Adobe has released security updates for Adobe Commerce, Adobe Commerce B2B, and Magento Open Source to address multiple critical vulnerabilities. One of…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
WhatsApp Introduces On-Device Scam Alert to Detect Fraud Messages
WhatsApp has initiated a limited beta rollout of a feature called Scam Alert, which utilises an on-device machine learning model to identify potentially…
Adobe ColdFusion Critical Vulnerabilities Enable Arbitrary Code Execution
Adobe has released critical security updates for ColdFusion 2025 and ColdFusion 2023, addressing 17 vulnerabilities that could enable arbitrary code…
Akira Ransomware Reboots Windows Into Safe Mode to Disable EDR and Microsoft Defender
An Akira ransomware affiliate has been observed rebooting a compromised Windows host into Safe Mode with Networking to disable endpoint protection an…
Gunra Ransomware Uses Up to 100 ChaCha20 Threads to Rapidly Encrypt Linux Systems
Gunra ransomware has added a Linux encryptor to its arsenal, giving affiliates control over how they lock enterprise data. The command-line payload can…
Kimwolf v7 Removes Exploitation Code and Leaves Infection to External Loaders
A newly identified Kimwolf v7 build shows the Android and IoT botnet shifting from an all-in-one compromise toolkit into a more specialized DDoS and…
China-Linked Hackers Use Autonomous AI Agents to Breach Taiwan Government Systems
A China-linked threat actor has reportedly utilized a multi-agent artificial intelligence framework to conduct a nearly autonomous intrusion campaign…
Phantom Stealer Uses PNG Steganography and PowerShell Injection to Steal Credentials
Phantom Stealer is a .NET-based credential-harvesting malware that combines PNG-backed payload concealment, PowerShell-driven process injection, and…
Palo Alto GlobalProtect Vulnerabilities Enable SYSTEM and Root-Level Access
Palo Alto Networks has released security advisories for multiple vulnerabilities in the GlobalProtect App that could allow a local attacker to elevate…
City-Forum Hackers Target Salesforce and ServiceNow Instances Worldwide for Data Theft
A sophisticated threat campaign, referred to as “City-Forum,” is targeting publicly accessible Salesforce Experience Cloud sites and ServiceNow Service…
WordPress RCE Vulnerability Lets Authenticated Authors Execute Remote Code
WordPress has released version 7.0.4 to address a high-impact authenticated remote code execution (RCE) vulnerability. This flaw could allow users with…
ShieldBreak Windows Defender 0-Day Lets Attackers Bypass Microsoft Patch and Gain SYSTEM Privileges
Security researcher Nightmare-Eclipse, also known as Chaotic Eclipse, has released a new Windows privilege escalation exploit named ShieldBreak. This…
CISA Warns Critical Metabase SQL Injection Flaw Lets Unauthenticated Attackers Gain Admin Access
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical SQL injection vulnerability in Metabase, adding it to its Known…
Hackers Exploit Critical VMware vCenter Flaw to Deploy Reverse SSH Across 47 Countries
Threat researchers have identified an active campaign exploiting the critical VMware vCenter vulnerability CVE-2026-59310, with 361 victim IP addresses…
Fake VPN Extensions Put Operators in Adversary-in-the-Middle Position Over Chrome Traffic
A Chrome Web Store operation that turns “free VPN” extensions into browser-wide traffic relays controlled by a single proxy provider. The campaign…
Google Chrome Blocks Abusive Notifications Used to Deliver Malware and Scams
Google Chrome has implemented enhanced defenses aimed at disrupting abusive web push notifications that are often used to distribute malware, phishing…
Dark Web Corporate Access Prices Surge 4,055% as Stolen Credentials Flood Cybercrime Markets
Corporate network access is becoming both cheaper to obtain at scale and vastly more valuable at the top end of the criminal market. That contradiction…
Google Chrome 151 Update Fixes 5 High-Severity Use-After-Free Vulnerabilities
Google has released Chrome version 151.0.7922.137/138 for Windows and macOS, and version 151.0.7922.137 for Linux. This update addresses five…
Microsoft SharePoint RCE Vulnerability Lets Remote Attackers Execute Code
A newly disclosed vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-63520, could allow attackers to execute arbitrary code remotely on…
Malicious CCleaner Installer Patches Chrome Security Extension to Deploy Browser Spyware
A counterfeit installer for the widely used PC-cleaning utility CCleaner is being used to compromise Windows systems and deploy a malicious Chrome…