❌

Reading view

There are new articles available, click to refresh the page.

Foxit PDF Reader Flaw Lets Local Attackers Gain SYSTEM Privileges via DLL Sideloading

A recently disclosed vulnerability in Foxit PDF Reader may allow a local attacker with existing code execution to elevate their privileges to NT AUTHORITY\SYSTEM. This issue, tracked as CVE-2026-57239, affects Foxit PDF Reader installations prior to version 2026.2 and arises from the insecure handling of an updater workflow triggered by a user-writable file in the […]

The post Foxit PDF Reader Flaw Lets Local Attackers Gain SYSTEM Privileges via DLL Sideloading appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos

An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, admitted to charges including aggravated identity theft, wire fraud, computer fraud, conspiracy to commit computer fraud, and […]

The post Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

JetBrains Patches Multiple Vulnerabilities Affecting IntelliJ IDEA and TeamCity

JetBrains has addressed a series of security vulnerabilities affecting IntelliJ IDEA and TeamCity, including several critical flaws that could allow code execution or unauthorized actions in development and continuous integration environments. The updates fix weaknesses in Remote Development sessions, Git and Perforce VCS integrations, workspace handling, agent registration, and permission validation. JetBrains Patches Multiple Vulnerabilities […]

The post JetBrains Patches Multiple Vulnerabilities Affecting IntelliJ IDEA and TeamCity appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Australian Energy Giant Origin Confirms Data Breach Exposes Customer Data

Origin Energy Limited has confirmed a cybersecurity incident involving unauthorized access to and disclosure of customer data, representing a significant data security event for one of Australia’s largest energy providers. The company identified the breach on July 22, 2026, and it is currently under active investigation to determine the full extent and impact on affected […]

The post Australian Energy Giant Origin Confirms Data Breach Exposes Customer Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code

Apache Syncope has released versions 4.1.24.1, 4.1.24.1.2, and 4.0.74.0.7 to address six security vulnerabilities affecting the 4.1, 4.0, and 3.0 release branches. These vulnerabilities include a self-service privilege escalation bug, multiple post-authentication remote code execution (RCE) pathways, authenticated server-side request forgery (SSRF), and SQL injection issues. Apache Syncope Flaws CVE-2026-62183 affects deployments that utilize the […]

The post Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Chrome 150 Update Fixes Four High-Severity Security Vulnerabilities

Google Chrome version 150.0.7871.186 has addressed four high-severity vulnerabilities that affect core browser components, including Codecs, WebMCP, Blink, and Input. While Google has not reported any evidence indicating that these vulnerabilities are actively being exploited, the company has restricted access to technical bug reports and related information until a majority of Chrome users receive the […]

The post Google Chrome 150 Update Fixes Four High-Severity Security Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Claude Cowork Sandbox Escape Flaw Lets Attackers Access SSH Keys and Cloud Credentials

A newly revealed sandbox escape vulnerability affecting Anthropic’s Claude Cowork could allow untrusted content processed by the AI agent to access sensitive files on a macOS host. This includes SSH private keys, cloud credentials, and other data that are available to the logged-in user. Security researcher Oren Yomtov from Accomplish has named this attack path […]

The post Claude Cowork Sandbox Escape Flaw Lets Attackers Access SSH Keys and Cloud Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day to Steal 90 Days of Emails

Russian state-supported threat actors, known as LAUNDRY BEAR, have exploited a zero-day vulnerability in the Zimbra Collaboration Suite to steal up to 909,090 days’ worth of emails from targeted organizations across Western countries. A joint cybersecurity advisory, AA26-204A, issued on July 23, 2026, warns that this espionage-focused group has targeted government, defense, energy, technology, education, […]

The post Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day to Steal 90 Days of Emails appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Weaponize Notepad++ Plugins to Silently Infect Windows Systems

CERT-UA has issued a warning regarding the UAC-0099 threat cluster, which has revised its malware delivery method by exploiting the legitimate Notepad++ application to load a malicious DLL disguised as a plugin. This campaign, observed since mid-summer 2026, introduces two newly identified tools, LUNCHPOKE and BURNYBEAR, along with an updated MATCHBOIL.V2 loader. This activity highlights […]

The post Hackers Weaponize Notepad++ Plugins to Silently Infect Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Next.js Patches Nine Security Flaws Enabling SSRF, Middleware Bypass, DoS, and Internal Endpoint Disclosure

The Next.js team has released security updates that address nine vulnerabilities affecting the App Router, Server Actions, rewrites, image optimization, caching, and middleware deployments. Organizations are urged to upgrade to Next.js versions 15.5.21 or 16.2.11 immediately, as these updates fix high- and moderate-severity flaws that could lead to server-side request forgery (SSRF), authentication bypass, denial […]

The post Next.js Patches Nine Security Flaws Enabling SSRF, Middleware Bypass, DoS, and Internal Endpoint Disclosure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Top 10 Best Physical Security Penetration Testing Firms 2026

In an era dominated by cyber threats, the importance of physical security penetration testing often gets overshadowed. However, a robust security posture requires a holistic approach that addresses vulnerabilities in both the digital and physical realms. A determined attacker can bypass sophisticated cyber defenses simply by walking through an unlocked door, exploiting weak physical controls, […]

The post Top 10 Best Physical Security Penetration Testing Firms 2026 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New Kimi K3 AI Agent Uncovers Redis Remote Code Execution Flaws in Just 27 Minutes

Moonshot AI’s newly unveiled Kimi K3 model is attracting considerable attention in the cybersecurity community after successfully demonstrating its ability to autonomously identify critical vulnerabilities in Redis within minutes. This 2.8-trillion-parameter AI agent reportedly discovered multiple remote code execution (RCE) vulnerabilities across various Redis versions, specifically 6.2.22, 7.4.9, 8.6.4, and 8.8.0. This highlights the increasing […]

The post New Kimi K3 AI Agent Uncovers Redis Remote Code Execution Flaws in Just 27 Minutes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical FreePBX Flaws Let Unauthenticated Attackers Execute Code and Take Over Administrator Accounts

Critical security vulnerabilities in FreePBX have been disclosed, exposing organizations to risks of unauthenticated remote code execution and the takeover of administrator accounts. These flaws, tracked under GitHub advisories GHSA-37j8-fhxx-9vhp and GHSA-g27h-xf3q-h3rm, affect FreePBX versions 16 and 17, carrying a CVSS v4 base score of 9.3, which highlights their severity. Security researchers warn that these […]

The post Critical FreePBX Flaws Let Unauthenticated Attackers Execute Code and Take Over Administrator Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical FreeRDP Clipboard Flaw Could Let Malicious RDP Servers Execute Code

A critical heap buffer overflow vulnerability in FreeRDP’s Windows client could allow a malicious Remote Desktop Protocol (RDP) server to corrupt memory and potentially execute arbitrary code on a connecting client. This flaw specifically affects the Clipboard Redirection (CLIPRDR) virtual channel in wfreerdp, where an attacker-controlled response can exceed the size that the client originally […]

The post Critical FreeRDP Clipboard Flaw Could Let Malicious RDP Servers Execute Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Exim Vulnerability Lets Attackers Access Files Outside the Mail Spool

A high-severity directory traversal vulnerability has been discovered in the Exim mail transfer agent. This flaw allows local attackers to access files outside the intended mail spool directory and potentially escalate their privileges. It is tracked as EXIM-Security-2026-06-22.1 and assigned GCVE-25-2026-07-45-1. The vulnerability affects Exim versions 4.88 through 4.99.4 and was announced on July 22, […]

The post Exim Vulnerability Lets Attackers Access Files Outside the Mail Spool appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication

A critical authentication bypass vulnerability affecting Check Point SmartConsole has been actively exploited in the wild, allowing attackers to gain unauthorized access to security management systems under specific configurations. The flaw, tracked as CVE-2026-16232, carries a CVSS score of 9.3 and impacts Check Point Security Management and Multi-Domain Management deployments, particularly when management interfaces are […]

The post Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root

A recently disclosed vulnerability in Ubuntu’s snap ecosystem, identified as CVE-2026-8933, presents a critical local privilege escalation flaw. This vulnerability allows unprivileged users to execute arbitrary code with root privileges. Qualys discovered the issue in snap-confine, a core component used by snapd to set up execution environments for snap applications. It affects specific Ubuntu releases […]

The post Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Adds Prompt Injection Protection to Defender for Office 365

Microsoft has introduced prompt injection protection in Defender for Office 365, representing a significant advancement in securing enterprise email environments against emerging AI-targeted threats. As organizations increasingly adopt AI assistants like Microsoft 365 Copilot to summarize, triage, and respond to emails, attackers are shifting their tactics from traditional phishing methods to manipulating AI systems directly. […]

The post Microsoft Adds Prompt Injection Protection to Defender for Office 365 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars

A critical Bluetooth vulnerability in dealer-installed KARR Security Systems is putting over 2 million vehicles at risk of unauthorized access and immobilization. This situation has prompted urgent calls for drivers to update affected devices. Researchers at the University of California, San Diego, revealed that the flaw allows attackers within Bluetooth range to issue commands such […]

The post KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data

Chick-fil-A has confirmed a data breach affecting an undisclosed number of Chick-fil-A One loyalty accounts. This breach occurred as threat actors executed credential-stuffing attacks on its website and mobile application. The incident underscores the ongoing risk associated with password reuse, where usernames and passwords exposed in unrelated third-party breaches are automatically tested against consumer platforms. […]

The post Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌