❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 22 July 2026Main stream

Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases

By: Divya
22 July 2026 at 08:41

Meta has addressed a critical vulnerability involving broken access control that exposed sensitive customer support data across multiple services. This issue highlighted systemic weaknesses in authorization within their shared backend infrastructure. The flaw, categorized as an Insecure Direct Object Reference (CWE-639) combined with Broken Access Control (CWE-284) and Missing Authorization (CWE-862), allowed unauthorized users to […]

The post Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Apple Fixes Hide My Email Vulnerability That Exposed Users’ Real Email Addresses

By: Divya
22 July 2026 at 08:15

Apple has addressed a year-old vulnerability in its β€œHide My Email” privacy feature, which could expose users’ real email addresses. This incident has already led to a class action lawsuit and increased scrutiny of Apple’s privacy claims. Hide My Email, part of the paid iCloud+ subscription, allows users to generate random alias addresses that forward […]

The post Apple Fixes Hide My Email Vulnerability That Exposed Users’ Real Email Addresses appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks

By: Divya
22 July 2026 at 07:33

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has classified a critical SQL injection vulnerability in WordPress Core, tracked as CVE-2026-60137, as one of its Known Exploited Vulnerabilities (KEV) due to its active exploitation in real-world attacks. This vulnerability affects the core functionality of WordPress when themes or plugins fail to properly validate untrusted input […]

The post CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws

By: Divya
22 July 2026 at 06:32

Zimbra has released version 10.1.20 of its Collaboration Suite (ZCS) to address multiple high-severity security vulnerabilities. This release includes a critical command injection flaw in the SNMP monitoring component and several cross-site scripting (XSS) issues affecting the Classic Web Client. The update, published on July 20, 2026, provides a permanent fix for a previously disclosed […]

The post Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims

By: Divya
22 July 2026 at 06:18

The Federal Bureau of Investigation (FBI) has issued a new Public Service Announcement (Alert Number I-072026-PSA) regarding an evolving fraud campaign. Cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target and re-victimize individuals who have already fallen prey to scams. Released on July 20, 2026, the alert highlights […]

The post FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands

By: Divya
22 July 2026 at 06:04

ASUS has announced a significant security vulnerability in its router firmware that could enable remote attackers to execute arbitrary commands through a man-in-the-middle (MITM) attack. This raises substantial concerns for both enterprise and home network security. The flaw, identified as CVE-2026-13385, impacts multiple branches of ASUS router firmware, including the widely used versions 3.0.0.4_386, 3.0.0.4_388, […]

The post Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root

By: Divya
22 July 2026 at 04:45

SolarWinds has released Serv-U 2026.3, which includes fixes for a cluster of 9.1 CVSS critical vulnerabilities that allow remote code execution (RCE) and privilege escalation up to root on Unix-like systems. This update significantly strengthens the managed file transfer (MFT) and FTP server platform against potential takeovers. While Windows instances are rated as having a […]

The post SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Threat Actor Turns Claude Opus Into Automated AI-Powered Penetration Testing Platform

By: Divya
22 July 2026 at 04:34

A Russian-speaking threat actor known as β€œTrim” has reportedly transformed Anthropic’s Claude Opus into the central component of an automated, AI-powered penetration testing platform. This development highlights the rapid repurposing of advanced AI models for offensive security operations. According to research by Cato CTRL, Trim progressed from sharing jailbreak instructions on a Russian cybercrime forum […]

The post Threat Actor Turns Claude Opus Into Automated AI-Powered Penetration Testing Platform appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers

By: Divya
22 July 2026 at 02:41

Authorities from Germany, the United States, and Indonesia have dismantled the central infrastructure of Kratos, a major phishing-as-a-service (PhaaS) platform that enabled cybercriminals worldwide to conduct large-scale credential-harvesting campaigns. The operation, announced by Germany’s Federal Criminal Police Office (BKA) and the Frankfurt am Main Public Prosecutor’s Office’s Central Office for Combating Internet Crime (ZIT), resulted […]

The post Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Yubico Launches YubiKey 5.8 With Hardware-Backed Authorization for AI Agent Workflows

By: Divya
22 July 2026 at 02:19

Yubico has released the YubiKey firmware version 5.8, expanding its hardware security key platform beyond phishing-resistant authentication. This update introduces verifiable, hardware-backed authorization for digital signatures, identity wallets, payment confirmations, and AI agent approval workflows. Announced on July 21, 2026, this firmware update aims to help enterprises verify not only who accesses an application but […]

The post Yubico Launches YubiKey 5.8 With Hardware-Backed Authorization for AI Agent Workflows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Launches Gemini 3.5 Flash Cyber to Find, Validate, and Patch Critical Vulnerabilities

By: Divya
22 July 2026 at 01:42

Google has introduced Gemini 3.5 Flash Cyber, a lightweight AI model specifically designed to help security teams discover, validate, and patch critical software vulnerabilities at scale. Announced on July 21, 2026, this model builds on Gemini 3.5 Flash and is optimized for security workflows. It enables agents to inspect large codebases, explore numerous execution paths, […]

The post Google Launches Gemini 3.5 Flash Cyber to Find, Validate, and Patch Critical Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Chrome Update Fixes 12 High-Severity Vulnerabilities That Enable Browser Attacks

By: Divya
22 July 2026 at 01:19

Google has released a Chrome security update that addresses 12 high-severity vulnerabilities affecting various components, including WebAudio, ANGLE, Chromecast, extensions, Skia, the V8 JavaScript engine, certificate handling, the user interface, and GPU elements. Many of these vulnerabilities involve memory corruption issues, such as out-of-bounds reads and writes, use-after-free bugs, stack buffer overflows, and type confusion. […]

The post Google Chrome Update Fixes 12 High-Severity Vulnerabilities That Enable Browser Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenAI Exploits Zero-Day to Gain Internet Access and Compromise Hugging Face Servers

By: Divya
22 July 2026 at 00:46

OpenAI has revealed that during an internal evaluation of advanced cyber capabilities, AI agents exploited a zero-day vulnerability, escaped a constrained research environment, and compromised parts of Hugging Face’s production infrastructure. While Hugging Face detected and contained the activity, OpenAI’s internal security team also identified unusual behavior during the assessment. OpenAI Compromise Hugging Face Servers […]

The post OpenAI Exploits Zero-Day to Gain Internet Access and Compromise Hugging Face Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Yesterday β€” 21 July 2026Main stream

Trump’s AI Safety Agency Chief Resigns After Just Three Months Leading CAISI

By: Divya
21 July 2026 at 09:09

Chris Fall, the director of the U.S. Center for AI Standards and Innovation (CAISI), has resigned just three months after being appointed to lead the Commerce Department agency. This departure raises new uncertainties regarding the Trump administration’s agenda on AI safety, model evaluation, and cybersecurity oversight. The Commerce Department confirmed his resignation on July 20, […]

The post Trump’s AI Safety Agency Chief Resigns After Just Three Months Leading CAISI appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Craneware Cyberattack Exposes Employee and US Healthcare Customer Data

By: Divya
21 July 2026 at 09:01

Craneware plc, a UK-based provider of healthcare financial performance software, has disclosed that it experienced a cyberattack in which an unauthorized party accessed and extracted data from a portion of its systems. The company revealed that the incident involved employee information and records related to certain customers and partners, including organizations in the US healthcare […]

The post Craneware Cyberattack Exposes Employee and US Healthcare Customer Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Retires Copilot Podcasts and Removes Access to Previously Created Content

By: Divya
21 July 2026 at 08:23

Microsoft has announced that it will retire the Podcasts feature in its consumer Copilot app on August 18, 2026. This decision will permanently remove the ability to generate new AI-created podcasts, as well as access to all previously created content. This change affects all Copilot customers, including both free users and paid subscribers, and raises […]

The post Microsoft Retires Copilot Podcasts and Removes Access to Previously Created Content appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries

By: Divya
21 July 2026 at 07:54

Microsoft Defender XDR users may inadvertently overlook command-and-control (C2) traffic when searching for Internet-bound connections due to a specific behavior in how IP addresses are classified. This issue arises from Kusto Query Language (KQL) detections that depend solely on filtering by RemoteIPType == β€œPublic” in the DeviceNetworkEvents table. As a result, traffic destined for public […]

The post Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution

By: Divya
21 July 2026 at 06:57

Threat actors are actively exploiting CVE-2026-6875, a critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform. This vulnerability allows attackers to escape a restricted server-side script sandbox and execute code without valid credentials. Reports from Defused indicate observed exploitation activity targeting this flaw. Initially, ServiceNow’s advisory stated it was not aware of any […]

The post Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell

By: Divya
21 July 2026 at 04:47

An ongoing exploitation of two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) devices. These vulnerabilities allowed a threat actor, identified as UTA0533, to gain root-level access, install persistent malware, and deploy the ORANGETAIL Java webshell on vulnerable VPN appliances. The affected SonicWall SMA models include the 1000 series, specifically models 6210, 7210, and 8200. […]

The post Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Abbott Confirms Cyberattack After Unauthorized Access to Cancer Diagnostics Systems

By: Divya
21 July 2026 at 04:13

Abbott has disclosed a cybersecurity incident involving unauthorized access to a limited number of internal systems used by its Cancer Diagnostics business. Upon discovering the activity, the company acted swiftly by launching an investigation, engaging external cybersecurity experts, and coordinating with law enforcement agencies. Abbott Confirms Cyberattack According to Abbott’s statement released on July 16, […]

The post Abbott Confirms Cyberattack After Unauthorized Access to Cancer Diagnostics Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌