Apple’s internal Biome framework is rapidly emerging as one of the most valuable sources of forensic intelligence on iOS, with newly analyzed data revealing detailed records of Safari browsing activity, Wallet transactions. Originally misunderstood due to its name, Biome is…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
AWS Launches Claude Opus 5 With Advanced Agentic Coding and Cybersecurity Capabilities
AWS has launched Anthropic’s Claude Opus 5 on Amazon Bedrock and the Claude Platform, introducing a groundbreaking model designed for agentic coding, complex enterprise workflows, visual understanding, and long-running autonomous tasks. Released on July 24, 2026, Claude Opus 5 is…
Claude Code Symlink Flaw Exfiltrates Sensitive Files Without User Approval
Claude Code has a flaw in its startup memory loader related to handling symbolic links (symlinks) that can unintentionally expose readable files from outside a cloned repository, without requiring explicit user approval. The issue arises not from the tool following…
SparkKitty Monitors Mobile Photo Galleries and Exfiltrates Sensitive Images to C2 Servers
SparkKitty is a cross‑platform mobile stealer that weaponizes users’ photo galleries, using OCR to extract sensitive text from images and silently exfiltrating it to attacker‑controlled C2 servers on both Android and iOS. Built as an apparent successor to SparkCat, the…
PyPI Blocks New File Uploads to Old Releases to Prevent Package Poisoning Attacks
PyPI has introduced a new supply-chain security control that prevents publishers from uploading additional files to package releases older than 14 days, reducing the risk of attackers poisoning previously trusted versions after compromising project credentials, automation workflows, or publishing tokens.…
BlueNoroff Fake Meeting Kit Captures Webcams, Disables Defender and Steals Cryptocurrency Credentials
BlueNoroff, a financially motivated threat cluster linked to the Lazarus Group, has been observed deploying a highly sophisticated “fake meeting” phishing kit. That goes far beyond traditional lures, enabling webcam capture, Microsoft Defender evasion, and targeted cryptocurrency credential theft. New…
Google Indexed Claude AI Shared Chats Exposing Sensitive User Conversations
Anthropic’s Claude includes a share feature that creates a publicly accessible URL for conversations, allowing users to share AI chats with colleagues, clients, or friends. However, this convenience also brings exposure risks when shared URLs are posted in public forums,…
GitLab RCE Flaws Allow Attackers to Execute Commands via Malicious Jupyter Notebooks
A critical remote code execution (RCE) vulnerability chain in GitLab’s Jupyter Notebook diff renderer. This issue is rooted in two long-standing memory safety vulnerabilities within the Oj Ruby JSON parser. The vulnerabilities impact both GitLab Community Edition and Enterprise Edition…
Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories– SonicWall Zero-Day, Cl0p Windchill Attack, AI-Weaponized Threats, Data Breaches & More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from July 20–24, 2026. It was a heavy week: Cl0p turned internet-exposed Windchill servers into a global data-theft campaign,…
Hackers Use Stealer Logs to Bypass MFA and Launch Ransomware Attacks
Infostealer malware has now become the invisible thread linking petty credential theft to full-blown ransomware campaigns. Attackers no longer bother forcing their way through firewalls when infostealers have already unlocked the front door for them. Documented by DarkOwl, a stealer log…
Google Launches Unified Cryptonym-Based Naming System for Threat Actors
Google Threat Intelligence Group (GTIG) has introduced a unified cryptonym-based naming system for cyber threat actors, aiming to simplify attribution, improve analyst workflows, and eliminate inconsistencies between legacy tracking conventions used across Google’s security teams. The initiative follows the integration…
Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials
A sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials, cookies, payment data, and cryptocurrency wallet information from victims. Documented by Seqrite, the campaign uses two distinct phishing themes that…
Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Hide Attacks
Six federal agencies have updated a joint advisory warning that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. critical infrastructure, manipulating human-machine interface (HMI) displays so operators cannot visually detect the intrusion.…
Cl0p Targets Internet-Exposed Windchill Servers in Global Engineering Data-Theft Campaign
Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM deployments in a global data-theft campaign targeting high-value engineering environments. Observed post-exploitation activity includes filesystem enumeration via files such as “flst.txt,” followed by staging and exfiltration of sensitive engineering…
Foxit PDF Reader Flaw Lets Local Attackers Gain SYSTEM Privileges via DLL Sideloading
A recently disclosed vulnerability in Foxit PDF Reader may allow a local attacker with existing code execution to elevate their privileges to NT AUTHORITY\SYSTEM. This issue, tracked as CVE-2026-57239, affects Foxit PDF Reader installations prior to version 2026.2 and arises…
Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos
An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, admitted to…
SectopRAT Gives Attackers Remote Access to Passwords, Credit Cards, Cookies and Corporate Files
SectopRAT is at the center of a highly targeted malvertising campaign abusing Anthropic’s Claude platform to deliver a stealthy, HVNC‑enabled RAT that gives attackers deep, persistent access to victims’ passwords, credit cards, cookies and corporate files. The artifact masqueraded as…
Golden Chickens Launches Four Modular Malware Families to Steal Chrome Credentials and Hijack Browser Sessions
Golden Chickens, tracked as TAG-195 and also known as Venom Spider, has launched four new modular malware families designed to enhance credential theft, browser session hijacking, and post-exploitation flexibility. The newly identified families TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and…
SourTrade Browser-Assembled Malware Defeats Hash-Based Detection by Design
SourTrade turns the browser itself into a malware build system, deliberately sidestepping the industry’s reliance on hash-based file fingerprints and traditional network-centric detection. SourTrade has been active since late 2024, abusing programmatic ads to reach retail traders and crypto investors…
Australian Energy Giant Origin Confirms Data Breach Exposes Customer Data
Origin Energy Limited has confirmed a cybersecurity incident involving unauthorized access to and disclosure of customer data, representing a significant data security event for one of Australia’s largest energy providers. The company identified the breach on July 22, 2026, and…