❌

Normal view

There are new articles available, click to refresh the page.
Yesterday β€” 22 July 2026Hacking and InfoSec

Malicious NuGet Typosquat Targets Digitain Betting Platform and Rigs Game Results

22 July 2026 at 13:21

JFrog Security Research has disclosed a precision supply-chain attack in which a typosquatted NuGet package, Newtonsoftt.Json.Net, impersonated the ubiquitous Newtonsoft.Json library while secretly rigging game outcomes at online betting operator Digitain. Unlike typical info-stealers that harvest credentials indiscriminately, this trojan functions as a fully operational JSON library for every host except its single intended target. […]

The post Malicious NuGet Typosquat Targets Digitain Betting Platform and Rigs Game Results appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases

By: Divya
22 July 2026 at 08:41

Meta has addressed a critical vulnerability involving broken access control that exposed sensitive customer support data across multiple services. This issue highlighted systemic weaknesses in authorization within their shared backend infrastructure. The flaw, categorized as an Insecure Direct Object Reference (CWE-639) combined with Broken Access Control (CWE-284) and Missing Authorization (CWE-862), allowed unauthorized users to […]

The post Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Apple Fixes Hide My Email Vulnerability That Exposed Users’ Real Email Addresses

By: Divya
22 July 2026 at 08:15

Apple has addressed a year-old vulnerability in its β€œHide My Email” privacy feature, which could expose users’ real email addresses. This incident has already led to a class action lawsuit and increased scrutiny of Apple’s privacy claims. Hide My Email, part of the paid iCloud+ subscription, allows users to generate random alias addresses that forward […]

The post Apple Fixes Hide My Email Vulnerability That Exposed Users’ Real Email Addresses appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks

By: Divya
22 July 2026 at 07:33

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has classified a critical SQL injection vulnerability in WordPress Core, tracked as CVE-2026-60137, as one of its Known Exploited Vulnerabilities (KEV) due to its active exploitation in real-world attacks. This vulnerability affects the core functionality of WordPress when themes or plugins fail to properly validate untrusted input […]

The post CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws

By: Divya
22 July 2026 at 06:32

Zimbra has released version 10.1.20 of its Collaboration Suite (ZCS) to address multiple high-severity security vulnerabilities. This release includes a critical command injection flaw in the SNMP monitoring component and several cross-site scripting (XSS) issues affecting the Classic Web Client. The update, published on July 20, 2026, provides a permanent fix for a previously disclosed […]

The post Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims

By: Divya
22 July 2026 at 06:18

The Federal Bureau of Investigation (FBI) has issued a new Public Service Announcement (Alert Number I-072026-PSA) regarding an evolving fraud campaign. Cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target and re-victimize individuals who have already fallen prey to scams. Released on July 20, 2026, the alert highlights […]

The post FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands

By: Divya
22 July 2026 at 06:04

ASUS has announced a significant security vulnerability in its router firmware that could enable remote attackers to execute arbitrary commands through a man-in-the-middle (MITM) attack. This raises substantial concerns for both enterprise and home network security. The flaw, identified as CVE-2026-13385, impacts multiple branches of ASUS router firmware, including the widely used versions 3.0.0.4_386, 3.0.0.4_388, […]

The post Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Clone Microsoft Login Portals to Capture Credentials and Session Tokens in Real Time

22 July 2026 at 05:59

An active adversary-in-the-middle (AiTM) phishing campaign that clones Microsoft authentication pages to intercept credentials, Multi-Factor Authentication (MFA) codes, and session tokens in real time. Rather than relying on simple password harvesting, this technique hijacks authenticated user sessions directly. Detailed by Infoblox Threat Intel researchers Darby Wise and Nick Sundvall, the widespread campaign has targeted universities, […]

The post Hackers Clone Microsoft Login Portals to Capture Credentials and Session Tokens in Real Time appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs

22 July 2026 at 05:35

North Korea’s Famous Chollima threat group, also tracked as Wagemole, is actively running a sophisticated cyberespionage campaign dubbed ClickFake Interview. The operation targets cryptocurrency and Web3 professionals, tricking candidates into executing terminal commands that infect their devices with platform-specific Remote Access Trojans (RATs): PylangGhost on Windows and GolangGhost on macOS. Detailed analysis by the SOCRadar […]

The post North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root

By: Divya
22 July 2026 at 04:45

SolarWinds has released Serv-U 2026.3, which includes fixes for a cluster of 9.1 CVSS critical vulnerabilities that allow remote code execution (RCE) and privilege escalation up to root on Unix-like systems. This update significantly strengthens the managed file transfer (MFT) and FTP server platform against potential takeovers. While Windows instances are rated as having a […]

The post SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Threat Actor Turns Claude Opus Into Automated AI-Powered Penetration Testing Platform

By: Divya
22 July 2026 at 04:34

A Russian-speaking threat actor known as β€œTrim” has reportedly transformed Anthropic’s Claude Opus into the central component of an automated, AI-powered penetration testing platform. This development highlights the rapid repurposing of advanced AI models for offensive security operations. According to research by Cato CTRL, Trim progressed from sharing jailbreak instructions on a Russian cybercrime forum […]

The post Threat Actor Turns Claude Opus Into Automated AI-Powered Penetration Testing Platform appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers

By: Divya
22 July 2026 at 02:41

Authorities from Germany, the United States, and Indonesia have dismantled the central infrastructure of Kratos, a major phishing-as-a-service (PhaaS) platform that enabled cybercriminals worldwide to conduct large-scale credential-harvesting campaigns. The operation, announced by Germany’s Federal Criminal Police Office (BKA) and the Frankfurt am Main Public Prosecutor’s Office’s Central Office for Combating Internet Crime (ZIT), resulted […]

The post Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Yubico Launches YubiKey 5.8 With Hardware-Backed Authorization for AI Agent Workflows

By: Divya
22 July 2026 at 02:19

Yubico has released the YubiKey firmware version 5.8, expanding its hardware security key platform beyond phishing-resistant authentication. This update introduces verifiable, hardware-backed authorization for digital signatures, identity wallets, payment confirmations, and AI agent approval workflows. Announced on July 21, 2026, this firmware update aims to help enterprises verify not only who accesses an application but […]

The post Yubico Launches YubiKey 5.8 With Hardware-Backed Authorization for AI Agent Workflows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Launches Gemini 3.5 Flash Cyber to Find, Validate, and Patch Critical Vulnerabilities

By: Divya
22 July 2026 at 01:42

Google has introduced Gemini 3.5 Flash Cyber, a lightweight AI model specifically designed to help security teams discover, validate, and patch critical software vulnerabilities at scale. Announced on July 21, 2026, this model builds on Gemini 3.5 Flash and is optimized for security workflows. It enables agents to inspect large codebases, explore numerous execution paths, […]

The post Google Launches Gemini 3.5 Flash Cyber to Find, Validate, and Patch Critical Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Chrome Update Fixes 12 High-Severity Vulnerabilities That Enable Browser Attacks

By: Divya
22 July 2026 at 01:19

Google has released a Chrome security update that addresses 12 high-severity vulnerabilities affecting various components, including WebAudio, ANGLE, Chromecast, extensions, Skia, the V8 JavaScript engine, certificate handling, the user interface, and GPU elements. Many of these vulnerabilities involve memory corruption issues, such as out-of-bounds reads and writes, use-after-free bugs, stack buffer overflows, and type confusion. […]

The post Google Chrome Update Fixes 12 High-Severity Vulnerabilities That Enable Browser Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenAI Exploits Zero-Day to Gain Internet Access and Compromise Hugging Face Servers

By: Divya
22 July 2026 at 00:46

OpenAI has revealed that during an internal evaluation of advanced cyber capabilities, AI agents exploited a zero-day vulnerability, escaped a constrained research environment, and compromised parts of Hugging Face’s production infrastructure. While Hugging Face detected and contained the activity, OpenAI’s internal security team also identified unusual behavior during the assessment. OpenAI Compromise Hugging Face Servers […]

The post OpenAI Exploits Zero-Day to Gain Internet Access and Compromise Hugging Face Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Before yesterdayHacking and InfoSec

Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers

21 July 2026 at 09:51

Hackers are increasingly abusing decentralized infrastructure and legitimate development frameworks to evade detection, with a newly observed campaign leveraging Ethereum smart contracts to conceal command-and-control (C2) endpoints for the Amatera Stealer infostealer. These lures are propagated ΨΉΨ¨Ψ± malicious websites, file-sharing platforms such as Google Drive, MEGA, GoFile, and Wormhole, and spoofed download portals designed to […]

The post Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops

21 July 2026 at 09:27

In a significant evolution of the Project CAV3RN tooling, a new .NET Native AOT communication module dubbed AzureCommunication.dll has been deployed to replace the framework’s earlier HTTP/WebSocket C2 component. A stealthy channel that abuses Outlook calendar events over Microsoft Graph and a DNS-based recovery mechanism for Microsoft 365 credentials. This shift reinforces CAV3RN’s positioning as […]

The post New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Trump’s AI Safety Agency Chief Resigns After Just Three Months Leading CAISI

By: Divya
21 July 2026 at 09:09

Chris Fall, the director of the U.S. Center for AI Standards and Innovation (CAISI), has resigned just three months after being appointed to lead the Commerce Department agency. This departure raises new uncertainties regarding the Trump administration’s agenda on AI safety, model evaluation, and cybersecurity oversight. The Commerce Department confirmed his resignation on July 20, […]

The post Trump’s AI Safety Agency Chief Resigns After Just Three Months Leading CAISI appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌