โŒ

Reading view

There are new articles available, click to refresh the page.

Swiss train maker tells ransomware crooks to get off at the next stop

Swiss rail manufacturer Stadler Rail says it refused a CHF 10 million ($12.3 million) ransom demand after the Everest ransomware gang compromised one of its suppliers. Stadler will not pay, and based on its account of events, the company appears to have got off lightly. It stated that "no security-relevant data [was] affected" in the breach, which was limited to "technical information from a supplier." According to its announcement, "no relevant personal data was stolen," and the incident had no impact on the functioning of its rolling stock (train and tram carriages) or its global production lines. The attackers accessed the technical data through a "data exchange platform" Stadler used with the unnamed supplier, authenticating with compromised login credentials. "Stadler's IT systems were not compromised and remained intact," the company said. At the time of writing, Stadler does not appear on Everest's data leak site (DLS), nor has the swiped technical data been leaked. Stadler's absence from the extortion group's website is unusual. The typical cyber extortion playbook involves the crooks first notifying victims that data has been stolen and/ or encrypted, then issuing their demand and threat to leak data if the ransom is unpaid. Failure to meet the deadline - or refuse outright, as Stadler did - typically lands the victim organization a spot on the extortionist's DLS. That's often when a second countdown timer begins. Criminals typically offer victims another few days to realize they are not bluffing and will leak the stolen data if a fee isn't paid. If they pay, victims are scrubbed from the DLS. If they don't, their data is leaked. That's the usual playbook. However, for a victim to both refuse to pay a ransom and not appear on the gang's DLS is an oddity. Everest, a Russian-speaking cybercrime group, has operated since circa December 2020 and claimed attacks on sportswear giant Under Armour, Mailchimp, AT&T, and Collins Aerospace, to name just a few. It's dabbled in both encryptionless extortion and double extortion, and has branched out into initial access brokering and recruiting corporate insiders. ยฎ

Critical FreePBX Flaws Let Unauthenticated Attackers Execute Code and Take Over Administrator Accounts

Critical security vulnerabilities in FreePBX have been disclosed, exposing organizations to risks of unauthenticated remote code execution and the takeover of administrator accounts. These flaws, tracked under GitHub advisories GHSA-37j8-fhxx-9vhp and GHSA-g27h-xf3q-h3rm, affect FreePBX versions 16 and 17, carrying a CVSS v4 base score of 9.3, which highlights their severity. Security researchers warn that these [โ€ฆ]

The post Critical FreePBX Flaws Let Unauthenticated Attackers Execute Code and Take Over Administrator Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical FreeRDP Clipboard Flaw Could Let Malicious RDP Servers Execute Code

A critical heap buffer overflow vulnerability in FreeRDPโ€™s Windows client could allow a malicious Remote Desktop Protocol (RDP) server to corrupt memory and potentially execute arbitrary code on a connecting client. This flaw specifically affects the Clipboard Redirection (CLIPRDR) virtual channel in wfreerdp, where an attacker-controlled response can exceed the size that the client originally [โ€ฆ]

The post Critical FreeRDP Clipboard Flaw Could Let Malicious RDP Servers Execute Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers

Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers, with a primary focus on cPanel and WHM deployments. The campaign first surfaced when malicious development versions were discovered across ten Packagist PHP packages tied to a legitimate PHP and DevOps [โ€ฆ]

The post Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Exim Vulnerability Lets Attackers Access Files Outside the Mail Spool

A high-severity directory traversal vulnerability has been discovered in the Exim mail transfer agent. This flaw allows local attackers to access files outside the intended mail spool directory and potentially escalate their privileges. It is tracked as EXIM-Security-2026-06-22.1 and assigned GCVE-25-2026-07-45-1. The vulnerability affects Exim versions 4.88 through 4.99.4 and was announced on July 22, [โ€ฆ]

The post Exim Vulnerability Lets Attackers Access Files Outside the Mail Spool appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims

A new Windows-focused infostealer and remote access trojan (RAT) dubbed Dolphin X is being advertised on cybercrime forums with a clear pitch: automate the theft and triage of high-value corporate targets. Unlike commodity stealers that focus mainly on browser passwords, Dolphin X is positioned as an enterprise-adjacent data vacuum with a built-in AI-powered victim scoring [โ€ฆ]

The post New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication

A critical authentication bypass vulnerability affecting Check Point SmartConsole has been actively exploited in the wild, allowing attackers to gain unauthorized access to security management systems under specific configurations. The flaw, tracked as CVE-2026-16232, carries a CVSS score of 9.3 and impacts Check Point Security Management and Multi-Domain Management deployments, particularly when management interfaces are [โ€ฆ]

The post Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root

A recently disclosed vulnerability in Ubuntuโ€™s snap ecosystem, identified as CVE-2026-8933, presents a critical local privilege escalation flaw. This vulnerability allows unprivileged users to execute arbitrary code with root privileges. Qualys discovered the issue in snap-confine, a core component used by snapd to set up execution environments for snap applications. It affects specific Ubuntu releases [โ€ฆ]

The post Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Adds Prompt Injection Protection to Defender for Office 365

Microsoft has introduced prompt injection protection in Defender for Office 365, representing a significant advancement in securing enterprise email environments against emerging AI-targeted threats. As organizations increasingly adopt AI assistants like Microsoft 365 Copilot to summarize, triage, and respond to emails, attackers are shifting their tactics from traditional phishing methods to manipulating AI systems directly. [โ€ฆ]

The post Microsoft Adds Prompt Injection Protection to Defender for Office 365 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars

A critical Bluetooth vulnerability in dealer-installed KARR Security Systems is putting over 2 million vehicles at risk of unauthorized access and immobilization. This situation has prompted urgent calls for drivers to update affected devices. Researchers at the University of California, San Diego, revealed that the flaw allows attackers within Bluetooth range to issue commands such [โ€ฆ]

The post KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data

Chick-fil-A has confirmed a data breach affecting an undisclosed number of Chick-fil-A One loyalty accounts. This breach occurred as threat actors executed credential-stuffing attacks on its website and mobile application. The incident underscores the ongoing risk associated with password reuse, where usernames and passwords exposed in unrelated third-party breaches are automatically tested against consumer platforms. [โ€ฆ]

The post Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Unknown Attackers Remain Inside South Korean Diplomatic System for Nearly 10 Months

Unknown attackers maintained long-term, covert access to South Koreaโ€™s diplomatic training infrastructure for nearly ten months, exposing personal data tied to almost the entire diplomatic cadre and highlighting structural weaknesses in the Foreign Ministryโ€™s security governance. South Koreaโ€™s Ministry of Foreign Affairs (MoFA) has confirmed a prolonged compromise of the Korea National Diplomatic Academy (KNDA) [โ€ฆ]

The post Unknown Attackers Remain Inside South Korean Diplomatic System for Nearly 10 Months appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Unveils CodeMender AI Agent for Automated Vulnerability Detection and Remediation

Google has unveiled CodeMender, a managed AI security agent designed to identify, validate, and remediate software vulnerabilities at machine speed. Announced in preview on July 22, 2023, the tool is available through the Gemini Enterprise Agent Platform and can also function as a core component of Googleโ€™s AI Threat Defense offering. This launch comes as [โ€ฆ]

The post Google Unveils CodeMender AI Agent for Automated Vulnerability Detection and Remediation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Talking smack about a doctor got him access to private medical files

PWNED Welcome back to PWNED, the weekly column where we focus on security own-goals so you can avoid them. This weekโ€™s topic involves serious problems in the healthcare sector, specifically the very human problem of compromised gatekeepers. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our legend of lameness comes courtesy of red teamer Dahvid Schloss, who shared so many great stories with us that weโ€™ve featured his tales a couple of times before. Schloss has made a career out of testing not only network security but also physical security at a wide variety of places. He has learned that if you act as you belong, people will usually treat you like you belong. At one hospital, Schloss was hired to test security by getting access to the records room and trying to steal a specific physical file that his client left there for him to pilfer. The challenge was that the records room had both an electronic lock and a nurse gatekeeper guarding it. Schloss told us that he considered several approaches to get into the records room. He could try picking the lock, cloning a badge, or even stealing the badge of someone who had access. Instead, he decided to try social engineering. Schloss did research on the hospital and he put on a pair of appropriate scrubs and made himself a fake security badge that could not possibly swipe in. Then he knew it was time to turn on the charm with the nurse who was on duty at the records room. And by โ€œturn on the charm,โ€ we mean โ€œdiss the doctor.โ€ โ€œNurses talk a lot of shit. It's the law of the land when it comes to the hospital,โ€ Schloss told us. So he tried to swipe his non-working badge and showed frustration when it didnโ€™t work. Then he walked up to the window where the on-duty nurse was standing and won her over. โ€œI'm doing fine, hon. How you doing,โ€ he told the nurse. โ€œLook, I'm gonna save you the details. But Dr Johnson's being an absolute asshole right now; he didn't pull out his patient records that he was supposed to pull out for trauma. We need these records, and they sent me down here. I'm brand new. I just started yesterday.โ€ Schloss had done his research and picked out the name of an actual doctor on staff. What he couldnโ€™t have known is that the doctor was actually a difficult person to work with. And the duty nurse let him know she was on his side before letting him in. โ€œThe nurse goes โ€˜honey, I know exactly the pain that you're going through,โ€™โ€ Schloss continued. โ€œShe goes โ€˜I got youโ€™ and she opens the door, lets me in.โ€ After Schloss went into the records room and retrieved the file, he hung around and talked to the nurse for another 10 minutes, complaining about how security was incompetent for not activating his badge and letting her complain about what jerks some of the doctors were. He even had a backstory about where he had worked before. She invited him to hang out and go for lunch sometime before he left with the folder. Other hospitals he tested had bad network security practices. He told us about one hospital where he sat down in the waiting room and logged into the guest Wi-Fi network and did a scan. What he found was that all the important devices in the hospital were on VLAN 1, the same network as guest Wi-Fi. All of the data coming out of medical devices like the MRI machine was readily accessible and unencrypted. He said that most medical devices at most hospitals heโ€™s tested do not encrypt data that they send over the network. โ€œSo you're getting Social Security numbers just being populated over the network via the MRI machine and you're getting the patient data, the date of birth, all the PII that any organization would lose their shit about,โ€ he said. Schloss said that he thinks hospitals heโ€™s tested prioritize the ability to keep machines running and distributing data quickly over good security hygiene. If someone tried to get data, failed, and had to call IT for help, those precious minutes of delay could cost a life. But even if it's a matter of life and death, do not let someone into a restricted area just because they look and act the part. ยฎ

New TrickBot Malware Variant Uses DNS Tunneling for Command-and-Control

A new TrickBot malware variant that significantly evolves its command-and-control (C2) communication by leveraging DNS tunneling, replacing the traditional HTTP-based mechanisms observed in earlier campaigns. The discovery highlights a continued shift among financially motivated threat actors toward stealthier communication channels designed to evade network detection and security controls. However, the newly analyzed samples demonstrate a [โ€ฆ]

The post New TrickBot Malware Variant Uses DNS Tunneling for Command-and-Control appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

26 Unauthenticated Vulnerability Advisories Expose Firewalls, VPNs, Switches, and Load Balancers

A structural risk in enterprise infrastructure: unauthenticated, remotely exploitable vulnerabilities embedded in the very devices designed to secure networks. In the 30 days ending July 17, 2026, 61 advisories across 14 vendors were disclosed, including six critical issues. However, the more consequential signal lies elsewhere 26 of those advisories require no authentication. They are reachable [โ€ฆ]

The post 26 Unauthenticated Vulnerability Advisories Expose Firewalls, VPNs, Switches, and Load Balancers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access

A critical vulnerability in the Linux kernel, identified as CVE-2026-64600 and referred to as RefluXFS. This vulnerability enables an unprivileged local user to gain root access on systems that utilize reflink-enabled XFS filesystems. The flaw resides in the XFS copy-on-write path and has reportedly existed since the release of Linux kernel version 4.1 in 2017. [โ€ฆ]

The post Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CISA Urges Organizations to Remove Rockwell PLCs From Direct Internet Exposure

CISA and partner agencies are directing U.S. critical infrastructure operators to immediately remove Rockwell and other programmable logic controllers (PLCs) from direct internet exposure and to hunt for Iranian-affiliated APT activity in OT environments aggressively. In a joint advisory first issued on April 7, 2026 and updated on July 22, 2026, the FBI, CISA, NSA, [โ€ฆ]

The post CISA Urges Organizations to Remove Rockwell PLCs From Direct Internet Exposure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Anthropic Launches Claude Security Plugin to Scan Codebases for Vulnerabilities Before Commit

Anthropic has launched the Claude Security plugin for Claude Code in beta, enhancing its AI-assisted development platform with security scanning capabilities designed to identify vulnerabilities earlier in the software development lifecycle. The company stated that developers can scan code changes before committing them or initiate comprehensive security reviews across an entire codebase directly from the [โ€ฆ]

The post Anthropic Launches Claude Security Plugin to Scan Codebases for Vulnerabilities Before Commit appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

โŒ