❌

Reading view

There are new articles available, click to refresh the page.

Hackers Use Stealer Logs to Bypass MFA and Launch Ransomware Attacks

Infostealer malware has now become the invisible thread linking petty credential theft to full-blown ransomware campaigns. Attackers no longer bother forcing their way through firewalls when infostealers have already unlocked the front door for them. Documented by DarkOwl,Β a stealer log archive generated by infostealer malware that silently harvests browser-saved passwords, session cookies, cryptocurrency wallet data, […]

The post Hackers Use Stealer Logs to Bypass MFA and Launch Ransomware Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Launches Unified Cryptonym-Based Naming System for Threat Actors

Google Threat Intelligence Group (GTIG) has introduced a unified cryptonym-based naming system for cyber threat actors, aiming to simplify attribution, improve analyst workflows, and eliminate inconsistencies between legacy tracking conventions used across Google’s security teams. The initiative follows the integration of Mandiant and Google’s Threat Analysis Group (TAG) into GTIG. Before the merger, both organizations […]

The post Google Launches Unified Cryptonym-Based Naming System for Threat Actors appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials

A sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials, cookies, payment data, and cryptocurrency wallet information from victims. Documented by Seqrite,Β the campaign uses two distinct phishing themes that both lead to the same infection chain. One email impersonates UPS Forwarding Hub, referencing fake […]

The post Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Hide Attacks

Six federal agencies have updated a joint advisory warning that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. critical infrastructure, manipulating human-machine interface (HMI) displays so operators cannot visually detect the intrusion. The advisory, first issued in April 2026 and revised on July 22, 2026, is cosigned […]

The post Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Hide Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical WordPress Core Flaw Lets Anonymous Hackers Gain Remote Code Execution

A newly disclosed a pre-authentication remote code execution (RCE) vulnerability in WordPress Core, dubbed β€œwp2shell,” that requires no authentication and affects stock WordPress installations with zero plugins installed. Given that WordPress powers an estimated 500 million websites globally. The flaw represents one of the most significant CMS security disclosures in recent memory. The issue stems […]

The post Critical WordPress Core Flaw Lets Anonymous Hackers Gain Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

EY Data Breach – Hackers Access Third-Party IT Support Platform and Steal Client Tax Documents

Ernst & Young LLP (EY) has confirmed a data security incident in which an unauthorized third party breached a third-party IT service management platform used by its tax practice, exfiltrating documents containing client personal and financial information. The Big Four firm filed formal breach notifications with the California Attorney General’s office on July 15, 2026, […]

The post EY Data Breach – Hackers Access Third-Party IT Support Platform and Steal Client Tax Documents appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenSSL DoS Vulnerability Lets Remote Attackers Exhaust Server Memory With an 11-Byte Payload

A newly disclosed vulnerability reminds us how deeply our digital infrastructure relies on foundational libraries. The Okta Red Team recently discovered β€œHollowByte,” a Denial of Service (DoS) flaw in OpenSSL that allows a remote, unauthenticated attacker to force a server to allocate disproportionate memory chunks before any security handshake even begins, using a payload just […]

The post OpenSSL DoS Vulnerability Lets Remote Attackers Exhaust Server Memory With an 11-Byte Payload appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Citrix Secure Access Client Flaw Lets Low-Privileged Windows Users Gain SYSTEM Privileges

Cloud Software Group has issued a High-severity security bulletin (CTX696734) disclosing two vulnerabilities in the Citrix Secure Access Client for Windows and the Citrix Endpoint Analysis Client for Windows. The more serious of the two, tracked as CVE-2026-53565, allows a standard, low-privileged user on a local system to escalate privileges and gain full SYSTEM access, […]

The post Citrix Secure Access Client Flaw Lets Low-Privileged Windows Users Gain SYSTEM Privileges appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

AWS GovCloud Credential Leak Leads CISA to Share Critical Cyber Incident Lessons

The Cybersecurity and Infrastructure Security Agency (CISA) has disclosed details of an internal security incident involving exposed AWS GovCloud credentials, offering a transparent account of its own incident response to help other organizations strengthen their defenses. On Friday, May 15, CISA’s Office of the Chief Information Officer (OCIO) launched an internal investigation after an investigative […]

The post AWS GovCloud Credential Leak Leads CISA to Share Critical Cyber Incident Lessons appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Infect C++ and C# Project Files to Spread Multi-Stage Windows Backdoor

A sophisticated Windows Trojan that compromises software development projects to distribute a multi-stage backdoor, data stealer, clipboard hijacker, cryptominer, and file infector. Documented by Doctor Web researchers and first observed in the final quarter of 2025, the malware has continued to develop and now targets C++ and C# development environments. By infecting Visual Studio project […]

The post Hackers Infect C++ and C# Project Files to Spread Multi-Stage Windows Backdoor appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Zimbra Releases Security Patch for Stored XSS Vulnerability in Classic Web Client

Zimbra has released its Daffodil v10.1.19 patch update, addressing a stored cross-site scripting (XSS) vulnerability in the platform’s Classic Web Client. The security issue could allow a specially crafted email message to execute malicious JavaScript within the context of a logged-in recipient’s webmail session. The update, released on July 7, 2026, includes fixes delivered through […]

The post Zimbra Releases Security Patch for Stored XSS Vulnerability in Classic Web Client appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Dell BIOS Flaw Lets Attackers Extract Plaintext Passwords Without Brute Force

A newly disclosed Dell BIOS password-storage flaw can allow attackers with physical access to recover administrator and user passwords from SPI flash dumps in milliseconds. Tracked as CVE-2026-40639 and addressed in Dell Security Advisory DSA-2026-197, the issue affects certain Dell client platforms that use the proprietary DVAR configuration store and the SystemPwSmm SMM driver. Dell […]

The post Dell BIOS Flaw Lets Attackers Extract Plaintext Passwords Without Brute Force appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌