Zscaler has addressed several vulnerabilities in its Client Connector endpoint application that could allow an unauthenticated, unprivileged attacker to…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
ASOS Warns Customers of Data Breach Following Credential-Based Account Takeovers
ASOS has started notifying affected customers in the U.S. after detecting unauthorized access to accounts linked to login credentials obtained from…
91 Spring CVEs Impact Over 209,000 Software Components Across the Supply Chain
Broadcom has disclosed 91 Common Vulnerabilities and Exposures (CVEs) affecting the Spring Framework and related projects, triggering a software supply…
PavinLoader Uses ClickFix and Fake Downloads to Deploy Amatera Stealer via Blockchain C2
PavinLoader, a multi-stage .NET malware loader, operating across ClickFix, fake software-download, and malicious game campaigns. The activity shows how…
Anthropic Expands Claude MCP Security With Enterprise-Managed Identity Controls
Anthropic has expanded Claude Enterprise’s Model Context Protocol (MCP) security capabilities with enterprise-managed authorization, allowing…
Critical miniOrange SAML SSO Flaws Let Attackers Take Over WordPress Admin Accounts
Two critical vulnerabilities have been identified in the miniOrange SAML 2.0 Single Sign-On WordPress plugin, which could allow unauthenticated attackers…
Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover
Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that allows an unauthenticated remote attacker to bypass a key safeguard…
Hackers Place Fake Codex Download Above Legitimate OpenAI Result to Infect Mac Users
Threat actors are using sponsored Google Search ads to place a fake OpenAI Codex download page above the legitimate result, steering macOS users into…
EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords
EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens.…
TP-Link Archer Command Injection Flaws Enable Root-Level Code Execution
TP-Link has released firmware updates for three Archer router models due to the discovery of multiple command injection vulnerabilities. These…
Fake GTA 6 Demo Sites Spread Vidar Stealer to Hijack Authenticated Browser Sessions
Cybercriminals are capitalizing on renewed interest in Grand Theft Auto VI by pushing fake Rockstar Games pages that advertise a non-existent GTA 6 demo…
WeedHack Malware Spreads Through SEO-Poisoned Minecraft Sites Despite C2 Disruption
A renewed distribution wave for the WeedHack malware-as-a-service operation, with threat actors continuing to push infected Minecraft clients and mods…
Hackers Exploit Critical Oracle HTTP Server Flaw to Access and Modify Sensitive Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle HTTP Server to its Known Exploited…
Microsoft Teams New Security Policy Lets Admins Automatically Block Meeting Bots
Microsoft is introducing a new Microsoft Teams meeting policy that automatically blocks identified external bots. This aims to address growing concerns…
5 Palo Alto GlobalProtect Flaws Let Attackers Gain SYSTEM/Root Access and Steal AD Passwords
Security researcher Martijn van Ramesdonk has disclosed five vulnerabilities affecting Palo Alto Networks’ GlobalProtect, an enterprise VPN and endpoint…
Google and Bing Search Results Used to Deliver Hidden Banking Phishing Pages
Threat actors are increasingly using Google and Bing as phishing delivery channels, employing a cloaking technique that presents harmless pages to…
North Korean Hackers Hide AnyDesk on Victim PCs to Maintain Secret Remote Access
North Korea-linked Kimsuky operators have targeted organizations in South Korea and Japan with spear-phishing campaigns that install and conceal AnyDesk,…
Hackers Impersonate Security Staff to Steal Credentials in ReliaQuest Social Engineering Attack
ReliaQuest has reported a targeted social engineering attack in which threat actors impersonated company security personnel, used a spoofed domain, and…
Mysterious Ox Alpha Stealth AI Model Emerges for Coding and Agentic Work
A newly discovered AI system called Ox Alpha has emerged on OpenRouter, sparking widespread speculation within the AI community regarding its origin,…
Zimbra Collaboration Suite Flaw Actively Exploited to Execute Arbitrary Commands
Threat actors are actively exploiting a critical operating system command injection vulnerability in Zimbra Collaboration Suite, identified as…
