A new Metasploit Framework module has been submitted for review, targeting the critical Ruby on Rails Active Storage vulnerability, tracked as…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Hackers Exploit Critical Arista VeloCloud Flaw to Execute OS Commands
Arista Networks has issued a warning about attackers actively exploiting CVE-2026-16812, a critical unauthenticated OS command injection vulnerability in…
CareCloud Data Breach Exposes Patients’ Health, Social Security and Credit Card Data
CareCloud has reported a data security incident involving unauthorized access to its Amazon Web Services (AWS) environment that supports the CareCloud…
SonicWall SMA Zero-Days Let Attackers Turn One WebSocket Request Into Root Control
SonicWall SMA Secure Mobile Access appliances are again at the center of a zero-day storm, with chained flaws that let attackers turn a single crafted…
Coldcard Firmware Flaw Lets Hackers Steal $70 Million in Bitcoin From 1,196 Addresses
Blockchain analysts have linked a rapid series of Bitcoin wallet drains to a reported vulnerability in Coldcard firmware. A total of 1,196 addresses lost…
XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs
XCSSET v40 marks a significant escalation in macOS-focused supply chain attacks, weaponizing poisoned Xcode projects to hijack Chrome and Trojanize…
Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week – Hugging Face, Iranian ICS Attacks, EY, Hyundai, AI Agent Breaches
Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from…
The Best Firewall-as-a-Service (FWaaS) Providers, Compared and Priced (2026)
Firewall-asa-service moved from experiment to default: inspection, IPS, and policy delivered from the cloud, priced per user or per site instead of per…
The Best Cloud Firewall Solutions, Compared and Priced (2026)
Cloud firewalls bill three ways — usage-metered native services, licensed virtual appliances, and managed platform subscriptions — and picking the wrong…
Autonomous AI Agent Exploits Zero-Day to Breach Hugging Face Infrastructure
An autonomous AI agent powered by OpenAI models breached Hugging Face’s production infrastructure in July 2026 after escaping its evaluation sandbox via a…
Arch Linux Suspends AUR Package Adoptions to Block Ongoing Malicious Commit Campaign
Arch Linux has temporarily disabled package adoptions on the Arch User Repository (AUR) after detecting a wave of malicious activity targeting orphaned…
CRPx0 Ransomware Claims Hyundai Turkey Breach, Steals 1.5GB of Assessment Data
The double-extortion ransomware group CRPx0 has listed Hyundai’s Turkish operations on its dark web leak site, claiming to have exfiltrated 1.5 GB of…
HackerOne Mandates ID Verification Before Bug Bounty Report Submissions
HackerOne has rolled out a significant policy change requiring all hackers to complete identity verification before submitting reports to Bug Bounty…
MacSync Stealer RAT Uses Fake Claude Guides to Steal Passwords and Crypto Wallets
A newly disclosed macOS malware campaign dubbed MacSync weaponizes fake Claude AI installation guides to deploy a six-stage stealer and remote access…
Keycloak Flaw Exposes Users’ Personal Data to Restricted Admins
A broken access control vulnerability in Keycloak could allow unauthorized administrator accounts to access users’ personal information. This issue,…
Ransomware Killers Overwrite Security Process Memory Without Terminating Applications
Ransomware operators are increasingly deploying “ransomware killers” that surgically overwrite the memory of security processes instead of simply…
Critical JetBrains TeamCity Flaw Enables Unauthenticated Remote Code Execution
JetBrains has revealed a critical security vulnerability in TeamCity On-Premises that enables unauthenticated remote code execution (RCE) on affected…
Google Uses AI to Fix 1,072 Chrome Security Vulnerabilities
Google has announced that its AI-assisted security workflows have helped Chrome fix 10,721 security vulnerabilities across Chrome Stable milestones 149…
ClickFix Campaign Uses EtherHiding to Hide Malware and Exposes DPRK Wallet Trail
ClickFix-style fake macOS updates are now being weaponized with EtherHiding-backed command‑and‑control and a DPRK-linked crypto laundering network,…
Critical Adobe Campaign Flaw Lets Attackers Execute Arbitrary Code
Adobe has released a critical security update for Adobe Campaign Classic to address multiple high-severity vulnerabilities that could allow attackers to…