❌

Reading view

There are new articles available, click to refresh the page.

China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks

Researcher has discovered a rapidly spreading exploit kit called BlueMoon, which combines vulnerabilities in the Chrome browser with a Windows kernel privilege-escalation flaw to compromise targets in espionage campaigns. This activity was first observed on August 28, 2026, and at least four threat clusters have adopted it, most of which are suspected to have ties […]

The post China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Windows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM

A newly published proof-of-concept (PoC) called ShieldCrash reveals an unpatched vulnerability in Microsoft Defender that allows a local attacker to gain arbitrary file-read access in the SYSTEM context. This disclosure, attributed to the researcher known as MSNightmare, comes shortly after Microsoft addressed an elevation-of-privilege flaw in the Microsoft Malware Protection Engine, tracked as CVE-2026-69414, referred […]

The post Windows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Magento and Adobe Commerce StyleSmuggler 0-Day RCE Actively Exploited in Attacks

Security researchers have discovered an actively exploited, unauthenticated remote code execution vulnerability affecting installations of Magento Open Source and Adobe Commerce. This vulnerability, known as StyleSmuggler, allows attackers to inject PHP payloads into Magento’s template system and execute them via standard application workflows. Sansec’s Forensics Team reported that attacks began on September 4, targeting internet-facing […]

The post Magento and Adobe Commerce StyleSmuggler 0-Day RCE Actively Exploited in Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CrowdStrike Falcon Zero-Day Lets Attackers Escalate Privileges on Windows Systems

A recently released proof-of-concept, named FalconFlank, claims to reveal a local privilege escalation vulnerability in the CrowdStrike Falcon Sensor on Windows. CrowdStrike is actively investigating these claims and has advised customers to turn off the Microsoft Office File Suspicious Macro Removal policy while the assessment is ongoing. CrowdStrike Falcon Zero-Day The project was published on […]

The post CrowdStrike Falcon Zero-Day Lets Attackers Escalate Privileges on Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Cursor’s Unpatched Zero-Day Lets a Fake git.exe Hijack Any Windows Developer

A Cursor zero-day vulnerability lets a planted git.exe run automatically when a Windows developer opens a repository. Mindgard disclosed it after seven months of silence from Cursor.

Cursor’s Unpatched Zero-Day Lets a Fake git.exe Hijack Any Windows Developer on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.

Two Joomla Extensions Hit by Zero-Day File Upload Attacks Before Patches Landed

CISA added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities catalog after automated attackers exploited file upload flaws in iCagenda and Balbooa Forms weeks before either bug had a CVE number.

Two Joomla Extensions Hit by Zero-Day File Upload Attacks Before Patches Landed on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.

❌