A security researcher has revealed a critical design flaw in HP ThinPro versions 8 and 9, which allows attackers with physical access to a thin client’s…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
WordPress Supply Chain Attack Exploits BdThemes Plugins to Create Rogue Admin Accounts and Install Webshells
A supply chain compromise affecting multiple BdThemes WordPress plugins has allowed attackers to hijack administrator sessions, create unauthorized admin…
Apple Private Cloud Compute Path Traversal Flaw Lets Attackers Write Files as Root
Security researcher Drinor Selmanaj has disclosed a path traversal vulnerability (CVE-2026-20685) in Apple’s Private Cloud Compute (PCC) that allows a…
Sophos Warns Unprotected Endpoints Let Interlock Credential Theft Go Undetected
Interlock ransomware incident that shows how unprotected endpoints can give attackers enough time to steal credentials, establish persistence, and reach a…
Ransomware Attackers Compromise Multiple Employees Inside the Same Company
Ransomware operations are increasingly targeting the people behind critical business processes, not just privileged IT administrators. Over a one-month…
Claude Opus 5 Most Resistant to Indirect Prompt Injection Attacks, With Just 2% Success Rate
Anthropic’s Claude Opus 5 has significantly reduced the likelihood of a successful indirect prompt injection (IPI) attack, bringing it down to 2% over 15…
North Korean Hackers Explore AI Transcription for Stolen Calls and Meetings
North Korea-linked Kimsuky operators are expanding their artificial intelligence capabilities, with newly observed evidence showing experimentation with…
Claude-Powered AI Agent Exploits API Authorization Flaw to Hack Gym Booking System
An Australian AI agent powered by Anthropic’s Claude reportedly exploited an authorization flaw in a gym booking platform, allowing it to book classes…
Claude Code Child Process Can Read Its Own OAuth Token From macOS Keychain
A macOS Keychain implementation weakness in Anthropic’s Claude Code CLI could allow any process running as the logged-in user including a Claude…
Payroll Pirates Abuse Microsoft Graph to Find HR and Finance Staff After Account Compromise
A widespread phishing operation that compromises Microsoft 365 accounts through adversary-in-the-middle (AiTM) infrastructure, then uses Microsoft Graph…
New CSS Bomb Attacks Let Hackers Steal Passwords and Tokens From Webmail Users
Security researcher Gareth Heyes has revealed techniques for webmail attacks that exploit HTML and CSS, the technologies used to format emails, to…
Metabase 0-Day Flaw Exploited in Attack to Inject Arbitrary SQL and Steal Database Credentials
Metabase has reported a critical security incident involving a zero-day vulnerability that is actively being exploited. This vulnerability affects…
Levi Strauss Hit by Cyberattack, Hackers Use Social Engineering to Steal Corporate Data
Levi Strauss & Co. has reported a cybersecurity incident in which an unauthorized third party used social engineering techniques to compromise three…
The Best Intrusion Detection & Prevention (IDS/IPS) Tools, Compared and Priced (2026)
This market runs from $0 to seven figures, and the free options power half the paid ones — so price comparisons here reward honesty. The verdict up front:…
Cybersecurity Newsletter Weekly – Top 50 Biggest Cybersecurity Stories – $70M Bitcoin Heist,Google Passkey Theft, Copilot CEO Fraud,Chrome 151 & Claude Exploits & More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from…
WordPress XSS2Shell Flaw Enables Attackers to Achieve Remote Code Execution
WordPress has patched a high-severity vulnerability, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that begins as an unauthenticated cross-site…
18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Root and Escape Containers
SCTPhantom, tracked as CVE-2026-64564, is a high-severity Linux kernel use-after-free vulnerability in the Stream Control Transmission Protocol (SCTP)…
Bugtraq Is Back: The Original Full Disclosure Mailing List Is Live Again
Sophia Antipolis, France, August 7th, 2026, CyberNewswire At DEF CON 34 in Las Vegas, security researcher Jonathan Brossard, known in the community as…
Fake Zoom Installer Uses .NET Downloader to Deploy Overlord RAT on macOS
A cross-platform malware campaign that disguises itself as a legitimate Zoom installer to deploy Overlord, an open-source remote access trojan (RAT), on…
Critical macOS RCE Vulnerability Allows Attackers to Gain Root Access Without Password
Apple has shipped emergency macOS updates to close a critical vulnerability in Screen Sharing, tracked as CVE-2026-65400, which allows unauthenticated…