DarkSword’s leaked iOS exploit chain is now powering a fast‑moving server cluster that marries one‑click Safari exploitation with a convincing fake Apple…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Fake Xeno Roblox Cheats Deliver Java RAT That Steals Discord and Gaming Accounts
Fake Roblox cheat tools are once again being weaponized, with a newly observed campaign distributing a sophisticated Java-based remote access trojan (RAT)…
OWASP Introduces Subtractive Security Top 10 to Eliminate Attack Paths and Reduce Cyber Risk
OWASP has launched the Subtractive Security Top 10 project, a security engineering initiative that shifts the focus from adding more detection controls to…
OpenAI Shuts Down ChatGPT Accounts Powering a Cambodia-Based Scam Factory
OpenAI has shut down a coordinated network of ChatGPT accounts that powered a Cambodia-based scam factory running multi-vector fraud and…
Shai-Hulud Supply Chain Attack Compromises Keyv and Hundreds of npm Packages
Attackers have compromised the GitHub account of a Keyv maintainer, a widely used JavaScript key-value storage library, to distribute credential-stealing…
CISA Adds Exploited N-able N-central Flaw Enabling Remote Admin Takeover to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-18577, an actively exploited authentication bypass vulnerability in…
Russian Access Broker Sells Network Access to Ransomware Gangs While Spying on Ukraine
An exposed server linked to a Russian‑speaking initial access broker (IAB) has revealed a sprawling operation that simultaneously fuels ransomware…
China Is Training Military AI With Knowledge Extracted From American Models
China’s artificial intelligence ecosystem is rapidly advancing through a controversial technique known as model distillation, with mounting evidence…
18 Malicious npm Packages Deploy Cross-Platform RAT Against Alibaba Developers
18 malicious npm packages have been used in a tightly coordinated software supply chain attack to deliver a cross‑platform RAT that specifically targets…
Critical Gitea Flaw Lets Unauthenticated Attackers Read Server Files and Execute Code
A critical vulnerability in Gitea has been identified, potentially allowing unauthenticated remote attackers to read arbitrary files on vulnerable servers…
macOS CUPS Flaw Lets Local Attackers Write Arbitrary Files as Root
A recently disclosed privilege-related vulnerability in the Common UNIX Printing System (CUPS) on macOS could allow an unprivileged local user to create…
Critical Adobe Campaign Flaws Let Unauthenticated Attackers Execute Arbitrary Code
Adobe has released an urgent security update for Adobe Campaign Classic, addressing multiple critical vulnerabilities that could allow remote attackers to…
Fake AI Tools Target Developers With Infostealers to Steal Credentials and Cloud Secrets
A large-scale malware campaign targeting developers and AI users has been uncovered ,revealing how attackers are weaponizing fake AI tools and cloned…
OctLurk-Linked Hackers Deploy BINDCLOAK Backdoor Against Middle East Governments
The published Part 2 of a two-part technical analysis exposing BINDCLOAK, a previously undocumented modular backdoor deployed against government entities…
Apache NiFi Flaw Enable Security Bypass and Memory Corruption
Apache NiFi has issued security advisories for four vulnerabilities affecting its web API. These include an authorization bypass that could allow…
Critical Check Point Flaw Lets Unauthenticated Attackers Execute Commands on Management Servers
Check Point has disclosed a high-severity authentication bypass vulnerability that could allow unauthenticated attackers to execute arbitrary commands on…
cPanel Database Privilege Escalation Flaw Enables Full Administrative Access
CVE-2026-58048 is a critical privilege-escalation vulnerability in the database management functionality of cPanel & WHM. This flaw allows an…
ChocoShell Steals Microsoft 365 Tokens and Browser Sessions From Travelers
ChocoShell is a PowerShell-based infostealer used in Microsoft’s newly disclosed “CaptiveCrunch” campaign to steal Microsoft 365 tokens, browser sessions,…
NullReceiver Is Harder to Discover but Still Exposes a Reusable Attacker Wallet
NullReceiver is a lean, stealth-focused evolution of DPRK’s blockchain C2 tradecraft that hides a reusable attacker wallet behind ordinary-looking…
Apple Removes Telegram From App Store Worldwide
Telegram Messenger was temporarily removed from Apple’s App Store in several countries late Monday, preventing new users from downloading the messaging…
