Threat actors have repurposed an AI prompt-injection technique known as ASCII smuggling to evade email security controls at massive scale, hiding…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Chinese-Speaking Hackers Use Claude, Qwen and DeepSeek AI Agents to Attack Government Systems
Chinese-speaking threat operators have been observed using Claude, Qwen and DeepSeek-powered AI agents as operational components in a second intrusion…
TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft
TP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on…
Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials
A Microsoft 365 email security-control bypass that lets attackers submit unauthenticated messages posing as internal users by leaving one SMTP field…
Google Chrome V8 Flaw Actively Exploited in the Wild, Update Released
Google has released an urgent update for Chrome Stable to address CVE-2026-85046, a high-severity type confusion vulnerability in the V8 JavaScript and…
CrowdStrike Falcon Zero-Day Lets Attackers Escalate Privileges on Windows Systems
A recently released proof-of-concept, named FalconFlank, claims to reveal a local privilege escalation vulnerability in the CrowdStrike Falcon Sensor on…
Contagious Interview Operators Move Beyond Git Hooks With Trojanized Mac Applications
North Korea-linked Contagious Interview operators have expanded their developer-targeting malware delivery operation beyond booby-trapped Git hooks and…
Hackers Compromise More Than 14,500 Dahua Security Cameras in Massive Campaign
A large-scale campaign dubbed Operation CameraSwarm compromised at least 14,530 Dahua IP cameras and related surveillance devices in just 35 days.…
LLMjacking Attack Abuses Leaked AWS Credentials to Hijack Amazon Bedrock AI Models
Threat actors are increasingly converting stolen cloud credentials into access to costly generative AI services, a technique known as LLMjacking.…
Fewer attacks, more force: Link11’s European Cyber Report finds new DDoS records for the first half of 2026
Frankfurt am Main, Germany, September 3rd, 2026, CyberNewswire Super-botnets and hijacked cloud servers drive new bandwidth and packet-rate records as…
Fake Acquisition Scam Uses Forged NDAs to Demand €626,000 Corporate Payment.
Threat actors impersonated Gen executives and major consulting firms in a targeted business email compromise-style operation that used forged…
Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems
A malicious ScreenConnect campaign in which rogue remote-access clients do more than provide attackers with hands-on control: modified clients can…
QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes
QR code phishing, widely known as “quishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images…
New $7 SweepLED Gadget Detects Hidden Cameras With 94% Accuracy in 5 Seconds
Researchers have developed SweepLED, a smartphone-based hidden-camera detection system that uses a low-cost LED accessory and computer vision to identify…
Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks
Microsoft will start automatically enabling Memory Integrity protection on eligible Windows devices through quality updates beginning in October 2026.…
HTML-Rendered QR Phishing Evades Image Extraction and OCR-Based Email Scanning
QR-code phishing, commonly known as quishing, is evolving beyond image-based payloads. Threat actors are now rendering scannable QR codes directly from…
Avast Antivirus Zero-Day PoC Lets Attackers Dump SAM Database and Gain SYSTEM Shell
A public proof-of-concept (PoC) repository has revealed a local privilege escalation zero-day vulnerability in GenDigital’s Avast Antivirus. This…
WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover
A high-severity vulnerability affecting over 5 million active WordPress installations could allow unauthenticated attackers to exploit stored SQL…
Sangoma Switchvox RCE Flaw Actively Exploited in Wild via Unauthenticated SQL Injection
Security researchers have reported active exploitation attempts targeting a critical vulnerability in Sangoma Switchvox, allowing unauthenticated…
StreamRAT Abuses Android Accessibility, MediaProjection and HVNC for Full Device Takeover
StreamRAT, a newly identified Android banking trojan distributed through fake free-TV streaming advertisements on Meta and TikTok. The campaign, tracked…
