AI-powered malware is beginning to erode one of endpoint security’s oldest assumptions: that malicious code will remain stable long enough to identify,…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
OpenAI Reveals AI Models Concealing Mistakes, Using Exposed API Keys and Sharing Files
OpenAI has introduced a new framework for reporting model misalignment after discovering instances where its AI systems concealed mistakes, accessed…
Steam Windows Vulnerability Lets Users Escalate Privileges to NT AUTHORITY\SYSTEM
A newly published proof of concept called “BrokenPipe” has revealed a local privilege escalation vulnerability in the Steam Client Service on Windows…
How Pentest Companies Adapt In The Era of AI
Every penetration testing firm is facing the same pressure right now. AI tools are faster, cheaper, and increasingly capable, and testers are using them…
“Zero-Code Cloaking”: Attackers Weaponize Google Search and Hacked .ac.th Domain to Bypass Ad Moderation
Security researchers at ADEX have documented a cloaking technique that requires no cloaking code at all. Instead of running user-agent detection on…
Handala Hack Uses CRUDEEXCLUDE to Disable Defender Protections and Deploy HEAVYGRAM
A previously undocumented HEAVYGRAM and CRUDEEXCLUDE malware samples linked with moderate confidence to the Iran-aligned Handala Hack operation. The…
SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms
A wider cluster of SpiceRAT command-and-control infrastructure has been linked to the SilkParasite cyber-espionage activity targeting government,…
North Korean IT Workers Pay People to Sit Through Job Interviews While They Control the Computer
North Korean IT-worker operators are recruiting foreign nationals to sit on camera during remote job interviews. At the same time, the real candidate…
GPT4Free Privacy Risks Expose AI Prompts to Third-Party Servers and Hidden Logs
Users of the GPT4Free hosted platform might believe they are directly interacting with the selected artificial intelligence model in its web interface.…
BIND 9.20.29 Fixes 14 Security Flaws Enabling DNSSEC Bypass and Denial-of-Service Attacks
The Internet Systems Consortium (ISC) has released BIND 9.20.29, which addresses 14 security vulnerabilities. These vulnerabilities could enable remote…
FamousSparrow Deploys New SparroWocky Backdoor Against Latin American Governments
China-aligned advanced persistent threat group FamousSparrow has replaced its long-running SparrowDoor implant with a new modular C++ backdoor,…
CISA Urges Organizations to Deploy Cyber Decoys to Detect Hackers Inside Networks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged organizations to deploy cyber decoys, which include fake credentials, systems,…
12 Best DSPM Tools Compared (2026): Features & Pricing
Quick Answer: DSPM has the scariest pricing curve in security bills track data volume, and data only grows. Microsoft Purview publishes pay-as-you-go…
Kubernetes Attack Lets Hackers Steal SPIFFE Workload Identities and Impersonate Applications
A post-exploitation technique that lets attackers with root-level access to a Kubernetes node steal workload identities issued through SPIFFE/SPIRE and…
Hackers Exploit Critical Cisco ISE Flaw to Bypass Authentication and Gain Root Access
Cisco has issued an urgent security advisory regarding a critical authentication-bypass vulnerability in Cisco Identity Services Engine (ISE) and Cisco…
APT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal
Pakistan-nexus threat actor APT36 has launched a renewed espionage campaign targeting government and defense organizations in India and Afghanistan.…
NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
The NightEagle advanced persistent threat group, tracked as APT-Q-95, has expanded its operations to target businesses in Russia, combining stolen VPN…
12 Serverless Security Options Compared (2026): Features & Pricing
Quick Answer: There is no standalone serverless-security SKU worth buying in 2026 functions are a line item inside CNAPP or observability contracts.…
RatHat Abuses Android Wireless Debugging to Gain Shell Access and Steal Banking PINs
RatHat, a newly identified Android banking malware family that combines Accessibility abuse, local Android Debug Bridge (ADB) pairing, native shell-level…
Docker Sandboxes Vulnerabilities Let Malicious Guests Escape Workspace and Access Host Files
Docker has released security fixes for two serious vulnerabilities in Docker Sandboxes that could let a malicious guest environment bypass workspace…
