Veeam has issued security updates to address multiple vulnerabilities in Veeam ONE, including a critical flaw that could enable an unauthenticated remote…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Ransomware Hackers Are Hiding Malware Command Servers Inside Ethereum Smart Contracts
Ransomware operators are now abusing Ethereum smart contracts as stealthy command‑and‑control resolvers, with a Gentlemen ransomware affiliate using the…
Mythos 5 and GPT-5.6-Sol AI Agents Broke Cyber Test Boundaries and Targeted Real Users
The UK AI Security Institute (AISI) has reported a serious incident involving autonomous AI agents that were conducting cybersecurity evaluations. These…
Django Flaws Let Attackers Trigger RCE, SSRF, DoS, and XSS Attacks
The Django project has released security updates, specifically Django 6.0.8 and Django 5.2.17, to address four vulnerabilities that could lead to…
7-Zip Default Setting Lets Extracted Files Bypass Windows SmartScreen
7-Zip’s default configuration allows files extracted from internet-delivered archives to shed the Mark of the Web (MotW), meaning Windows SmartScreen…
Botnet Scans Router Diagnostic Tools for OS Command Injection Vulnerabilities
Botnet operators are systematically probing router diagnostic interfaces for OS command injection flaws, chaining default credentials, legacy CGI…
1-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity Lets Attackers Execute Arbitrary Code
A serious one-click remote code execution (RCE) vulnerability that affects Cursor, Microsoft Visual Studio Code, and Google Antigravity, an AI-assisted…
Compromised Microsoft Copilot Accounts Let Hackers Impersonate CEOs and Steal $247,500
A controlled proof-of-concept by Barracuda’s Red Team has demonstrated how a compromised Microsoft 365 account with Copilot access can serve as a powerful…
Ransomware Attack Abuses Legitimate Windows Tool to Evade Traditional Containment
Microsoft Defender’s new automatic device isolation capability has emerged as a decisive control against modern ransomware intrusions that abuse…
Six Flowise Vulnerabilities Enable Remote Code Execution on AI Workflow Servers
Six newly disclosed vulnerabilities in Flowise, a popular open‑source platform for building AI agents and LLM workflows, allow unauthenticated and…
DarkSword Server Combines iPhone Exploits With Fake Apple ID Login Page
DarkSword’s leaked iOS exploit chain is now powering a fast‑moving server cluster that marries one‑click Safari exploitation with a convincing fake Apple…
Fake Xeno Roblox Cheats Deliver Java RAT That Steals Discord and Gaming Accounts
Fake Roblox cheat tools are once again being weaponized, with a newly observed campaign distributing a sophisticated Java-based remote access trojan (RAT)…
OWASP Introduces Subtractive Security Top 10 to Eliminate Attack Paths and Reduce Cyber Risk
OWASP has launched the Subtractive Security Top 10 project, a security engineering initiative that shifts the focus from adding more detection controls to…
OpenAI Shuts Down ChatGPT Accounts Powering a Cambodia-Based Scam Factory
OpenAI has shut down a coordinated network of ChatGPT accounts that powered a Cambodia-based scam factory running multi-vector fraud and…
Shai-Hulud Supply Chain Attack Compromises Keyv and Hundreds of npm Packages
Attackers have compromised the GitHub account of a Keyv maintainer, a widely used JavaScript key-value storage library, to distribute credential-stealing…
CISA Adds Exploited N-able N-central Flaw Enabling Remote Admin Takeover to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-18577, an actively exploited authentication bypass vulnerability in…
Russian Access Broker Sells Network Access to Ransomware Gangs While Spying on Ukraine
An exposed server linked to a Russian‑speaking initial access broker (IAB) has revealed a sprawling operation that simultaneously fuels ransomware…
China Is Training Military AI With Knowledge Extracted From American Models
China’s artificial intelligence ecosystem is rapidly advancing through a controversial technique known as model distillation, with mounting evidence…
18 Malicious npm Packages Deploy Cross-Platform RAT Against Alibaba Developers
18 malicious npm packages have been used in a tightly coordinated software supply chain attack to deliver a cross‑platform RAT that specifically targets…
Critical Gitea Flaw Lets Unauthenticated Attackers Read Server Files and Execute Code
A critical vulnerability in Gitea has been identified, potentially allowing unauthenticated remote attackers to read arbitrary files on vulnerable servers…