Category: gbhackers
-
Beware of Fake Captcha Verifications Spreading Lumma Malware
Beware of Fake Captcha Verifications Spreading Lumma Malware In January, Netskope Threat Labs uncovered a sophisticated global malware campaign leveraging fake CAPTCHA pages to deliver the Lumma Stealer malware.Lumma, a malware-as-a-service… Go to gbhackers.com
-
KEYPLUG Infrastructure Exposed: Server Configurations and TLS Certificates Revealed
KEYPLUG Infrastructure Exposed: Server Configurations and TLS Certificates Revealed In a recent technical investigation, researchers uncovered critical insights into the infrastructure linked to a suspected Chinese state-backed cyber actor referred to as “RedGolf.”… Go to gbhackers.com
-
HellCat and Morpheus Ransomware Share Identical Payloads for Attacks
HellCat and Morpheus Ransomware Share Identical Payloads for Attacks The cybersecurity landscape witnessed a surge in ransomware activity during the latter half of 2024 and into early 2025, with the emergence of operations… Go to gbhackers.com
-
PayPal Fined $2 Million Fine For Violating Cybersecurity Regulations
PayPal Fined $2 Million Fine For Violating Cybersecurity Regulations The New York State Department of Financial Services (NYDFS) has imposed a $2 million penalty on PayPal, Inc. for breaches of the state’s stringent… Go to gbhackers.com
-
AI Assistant Jailbreaked to Reveal its System Prompts
AI Assistant Jailbreaked to Reveal its System Prompts Anonymous tinkerer claims to have bypassed an AI assistant’s safeguards to uncover its highly confidential system prompt—the underlying instructions shaping its behavior.The breach, achieved… Go to gbhackers.com
-
Rails Apps Arbitrary File Write Vulnerability Let Attackers Execute Code Remotely
Rails Apps Arbitrary File Write Vulnerability Let Attackers Execute Code Remotely A newly exposed vulnerability in Ruby on Rails applications allows attackers to achieve Remote Code Execution (RCE) through a flaw that permits arbitrary file… Go to gbhackers.com
-
New Cookie Sandwich Technique Allows Stealing of HttpOnly cookies
New Cookie Sandwich Technique Allows Stealing of HttpOnly cookies A new attack technique known as the “cookie sandwich” has surfaced, raising significant concerns among cybersecurity professionals.This technique enables attackers to bypass the HttpOnly… Go to gbhackers.com
-
Open-Source ClamAV Releases Security Update for Buffer Overflow Vulnerability – Patch Now
Open-Source ClamAV Releases Security Update for Buffer Overflow Vulnerability – Patch Now ClamAV, a widely used open-source antivirus software, has released security patch updates to address a critical buffer overflow vulnerability (CVE-2025-20128).The vulnerability, identified in the… Go to gbhackers.com
-
WordPress Plugin Vulnerability Exposes 23k+ Websites to Hacking
WordPress Plugin Vulnerability Exposes 23k+ Websites to Hacking Researchers from Patchstack have warned that over 23,000 real estate websites using the popular RealHomes WordPress theme and its bundled Easy Real Estate plugin… Go to gbhackers.com
-
Ex-CIA Analyst Pleaded Guilty For Leaking Top Secret National Defense Information
Ex-CIA Analyst Pleaded Guilty For Leaking Top Secret National Defense Information A former CIA analyst, Asif William Rahman, has pleaded guilty to charges of retaining and transmitting Top Secret National Defense Information to unauthorized recipients…. Go to gbhackers.com
-
Record Breaking 5.6 Tbps DDoS attack Launched by Mirai Botnet
Record Breaking 5.6 Tbps DDoS attack Launched by Mirai Botnet The Mirai botnet unleashed a record-breaking Distributed Denial of Service (DDoS) attack on October 29, 2024, peaking at an astonishing 5.6 terabits per second… Go to gbhackers.com
-
Criminal IP and OnTheHub Partner to Deliver Advanced Cybersecurity Solutions for Education
Criminal IP and OnTheHub Partner to Deliver Advanced Cybersecurity Solutions for Education AI SPERA, a leading Cyber Threat Intelligence (CTI) provider, has collaborated with OnTheHub, a global provider of software in education, to deliver its integrated… Go to gbhackers.com
-
Three New ICS Advisories Released by CISA Detailing Vulnerabilities & Mitigations
Three New ICS Advisories Released by CISA Detailing Vulnerabilities & Mitigations The Cybersecurity and Infrastructure Security Agency (CISA) announced three new Industrial Control Systems (ICS) advisories.These advisories provide critical insights into vulnerabilities impacting Traffic Alert… Go to gbhackers.com
-
SQL Injection Vulnerability in Microsoft’s DevBlogs Lets Hackers Injecting Malicious SQL
SQL Injection Vulnerability in Microsoft’s DevBlogs Lets Hackers Injecting Malicious SQL In a recent discovery, a security researcher uncovered a critical SQL injection vulnerability on Microsoft’s DevBlogs website (accessible at https://devblogs.microsoft.com).This vulnerability could allow attackers… Go to gbhackers.com
-
Microsoft Rolls Out New Administrator Protection Feature Under Windows Security
Microsoft Rolls Out New Administrator Protection Feature Under Windows Security Microsoft has announced the release of Windows 11 Insider Preview Build 27774 to the Canary Channel.This build comes packed with enhancements, including a significant… Go to gbhackers.com
-
OWASP Smart Contract Top 10 2025 Released – What’s new!
OWASP Smart Contract Top 10 2025 Released – What’s new! The Open Web Application Security Project (OWASP) has released its updated Smart Contract Top 10 for 2025, providing essential insights for developers and security teams in… Go to gbhackers.com
-
PoC Exploit Released for TP-Link Code Execution Vulnerability (CVE-2024-54887)
PoC Exploit Released for TP-Link Code Execution Vulnerability (CVE-2024-54887) A serious code execution vulnerability in the TP-Link TL-WR940N router, identified as CVE-2024-54887, has become the focus of intense scrutiny following the release of… Go to gbhackers.com
-
Ransomware Attack Forces UK Brit High School to Close Doors For Students
Ransomware Attack Forces UK Brit High School to Close Doors For Students A ransomware attack has compelled UK Brit, a prominent British high school, to close its doors to students for two days, specifically Monday, January… Go to gbhackers.com
-
OpenVPN Easy-rsa Vulnerability Allows Attacker to Bruteforce Private CA key
OpenVPN Easy-rsa Vulnerability Allows Attacker to Bruteforce Private CA key A significant security vulnerability, designated as CVE-2024-13454, has been discovered in the OpenVPN Easy-RSA tool, specifically affecting versions from 3.0.5 to 3.2.0 that utilize… Go to gbhackers.com
-
Apple Confirms Removal of TikTok App US Users
Apple Confirms Removal of TikTok App US Users Apple has confirmed that popular apps developed by ByteDance Ltd., including TikTok, will no longer be available for download or updates in the United… Go to gbhackers.com
-
Pumakit – Sophisticated Linux Rootkit That Persist Even After Reboots
Pumakit – Sophisticated Linux Rootkit That Persist Even After Reboots Pumakit is a sophisticated rootkit that leverages system call interception to manipulate file and network activity. It ensures persistence through kernel-level embedding that allows… Go to gbhackers.com
-
FunkSec Ransomware Dominating Ransomware Attacks, Compromised 85 Victims In December
FunkSec Ransomware Dominating Ransomware Attacks, Compromised 85 Victims In December FunkSec is a RaaS operator that makes use of artificial intelligence and demonstrates how threat actor strategies are constantly evolving.The analysis reveals that… Go to gbhackers.com
-
Threat Actor IntelBroker Allegedly Claiming Breach of Hewlett Packard Enterprise Data
Threat Actor IntelBroker Allegedly Claiming Breach of Hewlett Packard Enterprise Data A threat actor known as IntelBroker has taken to a prominent dark web forum to claim a significant data breach at Hewlett Packard Enterprise… Go to gbhackers.com
-
Massive NBI Data Breach Exposes Millions of Users Records Online
Massive NBI Data Breach Exposes Millions of Users Records Online The National Bureau of Investigation (NBI), the Philippines’ top investigative agency, has reportedly been compromised, exposing the sensitive data of millions of Filipinos.A dark… Go to gbhackers.com
-
Hackers Easily Bypass Active Directory Group Policy to Allow Vulnerable NTLMv1 Auth Protocol
Hackers Easily Bypass Active Directory Group Policy to Allow Vulnerable NTLMv1 Auth Protocol Researchers have discovered a critical flaw in Active Directory’s NTLMv1 mitigation strategy, where misconfigured on-premises applications can bypass Group Policy settings intended to disable… Go to gbhackers.com
-
AWS Warns of Multiple Vulnerabilities in Amazon WorkSpaces, Amazon AppStream 2.0, & Amazon DCV
AWS Warns of Multiple Vulnerabilities in Amazon WorkSpaces, Amazon AppStream 2.0, & Amazon DCV Amazon Web Services (AWS) has issued a critical security advisory highlighting vulnerabilities in specific versions of its native clients for Amazon WorkSpaces, Amazon AppStream… Go to gbhackers.com
-
FlowerStorm PaaS Platform Attacking Microsoft Users With Fake Login Pages
FlowerStorm PaaS Platform Attacking Microsoft Users With Fake Login Pages Rockstar2FA is a PaaS kit that mimics the legitimate credential-request behavior of cloud/SaaS platforms. Phishing campaigns are delivered via Telegram and use unique URLs… Go to gbhackers.com
-
New Tool Unveiled to Scan Hacking Content on Telegram
New Tool Unveiled to Scan Hacking Content on Telegram A Russian software developer, aided by the National Technology Initiative, has introduced a groundbreaking AI module designed to monitor and analyze content on Telegram.Known… Go to gbhackers.com
-
PoC Exploit Released for Ivanti Connect Secure RCE Vulnerability
PoC Exploit Released for Ivanti Connect Secure RCE Vulnerability A serious security flaw has been identified in Ivanti Connect Secure, designated as CVE-2025-0282, which enables remote unauthenticated attackers to execute arbitrary code.As of January… Go to gbhackers.com
-
Let’s Encrypt Unveils Six-Day Certificate and IP Address Options for 2025
Let’s Encrypt Unveils Six-Day Certificate and IP Address Options for 2025 Let’s Encrypt has announced plans to introduce six-day certificate options and support for IP address certificates in 2025.This initiative is part of the organization’s… Go to gbhackers.com
-
Bug Bounty Bonanza: $40,000 Reward for Escalating Limited Path Traversal to RCE
Bug Bounty Bonanza: $40,000 Reward for Escalating Limited Path Traversal to RCE As a dedicated bug bounty hunter with an enviable track record on BugCrowd, Abdullah Nawaf, Full full-time bug Bounty Hunter, thrives on the thrill of… Go to gbhackers.com
-
AIRASHI Botnet Exploiting 0DAY Vulnerabilities In Large Scale DDoS Attacks
AIRASHI Botnet Exploiting 0DAY Vulnerabilities In Large Scale DDoS Attacks AISURU botnet launched a DDoS attack targeting Black Myth: Wukong distribution platforms in August 2024 that leveraged a 0DAY vulnerability on cnPilot routers and… Go to gbhackers.com
-
New Botnet Exploiting DNS Records Misconfiguration To Deliver Malware
New Botnet Exploiting DNS Records Misconfiguration To Deliver Malware Botnets are the networks of compromised devices that have evolved significantly since the internet’s inception. Threat actors exploit vulnerabilities to control these devices remotely… Go to gbhackers.com
-
FTC Slams GoDaddy For Not Implement Standard Security Practices Following Major Breaches
FTC Slams GoDaddy For Not Implement Standard Security Practices Following Major Breaches The Federal Trade Commission (FTC) has announced that it will require GoDaddy Inc. to develop and implement a comprehensive information security program.This decision comes… Go to gbhackers.com
-
W3 Total Cache Plugin Vulnerability Let Attackers Gain Unauthorized Access to Sensitive Data
W3 Total Cache Plugin Vulnerability Let Attackers Gain Unauthorized Access to Sensitive Data A significant security vulnerability has been identified in the W3 Total Cache plugin for WordPress, affecting all versions up to and including 2.8.1.This critical… Go to gbhackers.com
-
Thousands of PHP-based Web Applications Exploited to Deploy Malware
Thousands of PHP-based Web Applications Exploited to Deploy Malware A significant cybersecurity threat has emerged, threatening the integrity of thousands of PHP-based web applications.A report from Imperva Threat Research has unveiled a sophisticated… Go to gbhackers.com
-
Zoom Security Update – Patches Multiple Vulnerabilities That Let Attackers Escalate Privileges
Zoom Security Update – Patches Multiple Vulnerabilities That Let Attackers Escalate Privileges Zoom Video Communications has released a critical security update addressing multiple vulnerabilities in its suite of applications, including a high-severity flaw that could allow… Go to gbhackers.com
-
Chrome Security Update – Patch For 16 Vulnerabilities
Chrome Security Update – Patch For 16 Vulnerabilities Google has released a significant security update for its Chrome browser, addressing 16 vulnerabilities in version 132.0.6834.83/84 for Windows, Mac, and Linux platforms.This update,… Go to gbhackers.com
-
Google’s “Sign in with Google” Flaw Exposes Millions of Users’ Details
Google’s “Sign in with Google” Flaw Exposes Millions of Users’ Details A critical flaw in Google’s “Sign in with Google” authentication system has left millions of Americans vulnerable to potential data theft.This vulnerability mainly… Go to gbhackers.com
-
Hackers Attacking Internet Connected Fortinet Firewalls Using Zero-Day Vulnerability
Hackers Attacking Internet Connected Fortinet Firewalls Using Zero-Day Vulnerability A widespread campaign targeting Fortinet FortiGate firewall devices with exposed management interfaces on the public internet.The attacks, observed by Arctic Wolf between November… Go to gbhackers.com
-
Critical macOS Vulnerability Lets Hackers to Bypass Apple’s System Integrity Protection
Critical macOS Vulnerability Lets Hackers to Bypass Apple’s System Integrity Protection Microsoft Threat Intelligence has uncovered a critical macOS vulnerability that allowed attackers to bypass Apple’s System Integrity Protection (SIP).Known as CVE-2024-44243, this vulnerability… Go to gbhackers.com
-
Microsoft Warns of MFA Issue Affecting Microsoft 365 users
Microsoft Warns of MFA Issue Affecting Microsoft 365 users Microsoft has issued a warning regarding an ongoing issue with Multi-Factor Authentication (MFA) that is impacting some Microsoft 365 (M365) users.The problem, which surfaced… Go to gbhackers.com
-
CISA Released A Free Guide to Enhance OT Product Security
CISA Released A Free Guide to Enhance OT Product Security To address rising cyber threats targeting critical infrastructure, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a new step-by-step guide designed to… Go to gbhackers.com
-
RedCurl APT Deploys Malware via Windows Scheduled Tasks Exploitation
RedCurl APT Deploys Malware via Windows Scheduled Tasks Exploitation Researchers identified RedCurl APT group activity in Canada in late 2024, where the attackers used scheduled tasks to execute pcalua.exe to run malicious binaries… Go to gbhackers.com
-
Hackers Using YouTube Links and Microsoft 365 Themes to Steal Logins
Hackers Using YouTube Links and Microsoft 365 Themes to Steal Logins Cybercriminals are executing sophisticated phishing attacks targeting Microsoft 365 users by employing deceptive URLs that closely resemble legitimate O365 domains, creating a high degree… Go to gbhackers.com
-
IBM Robotic Process Automation Vulnerability Let Attackers Obtain Sensitive Data
IBM Robotic Process Automation Vulnerability Let Attackers Obtain Sensitive Data A newly disclosed security vulnerability in IBM Robotic Process Automation (RPA) has raised concerns about potential data breaches.The vulnerability, tracked as CVE-2024-51456, could allow remote attackers… Go to gbhackers.com
-
PoC Exploit Released for Critical macOS Sandbox Vulnerability (CVE-2024-54498)
PoC Exploit Released for Critical macOS Sandbox Vulnerability (CVE-2024-54498) A proof-of-concept (PoC) exploit has been publicly disclosed for a critical vulnerability impacting macOS systems, identified as CVE-2024-54498.This vulnerability poses a significant security risk by… Go to gbhackers.com
-
Credit Card Skimmer Hits WordPress Checkout Pages, Stealing Payment Data
Credit Card Skimmer Hits WordPress Checkout Pages, Stealing Payment Data Researchers analyzed a new stealthy credit card skimmer that targets WordPress checkout pages by injecting malicious JavaScript into the WordPress database. On checkout pages, the… Go to gbhackers.com
-
QSC: Multi-Plugin Malware Framework Installs Backdoor on Windows
QSC: Multi-Plugin Malware Framework Installs Backdoor on Windows The QSC Loader service DLL named “loader.dll” leverages two distinct methods to obtain the path to the Core module code.It either extracts the… Go to gbhackers.com
-
New NonEuclid RAT Evades Antivirus and Encrypts Critical Files
New NonEuclid RAT Evades Antivirus and Encrypts Critical Files A NonEuclid sophisticated C# Remote Access Trojan (RAT) designed for the.NET Framework 4.8 has been shown to pose a significant and ever-evolving cyber threat. The… Go to gbhackers.com
-
Weaponized LDAP Exploit Deploys Information-Stealing Malware
Weaponized LDAP Exploit Deploys Information-Stealing Malware Cybercriminals are exploiting the recent critical LDAP vulnerabilities (CVE-2024-49112 and CVE-2024-49113) by distributing fake proof-of-concept exploits for CVE-2024-49113 (dubbed “LDAPNightmare”). These malicious PoCs, often disguised… Go to gbhackers.com
-
Hackers Targeting Users Who Lodged Complaints On Government portal To Steal Credit Card Data
Hackers Targeting Users Who Lodged Complaints On Government portal To Steal Credit Card Data Fraudsters in the Middle East are exploiting a vulnerability in the government services portal. By impersonating government officials, they target individuals who have filed… Go to gbhackers.com
-
Juniper Networks Vulnerability Let Remote Attacker Execute Network Attacks
Juniper Networks Vulnerability Let Remote Attacker Execute Network Attacks Juniper Networks has disclosed a significant vulnerability affecting its Junos OS and Junos OS Evolved platforms.Identified as CVE-2025-21598, this flaw allows unauthenticated remote… Go to gbhackers.com
-
Beware! Fake Crowdstrike Recruitment Emails Spread Cryptominer Malware
Beware! Fake Crowdstrike Recruitment Emails Spread Cryptominer Malware CrowdStrike, a leader in cybersecurity, uncovered a sophisticated phishing campaign that leverages its recruitment branding to propagate malware disguised as an “employee CRM application.”This… Go to gbhackers.com
-
PowerSchool Hacked – Attackers Accessed Personal Data of Students and Teachers
PowerSchool Hacked – Attackers Accessed Personal Data of Students and Teachers Walker County Schools has reported that unauthorized access to personal data belonging to students and educators was achieved through the company’s student information system… Go to gbhackers.com
-
United Nations Aviation Agency Hacked Recruitment Data Exposed
United Nations Aviation Agency Hacked Recruitment Data Exposed The International Civil Aviation Organization (ICAO), a United Nations agency responsible for coordinating global aviation standards, has reported a significant information security incident that… Go to gbhackers.com
-
“Siri Data Stays Private, Not Used for Ads,” Apple Says
“Siri Data Stays Private, Not Used for Ads,” Apple Says Apple Inc. says its commitment to user privacy, emphasizing that its products, such as the digital assistant Siri, are designed to safeguard personal data… Go to gbhackers.com
-
Malicious Solana Packages Attacking Devs Abusing Slack And ImgBB For Data Theft
Malicious Solana Packages Attacking Devs Abusing Slack And ImgBB For Data Theft Malicious packages “solanacore,” “solana login,” and “walletcore-gen” on npmjs target Solana developers with Windows trojans and malware for keylogging and data exfiltration via Slack… Go to gbhackers.com
-
New Great Morpheus Hacker Group Claims Hacking Into Arrotex Pharmaceuticals And PUS GmbH
New Great Morpheus Hacker Group Claims Hacking Into Arrotex Pharmaceuticals And PUS GmbH A Data Leak Site (DLS) belonging to a new extortion group named Morpheus, which has stolen data from Arrotex Pharmaceuticals (Australia) on December 12th… Go to gbhackers.com
-
Green Bay Packers Store Hacked – Thousands of Credit Cards Data Stolen
Green Bay Packers Store Hacked – Thousands of Credit Cards Data Stolen The Green Bay Packers, Inc. has confirmed that its online merchandise store was hacked, leading to the theft of credit card data from over… Go to gbhackers.com
-
Gitlab Patches Multiple Vulnerabilities Including Resource Exhaustion & User Manipulation
Gitlab Patches Multiple Vulnerabilities Including Resource Exhaustion & User Manipulation GitLab has announced the release of critical updates to its Community Edition (CE) and Enterprise Edition (EE), specifically versions 17.7.1, 17.6.3, and 17.5.5.These… Go to gbhackers.com
-
Is this Website Safe: How to Check Website Safety – 2025
Is this Website Safe: How to Check Website Safety – 2025 is this website safe? In this digital world, Check a website is safe is the most critical concern since there are countless malicious websites… Go to gbhackers.com
-
Stalwart – All-in-One Open-Source Secure Mail Server with JMAP, IMAP4, POP3, and SMTP
Stalwart – All-in-One Open-Source Secure Mail Server with JMAP, IMAP4, POP3, and SMTP Stalwart is an innovative open-source mail server solution that supports JMAP, IMAP4, POP3, and SMTP, offering a comprehensive suite of features designed for security,… Go to gbhackers.com
-
Washington State Filed Lawsuit Against T-Mobile Massive Data Breach
Washington State Filed Lawsuit Against T-Mobile Massive Data Breach Washington State Attorney General Bob Ferguson filed a consumer protection lawsuit against T-Mobile for its alleged failure to secure sensitive personal information of over… Go to gbhackers.com
-
PriveShield – Advanced Privacy Protection with Browser Profile Isolation
PriveShield – Advanced Privacy Protection with Browser Profile Isolation A browser extension named PRIVESHIELD automatically creates isolated profiles to group websites based on browsing history and user interaction, which disrupts cross-website tracking practices… Go to gbhackers.com
-
Critical BIOS/UEFI Vulnerabilities Allow Attackers To Overwrite System Firmware
Critical BIOS/UEFI Vulnerabilities Allow Attackers To Overwrite System Firmware Researchers discovered critical BIOS/UEFI vulnerabilities in the Illumina iSeq 100 DNA sequencer, where the device utilizes an outdated firmware implementation with CSM mode lacking… Go to gbhackers.com
-
Silent Spies: How Russian Surveillance Systems Are Tracking You Worldwide
Silent Spies: How Russian Surveillance Systems Are Tracking You Worldwide In an age where digital footprints can be traced with just a few clicks, surveillance technology has become a double-edged sword. While it can… Go to gbhackers.com
-
India’s Draft Digital Personal Data Protection Rules
India’s Draft Digital Personal Data Protection Rules India has unveiled its draft Digital Personal Data Protection Rules, designed to operationalize the Digital Personal Data Protection Act, 2023 (DPDP Act).As the… Go to gbhackers.com
-
Android Security Updates: Patch for Critical RCE Vulnerabilities
Android Security Updates: Patch for Critical RCE Vulnerabilities The January 2025 Android Security Bulletin has issued important updates regarding critical vulnerabilities that affect Android devices.Users are urged to ensure their devices are… Go to gbhackers.com
-
Hackers Compromised Argentina’s Airport Security Payroll System
Hackers Compromised Argentina’s Airport Security Payroll System Hackers have successfully infiltrated Argentina’s Airport Security Police (PSA) payroll system, raising alarms about the safety of sensitive personnel information.This incident has revealed significant… Go to gbhackers.com
-
PoC Exploit Released for Critical OpenSSH Vulnerability (CVE-2024-6387)
PoC Exploit Released for Critical OpenSSH Vulnerability (CVE-2024-6387) An alarming new development emerged in the cybersecurity landscape with the release of a proof-of-concept (PoC) exploit targeting the critical vulnerability identified as CVE-2024-6387…. Go to gbhackers.com
-
Malicious EditThisCookie Extension Attacking Chrome Users to Steal Data
Malicious EditThisCookie Extension Attacking Chrome Users to Steal Data The popular cookie management extension EditThisCookie has been the target of a malicious impersonation. Originally a trusted tool for Chrome users, EditThisCookie allowed users… Go to gbhackers.com
-
WordPress Plugin Vulnerability Exposes 3 Million Websites to Injection Attacks
WordPress Plugin Vulnerability Exposes 3 Million Websites to Injection Attacks A critical vulnerability has been identified in the popular UpdraftPlus: WP Backup & Migration Plugin, potentially impacting over 3 million WordPress websites.This security flaw… Go to gbhackers.com
-
iPhone Sharing the Photos by Default to Apple
iPhone Sharing the Photos by Default to Apple A recent blog post by developer Jeff Johnson has brought to light a new feature in Apple’s Photos app within the recently launched iOS… Go to gbhackers.com
-
The Defender vs. The Attacker Game
The Defender vs. The Attacker Game The researcher proposes a game-theoretic approach to analyze the interaction between the model defender and attacker in trigger-based black-box model watermarking. They design payoff functions… Go to gbhackers.com
-
Stealthy Steganography Backdoor Attacks Target Android Apps
Stealthy Steganography Backdoor Attacks Target Android Apps BARWM, a novel backdoor attack approach for real-world deep learning (DL) models deployed on mobile devices. Existing backdoor attacks often suffer from limitations such… Go to gbhackers.com
-
LegionLoader Abusing Chrome Extensions To Deliver Infostealer Malware
LegionLoader Abusing Chrome Extensions To Deliver Infostealer Malware LegionLoader, a C/C++ downloader malware, first seen in 2019, delivers payloads like malicious Chrome extensions, which can manipulate emails, track browsing, and even transform… Go to gbhackers.com
-
ASUS Critical Vulnerabilities Let Attackers Execute Arbitrary Commands
ASUS Critical Vulnerabilities Let Attackers Execute Arbitrary Commands In a recent security advisory, ASUS has alerted users to critical vulnerabilities affecting several of its router models. These flaws, tracked as CVE-2024-12912 and CVE-2024-13062, pose severe risks… Go to gbhackers.com
-
Apple Agrees to $95M Settlement Over Siri Privacy Lawsuit
Apple Agrees to $95M Settlement Over Siri Privacy Lawsuit Apple Inc. has agreed to pay $95 million to settle a proposed class-action lawsuit alleging that its Siri voice assistant infringed on users’ privacy… Go to gbhackers.com
-
NTT Docomo Hit by DDoS Attack, Services Disrupted for 11 Hours
NTT Docomo Hit by DDoS Attack, Services Disrupted for 11 Hours NTT Docomo, one of Japan’s leading telecommunications and IT service providers, experienced a massive disruption on January 2, 2025, after a Distributed Denial of… Go to gbhackers.com
-
iTerm2 Emulator Vulnerability Let Attackers Access Sensitive User Data
iTerm2 Emulator Vulnerability Let Attackers Access Sensitive User Data A critical vulnerability discovered in the popular macOS terminal emulator iTerm2 has raised concerns among cybersecurity experts and software users.The flaw, which could… Go to gbhackers.com
-
PoC Exploit Released For Critical Windows LDAP RCE Vulnerability
PoC Exploit Released For Critical Windows LDAP RCE Vulnerability The CVE-2024-49112 vulnerability in Windows LDAP allows remote code execution on unpatched Domain Controllers, as a zero-click exploit leverages this by crafting malicious LDAP… Go to gbhackers.com
-
SmuggleShield – Browser Extension to Detect HTML Smuggling Attacks
SmuggleShield – Browser Extension to Detect HTML Smuggling Attacks SmuggleShield, a recently launched browser extension, is gaining attention in the cybersecurity space for its innovative approach to mitigating HTML smuggling attacks.With its… Go to gbhackers.com
-
EC2 Grouper Hackers Using AWS Tools To Exploit Compromised Credentials
EC2 Grouper Hackers Using AWS Tools To Exploit Compromised Credentials Cloud security researchers have uncovered alarming trends in identity compromises within Amazon Web Services (AWS) environments.Among the most prolific threat actors is a group… Go to gbhackers.com
-
Trend Micro Apex One Vulnerabilities Let Escalate Privilege
Trend Micro Apex One Vulnerabilities Let Escalate Privilege Trend Micro has addressed six high-severity vulnerabilities in its Apex One and Apex One as a Service product, which could allow attackers to escalate privileges on affected Windows… Go to gbhackers.com
-
US Army Soldier Arrested for Allegedly Selling Customer Call Records From AT&T & Verizon
US Army Soldier Arrested for Allegedly Selling Customer Call Records From AT&T & Verizon A 20-year-old U.S. Army soldier, Cameron John Wagenius, has been arrested and indicted by federal authorities for allegedly selling confidential customer call records stolen… Go to gbhackers.com
-
D-Link Warns of Botnets Exploiting End-of-Life Routers
D-Link Warns of Botnets Exploiting End-of-Life Routers D-Link warned users of several legacy router models about known vulnerabilities actively exploited by botnets.These devices, which have reached End-of-Life (EOL) and End-of-Service… Go to gbhackers.com
-
CISA Warns of Palo Alto Networks PAN-OS Vulnerability Exploited in Wild
CISA Warns of Palo Alto Networks PAN-OS Vulnerability Exploited in Wild The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert on a critical vulnerability in Palo Alto Networks PAN-OS.Tracked as CVE-2024-3393, this… Go to gbhackers.com
-
US Treasury Department Breach, Hackers Accessed Workstations
US Treasury Department Breach, Hackers Accessed Workstations The Biden administration confirmed that a Chinese state-sponsored hacking group breached the U.S. Treasury Department, gaining unauthorized access to employee workstations and unclassified documents.This… Go to gbhackers.com
-
TrueNAS CORE Vulnerability Let Attackers Execute Remote Code
TrueNAS CORE Vulnerability Let Attackers Execute Remote Code Security researchers Daan Keuper, Thijs Alkemade, and Khaled Nassar from Computest Sector 7 disclosed a critical vulnerability in TrueNAS CORE, a widely-used open-source storage… Go to gbhackers.com
-
New Botnet Exploiting D-Link Routers To Gain Control Remotely
New Botnet Exploiting D-Link Routers To Gain Control Remotely Researchers observed a recent surge in activity from the “FICORA” and “CAPSAICIN,” both variants of Mirai and Kaiten, respectively, which exploit known vulnerabilities in… Go to gbhackers.com
-
NFS Protocol Security Bypassed To Access Files From Remote Server
NFS Protocol Security Bypassed To Access Files From Remote Server The NFS protocol offers authentication methods like AUTH_SYS, which relies on untrusted user IDs, and Kerberos, providing cryptographic verification. While Kerberos offers strong security, its… Go to gbhackers.com
-
Hackers Weaponize Websites With LNK File To Deliver Weaponized LZH File
Hackers Weaponize Websites With LNK File To Deliver Weaponized LZH File The watering hole attack leverages a compromised website to deliver malware. When a user visits the infected site, their system downloads an LZH archive… Go to gbhackers.com
-
PoC Exploited Released for Oracle Weblogic Server Vulnerability
PoC Exploited Released for Oracle Weblogic Server Vulnerability Security researchers have warned that a Proof-of-Concept (PoC) exploit has been publicly released for a critical vulnerability affecting Oracle WebLogic Server.The flaw tracked… Go to gbhackers.com
-
Microsoft Warns of Windows 11 24H2 Issue that Blocks Windows Security Updates
Microsoft Warns of Windows 11 24H2 Issue that Blocks Windows Security Updates Microsoft has issued a warning about a significant issue impacting devices running Windows 11, version 24H2, that could block essential Windows Security updates.The problem… Go to gbhackers.com
-
Cyberhaven Hacked – Chrome Extension With 400,000 users Compromised
Cyberhaven Hacked – Chrome Extension With 400,000 users Compromised Cyberhaven, a prominent cybersecurity company, disclosed that its Chrome extension With 400,000+ users was targeted in a malicious cyberattack on Christmas Eve 2024, as… Go to gbhackers.com
-
Four-Faith Industrial Routers Vulnerability Exploited in the Wild to Gain Remote Access
Four-Faith Industrial Routers Vulnerability Exploited in the Wild to Gain Remote Access A significant post-authentication vulnerability affecting Four-Faith industrial routers has been actively exploited in the wild.Assigned as CVE-2024-12856, this flaw allows attackers to execute unauthenticated… Go to gbhackers.com
-
AT&T and Verizon Hacked – Salt Typhoon Compromised The Network For High Profiles
AT&T and Verizon Hacked – Salt Typhoon Compromised The Network For High Profiles AT&T and Verizon Communications, two of America’s largest telecommunications providers, have confirmed they were targeted by the China-linked Salt Typhoon hacking operation, though both… Go to gbhackers.com
-
New ‘OtterCookie’ Malware Attacking Software Developers Via Fake Job Offers
New ‘OtterCookie’ Malware Attacking Software Developers Via Fake Job Offers Palo Alto Networks reported the Contagious Interview campaign in November 2023, a financially motivated attack targeting various organizations, unlike typical nation-sponsored attacks. While primarily associated… Go to gbhackers.com
-
NjRat 2.3D Pro Edition Shared on GitHub: A Growing Cybersecurity Concern
NjRat 2.3D Pro Edition Shared on GitHub: A Growing Cybersecurity Concern The recent discovery of the NjRat 2.3D Professional Edition on GitHub has raised alarms in the cybersecurity community.This notorious Remote Access Trojan (RAT),… Go to gbhackers.com