❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

By: Divya
11 September 2026 at 08:03

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controlled RealRTSP servers. The more severe vulnerability, tracked as CVE-2026-56711, is a heap out-of-bounds write flaw with a CVSS v4 score of […]

The post VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

By: Divya
11 September 2026 at 07:57

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On September 10, CISA listed CVE-2026-67277 and CVE-2026-86060, giving affected organizations until September 13 to implement vendor-recommended mitigations. MikroTik RouterOS Flaws CVE-2026-67277 […]

The post CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

By: Divya
11 September 2026 at 07:20

A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026-65638, affects CSF versions 14.00 through 16.29 and has been addressed in version 16.30 and later. CSF is widely used on Linux servers and in cPanel/WHM environments […]

The post cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code

By: Divya
11 September 2026 at 06:13

GitLab has issued an emergency security update to address two critical vulnerabilities that could lead to unauthenticated file disclosure and authenticated credential theft, as well as a high-severity flaw that may enable remote code execution. The company released updated versions of GitLab Community Edition and Enterprise Edition, specifically versions 19.3.2, 19.2.6, and 19.1.8, on September […]

The post Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

By: Divya
11 September 2026 at 05:59

Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, to bypass authentication, escalate privileges, and gain administrative control of exposed instances. Wiz Research reports that multiple attackers are targeting self-hosted Artifactory deployments in the wild, using both a two-bug token escalation chain and a separate critical authentication-bypass flaw. A successful […]

The post Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Okta Patches Auth0 and Access Gateway Vulnerabilities Let Attackers Enable XSS, Authentication Bypass and SQL Injection

By: Divya
11 September 2026 at 05:42

Okta has released security updates for three high-severity vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. These vulnerabilities could allow authenticated attackers to trigger stored cross-site scripting (XSS), bypass Protected Rule authorization controls, or execute unintended SQL commands against configured backend databases under specific deployment conditions. All three vulnerabilities were disclosed on September […]

The post Okta Patches Auth0 and Access Gateway Vulnerabilities Let Attackers Enable XSS, Authentication Bypass and SQL Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CISA Urges Service Providers to Provide Transparent Updates During Major IT and OT Outages

By: Divya
11 September 2026 at 03:47

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released new guidance urging service providers to deliver timely, accurate, and transparent communications during major information technology (IT) and operational technology (OT) outages. The document, titled β€˜Communicating Under Pressure: Best Practices for Service Providers’, was developed with the Federal Bureau of Investigation (FBI) and international partners. […]

The post CISA Urges Service Providers to Provide Transparent Updates During Major IT and OT Outages appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Abuse Claude AI Agents to Automate Cyberattacks, Exploitation and Data Theft

By: Divya
11 September 2026 at 02:03

Threat actors increasingly deploy AI agents as operational systems for cyberattacks, moving beyond simple chatbot assistants. These AI systems automate various stages of the cyber kill chain, including reconnaissance, phishing, exploitation, persistence, and bulk data theft. Anthropic reported disrupting multiple such operations between December 2025 and August 2026, involving groups suspected to be linked to […]

The post Hackers Abuse Claude AI Agents to Automate Cyberattacks, Exploitation and Data Theft appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

πŸ’Ύ

πŸ’Ύ

WordPress Blocks High-Risk Plugin Releases With New AI-Powered Automated Security Review

By: Divya
11 September 2026 at 01:49

WordPress has launched an automated security review system that uses multiple AI models and Jetpack Scan to analyze every plugin release before distributing it to websites via the WordPress.org update API. This new control is designed to prevent vulnerable or malicious plugin updates from reaching millions of WordPress installations through dashboard-based, one-click updates. WordPress Blocks […]

The post WordPress Blocks High-Risk Plugin Releases With New AI-Powered Automated Security Review appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware

By: Divya
11 September 2026 at 01:30

Cisco Talos has warned that threat actors are actively exploiting two vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software. These vulnerabilities can lead to unauthorized access, root-level code execution, credential theft, network reconnaissance, and malware deployment. Critical Cisco FMC Flaws The most critical issue is identified as CVE-2026-20079, a critical authentication-bypass vulnerability with a […]

The post Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Check Point VPN Flaws Let Unauthenticated Attackers Execute Remote Code

By: Divya
11 September 2026 at 01:23

Check Point has announced two critical vulnerabilities in its VPN technology that could allow unauthenticated remote attackers to execute arbitrary code on affected security gateways under certain conditions. These vulnerabilities, tracked as CVE-2026-85102 and CVE-2026-85103, impact both Remote Access VPN and Site-to-Site VPN functionalities. Check Point said its internal research team discovered and resolved these […]

The post Critical Check Point VPN Flaws Let Unauthenticated Attackers Execute Remote Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

By: Divya
10 September 2026 at 08:28

Skullcandy Dime 3 wireless earbuds have a serious vulnerability related to unauthenticated Bluetooth pairing. This flaw allows nearby attackers to silently pair with the earbuds, disrupt legitimate audio sessions, and potentially capture microphone audio. This issue, tracked as VU#859658 by the CERT Coordination Center, affects the Skullcandy Dime 3 earbuds (model S2DCW) running firmware version […]

The post Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

By: Divya
10 September 2026 at 08:00

Threat actors are increasingly exploiting Active Directory replication mechanisms to steal password hashes without directly compromising a domain controller. This technique, known as DCSync, allows attackers with privileged domain credentials to impersonate a legitimate domain controller and request sensitive directory replication data. Unlike noisy attacks that use malware on servers or attempt to extract credentials […]

The post Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

By: Divya
10 September 2026 at 07:41

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O archive parser could allow a malicious static library to crash Xcode build processes or expose process memory through build logs. This flaw affects the parser used by Apple’s newer linker, ld-prime, as well as related developer tools, including libtool, ranlib, and potentially dyld_info. Apple Xcode Integer […]

The post Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

By: Divya
10 September 2026 at 07:39

Palo Alto Networks has announced a high-severity buffer overflow vulnerability in PAN-OS that may allow unauthenticated, network-based attackers to execute arbitrary code with root privileges on affected PA-Series hardware firewalls. This vulnerability is tracked as CVE-2026-0310 and stems from PAN-OS XML processing. It impacts both the firewall management web interfaces and the dataplane interfaces. The […]

The post Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenAI Builds β€˜Defense Factory’ as AI Agents Gain Ability to Chain Cyber Exploits

By: Divya
10 September 2026 at 05:24

OpenAI has announced its plans for a β€œDefense Factory,” a cybersecurity operation that prioritizes agent-driven actions. This initiative is designed to continuously discover, validate, remediate, and verify vulnerabilities as AI systems develop the ability to conduct increasingly complex cyber operations. The initiative addresses growing concerns that long-running autonomous agents, especially those powered by widely accessible […]

The post OpenAI Builds β€˜Defense Factory’ as AI Agents Gain Ability to Chain Cyber Exploits appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New AI Workflow Identity Hijacking Attack Lets Hackers Exfiltrate Sensitive Data

By: Divya
10 September 2026 at 03:51

Security researchers have recently disclosed a new enterprise AI attack technique known as Workflow Identity Hijacking. This method enables external attackers to exfiltrate sensitive corporate information by submitting seemingly harmless requests to AI-powered automations. Research published by Noma Labs researcher Sasi Levi reveals that this attack does not rely on prompt injection, stolen credentials, or […]

The post New AI Workflow Identity Hijacking Attack Lets Hackers Exfiltrate Sensitive Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers

By: Divya
10 September 2026 at 01:20

Threat intelligence firm GreyNoise has identified an AI-driven intrusion campaign, likely orchestrated by a Russian-speaking threat actor, that compromised at least 440 PaperCut NG/MF servers across 395 organizations in 48 countries. This campaign began on August 31, 2026, exploiting two vulnerabilities in PaperCut: CVE-2026-81578, an authentication bypass flaw, and CVE-2026-82078, a vulnerability that allows unsafe […]

The post Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks

By: Divya
10 September 2026 at 01:15

Researcher has discovered a rapidly spreading exploit kit called BlueMoon, which combines vulnerabilities in the Chrome browser with a Windows kernel privilege-escalation flaw to compromise targets in espionage campaigns. This activity was first observed on August 28, 2026, and at least four threat clusters have adopted it, most of which are suspected to have ties […]

The post China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Anthropic Claude AI Models Attack Real Systems During Misconfigured Cybersecurity Tests

By: Divya
10 September 2026 at 00:51

Anthropic has reported four cybersecurity evaluation incidents in which pre-release Claude AI models gained unauthorized access to real third-party systems after isolated test environments were accidentally connected to the internet. These cases revealed significant alignment failures, including biased reasoning and reckless task pursuit, when autonomous models operated for extended periods without production cyber safeguards. All […]

The post Anthropic Claude AI Models Attack Real Systems During Misconfigured Cybersecurity Tests appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌