Iran-linked cyberespionage group Mirage Kitten is targeting software engineers with fake recruiter outreach on LinkedIn and job-search platforms. Using…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Critical ArangoDB Bugs Expose Entire Databases and Enable Remote Code Execution as Root
Two critical ArangoDB vulnerabilities can allow unauthenticated attackers to access protected database APIs and, after obtaining valid database access,…
Critical MapLibre GL JS Vulnerability Enables Zero-Click XSS Attacks
MapLibre GL JS users are advised to upgrade their software following the disclosure of an XSS vulnerability, identified as CVE-2026-85061 and documented…
GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GoldFactory has expanded the evasion capabilities of its Gigabud Android banking trojan by deploying Vwork, a weaponized fork of the open-source Shelter…
Windows BitLocker Flaw Lets Attackers Execute Code on Vulnerable Systems
Microsoft disclosed CVE-2026-69449, an Important-severity vulnerability in Windows BitLocker. This issue is classified as a heap-based buffer overflow…
ChatGPT Flaw Could Let Attackers Steal Gmail Data Across User Accounts
Security researchers have revealed a recently patched flaw in ChatGPT’s isolation system that could have allowed attackers to access data from a victim’s…
Hackers Weaponize Agentic AI to Automate Reconnaissance, Exploitation and Post-Exploitation
Threat actors are increasingly operationalizing agentic artificial intelligence to compress cyberattack timelines, automating reconnaissance,…
Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT
Threat actors are actively exploiting a critical vulnerability in FortiGate to deploy PivotC2, a Node. js-based remote access trojan (RAT) designed for…
Windows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM
A newly published proof-of-concept (PoC) called ShieldCrash reveals an unpatched vulnerability in Microsoft Defender that allows a local attacker to gain…
DeepSeek, Alibaba and Chinese AI Firms Extract Billions of Tokens From U.S. AI Models
U.S. intelligence and cybersecurity agencies have accused six China-based AI companies including DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI…
The 12 Best Managed XDR Services, Compared and Priced
Best value overall: Bitdefender — competent managed XDR at pricing that mid-market organizations can approve, which most of this list cannot claim. Best…
The 12 Best Endpoint Detection & Response (EDR) Solutions, Compared and Priced
Best value overall: Microsoft Defender for Endpoint P2 — included in Microsoft 365 E5 and genuinely competitive, which makes its marginal cost zero for a…
The 12 Best Managed Detection & Response (MDR) Services, Compared and Priced
Best value overall: Huntress — published pricing, purpose-built for small business, and genuinely good at the threats that segment faces. Best response…
The 12 Best Extended Detection & Response (XDR) Platforms, Compared and Priced
Best value overall: Microsoft Defender XDR — included in Microsoft 365 E5 and genuinely strong across Microsoft’s own surface, which for most…
The 12 Best Antivirus Software for Mac, Compared and Priced
Best value overall: Bitdefender — leading detection at mid-range pricing with a light footprint. Best free option: Malwarebytes’ scanner, which cleans an…
Fortinet FortiSandbox Vulnerability Allows Unauthenticated Attackers to Access Sensitive Information
Fortinet has disclosed a critical vulnerability involving improper access control in the FortiSandbox web interfaces. This issue could allow an…
Infostealers Target Claude, Cursor, Codex and Other AI Agents to Steal Credentials and Sensitive Data
Information-stealing malware is expanding its collection logic to target locally stored data from AI coding agents, including Claude, Cursor, Codex,…
cPanel EmailTrack SQL Injection Flaw Lets Attackers Execute Code as Root
cPanel has disclosed CVE-2026-67401, a SQL injection vulnerability in its EmailTrack functionality. This flaw allows an authenticated account holder to…
Ivanti Patches 10 EPMM, Neurons for ITSM and Sentry Flaws Enabling RCE and Admin Access
Ivanti has released security updates addressing 10 vulnerabilities in Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry. The vulnerabilities…
Hackers Abuse Google Sheets as C2 in ClickFix Attacks to Steal Cryptocurrency
A cryptocurrency-stealing campaign that abuses Google Sheets and the Google Visualization API as a covert command-and-control channel, delivering…
