Vanta Stealer is a Python‑based, cross‑platform information stealer that uses layered PyArmor obfuscation on top of a PyInstaller‑packed executable to…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Critical Jenkins Deserialization Flaw Allows Attackers to Execute Code on Controllers
A critical vulnerability in Jenkins, tracked as CVE-2026-70426, may allow attackers to execute arbitrary code on Jenkins controllers by bypassing…
KHunt Toolkit Turns Oracle SQL Injection Into SYSTEM-Level RCE and Credential Theft
KHunt shows how a “routine” SQL injection against an Oracle‑backed web app can be weaponized into SYSTEM‑level remote code execution and credential theft…
Meta Confirms AI Model Launched Autonomous Attack on Another Organization
Meta has become the latest technology company to disclose that an AI agent accessed another organization’s online systems during a controlled…
PoC Released for Linux Kernel STP Use-After-Free Vulnerability
A proof-of-concept (PoC) has been released for a use-after-free vulnerability affecting the Linux kernel’s software bridge implementation found in…
Cisco Patches 7 IOS XE Vulnerability Classes, Including Critical Command Injection Flaws
Cisco has released security-hardening updates for IOS XE Software that address seven classes of vulnerabilities, including a critical command, operating…
Hackers Turn Ethereum Smart Contract Into Dead-Drop Resolver for Remus Malware
Hackers are abusing an Ethereum smart contract as a dead‑drop resolver to dynamically steer victims’ browsers to rotating command‑and‑control (C2)…
OpenAI Agents Worked Together to Find Exploits and Hack External Systems
OpenAI has revealed new details about an incident involving AI agents, in which multiple autonomous agents reportedly worked together to identify…
Canadian Hacker Pleads Guilty to Stealing Billions of Records From 165 Cloud Customers
Connor Riley Moucka, a 26-year-old Canadian national from Kitchener, Ontario, has pleaded guilty to charges related to a large-scale cloud data theft and…
CISA Alerts Issues on Actively Exploited TeamCity Remote Code Execution Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in JetBrains TeamCity, tracked as CVE-2026-63077, to…
250+ Fake Download Domains Target Mac Users With AMOS and MacSync Infostealers
Attackers are using more than 250 fake “download” domains to selectively target Mac users with AMOS and MacSync infostealers, hiding their ClickFix lures…
Hackers Abuse Cloud Startup Credits to Resell Claude and Gemini AI Access
Threat actors are exploiting free cloud trials and startup credit programs to build gray-market AI proxy services. These services resell discounted access…
Critical Cisco SD-WAN Flaws Expose Systems to Access Control Bypass Attacks
Cisco has released important security updates for Catalyst SD-WAN Software after discovering several critical vulnerabilities that could allow for access…
Stolen Greatness Tokens Provide Microsoft 365 Access More Than Two Weeks After Phishing
Stolen Greatness authentication tokens are providing sustained, MFA‑approved access to victim Microsoft 365 tenants for more than two weeks after the…
Four Million Malware Reports Reveal a Widespread No-DNS C2 Blind Spot
A long‑running supply chain compromise of the QuickFox VPN accelerator that quietly delivered an FDMTP backdoor to carefully profiled Windows systems,…
OVSwrap Open vSwitch Flaw Lets Unprivileged Linux Users Gain Root Access
A recently disclosed Linux local privilege-escalation vulnerability, tracked as CVE-2026-64531 and referred to as OVSwrap, affects the kernel’s Open…
Microsoft Paid Record $20 Million in Bug Bounties to 562 Security Researchers Worldwide
Microsoft’s Bug Bounty Program awarded over $20 million to 562 security researchers this year, marking the highest total payout and the largest number of…
15 TP-Link Omada Flaws Exploit Zero-Touch Provisioning to Hijack Devices and Infiltrate Networks
Security researchers have disclosed 15 vulnerabilities in TP-Link’s Omada zero-touch provisioning (ZTP) ecosystem, which can be exploited to hijack…
ScreenConnect Attackers Hide Windows, Delete Installers and Masquerade as Software Updates
ScreenConnect is being systematically weaponized in the SMOKE#SCREEN campaign, where attackers hide execution windows, delete installers, and disguise…
Fake Open VSX Extensions Hijack AMD, Azure, Salesforce and Government Namespaces
Fake Open VSX extensions have hijacked high‑trust namespaces like AMD, Azure, Salesforce, Hyperledger, and a U.S. government agency on the Open VSX…