In the fast-evolving digital landscape of 2026, an organization’s most sophisticated technological defenses can be rendered useless by a single click from a well-intentioned but unsuspecting employee. Cybercriminals are increasingly bypassing firewalls and encryption by exploiting the most unpredictable and…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Top 10 Best Cloud Security Providers – 2026 Review
As businesses continue to migrate critical applications and data to the cloud, the traditional security perimeter has dissolved. The responsibility for securing these dynamic, distributed environments now falls on a complex shared responsibility model between cloud service providers (CSPs) and…
281 Android VPN Apps Expose Users to Traffic Leaks, Tracking and Tunnel Hijacking
A recent security analysis has revealed that a significant number of Android VPN applications, 281,281,281, expose users to serious privacy and security risks. These risks include traffic leaks, third-party tracking, weak encryption practices, and VPN tunnel hijacking. Android findings highlight…
Linux FUSE Vulnerability Allows Unprivileged Users to Pop a Root Shell
A newly disclosed Linux kernel vulnerability in the FUSE subsystem allows unprivileged local users to escalate privileges to root by corrupting the page cache and hijacking execution of a SUID binary such as /usr/bin/su on Ubuntu 26.04. Tracked as CVE-2026-31694,…
Hackers Exploit CitrixBleed 2 to Hijack MFA-Protected Sessions and Deploy DragonForce Ransomware
Threat actors are exploiting the CitrixBleed 2 vulnerability, tracked as CVE-2025-5777, to hijack active NetScaler sessions protected by multi-factor authentication and gain a foothold in enterprise environments. The activity indicates a standardized operator playbook, potentially operated by an initial access…
Forg365 PhaaS Uses Telegram and AI Lures to Hijack Microsoft 365 Accounts
Forg365 is a commercial phishing-as-a-service (PhaaS) platform specifically targeting Microsoft 365 users. It employs methods such as device-code phishing, adversary-in-the-middle (AiTM) workflows, AI-assisted lure generation, and token persistence tools. The platform’s onboarding process through Telegram, subscription model, and post-compromise features…
GNU Guix Vulnerabilities Let Attackers Overwrite Arbitrary Files and Escalate Privileges
Security researcher Caleb Ristvedt disclosed the issues on July 222, 202620262026, warning that all GNU Guix installations are affected. Systems running guix-daemon as root face the highest risk because a malicious substitute server or a man-in-the-middle attacker could write files…
NetScaler MCP Gateway Secures LLM and Agentic AI Traffic From a Single Platform
Citrix, a Cloud Software Group company, announced major updates to its NetScaler® platform on July 9, 2026, introducing MCP Gateway functionality designed to secure and govern the explosive growth of AI agent traffic across enterprise environments. The new capability allows…
New Multi-Stage LNK Attack Targets Hospitality Firms With Node.js Backdoor
Hospitality firms are being targeted in an active phishing campaign that uses fake booking-related emails to deliver a multi-stage Node.js backdoor. The attack chain abuses Google Share links, malicious ZIP archives, Windows shortcut files, PowerShell, and the TON blockchain to…
Wireshark 4.6.7 Released to Patch 12 Vulnerabilities in SSH, TLS, Wi-Fi and pcapng
Wireshark has released version 4.6.74.6.74.6.7, addressing 121212 security flaws across protocol dissectors, capture-file parsers, and its external capture interface. The update resolves issues affecting SSH, TLS Encrypted Client Hello (ECH), IEEE 802.11802.11802.11 Wi-Fi traffic, and pcapng capture files, among other…
Process Parameter Poisoning Technique Hides Shellcode Inside Windows Startup Data
A newly documented Windows injection approach, dubbed Process Parameter Poisoning or P³, uses process startup parameters as an unconventional staging area for shellcode. Implemented in the P³-Shellcode Loader proof of concept, the technique can reduce exposure to telemetry that endpoint…
Odyssey Stealer Attacks Macs Worldwide and Replaces Crypto Wallet Apps With Drainers
Odyssey Stealer is driving a large-scale macOS infostealer campaign that now spans more than 100 countries, with operators systematically hijacking cryptocurrency ecosystems by replacing legitimate wallet apps with drainer trojans. The operation blends advanced social engineering, AppleScript-based stealth, and persistent…
Fake Robinhood Sign-In Alerts Trick Users Into Calling Hacker-Controlled Phone Numbers
A sophisticated callback phishing campaign impersonating Robinhood is coercing victims into dialing attacker-controlled phone numbers by exploiting fear of account compromise. The campaign begins with an unsolicited email or SMS posing as a Robinhood security alert, warning recipients of “unusual…
Hackers Compromise AWS AI Gateway Connected to Amazon Bedrock to Deploy XMRig Cryptominer
A compromise of an AI gateway linked to Amazon Bedrock, highlighting how generative AI infrastructure has become a new target within the enterprise attack landscape. The incident was disclosed on July 9, 2026, and reveals attackers exploiting a LiteLLM-Proxy EC2…
GigaWiper Uses OneDrive Update Scheduled Task for Persistent Destructive Access
A sophisticated Golang-based backdoor family now tracked as GigaWiper that fuses extensive C2 controls with multiple destructive payloads. What makes GigaWiper noteworthy is not merely its destructive capacity but how it packages several formerly separate wipers and extortion tools into…
Ransomware Negotiator Jailed for Leaking Victim Secrets to BlackCat Hackers
Angelo Martino, a former ransomware negotiator from Florida, has been sentenced to 70,707 months in federal prison for conspiring with ALPHV/BlackCat ransomware operators to extort victims whom he was supposed to help during incident-response engagements. The U.S. Department of Justice…
Malicious Braintree.Net Typosquat Steals PAN, CVV, and Payment Gateway Credentials
A malicious NuGet package masquerading as the official Braintree .NET client on July 3, 2026 and Socket’s automation labeled it potential malware within ten minutes. The package, published under the misleading name Braintree.Net, is a carefully crafted typosquat that mirrors…
OpenAI Launches GPT-5.6 With Multi-Agent Cybersecurity and Vulnerability-Exploitation Capabilities
OpenAI has introduced the GPT-5.6 family, comprising Sol, Terra, and Luna, positioning it as a multi-agent platform tailored for advanced cybersecurity workflows, vulnerability research, and exploit development. The company claims that these models offer better performance per dollar compared to…
Microsoft Uses AI-Powered Agentic Scanning to Find Windows Security Flaws and Accelerate Patching
Microsoft is expanding its AI-driven vulnerability discovery across Windows, introducing a multi-model “agentic” scanning system designed to identify security flaws earlier and accelerate global patch deployment. AI-Powered Vulnerability Discovery At the core of this initiative is Microsoft Security’s Multi-Model Agentic…
Multiple U-Boot Vulnerabilities Enable Pre-Authentication Code Execution and Device DoS Attacks
Six critical vulnerabilities in the widely used U-Boot bootloader, which can be exploited through malicious Flattened Image Tree (FIT) images, allowing attackers to achieve pre-authentication arbitrary code execution or crash devices during the early boot process. U-Boot is foundational to…