Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform

xRAT Malware Targets Windows Users via Fake Adult Game

AhnLab Security Intelligence Center (ASEC) has uncovered a dangerous distribution campaign targeting Windows users through Korean web hard services. Threat actors are leveraging xRAT (QuasarRAT) malware, disguising it as legitimate adult game content to deceive unsuspecting users into downloading and…

Microsoft Introduces Teams External Collaboration Administrator Role

Microsoft is expanding its administrative capabilities in Teams by introducing a new built-in role called Teams External Collaboration Administrator.   This specialized RBAC role enables organizations to delegate external collaboration management without granting full Teams admin permissions.  Rollout Timeline  The new role will begin rolling…

Microsoft Mandates MFA for Microsoft 365 Admin Center Access

Microsoft is tightening security for its cloud customers by making multi-factor authentication mandatory for anyone accessing the Microsoft 365 admin center, effectively ending password-only logins for high-privilege admin portals.   The enforcement will fully kick in on February 9, 2026, following a phased rollout that…

ChatGPT Health: A New Secure Space for Trusted Health and Medical Conversations

ChatGPT Health is launching as a dedicated health-focused version of ChatGPT that combines personalized health data with stronger privacy and security controls to support not replace conversations with clinicians.   The new experience isolates health chats, encrypts data with additional protections, and allows users to securely connect medical…

Cisco ISE Vulnerability Enables Access to Sensitive Data

Cisco has disclosed a new XML External Entity (XXE) vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that could allow authenticated attackers with administrative access to read sensitive data from the underlying operating system.…

New DocuSign-Themed Phishing Scam Delivers Stealth Malware to Windows Devices

New research has uncovered a sophisticated phishing campaign that abuses DocuSign’s brand to deliver Vidar malware and infect Windows systems.   The operation uses a realistic phishing site, a fake signed installer, access-code checks, and timebased execution barriers to evade both users and automated analysis.  DocuSign-themed phishing…

ownCloud Warns Users to Enable MFA After Credential Theft Incident

ownCloud has issued an urgent security advisory urging users to enable Multi-Factor Authentication (MFA) following a credential theft incident reported by threat intelligence firm Hudson Rock. The incident, discovered in January 2026, affected organizations using self-hosted file-sharing platforms, including some…

Three Malicious NPM Packages Target Developers’ Login Credentials

Security researchers at Zscaler ThreatLabz have uncovered three malicious npm packages designed to install a sophisticated remote access trojan (RAT) targeting JavaScript developers. The packages, named bitcoin-main-lib, bitcoin-lib-js, and bip40, collectively registered over 3,400 downloads before being removed from the…

GitLab Patches Multiple Flaws Allowing Arbitrary Code Execution

Linux administrators are being urged to update promptly after disclosures of multiple vulnerabilities in GitLab, including flaws that could enable cross-site scripting, authorization bypass, and denial of service in selfmanaged instances.   The latest patch releases, GitLab 18.7.1, 18.6.3, and 18.5.5, address these security…

Critical n8n Vulnerability Allows Authenticated Remote Code Execution

A critical security vulnerability has been discovered in n8n, the popular workflow automation tool, potentially allowing authenticated attackers to execute arbitrary code on the host server. Identified as CVE-2026-21877, this high-severity vulnerability affects both self-hosted and n8n Cloud instances, posing a…