❌

Reading view

There are new articles available, click to refresh the page.

AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process

A five-stage AsyncRAT campaign that chains a socially engineered batch file, hidden PowerShell execution, AutoIt abuse and process injection to conceal a .NET remote-access trojan inside Microsoft’s legitimate charmap.exe process. The infection begins with a lure named β€œRight-click to open Invoice Details.bat”, which relies on user interaction to trigger execution. While the precise delivery method […]

The post AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms to steal password hashes without directly compromising a domain controller. This technique, known as DCSync, allows attackers with privileged domain credentials to impersonate a legitimate domain controller and request sensitive directory replication data. Unlike noisy attacks that use malware on servers or attempt to extract credentials […]

The post Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks

Researcher has discovered a rapidly spreading exploit kit called BlueMoon, which combines vulnerabilities in the Chrome browser with a Windows kernel privilege-escalation flaw to compromise targets in espionage campaigns. This activity was first observed on August 28, 2026, and at least four threat clusters have adopted it, most of which are suspected to have ties […]

The post China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Windows BitLocker Flaw Lets Attackers Execute Code on Vulnerable Systems

Microsoft disclosed CVE-2026-69449, an Important-severity vulnerability in Windows BitLocker. This issue is classified as a heap-based buffer overflow (CWE-122) and may allow remote code execution (RCE). Microsoft released details about this vulnerability on September 8, 2026. The CVSS 3.1 base score is 6.7, with a temporal score of 5.8. Windows BitLocker Flaw The vulnerability uses […]

The post Windows BitLocker Flaw Lets Attackers Execute Code on Vulnerable Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Windows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM

A newly published proof-of-concept (PoC) called ShieldCrash reveals an unpatched vulnerability in Microsoft Defender that allows a local attacker to gain arbitrary file-read access in the SYSTEM context. This disclosure, attributed to the researcher known as MSNightmare, comes shortly after Microsoft addressed an elevation-of-privilege flaw in the Microsoft Malware Protection Engine, tracked as CVE-2026-69414, referred […]

The post Windows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Panzer Ransomware Emerges With Windows, Linux, ESXi and FreeBSD Attack Support

A newly identified ransomware-as-a-service operation, Panzer, has surfaced with advertised payload support for Windows, Linux, VMware ESXi and FreeBSD, positioning it as a cross-platform threat to enterprise and virtualized environments. The group’s rapid victim posting cadence, affiliate-focused infrastructure, and double-extortion model make it a ransomware operation security teams should begin tracking despite the current absence […]

The post Panzer Ransomware Emerges With Windows, Linux, ESXi and FreeBSD Attack Support appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

BYOTC Attack Abuses Trusted Windows Clients to Access Privileged Kernel Driver Operations

A newly documented Windows attack pattern, dubbed Bring Your Own Trusted Caller (BYOTC), shows how attackers can bypass driver-level authorization controls without exploiting a traditional memory-corruption flaw. Instead of attacking a privileged kernel driver directly, an adversary compromises or abuses the legitimate user-mode application that the driver already trusts. The technique expands on the well-known […]

The post BYOTC Attack Abuses Trusted Windows Clients to Access Privileged Kernel Driver Operations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors

The financially motivated threat actor Toy Ghouls has expanded its custom malware arsenal with two Windows backdoors that abuse HiveMQ’s public MQTT infrastructure and the Matrix-based Element messaging ecosystem for command-and-control communications. The development marks a notable evolution for the group, which previously leaned on publicly available tools and leaked ransomware builders before introducing its […]

The post Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CrowdStrike Falcon Zero-Day Lets Attackers Escalate Privileges on Windows Systems

A recently released proof-of-concept, named FalconFlank, claims to reveal a local privilege escalation vulnerability in the CrowdStrike Falcon Sensor on Windows. CrowdStrike is actively investigating these claims and has advised customers to turn off the Microsoft Office File Suspicious Macro Removal policy while the assessment is ongoing. CrowdStrike Falcon Zero-Day The project was published on […]

The post CrowdStrike Falcon Zero-Day Lets Attackers Escalate Privileges on Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems

A malicious ScreenConnect campaign in which rogue remote-access clients do more than provide attackers with hands-on control: modified clients can automatically push a multi-stage VBScript malware chain to newly connected Windows endpoints. Once deployed, the clients repeatedly spawned wscript.exe to execute four scripts 1.vbs, 2.vbs, 3.vbs, and 4.vbs from ScreenConnect-related temporary locations. The behavior is […]

The post Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks

Microsoft will start automatically enabling Memory Integrity protection on eligible Windows devices through quality updates beginning in October 2026. This change aims to strengthen defenses against kernel-level attacks by ensuring that only trusted kernel-mode code and drivers can run on supported systems. Memory Integrity is a security feature built on Virtualization-based Security (VBS), a Windows […]

The post Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Claude AI Can Now Control macOS and Windows Computers to Click, Type and Open Apps

Anthropic has enhanced Claude’s desktop automation capabilities, enabling the AI assistant to operate directly on macOS and Windows computers through Claude Cowork and Claude Code. When this feature is enabled, Claude can navigate a visible screen, click controls, type text, launch applications, open files, and work within browser-based or local tools if no dedicated connector […]

The post Claude AI Can Now Control macOS and Windows Computers to Click, Type and Open Apps appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Fake Microsoft Edge, Kaspersky and Razer Installers Used to Compromise Windows Systems

An active malware campaign that abuses counterfeit download pages for trusted software brands including Microsoft Edge, Kaspersky and Razer to compromise Windows devices. Victims span healthcare, manufacturing, gaming, technology, logistics, government and education, highlighting the broad appeal of software-download lures. Microsoft has not attributed the activity to a nation-state actor, but the campaign’s infrastructure, payload […]

The post Fake Microsoft Edge, Kaspersky and Razer Installers Used to Compromise Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌