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security
The Gentlemen ransomware operation has been linked to a previously undocumented, cross-platform command-and-control framework named TukTuk, alongside…
FreeRDP 3.31.0 Fixes 22 Security Flaws Including Heap Overflow and Pre-Auth DoS Bugs
FreeRDP version 3.31.0 has been released as a significant security and stability update, addressing 22 disclosed security vulnerabilities in the widely…
Critical SonicWall SMA 1000 Vulnerabilities Actively Exploited in the Wild
SonicWall has issued an urgent security advisory regarding two vulnerabilities affecting its SMA 1000 Series secure access appliances. The company warns…
Hackers Breach Brazilian Financial Firms and Execute Hundreds of Fraudulent Transactions
A financially motivated threat actor tracked as BREEZE COMET has breached Brazilian financial, retail, and eCommerce organizations, using privileged…
Google Patches 26 Chrome Vulnerabilities, Including Critical WebGL and Shared Tab Groups Flaws
Google has released a new update for the Chrome Stable Channel on desktop platforms, addressing 26 security vulnerabilities. This includes two critical…
Critical HPE Fabric Composer Flaw Lets Unauthenticated Attackers Execute Commands as Privileged User
Hewlett Packard Enterprise (HPE) has released security updates addressing 52 vulnerabilities in HPE Networking Fabric Composer, including two critical…
Hugging Face Transformers Flaw Writes Malicious Python Code to Disk Before User Consent
A newly disclosed vulnerability in the Hugging Face Transformers library could allow attacker-controlled Python files to be written to a victim’s system…
Hackers Hide Reverse Shell Traffic Behind Signed Apps and AWS API Gateway
Threat actors are using a layered fake IT-support campaign to obtain remote access, deploy a malicious MSI package and conceal hands-on-keyboard activity…
Fake Microsoft Edge, Kaspersky and Razer Installers Used to Compromise Windows Systems
An active malware campaign that abuses counterfeit download pages for trusted software brands including Microsoft Edge, Kaspersky and Razer to compromise…
