AI-enabled phishing-as-a-service operations are driving a sharp increase in identity attacks in 202620262026, with threat actors increasingly abusing OAuth device authorization flows and Microsoft Entra ID device enrollment to obtain durable access to SaaS environments. Jalisco is a device code…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Critical SonicWall SMA 1000 SSRF and Remote Code Execution Flaws Actively Exploited in the Wild
SonicWall has issued a security advisory regarding two vulnerabilities affecting the SMA1000 Series appliances. Among these, a critical server-side request forgery (SSRF) flaw has been identified, which carries a maximum CVSS score of 10.0. The company has confirmed that threat…
Microsoft Fixes Multiple Windows RDP Flaws Exposing Sensitive Data Over the Network
Microsoft has addressed multiple information-disclosure vulnerabilities in the Windows Remote Desktop Protocol (RDP). This widely used service enables remote administration and access to Windows systems. The five flaws could permit attackers to retrieve information from vulnerable hosts, potentially exposing data…
Fortinet Patches 7 Security Flaws Affecting FortiOS, FortiProxy, FortiPAM, FortiSASE, and FortiSandbox
Fortinet has released security updates for seven vulnerabilities affecting FortiOS, FortiProxy, FortiPAM, FortiSASE, and FortiSandbox, including a high-severity flaw that could expose Virtual Network Computing (VNC) access across all network interfaces. The advisories, published by the Fortinet Product Security Incident…
China-Linked Hackers Weaponize Claude Code and DeepSeek in Government Intrusion Campaign
A suspected China-linked threat actor has integrated Anthropic’s Claude Code and DeepSeek-v4-pro into an active intrusion campaign targeting government entities, Taiwanese industry, and financial-services organizations. TencShell was first documented by Cato CTRL in May and assessed as linked to suspected…
Critical Claude for Chrome Flaw Lets Malicious Extensions Read Gmail, Google Docs, and Calendar
Two vulnerabilities in Anthropic’s Claude for Chrome extension could allow a malicious browser extension to trigger AI-driven actions affecting a victim’s Gmail, Google Docs, and Google Calendar data. These issues are still reproducible in Claude for Chrome version 1.0.801.0, released…
Notepad++ v8.9.7 Security Update Fixes 5 Vulnerabilities, Including Stack Buffer Overflow and Zip Slip Flaws
Notepad++ has released version 8.9.7, codenamed “Slava Ukraini.” This update addresses five security vulnerabilities related to session-file handling, environment-variable expansion, ZIP extraction, macro validation, and the Windows installation process. The release date was July 14, 2026, and includes three CVE-tracked…
Microsoft Patch Tuesday July 2026 – Record 570 Vulnerabilities Patched
In July 2026, Microsoft addressed a record total of 570 vulnerabilities, including three zero-days, two of which were exploited in the wild and one that was publicly disclosed. The release includes 59 Critical vulnerabilities, with Remote Code Execution (RCE) flaws…
Artlist ClickFix Campaign Uses Infostealer-Stolen WordPress Credentials to Deploy RAT Malware
A threat campaign discovered in mid-July 2026 abused the compromised Artlist subdomain new-blog. artlist[.]io to distribute a Remote Access Trojan through a fake CAPTCHA prompt. The operation combined stolen WordPress credentials, blockchain-based EtherHiding infrastructure, ClickFix social engineering, DLL side-loading, and…
Miasma Worm Returns as RAT-First npm Attack With Automatic Propagation Disabled
Four AsyncAPI packages previously affected by the Shai-Hulud: The Second Coming campaign have been compromised again, with new malicious releases delivering a RAT-focused build of the Miasma worm. The impacted versions are @asyncapi/generator 3.3.13.3.13.3.1, @asyncapi/generator-components 0.7.10.7.10.7.1, @asyncapi/generator-helpers 1.1.11.1.11.1.1, and @asyncapi/specs…
Attackers Distribute Password Attacks Across Fictional OAuth Apps to Evade SOC Alerts
Attackers are increasingly abusing spoofed OAuth application identifiers to enumerate Microsoft Entra ID accounts, test credentials, and fragment authentication activity across hundreds of thousands or millions of fictional applications. The technique exploits how Entra ID processes the client_id parameter in…
xAI Grok CLI Exposed Developer Code Through Automatic Whole-Repository Uploads
According to a reproducible wire-level analysis of version 0.2.93, xAI’s Grok Build CLI allegedly transmitted entire Git repositories, including unread files and commit history, to xAI infrastructure by default. The researcher noted that the behavior also sent the contents of…
Cybercriminals Target Turkish Banks With 8,400 Phishing Domains and 6,600 Scam Ads
Cybercriminals are operating an industrial-scale fraud ecosystem targeting Turkey’s financial sector, using more than 8,400 phishing domains, thousands of social media advertisements, fake loan offers, illicit gambling services, and money-mule recruitment to steal credentials. Group-IB’s investigation links these operations into…
ANY.RUN Integrates Threat Intelligence and Interactive Sandbox to Streamline SOC Workflows
Security Operations Centers (SOCs) often encounter challenges that go beyond just managing alert volume. Each alert necessitates that analysts validate indicators, investigate behaviors, assess scope, decide on escalation paths, and create detections to prevent future occurrences. When these tasks rely…
CISA Adds Cisco IOS CSRF Flaw Enabling Arbitrary Command Execution to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2008-4128, a cross-site request forgery (CSRF) vulnerability affecting Cisco IOS, to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability was officially listed on July 13, 2026, with a remediation deadline…
SAP July 2026 Patch Day Fixes Critical NetWeaver, Approuter, and Commerce Cloud Vulnerabilities
SAP’s July 2026 Security Patch Day addresses multiple high-impact vulnerabilities across its enterprise products, including a severe memory corruption issue in the SAP NetWeaver Application Server ABAP. The most critical vulnerability, tracked as CVE-2026-44747, has a CVSS score of 9.9…
WinFsp Race Condition Flaw Allows Attackers to Gain SYSTEM-Level Access on Windows
A newly disclosed vulnerability in the Windows File System Proxy (WinFsp) could allow a local attacker to gain SYSTEM-level privileges by exploiting a race condition that triggers a kernel heap overflow. Tracked as CVE-2026-3006, this vulnerability affects WinFsp versions 2.1.25156…
Why programming true randomness in emulators is a developer worst nightmare
Asking a deterministic machine to behave indeterministically is the cleanest paradox in software engineering, and emulator developers live inside it every working day. The job description sounds reasonable until you read it twice: recreate, with mathematical precision, a piece of…
ShinyHunters Hackers Abuse Salesforce OAuth to Bypass MFA and Exfiltrate CRM Data
A series of high-impact campaigns linked by overlapping tradecraft to ShinyHunters, in which attackers abused trusted Salesforce OAuth relationships to bypass conventional MFA protections, establish persistence, and exfiltrate CRM data at scale. The activity, observed from mid-202520252025 through mid-202620262026, affected…
Pro-Iran Hacktivist Groups Launch DDoS and Hack-and-Leak Attacks Against Critical Infrastructure
A decentralized network of pro-Iran hacktivist groups is intensifying cyber operations against critical infrastructure, government entities, technology providers, and organizations perceived as aligned with U.S., Israeli, or Western interests. The activity is dominated by distributed denial-of-service attacks, defacements, credential-focused operations,…