Threat actors are impersonating corporate IT helpdesk staff in an active social-engineering campaign that hijacks Microsoft 365 identities, establishes…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
12 Best Application Control & Allowlisting Tools Compared (2026): Features & Pricing
Quick Answer: For dedicated deny-by-default allowlisting, ThreatLocker and Airlock Digital lead in 2026; Microsoft WDAC/AppLocker is the free native…
The 12 Best Mobile Device Management (MDM) Solutions, Compared and Priced
Best value overall: Microsoft Intune — included in Microsoft 365 E3 and E5. Best Apple pricing: Mosyle, with a free tier that genuinely works. Best Apple…
12 Best Patch Management Software Compared (2026): Features & Pricing
Quick Answer: The best patch management software in 2026 depends on your estate: Action1 offers a genuinely free tier for smaller fleets, NinjaOne and…
The 12 Best Unified Endpoint Management (UEM) Solutions, Compared and Priced
Best value overall: Microsoft Intune — included in Microsoft 365 E3 and E5, which means most organizations reading this already own it. Best published…
The 12 Best Mobile Threat Defense (MTD) Solutions, Compared and Priced
Best value overall: Microsoft Defender for Endpoint mobile threat defence is included in appropriate Defender licensing, which means many organizations…
New AI Workflow Identity Hijacking Attack Lets Hackers Exfiltrate Sensitive Data
Security researchers have recently disclosed a new enterprise AI attack technique known as Workflow Identity Hijacking. This method enables external…
Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
Threat actors are increasingly using ClickFix social-engineering lures and search-engine malvertising to deploy MacSync Stealer, a macOS-focused…
Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
Threat actors targeting organizations across Latin America are increasingly embedding commercial large language models (LLMs) into intrusion workflows,…
Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
Threat intelligence firm GreyNoise has identified an AI-driven intrusion campaign, likely orchestrated by a Russian-speaking threat actor, that…
China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
Researcher has discovered a rapidly spreading exploit kit called BlueMoon, which combines vulnerabilities in the Chrome browser with a Windows kernel…
Anthropic Claude AI Models Attack Real Systems During Misconfigured Cybersecurity Tests
Anthropic has reported four cybersecurity evaluation incidents in which pre-release Claude AI models gained unauthorized access to real third-party…
Hackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential-Stealing Malware
A multi-stage malware operation that combines fake Google CAPTCHA prompts, WebDAV-hosted DLL execution, malicious Cloudflare Workers and BNB Smart Chain…
FortiPAM Chrome Extension Vulnerability Lets Malicious Sites Control Browser Proxy and Record Tabs
A critical vulnerability has been identified in the Fortinet FortiPAM Chrome extension that could allow a malicious website to manipulate browser proxy…
SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise
Austin, Texas / USA, September 9th, 2026, CyberNewswire Ninety-five percent of organizations believe they have visibility into their AI and machine…
Iran-Linked Hackers Use Fake LinkedIn Job Offers to Deploy NodeRabbit and PollCat RATs
Iran-linked cyberespionage group Mirage Kitten is targeting software engineers with fake recruiter outreach on LinkedIn and job-search platforms. Using…
Critical ArangoDB Bugs Expose Entire Databases and Enable Remote Code Execution as Root
Two critical ArangoDB vulnerabilities can allow unauthenticated attackers to access protected database APIs and, after obtaining valid database access,…
Critical MapLibre GL JS Vulnerability Enables Zero-Click XSS Attacks
MapLibre GL JS users are advised to upgrade their software following the disclosure of an XSS vulnerability, identified as CVE-2026-85061 and documented…
GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GoldFactory has expanded the evasion capabilities of its Gigabud Android banking trojan by deploying Vwork, a weaponized fork of the open-source Shelter…
Windows BitLocker Flaw Lets Attackers Execute Code on Vulnerable Systems
Microsoft disclosed CVE-2026-69449, an Important-severity vulnerability in Windows BitLocker. This issue is classified as a heap-based buffer overflow…