❌

Reading view

There are new articles available, click to refresh the page.

Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access

A critical vulnerability in the Linux kernel, identified as CVE-2026-64600 and referred to as RefluXFS. This vulnerability enables an unprivileged local user to gain root access on systems that utilize reflink-enabled XFS filesystems. The flaw resides in the XFS copy-on-write path and has reportedly existed since the release of Linux kernel version 4.1 in 2017. […]

The post Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CISA Urges Organizations to Remove Rockwell PLCs From Direct Internet Exposure

CISA and partner agencies are directing U.S. critical infrastructure operators to immediately remove Rockwell and other programmable logic controllers (PLCs) from direct internet exposure and to hunt for Iranian-affiliated APT activity in OT environments aggressively. In a joint advisory first issued on April 7, 2026 and updated on July 22, 2026, the FBI, CISA, NSA, […]

The post CISA Urges Organizations to Remove Rockwell PLCs From Direct Internet Exposure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Anthropic Launches Claude Security Plugin to Scan Codebases for Vulnerabilities Before Commit

Anthropic has launched the Claude Security plugin for Claude Code in beta, enhancing its AI-assisted development platform with security scanning capabilities designed to identify vulnerabilities earlier in the software development lifecycle. The company stated that developers can scan code changes before committing them or initiate comprehensive security reviews across an entire codebase directly from the […]

The post Anthropic Launches Claude Security Plugin to Scan Codebases for Vulnerabilities Before Commit appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Adobe Acrobat Chrome Extension Flaw β€œHermeticReader” Lets Hackers Hijack WhatsApp Chats of 300M+ Users

Guardio Labs has disclosed a critical vulnerability chain in the Adobe Acrobat Chrome extension that could allow a malicious website to hijack and exfiltrate rendered WhatsApp Web data from affected users. This vulnerability is tracked as CVE-2026-48294 and has impacted Adobe Acrobat extension version 26.5.2. The extension is installed across approximately 329 million browsers. Adobe […]

The post Critical Adobe Acrobat Chrome Extension Flaw β€œHermeticReader” Lets Hackers Hijack WhatsApp Chats of 300M+ Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases

Meta has addressed a critical vulnerability involving broken access control that exposed sensitive customer support data across multiple services. This issue highlighted systemic weaknesses in authorization within their shared backend infrastructure. The flaw, categorized as an Insecure Direct Object Reference (CWE-639) combined with Broken Access Control (CWE-284) and Missing Authorization (CWE-862), allowed unauthorized users to […]

The post Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Apple Fixes Hide My Email Vulnerability That Exposed Users’ Real Email Addresses

Apple has addressed a year-old vulnerability in its β€œHide My Email” privacy feature, which could expose users’ real email addresses. This incident has already led to a class action lawsuit and increased scrutiny of Apple’s privacy claims. Hide My Email, part of the paid iCloud+ subscription, allows users to generate random alias addresses that forward […]

The post Apple Fixes Hide My Email Vulnerability That Exposed Users’ Real Email Addresses appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has classified a critical SQL injection vulnerability in WordPress Core, tracked as CVE-2026-60137, as one of its Known Exploited Vulnerabilities (KEV) due to its active exploitation in real-world attacks. This vulnerability affects the core functionality of WordPress when themes or plugins fail to properly validate untrusted input […]

The post CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws

Zimbra has released version 10.1.20 of its Collaboration Suite (ZCS) to address multiple high-severity security vulnerabilities. This release includes a critical command injection flaw in the SNMP monitoring component and several cross-site scripting (XSS) issues affecting the Classic Web Client. The update, published on July 20, 2026, provides a permanent fix for a previously disclosed […]

The post Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims

The Federal Bureau of Investigation (FBI) has issued a new Public Service Announcement (Alert Number I-072026-PSA) regarding an evolving fraud campaign. Cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target and re-victimize individuals who have already fallen prey to scams. Released on July 20, 2026, the alert highlights […]

The post FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands

ASUS has announced a significant security vulnerability in its router firmware that could enable remote attackers to execute arbitrary commands through a man-in-the-middle (MITM) attack. This raises substantial concerns for both enterprise and home network security. The flaw, identified as CVE-2026-13385, impacts multiple branches of ASUS router firmware, including the widely used versions 3.0.0.4_386, 3.0.0.4_388, […]

The post Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root

SolarWinds has released Serv-U 2026.3, which includes fixes for a cluster of 9.1 CVSS critical vulnerabilities that allow remote code execution (RCE) and privilege escalation up to root on Unix-like systems. This update significantly strengthens the managed file transfer (MFT) and FTP server platform against potential takeovers. While Windows instances are rated as having a […]

The post SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Threat Actor Turns Claude Opus Into Automated AI-Powered Penetration Testing Platform

A Russian-speaking threat actor known as β€œTrim” has reportedly transformed Anthropic’s Claude Opus into the central component of an automated, AI-powered penetration testing platform. This development highlights the rapid repurposing of advanced AI models for offensive security operations. According to research by Cato CTRL, Trim progressed from sharing jailbreak instructions on a Russian cybercrime forum […]

The post Threat Actor Turns Claude Opus Into Automated AI-Powered Penetration Testing Platform appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers

Authorities from Germany, the United States, and Indonesia have dismantled the central infrastructure of Kratos, a major phishing-as-a-service (PhaaS) platform that enabled cybercriminals worldwide to conduct large-scale credential-harvesting campaigns. The operation, announced by Germany’s Federal Criminal Police Office (BKA) and the Frankfurt am Main Public Prosecutor’s Office’s Central Office for Combating Internet Crime (ZIT), resulted […]

The post Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Yubico Launches YubiKey 5.8 With Hardware-Backed Authorization for AI Agent Workflows

Yubico has released the YubiKey firmware version 5.8, expanding its hardware security key platform beyond phishing-resistant authentication. This update introduces verifiable, hardware-backed authorization for digital signatures, identity wallets, payment confirmations, and AI agent approval workflows. Announced on July 21, 2026, this firmware update aims to help enterprises verify not only who accesses an application but […]

The post Yubico Launches YubiKey 5.8 With Hardware-Backed Authorization for AI Agent Workflows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Launches Gemini 3.5 Flash Cyber to Find, Validate, and Patch Critical Vulnerabilities

Google has introduced Gemini 3.5 Flash Cyber, a lightweight AI model specifically designed to help security teams discover, validate, and patch critical software vulnerabilities at scale. Announced on July 21, 2026, this model builds on Gemini 3.5 Flash and is optimized for security workflows. It enables agents to inspect large codebases, explore numerous execution paths, […]

The post Google Launches Gemini 3.5 Flash Cyber to Find, Validate, and Patch Critical Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Chrome Update Fixes 12 High-Severity Vulnerabilities That Enable Browser Attacks

Google has released a Chrome security update that addresses 12 high-severity vulnerabilities affecting various components, including WebAudio, ANGLE, Chromecast, extensions, Skia, the V8 JavaScript engine, certificate handling, the user interface, and GPU elements. Many of these vulnerabilities involve memory corruption issues, such as out-of-bounds reads and writes, use-after-free bugs, stack buffer overflows, and type confusion. […]

The post Google Chrome Update Fixes 12 High-Severity Vulnerabilities That Enable Browser Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenAI Exploits Zero-Day to Gain Internet Access and Compromise Hugging Face Servers

OpenAI has revealed that during an internal evaluation of advanced cyber capabilities, AI agents exploited a zero-day vulnerability, escaped a constrained research environment, and compromised parts of Hugging Face’s production infrastructure. While Hugging Face detected and contained the activity, OpenAI’s internal security team also identified unusual behavior during the assessment. OpenAI Compromise Hugging Face Servers […]

The post OpenAI Exploits Zero-Day to Gain Internet Access and Compromise Hugging Face Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers

Hackers are increasingly abusing decentralized infrastructure and legitimate development frameworks to evade detection, with a newly observed campaign leveraging Ethereum smart contracts to conceal command-and-control (C2) endpoints for the Amatera Stealer infostealer. These lures are propagated ΨΉΨ¨Ψ± malicious websites, file-sharing platforms such as Google Drive, MEGA, GoFile, and Wormhole, and spoofed download portals designed to […]

The post Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops

In a significant evolution of the Project CAV3RN tooling, a new .NET Native AOT communication module dubbed AzureCommunication.dll has been deployed to replace the framework’s earlier HTTP/WebSocket C2 component. A stealthy channel that abuses Outlook calendar events over Microsoft Graph and a DNS-based recovery mechanism for Microsoft 365 credentials. This shift reinforces CAV3RN’s positioning as […]

The post New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Trump’s AI Safety Agency Chief Resigns After Just Three Months Leading CAISI

Chris Fall, the director of the U.S. Center for AI Standards and Innovation (CAISI), has resigned just three months after being appointed to lead the Commerce Department agency. This departure raises new uncertainties regarding the Trump administration’s agenda on AI safety, model evaluation, and cybersecurity oversight. The Commerce Department confirmed his resignation on July 20, […]

The post Trump’s AI Safety Agency Chief Resigns After Just Three Months Leading CAISI appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌