❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayGBHackers

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

11 September 2026 at 08:24

A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to distribute malware at scale. The cluster, tracked as CL-CRI-1171, is linked to more than 10,000 distinct samples of a custom loader called OfferLoader, indicating a distribution pipeline far larger than the individual intrusions initially observed. Rather than relying on a […]

The post Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

11 September 2026 at 06:51

Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also for large language model-powered tools increasingly used to triage suspicious code. ESET researchers linked the activity to Russia-aligned threat actor UAC-0099, which used the method during an attack against an organization in Ukraine. The group inserted a safety-sensitive, weapon-related request […]

The post Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks

11 September 2026 at 05:07

A newly observed IoT malware family dubbed KATARU targets internet-exposed devices through Telnet credential brute-forcing, then attempts to gain root privileges with publicly available Linux kernel exploits before enrolling compromised systems in a DDoS botnet. The sample combines familiar Mirai-style flooding functions with encrypted command-and-control, broad persistence logic, anti-analysis checks and decoy network activity designed […]

The post New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.

11 September 2026 at 03:43

Threat actors are using AI-assisted phishing templates, executive impersonation, fake ServiceNow invoices, and fabricated email threads to pressure finance teams into authorizing fraudulent ACH payments worth nearly $50,000. Microsoft detected more than one million messages in the campaign, demonstrating how business email compromise (BEC) operations are becoming more polished, scalable, and difficult to spot. The […]

The post Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files

11 September 2026 at 03:14

Mantax OTAX is aggressive Android malware family combines ransomware, spyware, credential theft, and remote device-control features in a single infection chain. Linked to Indonesian threat actors, the campaign targets users through sideloaded APKs and turns compromised devices into tools for surveillance, financial fraud and real-time extortion. Unlike conventional Android ransomware that focuses primarily on locking […]

The post Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement

11 September 2026 at 02:17

A new Windows remote-access trojan dubbed SloppyRAT, which appears to be positioned as an intrusion-enablement tool for ransomware operations. First observed in June 2026, the malware is delivered through a multi-stage ClickFix chain and combines host reconnaissance, stealthy command execution, reverse proxying, and resilient command-and-control mechanisms to support post-compromise activity and lateral movement. Rather than […]

The post Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New AI Attack Hides Malicious Instructions in Normal-Looking Text to Evade Safety Filters

11 September 2026 at 01:53

A newly disclosed prompt-crafting technique can hide policy-violating instructions inside ordinary-looking English prose, allowing malicious requests to pass through lightweight LLM safety filters before being recovered and processed by a more capable downstream model. Researchers found that carefully structured prose can make the first model miss an embedded instruction entirely, while the target model invests […]

The post New AI Attack Hides Malicious Instructions in Normal-Looking Text to Evade Safety Filters appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

10 September 2026 at 08:56

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted the widely documented default master key, sk-1234, or required no authentication, creating a direct path to LLMjacking, sensitive credential exposure, and in vulnerable versions root-level code execution inside the gateway container. Their internet scan of 3,074 publicly reachable instances found that 294 systems, or 9.6%, accepted […]

The post Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

10 September 2026 at 07:43

Threat actors are exploiting anticipation around Grand Theft Auto VI by pushing fraudulent β€œleaked” game downloads that install a layered malware bundle that steals browser credentials, Discord tokens, gaming-session data, and cryptocurrency-related information. A Chaos ransomware variant used as a wiper, and an unexpected Yandex Browser installer. The campaign demonstrates how cybercriminals are turning one […]

The post Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

10 September 2026 at 06:57

A phishing campaign that moves the credential-harvesting page out of attacker-controlled web infrastructure and into the victim’s browser. Unlike ordinary phishing kits, which host cloned login portals on domains that can eventually be detected and disrupted, this campaign delivers malicious content assembled only after a user follows the attack chain. A blob URL is a […]

The post New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts

10 September 2026 at 05:19

Threat actors are impersonating corporate IT helpdesk staff in an active social-engineering campaign that hijacks Microsoft 365 identities, establishes MFA persistence, and systematically collects data from SharePoint, OneDrive, and Exchange Online. Microsoft Security Research said it has observed the cloud-focused intrusions since May 2026. The activity is marked by unusual sign-ins, attacker-added authentication methods, extensive […]

The post Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.

10 September 2026 at 03:01

Threat actors are increasingly using ClickFix social-engineering lures and search-engine malvertising to deploy MacSync Stealer, a macOS-focused information stealer and remote-access staging framework sold through a malware-as-a-service model. The campaigns do not require a macOS vulnerability; instead, they abuse user trust by persuading victims to paste attacker-controlled commands into Terminal, sidestepping traditional file-centric protections. However, […]

The post Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security. appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America

10 September 2026 at 02:02

Threat actors targeting organizations across Latin America are increasingly embedding commercial large language models (LLMs) into intrusion workflows, using AI-assisted scripting, troubleshooting, and proxy deployment to accelerate post-exploitation and data theft. The campaigns show that AI is no longer limited to phishing, content generation, or reconnaissance. Instead, attackers appear to be using LLMs as an […]

The post Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential-Stealing Malware

9 September 2026 at 09:27

A multi-stage malware operation that combines fake Google CAPTCHA prompts, WebDAV-hosted DLL execution, malicious Cloudflare Workers and BNB Smart Chain smart contracts to deploy the Amatera information stealer. The activity was first identified in April 2026 after a Ukrainian government organization executed a disguised DLL named β€œverification.google” from a WebDAV path using the 32-bit rundll32.exe […]

The post Hackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential-Stealing Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Iran-Linked Hackers Use Fake LinkedIn Job Offers to Deploy NodeRabbit and PollCat RATs

9 September 2026 at 08:52

Iran-linked cyberespionage group Mirage Kitten is targeting software engineers with fake recruiter outreach on LinkedIn and job-search platforms. Using trojanized coding assessments to deploy two previously undocumented cross-platform remote access trojans: NodeRabbit and PollCat. The campaign targets developer workstations across Windows, Linux, and macOS, with victims identified in aviation, aerospace, and fintech organizations in Egypt, […]

The post Iran-Linked Hackers Use Fake LinkedIn Job Offers to Deploy NodeRabbit and PollCat RATs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical ArangoDB Bugs Expose Entire Databases and Enable Remote Code Execution as Root

9 September 2026 at 08:28

Two critical ArangoDB vulnerabilities can allow unauthenticated attackers to access protected database APIs and, after obtaining valid database access, escalate to root-level code execution on affected hosts. Security researchers reported the vulnerabilities to ArangoDB on August 23, 2026. Patches shipped on August 31, followed by GitHub Security Advisories published on September 6: GHSA-rrgq-978q-36mq for the […]

The post Critical ArangoDB Bugs Expose Entire Databases and Enable Remote Code Execution as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks

9 September 2026 at 06:49

GoldFactory has expanded the evasion capabilities of its Gigabud Android banking trojan by deploying Vwork, a weaponized fork of the open-source Shelter application. The companion tool abuses Android Work Profile isolation to clone banking apps into a separate managed environment, weakening the link between malware signals detected in a victim’s personal profile and fraudulent activity […]

The post GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Weaponize Agentic AI to Automate Reconnaissance, Exploitation and Post-Exploitation

9 September 2026 at 05:12

Threat actors are increasingly operationalizing agentic artificial intelligence to compress cyberattack timelines, automating reconnaissance, vulnerability research, exploit development and credential theft with far less hands-on-keyboard activity. However, current evidence points to semi-autonomous, human-supervised attack chains rather than fully independent AI-driven intrusions in the wild. Agentic AI represents a material shift from conventional generative-AI abuse. Rather […]

The post Hackers Weaponize Agentic AI to Automate Reconnaissance, Exploitation and Post-Exploitation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

DeepSeek, Alibaba and Chinese AI Firms Extract Billions of Tokens From U.S. AI Models

9 September 2026 at 04:29

U.S. intelligence and cybersecurity agencies have accused six China-based AI companies including DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI of extracting billions of tokens from leading American AI systems through industrial-scale knowledge-distillation campaigns. A joint Cybersecurity Advisory, AA26-251A, issued by the National Security Agency, Cybersecurity and Infrastructure Security Agency and FBI, said the campaigns […]

The post DeepSeek, Alibaba and Chinese AI Firms Extract Billions of Tokens From U.S. AI Models appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Infostealers Target Claude, Cursor, Codex and Other AI Agents to Steal Credentials and Sensitive Data

9 September 2026 at 03:05

Information-stealing malware is expanding its collection logic to target locally stored data from AI coding agents, including Claude, Cursor, Codex, Cline, Continue, and OpenCode. The shift puts developer credentials, Model Context Protocol configurations, prompt histories, project metadata, and potentially proprietary source code into the same theft pipeline long used for browser cookies, cryptocurrency wallets, and […]

The post Infostealers Target Claude, Cursor, Codex and Other AI Agents to Steal Credentials and Sensitive Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌