A critical Docker vulnerability tracked as CVE-2026-17106, also known as CopyEscape, could allow a malicious container to overwrite files on the host…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Attackers Target Developer Credentials to Expand Supply Chain Intrusions Beyond Source Code
Software supply chain attacks are increasingly evolving into cloud identity breaches, as attackers weaponize trusted packages to steal credentials from…
Claude Compliance API Lets Security Teams Monitor Chats, Files and Agent Activity
Anthropic has enhanced enterprise security visibility for its AI assistant, Claude, with the Compliance API. This feature lets organizations extract data…
Critical MikroTik RouterOS Vulnerability Exposes Devices to Remote Code Execution
A critical vulnerability in MikroTik RouterOS could allow unauthenticated remote attackers to execute code on vulnerable devices or trigger a…
Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Bug
Google has released Chrome version 154 for desktop platforms, addressing 32 security vulnerabilities, including a critical buffer overflow flaw in the…
12 Best IGA Tools in 2026: The Ranked Buyer’s Guide
Identity governance and administration has become essential as organizations manage employees, contractors, service accounts, machine identities, and AI…
Hackers Abuse MSP360 and ScreenConnect RMM Tools for Persistent Access and Credential Theft
The phishing campaigns that weaponize legitimate remote monitoring and management software to establish persistent access and support credential theft on…
Attackers Use PaperCut RCE Chain to Steal Tokens and Access Domain Controller
Threat actors exploited a chained pair of PaperCut MF zero-day vulnerabilities to compromise an education-sector environment, steal a domain-privileged…
RSA Agent ID Secures AI Agents and MCP Servers With Identity-Based Access Controls
RSA has launched RSA Agent ID, an identity security platform that discovers, secures, and governs AI agents and Model Context Protocol (MCP) servers in…
Hackers Exploit Citrix NetScaler Zero-Day to Gain Root Access and Deploy Web Shells
Threat actors are actively exploiting a critical zero-day vulnerability in Citrix NetScaler, identified as CVE-2026-88772, to gain unauthenticated…
OperTraitor Finds Kubernetes Operators With Cluster-Wide Secret Access and Admin Paths
OperTraitor, an open-source, LLM-powered engine that identifies Kubernetes operators whose RBAC (Role-Based Access Control) privileges exceed their…
Linux Kernel CVE-2026-72018 Flaw Lets Local Attackers Gain Root Access
A high-severity Linux kernel vulnerability, tracked as CVE-2026-72018, lets a local attacker with CAP_NET_ADMIN privileges escalate to root. This…
Hackers Target 5,700 Microsoft 365 Accounts Using Forgotten Service Accounts With No MFA
Threat actors have targeted more than 5,700 Microsoft 365 accounts across 28 tenants in a password-spraying campaign that successfully breached seven…
Storm-3068 Hijacks Azure DevOps Pipelines to Steal Kubernetes Credentials After Account Takeover
Microsoft has detailed a cloud-focused intrusion attributed to Storm-3068, in which attackers turned a compromised user account into a launch point for…
Unsloth Fixes Arbitrary Code Execution Flaw Triggered by Malicious Hugging Face Models
Unsloth has addressed a critical arbitrary code execution vulnerability in its Studio web interface. This flaw allowed a malicious Hugging Face model…
Android Malware Turns Gemini AI Into an Assistant for On-Device Attacks
A newly documented Android banking trojan named RATHat is demonstrating how generative AI can be operationalized inside mobile malware. The threat uses…
SectopRAT Malware Hides in Legitimate Software to Steal Browser Credentials and Crypto Wallets
A newly analyzed SectopRAT campaign demonstrates how threat actors can weaponize trusted application components to conceal a full-featured remote access…
OpenSSL High-Severity Flaw Lets Attackers Leak Heap Memory in Plaintext
OpenSSL has announced a high-severity vulnerability in its Datagram Transport Layer Security (DTLS) implementation that could allow a remote peer to read…
FBI, Dutch Police Take Down Alleged ShinyHunters Cybercrime Group Leader
The FBI and Dutch National Police have announced the arrest of a 24-year-old man from Amsterdam who is suspected of playing a major role in the…
OpenAI Launches Codex Security Cloud for Always-On Application Security Scanning
OpenAI has expanded its Codex platform with Codex Security Cloud, a cloud-hosted application security feature that continuously analyzes GitHub…
