GitLab has released security updates for both the Community Edition (CE) and Enterprise Edition (EE), addressing 13 vulnerabilities that could allow…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
TA488 Exploits Outlook Half-Click Flaw to Deploy Persistent OWAReaper Backdoor
TA488 has resurfaced with a high‑end half‑click campaign against on‑premises Outlook Web Access (OWA), exploiting CVE‑2026‑42897 to deploy a persistent…
Claude Global Outage Hits Users With “529 Overloaded” Error Messages
Users of Claude experienced service disruptions on Wednesday when Anthropic reported elevated error rates across all Claude models. This incident affected…
Microsoft Word Copilot Flaw Lets Hidden Prompts Spread Self-Propagating AI Worms Across Documents
Security researcher Håkon Måløy has disclosed a cross-domain prompt injection vulnerability affecting Microsoft Copilot for Word. This vulnerability could…
Hackers Can Compromise Tor Browser Users by Exploiting Firefox JIT Flaw
Tor Browser users on unpatched versions may be at risk of compromise simply by visiting a malicious webpage, following the disclosure of CVE-2026-10702, a…
Critical Rails Flaw Lets Unauthenticated Attackers Read Server Files and Execute Code
A critical vulnerability in Ruby on Rails’ Active Storage component could allow unauthenticated attackers to read arbitrary files on vulnerable…
Top 10 Best Security Configuration Assessment Tools in 2026
In the complex and ever-expanding digital landscape of 2026, a strong cybersecurity posture depends not only on identifying vulnerabilities in software…
Critical VMware vCenter Flaws Let Remote Attackers Bypass Authentication and Execute Code
Broadcom has released important security updates addressing critical vulnerabilities in VMware that could allow remote attackers to bypass vCenter…
Critical Ruflo MCP Bridge Flaw Allows Full AI Agent Platform Takeover
A critical vulnerability in the open-source AI orchestration platform Ruflo has been disclosed, allowing unauthenticated attackers to achieve full remote…
macOS ClickFix Attacks Use Fake CAPTCHAs to Deploy Atomic Stealer and Hijack Crypto Wallets
macOS users are facing a new, highly polished ClickFix campaign that abuses fake CAPTCHAs to execute Terminal commands, silently deploy Atomic macOS…
NVIDIA BlueField Flaw Lets VM Users Execute Code via Crafted Messages
NVIDIA has revealed a significant security vulnerability in its BlueField data processing units (DPUs) that could allow virtual machine (VM) users to…
Threat Actor Claims Revolut Data Breach Exposes Financial Records of 75 Million Users
A threat actor has reportedly claimed to possess and sell a large dataset allegedly linked to the fintech company Revolut, purportedly affecting more than…
Russian Intelligence Hackers Target Signal Backup Recovery Keys in Account Takeover Attacks
Russian intelligence-linked hackers have shifted tactics to target Signal users’ backup recovery keys, enabling full account takeover and access to…
CISA Urges Critical Infrastructure Operators to Isolate Vital OT Systems During Cyberattacks
CISA, in collaboration with the Australian Signals Directorate’s Australian Cyber Security Center (ASD’s ACSC), the FBI, and international partners, has…
Houston City College Data Breach Impacts 832,000 Students and Alumni
Houston City College has been linked to a significant data breach that has affected approximately 832,000 students and alums. This breach occurred in June…
Joyfill npm Supply-Chain Attack Deploys RAT and Developer Credential Stealer
A supply-chain compromise targeting the npm ecosystem has introduced a multi-stage remote access trojan (RAT) and credential stealer through hijacked…
Fake Web3 Job Interview Software Delivers Infostealer to Steal Crypto Wallets and Passwords
A newly uncovered cyber campaign is targeting Web3 professionals with sophisticated social engineering, leveraging fake job interviews to deploy…
Critical WordPress Plugin Backdoor Exposes 20,000 Sites to Full Administrator Takeover
A critical supply-chain compromise in a widely used WordPress plugin has exposed approximately 20,000 websites to potential administrator takeover.…
Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware
Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in…
Check Point SmartConsole Zero-Day Lets Unauthenticated Attackers Gain Full Admin Access
A critical zero-day vulnerability in Check Point SmartConsole, identified as CVE-2026-16232, has been actively exploited, allowing unauthenticated…