A critical one-click vulnerability in Microsoft Copilot Personal, tracked as CVE-2026-24301 and dubbed CoSnitch. This flaw could enable an attacker to…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Projextor Abuses Cross-Platform Electron Framework to Conceal Malware Activity
Threat actors behind the Projextor campaign are abusing Electron-based productivity applications to conceal malware-like capabilities behind fully…
Critical MLflow SSRF Flaw Exploited in the Wild
A critical unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, tracked as CVE-2026-64849, is being actively exploited within hours…
OpenAI Warns Organizations to Automate Cybersecurity as AI-Powered Attacks Accelerate
OpenAI has issued a warning that organizations need to quickly automate core cybersecurity functions as increasingly advanced AI systems make it easier…
BTMob Uses Custom Phishing Apps to Turn Android Users Into Remote-Controlled Fraud Victims
BTMOB has evolved beyond a conventional Android banking trojan into a turnkey fraud platform that lets criminals build branded phishing apps, remotely…
French Tax Authority Cyberattack Exposes Tax Data of 678,000 Individuals and Businesses
France’s Directorate General of Public Finances (DGFiP) has reported a cyberattack that resulted in unauthorized access to and extraction of tax and…
Asruex Trojan Found Embedded in GEEKOM Mini PC Realtek Ethernet Driver
GEEKOM has confirmed that a malware-flagged Realtek LAN driver package was previously accessible through an outdated support page for its mini PCs,…
Apple Addresses 28 Security Flaws Across macOS, iOS, and iPadOS
Apple has released security updates for iPhones, iPads, and Macs to address 28 vulnerabilities across its latest operating systems. These updates, issued…
JWR Phishing-as-a-Service Kit Uses WebSockets and AES to Run Real-Time Banking Fraud
JWR, an undocumented phishing-as-a-service (PhaaS) framework that turns conventional credential theft into an operator-led, real-time banking and payment…
AI Agents Gain Unintended Internet Access During Cybersecurity Evaluations
AI security evaluation firm has disclosed that several frontier AI models unintentionally accessed and acted against real internet-connected systems…
CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.…
Kimsuky Uses Local AI Development Environment to Expand Cyber Espionage Tooling in Operation GitPower
North Korean state-backed threat actor Kimsuky is extending its established espionage playbook with locally hosted artificial intelligence tooling,…
Octagon Android Bot Uses Hidden VNC and Accessibility Overlays to Steal Crypto Wallet Credentials
Octagon, a previously undocumented Android banking and cryptocurrency fraud platform marketed as malware-as-a-service by a Russian-speaking actor using…
Microsoft Adds Customizable Context Menu to Windows 11 File Explorer
Microsoft has introduced a redesigned and customizable context menu for the Windows 11 File Explorer, along with significant improvements in reliability…
C2Looper v2 Uses GitHub Repositories as Full Command-and-Control Infrastructure.
C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor. A newer build, internally identified as version 2, replaces…
GitLab Patches Multiple Security Flaws in CE and EE With 19.2.4 Update
GitLab has released critical security updates for both the Community Edition (CE) and the Enterprise Edition (EE), addressing two GraphQL-related…
Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed Phrases
Operation ASTERIX, a cryptocurrency fraud campaign that combined account enumeration, branded phishing, targeted voice calls, and trojanized wallet…
Hackers Turn Claude Code and Codex Into AI-Powered Tools for Credential Theft and Cloud Attacks
Threat actors are increasingly using coding assistants as operational tools. Detailed research from Gambit Security highlights three campaigns where…
Shadow hVNC Malware Kit Gives Hackers Hidden Windows Desktop for Covert Remote Control
A newly advertised malware-as-a-service toolkit named Shadow hVNC combines browser credential theft, hidden virtual desktop control, reverse proxying, and…
VMware vCenter RCE Gives Attackers a Path From One Appliance to Entire Virtual Infrastructure
A critical VMware vCenter vulnerability is being actively exploited in a fast-moving campaign that turns a single exposed management appliance into a…