❌

Reading view

There are new articles available, click to refresh the page.

Apple iOS 26.6 Update Fixes Flaws Allowing Kernel-Level Code Execution and Root Access

Apple has released iOS 26.6 and iPadOS 26.6, a significant security update that addresses numerous vulnerabilities across core operating system components, media frameworks, WebKit, wireless services, and application frameworks. Released on July 27, 2026, this update is available for iPhone 11 and later models, as well as supported iPads. It should be prioritized for deployment […]

The post Apple iOS 26.6 Update Fixes Flaws Allowing Kernel-Level Code Execution and Root Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenAI CEO Sam Altman Claims AI Has Reached Singularity as Systems Begin Improving Themselves

OpenAI CEO Sam Altman has stated that artificial intelligence has entered the long-discussed stage of technological singularity, referring to the current period as the point where AI systems can increasingly improve future AI capabilities. His remarks, made during the β€œRelentless” podcast released on Saturday, have reignited the debate over whether advanced AI models have reached […]

The post OpenAI CEO Sam Altman Claims AI Has Reached Singularity as Systems Begin Improving Themselves appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Operation BlueDash Maintains Redundant Remote Access Even After One RMM Tool Is Removed

A newly analyzed phishing-driven intrusion set tracked as Operation BlueDash demonstrates how threat actors are operationalizing legitimate remote monitoring and management (RMM) tools to maintain persistent and redundant access to compromised environments. The infection chain begins with a Microsoft Teams-themed phishing email delivering a β€œsecure document” lure. Victims are redirected through compromised infrastructur to a […]

The post Operation BlueDash Maintains Redundant Remote Access Even After One RMM Tool Is Removed appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

ShinyHunters Claims EY Data Breach, Threatens to Leak Stolen Client Tax Data

ShinyHunters has claimed responsibility for the data breach at Ernst & Young (EY) and is threatening to publish allegedly stolen client tax information unless the professional services firm engages in negotiations before July 31, 2026. The extortion group posted about EY on its dark web leak site, describing the deadline as a β€œfinal warning” and […]

The post ShinyHunters Claims EY Data Breach, Threatens to Leak Stolen Client Tax Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

NVIDIA, Microsoft, and CrowdStrike Launch Alliance for Open-Source AI Security

NVIDIA, Microsoft, and CrowdStrike have joined a broad coalition of technology, cybersecurity, and open-source organizations to launch the Open Secure AI Alliance. This initiative focuses on developing open tools, models, agent harnesses, and security techniques to defend AI-enabled infrastructure. The alliance builds on the groundwork laid by the Linux Foundation’s Akrites initiative and the Open […]

The post NVIDIA, Microsoft, and CrowdStrike Launch Alliance for Open-Source AI Security appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Anyone With a Browser Could Access 700,000 Vatican Prayer App Accounts

A critical access control vulnerability in the Vatican’s official β€œClick to Pray” platform has exposed the personal data of more than 700,000 users, highlighting once again how basic web security misconfigurations continue to put large-scale user bases at risk. The service, operated by the Pope’s Worldwide Prayer Network, is widely used across the globe to […]

The post Anyone With a Browser Could Access 700,000 Vatican Prayer App Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Claude Opus 5 Finds Software Vulnerabilities While Blocking Exploit Generation

Claude Opus 5, the latest flagship AI model from Anthropic, represents a significant shift in how advanced systems can be safely utilized in cybersecurity. This model can proactively identify software vulnerabilities while specifically preventing the generation of exploits and offensive usage. Announced on July 24, 2026, Opus 5 is positioned as a high-end, general-purpose intelligence […]

The post Claude Opus 5 Finds Software Vulnerabilities While Blocking Exploit Generation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Europol Launches Project COMPASS to Disrupt β€˜The Com’ Cybercrime Network Targeting Minors

Europol has launched Project COMPASS, a coordinated transnational initiative aimed at disrupting β€œThe Com,” a highly dangerous cybercrime and nihilistic extremist network that systematically targets minors and vulnerable young people across digital platforms. The Com operates as a sprawling transnational virtual network (TVN), utilizing social media, messaging apps, music platforms, and online games to recruit, […]

The post Europol Launches Project COMPASS to Disrupt β€˜The Com’ Cybercrime Network Targeting Minors appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

vBulletin Pre-Auth RCE Flaw Allows Remote PHP Code Execution

A critical pre-authentication remote code execution vulnerability in vBulletin, tracked as CVE-2026-61511, could allow unauthenticated attackers to execute arbitrary PHP code on vulnerable forum servers. This issue affects vBulletin versions 6.2.1 and earlier, as well as 6.1.6 and earlier, according to a July 27, 2026, disclosure from SSD Secure Disclosure. If exploited successfully, this vulnerability […]

The post vBulletin Pre-Auth RCE Flaw Allows Remote PHP Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Over 70 Fake Windows App Sites Could Turn Trusted Downloads Into Malware

A newly uncovered cluster of more than 70 impersonation domains targeting popular Windows applications is raising fresh concerns about a scalable malware distribution campaign that leverages trust in legitimate software ecosystems. The discovery, triggered by a developer investigating unusual search results for their own application, reveals a coordinated infrastructure designed to mimic well-known tools while […]

The post Over 70 Fake Windows App Sites Could Turn Trusted Downloads Into Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies

GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies as soon as they are released. This change comes in response to a rise in supply chain attacks where attackers publish trojanized package versions to public registries, relying on automated update […]

The post GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Crypto Criminals Use Social Media Profiling to Select Victims for Violent Wrench Attacks

Crypto criminals are increasingly weaponizing social media intelligence to identify and target high-value individuals in a surge of violent β€œwrench attacks,” marking a shift from purely digital exploitation to coordinated physical coercion campaigns. Recent threat intelligence indicates that attackers are systematically profiling cryptocurrency holders using publicly available data across platforms such as Instagram, TikTok, X, […]

The post Crypto Criminals Use Social Media Profiling to Select Victims for Violent Wrench Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure

Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-connected programmable logic controllers (PLCs) from major industrial vendors, including Rockwell Automation, Schneider Electric, and Siemens, targeting U.S. critical infrastructure sectors. A joint cybersecurity advisory (AA26-097A) released by the FBI, CISA, NSA, DOE, EPA, Treasury, and U.S. Cyber Command highlights sustained exploitation activity against operational technology […]

The post Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Windows WalletService Flaw Lets Standard Users Gain SYSTEM Privileges

Microsoft Windows WalletService is affected by a local privilege escalation vulnerability tracked as CVE-2026-49176. This flaw could allow a standard authenticated user to obtain SYSTEM-level privileges. The vulnerability arises from WalletService’s handling of user-controlled file paths during initialization. An attacker can exploit this by redirecting the service to a maliciously crafted Extensible Storage Engine (ESE) […]

The post Windows WalletService Flaw Lets Standard Users Gain SYSTEM Privileges appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New usbliter8 SecureROM Exploit Enables iOS 27 Jailbreak on iPhone 11 Pro

A new developer-focused project, usbliter8-fun, showcases an iOS 27 jailbreak workflow specifically for the iPhone 11 Pro. It combines the usbliter8 SecureROM exploit with a custom firmware restoration process. This proof of concept targets Apple’s A13-based iPhone 11 Pro. It is labeled as experimental, destructive, and unsuitable for use on primary devices. New usbliter8 SecureROM […]

The post New usbliter8 SecureROM Exploit Enables iOS 27 Jailbreak on iPhone 11 Pro appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Introduces KMS Hardware-Secured for Windows Server Activation

Microsoft has introduced KMS Hardware-Secured, an upcoming enhancement to Windows Server activation that utilizes Trusted Platform Module (TPM)-based attestation to validate Key Management Service (KMS) hosts before they can activate Windows devices. Announced in a July 2022 Windows IT Pro Blog post, this initiative addresses risks related to spoofed, cloned, or otherwise untrusted KMS infrastructure. […]

The post Microsoft Introduces KMS Hardware-Secured for Windows Server Activation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

AWS Launches Claude Opus 5 With Advanced Agentic Coding and Cybersecurity Capabilities

AWS has launched Anthropic’s Claude Opus 5 on Amazon Bedrock and the Claude Platform, introducing a groundbreaking model designed for agentic coding, complex enterprise workflows, visual understanding, and long-running autonomous tasks. Released on July 24, 2026, Claude Opus 5 is Anthropic’s first fifth-generation Opus model. According to AWS, it offers significant improvements in production-grade reasoning, […]

The post AWS Launches Claude Opus 5 With Advanced Agentic Coding and Cybersecurity Capabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Apple Biome Data Reveals Safari Activity, Wallet Transactions and Location Visits

Apple’s internal Biome framework is rapidly emerging as one of the most valuable sources of forensic intelligence on iOS, with newly analyzed data revealing detailed records of Safari browsing activity, Wallet transactions. Originally misunderstood due to its name, Biome is not Ω…Ψ±ΨͺΨ¨Ψ· with biometrics but instead powers Apple’s predictive intelligence ecosystem, including Siri suggestions, personalization, […]

The post Apple Biome Data Reveals Safari Activity, Wallet Transactions and Location Visits appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Claude Code Symlink Flaw Exfiltrates Sensitive Files Without User Approval

Claude Code has a flaw in its startup memory loader related to handling symbolic links (symlinks) that can unintentionally expose readable files from outside a cloned repository, without requiring explicit user approval. The issue arises not from the tool following symlinks, something that is standard behavior in filesystems, but from a mismatch in how its […]

The post Claude Code Symlink Flaw Exfiltrates Sensitive Files Without User Approval appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

πŸ’Ύ

SparkKitty Monitors Mobile Photo Galleries and Exfiltrates Sensitive Images to C2 Servers

SparkKitty is a cross‑platform mobile stealer that weaponizes users’ photo galleries, using OCR to extract sensitive text from images and silently exfiltrating it to attacker‑controlled C2 servers on both Android and iOS. Built as an apparent successor to SparkCat, the malware is tuned to hunt cryptocurrency wallet seed phrases, but its indiscriminate photo theft dramatically […]

The post SparkKitty Monitors Mobile Photo Galleries and Exfiltrates Sensitive Images to C2 Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌