A publicly indexed server at 198[.]245[.]53[.]26, discovered via Shodan, exposed more than simple staging files it revealed an active payload-generation backend and obfuscation tooling tied to two distinct Banana RAT branches. The host served static stages (st.txt, payload.php) and a…
Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
CrowdStrike Uncovers 5 New Prompt Injection Techniques Targeting AI Agents
CrowdStrike has identified five new techniques for prompt injection targeting AI agents, emphasizing the rapid evolution of adversarial methods as enterprises increasingly deploy autonomous AI systems. Detailed in a report published on July 7, 2026, by CrowdStrike’s AI security research…
Discord Confirms Bug That Incorrectly Banned 8,200 Users Since May 2026
Discord has confirmed a significant flaw in its automated moderation and enforcement pipeline that led to the wrongful banning of approximately 8,200 user accounts between May and early July 2026. This raises concerns about the reliability of AI-assisted trust and…
AI-as-a-Service Botnet Routes Malicious Workloads Across Compromised Windows and Linux Hosts
The underground advertisement for the so-called Mycelium Framework reads like another feature‑packed botnet sales pitch: cross‑platform payloads, encrypted C2, persistence, exploit modules, credential theft, and lateral movement. Those building blocks are not new. What makes Mycelium notable is its advertised…
Claude Code, Cursor, and OpenAI Codex Trigger Cyberattack-Like Telemetry Alerts
AI-powered coding assistants such as Claude Code, Cursor, and OpenAI Codex are increasingly triggering endpoint detection and response (EDR) alerts that resemble active cyberattacks, according to new research from Sophos X-Ops. This analysis, based on real-world telemetry collected in June…
REF6045 Uses SCMBANKER PowerShell Toolkit to Target Mexican Banking Customers
A human-operated Mexican banking fraud campaign tracked as REF6045 has been observed using a bespoke PowerShell toolkit SCMBANKER to turn commodity click-fraud lures into operator-assisted account takeovers and payment diversion. The operation relies on social engineering through fake CAPTCHA/verification pages…
CISA Warns of Actively Exploited Adobe ColdFusion Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Adobe ColdFusion, tracked as CVE-2026-48282, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability is actively being exploited in the wild. Disclosed on July 7, 2026,…
Over 70% of Public WordPress Sites Running Outdated PHP Exposed to Cyberattacks
A new analysis has revealed a significant security gap within the global web ecosystem. Over 70% of publicly accessible WordPress sites are running outdated, end-of-life (EOL) PHP versions, significantly increasing their vulnerability to cyberattacks. These findings highlight a systemic issue…
Lurking Lizard Uses Drop-Catch Domains and Lookalike Brands to Distribute Proxyware
A sophisticated, long-running operation that converts consumer devices into rentable exit nodes for residential proxy services. The initial signal was a fake 7-Zip installer hosted at 7zip[.]com a domain that mimicked the legitimate 7-zip[.]org and benefitted from years of search-engine…
15-Year-Old GhostLock Linux Kernel Vulnerability Enables Root Access and Container Escape
A critical vulnerability in the Linux kernel, known as “GhostLock” (CVE-2026-43499), has been disclosed by researchers at Nebula Security. This vulnerability, which has existed for 15 years, allows for reliable privilege escalation and container escape across nearly all Linux distributions.…
Indian Income Tax Department Phishing Lure Deploys Gh0st RAT and AsyncRAT Implants
A targeted phishing campaign impersonating the Indian Income Tax Department has been observed delivering a sophisticated, six-stage infection chain that culminates in two in-memory remote-access implants: a Gh0st RAT derivative and a Quasar/AsyncRAT-family .NET payload. Victims are funneled to fake…
LONGLEASH Malware Adds Reverse Shell, Proxying, and Intermediate C2 Capabilities
A significant upgrade to malware maintained by the UAT-7810 actor: LONGLEASH, a successor to the previously reported SHORTLEASH implant, now sporting reverse-shell, multi-protocol proxying, and intermediate command-and-control (C2) forwarding capabilities. LONGLEASH retains SHORTLEASH’s ff-agent codebase but expands its operational scope.…
China-Aligned UNK_MassTraction Exploits Roundcube Servers to Target Universities
A suspected China-aligned cluster dubbed UNK_MassTraction that is exploiting n-day flaws in Roundcube webmail to compromise physics and engineering departments at U.S. and Canadian universities. The operators use a two-stage browser-to-server infection chain that begins with a Cross-Site Scripting (XSS)…
U.S. Government Reportedly Approves OpenAI’s GPT-5.6 Sol, Terra, and Luna Models
The Trump administration has reportedly lifted previous restrictions on the launch of OpenAI’s GPT-5.6, enabling a broader commercial rollout of this advanced model after weeks of government-mandated cybersecurity and national security vetting. This decision marks a significant turning point in…
Google Dialogflow CX Flaw Lets Attackers Bypass VPC-SC and Steal Sensitive Chatbot Data
A critical vulnerability in Google Cloud’s Dialogflow CX platform allowed attackers to bypass VPC Service Controls (VPC-SC) and silently exfiltrate sensitive chatbot data, raising significant concerns about the security of enterprise AI deployments. Discovered by Varonis Threat Labs and dubbed…
Anthropic Keeps Claude Fable 5 Available on Paid Plans Until July 12
Anthropic has announced an extension of access to its advanced AI model, Claude Fable 5, allowing users on all paid plans to continue using the system until July 12, 2026. This update, shared via the company’s official X account, comes…
GitLost Vulnerability Lets Attackers Trick GitHub AI Agent Into Leaking Private Repos
A critical vulnerability known as “GitLost” has been discovered in GitHub’s newly introduced Agentic Workflows by Noma Labs. This flaw allows unauthenticated attackers to exfiltrate sensitive data from private repositories. It demonstrates how AI-driven automation within development pipelines can be…
Accenture Data Breach Exposes 35GB Source Code and Azure DevOps Credentials
Accenture is currently investigating a potential data breach after a threat actor using the alias “888” claimed to be selling approximately 35GB of stolen data, including source code and sensitive credentials, on a cybercrime forum. This listing, posted on July…
SindriKit 1.3.0 Abuses Call Stack Spoofing to Bypass EDR Detection
SindriKit 1.3.0 introduces a significant advancement in evading Endpoint Detection and Response (EDR) systems by exploiting dynamic call stack spoofing. This method defeats telemetry that inspects kernel-transition call chains, going beyond just user-mode hooks. Previously, SindriKit 1.2.0 had already separated…
TeamPCP Supply Chain Attacks Feed VECT Ransomware With Stolen CI/CD Credentials
TeamPCP’s wide-scale supply-chain compromises have materially fueled VECT ransomware operations by supplying a vast archive of stolen CI/CD credentials, reshaping how organizations should measure ransomware exposure. Rather than choosing victims in advance, TeamPCP contaminated widely used components Trivy, Checkmarx KICS,…
