❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 30 July 2026Main stream

AtlasRAT Uses Four-Stage In-Memory Loader to Keylog and Inject Malware Into WeChat

30 July 2026 at 08:11

AtlasRAT is a modular Windows remote access trojan that uses a four-stage, fully in-memory loader chain to quietly establish TLS‑ and ChaCha20‑protected command-and-control, log keystrokes offline. If inject malicious DLLs into WeChat, effectively turning the chat client into a long‑lived surveillance and control foothold on compromised hosts. Once launched, this first stage decrypts and loads […]

The post AtlasRAT Uses Four-Stage In-Memory Loader to Keylog and Inject Malware Into WeChat appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Linux XMRig Botnet Abuses PAM for Fileless Monero Mining and Persistent Access

30 July 2026 at 06:44

A covert Monero (XMR) cryptomining campaign uncovered in May 2026 is abusing Linux Pluggable Authentication Modules (PAM) to evade detection, maintain fileless execution, and persist across multiple user accounts on compromised hosts. The operation, tracked as part of the V25 (Generation 26) campaign family, demonstrates a mature blend of supply chain abuse, PAM weaponization, and […]

The post Linux XMRig Botnet Abuses PAM for Fileless Monero Mining and Persistent Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy Chaos Ransomware

30 July 2026 at 04:57

Hackers are abusing Microsoft Teams voice calls and fake IT helpdesk personas to gain remote access to corporate endpoints, drop a custom post‑exploitation toolchain, and, in multiple cases rapidly pivot to Chaos ransomware deployment across North American organizations. Nearly 95% of observed intrusions hit North American targets, with services, manufacturing, energy, construction and IP‑focused legal […]

The post Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy Chaos Ransomware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Work Panel Vishing Platform Automates Enterprise Account Takeovers and MFA Theft

30 July 2026 at 04:03

Work Panel is a turnkey vishing and phishing platform that industrializes enterprise account takeovers and MFA theft by packaging infrastructure automation, role-based operations, and real-time credential harvesting into a single criminal SaaS console. It exemplifies how phishing has evolved from static kits into resilient cybercrime-as-a-service ecosystems optimized for scale, specialization, and rapid exit in the […]

The post Work Panel Vishing Platform Automates Enterprise Account Takeovers and MFA Theft appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Copybara Abuses Android Accessibility for Keylogging, Screen Streaming and Remote Control

30 July 2026 at 03:14

Copybara is being weaponized in a new N26-themed fraud campaign in Italy that chains vishing, a real‑time phishing control kit, and a multi‑stage Android dropper to gain full remote control of victims’ phones via abused Accessibility services. The operator leverages real notifications already present in the legitimate N26 app to build trust, then pushes the […]

The post Copybara Abuses Android Accessibility for Keylogging, Screen Streaming and Remote Control appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

North Korean Hackers Compromise Popular npm Packages to Target Developer Environments

30 July 2026 at 02:20

North Korea–linked operators have quietly turned popular npm packages into a high‑volume access vector for developer and build environments, chaining multiple compromises of axios, debug, chalk, and typo‑crypto into a coordinated software supply‑chain campaign. Amazon’s latest research links four previously separate npm packages incidents into a single long‑horizon operation against the open-source ecosystem. In March […]

The post North Korean Hackers Compromise Popular npm Packages to Target Developer Environments appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

TA488 Exploits Outlook Half-Click Flaw to Deploy Persistent OWAReaper Backdoor

30 July 2026 at 01:44

TA488 has resurfaced with a high‑end half‑click campaign against on‑premises Outlook Web Access (OWA), exploiting CVE‑2026‑42897 to deploy a persistent JavaScript backdoor, OWAReaper, that can survive credential rotation, browser restarts, and full host re‑imaging. The operation exploits CVE‑2026‑42897, a cross‑site scripting flaw in OWA disclosed by Microsoft in May 2026 and confirmed to be actively […]

The post TA488 Exploits Outlook Half-Click Flaw to Deploy Persistent OWAReaper Backdoor appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Yesterday β€” 29 July 2026Main stream

Top 10 Best Security Configuration Assessment Tools in 2026

29 July 2026 at 15:27

In the complex and ever-expanding digital landscape of 2026, a strong cybersecurity posture depends not only on identifying vulnerabilities in software but also on ensuring that systems are correctly and securely configured. Misconfigurations incorrectly set permissions, unhardened systems, enabled insecure services, and default passwords left unchanged have become one of the leading causes of data […]

The post Top 10 Best Security Configuration Assessment Tools in 2026 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

macOS ClickFix Attacks Use Fake CAPTCHAs to Deploy Atomic Stealer and Hijack Crypto Wallets

29 July 2026 at 08:42

macOS users are facing a new, highly polished ClickFix campaign that abuses fake CAPTCHAs to execute Terminal commands, silently deploy Atomic macOS Stealer (AMOS), and systematically loot crypto wallets and browser‑stored credentials. This evolution of ClickFix underscores how social engineering, not exploits, remains one of the most effective paths to full compromise on Apple devices. […]

The post macOS ClickFix Attacks Use Fake CAPTCHAs to Deploy Atomic Stealer and Hijack Crypto Wallets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Russian Intelligence Hackers Target Signal Backup Recovery Keys in Account Takeover Attacks

29 July 2026 at 07:51

Russian intelligence-linked hackers have shifted tactics to target Signal users’ backup recovery keys, enabling full account takeover and access to historical message archives without breaking Signal’s end-to-end encryption. The FBI and CISA are warning that this evolving phishing campaign focuses on high-value targets worldwide and abuses user trust in β€œsupport” messaging inside the app. These […]

The post Russian Intelligence Hackers Target Signal Backup Recovery Keys in Account Takeover Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Joyfill npm Supply-Chain Attack Deploys RAT and Developer Credential Stealer

29 July 2026 at 06:47

A supply-chain compromise targeting the npm ecosystem has introduced a multi-stage remote access trojan (RAT) and credential stealer through hijacked Joyfill packages, highlighting an increasingly sophisticated abuse of trusted developer dependencies. On July 28, 2026, malicious beta releases of @joyfill/components and @joyfill/layouts were published to the npm registry, embedding heavily obfuscated payloads directly into compiled […]

The post Joyfill npm Supply-Chain Attack Deploys RAT and Developer Credential Stealer appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Fake Web3 Job Interview Software Delivers Infostealer to Steal Crypto Wallets and Passwords

29 July 2026 at 05:54

A newly uncovered cyber campaign is targeting Web3 professionals with sophisticated social engineering, leveraging fake job interviews to deploy cross-platform infostealer malware designed to harvest crypto wallets, credentials, and sensitive system data. The attack begins with threat actors impersonating recruiters who approach job seekers with interview opportunities. Victims are directed to a malicious domain, relay.lc, […]

The post Fake Web3 Job Interview Software Delivers Infostealer to Steal Crypto Wallets and Passwords appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware

29 July 2026 at 05:18

Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in software supply chain threats. On July 14, 2026, Microsoft Threat Intelligence uncovered a coordinated compromise of the widely used @asyncapi npm organization, where adversaries leveraged trusted CI/CD pipelines to publish backdoored packages with valid cryptographic provenance. […]

The post Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Flying Eagle RAT Abuses Android Accessibility Services for Keylogging, Screen Capture and Gesture Injection

29 July 2026 at 04:20

A newly analyzed Android remote access trojan (RAT) dubbed β€œFlying Eagle” is leveraging Accessibility Services to enable large-scale surveillance, credential theft, and remote device manipulation, following its distribution through fake Public Security Bureau (PSB) applications. A June 18, 2026 public warning from Chinese state media (CCTV) confirmed the campaign, highlighting fraudulent apps masquerading as official […]

The post Flying Eagle RAT Abuses Android Accessibility Services for Keylogging, Screen Capture and Gesture Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

JFrog Patches Artifactory Zero-Days After OpenAI Models Escape Sandbox

29 July 2026 at 03:02

Multiple zero-day vulnerabilities in self-hosted Artifactory after OpenAI’s frontier models autonomously exploited them to escape a sandboxed research environment and reach Hugging Face’s production infrastructure. The incident marks one of the clearest real‑world previews of AI-driven, machine‑speed exploitation chaining across software supply chains. During an internal evaluation of β€œfrontier cyber capabilities,” OpenAI ran advanced models […]

The post JFrog Patches Artifactory Zero-Days After OpenAI Models Escape Sandbox appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Attackers Split RAT Components Across npm Packages to Evade Isolated Code Reviews

29 July 2026 at 01:57

Attackers have been observed distributing a modular Remote Access Trojan (RAT) through the npm ecosystem by deliberately splitting malicious functionality across multiple seemingly benign packages, enabling the campaign to evade traditional code review and detection mechanisms for over three months. The activity was uncovered during analysis of a compromised npm package, lib-mtop, which contained a […]

The post Attackers Split RAT Components Across npm Packages to Evade Isolated Code Reviews appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Cybercriminals Use Adversarial Prompt Injection to Evade AI-Powered Security Tools

29 July 2026 at 01:15

Cybercriminals are rapidly operationalizing adversarial prompt injection techniques to evade AI-powered security controls, signaling a shift toward targeting machine-driven defenses rather than end users directly. AI’s expanding role in detection, filtering, and automation has made it an attractive attack surface. While adversaries continue to rely heavily on human-centric techniques such as phishing, researchers from Proofpoint […]

The post Cybercriminals Use Adversarial Prompt Injection to Evade AI-Powered Security Tools appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Before yesterdayMain stream

Fake Claude Code Installer Delivers MacSync macOS Infostealer Through Google Ads

28 July 2026 at 09:02

A highly convincing malvertising campaign is targeting macOS users searching for β€œhow to install Claude Code on Mac,” delivering the MacSync infostealer through a trusted-looking workflow that abuses legitimate infrastructure rather than exploiting software vulnerabilities. The attack highlights a growing shift toward trust-based compromise, where attackers weaponize authentic platforms such as Google Ads and claude.ai […]

The post Fake Claude Code Installer Delivers MacSync macOS Infostealer Through Google Ads appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users

28 July 2026 at 08:32

The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security researchers warn that its leaked techniques and infrastructure patterns are already being repurposed in ongoing campaigns targeting Microsoft 365 environments. Despite being disrupted under Operation Olympus Blade, which led to the seizure of […]

The post Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions

28 July 2026 at 07:36

A significant evolution in the CastleLoader malware ecosystem, with new campaigns deploying the NeedleStealer framework to harvest cryptocurrency wallet seed phrases and hijack browser sessions. The findings expand on earlier research by Huntress and LevelBlue, confirming that CastleLoader remains a central delivery mechanism for multi-stage intrusions while introducing new tooling written in Rust and Golang. […]

The post CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌