❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 15 September 2026GBHackers

Google Search Makes It Harder to See Where a Link Really Goes Before You Click

15 September 2026 at 09:42

Google has begun routing some organic Search result links through opaque google.com/goto?url=… redirects, reducing users’ ability to independently inspect a destination URL before clicking. The change appears designed to raise the technical and financial cost of mass scraping. However, it also weakens a long-standing, basic anti-phishing habit: hovering over a link to verify where it […]

The post Google Search Makes It Harder to See Where a Link Really Goes Before You Click appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters

15 September 2026 at 09:04

Phishing operators are increasingly shifting away from malware-laden attachments and toward trusted delivery services, authenticated domains, and multi-stage URL cloaking designed to defeat conventional email inspection. The continuously running VBSpam comparative test evaluated ten public full email-security products and one open-source solution against wanted, unwanted, and malicious mail streams. The assessment was conducted under the […]

The post Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors

15 September 2026 at 08:05

Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload malicious PHP files and potentially seize full control of vulnerable WordPress sites. The vulnerability , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 out of […]

The post Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites

By: Divya
15 September 2026 at 07:24

Two critical unauthenticated vulnerability chains in the widely used The Events Calendar WordPress plugin could allow attackers to execute code and fully compromise affected websites remotely. These flaws, identified by Wordfence Argus, impact plugin versions up to 6.17.4 and have been patched in version 6.17.4.1. The Events Calendar is active on over 600,000 WordPress websites, […]

The post WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Rootkit

By: Divya
15 September 2026 at 07:16

A Chinese-speaking threat actor known as Red Heron has exploited a critical remote code execution (RCE) vulnerability in Gitea to steal private source code, harvest credentials, establish persistent access, and move laterally within victim infrastructures. Researchers from the Acronis Threat Research Unit (TRU) have linked this operation to a newly documented Linux implant called JITTERLY, […]

The post Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Rootkit appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Telegram Desktop XSS Vulnerability Lets Attackers Steal Entire Chat Histories

By: Divya
15 September 2026 at 06:11

A stored cross-site scripting (XSS) vulnerability in Telegram Desktop could enable attackers to steal the contents of exported chat histories by embedding malicious code in an inline keyboard button, according to security researchers. This issue affects the HTML chat export feature in Telegram Desktop builds released before Beta version 6.9.4 and Stable version 7.0.1. Researchers […]

The post Telegram Desktop XSS Vulnerability Lets Attackers Steal Entire Chat Histories appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds

By: Divya
15 September 2026 at 05:58

A threat actor exploited a critical pre-authentication remote code execution vulnerability in marimo to harvest AWS credentials, retrieve an SSH private key from AWS Secrets Manager, and authenticate to a bastion host in just eight seconds, according to the Sysdig Threat Research Team. This vulnerability, tracked as CVE-2026-39987, affects marimo versions up to 0.20.4 and […]

The post Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

DDRop Attack Forces Intel TDX Confidential VMs Into Debug Mode and Exposes Memory

15 September 2026 at 05:57

A newly disclosed hardware attack dubbed DDRop can undermine Intel Trust Domain Extensions (TDX) by manipulating DDR5 memory traffic, allowing an attacker with physical server access to force confidential virtual machines into debug mode and extract private memory in plaintext. Researchers from KU Leuven, ETH Zurich, Google, Durham University, and other institutions released proof-of-concept code, […]

The post DDRop Attack Forces Intel TDX Confidential VMs Into Debug Mode and Exposes Memory appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Linux Kernel ZcopyReaper Vulnerability Lets Local Attackers Gain Root Privileges

By: Divya
15 September 2026 at 04:18

Security researchers have disclosed a local privilege escalation vulnerability in the Linux kernel related to the Reliable Datagram Sockets (RDS) zero-copy send path. This vulnerability could let an unprivileged local attacker gain root privileges. It is tracked as CVE-2026-43502 and is referred to as β€œZcopyReaper.” NebuSec researcher Yuan Tan reported the issue in a disclosure […]

The post Linux Kernel ZcopyReaper Vulnerability Lets Local Attackers Gain Root Privileges appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Offers $60,000 Bounty for Critical Cross-Tenant Vulnerabilities

By: Divya
15 September 2026 at 04:08

Microsoft has expanded its incentives for security researchers focusing on Dynamics 365 and Power Platform, offering rewards ranging from $1,250 to $60,000 for qualifying vulnerabilities. The program prioritizes flaws that have a direct and demonstrable security impact in supported cloud services, including cross-tenant issues that could compromise isolation between customer environments. Microsoft Offers $60,000 Bounty […]

The post Microsoft Offers $60,000 Bounty for Critical Cross-Tenant Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Deploy Agentic AI to Automate Exploitation and Mass Credential Harvesting

15 September 2026 at 03:46

Threat actors are moving from using artificial intelligence as a productivity aid to deploying autonomous agentic systems that can execute major portions of an intrusion with minimal human intervention. Google Threat Intelligence Group (GTIG) has documented a financially motivated actor that used a multi-agent framework to plan, build, and run a mass credential-harvesting operation in […]

The post Hackers Deploy Agentic AI to Automate Exploitation and Mass Credential Harvesting appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Turn Windows Shadow Copies Into a Tool for Credential Theft and Ransomware

15 September 2026 at 01:51

Threat actors are increasingly weaponizing Microsoft’s Volume Shadow Copy Service (VSS) for two distinct objectives: removing recovery options before ransomware deployment and extracting credential material from protected Windows files. The shift means VSS telemetry should no longer be treated as a simple backup or disk-maintenance event, but as behavior requiring process, identity, and endpoint context. […]

The post Hackers Turn Windows Shadow Copies Into a Tool for Credential Theft and Ransomware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

UK Government Enables Passkey Login for 23 Million Users to Fight Phishing Attacks

By: Divya
15 September 2026 at 01:48

The UK government has started implementing passkey authentication for GOV. UK One Login,UK One Login, providing over 23 million users with a faster and more secure way to access public services. This initiative aims to reduce reliance on passwords and SMS-based verification codes, which are common targets for fraud and credential theft. UK Enables Passkey […]

The post UK Government Enables Passkey Login for 23 Million Users to Fight Phishing Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Mass Scanning Targets Exposed Vite Servers to Steal AWS Keys and Azure Tokens

By: Divya
15 September 2026 at 01:35

In August 2026, automated threat activity targeting exposed Vite development servers increased significantly. Attackers aimed to extract cloud credentials, environment files, and infrastructure state data by exploiting a critical file-read vulnerability known as CVE-2026-39364. Honeynet telemetry recorded 807 session-grouped attacks and approximately 32,000 raw events during the monthly analysis period. This campaign shows how quickly […]

The post Mass Scanning Targets Exposed Vite Servers to Steal AWS Keys and Azure Tokens appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware

15 September 2026 at 01:22

Threat actors hijacked HBO Max’s verified Reddit account, u/hbomax, and used its trusted advertising identity to distribute 108 malicious ClickFix advertisements in a coordinated 48-hour malvertising campaign. The operation, tracked as PasteSwitch, delivered platform-specific malware to macOS and Windows users, including information stealers, in-memory loaders, cryptocurrency clippers, and fake wallet applications. The campaign came to […]

The post HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor

By: Divya
15 September 2026 at 01:20

Threat actors exploited the critical FortiGate SSL-VPN vulnerability CVE-2024-21762 to target the Thai broadband provider Triple T Broadband (3BB). They gained access to its internal environment and deployed MeshCentral remote management agents for persistent control. Hunt.io uncovered the operation after AttackCapture identified an internet-accessible directory hosted on a server in Thailand. This directory contained exploitation […]

The post Hackers Exploit FortiGate SSL-VPN Flaw to Breach Thai ISP and Deploy MeshCentral Backdoor appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Exploit Critical Cisco Secure Email Gateway Flaw to Execute Commands as Root

By: Divya
15 September 2026 at 01:01

Cisco has released security updates to address a critical SQL injection vulnerability in the Cisco Secure Email Gateway. This vulnerability can be exploited remotely and without authentication, allowing attackers to execute arbitrary commands with root privileges on affected devices. Tracked as CVE-2026-76461, this flaw has a CVSS base score of 9.8 out of 10. It […]

The post Hackers Exploit Critical Cisco Secure Email Gateway Flaw to Execute Commands as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Yesterday β€” 14 September 2026GBHackers

Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities

14 September 2026 at 05:27

A newly identified Cyclops Blink variant has resurfaced on compromised Cisco Secure Firewall Management Center (FMC) appliances, adding active internal-network scanning and programmable packet-sniffing capabilities to an already mature modular implant. Assessed with high confidence that the activity has a Russian nexus, with a moderate-confidence link to IRON VIKING also tracked as Sandworm and Seashell […]

The post Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor

14 September 2026 at 04:09

China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencent’s Sogou Input Method for Windows to deploy the GRAYRABBIT backdoor on targeted systems. Tracked as CVE-2026-51990, the vulnerability chains an insecure custom protocol handler, unrestricted embedded-browser navigation, and an obsolete Chromium build running without sandbox protections. Tencent addressed […]

The post China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users

14 September 2026 at 01:56

A Casbaneiro banking Trojan campaign targeting users across Latin America, using phishing lures, geofenced delivery infrastructure, and distributed command-and-control (C2) servers to obscure malicious activity. The operation, observed in August 2026, primarily targets victims in Argentina, Peru, Colombia, and Mexico through fake invoice and legal-notice emails carrying links to malicious PDF files. The campaign demonstrates […]

The post Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌