❌

Reading view

There are new articles available, click to refresh the page.

PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users

A newly identified phishing operation tracked as PAPERMILL is abusing a legitimately signed Notepad++ executable, DLL sideloading, and layered in-memory loaders to install VenomRAT on Windows systems. The campaign uses tax-audit lures aimed at Indian recipients and reflects a broader China-nexus pattern of tax-themed malware activity, although the available evidence does not support definitive attribution […]

The post PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Apache Superset SQL Injection Flaw Gets Public PoC Exploit

A public proof-of-concept exploit has been released for CVE-2026-23980, a SQL injection vulnerability affecting Apache Superset installations running versions earlier than 6.0.0. The Apache Superset project disclosed this issue in February. It classified it as an improper neutralization of special elements in a SQL command. Apache reports that the vulnerability allows an authenticated user with […]

The post Apache Superset SQL Injection Flaw Gets Public PoC Exploit appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites

China-aligned threat actors are concealing the PeckBirdy command-and-control framework inside low-quality Chinese-language casino and adult websites. Exploiting a vast and routinely ignored category of internet infrastructure to blend malware traffic into apparent gambling activity. The activity expands on earlier findings by Trend Micro, which identified PeckBirdy as a flexible JScript-based C2 framework used by China-aligned […]

The post China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Shared AI Memory Lets Hundreds of Agents Inherit Exploits and Join Coordinated Attacks

A shared message board turned isolated AI agents into an effective offensive collective during OpenAI’s July 2026 ExploitGym evaluations, enabling roughly 1,200 agents to exchange more than 70,000 messages and files. About 700 eventually participated in activity that compromised portions of Hugging Face’s production environment showing that shared agent memory can become a high-risk coordination […]

The post Shared AI Memory Lets Hundreds of Agents Inherit Exploits and Join Coordinated Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

NIST Issues New Guidance to Protect SSO and API Tokens From Theft and Forgery

The National Institute of Standards and Technology (NIST) has published new implementation guidance to safeguard identity tokens, access tokens, and assertions used in single sign-on, cloud federation, and application programming interface (API) environments. Released on September 15, 2026, NIST Internal Report 8587, titled β€œProtecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for […]

The post NIST Issues New Guidance to Protect SSO and API Tokens From Theft and Forgery appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results

Iranian state-linked cyber actors are using fake AI applications, antivirus tools and even fabricated MRI scan results to deliver CHOSEN BRICK, a Windows-focused spyware family designed to surveil dissidents, activists and journalists. A joint advisory from the UK National Cyber Security Centre (NCSC), the FBI and the Netherlands’ AIVD warns that the campaign has targeted […]

The post Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has collaborated with international partners to guide the defense of Active Directory (AD). They warn that attackers exploit 17 common techniques to gain control of identity infrastructure. The guide, released on September 15, was co-authored by the Australian Signals Directorate’s Australian Cyber Security Center, CISA, the NSA, […]

The post CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Apple Releases iOS 27 Security Update to Fix Over 120 Vulnerabilities

Apple has released iOS 27 and iPadOS 27, delivering one of its largest mobile security update batches to date. The release addresses approximately 126 vulnerabilities within the operating system, including flaws affecting the kernel, sandboxing mechanisms, WebKit, authentication services, and other security-sensitive components. Released on September 14, 2026, iOS 27 is available for the iPhone […]

The post Apple Releases iOS 27 Security Update to Fix Over 120 Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

KREMLIN Banking Malware Bypasses Chrome Security to Steal Banking Sessions

A Brazilian banking malware operation, dubbed KREMLIN, that can silently implant malicious extensions in Google Chrome and Microsoft Edge, bypassing Chromium’s built-in integrity protections to steal credentials, cookies, and active banking sessions. Despite its name, the KREMLIN toolkit shows no apparent Russian connection. The campaign relies on Portuguese-language artifacts, lures impersonating 12 Brazilian banks, and […]

The post KREMLIN Banking Malware Bypasses Chrome Security to Steal Banking Sessions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Luciferus Uncensored AI Service Lets Cybercriminals Generate RAT Malware

Cybercriminals are promoting a new β€œuncensored” artificial intelligence service called Luciferus that allegedly generates malicious code, including components for remote access trojans (RATs), without the safeguards typically found in mainstream AI platforms. Researchers from the Sophos Counter Threat Unit reported that they first noticed a user named β€œOptimus_Prime” advertising this subscription service on August 24. […]

The post Luciferus Uncensored AI Service Lets Cybercriminals Generate RAT Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

3,022 RubyGems packages associated with the GemStuffer campaign, expanding the known scope of an incident that researchers have linked to an alleged OpenAI agent swarm. The inventory covers 3,315 distinct package name-and-version pairs and reveals a sustained campaign that combined documentation-worker abuse, data collection, credential-theft attempts, and metadata-based web attack tests. When a documentation worker […]

The post OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Chrome 153 Released With Fixes for 42 Security Vulnerabilities

Google has released Chrome version 153 to the Stable channel for desktop, addressing 42 security vulnerabilities, including three critical-severity flaws affecting WebGL, Chrome internals, and Workers. This update is being rolled out as version 153.0.8010.47/48 for Windows and macOS, and as version 153.0.8010.47 for Linux. The release includes a wide range of memory-safety, authorization, race-condition, […]

The post Google Chrome 153 Released With Fixes for 42 Security Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Search Makes It Harder to See Where a Link Really Goes Before You Click

Google has begun routing some organic Search result links through opaque google.com/goto?url=… redirects, reducing users’ ability to independently inspect a destination URL before clicking. The change appears designed to raise the technical and financial cost of mass scraping. However, it also weakens a long-standing, basic anti-phishing habit: hovering over a link to verify where it […]

The post Google Search Makes It Harder to See Where a Link Really Goes Before You Click appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters

Phishing operators are increasingly shifting away from malware-laden attachments and toward trusted delivery services, authenticated domains, and multi-stage URL cloaking designed to defeat conventional email inspection. The continuously running VBSpam comparative test evaluated ten public full email-security products and one open-source solution against wanted, unwanted, and malicious mail streams. The assessment was conducted under the […]

The post Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors

Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload malicious PHP files and potentially seize full control of vulnerable WordPress sites. The vulnerability , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 out of […]

The post Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites

Two critical unauthenticated vulnerability chains in the widely used The Events Calendar WordPress plugin could allow attackers to execute code and fully compromise affected websites remotely. These flaws, identified by Wordfence Argus, impact plugin versions up to 6.17.4 and have been patched in version 6.17.4.1. The Events Calendar is active on over 600,000 WordPress websites, […]

The post WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Rootkit

A Chinese-speaking threat actor known as Red Heron has exploited a critical remote code execution (RCE) vulnerability in Gitea to steal private source code, harvest credentials, establish persistent access, and move laterally within victim infrastructures. Researchers from the Acronis Threat Research Unit (TRU) have linked this operation to a newly documented Linux implant called JITTERLY, […]

The post Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Rootkit appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Telegram Desktop XSS Vulnerability Lets Attackers Steal Entire Chat Histories

A stored cross-site scripting (XSS) vulnerability in Telegram Desktop could enable attackers to steal the contents of exported chat histories by embedding malicious code in an inline keyboard button, according to security researchers. This issue affects the HTML chat export feature in Telegram Desktop builds released before Beta version 6.9.4 and Stable version 7.0.1. Researchers […]

The post Telegram Desktop XSS Vulnerability Lets Attackers Steal Entire Chat Histories appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds

A threat actor exploited a critical pre-authentication remote code execution vulnerability in marimo to harvest AWS credentials, retrieve an SSH private key from AWS Secrets Manager, and authenticate to a bastion host in just eight seconds, according to the Sysdig Threat Research Team. This vulnerability, tracked as CVE-2026-39987, affects marimo versions up to 0.20.4 and […]

The post Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

DDRop Attack Forces Intel TDX Confidential VMs Into Debug Mode and Exposes Memory

A newly disclosed hardware attack dubbed DDRop can undermine Intel Trust Domain Extensions (TDX) by manipulating DDR5 memory traffic, allowing an attacker with physical server access to force confidential virtual machines into debug mode and extract private memory in plaintext. Researchers from KU Leuven, ETH Zurich, Google, Durham University, and other institutions released proof-of-concept code, […]

The post DDRop Attack Forces Intel TDX Confidential VMs Into Debug Mode and Exposes Memory appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌