❌

Reading view

There are new articles available, click to refresh the page.

Hotel Wi-Fi DNS Poisoning Attacks Hijack Microsoft 365 Accounts Without Phishing

Adversaries are silently hijacking Microsoft 365 accounts by compromising hotel and conference-center Wi-Fi gateways and poisoning DNS no phishing emails, malicious attachments, or endpoint malware required. ReliaQuest assesses that the tradecraft closely mirrors prior APT28-linked router campaigns, extending them into captive-portal infrastructure used by traveling corporate staff. Since at least June 2026, threat actors have […]

The post Hotel Wi-Fi DNS Poisoning Attacks Hijack Microsoft 365 Accounts Without Phishing appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Chrome 150 Update Fixes Four High-Severity Security Vulnerabilities

Google Chrome version 150.0.7871.186 has addressed four high-severity vulnerabilities that affect core browser components, including Codecs, WebMCP, Blink, and Input. While Google has not reported any evidence indicating that these vulnerabilities are actively being exploited, the company has restricted access to technical bug reports and related information until a majority of Chrome users receive the […]

The post Google Chrome 150 Update Fixes Four High-Severity Security Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Lampion Malware Targets Portuguese Users With Multistage Phishing and 750MB RAT Payload

A highly targeted Lampion malware campaign abusing localized phishing lures to compromise users in Portugal. The activity reflects a continued evolution of the Brazilian-origin banking trojan, first documented in 2019, which has consistently focused on Portuguese-speaking victims rather than domestic Brazilian targets. In the latest campaign, attackers leverage convincing financial-themed phishing emails masquerading as routine […]

The post Lampion Malware Targets Portuguese Users With Multistage Phishing and 750MB RAT Payload appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Claude Cowork Sandbox Escape Flaw Lets Attackers Access SSH Keys and Cloud Credentials

A newly revealed sandbox escape vulnerability affecting Anthropic’s Claude Cowork could allow untrusted content processed by the AI agent to access sensitive files on a macOS host. This includes SSH private keys, cloud credentials, and other data that are available to the logged-in user. Security researcher Oren Yomtov from Accomplish has named this attack path […]

The post Claude Cowork Sandbox Escape Flaw Lets Attackers Access SSH Keys and Cloud Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Attackers Abuse Microsoft Teams to Impersonate IT Support and Steal Corporate Access

Attackers are increasingly abusing Microsoft Teams to impersonate internal IT support and trick employees into handing over remote access and corporate credentials, even as traditional email phishing volumes tied to major platforms like Tycoon2FA decline. Microsoft’s recent email threat landscape data for Q2 2026 shows a sharp downstream impact from the March disruption of the […]

The post Attackers Abuse Microsoft Teams to Impersonate IT Support and Steal Corporate Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day to Steal 90 Days of Emails

Russian state-supported threat actors, known as LAUNDRY BEAR, have exploited a zero-day vulnerability in the Zimbra Collaboration Suite to steal up to 909,090 days’ worth of emails from targeted organizations across Western countries. A joint cybersecurity advisory, AA26-204A, issued on July 23, 2026, warns that this espionage-focused group has targeted government, defense, energy, technology, education, […]

The post Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day to Steal 90 Days of Emails appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Weaponize Notepad++ Plugins to Silently Infect Windows Systems

CERT-UA has issued a warning regarding the UAC-0099 threat cluster, which has revised its malware delivery method by exploiting the legitimate Notepad++ application to load a malicious DLL disguised as a plugin. This campaign, observed since mid-summer 2026, introduces two newly identified tools, LUNCHPOKE and BURNYBEAR, along with an updated MATCHBOIL.V2 loader. This activity highlights […]

The post Hackers Weaponize Notepad++ Plugins to Silently Infect Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

136 Malicious RubyGems Packages Deploy XMRig Miner and Spread via SSH

A large-scale supply chain attack has flooded RubyGems with 136 trojanized packages that deploy an XMRig Monero miner and self-propagate via SSH, underscoring systemic weaknesses in language ecosystems beyond npm and PyPI. On July 22, 2026, researchers Moe Ghasemisharif, Ruian Duan, Zhanhao Chen, and Daiping Liu documented a coordinated cryptojacking campaign abusing RubyGems as the […]

The post 136 Malicious RubyGems Packages Deploy XMRig Miner and Spread via SSH appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Next.js Patches Nine Security Flaws Enabling SSRF, Middleware Bypass, DoS, and Internal Endpoint Disclosure

The Next.js team has released security updates that address nine vulnerabilities affecting the App Router, Server Actions, rewrites, image optimization, caching, and middleware deployments. Organizations are urged to upgrade to Next.js versions 15.5.21 or 16.2.11 immediately, as these updates fix high- and moderate-severity flaws that could lead to server-side request forgery (SSRF), authentication bypass, denial […]

The post Next.js Patches Nine Security Flaws Enabling SSRF, Middleware Bypass, DoS, and Internal Endpoint Disclosure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation

Security operations teams face a constant balancing act: stopping sophisticated email threats, maintaining visibility across their attack surface and keeping administrative workflows running smoothly. When security tools operate in silos or rely on rigid, manual processes, friction builds up quickly. This friction consumes valuable time that analysts could spend on higher-priority initiatives.

New Kimi K3 AI Agent Uncovers Redis Remote Code Execution Flaws in Just 27 Minutes

Moonshot AI’s newly unveiled Kimi K3 model is attracting considerable attention in the cybersecurity community after successfully demonstrating its ability to autonomously identify critical vulnerabilities in Redis within minutes. This 2.8-trillion-parameter AI agent reportedly discovered multiple remote code execution (RCE) vulnerabilities across various Redis versions, specifically 6.2.22, 7.4.9, 8.6.4, and 8.8.0. This highlights the increasing […]

The post New Kimi K3 AI Agent Uncovers Redis Remote Code Execution Flaws in Just 27 Minutes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New TriBack Loader Evades EDR Using Signed Binaries and Win32 Callback APIs

A new shellcode loader, dubbed β€œTriBack Loader,” to a China-nexus intrusion cluster tracked as JadeProx, with the malware explicitly engineered to evade modern EDR by abusing signed binaries and uncommon Win32 callback APIs. Across at least four observed variants, the loader underpins simultaneous espionage campaigns in South-East Asia and Latin America, including targeting of a […]

The post New TriBack Loader Evades EDR Using Signed Binaries and Win32 Callback APIs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical FreePBX Flaws Let Unauthenticated Attackers Execute Code and Take Over Administrator Accounts

Critical security vulnerabilities in FreePBX have been disclosed, exposing organizations to risks of unauthenticated remote code execution and the takeover of administrator accounts. These flaws, tracked under GitHub advisories GHSA-37j8-fhxx-9vhp and GHSA-g27h-xf3q-h3rm, affect FreePBX versions 16 and 17, carrying a CVSS v4 base score of 9.3, which highlights their severity. Security researchers warn that these […]

The post Critical FreePBX Flaws Let Unauthenticated Attackers Execute Code and Take Over Administrator Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical FreeRDP Clipboard Flaw Could Let Malicious RDP Servers Execute Code

A critical heap buffer overflow vulnerability in FreeRDP’s Windows client could allow a malicious Remote Desktop Protocol (RDP) server to corrupt memory and potentially execute arbitrary code on a connecting client. This flaw specifically affects the Clipboard Redirection (CLIPRDR) virtual channel in wfreerdp, where an attacker-controlled response can exceed the size that the client originally […]

The post Critical FreeRDP Clipboard Flaw Could Let Malicious RDP Servers Execute Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers

Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers, with a primary focus on cPanel and WHM deployments. The campaign first surfaced when malicious development versions were discovered across ten Packagist PHP packages tied to a legitimate PHP and DevOps […]

The post Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Exim Vulnerability Lets Attackers Access Files Outside the Mail Spool

A high-severity directory traversal vulnerability has been discovered in the Exim mail transfer agent. This flaw allows local attackers to access files outside the intended mail spool directory and potentially escalate their privileges. It is tracked as EXIM-Security-2026-06-22.1 and assigned GCVE-25-2026-07-45-1. The vulnerability affects Exim versions 4.88 through 4.99.4 and was announced on July 22, […]

The post Exim Vulnerability Lets Attackers Access Files Outside the Mail Spool appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims

A new Windows-focused infostealer and remote access trojan (RAT) dubbed Dolphin X is being advertised on cybercrime forums with a clear pitch: automate the theft and triage of high-value corporate targets. Unlike commodity stealers that focus mainly on browser passwords, Dolphin X is positioned as an enterprise-adjacent data vacuum with a built-in AI-powered victim scoring […]

The post New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication

A critical authentication bypass vulnerability affecting Check Point SmartConsole has been actively exploited in the wild, allowing attackers to gain unauthorized access to security management systems under specific configurations. The flaw, tracked as CVE-2026-16232, carries a CVSS score of 9.3 and impacts Check Point Security Management and Multi-Domain Management deployments, particularly when management interfaces are […]

The post Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root

A recently disclosed vulnerability in Ubuntu’s snap ecosystem, identified as CVE-2026-8933, presents a critical local privilege escalation flaw. This vulnerability allows unprivileged users to execute arbitrary code with root privileges. Qualys discovered the issue in snap-confine, a core component used by snapd to set up execution environments for snap applications. It affects specific Ubuntu releases […]

The post Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌