❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 28 July 2026Hacking and InfoSec

Fake Claude Code Installer Delivers MacSync macOS Infostealer Through Google Ads

28 July 2026 at 09:02

A highly convincing malvertising campaign is targeting macOS users searching for β€œhow to install Claude Code on Mac,” delivering the MacSync infostealer through a trusted-looking workflow that abuses legitimate infrastructure rather than exploiting software vulnerabilities. The attack highlights a growing shift toward trust-based compromise, where attackers weaponize authentic platforms such as Google Ads and claude.ai […]

The post Fake Claude Code Installer Delivers MacSync macOS Infostealer Through Google Ads appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users

28 July 2026 at 08:32

The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security researchers warn that its leaked techniques and infrastructure patterns are already being repurposed in ongoing campaigns targeting Microsoft 365 environments. Despite being disrupted under Operation Olympus Blade, which led to the seizure of […]

The post Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions

28 July 2026 at 07:36

A significant evolution in the CastleLoader malware ecosystem, with new campaigns deploying the NeedleStealer framework to harvest cryptocurrency wallet seed phrases and hijack browser sessions. The findings expand on earlier research by Huntress and LevelBlue, confirming that CastleLoader remains a central delivery mechanism for multi-stage intrusions while introducing new tooling written in Rust and Golang. […]

The post CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical TeamCity Flaw Lets Unauthenticated Attackers Execute System Commands

By: Divya
28 July 2026 at 06:58

JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077. This vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on affected servers. The issue impacts every version of the self-hosted continuous integration and continuous delivery platform, making it urgent for organizations that expose TeamCity instances over HTTP or HTTPS to […]

The post Critical TeamCity Flaw Lets Unauthenticated Attackers Execute System Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Chinese Hackers Use RedRelay Multi-Hop Network to Conceal Global Cyber Operations

28 July 2026 at 06:38

Chinese state-linked hackers are increasingly relying on a covert multi-hop infrastructure dubbed RedRelay (also known as ORBWEAVER) to mask the origins of global cyber operations, with evidence pointing to little-known Guangdong Chanming as a key enabler behind the network. Guangdong Chanming, a low‑visibility company with no public‑facing products or marketing, has quietly amassed a portfolio […]

The post Chinese Hackers Use RedRelay Multi-Hop Network to Conceal Global Cyber Operations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

AI-Discovered Linux Kernel Zero-Day Enables Root Privilege Escalation

By: Divya
28 July 2026 at 06:34

A researcher recently disclosed an AI-assisted Linux kernel zero-day vulnerability, tracked as CVE-2026-53264, which allows local privilege escalation to root on affected systems. This flaw is found in the Linux packet scheduling subsystem (net/sched) and arises from a use-after-free condition involving traffic-control action objects. AI-Discovered Linux Kernel Zero-Day Star Labs researcher developed a reliable exploit […]

The post AI-Discovered Linux Kernel Zero-Day Enables Root Privilege Escalation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Tengu Mirai Botnet Uses Watchdog Reboots and Binary Bricking to Resist Removal

28 July 2026 at 05:47

Tengu, a newly observed Mirai-derived botnet, is demonstrating how modern IoT malware is rapidly evolving beyond traditional distributed denial-of-service (DDoS) operations by integrating persistence, evasion, and multi-functional attack capabilities. Unlike legacy Mirai variants, Tengu employs a hybrid C2 model that blends plaintext and encrypted communications. Initial registration and heartbeat messages are transmitted in cleartext, while […]

The post Tengu Mirai Botnet Uses Watchdog Reboots and Binary Bricking to Resist Removal appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Fake ShinyHunters Emails Give Victims 48 Hours to Pay $2,000 Bitcoin Ransom

28 July 2026 at 05:14

Fake ShinyHunters-themed sextortion emails are abusing data from recent ShinyHunters leaks to threaten victims with the release of fabricated β€œwebcam recordings” unless a 2,000 dollar Bitcoin ransom is paid within 48 hours. Despite the technical-sounding claims, there is no evidence of actual device compromise, malware deployment, or recorded content behind these messages. The emails impersonate […]

The post Fake ShinyHunters Emails Give Victims 48 Hours to Pay $2,000 Bitcoin Ransom appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

LegacyHive Exploit Abuses Windows Profile Loading to Hijack User Registry Hives

By: Divya
28 July 2026 at 04:16

LegacyHive is a newly discovered proof-of-concept (PoC) for Windows that exploits profile initialization and offline registry hive manipulation to redirect user-level registry paths, potentially allowing access to resources associated with another account. This technique was published by the Nightmare-Eclipse disclosure actor shortly after Microsoft’s July 2026 Patch Tuesday. Unlike traditional software vulnerabilities, LegacyHive chains legitimate […]

The post LegacyHive Exploit Abuses Windows Profile Loading to Hijack User Registry Hives appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Top 10 Best VPN Alternatives For Secure Remote Access in 2026

28 July 2026 at 03:58

In the rapidly evolving landscape of 2026, the traditional VPN is increasingly showing its age. While a VPN creates a secure, encrypted tunnel to a private network, it often functions like an β€œall-access key,” granting users broad, undifferentiated access once connected. This model presents a significant security risk, as a single compromised endpoint can give […]

The post Top 10 Best VPN Alternatives For Secure Remote Access in 2026 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

PortSwigger Introduces Burp AT Agentic AI for Automated Penetration Testing

By: Divya
28 July 2026 at 03:48

PortSwigger has launched Burp AT, an agentic AI system that allows penetration testers to delegate web security investigation tasks while maintaining direct control over the testing scope, approvals, and final conclusions. The public beta is currently available for Burp Suite Professional users. Unlike standalone AI assistants that operate based on prompts with limited context, Burp […]

The post PortSwigger Introduces Burp AT Agentic AI for Automated Penetration Testing appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Dysphoria IoT Botnet Uses Blockchain Domains and 200,000 Devices for DDoS Attacks

28 July 2026 at 03:47

A rapidly evolving IoT botnet dubbed β€œDysphoria” has emerged as a significant global threat, leveraging blockchain-based domain resolution and a hybrid command-and-control (C2) architecture to sustain large-scale distributed denial-of-service (DDoS) operations. Dysphoria’s evolution has been unusually aggressive, transitioning from early jackskid-derived variants to more sophisticated fbot-based implementations within weeks. Initial samples observed in March 2026 […]

The post Dysphoria IoT Botnet Uses Blockchain Domains and 200,000 Devices for DDoS Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor

28 July 2026 at 02:34

An evolving intrusion campaign in which threat actors impersonate IT helpdesk personnel via Microsoft Teams to gain initial access and deploy a custom Go-based backdoor dubbed β€œGoGRPC.” Active since January 2026, the activity is assessed to be linked to an initial access broker (IAB) operation that likely facilitates downstream ransomware attacks. Aligning with tactics observed […]

The post Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Multiple FFmpeg Flaws Allow Arbitrary Memory Corruption via Malicious Videos

By: Divya
28 July 2026 at 02:17

Multiple high-severity vulnerabilities in FFmpeg could allow attackers to corrupt memory, disclose process data, or exhaust system resources. This can happen if users or automated media-processing services are manipulated into handling specially crafted video, audio, image, or subtitle files. The vulnerabilities affect FFmpeg versions up to 8.1.28. Organizations operating transcoding pipelines, media upload platforms, streaming […]

The post Multiple FFmpeg Flaws Allow Arbitrary Memory Corruption via Malicious Videos appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Operation STANDOFF Uses GitHub Redirects Across 44 Servers to Hide Multi-Malware C2 Traffic

28 July 2026 at 01:45

Operation STANDOFF is a Russian‑speaking cybercriminal campaign that uses a cluster of at least 44 TimeWeb‑hosted servers that all masquerade as benign GitHub redirectors to conceal multi‑malware command‑and‑control (C2) and proxy traffic. This infrastructure underpins a full ecosystem: a pay‑per‑install loader, a proxy‑botnet, a multi‑operator intrusion console, and an AI‑driven influence and outreach platform. All […]

The post Operation STANDOFF Uses GitHub Redirects Across 44 Servers to Hide Multi-Malware C2 Traffic appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Apple iOS 26.6 Update Fixes Flaws Allowing Kernel-Level Code Execution and Root Access

By: Divya
28 July 2026 at 01:38

Apple has released iOS 26.6 and iPadOS 26.6, a significant security update that addresses numerous vulnerabilities across core operating system components, media frameworks, WebKit, wireless services, and application frameworks. Released on July 27, 2026, this update is available for iPhone 11 and later models, as well as supported iPads. It should be prioritized for deployment […]

The post Apple iOS 26.6 Update Fixes Flaws Allowing Kernel-Level Code Execution and Root Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenAI CEO Sam Altman Claims AI Has Reached Singularity as Systems Begin Improving Themselves

By: Divya
28 July 2026 at 01:11

OpenAI CEO Sam Altman has stated that artificial intelligence has entered the long-discussed stage of technological singularity, referring to the current period as the point where AI systems can increasingly improve future AI capabilities. His remarks, made during the β€œRelentless” podcast released on Saturday, have reignited the debate over whether advanced AI models have reached […]

The post OpenAI CEO Sam Altman Claims AI Has Reached Singularity as Systems Begin Improving Themselves appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Operation BlueDash Maintains Redundant Remote Access Even After One RMM Tool Is Removed

28 July 2026 at 01:08

A newly analyzed phishing-driven intrusion set tracked as Operation BlueDash demonstrates how threat actors are operationalizing legitimate remote monitoring and management (RMM) tools to maintain persistent and redundant access to compromised environments. The infection chain begins with a Microsoft Teams-themed phishing email delivering a β€œsecure document” lure. Victims are redirected through compromised infrastructur to a […]

The post Operation BlueDash Maintains Redundant Remote Access Even After One RMM Tool Is Removed appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌