Threat actors are increasingly abusing Microsoft 365 identity sessions rather than deploying malware, as shown in a cloud-only business email compromise…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
CyberPanel Pre-Auth RCE Flaws Let Attackers Gain Remote Server Access
Researchers have revealed a pre-authentication remote code execution (RCE) vulnerability chain in CyberPanel that could allow an internet-based attacker…
Hackers Trick AI Agents Into Telling Users to Install the Malware Themselves
A supply-chain campaign targeting OpenClaw has shown how threat actors can turn autonomous AI agents into persuasive malware-delivery intermediaries.…
Claude AI Finds Authentication Bypass Flaws in Multiple SAML Implementations
Multiple critical vulnerabilities in SAML implementations after employing Anthropic’s Claude Code in an AI-assisted vulnerability research pipeline.…
Zimbra RCE Vulnerability Lets Remote Attackers Execute System Commands
An urgent alert regarding an actively exploited remote code execution vulnerability affecting the Zimbra Collaboration Suite, a widely used enterprise…
ClearFake Fake CAPTCHA Campaigns Use New WordlistLoader to Deploy Amatera Stealer
A new ClearFake infection chain using a previously undocumented intermediate payload dubbed WordlistLoader to deploy Amatera Stealer. The campaign…
Hackers Impersonate Claude, ChatGPT and Copilot to Deliver Infostealers and Backdoors
Threat actors are increasingly abusing the popularity of generative AI brands to distribute malware, turning trusted names such as Claude, ChatGPT and…
Microsoft Defender Update Crashes Virus Scans on Windows PCs
Microsoft Defender has been aborting Quick, Full, and Offline virus scans on Windows systems following a series of Security Intelligence updates released…
13 Malicious Rabby Firefox Extensions Steal Wallet Keyrings Before They Are Encrypted
A broad Firefox add-on campaign that includes 13 malicious Rabby Wallet impersonators engineered to exfiltrate wallet keyring data before the application…
Critical Citrix NetScaler Flaw Allows Attackers to Bypass Authentication
Cloud Software Group has issued a critical security bulletin regarding two vulnerabilities that affect customer-managed NetScaler ADC and NetScaler…
T-Mobile Physically Cuts Network Cable to Evict Chinese Salt Typhoon Hackers
In 2024, T-Mobile’s security team took an unusually direct approach to contain a cybersecurity threat: they physically cut a network cable to terminate…
Aeternum Operators Use Polygon Smart Contracts to Rotate Malware C2 Domains Dynamically
Aeternum operators are abusing Polygon smart contracts as a decentralized dead-drop resolver, allowing malware to retrieve and rotate command-and-control…
Critical Snowflake GitHub Actions Flaw Allows Attackers to Steal Internal Jira Credentials
A significant GitHub Actions injection vulnerability in Snowflake’s public snowflake-connector-net repository. This flaw could have allowed…
CISA, NSA and FBI Warn Hackers Using AI-Generated Scripts to Target Siemens S7 PLCs
U.S. cybersecurity agencies have issued an urgent warning about an active campaign targeting Siemens S7 series programmable logic controllers (PLCs).…
Former Ping Identity and CyberArk Executives Join AppViewX to Scale Machine and Agent Identity Security
New York, New York, August 19th, 2026, CyberNewswire New revenue leader and board member join as AppViewX’s identity security business continues its rapid…
China-Nexus Hackers Target Myanmar Diplomats With QUICAgent Go Backdoor via Malicious VHD Files
A China-nexus threat actor is targeting Myanmar government and diplomatic personnel with a multi-stage malware campaign that delivers a custom Go-based…
CISA Warns Microsoft Internet Key Exchange RCE Flaw Is Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Microsoft Internet Key Exchange (IKE) Service…
Google Mandiant AI Agents Find Over 100 Critical Vulnerabilities in Source Code Within Two Days
Google’s Threat Intelligence Group has announced that its Agentic Vulnerability Discovery Harness (AVDH) identified over 100 critical true-positive…
Balonx PhaaS Steals Bank OTPs in Real Time While AI Calls and Android RAT Target Victims
Mexico’s banking sector is facing a more industrialized fraud threat as the Balonx Sistema phishing-as-a-service (PhaaS) operation combines real-time OTP…
Windows 11 24H2 Home and Pro Support Ends in October 2026
Microsoft has issued a 60-day reminder that the Windows 11 version 24H2 Home and Pro editions will reach the end of updates on October 13, 2026. This date…
