A recently disclosed high-severity vulnerability in Sudo could allow local, unprivileged Linux users to manipulate time-based authorization restrictions…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Duelbits Hot Wallet Hack Drains $7 Million, Forces Platform Offline
Crypto casino Duelbits has confirmed a cybersecurity breach that drained approximately $7 million from its hot wallets. In response, the company has taken…
Bitget Confirms $351.6 Million Hot Wallet Hack, Suspends Withdrawals
Crypto exchange Bitget has confirmed unauthorized transfers from part of its hot wallet infrastructure, resulting in estimated losses of about $351.6…
Attackers Drain Payy Network After Exploiting Ethereum Bridge Contract
Payy Network has confirmed that an attacker exploited its Ethereum bridge contract and drained its entire balance. As a result, the network and wallet…
Cloudflare Containers Flaw Could Expose Data From Other Customers’ Workloads
Cloudflare has addressed a cross-tenant data exposure vulnerability in its Containers platform that could have allowed one customer’s workload to recover…
Operation Conflict Compass Deploys VelvetCake PowerShell Malware Through Malicious LNK Files
North Korea-linked threat actor Konni has launched a targeted cyberespionage operation against Ukraine-focused entities using malicious Windows shortcut…
Hackers Exploit Check Point VPN RCE and Management Zero-Day in Attacks
Check Point has warned customers about the active exploitation of two critical vulnerabilities in its VPN gateway and Security Management products:…
Roundcube Webmail Flaw Lets Attackers Trigger SQL Injection Without Authentication
A highly severe vulnerability in Roundcube Webmail is being actively exploited, posing risks to unpatched email servers through unauthenticated SQL…
New Windows Malware Built to Survive Takedowns With a Hidden P2P Command Network
AvisLoader, a newly observed Windows malware loader designed to maintain operator access even when conventional command-and-control infrastructure is…
Microsoft Rebuilds the SOC With AI Agents to Fight Machine-Speed Cyberattacks
An Integrated Security Operations Center (ISOC) in Microsoft Defender, unifying security information and event management (SIEM) and threat-protection…
RemControl Android Malware Targets 30+ Banking Apps to Steal PINs and Credentials
A newly uncovered Android banking trojan dubbed RemControl is targeting customers of more than 30 financial institutions across Europe, the Middle East,…
cPanel Permissions Flaw Allows Local Users to Read Other Accounts’ Calendar Data
cPanel has released patches for CVE-2026-68490, a vulnerability related to incorrect permissions in its CalDAV/CardDAV implementation. This flaw could…
New Galago Ransomware Operation Emerges With Links to Panzer Extortion Group
A newly identified ransomware operation tracked as Galago has emerged with apparent operational links to the Panzer ransomware group, raising concerns of…
GitLab Email Token Lets Attackers Push Code to Main and Execute CI/CD Jobs
A long-lived GitLab incoming email token embedded in project email addresses for the “Email work item” feature can be exploited to push…
Apache Tomcat 11.0.26 Fixes 12 Security Flaws Enabling WebSocket Bypass and DoS Attacks
Apache Tomcat 11.0.26 has been released with fixes for 12 security vulnerabilities, including a significant flaw that could allow attackers to bypass…
Fake Firefox Extension Hijacks Google Accounts Without Stealing Passwords First
A malicious Firefox extension masquerading as a PDF identity-verification utility has been found targeting Google accounts through session-cookie theft…
Fake Crypto Wallet App Delivers PamStealer Malware That Hijacks Mac Credentials
A new variant of the macOS infostealer PamStealer is being distributed through a fake cryptocurrency wallet application, using a server-assisted…
Exvicy ClickFix Malware-as-a-Service Copies ErrTraffic to Hijack WordPress Sites
A new Malware-as-a-Service platform, Exvicy, is actively abusing compromised WordPress websites to deliver ClickFix lures disguised as Cloudflare…
SolarWinds Observability Flaws Let Unauthenticated Attackers Execute Remote Code
SolarWinds has released SolarWinds Observability Self-Hosted version 2026.2.3 to address two critical remote code execution (RCE) vulnerabilities. These…
HPE Networking Analytics Engine Flaws Let Attackers Gain Root Access
Hewlett Packard Enterprise (HPE) has announced security updates for its Networking Analytics and Location Engine (ALE), addressing 10 vulnerabilities that…
