Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week
Microsoft Patches 973 CVEs, Claude Agents Automate Attacks, China Chains Chrome Zero-Day, Cisco FMC Exploited & More. Welcome to this week’s edition of…
WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites
Two critical unauthenticated vulnerability chains in the widely used The Events Calendar WordPress plugin could allow attackers to execute code and fully…
Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Rootkit
A Chinese-speaking threat actor known as Red Heron has exploited a critical remote code execution (RCE) vulnerability in Gitea to steal private source…
Telegram Desktop XSS Vulnerability Lets Attackers Steal Entire Chat Histories
A stored cross-site scripting (XSS) vulnerability in Telegram Desktop could enable attackers to steal the contents of exported chat histories by embedding…
Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds
A threat actor exploited a critical pre-authentication remote code execution vulnerability in marimo to harvest AWS credentials, retrieve an SSH private…
DDRop Attack Forces Intel TDX Confidential VMs Into Debug Mode and Exposes Memory
A newly disclosed hardware attack dubbed DDRop can undermine Intel Trust Domain Extensions (TDX) by manipulating DDR5 memory traffic, allowing an attacker…
Linux Kernel ZcopyReaper Vulnerability Lets Local Attackers Gain Root Privileges
Security researchers have disclosed a local privilege escalation vulnerability in the Linux kernel related to the Reliable Datagram Sockets (RDS)…
Microsoft Offers $60,000 Bounty for Critical Cross-Tenant Vulnerabilities
Microsoft has expanded its incentives for security researchers focusing on Dynamics 365 and Power Platform, offering rewards ranging from $1,250 to…
Hackers Deploy Agentic AI to Automate Exploitation and Mass Credential Harvesting
Threat actors are moving from using artificial intelligence as a productivity aid to deploying autonomous agentic systems that can execute major portions…
11 Best CSPM Tools Compared (2026): Features & Pricing
Quick Answer: Wiz leads agentless attack-path CSPM; Prisma Cloud leads breadth; Microsoft Defender for Cloud offers a free foundational tier plus…
12 Best CNAPP Platforms Compared (2026): Features & Pricing
Quick Answer: CNAPP quotes swing 2–3× on identical estates because “workload” definitions differ. Microsoft Defender for Cloud is the only major with…
12 Best Enterprise Browsers Compared (2026): Features & Pricing
Quick Answer: Island and Palo Alto (Talon) lead purpose-built enterprise browsers; Chrome Enterprise (free Core tier) and Edge for Business (bundled)…
12 Best CWPP Solutions Compared (2026): Features & Pricing
Quick Answer: Sysdig (built on open-source Falco) leads container/K8s runtime depth; Prisma Cloud leads workload breadth including serverless; Aqua leads…
Nintendo Switch QR Code Vulnerability Lets Nearby Attackers Execute Unauthorized Code
Nintendo released system version 23.0.0 to address CVE-2026-82079, a vulnerability in the Nintendo Switch’s local wireless networking that could turn the…
12 Best Browser Isolation Solutions Compared (2026): Features & Pricing
Quick Answer: Zscaler and Cloudflare lead RBI delivered inside SSE platforms; Menlo Security leads isolate-everything efficacy; Garrison (Everfox) owns…
Hackers Turn Windows Shadow Copies Into a Tool for Credential Theft and Ransomware
Threat actors are increasingly weaponizing Microsoft’s Volume Shadow Copy Service (VSS) for two distinct objectives: removing recovery options before…
UK Government Enables Passkey Login for 23 Million Users to Fight Phishing Attacks
The UK government has started implementing passkey authentication for GOV. UK One Login,UK One Login, providing over 23 million users with a faster and…
Mass Scanning Targets Exposed Vite Servers to Steal AWS Keys and Azure Tokens
In August 2026, automated threat activity targeting exposed Vite development servers increased significantly. Attackers aimed to extract cloud…
Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor
Threat actors exploited the critical FortiGate SSL-VPN vulnerability CVE-2024-21762 to target the Thai broadband provider Triple T Broadband (3BB). They…
