A macOS-focused information stealer is combining stolen wallet databases with credentials harvested from the Apple Keychain, browsers, and Apple Notes to conduct offline cryptocurrency theft attempts. Detected by the MistEye security monitoring system, the malware appears designed for broad data…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Critical JetBrains Flaws Impact IntelliJ IDEA, TeamCity, and YouTrack Users
JetBrains has released security updates for IntelliJ IDEA, TeamCity, and YouTrack that address six vulnerabilities, including a critical path traversal issue that could enable code execution in IntelliJ IDEA. The fixes affect core developer tooling, CI/CD infrastructure, and issue-tracking environments,…
Malicious AI Agents Attempt Reverse Shells, Credential Theft, and Persistent SSH Access
AI agents are increasingly crossing the line from generating content to executing actions inside developer workstations, cloud environments, and enterprise systems. New telemetry from Gen’s H1 2026 Threat Report shows that agent runtime controls detected attempts involving reverse shells, credential-file…
Kratos PhaaS Targets Microsoft 365 Users With SharePoint Links and Cloudflare Anti-Bot Checks
Kratos, a subscription-based phishing-as-a-service platform, is targeting Microsoft 365 users in the United States, Europe, and other regions through campaigns designed to blend into ordinary document-sharing workflows. The operation abuses trusted services, including Microsoft SharePoint, OneDrive, Microsoft Forms, Canva, Tilda,…
F5 Fixes 3 NGINX Flaws Enabling Potential Remote Code Execution, Memory Disclosure, and DoS Attacks
F5 has issued security advisories for three vulnerabilities affecting NGINX Plus and NGINX Open Source. These flaws could allow unauthenticated attackers to trigger crashes in worker processes, disclose limited memory contents, or potentially execute code under specific conditions. The vulnerabilities,…
Hackers Use Google Ads and Claude AI Chats to Steal macOS Credentials and Crypto Wallets
Threat actors have exploited Google Ads and Anthropic’s Claude shared-chat feature to distribute the MacSync Stealer to macOS users. They used a social engineering technique called ClickFix, designed to steal credentials, browser data, cloud keys, sensitive files, and cryptocurrency wallets.…
LLM-Assisted TuxBot Botnet Targets IoT Devices Across 17 Processor Architectures
TuxBot v3 Evolution, a modular IoT botnet framework capable of infecting devices running architectures ranging from ARM and MIPS to x86_64, PowerPC and RISC-V. The platform appears designed for mass compromise, persistence and distributed denial-of-service operations, with a C-based bot…
GPT-5.6 Sol Ultra Writes Complete Chrome Exploit With V8 Sandbox Escape
A security researcher reported that the GPT-5.6 Sol Ultra model successfully produced a working renderer exploit for Chrome version 149.0.7827.201. This exploit utilized V8 version 14.9.207.35. The model reportedly combined multiple patched issues in the JavaScript engine and WebAssembly infrastructure,…
China-Linked Daxin Backdoor Resurfaces in Taiwan Alongside New STUPIG SYSTEM-Level Malware
The China-linked Daxin backdoor has resurfaced in an active intrusion targeting a Taiwan-based subsidiary of a multinational high-tech manufacturer, exposing the enduring reach of an espionage operation first publicly detailed in 2022. Daxin’s return is significant because the malware was…
Cursor 0-Day Flaw Executes Malicious git.exe From Repositories Without User Interaction
Cursor users on Windows may be at risk of arbitrary code execution following Mindgard’s disclosure of a zero-day vulnerability. This flaw allows the AI-powered integrated development environment (IDE) to automatically execute a malicious git.exe file located at the root of…
Russian-Speaking Hacker Uses Gemini CLI to Deploy C2 Botnet in Six Minutes
A Russian-speaking threat actor tracked as “bandcampro” used Google Gemini CLI as an end-to-end operational assistant to migrate a command-and-control server, deploy a replacement VPS, configure Cloudflare tunnels, and restore control of compromised endpoints within six minutes. The findings are…
Microsoft Blocks Windows 11 Security Update on Dell PCs Over Intel Driver Causing Shutdowns and Battery Drain
Microsoft has temporarily halted delivery of the July 14, 2026, Windows 11 security update to a limited number of Dell devices due to an incompatibility with an Intel driver that causes significant stability and power management issues. This precaution affects…
OkoBot Malware Uses ClickFix and SeedHunter to Steal Ledger and Trezor Seed Phrases
A newly documented malware framework dubbed OkoBot is targeting cryptocurrency users with a multi-stage intrusion chain designed to capture Ledger and Trezor recovery phrases, browser credentials, wallet files, keystrokes, screenshots, and application video recordings. Researchers first observed the activity in…
3 Russian Nationals Indicted for Running Bulletproof Hosting Network Behind $62 Million Cyberattacks
Three Russian nationals and two St. Petersburg-based companies have been indicted in the United States for allegedly operating a bulletproof hosting network that facilitated ransomware, malware, phishing, and other cyberattacks, resulting in over $62 million in losses for victims. The…
LabubaRAT Rust Malware Masquerades as NVIDIA Software to Backdoor Windows Systems
A previously undocumented Rust-based remote access trojan, dubbed LabubaRAT, which masquerades as legitimate NVIDIA software to establish persistent access on Windows systems. The malware was identified by the company’s Adversary Pursuit Group (APG) and appears designed as a reusable, panel-managed…
Dell Warns of Critical PowerProtect Data Domain Flaws Allowing Remote Attackers to Take Complete Control
Dell has recently disclosed two critical vulnerabilities in PowerProtect Data Domain appliances that could allow unauthenticated remote attackers to gain complete control of affected systems. These vulnerabilities are tracked as CVE-2026-53483 and CVE-2026-53481, both of which received a critical CVSS…
11 Malicious NuGet Game Cheat Packages Deploy Pepesoft Windows Surveillance Malware
11 malicious NuGet packages masquerading as game cheats, automation bots, and management “panels” that deploy a Windows payload called pepesoft.exe. The packages were published as .NET command-line tools, enabling users to install them through the dotnet tool install workflow and…
SheetAgent RAT Runs 14 Virtual Machine Checks and Self-Deletes When Analysis Is Detected
A threat campaign targeting Indian government job seekers is using a recruitment notice for Senior Field Officer positions in the Cabinet Secretariat as a lure to deploy a custom remote access Trojan, SheetAgent RAT. The campaign begins with a ZIP…
FaceTime Scammers Combine Credential Theft, Remote-Access Apps, and iOS Exploits for Device Takeover.
Apple-focused scam operations are increasingly using FaceTime as a high-trust social-engineering channel to steal credentials and, in higher-risk cases, prepare victims for device compromise. Apple said threat actors may approach targets via phone calls, FaceTime, SMS, email, and other communications,…
Google Chrome 150 Update Fixes 15 Security Vulnerabilities, Including 2 Critical Use-After-Free Flaws
Google Chrome version 150 addresses vulnerabilities in several core browser components, including Ozone, Skia, V8, GPU, Media, UI, Navigation, libyuv, and Linux Toolkit Theming. Among the updates, two critical vulnerabilities, designated as CVE-2026-15764 and CVE-2026-15765, involve use-after-free issues in Ozone,…