Anthropic’s Claude AI platform is currently dealing with two separate cybercrime campaigns that aim to steal account credentials, misuse paid…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Simple Router DNS Tweak Blocks Malware and Phishing Across All Connected Devices
A recent router-level DNS change is gaining attention as a method to reduce exposure to phishing pages and malware across all devices connected to a home…
Infostealer Infection Exposes Blind Eagle-Linked Operator’s Malware Production Pipeline
A compromised attacker-side workstation has given researchers an unusual view into the operational ecosystem behind a suspected Blind Eagle malware…
OpenAI Warns Astra AI Model May Develop Zero-Day Exploits and Launch Autonomous Cyberattacks
OpenAI has issued a warning regarding Astra, an upcoming artificial intelligence model, which may be close to a threshold of cybersecurity capabilities…
Critical Gogs Flaw Enables Remote Code Execution Through Path Traversal
A critical vulnerability in Gogs, the self-hosted Git service, could allow authenticated attackers to execute commands on the server by abusing path…
Hackers Compromise TanStack Query npm Package to Steal Developer Credentials
A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen, an npm package that generates type-safe TanStack Query hooks.…
Hackers Use Fake Cloudflare CAPTCHA to Deploy TerminalFix Reverse Tunnel
A newly documented TerminalFix campaign is using fake Cloudflare CAPTCHA prompts to trick users into manually executing malicious PowerShell commands,…
Chinese Hackers Deploy PackClient RAT via Tax-Themed Phishing Attacks to Steal Data
A Chinese-speaking threat actor tracked as TA4922 is deploying the PackClient remote access trojan via tax-themed phishing campaigns targeting…
Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure
Attackers are increasingly treating AI infrastructure as a high-value cloud entry point, exploiting exposed Model Context Protocol (MCP) services, agent…
700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution
OpenAI’s ExploitGym evaluation environment reportedly became the site of a large-scale, unsanctioned multi-agent campaign after hundreds of models found…
Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit
A newly analyzed phishing operation is using server-side polymorphism to generate a distinct credential-harvesting page for virtually every request,…
Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover
A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin, which could allow unauthenticated attackers…
ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection
ServiceNow has issued security advisories for four vulnerabilities, including critical flaws in its AI platform. These vulnerabilities could allow…
Researchers Execute Code Inside Fortune 500 Companies via AI Agent llms.txt Files
Security researchers have shown that AI coding agents can be manipulated into installing attacker-controlled packages by following instructions found in…
Suspected Iran-Linked Cyberattack Knocks UK Power Plant Offline for Four Days
A cyber incident reportedly forced a small UK power generation facility offline for about four days in July 2026. While the activity has been linked in…
BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE Malware
Russian state-linked threat actor BlueDelta has launched a renewed espionage campaign against defense manufacturing, government, and diplomatic…
Unitree G1 Humanoid Robot Flaws Allow Unauthenticated Root RCE Over Bluetooth
Security researcher Boschko has revealed two vulnerabilities in Unitree’s G1 humanoid robot that can be exploited to achieve unauthenticated remote code…
Prompt Injection Attack Hijacks Claude Code Opus 5 Auto Mode to Execute Malicious Code
A recent demonstration of prompt-injection research has revealed that Claude Code Opus 5, when running in its default Auto Mode, can be manipulated to…
TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation
A newly emerged ransomware-as-a-service operation named TITAN is advertising an AI-driven extortion platform that it claims can autonomously classify…
Hundreds of WordPress Sites Hijacked to Show Fake reCAPTCHA and Steal Windows Passwords.
Hundreds of compromised WordPress websites are being used in a sophisticated malware-delivery campaign that combines browser persistence,…
