Mathspace, an online mathematics learning platform used by schools in Australia and New Zealand, has reported a data breach affecting 1,079,819 students,…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Switzerland Builds Open-Source Workplace Platform to Operate Alongside Microsoft 365
Switzerland’s Federal Chancellery is advancing a sovereign digital workplace initiative following a feasibility study that demonstrated how open-source…
Known npm Worm Returns After 111 Days and Security Scanning Still Let It Through
A known Shai-Hulud npm worm payload has resurfaced after 111 days of inactivity, raising fresh questions about the effectiveness of registry-level malware…
New InjectEave Attack Lets Hackers Eavesdrop on Headphone Audio From 30 Meters Away
Security researchers have unveiled InjectEave, an electromagnetic side-channel attack that can turn ordinary headphones into unintended transmitters. By…
PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells
A sophisticated Linux implant linked to compromised F5 BIG-IP Access Policy Management (APM) environments. The activity has been associated with…
ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions
ConnectWise has announced a security issue affecting file transfer functionality in ScreenConnect Remote Access Support and Access sessions. This issue…
Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data
Natural Resources Wales (NRW) has reported a personal data breach involving sensitive diversity-monitoring information from both former and current…
OpenAI Commits $1 Billion in Daybreak AI Cyber Tools to Protect Critical Infrastructure
OpenAI has announced a $1 billion global commitment to expanding access to its Daybreak AI cybersecurity platform for frontline defenders who protect…
Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials
A large-scale phishing operation is abusing trusted Google services as a multi-stage redirect network to bypass email security controls, deliver highly…
Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks
A newly analyzed Linux malware sample, dubbed Tengu, combines Mirai-style botnet tradecraft with broad persistence, DDoS, SSH probing, and proxy…
The 12 Best Software-Defined Perimeter (SDP) Solutions, Compared and Priced
Best value overall: Cloudflare. Published per-user pricing, a free tier you can genuinely deploy on, and a global edge network behind it. Best for small…
The 12 Best Wireless / Wi-Fi Security Solutions, Compared and Priced
Best value overall: Ubiquiti. Published hardware pricing, no mandatory licensing, and WPA3 with VLAN segmentation included for organizations whose…
The 12 Best Secure Web Gateway (SWG) Solutions, Compared and Priced
Best value overall: Cloudflare. It publishes per-user pricing, offers a free tier that lets you test the model properly, and delivers from one of the…
The 12 Best Network Sandboxing Solutions, Compared and Priced
Best value overall: ANY.RUN. It publishes its pricing, offers a free community tier that analysts genuinely use daily, and its interactive model lets you…
Roundcube Fixes 12 Security Flaws Including Zero-Click XSS and SSRF Bypass
Roundcube has released security updates 1.6.19 and 1.7.4, which address 12 vulnerabilities affecting its 1.6 LTS and 1.7 Webmail branches. The flaws…
BYOTC Attack Abuses Trusted Windows Clients to Access Privileged Kernel Driver Operations
A newly documented Windows attack pattern, dubbed Bring Your Own Trusted Caller (BYOTC), shows how attackers can bypass driver-level authorization…
The Best 12 Business VPN Solutions, Compared and Priced
Best value overall: Tailscale. It publishes its pricing, has a genuinely usable free tier for small teams, and its per-service access model is more secure…
Telerik UI Flaws Let Attackers Chain AES-CBC Padding Oracle to Unauthenticated RCE
Security researchers have identified a critical vulnerability chain in Progress Telerik UI for ASP.NET AJAX, which allows unauthenticated attackers to…
Kimsuky Uses OpenCode AI Agent and GitHub PATs in Operation GitPower Attacks
North Korea-linked threat actor Kimsuky has expanded its Operation GitPower activity with malicious LNK shortcuts, GitHub Personal Access Token…
Critical N-able N-central Flaw Enables Pre-Auth Remote Code Execution
N-able has released a security update to address CVE-2026-86218, a critical-severity vulnerability in its N-central remote monitoring and management…
