A growing wave of supply-chain attacks is proving the opposite: attackers are compromising legitimate open-source packages and using trusted update…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
TIKTOUK WordPress Toolkit Could Enable AWS, SMTP and API Credential Theft Attacks
A credential-collection toolkit dubbed TIKTOUK that combines WordPress reconnaissance, exposed-file harvesting, plugin credential decryption, and…
12 Best IAM Solutions Compared (2026): Features & Pricing
For workforce identity, Microsoft Entra ID is the best pick for M365-gravity organizations (bundled economics are decisive) and Okta the best neutral…
Authentication Bypass Successfully Impersonated 95 Users Without Passwords or MFA
A critical authentication bypass that enabled the impersonation of 95 employee accounts, including privileged users, without passwords, multi-factor…
10 Best Container Registry Security Tools Compared (2026): Features & Pricing
The best container registry security stack in 2026 starts free Harbor (CNCF registry with built-in scanning) and Grype/Trivy (open-source scanners) are…
China-Linked TA419 Hackers Target US AI Policy Experts With Credential Phishing Attacks
A China-linked threat actor known as TA419 has targeted U.S. artificial intelligence policy specialists through highly customized credential-phishing…
11 Best PAM Solutions Compared (2026): Features & Pricing
CyberArk remains the best overall PAM platform for depth-driven enterprises, while Delinea is the best pick for usability-led deployments and Teleport the…
12 Best SSO Solutions Compared (2026): Features & Pricing
Microsoft Entra ID is the best SSO for M365-licensed organizations bundled economics end most debates while Okta is the best neutral anchor for mixed-SaaS…
12 Best IGA Tools Compared (2026): Features & Pricing
SailPoint remains the best overall IGA platform for certification depth and AI-assisted reviews, with Saviynt the best converged alternative when…
Windows 11 26H2 Enables Settings Backup by Default for Eligible Devices
Microsoft has automatically enabled Windows settings backup for eligible commercial devices running Windows 11, version 26H2. Microsoft positions this…
Milk Dragon Phishing Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA
A phishing-as-a-service operation dubbed Milk Dragon, also known as NaiLong, is abusing discount-themed Facebook and TikTok posts to steal payment-card…
16-Year-Old Suspected KillSec Ransomware Leader Arrested in International Operation
International law enforcement authorities have arrested three suspects linked to the KillSec ransomware group, including a 16-year-old who is alleged to…
Tren de Aragua ATM Jackpotting Network Linked to $40.7 Million in U.S. Losses
The U.S. Treasury Department has sanctioned a Tren de Aragua (TdA)-linked financial network accused of using malware-driven ATM jackpotting attacks to…
FTC Investigates OpenAI and Anthropic Over Consumer Risks From Advanced AI Models
The U.S. Federal Trade Commission (FTC) has initiated a broad investigation into OpenAI, Anthropic, and other leading artificial intelligence developers…
New Infostealer Can Steal Passwords, Cards, Cookies and Wi-Fi Keys From Windows PCs
A Python-based infostealer builder that enables threat actors to generate customized Windows payloads capable of stealing browser credentials,…
Fortinet FortiMail Path Traversal Flaw Actively Exploited to Compromise Servers
Fortinet has disclosed a critical vulnerability in FortiMail that attackers are actively exploiting to compromise vulnerable email security appliances.…
Apache HTTP Server Flaws Enable Remote Code Execution and Denial-of-Service Attacks
Apache HTTP Server administrators are urged to apply security updates following the disclosure of multiple vulnerabilities affecting Apache HTTP Server…
U.S. Arrests Company Owner Accused of Shipping $300 Million in Restricted GPU Servers to China
U.S. authorities have arrested Greg Lui, a 38-year-old California-based technology company owner, on allegations of orchestrating the illegal export of…
Next.js ImageResponse Vulnerability Lets Remote Attackers Execute Code Through SVG Content
A critical vulnerability in Next.js could let unauthenticated remote attackers execute code on affected servers by supplying crafted input that gets…
TerminalFix Attacks Deploy Lorem Ipsum Loader to Create Covert Tunnels Into Corporate Networks
A newly tracked intrusion set, STAC4924, is using TerminalFix social-engineering lures to deploy the Lorem Ipsum Loader and establish covert reverse…
