Apache has released version 11.0.25 of Apache Tomcat to address ten security vulnerabilities, including multiple flaws that could lead to authentication…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Russia-Linked Operators Used ChatGPT to Run a Secretive Online Influence Campaign
OpenAI has disrupted a covert influence operation that used ChatGPT to promote a purported Israeli think tank, spread Russia-favorable narratives, and…
Iran-Linked Hackers Use Reverse SSH Tunnels to Reach Deep Inside Compromised Networks
Iran-linked threat actor Tortoiseshell is expanding its espionage toolkit with reverse SSH tunneling utilities and a TWOSTROKE-like backdoor designed to…
SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root
SonicWall has released security updates for two high-severity vulnerabilities in its NetExtender Linux Client. One of these is a path traversal flaw that…
Critical WatchGuard Agent Flaws Let Unauthenticated Attackers Execute Remote Code
WatchGuard has revealed two critical vulnerabilities in its Windows WatchGuard Agent, which could allow unauthenticated attackers to execute arbitrary…
Fake Claude Desktop Installer Deploys SectopRAT Using DLL Sideloading and Blockchain C2
A fake Claude Desktop installer campaign is using Bing malvertising to impersonate trusted Claude. ai-hosted content, DLL sideloading, and…
Hackers Turn Trusted npm Mirrors Into Hosts for Fake Cloudflare ClickFix Pages.
Threat actors are abusing npm’s package-distribution ecosystem to host convincing fake Cloudflare verification pages on trusted mirror domains, turning…
Google Chrome 152 Patches 327 Security Flaws, Including 10 Critical Vulnerabilities
Google has released Chrome version 152 for Windows, macOS, and Linux, addressing 327 security vulnerabilities, including 10 rated as Critical. This…
Iran-Linked Hackers Abuse Legitimate Deno Runtime to Hide Dindoor Backdoor on Windows Systems
Iran-linked threat actors associated with MuddyWater are using a newly tracked Windows backdoor dubbed Dindoor that hijacks the legitimate Deno runtime to…
Critical WordPress TranslatePress Flaw Lets Attackers Take Over Admin Accounts
A critical vulnerability in the TranslatePress multilingual WordPress plugin could enable unauthenticated attackers to take control of administrator…
NVIDIA NemoClaw Vulnerability Lets Attackers Hijack AI Agents via DNS Rebinding
A critical vulnerability in NVIDIA NemoClaw, tracked as CVE-2026-65105, could enable attackers to gain persistent control of locally deployed AI agents…
Microsoft SharePoint Flaws Let Unauthenticated Attackers Execute Remote Code
Microsoft SharePoint Server administrators are being urged to patch two vulnerabilities that could be combined to allow unauthenticated remote code…
28,000 Exposed .git Repositories Leak Active AWS, OpenAI, Stripe and GitHub Credentials
A large-scale internet scan has uncovered 28,000 publicly accessible .git repositories exposing credentials for AWS, OpenAI, Stripe, GitHub, and other…
Linux Turns 35 as Open-Source Kernel Powers Global Critical Infrastructure
Linux has now reached 35 years old, serving as a reminder of the modern world’s reliance on an open-source kernel. On August 25, 1991, a 21-year-old…
AI-Powered Balonx Sistema PhaaS Harvests Credentials From Over 1,100 Banking Users
Mexico’s financial sector is facing an industrialized phishing Balonx Sistema, a Mexico-focused Phishing-as-a-Service (PhaaS) platform that has harvested…
OpenSSL Flaws Allow Remote Attackers to Crash Servers With Malformed Packets
OpenSSL has released security updates addressing nine vulnerabilities that could allow remote attackers to crash QUIC, DTLS, CMS, CMP, and TLS-enabled…
Hackers Hide Malware Inside Plain English Words to Infect Windows Users With Amatera Stealer
Threat actors behind ClearFake campaigns are using a newly identified loader, WordlistLoader, to deliver the Amatera Stealer to Windows systems. The…
Microsoft Teams Outage Disrupts Meetings and Screen Sharing for Users
Microsoft confirmed that some customers were unable to use multiple features of Microsoft Teams. However, the company reported that monitoring indicated…
CISA Red Team Achieves Full Domain Compromise Across Critical Infrastructure Networks
CISA’s latest red team assessment shows how common failures in Active Directory, cloud identity, and SOC processes can turn a phishing foothold into an…
WhatsApp Passkeys Now Protect Over 1 Billion Users Against Account Takeover Attacks
WhatsApp has announced that over one billion people now use passkeys to secure their accounts, enhancing phishing-resistant authentication across one of…
