D-Link has disclosed and patched 15 Common Vulnerabilities and Exposures (CVEs) affecting its DWR-M961 4G/LTE router, specifically hardware revision C1.…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Critical Apache HttpComponents Client Flaw Lets Attackers Impersonate Servers
A critical vulnerability in the Apache HttpComponents Client can allow man-in-the-middle attackers to impersonate trusted servers when applications use…
RAVEN Tool Steals Entire Elasticsearch Databases and Rebuilds Deleted Backdoors
The RAVEN offensive framework can turn compromised Elasticsearch and Kibana environments into durable data-theft and persistence operations. RAVEN, short…
CISA Warns Hackers Are Actively Exploiting VMware vCenter Path Traversal Flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Broadcom VMware vCenter to its Known…
Fake Claude Install Guide Steals Mac Passwords and Turns Trusted Crypto Wallet Apps Into Phishing Traps
A Google-sponsored search result for Claude installation instructions is being used to deliver a sophisticated macOS stealer and remote-access trojan…
Medusa Ransomware Attacks 300+ Critical Infrastructure Organizations Using Double Extortion
Medusa ransomware operators have compromised over 500 organizations across critical infrastructure sectors, according to a joint advisory issued by the…
Cl0p Hackers Exploit PTC Windchill Vulnerability to Deploy Custom Web Shell and Steal Data
The Cl0p ransomware and extortion operation is likely exploiting a critical PTC Windchill vulnerability to deploy a purpose-built Java web shell that can…
Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix
A large-scale malware operation called StopAndProtect is exploiting thousands of compromised WordPress websites to distribute ransomware, steal files,…
Critical Microsoft Copilot CoSnitch Flaw Lets Hackers Steal Sensitive Data With One Click
A critical one-click vulnerability in Microsoft Copilot Personal, tracked as CVE-2026-24301 and dubbed CoSnitch. This flaw could enable an attacker to…
Projextor Abuses Cross-Platform Electron Framework to Conceal Malware Activity
Threat actors behind the Projextor campaign are abusing Electron-based productivity applications to conceal malware-like capabilities behind fully…
Critical MLflow SSRF Flaw Exploited in the Wild
A critical unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, tracked as CVE-2026-64849, is being actively exploited within hours…
OpenAI Warns Organizations to Automate Cybersecurity as AI-Powered Attacks Accelerate
OpenAI has issued a warning that organizations need to quickly automate core cybersecurity functions as increasingly advanced AI systems make it easier…
BTMob Uses Custom Phishing Apps to Turn Android Users Into Remote-Controlled Fraud Victims
BTMOB has evolved beyond a conventional Android banking trojan into a turnkey fraud platform that lets criminals build branded phishing apps, remotely…
French Tax Authority Cyberattack Exposes Tax Data of 678,000 Individuals and Businesses
France’s Directorate General of Public Finances (DGFiP) has reported a cyberattack that resulted in unauthorized access to and extraction of tax and…
Asruex Trojan Found Embedded in GEEKOM Mini PC Realtek Ethernet Driver
GEEKOM has confirmed that a malware-flagged Realtek LAN driver package was previously accessible through an outdated support page for its mini PCs,…
Apple Addresses 28 Security Flaws Across macOS, iOS, and iPadOS
Apple has released security updates for iPhones, iPads, and Macs to address 28 vulnerabilities across its latest operating systems. These updates, issued…
JWR Phishing-as-a-Service Kit Uses WebSockets and AES to Run Real-Time Banking Fraud
JWR, an undocumented phishing-as-a-service (PhaaS) framework that turns conventional credential theft into an operator-led, real-time banking and payment…
AI Agents Gain Unintended Internet Access During Cybersecurity Evaluations
AI security evaluation firm has disclosed that several frontier AI models unintentionally accessed and acted against real internet-connected systems…
CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.…
Kimsuky Uses Local AI Development Environment to Expand Cyber Espionage Tooling in Operation GitPower
North Korean state-backed threat actor Kimsuky is extending its established espionage playbook with locally hosted artificial intelligence tooling,…
