❌

Reading view

There are new articles available, click to refresh the page.

New Kimi K3 AI Agent Uncovers Redis Remote Code Execution Flaws in Just 27 Minutes

Moonshot AI’s newly unveiled Kimi K3 model is attracting considerable attention in the cybersecurity community after successfully demonstrating its ability to autonomously identify critical vulnerabilities in Redis within minutes. This 2.8-trillion-parameter AI agent reportedly discovered multiple remote code execution (RCE) vulnerabilities across various Redis versions, specifically 6.2.22, 7.4.9, 8.6.4, and 8.8.0. This highlights the increasing […]

The post New Kimi K3 AI Agent Uncovers Redis Remote Code Execution Flaws in Just 27 Minutes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New TriBack Loader Evades EDR Using Signed Binaries and Win32 Callback APIs

A new shellcode loader, dubbed β€œTriBack Loader,” to a China-nexus intrusion cluster tracked as JadeProx, with the malware explicitly engineered to evade modern EDR by abusing signed binaries and uncommon Win32 callback APIs. Across at least four observed variants, the loader underpins simultaneous espionage campaigns in South-East Asia and Latin America, including targeting of a […]

The post New TriBack Loader Evades EDR Using Signed Binaries and Win32 Callback APIs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical FreePBX Flaws Let Unauthenticated Attackers Execute Code and Take Over Administrator Accounts

Critical security vulnerabilities in FreePBX have been disclosed, exposing organizations to risks of unauthenticated remote code execution and the takeover of administrator accounts. These flaws, tracked under GitHub advisories GHSA-37j8-fhxx-9vhp and GHSA-g27h-xf3q-h3rm, affect FreePBX versions 16 and 17, carrying a CVSS v4 base score of 9.3, which highlights their severity. Security researchers warn that these […]

The post Critical FreePBX Flaws Let Unauthenticated Attackers Execute Code and Take Over Administrator Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical FreeRDP Clipboard Flaw Could Let Malicious RDP Servers Execute Code

A critical heap buffer overflow vulnerability in FreeRDP’s Windows client could allow a malicious Remote Desktop Protocol (RDP) server to corrupt memory and potentially execute arbitrary code on a connecting client. This flaw specifically affects the Clipboard Redirection (CLIPRDR) virtual channel in wfreerdp, where an attacker-controlled response can exceed the size that the client originally […]

The post Critical FreeRDP Clipboard Flaw Could Let Malicious RDP Servers Execute Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers

Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers, with a primary focus on cPanel and WHM deployments. The campaign first surfaced when malicious development versions were discovered across ten Packagist PHP packages tied to a legitimate PHP and DevOps […]

The post Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Exim Vulnerability Lets Attackers Access Files Outside the Mail Spool

A high-severity directory traversal vulnerability has been discovered in the Exim mail transfer agent. This flaw allows local attackers to access files outside the intended mail spool directory and potentially escalate their privileges. It is tracked as EXIM-Security-2026-06-22.1 and assigned GCVE-25-2026-07-45-1. The vulnerability affects Exim versions 4.88 through 4.99.4 and was announced on July 22, […]

The post Exim Vulnerability Lets Attackers Access Files Outside the Mail Spool appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims

A new Windows-focused infostealer and remote access trojan (RAT) dubbed Dolphin X is being advertised on cybercrime forums with a clear pitch: automate the theft and triage of high-value corporate targets. Unlike commodity stealers that focus mainly on browser passwords, Dolphin X is positioned as an enterprise-adjacent data vacuum with a built-in AI-powered victim scoring […]

The post New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication

A critical authentication bypass vulnerability affecting Check Point SmartConsole has been actively exploited in the wild, allowing attackers to gain unauthorized access to security management systems under specific configurations. The flaw, tracked as CVE-2026-16232, carries a CVSS score of 9.3 and impacts Check Point Security Management and Multi-Domain Management deployments, particularly when management interfaces are […]

The post Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root

A recently disclosed vulnerability in Ubuntu’s snap ecosystem, identified as CVE-2026-8933, presents a critical local privilege escalation flaw. This vulnerability allows unprivileged users to execute arbitrary code with root privileges. Qualys discovered the issue in snap-confine, a core component used by snapd to set up execution environments for snap applications. It affects specific Ubuntu releases […]

The post Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Adds Prompt Injection Protection to Defender for Office 365

Microsoft has introduced prompt injection protection in Defender for Office 365, representing a significant advancement in securing enterprise email environments against emerging AI-targeted threats. As organizations increasingly adopt AI assistants like Microsoft 365 Copilot to summarize, triage, and respond to emails, attackers are shifting their tactics from traditional phishing methods to manipulating AI systems directly. […]

The post Microsoft Adds Prompt Injection Protection to Defender for Office 365 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars

A critical Bluetooth vulnerability in dealer-installed KARR Security Systems is putting over 2 million vehicles at risk of unauthorized access and immobilization. This situation has prompted urgent calls for drivers to update affected devices. Researchers at the University of California, San Diego, revealed that the flaw allows attackers within Bluetooth range to issue commands such […]

The post KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data

Chick-fil-A has confirmed a data breach affecting an undisclosed number of Chick-fil-A One loyalty accounts. This breach occurred as threat actors executed credential-stuffing attacks on its website and mobile application. The incident underscores the ongoing risk associated with password reuse, where usernames and passwords exposed in unrelated third-party breaches are automatically tested against consumer platforms. […]

The post Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Unknown Attackers Remain Inside South Korean Diplomatic System for Nearly 10 Months

Unknown attackers maintained long-term, covert access to South Korea’s diplomatic training infrastructure for nearly ten months, exposing personal data tied to almost the entire diplomatic cadre and highlighting structural weaknesses in the Foreign Ministry’s security governance. South Korea’s Ministry of Foreign Affairs (MoFA) has confirmed a prolonged compromise of the Korea National Diplomatic Academy (KNDA) […]

The post Unknown Attackers Remain Inside South Korean Diplomatic System for Nearly 10 Months appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Unveils CodeMender AI Agent for Automated Vulnerability Detection and Remediation

Google has unveiled CodeMender, a managed AI security agent designed to identify, validate, and remediate software vulnerabilities at machine speed. Announced in preview on July 22, 2023, the tool is available through the Gemini Enterprise Agent Platform and can also function as a core component of Google’s AI Threat Defense offering. This launch comes as […]

The post Google Unveils CodeMender AI Agent for Automated Vulnerability Detection and Remediation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New TrickBot Malware Variant Uses DNS Tunneling for Command-and-Control

A new TrickBot malware variant that significantly evolves its command-and-control (C2) communication by leveraging DNS tunneling, replacing the traditional HTTP-based mechanisms observed in earlier campaigns. The discovery highlights a continued shift among financially motivated threat actors toward stealthier communication channels designed to evade network detection and security controls. However, the newly analyzed samples demonstrate a […]

The post New TrickBot Malware Variant Uses DNS Tunneling for Command-and-Control appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

26 Unauthenticated Vulnerability Advisories Expose Firewalls, VPNs, Switches, and Load Balancers

A structural risk in enterprise infrastructure: unauthenticated, remotely exploitable vulnerabilities embedded in the very devices designed to secure networks. In the 30 days ending July 17, 2026, 61 advisories across 14 vendors were disclosed, including six critical issues. However, the more consequential signal lies elsewhere 26 of those advisories require no authentication. They are reachable […]

The post 26 Unauthenticated Vulnerability Advisories Expose Firewalls, VPNs, Switches, and Load Balancers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access

A critical vulnerability in the Linux kernel, identified as CVE-2026-64600 and referred to as RefluXFS. This vulnerability enables an unprivileged local user to gain root access on systems that utilize reflink-enabled XFS filesystems. The flaw resides in the XFS copy-on-write path and has reportedly existed since the release of Linux kernel version 4.1 in 2017. […]

The post Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CISA Urges Organizations to Remove Rockwell PLCs From Direct Internet Exposure

CISA and partner agencies are directing U.S. critical infrastructure operators to immediately remove Rockwell and other programmable logic controllers (PLCs) from direct internet exposure and to hunt for Iranian-affiliated APT activity in OT environments aggressively. In a joint advisory first issued on April 7, 2026 and updated on July 22, 2026, the FBI, CISA, NSA, […]

The post CISA Urges Organizations to Remove Rockwell PLCs From Direct Internet Exposure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Anthropic Launches Claude Security Plugin to Scan Codebases for Vulnerabilities Before Commit

Anthropic has launched the Claude Security plugin for Claude Code in beta, enhancing its AI-assisted development platform with security scanning capabilities designed to identify vulnerabilities earlier in the software development lifecycle. The company stated that developers can scan code changes before committing them or initiate comprehensive security reviews across an entire codebase directly from the […]

The post Anthropic Launches Claude Security Plugin to Scan Codebases for Vulnerabilities Before Commit appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Adobe Acrobat Chrome Extension Flaw β€œHermeticReader” Lets Hackers Hijack WhatsApp Chats of 300M+ Users

Guardio Labs has disclosed a critical vulnerability chain in the Adobe Acrobat Chrome extension that could allow a malicious website to hijack and exfiltrate rendered WhatsApp Web data from affected users. This vulnerability is tracked as CVE-2026-48294 and has impacted Adobe Acrobat extension version 26.5.2. The extension is installed across approximately 329 million browsers. Adobe […]

The post Critical Adobe Acrobat Chrome Extension Flaw β€œHermeticReader” Lets Hackers Hijack WhatsApp Chats of 300M+ Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌