Securing Google Cloud starts with Security Command Center Standard included with every org and the best free first move while Wiz is the best third-party…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Hackers Turn an Open-Source AI Agent Into a Tool for Controlling Compromised Docker Servers
A Docker-focused botnet that repurposes the legitimate, open-source Hermes Agent framework as an interactive post-compromise control layer. The campaign,…
12 Best Azure Security Tools Compared (2026): Features & Pricing
For most Azure estates, Microsoft Defender for Cloud is the best starting point its free foundational tier plus published per-resource plans make it the…
12 Best AWS Security Tools Compared (2026): Features & Pricing
If you’re securing AWS in 2026, Wiz is the best overall third-party platform for most mid-size and enterprise estates, thanks to agentless attack-path…
16-Year-Old Researcher Discovers Microsoft Authentication Bug Exposing 17.3 Trillion Records
A 16-year-old security researcher known as Faav discovered a significant authentication flaw in Microsoft’s internal Titan analytics service. This…
MacSync’s New Infection Chain Shows How Mac Malware Is Becoming More Sophisticated
A newly observed MacSync campaign shows a marked evolution in macOS-focused crimeware, replacing relatively simple AppleScript-driven delivery with…
New Windows Process Injection Technique Bypasses EDR Monitoring Without WriteProcessMemory
A newly disclosed method for Windows process injection utilizes redirected console input and named pipes to transfer payload data into a child process…
Citrix Confirms NetScaler Zero-Day RCE Flaws Actively Exploited in Attacks
Citrix has released emergency security updates for NetScaler ADC and NetScaler Gateway after confirming active exploitation of two critical zero-day…
Red Heron Exploits Critical Gitea Flaw to Steal Repositories and Deploy Linux Rootkit
A threat actor tracked as Red Heron has exploited the critical Gitea remote code execution vulnerability CVE-2026-60004 to steal source-code repositories,…
Windows 11 Update Causes Black Screen and Desktop Loading Issues After Sign-In
Microsoft has confirmed a Windows 11 issue that can leave users with a black screen after sign-in or prevent the desktop from loading automatically. The…
Kiteworks Warns Users to Take Systems Offline Amid Suspected Zero-Day Threat
Kiteworks has urged customers worldwide to temporarily shut down their servers after receiving credible law-enforcement intelligence that a threat actor…
Uncensored Local AI Model Bypasses EDR to Dump Windows LSASS Credentials
A new demonstration shows how a locally hosted, uncensored AI model can help generate a Windows LSASS credential-dumping utility that reportedly evaded…
Storm-3168 Hackers Abuse Compromised Service Principals to Destroy Azure Cloud Resources
Microsoft has uncovered a destructive Azure campaign linked to Storm-3168, also known as JADEPUFFER, in which attackers abused compromised service…
OpenAI Says Misaligned AI Agents Hacked Hugging Face and Bypassed Security Controls
OpenAI has disclosed that autonomous AI agents compromised portions of Hugging Face’s infrastructure during internal cybersecurity evaluations after…
14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape
A vulnerability in the Linux kernel’s AF_ALG cryptographic interface, which has existed for 14 years, can let an unprivileged local attacker gain root…
Rogue AI Agents Tried to Hack Public Websites After Data Retrieval Failed
Research from Transluce shows that autonomous AI agents shifted from standard web data collection to probing for vulnerabilities in three public-facing…
ServiceNow Security Flaws Allow Attackers to Execute SQL and Modify Instance Data
ServiceNow has disclosed five vulnerabilities affecting its AI Platform, including two critical flaws that could allow unauthenticated attackers to…
CISA Adds Multiple Check Point Product Flaws to Exploited Vulnerabilities List
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities affecting multiple Check Point products to its…
CISA Flags WSO2 Security Flaw Under Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting WSO2, tracked as CVE-2026-5430, to its Known…
Salesforce Agentforce Flaw Enables 0-Click Data Exfiltration via Prompt Injection
Security researchers have revealed a vulnerability chain known as “SalesBleed,” associated with Salesforce’s Agentforce. This vulnerability could allow…
