A newly documented Windows attack pattern, dubbed Bring Your Own Trusted Caller (BYOTC), shows how attackers can bypass driver-level authorization…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
The Best 12 Business VPN Solutions, Compared and Priced
Best value overall: Tailscale. It publishes its pricing, has a genuinely usable free tier for small teams, and its per-service access model is more secure…
Telerik UI Flaws Let Attackers Chain AES-CBC Padding Oracle to Unauthenticated RCE
Security researchers have identified a critical vulnerability chain in Progress Telerik UI for ASP.NET AJAX, which allows unauthenticated attackers to…
Kimsuky Uses OpenCode AI Agent and GitHub PATs in Operation GitPower Attacks
North Korea-linked threat actor Kimsuky has expanded its Operation GitPower activity with malicious LNK shortcuts, GitHub Personal Access Token…
Critical N-able N-central Flaw Enables Pre-Auth Remote Code Execution
N-able has released a security update to address CVE-2026-86218, a critical-severity vulnerability in its N-central remote monitoring and management…
OpenAI Confirms AI Agents Wrote to Multiple Internet Sites in ‘Wiki Incident’
OpenAI has acknowledged that its AI agents posted content on multiple internet sites during an event it has termed the “wiki incident.” The company…
Hackers Exploit PaperCut NG/MF Flaws to Steal Credentials and Deploy Meterpreter
Threat actors are actively exploiting two critical vulnerabilities in PaperCut NG/MF, identified as CVE-2026-81578 and CVE-2026-82078. These exploits…
DPRK-Linked Hackers Backdoor HAProxy Servers to Spy on South Korean Organizations
A previously undocumented Linux espionage toolkit linked with medium confidence to DPRK-aligned threat actors has been used to compromise South Korean…
Magento and Adobe Commerce StyleSmuggler 0-Day RCE Actively Exploited in Attacks
Security researchers have discovered an actively exploited, unauthenticated remote code execution vulnerability affecting installations of Magento Open…
Fake Minecraft Mod Drops Myth Stealer RAT to Steal Passwords and Remotely Control PCs
A trojanized Minecraft optimization mod posing as a companion to the legitimate Lithium project has been used to deploy Myth Stealer 3.2-FIX, a…
Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week
Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from…
Hackers Actively Exploiting MikroTik RouterOS MikroTrick Flaws to Take Full Control of Routers
Threat actors are actively exploiting critical vulnerabilities in MikroTik RouterOS, collectively known as MikroTrick, to compromise internet-exposed…
Hackers Can Use PEEP Chrome Extension to Steal Credentials and Execute Shell Commands
A newly identified Chromium-based post-exploitation toolkit named PEEP can turn Google Chrome and Microsoft Edge into persistent remote-access platforms,…
CrowdStrike Launches SafeMind Agentic AI Cybersecurity System Built With NVIDIA Nemotron
CrowdStrike has launched SafeMind, an AI-driven cybersecurity system developed using NVIDIA’s Nemotron models. This new technology is designed as an…
Critical ASUS Control Center CVE-2026-75754 Flaw Allows Unauthenticated Root Access
ASUS has issued a security bulletin regarding a critical vulnerability in ASUS Control Center Enterprise (ACC), identified as CVE-2026-75754. This flaw…
Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security
Chainguard has surpassed 1 billion container build manifests, doubling production from 500 million in six months as it expands its AI-assisted software…
Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe
Russian state-sponsored threat actor BlueDelta, also tracked as APT28, Fancy Bear, and Forest Blizzard, has deployed a lightweight Windows backdoor named…
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to…
New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption
Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS) operation, publishing 16 alleged victims across 11 countries while combining data…
CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each
Used-car platform CARS24 has alleged that confidential information belonging to approximately 3,100 customers was stolen and supplied to a rival business…
