A covert Monero (XMR) cryptomining campaign uncovered in May 2026 is abusing Linux Pluggable Authentication Modules (PAM) to evade detection, maintain…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Top 10 Best Tools for Simulated DDoS Attacks in 2026
You don’t know your DDoS defenses work until you attack them yourself — safely, on purpose, with a kill switch. Simulated DDoS attack tools generate…
New GenieLocker Ransomware Encrypts Windows, Linux and VMware ESXi Systems
GenieLocker is a custom ransomware family linked to the Toy Ghouls group (also known as Bearlyfy or Labubu). It can encrypt systems running Windows,…
Hackers Exploit Nearly 1 in 4 Vulnerabilities Before or on Disclosure Day
Hackers are increasingly exploiting vulnerabilities at an unprecedented speed, with nearly one in four flaws being abused before or on the same day they…
Home Assistant FFmpeg Flaw Lets Attackers Steal Supervisor Tokens and Execute Code as Root
Home Assistant’s FFmpeg integration recently came under scrutiny after researchers demonstrated that unsafe argument handling in the Wyoming Assist…
Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy Chaos Ransomware
Hackers are abusing Microsoft Teams voice calls and fake IT helpdesk personas to gain remote access to corporate endpoints, drop a custom…
Work Panel Vishing Platform Automates Enterprise Account Takeovers and MFA Theft
Work Panel is a turnkey vishing and phishing platform that industrializes enterprise account takeovers and MFA theft by packaging infrastructure…
Copybara Abuses Android Accessibility for Keylogging, Screen Streaming and Remote Control
Copybara is being weaponized in a new N26-themed fraud campaign in Italy that chains vishing, a real‑time phishing control kit, and a multi‑stage Android…
Node.js Patches 11 Security Flaws Enabling Memory Exhaustion, File Access and Request Smuggling
The Node.js Project has released security updates for the active Node.js versions 22.x, 24.x, and 26.x, addressing 11 vulnerabilities. These…
North Korean Hackers Compromise Popular npm Packages to Target Developer Environments
North Korea–linked operators have quietly turned popular npm packages into a high‑volume access vector for developer and build environments, chaining…
Google Chrome 151 Fixes 370 Security Flaws, Including 7 Critical Bugs
Google has released stable Chrome version 151 updates for Windows, macOS, and Linux, addressing 370 security vulnerabilities. This update includes fixes…
GitLab Patches 13 Security Flaws Enabling Data Exposure, CI/CD Tampering and DoS Attacks
GitLab has released security updates for both the Community Edition (CE) and Enterprise Edition (EE), addressing 13 vulnerabilities that could allow…
TA488 Exploits Outlook Half-Click Flaw to Deploy Persistent OWAReaper Backdoor
TA488 has resurfaced with a high‑end half‑click campaign against on‑premises Outlook Web Access (OWA), exploiting CVE‑2026‑42897 to deploy a persistent…
Claude Global Outage Hits Users With “529 Overloaded” Error Messages
Users of Claude experienced service disruptions on Wednesday when Anthropic reported elevated error rates across all Claude models. This incident affected…
Microsoft Word Copilot Flaw Lets Hidden Prompts Spread Self-Propagating AI Worms Across Documents
Security researcher Håkon Måløy has disclosed a cross-domain prompt injection vulnerability affecting Microsoft Copilot for Word. This vulnerability could…
Hackers Can Compromise Tor Browser Users by Exploiting Firefox JIT Flaw
Tor Browser users on unpatched versions may be at risk of compromise simply by visiting a malicious webpage, following the disclosure of CVE-2026-10702, a…
Critical Rails Flaw Lets Unauthenticated Attackers Read Server Files and Execute Code
A critical vulnerability in Ruby on Rails’ Active Storage component could allow unauthenticated attackers to read arbitrary files on vulnerable…
Top 10 Best Security Configuration Assessment Tools in 2026
In the complex and ever-expanding digital landscape of 2026, a strong cybersecurity posture depends not only on identifying vulnerabilities in software…
Critical VMware vCenter Flaws Let Remote Attackers Bypass Authentication and Execute Code
Broadcom has released important security updates addressing critical vulnerabilities in VMware that could allow remote attackers to bypass vCenter…
Critical Ruflo MCP Bridge Flaw Allows Full AI Agent Platform Takeover
A critical vulnerability in the open-source AI orchestration platform Ruflo has been disclosed, allowing unauthenticated attackers to achieve full remote…