❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayHacking and InfoSec

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

By: Divya
11 September 2026 at 08:03

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controlled RealRTSP servers. The more severe vulnerability, tracked as CVE-2026-56711, is a heap out-of-bounds write flaw with a CVSS v4 score of […]

The post VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

By: Divya
11 September 2026 at 07:57

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On September 10, CISA listed CVE-2026-67277 and CVE-2026-86060, giving affected organizations until September 13 to implement vendor-recommended mitigations. MikroTik RouterOS Flaws CVE-2026-67277 […]

The post CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

By: Divya
11 September 2026 at 07:20

A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026-65638, affects CSF versions 14.00 through 16.29 and has been addressed in version 16.30 and later. CSF is widely used on Linux servers and in cPanel/WHM environments […]

The post cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code

By: Divya
11 September 2026 at 06:13

GitLab has issued an emergency security update to address two critical vulnerabilities that could lead to unauthenticated file disclosure and authenticated credential theft, as well as a high-severity flaw that may enable remote code execution. The company released updated versions of GitLab Community Edition and Enterprise Edition, specifically versions 19.3.2, 19.2.6, and 19.1.8, on September […]

The post Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

By: Divya
11 September 2026 at 05:59

Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, to bypass authentication, escalate privileges, and gain administrative control of exposed instances. Wiz Research reports that multiple attackers are targeting self-hosted Artifactory deployments in the wild, using both a two-bug token escalation chain and a separate critical authentication-bypass flaw. A successful […]

The post Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Okta Patches Auth0 and Access Gateway Vulnerabilities Let Attackers Enable XSS, Authentication Bypass and SQL Injection

By: Divya
11 September 2026 at 05:42

Okta has released security updates for three high-severity vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. These vulnerabilities could allow authenticated attackers to trigger stored cross-site scripting (XSS), bypass Protected Rule authorization controls, or execute unintended SQL commands against configured backend databases under specific deployment conditions. All three vulnerabilities were disclosed on September […]

The post Okta Patches Auth0 and Access Gateway Vulnerabilities Let Attackers Enable XSS, Authentication Bypass and SQL Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware

By: Divya
11 September 2026 at 01:30

Cisco Talos has warned that threat actors are actively exploiting two vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software. These vulnerabilities can lead to unauthorized access, root-level code execution, credential theft, network reconnaissance, and malware deployment. Critical Cisco FMC Flaws The most critical issue is identified as CVE-2026-20079, a critical authentication-bypass vulnerability with a […]

The post Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Check Point VPN Flaws Let Unauthenticated Attackers Execute Remote Code

By: Divya
11 September 2026 at 01:23

Check Point has announced two critical vulnerabilities in its VPN technology that could allow unauthenticated remote attackers to execute arbitrary code on affected security gateways under certain conditions. These vulnerabilities, tracked as CVE-2026-85102 and CVE-2026-85103, impact both Remote Access VPN and Site-to-Site VPN functionalities. Check Point said its internal research team discovered and resolved these […]

The post Critical Check Point VPN Flaws Let Unauthenticated Attackers Execute Remote Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

By: Divya
10 September 2026 at 07:41

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O archive parser could allow a malicious static library to crash Xcode build processes or expose process memory through build logs. This flaw affects the parser used by Apple’s newer linker, ld-prime, as well as related developer tools, including libtool, ranlib, and potentially dyld_info. Apple Xcode Integer […]

The post Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

By: Divya
10 September 2026 at 07:39

Palo Alto Networks has announced a high-severity buffer overflow vulnerability in PAN-OS that may allow unauthenticated, network-based attackers to execute arbitrary code with root privileges on affected PA-Series hardware firewalls. This vulnerability is tracked as CVE-2026-0310 and stems from PAN-OS XML processing. It impacts both the firewall management web interfaces and the dataplane interfaces. The […]

The post Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

FortiPAM Chrome Extension Vulnerability Lets Malicious Sites Control Browser Proxy and Record Tabs

By: Divya
9 September 2026 at 09:18

A critical vulnerability has been identified in the Fortinet FortiPAM Chrome extension that could allow a malicious website to manipulate browser proxy settings, open tabs at the attacker’s discretion, and record activity within those tabs. This issue, tracked as CVE-2026-84388 and rated with a CVSS score of 9.1, impacts an extension that facilitates privileged access […]

The post FortiPAM Chrome Extension Vulnerability Lets Malicious Sites Control Browser Proxy and Record Tabs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical MapLibre GL JS Vulnerability Enables Zero-Click XSS Attacks

By: Divya
9 September 2026 at 07:34

MapLibre GL JS users are advised to upgrade their software following the disclosure of an XSS vulnerability, identified as CVE-2026-85061 and documented in GitHub advisory GHSA-jrc7-96c5-q579. This vulnerability affects maplibre-gl versions 6.4.0 and earlier and is resolved in version 6.4.1. Critical MapLibre GL JS Flaw The issue lies in the DOM.sanitize() function in src/util/dom.ts, which […]

The post Critical MapLibre GL JS Vulnerability Enables Zero-Click XSS Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Windows BitLocker Flaw Lets Attackers Execute Code on Vulnerable Systems

By: Divya
9 September 2026 at 06:28

Microsoft disclosed CVE-2026-69449, an Important-severity vulnerability in Windows BitLocker. This issue is classified as a heap-based buffer overflow (CWE-122) and may allow remote code execution (RCE). Microsoft released details about this vulnerability on September 8, 2026. The CVSS 3.1 base score is 6.7, with a temporal score of 5.8. Windows BitLocker Flaw The vulnerability uses […]

The post Windows BitLocker Flaw Lets Attackers Execute Code on Vulnerable Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT

By: Divya
9 September 2026 at 04:57

Threat actors are actively exploiting a critical vulnerability in FortiGate to deploy PivotC2, a Node. js-based remote access trojan (RAT) designed for persistent post-exploitation of FortiOS appliances. Researchers at SOCRadar’s Threat Research Unit (STRU) reported that this campaign has targeted over 30,000 internet-exposed FortiGate IP addresses and has successfully compromised at least 178 devices since […]

The post Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Windows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM

By: Divya
9 September 2026 at 04:40

A newly published proof-of-concept (PoC) called ShieldCrash reveals an unpatched vulnerability in Microsoft Defender that allows a local attacker to gain arbitrary file-read access in the SYSTEM context. This disclosure, attributed to the researcher known as MSNightmare, comes shortly after Microsoft addressed an elevation-of-privilege flaw in the Microsoft Malware Protection Engine, tracked as CVE-2026-69414, referred […]

The post Windows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

cPanel EmailTrack SQL Injection Flaw Lets Attackers Execute Code as Root

By: Divya
9 September 2026 at 03:27

cPanel has disclosed CVE-2026-67401, a SQL injection vulnerability in its EmailTrack functionality. This flaw allows an authenticated account holder to create arbitrary files on a server, which can ultimately enable them to execute code with root privileges. The issue, published on September 8, 2026, affects all supported cPanel/WHM release versions before their respective fixes. Because […]

The post cPanel EmailTrack SQL Injection Flaw Lets Attackers Execute Code as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Fortinet FortiSandbox Vulnerability Allows Unauthenticated Attackers to Access Sensitive Information

By: Divya
9 September 2026 at 03:15

Fortinet has disclosed a critical vulnerability involving improper access control in the FortiSandbox web interfaces. This issue could allow an unauthenticated remote attacker to access sensitive information by sending specially crafted HTTP requests. The vulnerability is tracked as CVE-2026-26084 and documented in advisory FG-IR-26-166. It affects the graphical user interface (GUI) component of FortiSandbox, FortiSandbox […]

The post Fortinet FortiSandbox Vulnerability Allows Unauthenticated Attackers to Access Sensitive Information appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ivanti Patches 10 EPMM, Neurons for ITSM and Sentry Flaws Enabling RCE and Admin Access

By: Divya
9 September 2026 at 02:34

Ivanti has released security updates addressing 10 vulnerabilities in Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry. The vulnerabilities include several critical remote code execution (RCE) issues in Neurons for ITSM, an authentication bypass in Sentry that could grant administrative access, and a privilege escalation flaw in EPMM. Ivanti Patches 10 EPMM Flaws The […]

The post Ivanti Patches 10 EPMM, Neurons for ITSM and Sentry Flaws Enabling RCE and Admin Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Jellyfin 12.0 Released With Security Fixes for Unauthorized File Access and XSS Flaws

By: Divya
8 September 2026 at 08:23

Jellyfin has released version 12.0, a significant update to its open-source media server. This version includes a wide range of platform improvements and essential security updates affecting both the server and the web client. The project strongly advises administrators to plan their upgrade carefully because it includes database migrations and compatibility-breaking changes for existing deployments. […]

The post Jellyfin 12.0 Released With Security Fixes for Unauthorized File Access and XSS Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access

By: Divya
8 September 2026 at 08:04

Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities. These flaws can expose enterprise deployments to unauthenticated administrative access, remote command execution, and potential host-level compromise. Detailed in Dell Security Advisory DSA-2026-382, these issues affect SCG 5.0 appliance versions earlier than 5.36.00.16 and application versions […]

The post Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌