Researchers have revealed a technique called “GhostCommit,” which involves prompt injection by hiding malicious instructions within images included in pull requests. This technique has the potential to bypass text-only AI code reviewers and later manipulate coding agents into exposing repository…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Cybersecurity Newsletter Weekly – The 40 Biggest Cybersecurity Stories – Accenture Breach, AI Attack, Exploits Releases, Data Breaches & More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 40 most important stories from July 6–10, 2026. This week the security world collided with AI head-on: prompt-injection attacks turned chatbots into C2…
AWS GovCloud Credential Leak Leads CISA to Share Critical Cyber Incident Lessons
The Cybersecurity and Infrastructure Security Agency (CISA) has disclosed details of an internal security incident involving exposed AWS GovCloud credentials, offering a transparent account of its own incident response to help other organizations strengthen their defenses. On Friday, May 15,…
Hackers Infect C++ and C# Project Files to Spread Multi-Stage Windows Backdoor
A sophisticated Windows Trojan that compromises software development projects to distribute a multi-stage backdoor, data stealer, clipboard hijacker, cryptominer, and file infector. Documented by Doctor Web researchers and first observed in the final quarter of 2025, the malware has continued…
Zimbra Releases Security Patch for Stored XSS Vulnerability in Classic Web Client
Zimbra has released its Daffodil v10.1.19 patch update, addressing a stored cross-site scripting (XSS) vulnerability in the platform’s Classic Web Client. The security issue could allow a specially crafted email message to execute malicious JavaScript within the context of a…
Dell BIOS Flaw Lets Attackers Extract Plaintext Passwords Without Brute Force
A newly disclosed Dell BIOS password-storage flaw can allow attackers with physical access to recover administrator and user passwords from SPI flash dumps in milliseconds. Tracked as CVE-2026-40639 and addressed in Dell Security Advisory DSA-2026-197, the issue affects certain Dell…
Top 10 Best Social Engineering Testing Companies in 2026
In the fast-evolving digital landscape of 2026, an organization’s most sophisticated technological defenses can be rendered useless by a single click from a well-intentioned but unsuspecting employee. Cybercriminals are increasingly bypassing firewalls and encryption by exploiting the most unpredictable and…
Top 10 Best Cloud Security Providers – 2026 Review
As businesses continue to migrate critical applications and data to the cloud, the traditional security perimeter has dissolved. The responsibility for securing these dynamic, distributed environments now falls on a complex shared responsibility model between cloud service providers (CSPs) and…
281 Android VPN Apps Expose Users to Traffic Leaks, Tracking and Tunnel Hijacking
A recent security analysis has revealed that a significant number of Android VPN applications, 281,281,281, expose users to serious privacy and security risks. These risks include traffic leaks, third-party tracking, weak encryption practices, and VPN tunnel hijacking. Android findings highlight…
Linux FUSE Vulnerability Allows Unprivileged Users to Pop a Root Shell
A newly disclosed Linux kernel vulnerability in the FUSE subsystem allows unprivileged local users to escalate privileges to root by corrupting the page cache and hijacking execution of a SUID binary such as /usr/bin/su on Ubuntu 26.04. Tracked as CVE-2026-31694,…
Hackers Exploit CitrixBleed 2 to Hijack MFA-Protected Sessions and Deploy DragonForce Ransomware
Threat actors are exploiting the CitrixBleed 2 vulnerability, tracked as CVE-2025-5777, to hijack active NetScaler sessions protected by multi-factor authentication and gain a foothold in enterprise environments. The activity indicates a standardized operator playbook, potentially operated by an initial access…
Forg365 PhaaS Uses Telegram and AI Lures to Hijack Microsoft 365 Accounts
Forg365 is a commercial phishing-as-a-service (PhaaS) platform specifically targeting Microsoft 365 users. It employs methods such as device-code phishing, adversary-in-the-middle (AiTM) workflows, AI-assisted lure generation, and token persistence tools. The platform’s onboarding process through Telegram, subscription model, and post-compromise features…
GNU Guix Vulnerabilities Let Attackers Overwrite Arbitrary Files and Escalate Privileges
Security researcher Caleb Ristvedt disclosed the issues on July 222, 202620262026, warning that all GNU Guix installations are affected. Systems running guix-daemon as root face the highest risk because a malicious substitute server or a man-in-the-middle attacker could write files…
NetScaler MCP Gateway Secures LLM and Agentic AI Traffic From a Single Platform
Citrix, a Cloud Software Group company, announced major updates to its NetScaler® platform on July 9, 2026, introducing MCP Gateway functionality designed to secure and govern the explosive growth of AI agent traffic across enterprise environments. The new capability allows…
New Multi-Stage LNK Attack Targets Hospitality Firms With Node.js Backdoor
Hospitality firms are being targeted in an active phishing campaign that uses fake booking-related emails to deliver a multi-stage Node.js backdoor. The attack chain abuses Google Share links, malicious ZIP archives, Windows shortcut files, PowerShell, and the TON blockchain to…
Wireshark 4.6.7 Released to Patch 12 Vulnerabilities in SSH, TLS, Wi-Fi and pcapng
Wireshark has released version 4.6.74.6.74.6.7, addressing 121212 security flaws across protocol dissectors, capture-file parsers, and its external capture interface. The update resolves issues affecting SSH, TLS Encrypted Client Hello (ECH), IEEE 802.11802.11802.11 Wi-Fi traffic, and pcapng capture files, among other…
Process Parameter Poisoning Technique Hides Shellcode Inside Windows Startup Data
A newly documented Windows injection approach, dubbed Process Parameter Poisoning or P³, uses process startup parameters as an unconventional staging area for shellcode. Implemented in the P³-Shellcode Loader proof of concept, the technique can reduce exposure to telemetry that endpoint…
Odyssey Stealer Attacks Macs Worldwide and Replaces Crypto Wallet Apps With Drainers
Odyssey Stealer is driving a large-scale macOS infostealer campaign that now spans more than 100 countries, with operators systematically hijacking cryptocurrency ecosystems by replacing legitimate wallet apps with drainer trojans. The operation blends advanced social engineering, AppleScript-based stealth, and persistent…
Fake Robinhood Sign-In Alerts Trick Users Into Calling Hacker-Controlled Phone Numbers
A sophisticated callback phishing campaign impersonating Robinhood is coercing victims into dialing attacker-controlled phone numbers by exploiting fear of account compromise. The campaign begins with an unsolicited email or SMS posing as a Robinhood security alert, warning recipients of “unusual…
Hackers Compromise AWS AI Gateway Connected to Amazon Bedrock to Deploy XMRig Cryptominer
A compromise of an AI gateway linked to Amazon Bedrock, highlighting how generative AI infrastructure has become a new target within the enterprise attack landscape. The incident was disclosed on July 9, 2026, and reveals attackers exploiting a LiteLLM-Proxy EC2…