❌

Reading view

There are new articles available, click to refresh the page.

Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code

GitLab has issued an emergency security update to address two critical vulnerabilities that could lead to unauthenticated file disclosure and authenticated credential theft, as well as a high-severity flaw that may enable remote code execution. The company released updated versions of GitLab Community Edition and Enterprise Edition, specifically versions 19.3.2, 19.2.6, and 19.1.8, on September […]

The post Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware

Cisco Talos has warned that threat actors are actively exploiting two vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software. These vulnerabilities can lead to unauthorized access, root-level code execution, credential theft, network reconnaissance, and malware deployment. Critical Cisco FMC Flaws The most critical issue is identified as CVE-2026-20079, a critical authentication-bypass vulnerability with a […]

The post Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ivanti Patches 10 EPMM, Neurons for ITSM and Sentry Flaws Enabling RCE and Admin Access

Ivanti has released security updates addressing 10 vulnerabilities in Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry. The vulnerabilities include several critical remote code execution (RCE) issues in Neurons for ITSM, an authentication bypass in Sentry that could grant administrative access, and a privilege escalation flaw in EPMM. Ivanti Patches 10 EPMM Flaws The […]

The post Ivanti Patches 10 EPMM, Neurons for ITSM and Sentry Flaws Enabling RCE and Admin Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Jellyfin 12.0 Released With Security Fixes for Unauthorized File Access and XSS Flaws

Jellyfin has released version 12.0, a significant update to its open-source media server. This version includes a wide range of platform improvements and essential security updates affecting both the server and the web client. The project strongly advises administrators to plan their upgrade carefully because it includes database migrations and compatibility-breaking changes for existing deployments. […]

The post Jellyfin 12.0 Released With Security Fixes for Unauthorized File Access and XSS Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access

Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities. These flaws can expose enterprise deployments to unauthenticated administrative access, remote command execution, and potential host-level compromise. Detailed in Dell Security Advisory DSA-2026-382, these issues affect SCG 5.0 appliance versions earlier than 5.36.00.16 and application versions […]

The post Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions

ConnectWise has announced a security issue affecting file transfer functionality in ScreenConnect Remote Access Support and Access sessions. This issue affects both cloud-hosted and on-premises ScreenConnect deployments. In response, the company has issued immediate mitigation guidance. At the same time, it is working on an official patch and securing a CVE identifier. The advisory, released […]

The post ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Roundcube Fixes 12 Security Flaws Including Zero-Click XSS and SSRF Bypass

Roundcube has released security updates 1.6.19 and 1.7.4, which address 12 vulnerabilities affecting its 1.6 LTS and 1.7 Webmail branches. The flaws include a zero-click stored cross-site scripting (XSS) vulnerability, several bypasses of remote content filtering, email header injection bugs, cross-user contact access issues, and a server-side request forgery (SSRF) bypass. Published on September 6, […]

The post Roundcube Fixes 12 Security Flaws Including Zero-Click XSS and SSRF Bypass appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Exploit PaperCut NG/MF Flaws to Steal Credentials and Deploy Meterpreter

Threat actors are actively exploiting two critical vulnerabilities in PaperCut NG/MF, identified as CVE-2026-81578 and CVE-2026-82078. These exploits allow attackers to take control of print management servers, steal credentials, and deploy Meterpreter payloads within enterprise networks. Analysts Jens Pose and Ross Phillips from Arctic Wolf reported that these intrusions progressed from remote command execution to […]

The post Hackers Exploit PaperCut NG/MF Flaws to Steal Credentials and Deploy Meterpreter appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution

Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin, allowing them to upload PHP backdoors and gain remote code execution. This flaw, tracked as CVE-2026-14894, affects Super Forms versions 6.3.313 and earlier. Administrators are urged to upgrade to version 6.3.314 immediately. Super Forms WordPress Flaw Wordfence disclosed this unauthenticated arbitrary […]

The post Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Plex Urges Users to Update Media Server as Multiple Security Flaws Are Discovered

Plex has urged users to promptly update their Plex Media Server and Plex Desktop software following the release of fixes for several undisclosed security issues in older versions. The recommended versions are Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The company advises that all server owners and desktop users upgrade to the latest release […]

The post Plex Urges Users to Update Media Server as Multiple Security Flaws Are Discovered appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft

TP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administrator credentials from captured login traffic. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh component and […]

The post TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Chrome V8 Flaw Actively Exploited in the Wild, Update Released

Google has released an urgent update for Chrome Stable to address CVE-2026-85046, a high-severity type confusion vulnerability in the V8 JavaScript and WebAssembly engine that is actively being exploited. This flaw can allow remote attackers to execute code within Chrome’s sandbox by convincing a victim to open a specially crafted HTML page. The security update […]

The post Google Chrome V8 Flaw Actively Exploited in the Wild, Update Released appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Sangoma Switchvox RCE Flaw Actively Exploited in Wild via Unauthenticated SQL Injection

Security researchers have reported active exploitation attempts targeting a critical vulnerability in Sangoma Switchvox, allowing unauthenticated attackers to execute code remotely via SQL injection. This vulnerability, tracked as CVE-2026-9586, affects internet-exposed Switchvox enterprise VoIP systems and was addressed in Switchvox version 8.4.0.2. Sangoma Switchvox RCE Flaw Zach Hanley, a researcher at Horizon3.ai, revealed that this […]

The post Sangoma Switchvox RCE Flaw Actively Exploited in Wild via Unauthenticated SQL Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Three HP Easy Start Flaws Let Attackers Gain Root Privileges on macOS

Three high-severity vulnerabilities in HP Easy Start for macOS could allow both local and network-positioned attackers to disrupt the printer software installation process and, under certain conditions, gain privileged access or modify files with root permissions. These vulnerabilities, tracked as CVE-2026-12554, CVE-2026-12555, and CVE-2026-12556, were discovered by researcher Nir Yehoshua from Cipher Security Labs during […]

The post Three HP Easy Start Flaws Let Attackers Gain Root Privileges on macOS appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CISA Warns SonicWall SMA1000 Flaws Are Actively Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting SonicWall SMA1000 appliances to its Known Exploited Vulnerabilities (KEV) Catalog, warning that these flaws are actively being exploited in real-world attacks. The vulnerabilities, identified as CVE-2026-83548 and CVE-2026-83549, affect SonicWall’s Secure Mobile Access (SMA1000) remote-access appliances. CISA Warns SonicWall SMA1000 Flaws CISA […]

The post CISA Warns SonicWall SMA1000 Flaws Are Actively Exploited in Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

FreeRDP 3.31.0 Fixes 22 Security Flaws Including Heap Overflow and Pre-Auth DoS Bugs

FreeRDP version 3.31.0 has been released as a significant security and stability update, addressing 22 disclosed security vulnerabilities in the widely used open-source implementation of the Remote Desktop Protocol (RDP). Project maintainers have termed this release a β€œhuge bug fix and security release” and strongly encourage distributors to update promptly due to the serious nature […]

The post FreeRDP 3.31.0 Fixes 22 Security Flaws Including Heap Overflow and Pre-Auth DoS Bugs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical SonicWall SMA 1000 Vulnerabilities Actively Exploited in the Wild

SonicWall has issued an urgent security advisory regarding two vulnerabilities affecting its SMA 1000 Series secure access appliances. The company warns that there have been cases indicating active exploitation in the wild. The vulnerabilities are tracked as CVE-2026-83548 and CVE-2026-83549 and impact SonicWall SMA 1000 models 6210, 7210, and 8200v that are running vulnerable platform […]

The post Critical SonicWall SMA 1000 Vulnerabilities Actively Exploited in the Wild appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Patches 26 Chrome Vulnerabilities, Including Critical WebGL and Shared Tab Groups Flaws

Google has released a new update for the Chrome Stable Channel on desktop platforms, addressing 26 security vulnerabilities. This includes two critical use-after-free flaws affecting WebGL and Shared Tab Groups. The update upgrades Chrome to version 152.0.7977.75 on Windows and macOS, while Linux users receive version 152.0.7977.76. Google stated that the update will be rolled […]

The post Google Patches 26 Chrome Vulnerabilities, Including Critical WebGL and Shared Tab Groups Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌