Okta’s Auth0 line is the best CIAM for most product teams the benchmark ecosystem with the procurement fast-pass while Amazon Cognito and Microsoft Entra…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
12 Best Passwordless Authentication Solutions Compared (2026): Features & Pricing
Microsoft is the best passwordless starting point for most workforces passkeys and Windows Hello ride licensing you already own while HYPR leads the…
GlassWorm Supply Chain Attack Hides Malware Inside VS Code Color Themes
A GlassWorm-linked software supply chain campaign has abused seemingly harmless Visual Studio Code color themes to distribute malicious loaders across the…
Attackers Abuse Legitimate ScreenConnect Client in Phishing Campaign to Gain Remote Access
Threat actors are increasingly bypassing conventional malware detection by abusing legitimate remote monitoring and management software instead of…
Microsoft Releases Emergency Exchange Server Update to Fix CVE-2026-96940
Microsoft has released a revised security update package for on-premises Exchange Server, dated September 2026, which includes a fix for CVE-2026-96940.…
Google PageBreak AI Agent Finds Over 500 XSS Vulnerabilities Across Its Web Applications
Google has disclosed that PageBreak, an internal AI security agent developed by its Product Security team, has identified and validated more than 500…
South Korea Orders Investigation Into AI-Powered Cyberattacks on Major Banks
South Korean President Lee Jae Myung has ordered a comprehensive investigation into a series of data breaches impacting major banks and other financial…
Citrix NetScaler SAML Vulnerability Enables Unauthenticated Remote DoS Attacks
Citrix has released emergency security updates to address a high-severity memory overflow vulnerability in NetScaler ADC and NetScaler Gateway. This flaw,…
Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices
A newly identified IoT botnet, Cling, disguises its command-and-control communications as legitimate STUN traffic, including packets that appear to…
Microsoft Warns ClickFix Attacks Use Fake CAPTCHA Lures to Execute Malicious Commands
Microsoft Threat Intelligence has identified a ClickFix campaign in which compromised websites use fake CAPTCHA-style verification prompts to trick…
AWS AI Agent Vulnerabilities Let Attackers Bypass Authentication and Steal Credentials
AWS has released security fixes for four vulnerabilities affecting its open-source Loom AI agent orchestration platform and Amazon SageMaker Unified…
Critical GitLab AI Gateway Flaw Lets Attackers Execute Arbitrary Commands
GitLab has issued emergency security updates for a critical vulnerability in its Self-Hosted AI Gateway that could allow authenticated attackers to…
Citrix NetScaler Appliances Reboot Repeatedly After 0-Day Security Update
Citrix NetScaler administrators report repeated appliance crashes and forced reboots after deploying emergency updates for recently disclosed zero-day…
Sony PS5 Relapse Jailbreak Exploit Uses JSC Memory Corruption and Kernel UAF
A newly released PlayStation 5 jailbreak chain, called Relapse, targets PS5 and PS5 Pro consoles running firmware versions 7.00 through 13.60. This…
Safari History Database Tags Can Reveal Users’ Browsing Themes in Forensic Investigations
Safari’s History database contains a lesser-known tagging artifact that can help investigators infer a user’s browsing themes. While this feature is not…
Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root
Two critical vulnerabilities in the open-source Zammad helpdesk and ticketing platform can be exploited together, enabling attackers to achieve remote…
Exposed Hacker Server Reveals Toolkit Used in Viva Aerobus-Linked Intrusion
A publicly exposed attacker staging server has provided a rare, detailed view of a Microsoft SQL Server-focused intrusion linked to a Viva Aerobus-side…
Capacitor Vulnerability Lets Remote Content Run With Full App Origin Trust
A critical vulnerability in Capacitor, identified as CVE-2026-103922, could allow attacker-controlled remote content to execute within vulnerable Android…
OpenAI Blocks 15,000 Requests Trying to Extract Protected Model Reasoning
OpenAI has disrupted a coordinated campaign to extract protected internal reasoning from its AI models on a large scale. The company took action against…
Multiple cPanel & WHM Vulnerabilities Enable Root Code Execution and Admin Session Hijacking
cPanel has released security updates to address three vulnerabilities in cPanel & WHM that could allow attackers to hijack WHM administrator sessions or…
