A newly identified Kimwolf v7 build shows the Android and IoT botnet shifting from an all-in-one compromise toolkit into a more specialized DDoS and…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
China-Linked Hackers Use Autonomous AI Agents to Breach Taiwan Government Systems
A China-linked threat actor has reportedly utilized a multi-agent artificial intelligence framework to conduct a nearly autonomous intrusion campaign…
Phantom Stealer Uses PNG Steganography and PowerShell Injection to Steal Credentials
Phantom Stealer is a .NET-based credential-harvesting malware that combines PNG-backed payload concealment, PowerShell-driven process injection, and…
Palo Alto GlobalProtect Vulnerabilities Enable SYSTEM and Root-Level Access
Palo Alto Networks has released security advisories for multiple vulnerabilities in the GlobalProtect App that could allow a local attacker to elevate…
City-Forum Hackers Target Salesforce and ServiceNow Instances Worldwide for Data Theft
A sophisticated threat campaign, referred to as “City-Forum,” is targeting publicly accessible Salesforce Experience Cloud sites and ServiceNow Service…
WordPress RCE Vulnerability Lets Authenticated Authors Execute Remote Code
WordPress has released version 7.0.4 to address a high-impact authenticated remote code execution (RCE) vulnerability. This flaw could allow users with…
ShieldBreak Windows Defender 0-Day Lets Attackers Bypass Microsoft Patch and Gain SYSTEM Privileges
Security researcher Nightmare-Eclipse, also known as Chaotic Eclipse, has released a new Windows privilege escalation exploit named ShieldBreak. This…
CISA Warns Critical Metabase SQL Injection Flaw Lets Unauthenticated Attackers Gain Admin Access
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical SQL injection vulnerability in Metabase, adding it to its Known…
Hackers Exploit Critical VMware vCenter Flaw to Deploy Reverse SSH Across 47 Countries
Threat researchers have identified an active campaign exploiting the critical VMware vCenter vulnerability CVE-2026-59310, with 361 victim IP addresses…
Fake VPN Extensions Put Operators in Adversary-in-the-Middle Position Over Chrome Traffic
A Chrome Web Store operation that turns “free VPN” extensions into browser-wide traffic relays controlled by a single proxy provider. The campaign…
Google Chrome Blocks Abusive Notifications Used to Deliver Malware and Scams
Google Chrome has implemented enhanced defenses aimed at disrupting abusive web push notifications that are often used to distribute malware, phishing…
Dark Web Corporate Access Prices Surge 4,055% as Stolen Credentials Flood Cybercrime Markets
Corporate network access is becoming both cheaper to obtain at scale and vastly more valuable at the top end of the criminal market. That contradiction…
Google Chrome 151 Update Fixes 5 High-Severity Use-After-Free Vulnerabilities
Google has released Chrome version 151.0.7922.137/138 for Windows and macOS, and version 151.0.7922.137 for Linux. This update addresses five…
Microsoft SharePoint RCE Vulnerability Lets Remote Attackers Execute Code
A newly disclosed vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-63520, could allow attackers to execute arbitrary code remotely on…
Malicious CCleaner Installer Patches Chrome Security Extension to Deploy Browser Spyware
A counterfeit installer for the widely used PC-cleaning utility CCleaner is being used to compromise Windows systems and deploy a malicious Chrome…
WindRelay Turns Android Phones Into Fake Payment Terminals for Remote Card Fraud
A newly identified Android malware family, tracked as WindRelay, is being used alongside the SpyNote remote-access trojan to convert victims’ phones into…
Microsoft Outlook RCE Vulnerability Lets Attackers Execute Code Remotely
Microsoft has disclosed a new remote code execution (RCE) vulnerability in Outlook, tracked as CVE-2026-70329. They warn that successful exploitation…
The Best Network Traffic Analysis (NTA) Tools, Compared and Priced (2026)
Network traffic analysis spans two buying worlds — ops tools with published price lists and security platforms with quote-only enterprise pricing — and…
Project CAV3RN Uses Google Apps Script and DNS to Hide C2 Traffic in Israeli Cyberespionage Attacks
Project CAV3RN, a modular cyberespionage framework targeting organizations in Israel, has added a sophisticated command-and-control design that…
Windows AFD.sys Zero-Day Exploited by Lazarus Hackers to Gain SYSTEM Access
Lazarus has expanded its long-running Operation Dream Job campaign by exploiting a Windows zero-day vulnerability that grants attackers SYSTEM-level…
