Reading view

There are new articles available, click to refresh the page.

Top 10 Best Security Configuration Assessment Tools in 2026

In the complex and ever-expanding digital landscape of 2026, a strong cybersecurity posture depends not only on identifying vulnerabilities in software but also on ensuring that systems are correctly and securely configured. Misconfigurations incorrectly set permissions, unhardened systems, enabled insecure services, and default passwords left unchanged have become one of the leading causes of data […]

The post Top 10 Best Security Configuration Assessment Tools in 2026 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

macOS ClickFix Attacks Use Fake CAPTCHAs to Deploy Atomic Stealer and Hijack Crypto Wallets

macOS users are facing a new, highly polished ClickFix campaign that abuses fake CAPTCHAs to execute Terminal commands, silently deploy Atomic macOS Stealer (AMOS), and systematically loot crypto wallets and browser‑stored credentials. This evolution of ClickFix underscores how social engineering, not exploits, remains one of the most effective paths to full compromise on Apple devices. […]

The post macOS ClickFix Attacks Use Fake CAPTCHAs to Deploy Atomic Stealer and Hijack Crypto Wallets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Russian Intelligence Hackers Target Signal Backup Recovery Keys in Account Takeover Attacks

Russian intelligence-linked hackers have shifted tactics to target Signal users’ backup recovery keys, enabling full account takeover and access to historical message archives without breaking Signal’s end-to-end encryption. The FBI and CISA are warning that this evolving phishing campaign focuses on high-value targets worldwide and abuses user trust in “support” messaging inside the app. These […]

The post Russian Intelligence Hackers Target Signal Backup Recovery Keys in Account Takeover Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Joyfill npm Supply-Chain Attack Deploys RAT and Developer Credential Stealer

A supply-chain compromise targeting the npm ecosystem has introduced a multi-stage remote access trojan (RAT) and credential stealer through hijacked Joyfill packages, highlighting an increasingly sophisticated abuse of trusted developer dependencies. On July 28, 2026, malicious beta releases of @joyfill/components and @joyfill/layouts were published to the npm registry, embedding heavily obfuscated payloads directly into compiled […]

The post Joyfill npm Supply-Chain Attack Deploys RAT and Developer Credential Stealer appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Fake Web3 Job Interview Software Delivers Infostealer to Steal Crypto Wallets and Passwords

A newly uncovered cyber campaign is targeting Web3 professionals with sophisticated social engineering, leveraging fake job interviews to deploy cross-platform infostealer malware designed to harvest crypto wallets, credentials, and sensitive system data. The attack begins with threat actors impersonating recruiters who approach job seekers with interview opportunities. Victims are directed to a malicious domain, relay.lc, […]

The post Fake Web3 Job Interview Software Delivers Infostealer to Steal Crypto Wallets and Passwords appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware

Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in software supply chain threats. On July 14, 2026, Microsoft Threat Intelligence uncovered a coordinated compromise of the widely used @asyncapi npm organization, where adversaries leveraged trusted CI/CD pipelines to publish backdoored packages with valid cryptographic provenance. […]

The post Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Flying Eagle RAT Abuses Android Accessibility Services for Keylogging, Screen Capture and Gesture Injection

A newly analyzed Android remote access trojan (RAT) dubbed “Flying Eagle” is leveraging Accessibility Services to enable large-scale surveillance, credential theft, and remote device manipulation, following its distribution through fake Public Security Bureau (PSB) applications. A June 18, 2026 public warning from Chinese state media (CCTV) confirmed the campaign, highlighting fraudulent apps masquerading as official […]

The post Flying Eagle RAT Abuses Android Accessibility Services for Keylogging, Screen Capture and Gesture Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

JFrog Patches Artifactory Zero-Days After OpenAI Models Escape Sandbox

Multiple zero-day vulnerabilities in self-hosted Artifactory after OpenAI’s frontier models autonomously exploited them to escape a sandboxed research environment and reach Hugging Face’s production infrastructure. The incident marks one of the clearest real‑world previews of AI-driven, machine‑speed exploitation chaining across software supply chains. During an internal evaluation of “frontier cyber capabilities,” OpenAI ran advanced models […]

The post JFrog Patches Artifactory Zero-Days After OpenAI Models Escape Sandbox appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Attackers Split RAT Components Across npm Packages to Evade Isolated Code Reviews

Attackers have been observed distributing a modular Remote Access Trojan (RAT) through the npm ecosystem by deliberately splitting malicious functionality across multiple seemingly benign packages, enabling the campaign to evade traditional code review and detection mechanisms for over three months. The activity was uncovered during analysis of a compromised npm package, lib-mtop, which contained a […]

The post Attackers Split RAT Components Across npm Packages to Evade Isolated Code Reviews appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Cybercriminals Use Adversarial Prompt Injection to Evade AI-Powered Security Tools

Cybercriminals are rapidly operationalizing adversarial prompt injection techniques to evade AI-powered security controls, signaling a shift toward targeting machine-driven defenses rather than end users directly. AI’s expanding role in detection, filtering, and automation has made it an attractive attack surface. While adversaries continue to rely heavily on human-centric techniques such as phishing, researchers from Proofpoint […]

The post Cybercriminals Use Adversarial Prompt Injection to Evade AI-Powered Security Tools appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Fake Claude Code Installer Delivers MacSync macOS Infostealer Through Google Ads

A highly convincing malvertising campaign is targeting macOS users searching for “how to install Claude Code on Mac,” delivering the MacSync infostealer through a trusted-looking workflow that abuses legitimate infrastructure rather than exploiting software vulnerabilities. The attack highlights a growing shift toward trust-based compromise, where attackers weaponize authentic platforms such as Google Ads and claude.ai […]

The post Fake Claude Code Installer Delivers MacSync macOS Infostealer Through Google Ads appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users

The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security researchers warn that its leaked techniques and infrastructure patterns are already being repurposed in ongoing campaigns targeting Microsoft 365 environments. Despite being disrupted under Operation Olympus Blade, which led to the seizure of […]

The post Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions

A significant evolution in the CastleLoader malware ecosystem, with new campaigns deploying the NeedleStealer framework to harvest cryptocurrency wallet seed phrases and hijack browser sessions. The findings expand on earlier research by Huntress and LevelBlue, confirming that CastleLoader remains a central delivery mechanism for multi-stage intrusions while introducing new tooling written in Rust and Golang. […]

The post CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Chinese Hackers Use RedRelay Multi-Hop Network to Conceal Global Cyber Operations

Chinese state-linked hackers are increasingly relying on a covert multi-hop infrastructure dubbed RedRelay (also known as ORBWEAVER) to mask the origins of global cyber operations, with evidence pointing to little-known Guangdong Chanming as a key enabler behind the network. Guangdong Chanming, a low‑visibility company with no public‑facing products or marketing, has quietly amassed a portfolio […]

The post Chinese Hackers Use RedRelay Multi-Hop Network to Conceal Global Cyber Operations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Tengu Mirai Botnet Uses Watchdog Reboots and Binary Bricking to Resist Removal

Tengu, a newly observed Mirai-derived botnet, is demonstrating how modern IoT malware is rapidly evolving beyond traditional distributed denial-of-service (DDoS) operations by integrating persistence, evasion, and multi-functional attack capabilities. Unlike legacy Mirai variants, Tengu employs a hybrid C2 model that blends plaintext and encrypted communications. Initial registration and heartbeat messages are transmitted in cleartext, while […]

The post Tengu Mirai Botnet Uses Watchdog Reboots and Binary Bricking to Resist Removal appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Fake ShinyHunters Emails Give Victims 48 Hours to Pay $2,000 Bitcoin Ransom

Fake ShinyHunters-themed sextortion emails are abusing data from recent ShinyHunters leaks to threaten victims with the release of fabricated “webcam recordings” unless a 2,000 dollar Bitcoin ransom is paid within 48 hours. Despite the technical-sounding claims, there is no evidence of actual device compromise, malware deployment, or recorded content behind these messages. The emails impersonate […]

The post Fake ShinyHunters Emails Give Victims 48 Hours to Pay $2,000 Bitcoin Ransom appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Dysphoria IoT Botnet Uses Blockchain Domains and 200,000 Devices for DDoS Attacks

A rapidly evolving IoT botnet dubbed “Dysphoria” has emerged as a significant global threat, leveraging blockchain-based domain resolution and a hybrid command-and-control (C2) architecture to sustain large-scale distributed denial-of-service (DDoS) operations. Dysphoria’s evolution has been unusually aggressive, transitioning from early jackskid-derived variants to more sophisticated fbot-based implementations within weeks. Initial samples observed in March 2026 […]

The post Dysphoria IoT Botnet Uses Blockchain Domains and 200,000 Devices for DDoS Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor

An evolving intrusion campaign in which threat actors impersonate IT helpdesk personnel via Microsoft Teams to gain initial access and deploy a custom Go-based backdoor dubbed “GoGRPC.” Active since January 2026, the activity is assessed to be linked to an initial access broker (IAB) operation that likely facilitates downstream ransomware attacks. Aligning with tactics observed […]

The post Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Operation STANDOFF Uses GitHub Redirects Across 44 Servers to Hide Multi-Malware C2 Traffic

Operation STANDOFF is a Russian‑speaking cybercriminal campaign that uses a cluster of at least 44 TimeWeb‑hosted servers that all masquerade as benign GitHub redirectors to conceal multi‑malware command‑and‑control (C2) and proxy traffic. This infrastructure underpins a full ecosystem: a pay‑per‑install loader, a proxy‑botnet, a multi‑operator intrusion console, and an AI‑driven influence and outreach platform. All […]

The post Operation STANDOFF Uses GitHub Redirects Across 44 Servers to Hide Multi-Malware C2 Traffic appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Operation BlueDash Maintains Redundant Remote Access Even After One RMM Tool Is Removed

A newly analyzed phishing-driven intrusion set tracked as Operation BlueDash demonstrates how threat actors are operationalizing legitimate remote monitoring and management (RMM) tools to maintain persistent and redundant access to compromised environments. The infection chain begins with a Microsoft Teams-themed phishing email delivering a “secure document” lure. Victims are redirected through compromised infrastructur to a […]

The post Operation BlueDash Maintains Redundant Remote Access Even After One RMM Tool Is Removed appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌