Apache HTTP Server administrators are urged to apply security updates following the disclosure of multiple vulnerabilities affecting Apache HTTP Server…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
U.S. Arrests Company Owner Accused of Shipping $300 Million in Restricted GPU Servers to China
U.S. authorities have arrested Greg Lui, a 38-year-old California-based technology company owner, on allegations of orchestrating the illegal export of…
Next.js ImageResponse Vulnerability Lets Remote Attackers Execute Code Through SVG Content
A critical vulnerability in Next.js could let unauthenticated remote attackers execute code on affected servers by supplying crafted input that gets…
TerminalFix Attacks Deploy Lorem Ipsum Loader to Create Covert Tunnels Into Corporate Networks
A newly tracked intrusion set, STAC4924, is using TerminalFix social-engineering lures to deploy the Lorem Ipsum Loader and establish covert reverse…
Axios Flaws Let Attackers Bypass Proxy Controls and Trigger SSRF Attacks
Axios maintainers have disclosed several high-severity security vulnerabilities that could allow attackers to bypass proxy and DNS controls in server-side…
China-Nexus Hackers Compromise 350 Systems Across Asia With New Antino Backdoor
A China-nexus cyber-espionage campaign that compromised approximately 350 endpoints across Asia using a previously undocumented Rust-based Windows…
CloudSyncD Uses Invisible Unicode to Hide Phished Mac Passwords in Plain Sight
A new macOS backdoor, tracked as CloudSyncD, that masquerades as a Zoom installer and uses invisible Unicode characters to conceal a victim’s phished…
Multiple TeamViewer Vulnerabilities Enable RCE, Access Control Bypass and Privilege Escalation
TeamViewer has issued security bulletin TV-2026-1010 to address five high-severity vulnerabilities found in the TeamViewer Full Client, Host, and related…
Researchers Find 543,699 Active Credentials Leaked in Public GitHub Repos
Security researchers have identified 543,699 unique credentials that remain valid despite being exposed in public GitHub repositories. This highlights a…
SC WordPress Malware Rebuilds Itself After Removal Using Database and Memory Persistence
A newly analyzed WordPress malware family, tracked as SC for the “SC_” markers embedded in its injected code, uses a self-healing persistence mesh that…
HPE Instant On AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands
HPE has released security updates for its Networking Instant On access points after identifying 18 vulnerabilities, including several critical flaws that…
Critical Cisco SD-WAN Vulnerability Lets Remote Attackers Bypass Authentication as Admin
Cisco has disclosed a critical authentication bypass vulnerability in the Catalyst SD-WAN Manager, which could allow unauthenticated remote attackers to…
Multiple ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules and Execute Malicious Requests
OWASP ModSecurity has disclosed multiple vulnerabilities that could let attackers bypass web application firewall rules, evade request and response…
Hackers Hide Microsoft Defender Exclusions From Admins to Evade Antivirus Scans
Threat actors are increasingly abusing Microsoft Defender Antivirus exclusions to keep malicious files outside the reach of endpoint scans, and a…
Zimbra Vulnerability Exploited to Gain Root Access and Steal Mailbox Authentication Secrets
An active exploitation of CVE-2026-73570, a high-severity unauthenticated OS command-injection vulnerability in Zimbra Collaboration Suite. Attackers used…
New 2CLoader Malware Uses Anti-VM and API Hooking to Deliver Vidar and Remus Stealers
A new Windows malware loader, tracked as 2CLoader, that combines extensive anti-analysis logic, indirect system calls, API tampering, and flexible…
AI Agents Expose 13,000+ Developer Screenshots Across 900+ GitHub Repositories
AI coding agents have inadvertently exposed over 13,000 internal developer screenshots in public GitHub repositories. These exposures potentially revealed…
FBI’s Operation Blackout Takes Down Overseas Scammers Targeting Americans
The FBI has intensified its global effort to crack down on large-scale scam operations targeting Americans. Director Kash Patel announced that Operation…
RedFlick Uses Scheduled Tasks and Password-Protected Archives to Deploy CosmicPulse Backdoor
Russian state-linked threat actor Star Blizzard has expanded its cyberespionage operations in 2026 with a phishing and malware-delivery technique tracked…
PaperPhone Cluster Shows How One Bot Operator Can Look Like Thousands of Mobile Users
A large-scale scraping cluster dubbed PaperPhone, exposing how one operator can manufacture the appearance of tens of thousands of legitimate mobile users…
