Category: gbhackers
-
DCRat Malware Spreading via YouTube to Steal Login Credentials
DCRat Malware Spreading via YouTube to Steal Login Credentials Cybersecurity researchers have identified a renewed wave of attacks involving the Dark Crystal RAT (DCRat), a dangerous remote access Trojan that has resurfaced through… Go to gbhackers.com
-
Java Axios Package Vulnerability Threatens Millions of Servers with SSRF Exploit
Java Axios Package Vulnerability Threatens Millions of Servers with SSRF Exploit A critical security issue has been identified in the Axios package for JavaScript, which poses significant risks to millions of servers due to server-side… Go to gbhackers.com
-
PHP XXE Injection Vulnerability Allows Attackers to Access Config Files & Private Keys
PHP XXE Injection Vulnerability Allows Attackers to Access Config Files & Private Keys A newly uncovered XML External Entity (XXE) injection vulnerability in PHP has demonstrated how attackers can bypass multiple security mechanisms to access sensitive configuration… Go to gbhackers.com
-
Microsoft Patch Tuesday March 2025 – 6 Actively Exploited Zero-Days & 57 Vulnerabilities Are…
Microsoft Patch Tuesday March 2025 – 6 Actively Exploited Zero-Days & 57 Vulnerabilities Are… Microsoft has rolled out its March 2025 Patch Tuesday update, addressing a total of 57 vulnerabilities across its software ecosystem, including 6 actively exploited… Go to gbhackers.com
-
Hackers Exploit Advanced MFA Bypass Techniques to Compromise User Accounts
Hackers Exploit Advanced MFA Bypass Techniques to Compromise User Accounts In recent years, phishing has remained the most prevalent form of cyberattack, with approximately 1.2% of global email traffic being phishing attempts, amounting to… Go to gbhackers.com
-
Apache Pinot Vulnerability Allows Attackers to Bypass Authentication
Apache Pinot Vulnerability Allows Attackers to Bypass Authentication A significant security vulnerability affecting Apache Pinot, an open-source distributed data store designed for real-time analytics, has been publicly disclosed.The flaw, identified as CVE-2024-56325, allows… Go to gbhackers.com
-
Lazarus Hackers Exploit 6 NPM Packages to Steal Login Credentials
Lazarus Hackers Exploit 6 NPM Packages to Steal Login Credentials North Korea’s Lazarus Group has launched a new wave of attacks targeting the npm ecosystem, compromising six packages designed to steal login credentials and… Go to gbhackers.com
-
CISA Added 3 Ivanti Endpoint Manager Bugs to Wildly Exploited Vulnerabilities Catalog
CISA Added 3 Ivanti Endpoint Manager Bugs to Wildly Exploited Vulnerabilities Catalog The Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog with the addition of three high-risk security flaws affecting… Go to gbhackers.com
-
Hackers Compromise Windows Systems Using 5000+ Malicious Packages
Hackers Compromise Windows Systems Using 5000+ Malicious Packages A recent analysis by FortiGuard Labs has revealed a significant increase in malicious software packages, with over 5,000 identified since November 2024.These packages… Go to gbhackers.com
-
Telecom Giant NTT Confirms Data Breach Affecting 18,000 Corporate Customers
Telecom Giant NTT Confirms Data Breach Affecting 18,000 Corporate Customers Japanese telecom giant NTT Communications (NTT Com) has confirmed a data breach that compromised the information of nearly 18,000 corporate customers.The breach, which occurred… Go to gbhackers.com
-
Developer Pleads Guilty to Injecting Malware and Crippling Company Systems
Developer Pleads Guilty to Injecting Malware and Crippling Company Systems In a stunning case of corporate sabotage, a former software developer for Eaton Corp., Davis Lu, 55, of Houston, has been found guilty by… Go to gbhackers.com
-
WinDbg Vulnerability Allows Attackers to Execute Remote Code
WinDbg Vulnerability Allows Attackers to Execute Remote Code Microsoft recently disclosed a critical vulnerability impacting its debugging tool, WinDbg, and associated .NET packages.Tracked CVE-2025-24043, this flaw allows remote code execution (RCE) due… Go to gbhackers.com
-
Thinkware Dashcam Vulnerability Leaks Credentials to Attackers
Thinkware Dashcam Vulnerability Leaks Credentials to Attackers A series of significant security vulnerabilities have been discovered in the Thinkware Dashcam, specifically the F800 Pro model, which could pose serious risks to… Go to gbhackers.com
-
New Apache Traffic Server Flaws Allow Malformed Request Exploits
New Apache Traffic Server Flaws Allow Malformed Request Exploits The Apache Software Foundation has disclosed several vulnerabilities affecting its Traffic Server software.These vulnerabilities allow malicious actors to exploit malformed requests and access control… Go to gbhackers.com
-
Commvault Webserver Flaw Allows Attackers to Gain Full Control
Commvault Webserver Flaw Allows Attackers to Gain Full Control Commvault has revealed a major vulnerability in its software that could allow malicious actors to gain full control of its webservers.The issue, identified as CV_2025_03_1,… Go to gbhackers.com
-
10 Best Penetration Testing Companies in 2025
10 Best Penetration Testing Companies in 2025 Penetration testing companies play a vital role in strengthening the cybersecurity defenses of organizations by identifying vulnerabilities in their systems, applications, and networks.These… Go to gbhackers.com
-
Lumma Stealer Using Fake Google Meet & Windows Update Sites to Launch “Click Fix”…
Lumma Stealer Using Fake Google Meet & Windows Update Sites to Launch “Click Fix”… Cybersecurity researchers continue to track sophisticated “Click Fix” style distribution campaigns that deliver the notorious Lumma Stealer malware to unsuspecting victims.These increasingly sophisticated tactics,… Go to gbhackers.com
-
Fake BianLian Ransom Demands Sent via Physical Letters to U.S. Firms
Fake BianLian Ransom Demands Sent via Physical Letters to U.S. Firms In a novel and concerning development, multiple U.S. organizations have reported receiving suspicious physical letters claiming to be from the BianLian ransomware group.These… Go to gbhackers.com
-
Strela Stealer Malware Attack Microsoft Outlook Users for Credential Theft
Strela Stealer Malware Attack Microsoft Outlook Users for Credential Theft The cybersecurity landscape has recently been impacted by the emergence of the Strela Stealer malware, a sophisticated infostealer designed to target specific email clients,… Go to gbhackers.com
-
New PyPI Malware Targets Developers to Steal Ethereum Wallets
New PyPI Malware Targets Developers to Steal Ethereum Wallets A recent discovery by the Socket Research Team has unveiled a malicious PyPI package named set-utils, designed to steal Ethereum private keys by exploiting… Go to gbhackers.com
-
GitHub Explains How Security Professionals Can Use Copilot for Log Analysis
GitHub Explains How Security Professionals Can Use Copilot for Log Analysis GitHub Copilot, once a developer-centric tool, is now revolutionizing workflows across technical and non-technical roles.With features like Agent Mode, CLI integration, and Project… Go to gbhackers.com
-
Microsoft Introduces 365 E5 Security Add-On for Business Premium Customers
Microsoft Introduces 365 E5 Security Add-On for Business Premium Customers Microsoft has launched Microsoft 365 E5 Security as an add-on to its Business Premium suite, providing small and medium-sized businesses (SMBs) with advanced tools… Go to gbhackers.com
-
AMD Microcode Vulnerability Allows Attackers to Load Malicious Patches
AMD Microcode Vulnerability Allows Attackers to Load Malicious Patches A critical vulnerability in AMD’s Zen 1 through Zen 4 processors allows attackers to bypass microcode signature validation, potentially undermining hardware-based security mechanisms.The… Go to gbhackers.com
-
Activating Incognito Mode in RDP to Erase All Traces
Activating Incognito Mode in RDP to Erase All Traces The Remote Desktop Protocol (RDP) is a widely used tool for remote access, but it often leaves behind traces of user activity, which can… Go to gbhackers.com
-
Medusa Ransomware Attacks Surge 42% with Advanced Tools & Tactics
Medusa Ransomware Attacks Surge 42% with Advanced Tools & Tactics Medusa ransomware attacks have seen a significant increase, rising by 42% between 2023 and 2024, with a further escalation in early 2025.This surge… Go to gbhackers.com
-
Two Cybercriminals Arrested for ATM Jackpotting Scheme
Two Cybercriminals Arrested for ATM Jackpotting Scheme Federal authorities have unveiled details of a sophisticated cybercrime operation targeting financial institutions across four states, resulting in the arrests of two Venezuelan nationals… Go to gbhackers.com
-
7 Malicious Go Packages Target Linux & macOS to Deploy Stealthy Malware Loader
7 Malicious Go Packages Target Linux & macOS to Deploy Stealthy Malware Loader Security researchers at Socket have uncovered a sophisticated malware campaign targeting the Go ecosystem.The threat actor has published at least seven malicious packages… Go to gbhackers.com
-
Black Basta’s Notorious Tactics and Techniques Exposed in Leaked Intel
Black Basta’s Notorious Tactics and Techniques Exposed in Leaked Intel A significant leak of internal chat logs from the Black Basta ransomware group has provided cybersecurity researchers with unprecedented insight into their operations, capabilities,… Go to gbhackers.com
-
Cybercriminals Exploit YouTubers to Spread SilentCryptoMiner on Windows Systems
Cybercriminals Exploit YouTubers to Spread SilentCryptoMiner on Windows Systems A sophisticated malware campaign has been uncovered, exploiting the growing popularity of Windows Packet Divert drivers for bypassing internet restrictions.Cybercriminals are distributing the… Go to gbhackers.com
-
Case Study: Gaining Internal Network Access Through Physical Penetration Testing
Case Study: Gaining Internal Network Access Through Physical Penetration Testing A recent physical penetration test conducted by cybersecurity firm Hackmosphere, revealed critical security flaws in a furniture company’s retail store.The test, which simulated… Go to gbhackers.com
-
U.S. Cracks Down on Nemesis Darknet Admin with New Treasury Sanctions
U.S. Cracks Down on Nemesis Darknet Admin with New Treasury Sanctions The U.S. Department of the Treasury has intensified its global campaign against darknet-facilitated drug trafficking by sanctioning Behrouz Parsarad, the Iran-based administrator of the… Go to gbhackers.com
-
Vim Vulnerability (CVE-2025-27423) Allows Code Execution via Malicious TAR Archives
Vim Vulnerability (CVE-2025-27423) Allows Code Execution via Malicious TAR Archives A high-severity security flaw in the widely used Vim text editor allows attackers to execute arbitrary code on vulnerable systems by tricking users into… Go to gbhackers.com
-
Telegram EvilVideo Vulnerability Exploited to Run Malicious Code on Victims’ Devices
Telegram EvilVideo Vulnerability Exploited to Run Malicious Code on Victims’ Devices A newly documented exploitation technique targeting Telegram’s file-sharing infrastructure has raised alarms in cybersecurity circles.Dubbed “EvilVideo,” this attack vector leverages a vulnerability (CVE-2024-7014) in… Go to gbhackers.com
-
PoC Released for HPE Remote Support Tool Vulnerability Allowing Remote Code Execution
PoC Released for HPE Remote Support Tool Vulnerability Allowing Remote Code Execution Security researchers have released proof-of-concept (PoC) exploit code for critical vulnerabilities in Hewlett Packard Enterprise’s (HPE) Insight Remote Support (IRS) tool, including an unauthenticated XML… Go to gbhackers.com
-
Zoho ADSelfService Plus Flaw Allows Hackers to Gain Unauthorized Access
Zoho ADSelfService Plus Flaw Allows Hackers to Gain Unauthorized Access A critical security flaw in Zoho’s widely used identity management solution, ADSelfService Plus, has been patched after researchers discovered it could enable attackers to… Go to gbhackers.com
-
CISA Warns of Active Exploitation of Microsoft Windows Win32k Vulnerability
CISA Warns of Active Exploitation of Microsoft Windows Win32k Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-8639, a decade-old Microsoft Windows privilege escalation flaw, to its Known Exploited Vulnerabilities (KEV) catalog… Go to gbhackers.com
-
BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely
BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely A critical vulnerability in BigAntSoft’s enterprise chat server software has exposed ~50 internet-facing systems to unauthenticated remote code execution attacks.Designated CVE-2025-0364, this exploit chain enables… Go to gbhackers.com
-
Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit
Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under limited, targeted exploitation.These flaws, impacting Android versions 12 through 15,… Go to gbhackers.com
-
IBM Storage Virtualize Flaws Allow Remote Code Execution
IBM Storage Virtualize Flaws Allow Remote Code Execution Two critical security flaws in IBM Storage Virtualize products could enable attackers to bypass authentication protections and execute malicious code on enterprise storage systems,… Go to gbhackers.com
-
Progress WhatsUp Gold Path Traversal Vulnerability Exposes Systems to Remote code Execution
Progress WhatsUp Gold Path Traversal Vulnerability Exposes Systems to Remote code Execution A newly disclosed path traversal vulnerability (CVE-2024-4885) in Progress Software’s WhatsUp Gold network monitoring solution has raised alarms across the cybersecurity community.Rated as critical,… Go to gbhackers.com
-
New Poco RAT Via Weaponized PDF Attacking Users to Capture Sensitive Data
New Poco RAT Via Weaponized PDF Attacking Users to Capture Sensitive Data A new variant of malware, dubbed “Poco RAT,” has emerged as a potent espionage tool in a campaign targeting Spanish-speaking users in Latin America…. Go to gbhackers.com
-
U.S. Suspends Cyberattacks Against Russia
U.S. Suspends Cyberattacks Against Russia The United States has suspended offensive cyber operations against Russia under an order issued by Defense Secretary Pete Hegseth, according to multiple confirmed reports.The… Go to gbhackers.com
-
Hackers Abused Google and PayPal’s Infrastructure to Steal Users Personal Data
Hackers Abused Google and PayPal’s Infrastructure to Steal Users Personal Data Cybersecurity researchers have uncovered a sophisticated phishing campaign leveraging Google Ads and PayPal’s infrastructure to deceive users and steal sensitive personal data.The attackers… Go to gbhackers.com
-
Njrat Exploits Microsoft Dev Tunnels for C2 Communication
Njrat Exploits Microsoft Dev Tunnels for C2 Communication A new campaign involving the notorious remote access trojan (RAT) Njrat has been uncovered, leveraging Microsoft’s Dev Tunnels service for command-and-control (C2) communication.This… Go to gbhackers.com
-
North Korean IT Workers Hide Their IPs Using Astrill VPN
North Korean IT Workers Hide Their IPs Using Astrill VPN Security researchers have uncovered new evidence that North Korean threat actors, particularly the Lazarus Group, are actively using Astrill VPN to conceal their true… Go to gbhackers.com
-
Hackers can Crack Into Car Cameras Within Minutes Exploiting Vulnerabilities
Hackers can Crack Into Car Cameras Within Minutes Exploiting Vulnerabilities At the upcoming Black Hat Asia 2025 conference, cybersecurity experts will unveil a groundbreaking vulnerability in modern dashcam technology, exposing how hackers can exploit… Go to gbhackers.com
-
Network Penetration Testing Checklist – 2025
Network Penetration Testing Checklist – 2025 Network penetration testing is a cybersecurity practice that simulates cyberattacks on an organization’s network to identify vulnerabilities and improve security defenses.Ethical hackers, or… Go to gbhackers.com
-
Chinese Hackers Breach Belgium State Security Service as Investigation Continues
Chinese Hackers Breach Belgium State Security Service as Investigation Continues Belgium’s State Security Service (VSSE) has suffered what is being described as its most severe security breach to date.For nearly two years, a… Go to gbhackers.com
-
Hacktivist Groups Emerge With Powerful Tools for Large-Scale Cyber Operations
Hacktivist Groups Emerge With Powerful Tools for Large-Scale Cyber Operations Hacktivism, once synonymous with symbolic website defacements and distributed denial-of-service (DDoS) attacks, has evolved into a sophisticated tool for cyber warfare and influence operations…. Go to gbhackers.com
-
New Pass-the-Cookie Attacks Bypass MFA, Giving Hackers Full Account Access
New Pass-the-Cookie Attacks Bypass MFA, Giving Hackers Full Account Access Multi-factor authentication (MFA), long considered a cornerstone of cybersecurity defense, is facing a formidable new threat: “Pass-the-Cookie” attacks.Recent findings reveal from Long Wall shows that… Go to gbhackers.com
-
Chinese Hackers Exploit Check Point VPN Zero-Day to Target Organizations Globally
Chinese Hackers Exploit Check Point VPN Zero-Day to Target Organizations Globally A sophisticated cyberespionage campaign linked to Chinese state-sponsored actors has exploited a previously patched Check Point VPN vulnerability (CVE-2024-24919) to infiltrate organizations across Europe,… Go to gbhackers.com
-
PingAM Java Agent Vulnerability Allows Attackers to Bypass Security
PingAM Java Agent Vulnerability Allows Attackers to Bypass Security A critical security flaw (CVE-2025-20059) has been identified in supported versions of Ping Identity’s PingAM Java Agent, potentially enabling attackers to bypass policy enforcement… Go to gbhackers.com
-
New GitHub Scam Uses Fake “Mods” and “Cracks” to Steal User Data
New GitHub Scam Uses Fake “Mods” and “Cracks” to Steal User Data A sophisticated malware campaign leveraging GitHub repositories disguised as game modifications and cracked software has been uncovered, exposing a dangerous convergence of social engineering… Go to gbhackers.com
-
260 Domains Hosting 5,000 Malicious PDFs to Steal Credit Card Data
260 Domains Hosting 5,000 Malicious PDFs to Steal Credit Card Data Netskope Threat Labs uncovered a sprawling phishing operation involving 260 domains hosting approximately 5,000 malicious PDF files.These documents, disguised as legitimate resources, employ fake… Go to gbhackers.com
-
Winos4.0 Malware Targets Windows Users Through Malicious PDF Files
Winos4.0 Malware Targets Windows Users Through Malicious PDF Files A new wave of cyberattacks leveraging the Winos4.0 malware framework has targeted organizations in Taiwan through malicious PDF attachments disguised as tax inspection alerts,… Go to gbhackers.com
-
Cisco Nexus Vulnerability Allows Attackers to Inject Malicious Commands
Cisco Nexus Vulnerability Allows Attackers to Inject Malicious Commands Cisco Systems has issued a critical security advisory for a newly disclosed command injection vulnerability affecting its Nexus 3000 and 9000 Series Switches operating… Go to gbhackers.com
-
Authorities Arrested Hacker Behind 90 Major Data Breaches Worldwide
Authorities Arrested Hacker Behind 90 Major Data Breaches Worldwide Cybersecurity firm Group-IB, alongside the Royal Thai Police and Singapore Police Force, announced the arrest of a prolific hacker linked to over 90 major data… Go to gbhackers.com
-
New Wi-Fi Jamming Attack Can Disable Specific Devices
New Wi-Fi Jamming Attack Can Disable Specific Devices A newly discovered Wi-Fi jamming technique enables attackers to selectively disconnect individual devices from networks with surgical precision, raising alarms across cybersecurity and telecommunications… Go to gbhackers.com
-
GitLab Vulnerabilities Allow Attackers to Bypass Security and Run Arbitrary Scripts
GitLab Vulnerabilities Allow Attackers to Bypass Security and Run Arbitrary Scripts GitLab has urgently released security updates to address multiple high-severity vulnerabilities in its platform that could allow attackers to bypass security mechanisms, execute malicious… Go to gbhackers.com
-
LibreOffice Flaws Allow Attackers to Run Malicious Files on Windows
LibreOffice Flaws Allow Attackers to Run Malicious Files on Windows A high-severity security vulnerability (CVE-2025-0514) in LibreOffice, the widely used open-source office suite, has been patched after researchers discovered it could allow attackers to… Go to gbhackers.com
-
GRUB2 Flaws Expose Millions of Linux Devices to Exploitation
GRUB2 Flaws Expose Millions of Linux Devices to Exploitation A critical set of 20 security vulnerabilities in GRUB2, the widely used bootloader for Linux systems, has been revealed, exposing millions of devices to… Go to gbhackers.com
-
Orange Communication Breached – Hackers Allegedly Claim 380,000 Email Records Exposed
Orange Communication Breached – Hackers Allegedly Claim 380,000 Email Records Exposed Telecommunications provider Orange Communication faces a potential data breach after a threat actor using the pseudonym “Rey” claimed responsibility for leaking 380,000 email records and sensitive corporate data… Go to gbhackers.com
-
RSync Vulnerabilities Allow Hackers to Take Full Control of Servers – PoC Released
RSync Vulnerabilities Allow Hackers to Take Full Control of Servers – PoC Released A series of critical security vulnerabilities in the widely-used Rsync file synchronization tool have been uncovered, exposing millions of servers to potential takeover by… Go to gbhackers.com
-
Millions of WordPress Websites Vulnerable to Script Injection Due to Plugin Flaw
Millions of WordPress Websites Vulnerable to Script Injection Due to Plugin Flaw A critical security vulnerability in the Essential Addons for Elementor plugin, installed on over 2 million WordPress websites, has exposed sites to script injection attacks via… Go to gbhackers.com
-
New Undetectable Batch Script Uses PowerShell and Visual Basic to Install XWorm
New Undetectable Batch Script Uses PowerShell and Visual Basic to Install XWorm A novel malware delivery framework employing advanced obfuscation techniques has evaded detection by security tools for over 48 hours.The attack chain centers around a… Go to gbhackers.com
-
Poseidon Stealer Targets Mac Users via Fake DeepSeek Website
Poseidon Stealer Targets Mac Users via Fake DeepSeek Website Cybersecurity researchers uncovered a sophisticated malware campaign targeting macOS users through a fraudulent DeepSeek.ai interface.Dubbed “Poseidon Stealer,” this information-stealing malware employs advanced anti-analysis techniques… Go to gbhackers.com
-
Beware of Fake Job Interview Challenges Targeting Developers to Deliver Malware
Beware of Fake Job Interview Challenges Targeting Developers to Deliver Malware A new wave of cyberattacks, dubbed “DeceptiveDevelopment,” has been targeting freelance developers through fake job interview challenges, according to ESET researchers.These attacks, linked… Go to gbhackers.com
-
LightSpy Malware Expands With 100+ Commands to Target Users Across All Major OS Platforms
LightSpy Malware Expands With 100+ Commands to Target Users Across All Major OS Platforms The LightSpy surveillance framework has significantly evolved its operational capabilities, now supporting over 100 commands to infiltrate Android, iOS, Windows, macOS, and Linux systems,… Go to gbhackers.com
-
New Phishing Attack Targets Amazon Prime Users to Steal Login Credentials
New Phishing Attack Targets Amazon Prime Users to Steal Login Credentials A new phishing campaign targeting Amazon Prime users has been identified, aiming to steal login credentials and other sensitive information, including payment details and… Go to gbhackers.com
-
Critical RCE Vulnerability in MITRE Caldera – Proof of Concept Released
Critical RCE Vulnerability in MITRE Caldera – Proof of Concept Released A critical remote code execution (RCE) vulnerability has been uncovered in MITRE Caldera, a widely used adversarial emulation framework.The flaw (CVE-2025-27364) affects all versions… Go to gbhackers.com
-
Wireshark 4.4.4 Released – Explore the Latest Features!
Wireshark 4.4.4 Released – Explore the Latest Features! The Wireshark Foundation has announced the release of Wireshark 4.4.4, the latest iteration of the world’s most widely used network protocol analyzer.This update focuses… Go to gbhackers.com
-
Stablecoin Bank Hit by Cyberattack, Loses $49.5M to Hackers
Stablecoin Bank Hit by Cyberattack, Loses $49.5M to Hackers The cryptocurrency sector faced one of its most significant security breaches this year as stablecoin banking platform @0xinfini fell victim to a sophisticated cyberattack.Hackers… Go to gbhackers.com
-
GhostSocks Malware Uses SOCKS5 Proxy to Evade Detection Systems
GhostSocks Malware Uses SOCKS5 Proxy to Evade Detection Systems GhostSocks, a Golang-based SOCKS5 backconnect proxy malware, has emerged as a significant threat within the cybercrime ecosystem.First identified in October 2023 on Russian-language… Go to gbhackers.com
-
LockBit Ransomware Strikes: Exploiting a Confluence Vulnerability
LockBit Ransomware Strikes: Exploiting a Confluence Vulnerability In a swift and highly coordinated attack, LockBit ransomware operators exploited a critical remote code execution vulnerability (CVE-2023-22527) in Atlassian Confluence servers, targeting an… Go to gbhackers.com
-
Fake ChatGPT Premium Phishing Scam Spreads to Steal User Credentials
Fake ChatGPT Premium Phishing Scam Spreads to Steal User Credentials A sophisticated phishing campaign impersonating OpenAI’s ChatGPT Premium subscription service has surged globally, targeting users with fraudulent payment requests to steal credentials.Cybersecurity firm Symantec… Go to gbhackers.com
-
New Zhong Stealer Malware Exploit Zendesk to Attack Fintech and Cryptocurrency
New Zhong Stealer Malware Exploit Zendesk to Attack Fintech and Cryptocurrency A newly identified malware, dubbed Zhong Stealer, has emerged as a significant threat to the fintech and cryptocurrency sectors.Any.run researchers discovered zhong malware… Go to gbhackers.com
-
Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key
Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing attackers to extract private keys used for signing SAML authentication… Go to gbhackers.com
-
SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix
SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer overflow vulnerability CVE-2025-0282 in Ivanti Connect Secure, as confirmed by… Go to gbhackers.com
-
NSA Allegedly Hacked Northwestern Polytechnical University, China Claims
NSA Allegedly Hacked Northwestern Polytechnical University, China Claims Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a cyberattack on Northwestern Polytechnical University, a prominent Chinese institution specializing… Go to gbhackers.com
-
ACRStealer Malware Abuses Google Docs as C2 to Steal Login Credentials
ACRStealer Malware Abuses Google Docs as C2 to Steal Login Credentials The ACRStealer malware, an infostealer disguised as illegal software such as cracks and keygens, has seen a significant increase in its distribution since the… Go to gbhackers.com
-
Nagios XI Flaw Exposes User Details and Emails to Unauthenticated Attackers”
Nagios XI Flaw Exposes User Details and Emails to Unauthenticated Attackers” A security vulnerability in Nagios XI 2024R1.2.2, tracked as CVE-2024-54961, has been disclosed, allowing unauthenticated attackers to retrieve sensitive user information, including usernames and… Go to gbhackers.com
-
New Darcula 3.0 Tool Generates Phishing Kits to Mimic Global Brands
New Darcula 3.0 Tool Generates Phishing Kits to Mimic Global Brands The cybercriminal group behind the notorious “darcula-suite” platform has unveiled its latest iteration, darcula 3.0, which introduces groundbreaking capabilities for creating phishing kits targeting… Go to gbhackers.com
-
Salt Typhoon Hackers Exploit Cisco Vulnerability to Gain Device Access on US.Telecom Networks
Salt Typhoon Hackers Exploit Cisco Vulnerability to Gain Device Access on US.Telecom Networks A highly advanced threat actor, dubbed “Salt Typhoon,” has been implicated in a series of cyberattacks targeting major U.S. telecommunications networks, according to a… Go to gbhackers.com
-
CL0P Ransomware Launches Large-Scale Attacks on Telecom and Healthcare Sectors
CL0P Ransomware Launches Large-Scale Attacks on Telecom and Healthcare Sectors The notorious CL0P ransomware group has intensified its operations in early 2025, targeting critical sectors such as telecommunications and healthcare.Known for its sophisticated… Go to gbhackers.com
-
Adversary-in-the-Middle Hackers Exploit Vulnerabilities to Deploy Advanced Malware
Adversary-in-the-Middle Hackers Exploit Vulnerabilities to Deploy Advanced Malware Cybercriminals are increasingly leveraging sophisticated Adversary-in-the-Middle (AiTM) phishing techniques, enabled by the rise of Phishing-as-a-Service (PhaaS) ecosystems.These operations target financial institutions globally, bypassing… Go to gbhackers.com
-
CISA Issues Seven ICS Advisories Highlighting Critical Vulnerabilities
CISA Issues Seven ICS Advisories Highlighting Critical Vulnerabilities The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released seven Industrial Control Systems (ICS) advisories on February 20, 2025, addressing critical vulnerabilities in products… Go to gbhackers.com
-
AWS Key Hunter: An Automated Solution for Exposed Key Detection
AWS Key Hunter: An Automated Solution for Exposed Key Detection AWS Key Hunter, a cutting-edge automated solution designed to identify exposed AWS keys in GitHub repositories.This powerful tool combines real-time monitoring, advanced scanning capabilities,… Go to gbhackers.com
-
NSA Adds Innovative Features to Ghidra 11.3 Release
NSA Adds Innovative Features to Ghidra 11.3 Release The National Security Agency (NSA) has unveiled Ghidra 11.3, the latest iteration of its open-source software reverse engineering (SRE) framework, introducing transformative features that streamline… Go to gbhackers.com
-
CISA & FBI Warns that Ghost Ransomware Hits Over 70 Organizations
CISA & FBI Warns that Ghost Ransomware Hits Over 70 Organizations The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have issued a joint advisory warning about the widespread impact… Go to gbhackers.com
-
CISA and FBI Issue Alert as Ghost Ransomware Targets 70+ Organizations
CISA and FBI Issue Alert as Ghost Ransomware Targets 70+ Organizations The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have issued a joint advisory warning about the increasing threat… Go to gbhackers.com
-
Symantec Diagnostic Tool Flaw Enables Unauthorized Privilege Escalation
Symantec Diagnostic Tool Flaw Enables Unauthorized Privilege Escalation Symantec, a division of Broadcom, has released a critical security update to address a high-severity vulnerability identified in its Symantec Diagnostic Tool (SymDiag).This vulnerability… Go to gbhackers.com
-
90,000 WordPress Sites Exposed to Local File Inclusion Attacks
90,000 WordPress Sites Exposed to Local File Inclusion Attacks A critical vulnerability (CVE-2025-0366) in the Jupiter X Core WordPress plugin, actively installed on over 90,000 websites, was disclosed on January 6, 2025.The flaw… Go to gbhackers.com
-
CISA Issues Warning on Palo Alto PAN-OS Security Flaw Under Attack
CISA Issues Warning on Palo Alto PAN-OS Security Flaw Under Attack CISA and Palo Alto Networks are scrambling to contain widespread exploitation of a critical authentication bypass vulnerability (CVE-2025-0108) affecting firewall devices running unpatched PAN-OS… Go to gbhackers.com
-
CISA Warns of Active Exploitation of SonicWall SonicOS RCE Vulnerability
CISA Warns of Active Exploitation of SonicWall SonicOS RCE Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding the active exploitation of critical remote code execution (RCE) vulnerability… Go to gbhackers.com
-
Surge in IRS and Tax-Themed Cyber Attacks Driven by Fresh Domain Registrations
Surge in IRS and Tax-Themed Cyber Attacks Driven by Fresh Domain Registrations The months of January through April, marking the U.S. tax season, have seen a sharp rise in malicious cyber activity targeting taxpayers.Broadcom’s Symantec… Go to gbhackers.com
-
Critical Flaw in Apache Ignite (CVE-2024-52577) Allows Attackers to Execute Code Remotely
Critical Flaw in Apache Ignite (CVE-2024-52577) Allows Attackers to Execute Code Remotely A severe security vulnerability (CVE-2024-52577) in Apache Ignite, the open-source distributed database and computing platform, has been disclosed.The flaw enables remote attackers to execute… Go to gbhackers.com
-
Zacks Investment Data Breach Exposes 12 Million Emails and Phone Numbers
Zacks Investment Data Breach Exposes 12 Million Emails and Phone Numbers A cybersecurity incident at Zacks Investment Research has exposed sensitive data belonging to 12 million users, marking the second major breach for the financial… Go to gbhackers.com
-
BitConnect Scam Exposed as Indian Authorities Seize Illicit Gains
BitConnect Scam Exposed as Indian Authorities Seize Illicit Gains The Directorate of Enforcement (ED) in Ahmedabad has dealt a significant blow to one of history’s largest cryptocurrency frauds, recovering Rs. 1,646 crore (approx. $219… Go to gbhackers.com
-
WinRAR 7.10 Latest Version Released – What’s New!
WinRAR 7.10 Latest Version Released – What’s New! The popular file compression and archiving tool, WinRAR 7.10, has released with new features, interface enhancements, and improved performance.WinRAR 7.10 represents a landmark… Go to gbhackers.com
-
Black-Hat SEO Poisioning Attacks Exploit Indian Government and Financial Websites
Black-Hat SEO Poisioning Attacks Exploit Indian Government and Financial Websites A sophisticated black-hat SEO poisoning campaign has compromised over 150 Indian government websites and financial institutions, redirecting millions of users to fraudulent gambling platforms… Go to gbhackers.com