Google Chrome has implemented enhanced defenses aimed at disrupting abusive web push notifications that are often used to distribute malware, phishing…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Dark Web Corporate Access Prices Surge 4,055% as Stolen Credentials Flood Cybercrime Markets
Corporate network access is becoming both cheaper to obtain at scale and vastly more valuable at the top end of the criminal market. That contradiction…
Google Chrome 151 Update Fixes 5 High-Severity Use-After-Free Vulnerabilities
Google has released Chrome version 151.0.7922.137/138 for Windows and macOS, and version 151.0.7922.137 for Linux. This update addresses five…
Microsoft SharePoint RCE Vulnerability Lets Remote Attackers Execute Code
A newly disclosed vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-63520, could allow attackers to execute arbitrary code remotely on…
Malicious CCleaner Installer Patches Chrome Security Extension to Deploy Browser Spyware
A counterfeit installer for the widely used PC-cleaning utility CCleaner is being used to compromise Windows systems and deploy a malicious Chrome…
WindRelay Turns Android Phones Into Fake Payment Terminals for Remote Card Fraud
A newly identified Android malware family, tracked as WindRelay, is being used alongside the SpyNote remote-access trojan to convert victims’ phones into…
Microsoft Outlook RCE Vulnerability Lets Attackers Execute Code Remotely
Microsoft has disclosed a new remote code execution (RCE) vulnerability in Outlook, tracked as CVE-2026-70329. They warn that successful exploitation…
The Best Network Traffic Analysis (NTA) Tools, Compared and Priced (2026)
Network traffic analysis spans two buying worlds — ops tools with published price lists and security platforms with quote-only enterprise pricing — and…
Project CAV3RN Uses Google Apps Script and DNS to Hide C2 Traffic in Israeli Cyberespionage Attacks
Project CAV3RN, a modular cyberespionage framework targeting organizations in Israel, has added a sophisticated command-and-control design that…
Windows AFD.sys Zero-Day Exploited by Lazarus Hackers to Gain SYSTEM Access
Lazarus has expanded its long-running Operation Dream Job campaign by exploiting a Windows zero-day vulnerability that grants attackers SYSTEM-level…
Fake Corporate VPN Test Creates Scheduled Task and Downloads Malware on Windows
An advanced recruitment-themed intrusion campaign attributed to UAC-0145, a cluster that includes subcluster UAC-0002, also tracked as Sandworm, APT44 and…
Microsoft Patch Tuesday Update August 2026 Fixes Actively Exploited Windows Zero-Day
Microsoft’s August 2026 Patch Tuesday released fixes for hundreds of vulnerabilities across various products, including Windows, Office, SharePoint,…
DEF CON Attendees Allegedly Jam Plane Wi‑Fi, Launch ‘Evil Twin’ Phishing Attack
A Delta Air Lines flight returning travelers from Las Vegas reportedly became the site of a high-altitude Wi-Fi phishing incident when someone on board…
Zoom Zero-Click ‘Zoomsday’ Flaw Lets Meeting Participants Execute Code on Other Users’ Devices
Zoom has released security updates to address four vulnerabilities that could expose meeting participants to significant attacks, including a zero-click…
One ClickFix Lure Can Give Hackers a Persistent Remote Shell Through New CNCMachineRMS RAT
A ClickFix prompt can end in a remote-access foothold. CNCMachineRMS, an undocumented x64 RAT deployed at the end of a BabaDeda loader chain that turns a…
Docker CopyEscape Vulnerability Enables Host File Overwrite and Root Code Execution
A critical vulnerability in Docker, tracked as CVE-2026-17106 and referred to as “CopyEscape,” allows malicious containers to overwrite files on the host…
Plug & Pwn Attack Exploits Windows PnP to Gain SYSTEM Access With Zero Clicks
Security researchers Alejandro Hernando, also known as 0xedh, and Borja Martínez have unveiled a research project titled “Plug & Pwn.” This project…
LiteLLM Attack Shows AI Infrastructure Is Becoming a Strategic Software Supply Chain Target
The March 2026 compromise of LiteLLM was more than a short-lived malicious PyPI upload. It demonstrated how an upstream breach in developer tooling can…
Copeland XWEB Pro Vulnerabilities Let Attackers Gain Root Access and Manipulate Refrigeration Systems
Security researchers have discovered 23 vulnerabilities in Copeland’s XWEB Pro commercial refrigeration controllers, with 21 rated as high severity. These…
Mozilla Rotates Firefox and Thunderbird GPG Signing Key After Private GitHub Exposure
Mozilla has rotated a GPG signing subkey used to authenticate release artifacts for Firefox and Thunderbird after an unencrypted copy of the previous…