Microsoft Threat Intelligence has discovered NeedyMantis, a modular post-compromise malware framework that targets specific industries, including…
Tag: GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused…
Pentagon Data Breach Exposes Sensitive Data of Over 3 Million People
The Pentagon has confirmed a major data breach involving the Defense Manpower Data Center (DMDC) information system, exposing sensitive personal…
Researchers Found a Windows RAT That Turns Victims’ Screens Into Live Streams
A previously undocumented Windows remote access trojan capable of turning an infected victim’s display into a live stream for its operators. Dubbed…
File Notification Attacks Let Hackers Track Keystrokes and Website Visits on Linux, Windows and macOS
Researchers have disclosed a new class of cross-platform side-channel attacks that exploit file-notification mechanisms in Linux, Windows, macOS, and…
Malicious VPN Extensions Turn Browser Users Into Residential Proxy Servers
A cluster of 31 Russian-language Chrome extensions, marketed as “VPN for X” tools, has been discovered using a shared codebase to redirect browser traffic…
Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data
An internet-exposed cybercrime server linked to the BlackHatSect0r and DXQRTXX personas, revealing an operational environment that allegedly combined…
OpenAI Agent Swarm Used Nearly 1 Million URLs to Hack Hugging Face
A newly released forensic investigation has reconstructed how a swarm of about 700 OpenAI evaluation agents allegedly used nearly one million chained URLs…
NVIDIA Launches In-Silicon Security Platform to Monitor and Control Autonomous AI Agents
NVIDIA has launched its Open Agent Safety Platform, a security architecture designed for out-of-band monitoring, runtime policy enforcement, and…
Oracle PeopleSoft Servers Targeted Again as ShinyHunters Expands Extortion Operations
The ShinyHunters-linked threat cluster tracked as UNC6240 has renewed mass exploitation of Oracle PeopleSoft servers vulnerable to CVE-2026-35273.…
670 Jev Domains Registered After Launch as Fake AI Marketplaces Target Users
A surge of lookalike domains targeting users of TypeSafe AI’s newly launched Jev decision model, with roughly 670 “jev”-branded domains obtaining TLS…
Microsoft Entra TrustSink Attack Uses Rogue MFA Provider to Steal Passwords
TrustSink, a post-compromise credential-phishing technique that abuses Microsoft Entra External Authentication Methods (EAMs) to place a rogue password…
Lumma, RedLine and Vidar Infostealers Fuel Cloud Credential Theft Campaigns
Infostealer malware is increasingly becoming the bridge between a compromised developer workstation and an enterprise cloud environment, with Lumma,…
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data…
Kiteworks Urges Customers to Shut Down Servers Over Potential Zero-Day Threat
Kiteworks has lifted its emergency shutdown recommendation after advising customers to temporarily take their systems offline in response to credible…
New Python Infostealer Targets 17 Browsers to Steal Passwords, Cards and Session Cookies
A Python-based information stealer that targets data from 17 Chromium-based browsers, alongside Firefox, to harvest saved credentials, payment-card…
12 Best Cloud Compliance Tools Compared (2026): Features & Pricing
For most teams facing an audit, Vanta is the best overall compliance automation platform, with Drata the closest rival choose between them on integrations…
12 Best Cloud Encryption Solutions Compared (2026): Features & Pricing
For most estates, native KMS is the best starting point AWS KMS, Azure Key Vault, and Google Cloud KMS are usage-priced, deeply integrated, and publish…
ViewSonic vCast Vulnerabilities Let Attackers Gain Full Device Control Without Authentication
The CERT Coordination Center (CERT/CC) has revealed a chain of three vulnerabilities in ViewSonic’s vCast software that could enable unauthenticated…
11 Best GCP Security Tools Compared (2026): Features & Pricing
Securing Google Cloud starts with Security Command Center Standard included with every org and the best free first move while Wiz is the best third-party…
