❌

Normal view

There are new articles available, click to refresh the page.
Yesterday β€” 12 September 2026Main stream

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

By: Eswar
12 September 2026 at 04:40

Threat actors are increasingly using Claude-based AI workflows to automate cyberattacks, accelerate data theft, and reduce the technical expertise needed to run complex intrusions. Anthropic’s report details cyber espionage, financially motivated extortion, supply-chain compromise, and hacktivist activity disrupted between December 2025 and August 2026. Rather than using an AI chatbot only for occasional coding assistance, […]

The post Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

By: Eswar
12 September 2026 at 04:04

China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on September 1, 2026, as using identical browser-to-kernel exploit components but ultimately installing separate espionage payloads: the GRIMWEDGE JScript backdoor and the LONGTALE credential-stealing Chrome […]

The post China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

By: Eswar
12 September 2026 at 02:16

A newly identified phishing campaign is abusing the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files, conduct system reconnaissance, and potentially deploy payloads designed to steal credentials and local secrets. Fortra’s Intelligence and Research Experts (FIRE) said the activity began in June and remains active, with operators regularly recompiling malware samples to […]

The post New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE

By: Eswar
12 September 2026 at 02:03

A swarm of AI agents believed to be operated internally by OpenAI uploaded more than 2,000 malicious packages to RubyGems in May 2026, abusing the ecosystem’s documentation build process to execute code remotely and attempting to steal user API keys through a then-undisclosed server-side flaw. Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said […]

The post OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

By: Eswar
12 September 2026 at 01:17

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects both GitLab Community Edition and Enterprise Edition and requires urgent mitigation, particularly for internet-accessible GitLab instances. CVE-2026-85706 is a path traversal vulnerability […]

The post CISA Warns of Critical GitLab Vulnerability Exploited in Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Before yesterdayMain stream

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

11 September 2026 at 08:24

A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to distribute malware at scale. The cluster, tracked as CL-CRI-1171, is linked to more than 10,000 distinct samples of a custom loader called OfferLoader, indicating a distribution pipeline far larger than the individual intrusions initially observed. Rather than relying on a […]

The post Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

By: Divya
11 September 2026 at 08:03

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controlled RealRTSP servers. The more severe vulnerability, tracked as CVE-2026-56711, is a heap out-of-bounds write flaw with a CVSS v4 score of […]

The post VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

By: Divya
11 September 2026 at 07:57

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On September 10, CISA listed CVE-2026-67277 and CVE-2026-86060, giving affected organizations until September 13 to implement vendor-recommended mitigations. MikroTik RouterOS Flaws CVE-2026-67277 […]

The post CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

By: Divya
11 September 2026 at 07:20

A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026-65638, affects CSF versions 14.00 through 16.29 and has been addressed in version 16.30 and later. CSF is widely used on Linux servers and in cPanel/WHM environments […]

The post cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

11 September 2026 at 06:51

Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also for large language model-powered tools increasingly used to triage suspicious code. ESET researchers linked the activity to Russia-aligned threat actor UAC-0099, which used the method during an attack against an organization in Ukraine. The group inserted a safety-sensitive, weapon-related request […]

The post Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code

By: Divya
11 September 2026 at 06:13

GitLab has issued an emergency security update to address two critical vulnerabilities that could lead to unauthenticated file disclosure and authenticated credential theft, as well as a high-severity flaw that may enable remote code execution. The company released updated versions of GitLab Community Edition and Enterprise Edition, specifically versions 19.3.2, 19.2.6, and 19.1.8, on September […]

The post Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

By: Divya
11 September 2026 at 05:59

Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, to bypass authentication, escalate privileges, and gain administrative control of exposed instances. Wiz Research reports that multiple attackers are targeting self-hosted Artifactory deployments in the wild, using both a two-bug token escalation chain and a separate critical authentication-bypass flaw. A successful […]

The post Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Okta Patches Auth0 and Access Gateway Vulnerabilities Let Attackers Enable XSS, Authentication Bypass and SQL Injection

By: Divya
11 September 2026 at 05:42

Okta has released security updates for three high-severity vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. These vulnerabilities could allow authenticated attackers to trigger stored cross-site scripting (XSS), bypass Protected Rule authorization controls, or execute unintended SQL commands against configured backend databases under specific deployment conditions. All three vulnerabilities were disclosed on September […]

The post Okta Patches Auth0 and Access Gateway Vulnerabilities Let Attackers Enable XSS, Authentication Bypass and SQL Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks

11 September 2026 at 05:07

A newly observed IoT malware family dubbed KATARU targets internet-exposed devices through Telnet credential brute-forcing, then attempts to gain root privileges with publicly available Linux kernel exploits before enrolling compromised systems in a DDoS botnet. The sample combines familiar Mirai-style flooding functions with encrypted command-and-control, broad persistence logic, anti-analysis checks and decoy network activity designed […]

The post New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CISA Urges Service Providers to Provide Transparent Updates During Major IT and OT Outages

By: Divya
11 September 2026 at 03:47

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released new guidance urging service providers to deliver timely, accurate, and transparent communications during major information technology (IT) and operational technology (OT) outages. The document, titled β€˜Communicating Under Pressure: Best Practices for Service Providers’, was developed with the Federal Bureau of Investigation (FBI) and international partners. […]

The post CISA Urges Service Providers to Provide Transparent Updates During Major IT and OT Outages appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments.

11 September 2026 at 03:43

Threat actors are using AI-assisted phishing templates, executive impersonation, fake ServiceNow invoices, and fabricated email threads to pressure finance teams into authorizing fraudulent ACH payments worth nearly $50,000. Microsoft detected more than one million messages in the campaign, demonstrating how business email compromise (BEC) operations are becoming more polished, scalable, and difficult to spot. The […]

The post Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments. appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

12 Best Server Security Solutions Compared (2026): Features & Pricing

11 September 2026 at 03:24

Quick Answer: CrowdStrike and SentinelOne lead server EDR; Trend Micro Deep Security owns virtual patching for unpatchable estates; Microsoft Defender for Servers is the per-resource anchor for Azure/hybrid; Bitdefender and ESET deliver efficacy at value. Server pricing runs per server/workload always confirm Linux feature parity. Servers are where ransomware crews head after the first phish: […]

The post 12 Best Server Security Solutions Compared (2026): Features & Pricing appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

12 Best Ransomware Protection Solutions Compared (2026): Features & Pricing

11 September 2026 at 03:18

Quick Answer: No single product stops ransomware. The strongest stacks combine EDR prevention (CrowdStrike, SentinelOne, Microsoft Defender, Sophos, Bitdefender), managed eyes-on-glass (Huntress, Sophos MDR), and guaranteed recovery (Rubrik, Acronis). Note: ColorTokens is microsegmentation and Rubrik is cyber resilience containment and recovery layers, not EDR. Ransomware is now a professionalized industry double-extortion ransomware operations, hands-on-keyboard operators, […]

The post 12 Best Ransomware Protection Solutions Compared (2026): Features & Pricing appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files

11 September 2026 at 03:14

Mantax OTAX is aggressive Android malware family combines ransomware, spyware, credential theft, and remote device-control features in a single infection chain. Linked to Indonesian threat actors, the campaign targets users through sideloaded APKs and turns compromised devices into tools for surveillance, financial fraud and real-time extortion. Unlike conventional Android ransomware that focuses primarily on locking […]

The post Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌