Astaroth operators have expanded their Brazilian banking malware operations by weaponizing a new WhatsApp Web spambot module that turns infected hosts…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
ShutterGap Exposes Millions of Misconfigured AWS Resources to Attackers
A cloud-security blind spot known as Cloud ShutterGap, which involves millions of AWS resources being briefly exposed to the public before being removed,…
CosmosEscape Vulnerability Enables Full Takeover of Azure Cosmos DB Databases
A critical vulnerability chain in Azure Cosmos DB, named CosmosEscape, allowed attackers to gain full read and write access to every Cosmos DB database,…
CISA Urges Water Utilities to Remove Publicly Exposed PLCs From the Internet
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert to the Water and Wastewater Systems (WWS) Sector due to a…
OctLurk and SilkLurk Backdoors Target Central Asian Governments in Cyberespionage Campaign
OctLurk and SilkLurk are highly customized, memory‑resident backdoors used in an ongoing cyberespionage campaign against government and critical‑sector…
Analog Devices Confirms Cyberattack After Hackers Exfiltrate Files From Company Systems
Analog Devices, Inc. has confirmed that unauthorized actors gained access to certain company systems and exfiltrated files. The semiconductor manufacturer…
Anthropic Confirms Claude AI Models Hacked 3 Organizations During Cybersecurity Evaluations
Anthropic has disclosed that three Claude AI models gained unauthorized access to the production systems of three real-world organizations during…
AtlasRAT Uses Four-Stage In-Memory Loader to Keylog and Inject Malware Into WeChat
AtlasRAT is a modular Windows remote access trojan that uses a four-stage, fully in-memory loader chain to quietly establish TLS‑ and ChaCha20‑protected…
CISA Adds Cisco Secure Firewall Management Flaw to Exploited Vulnerabilities List
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Cisco Secure Firewall Management Center (FMC),…
Linux XMRig Botnet Abuses PAM for Fileless Monero Mining and Persistent Access
A covert Monero (XMR) cryptomining campaign uncovered in May 2026 is abusing Linux Pluggable Authentication Modules (PAM) to evade detection, maintain…
Top 10 Best Tools for Simulated DDoS Attacks in 2026
You don’t know your DDoS defenses work until you attack them yourself — safely, on purpose, with a kill switch. Simulated DDoS attack tools generate…
New GenieLocker Ransomware Encrypts Windows, Linux and VMware ESXi Systems
GenieLocker is a custom ransomware family linked to the Toy Ghouls group (also known as Bearlyfy or Labubu). It can encrypt systems running Windows,…
Hackers Exploit Nearly 1 in 4 Vulnerabilities Before or on Disclosure Day
Hackers are increasingly exploiting vulnerabilities at an unprecedented speed, with nearly one in four flaws being abused before or on the same day they…
Home Assistant FFmpeg Flaw Lets Attackers Steal Supervisor Tokens and Execute Code as Root
Home Assistant’s FFmpeg integration recently came under scrutiny after researchers demonstrated that unsafe argument handling in the Wyoming Assist…
Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy Chaos Ransomware
Hackers are abusing Microsoft Teams voice calls and fake IT helpdesk personas to gain remote access to corporate endpoints, drop a custom…
Work Panel Vishing Platform Automates Enterprise Account Takeovers and MFA Theft
Work Panel is a turnkey vishing and phishing platform that industrializes enterprise account takeovers and MFA theft by packaging infrastructure…
Copybara Abuses Android Accessibility for Keylogging, Screen Streaming and Remote Control
Copybara is being weaponized in a new N26-themed fraud campaign in Italy that chains vishing, a real‑time phishing control kit, and a multi‑stage Android…
Node.js Patches 11 Security Flaws Enabling Memory Exhaustion, File Access and Request Smuggling
The Node.js Project has released security updates for the active Node.js versions 22.x, 24.x, and 26.x, addressing 11 vulnerabilities. These…
North Korean Hackers Compromise Popular npm Packages to Target Developer Environments
North Korea–linked operators have quietly turned popular npm packages into a high‑volume access vector for developer and build environments, chaining…
Google Chrome 151 Fixes 370 Security Flaws, Including 7 Critical Bugs
Google has released stable Chrome version 151 updates for Windows, macOS, and Linux, addressing 370 security vulnerabilities. This update includes fixes…