Security researchers have shown that AI coding agents can be manipulated into installing attacker-controlled packages by following instructions found in…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Suspected Iran-Linked Cyberattack Knocks UK Power Plant Offline for Four Days
A cyber incident reportedly forced a small UK power generation facility offline for about four days in July 2026. While the activity has been linked in…
BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE Malware
Russian state-linked threat actor BlueDelta has launched a renewed espionage campaign against defense manufacturing, government, and diplomatic…
Unitree G1 Humanoid Robot Flaws Allow Unauthenticated Root RCE Over Bluetooth
Security researcher Boschko has revealed two vulnerabilities in Unitree’s G1 humanoid robot that can be exploited to achieve unauthenticated remote code…
Prompt Injection Attack Hijacks Claude Code Opus 5 Auto Mode to Execute Malicious Code
A recent demonstration of prompt-injection research has revealed that Claude Code Opus 5, when running in its default Auto Mode, can be manipulated to…
TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation
A newly emerged ransomware-as-a-service operation named TITAN is advertising an AI-driven extortion platform that it claims can autonomously classify…
Hundreds of WordPress Sites Hijacked to Show Fake reCAPTCHA and Steal Windows Passwords.
Hundreds of compromised WordPress websites are being used in a sophisticated malware-delivery campaign that combines browser persistence,…
Hackers Can Buy Corporate Executives’ Social Security Numbers for Just 25 Cents
Corporate executives’ Social Security numbers (SSNs) are being sold on dark web identity marketplaces for as little as $0.25 per record. This creates a…
Go Loader Uses Anti-Sandbox Checks and SNOWLIGHT to Execute Fileless VShell RAT in Memory
A Windows malware campaign disguised as a graduate-school resume has been observed delivering the SNOWLIGHT stager and a fileless VShell remote-access…
Leaked University Files Reveal How Russia Trains Hackers for Military Cyber Operations
A cache of leaked internal records has exposed what appears to be a structured Russian military cyber-operator pipeline embedded inside Bauman Moscow…
OpenAI Warns AI-Enabled Cyberattacks Will Surge, Calls for Global Cyber Defense
OpenAI has issued a warning that AI-enabled cyberattacks could become significantly more widespread and sophisticated within months. The organization…
PaperCut Warns of Actively Exploited Vulnerability Affecting NG and MF Servers
PaperCut has issued an urgent security advisory after confirming the active exploitation of a vulnerability affecting all versions of its PaperCut NG and…
Hackers Use Ethereum Smart Contracts to Keep New GoCaracal Malware Connected
Dark Caracal-linked operators are using Ethereum smart contracts as a resilient fallback mechanism for a newly identified Go-based malware framework…
Critical cPanel Vulnerability Allows Attackers to Gain Full Root Control of Servers
A critical vulnerability in cPanel/WHM could allow authenticated attackers to gain root-level code execution and take full control of vulnerable hosting…
Active Directory SPN Misconfigurations Enable Kerberoasting Without Account Lockouts
A common configuration error in Active Directory is assigning Service Principal Names (SPNs) to ordinary user accounts. This mistake can create an…
AWS Security Teams Can Correlate CloudTrail, VPC and Route 53 Logs to Detect Attacks
AWS security teams can improve detection of multi-stage intrusions by correlating API activity in CloudTrail with network metadata in VPC Flow Logs and…
Hackers Exploit CVE-2023-49105 to Steal Nuclear Records From Philippine Research Agency
Suspected Chinese-speaking operators exploited the critical ownCloud flaw CVE-2023-49105 to steal nuclear material records, research reactor data,…
Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power
AI infrastructure is rapidly becoming a high-value enterprise attack surface. Attackers targeting LiteLLM AI gateways, RAGFlow retrieval platforms, and…
CISA Warns of Actively Exploited Citrix NetScaler ADC and Gateway Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8452, a vulnerability affecting Citrix NetScaler ADC and NetScaler…
TP-Link Kasa Smart Home Flaw Lets Attackers Forge Control Messages and Take Control of Devices
TP-Link has revealed a critical vulnerability in Kasa smart home devices that could allow an attacker on the same local network to intercept, replay, or…
