no alarms and no surprises please..
-
GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection
GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection The JavaScript (aka JScript) malware loader called GootLoader has been observed using a malformed ZIP archive that’s designed to sidestep detection efforts by concatenating anywhere from 500 to 1,000 archives. “The actor creates a malformed archive as an anti-analysis technique,” Expel security researcher Aaron Walton…
-
Five Malicious Chrome Extensions Impersonate Workday and NetSuite to Hijack Accounts
Five Malicious Chrome Extensions Impersonate Workday and NetSuite to Hijack Accounts Cybersecurity researchers have discovered five new malicious Google Chrome web browser extensions that masquerade as human resources (HR) and enterprise resource planning (ERP) platforms like Workday, NetSuite, and SuccessFactors to take control of victim accounts. “The extensions work in concert to steal authentication tokens,…
-
Your Digital Footprint Can Lead Right to Your Front Door
Your Digital Footprint Can Lead Right to Your Front Door You lock your doors at night. You avoid sketchy phone calls. You’re careful about what you post on social media. But what about the information about you that’s already out there—without your permission? Your name. Home address. Phone number. Past jobs. Family members. Old usernames.…
-
LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing
LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing Security experts have disclosed details of a new campaign that has targeted U.S. government and policy entities using politically themed lures to deliver a backdoor known as LOTUSLITE. The targeted malware campaign leverages decoys related to the recent geopolitical developments between the U.S. and Venezuela…
-
China-Linked APT Exploited Sitecore Zero-Day in Critical Infrastructure Intrusions
China-Linked APT Exploited Sitecore Zero-Day in Critical Infrastructure Intrusions A threat actor likely aligned with China has been observed targeting critical infrastructure sectors in North America since at least last year. Cisco Talos, which is tracking the activity under the name UAT-8837, assessed it to be a China-nexus advanced persistent threat (APT) actor with medium…
-
TamperedChef serves bad ads with infostealers as the main course
TamperedChef serves bad ads with infostealers as the main course Go to sophos
-
AI and the Corporate Capture of Knowledge
AI and the Corporate Capture of Knowledge More than a decade after Aaron Swartz’s death, the United States is still living inside the contradiction that destroyed him. Swartz believed that knowledge, especially publicly funded knowledge, should be freely accessible. Acting on that, he downloaded thousands of academic articles from the JSTOR archive with the intention…
-
Weekly Update 486
Weekly Update 486 I’m in Oslo! Flighty is telling me I’ve flown in or out of here 43 times since a visit in 2014 set me on a new path professionally and, many years later, personally. It’s special here, like a second home that just feels… right. This week, the business end of things is…
-
More Problems for Fortinet: Critical FortiSIEM Flaw Exploited
More Problems for Fortinet: Critical FortiSIEM Flaw Exploited CVE-2025-64155, a command injection vulnerability, was disclosed earlier this week and quickly came under attack from a variety of IP addresses. Rob Wright Go to gbhackers.com
-
CISOs Rise to Prominence: Security Leaders Join the Executive Suite
CISOs Rise to Prominence: Security Leaders Join the Executive Suite Security professionals are moving on up the executive ranks as enterprises face rising regulatory and compliance standards. Arielle Waldman Go to gbhackers.com
-
AI System Reduces Attack Reconstruction Time From Weeks to Hours
AI System Reduces Attack Reconstruction Time From Weeks to Hours Pacific Northwest National Labs’ expert cybersecurity system, ALOHA, can recreate attacks and test them against organizations’ infrastructure to bolster defense. Robert Lemos, Contributing Writer Go to gbhackers.com
-
AWS Console Supply Chain Breach Enables GitHub Repository Hijacking
AWS Console Supply Chain Breach Enables GitHub Repository Hijacking A newly reported supply chain attack targeting the Amazon Web Services (AWS) management console has raised alarms across the developer community. Cybersecurity researchers have discovered… Go to gbhackers.com
-
Zero-Click Exploit Chain Discovered Targeting Google Pixel 9 Devices
Zero-Click Exploit Chain Discovered Targeting Google Pixel 9 Devices Security researchers at Google Project Zero have disclosed a complete zero-click exploit chain affecting Google Pixel 9 smartphones, chaining vulnerabilities in the Dolby audio… Go to gbhackers.com
-
Azure Identity Token Flaw Exposes Windows Admin Center to Tenant-Wide Breaches
Azure Identity Token Flaw Exposes Windows Admin Center to Tenant-Wide Breaches Cymulate Research Labs discovered a high-severity authentication bypass vulnerability in Microsoft Windows Admin Centre’s Azure AD Single Sign-On implementation that enables attackers with local… Go to gbhackers.com
-
Promptware Kill Chain – Five-step Kill Chain Model For Analyzing Cyberthreats
Promptware Kill Chain – Five-step Kill Chain Model For Analyzing Cyberthreats Promptware Kill Chain is a new five-step model that explains how attacks against AI systems powered by large language models (LLMs) behave more like… Go to gbhackers.com
-
Critical Cal.com Vulnerability Let Attackers Bypass Authentication and Hijack Any User Account
Critical Cal.com Vulnerability Let Attackers Bypass Authentication and Hijack Any User Account A newly disclosed critical vulnerability in Cal.com, an open-source scheduling and booking platform, could allow attackers to bypass authentication and gain full access to any user… Go to gbhackers.com
-
Cisco finally fixes AsyncOS zero-day exploited since November
Cisco finally fixes AsyncOS zero-day exploited since November Cisco finally patched a maximum-severity AsyncOS zero-day exploited in attacks targeting Secure Email Gateway (SEG) appliances since November 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Some Windows PCs fail to shut down after January update
Microsoft: Some Windows PCs fail to shut down after January update Microsoft has confirmed a new issue that prevents Windows 11 23H2 devices with System Guard Secure Launch enabled from shutting down. […] Sergiu Gatlan Go to bleepingcomputer
-
Google now lets you change your @gmail.com address, rolling out
Google now lets you change your @gmail.com address, rolling out Google has confirmed that it’s now possible to change your @gmail.com address. This means that if your current email is [email protected], you can now change it to [email protected]. […] Mayank Parmar Go to bleepingcomputer
-
ChatGPT is now more reliable at finding and remembering your past chat
ChatGPT is now more reliable at finding and remembering your past chat OpenAI is rolling out a big upgrade for ChatGPT with support for advanced chat history search, but the feature is rolling out to Plus and Pro subscribers only. […] Mayank Parmar Go to bleepingcomputer
-
Gootloader now uses 1,000-part ZIP archives for stealthy delivery
Gootloader now uses 1,000-part ZIP archives for stealthy delivery The Gootloader malware, typically used for initial access, is now using a malformed ZIP archive designed to evade detection by concatenating up to 1,000 archives. […] Bill Toulas Go to bleepingcomputer
-
Go 1.25.6 and 1.24.12 Patch Critical Vulnerabilities Lead to DoS and Memory Exhaustion Risks
Go 1.25.6 and 1.24.12 Patch Critical Vulnerabilities Lead to DoS and Memory Exhaustion Risks The Go programming language team has rolled out emergency point releases, Go 1.25.6 and 1.24.12, to address six high-impact security flaws. These updates fix denial-of-service (DoS) vectors, arbitrary code execution risks, and TLS mishandlings that could expose developers to remote attacks.…
-
New AWS Console Supply Chain Attack Lets Attackers Hijack AWS GitHub Repositories
New AWS Console Supply Chain Attack Lets Attackers Hijack AWS GitHub Repositories A critical misconfiguration in AWS CodeBuild enabled unauthenticated attackers to seize control of key AWS-owned GitHub repositories, including the widely used AWS JavaScript SDK powering the AWS Console itself. This supply chain vulnerability threatened platform-wide compromise, potentially injecting malicious code into applications and…
-
Hackers Abusing Legitimate Cloud and CDN Platforms to Host Phishing Kits
Hackers Abusing Legitimate Cloud and CDN Platforms to Host Phishing Kits Threat actors are increasingly using trusted cloud and content delivery network platforms to host phishing kits, creating major detection challenges for security teams. Unlike traditional phishing campaigns that rely on newly registered suspicious domains, these attacks use legitimate infrastructure from providers like Google, Microsoft…
-
Promptware Kill Chain – Five-Step Kill Chain Model for Analyzing Cyberthreats
Promptware Kill Chain – Five-Step Kill Chain Model for Analyzing Cyberthreats Large language models have become deeply integrated into everyday business operations, from customer service chatbots to autonomous agents managing calendars, executing code, and handling financial transactions. This rapid expansion has created a critical security blind spot. Researchers have identified that attacks targeting these systems…
-
Fortinet FortiSIEM Vulnerability CVE-2025-64155 Actively Exploited in Attacks
Fortinet FortiSIEM Vulnerability CVE-2025-64155 Actively Exploited in Attacks Fortinet FortiSIEM vulnerability CVE-2025-64155 is under active exploitation, as confirmed by Defused through their honeypot deployments. This critical OS command injection flaw enables unauthenticated remote code execution, posing severe risks to enterprise security monitoring systems. CVE-2025-64155 stems from improper neutralization of special elements in OS commands within…
-
Cisco Patches Zero-Day RCE Exploited by China-Linked APT in Secure Email Gateways
Cisco Patches Zero-Day RCE Exploited by China-Linked APT in Secure Email Gateways Cisco on Thursday released security updates for a maximum-severity security flaw impacting Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, nearly a month after the company disclosed that it had been exploited as a zero-day by…
-
AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain Attacks
AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain Attacks A critical misconfiguration in Amazon Web Services (AWS) CodeBuild could have allowed complete takeover of the cloud service provider’s own GitHub repositories, including its AWS JavaScript SDK, putting every AWS environment at risk. The vulnerability has been codenamed CodeBreach by cloud security company Wiz.…
-
Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin Access
Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin Access A maximum-severity security flaw in a WordPress plugin called Modular DS has come under active exploitation in the wild, according to Patchstack. The vulnerability, tracked as CVE-2026-23550 (CVSS score: 10.0), has been described as a case of unauthenticated privilege escalation impacting all versions…
-
Researchers Reveal Reprompt Attack Allowing Single-Click Data Exfiltration From Microsoft Copilot
Researchers Reveal Reprompt Attack Allowing Single-Click Data Exfiltration From Microsoft Copilot Cybersecurity researchers have disclosed details of a new attack method dubbed Reprompt that could allow bad actors to exfiltrate sensitive data from artificial intelligence (AI) chatbots like Microsoft Copilot in a single click, while bypassing enterprise security controls entirely. “Only a single click on…
-
ThreatsDay Bulletin: AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More Stories
ThreatsDay Bulletin: AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More Stories The internet never stays quiet. Every week, new hacks, scams, and security problems show up somewhere. This week’s stories show how fast attackers change their tricks, how small mistakes turn into big risks, and how the same old tools keep…
-
New Vulnerability in n8n
New Vulnerability in n8n This isn’t good: We discovered a critical vulnerability (CVE-2026-21858, CVSS 10.0) in n8n that enables attackers to take over locally deployed instances, impacting an estimated 100,000 servers globally. No official workarounds are available for this vulnerability. Users should upgrade to version 1.121.0 or later to remediate the vulnerability. Three technical links…
-
ISC Stormcast For Friday, January 16th, 2026 https://isc.sans.edu/podcastdetail/9770, (Fri, Jan 16th)
ISC Stormcast For Friday, January 16th, 2026 https://isc.sans.edu/podcastdetail/9770, (Fri, Jan 16th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Battling Cryptojacking, Botnets, and IABs [Guest Diary], (Thu, Jan 15th)
Battling Cryptojacking, Botnets, and IABs [Guest Diary], (Thu, Jan 15th) [This is a Guest Diary by Matthew Presnal, an ISC intern as part of the SANS.edu BACS program] Cryptojacking and botnets can pose a greater threat than a simple drain of resources. These organizations have been known to engage in “DDoS for Hire” or even…
-
WEF: AI overtakes ransomware as fastest-growing cyber risk
WEF: AI overtakes ransomware as fastest-growing cyber risk We can no longer say that artificial intelligence is a “future risk”, lurking somewhere on a speculative threat horizon. The truth is that it is a fast-growing cybersecurity risk that organizations are facing today. That’s not just my opinion, that’s also the message that comes loud and…
-
Smashing Security podcast #450: From Instagram panic to Grok gone wild
Smashing Security podcast #450: From Instagram panic to Grok gone wild Confusion reigns after claims that data linked to 17.5 million Instagram accounts is up for sale – sparked by a vague post, contradictory statements, and a flood of password reset emails nobody asked for. And we dig into Grok, Elon Musk’s AI chatbot, after…
-
Predator Spyware Sample Indicates ‘Vendor-Controlled’ C2
Predator Spyware Sample Indicates ‘Vendor-Controlled’ C2 Researchers detailed how Intellexa, Predator’s owner, uses failed deployments and thwarted infections to strengthen its commercial spyware and generate more effective attacks. Rob Wright Go to gbhackers.com
-
Winter Olympics Could Share Podium With Cyberattackers
Winter Olympics Could Share Podium With Cyberattackers The upcoming Winter Games in the Italian Alps are attracting both hacktivists looking to reach billions of people and state-sponsored cyber-spies targeting the attending glitterati. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
Vulnerabilities Surge, But Messy Reporting Blurs Picture
Vulnerabilities Surge, But Messy Reporting Blurs Picture MITRE loses its lead as the top reporter of vulnerabilities, while new organizations pump out CVEs and reported bugs in WordPress plugins surge. Robert Lemos, Contributing Writer Go to gbhackers.com
-
Trio of Critical Bugs Spotted in Delta Industrial PLCs
Trio of Critical Bugs Spotted in Delta Industrial PLCs Experts disagree on whether the vulnerabilities in a programmable logic controller from Delta are a five-alarm fire or not much to worry over. Nate Nelson, Contributing Writer Go to gbhackers.com
-
DragonForce Ransomware Breakdown and Decryptor for ESXi & Windows
DragonForce Ransomware Breakdown and Decryptor for ESXi & Windows Security researchers have published an in‑depth technical analysis of the DragonForce ransomware operation, along with details of working decryptors for both Windows and ESXi… Go to gbhackers.com
-
North Korean Hackers Exploit Code Repositories in “Contagious Interview” Campaign
North Korean Hackers Exploit Code Repositories in “Contagious Interview” Campaign A newly documented campaign dubbed “Contagious Interview” shows North Korean threat actors weaponising developer tooling and code-repository workflows to steal credentials, cryptocurrency wallets and… Go to gbhackers.com
-
Betterment Confirms Unauthorised Access to Its Internal Systems
Betterment Confirms Unauthorised Access to Its Internal Systems Digital investment advisor Betterment has confirmed that unauthorized individuals gained access to its internal systems in a recent security breach. The compromise allowed attackers to… Go to gbhackers.com
-
Android Users Hit by Volume Button Bug Linked to Select to Speak
Android Users Hit by Volume Button Bug Linked to Select to Speak Google has confirmed a critical bug affecting Android devices where volume buttons malfunction when the Select to Speak accessibility feature is enabled. The issue… Go to gbhackers.com
-
Spring CLI Vulnerability Allows Attackers to Execute Commands on User Systems
Spring CLI Vulnerability Allows Attackers to Execute Commands on User Systems A command-injection vulnerability in the Spring CLI VSCode extension allows attackers to execute arbitrary commands on affected user machines. The vulnerability, tracked as CVE-2026-22718, affects all versions of the extension through… Go to gbhackers.com
-
FTC bans GM from selling drivers’ location data for five years
FTC bans GM from selling drivers’ location data for five years The FTC has finalized an order with General Motors, settling charges that it collected and sold the location and driving data of millions of drivers without consent. […] Sergiu Gatlan Go to bleepingcomputer
-
Palo Alto Networks warns of DoS bug letting hackers disable firewalls
Palo Alto Networks warns of DoS bug letting hackers disable firewalls Palo Alto Networks patched a high-severity vulnerability that could allow unauthenticated attackers to disable firewall protections in denial-of-service (DoS) attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft disrupts massive RedVDS cybercrime virtual desktop service
Microsoft disrupts massive RedVDS cybercrime virtual desktop service Microsoft announced on Wednesday that it disrupted RedVDS, a massive cybercrime platform linked to at least $40 million in reported losses in the United States alone since March 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
ChatGPT’s upcoming cross-platform feature is codenamed “Agora”
ChatGPT’s upcoming cross-platform feature is codenamed “Agora” OpenAI is internally testing a new feature called “Agora,” and it could be related to some sort of cross-platform feature that works in real time or some other new product. […] Mayank Parmar Go to bleepingcomputer
-
Google plans to make Chrome for Android an agentic browser with Gemini
Google plans to make Chrome for Android an agentic browser with Gemini Google appears to be testing a new feature that integrates Gemini into Chrome for Android, allowing you to use agentic browser capabilities on your mobile device. […] Mayank Parmar Go to bleepingcomputer
-
Chinese Threat Actors Hosted 18,000 Active C2 Servers Across 48 Hosting Providers
Chinese Threat Actors Hosted 18,000 Active C2 Servers Across 48 Hosting Providers Threat actors linked to Chinese hosting infrastructure have established a massive network of over 18,000 active command-and-control servers across 48 different hosting providers in recent months. This widespread abuse highlights a serious issue in how malicious infrastructure can hide within trusted networks and…
-
Palo Alto Networks Firewall Vulnerability Allows Attacker to Trigger DoS Attacks
Palo Alto Networks Firewall Vulnerability Allows Attacker to Trigger DoS Attacks Palo Alto Networks has patched a critical denial-of-service vulnerability in its PAN-OS firewall software, tracked as CVE-2026-0227, which lets unauthenticated attackers disrupt GlobalProtect gateways and portals. The flaw carries a CVSS v4.0 base score of 7.7 (HIGH severity), stemming from improper checks for unusual conditions…
-
Microsoft SQL Server Vulnerability Allows Attackers to Elevate Privileges over a Network
Microsoft SQL Server Vulnerability Allows Attackers to Elevate Privileges over a Network Microsoft released security updates on January 13, 2026, addressing a critical elevation of privilege vulnerability in SQL Server that enables authorized attackers to bypass authentication controls and gain elevated system privileges remotely. Tracked as CVE-2026-20803, the vulnerability stems from missing authentication mechanisms for…
-
Stealthy CastleLoader Malware Attacking US Government Agencies and Critical Infrastructure
Stealthy CastleLoader Malware Attacking US Government Agencies and Critical Infrastructure A sophisticated malware loader known as CastleLoader has emerged as a critical threat to US government agencies and critical infrastructure organizations. First identified in early 2025, this stealthy malware has been used as the initial access point in coordinated attacks targeting multiple sectors including federal…
-
Researchers Breakdown DragonForce Ransomware Along with Decryptor for ESXi and Windows Systems
Researchers Breakdown DragonForce Ransomware Along with Decryptor for ESXi and Windows Systems DragonForce is the latest ransomware brand to move from noisy forum posts to full RaaS operations, targeting both Windows and VMware ESXi environments. First seen in December 2023 on BreachForums, the group advertises stolen data and uses a dark web blog to pressure…
-
Researchers Null-Route Over 550 Kimwolf and Aisuru Botnet Command Servers
Researchers Null-Route Over 550 Kimwolf and Aisuru Botnet Command Servers The Black Lotus Labs team at Lumen Technologies said it null-routed traffic to more than 550 command-and-control (C2) nodes associated with the AISURU/Kimwolf botnet since early October 2025. AISURU and its Android counterpart, Kimwolf, have emerged as some of the biggest botnets in recent times,…
-
AI Agents Are Becoming Privilege Escalation Paths
AI Agents Are Becoming Privilege Escalation Paths AI agents have quickly moved from experimental tools to core components of daily workflows across security, engineering, IT, and operations. What began as individual productivity aids, like personal code assistants, chatbots, and copilots, has evolved into shared, organization-wide agents embedded in critical processes. These agents can orchestrate workflows…
-
Hackers Exploit c-ares DLL Side-Loading to Bypass Security and Deploy Malware
Hackers Exploit c-ares DLL Side-Loading to Bypass Security and Deploy Malware Security experts have disclosed details of an active malware campaign that’s exploiting a DLL side-loading vulnerability in a legitimate binary associated with the open-source c-ares library to bypass security controls and deliver a wide range of commodity trojans and stealers. “Attackers achieve evasion by…
-
Fortinet Fixes Critical FortiSIEM Flaw Allowing Unauthenticated Remote Code Execution
Fortinet Fixes Critical FortiSIEM Flaw Allowing Unauthenticated Remote Code Execution Fortinet has released updates to fix a critical security flaw impacting FortiSIEM that could allow an unauthenticated attacker to achieve code execution on susceptible instances. The operating system (OS) injection vulnerability, tracked as CVE-2025-64155, is rated 9.4 out of 10.0 on the CVSS scoring system.…
-
New Research: 64% of 3rd-Party Applications Access Sensitive Data Without Justification
New Research: 64% of 3rd-Party Applications Access Sensitive Data Without Justification Research analyzing 4,700 leading websites reveals that 64% of third-party applications now access sensitive data without business justification, up from 51% in 2024. Government sector malicious activity spiked from 2% to 12.9%, while 1 in 7 Education sites show active compromise. Specific offenders: Google…
-
Hacking Wheelchairs over Bluetooth
Hacking Wheelchairs over Bluetooth Researchers have demonstrated remotely controlling a wheelchair over Bluetooth. CISA has issued an advisory. CISA said the WHILL wheelchairs did not enforce authentication for Bluetooth connections, allowing an attacker who is in Bluetooth range of the targeted device to pair with it. The attacker could then control the wheelchair’s movements, override…
-
Upcoming Speaking Engagements
Upcoming Speaking Engagements This is a current list of where and when I am scheduled to speak: I’m speaking at the David R. Cheriton School of Computer Science in Waterloo, Ontario, Canada, on January 27, 2026, at 1:30 PM ET. I’m speaking at the Université de Montréal in Montreal, Quebec, Canada, on January 29, 2026,…
-
ISC Stormcast For Thursday, January 15th, 2026 https://isc.sans.edu/podcastdetail/9768, (Thu, Jan 15th)
ISC Stormcast For Thursday, January 15th, 2026 https://isc.sans.edu/podcastdetail/9768, (Thu, Jan 15th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain, (Wed, Jan 14th)
Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain, (Wed, Jan 14th) Introduction In recent weeks, Lumma Stealer infections have followed a specific pattern in follow-up activity. This pattern adds scheduled tasks for the same action, which increases traffic to the same C2 domain. This diary documents an example from one…
-
Retail, Services Industries Under Fire in Oceania
Retail, Services Industries Under Fire in Oceania Last year in Australia, New Zealand, and the South Pacific, Main Street businesses like retail and construction suffered more cyberattacks than their critical sector counterparts. Nate Nelson, Contributing Writer Go to gbhackers.com
-
Secure Your Spot at RSAC 2026 Conference
Secure Your Spot at RSAC 2026 Conference Go to gbhackers.com
-
‘VoidLink’ Malware Poses Advanced Threat to Linux Systems
‘VoidLink’ Malware Poses Advanced Threat to Linux Systems Researchers discovered a modular, “cloud-first” framework that is feature-rich and designed to maintain stealthy, long-term access to Linux environments. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
LLMs Supercharge Ransomware Speed, Scale, and Global Reach
LLMs Supercharge Ransomware Speed, Scale, and Global Reach Large language models are not fundamentally transforming ransomware operations. However, they are dramatically accelerating the threat landscape through measurable gains in speed, volume, and… Go to gbhackers.com
-
CastleLoader Malware Targets U.S. Government Agencies
CastleLoader Malware Targets U.S. Government Agencies Security researchers are sounding the alarm over CastleLoader, a stealthy first-stage malware loader now implicated in campaigns targeting US-based government entities and multiple high-value… Go to gbhackers.com
-
Google Releases Chrome 144, Fixing 10 V8 Engine Vulnerabilities
Google Releases Chrome 144, Fixing 10 V8 Engine Vulnerabilities Google has launched Chrome 144 for desktop platforms, addressing ten security vulnerabilities including multiple high-severity flaws in the V8 JavaScript engine. The stable channel… Go to gbhackers.com
-
VVS Stealer Targeting Discord Users for Credential Theft
VVS Stealer Targeting Discord Users for Credential Theft Discord users face an emerging threat from VVS stealer. This Python-based malware campaign demonstrates the sophistication malware authors achieve when combining obfuscation frameworks with… Go to gbhackers.com
-
Charity-Themed Malware Used by Threat Actors to Target Ukraine’s Defense Forces
Charity-Themed Malware Used by Threat Actors to Target Ukraine’s Defense Forces Ukrainian cybersecurity authorities have uncovered a sustained, targeted campaign against Ukraine’s defense forces, orchestrated by Russian-affiliated threat actors that disguise malware distribution as charitable… Go to gbhackers.com
-
Microsoft: Windows 365 update blocks access to Cloud PC sessions
Microsoft: Windows 365 update blocks access to Cloud PC sessions Microsoft confirmed that a recent Windows 365 update is blocking customers from accessing their Microsoft 365 Cloud PC sessions. […] Sergiu Gatlan Go to bleepingcomputer
-
Monroe University says 2024 data breach affects 320,000 people
Monroe University says 2024 data breach affects 320,000 people Monroe University revealed that threat actors stole the personal, financial, and health information of over 320,000 people after breaching its systems in a December 2024 cyberattack. […] Sergiu Gatlan Go to bleepingcomputer
-
Ukraine’s army targeted in new charity-themed malware campaign
Ukraine’s army targeted in new charity-themed malware campaign Officials of Ukraine’s Defense Forces were targeted in a charity-themed campaign between October and December 2025 that delivered backdoor malware called PluggyApe. […] Bill Toulas Go to bleepingcomputer
-
New VoidLink malware framework targets Linux cloud servers
New VoidLink malware framework targets Linux cloud servers A newly discovered advanced cloud-native Linux malware framework named VoidLink focuses on cloud environments, providing attackers with custom loaders, implants, rootkits, and plugins designed for modern infrastructures. […] Bill Toulas Go to bleepingcomputer
-
Central Maine Healthcare breach exposed data of over 145,000 people
Central Maine Healthcare breach exposed data of over 145,000 people A data breach last year at Central Maine Healthcare (CMH) exposed sensitive information of more than 145,000 individuals. […] Bill Toulas Go to bleepingcomputer
-
New Magecart Attack Steals Customers Credit Cards from Website Checkout Pages
New Magecart Attack Steals Customers Credit Cards from Website Checkout Pages A sophisticated web-skimming campaign targeting online shoppers has emerged with renewed intensity in 2026, compromising e-commerce websites and extracting sensitive payment information during checkout processes. The attack, identified as part of the broader Magecart family of threats, represents an evolving challenge to online retail…
-
Top 12 Best Open Source Intelligence Tools (OSINT Tools) for Penetration Testing 2026
Top 12 Best Open Source Intelligence Tools (OSINT Tools) for Penetration Testing 2026 We all know very well that getting or gathering any information by using various tools becomes really easy. In this article, we have discussed various OSINT tools, as if we search over the internet, then there will be many different pages to…
-
Top 11 Best DNS Filtering Solutions – 2026
Top 11 Best DNS Filtering Solutions – 2026 Before diving into DNS filtering solutions, it’s essential to understand the concept of DNS filtering and its significance in cybersecurity. In today’s digital landscape, cybersecurity has become a critical priority as cyberattacks are increasingly prevalent worldwide. Organizations must protect not only their infrastructure but also their employees…
-
10 Most Dangerous Injection Attacks in 2026
10 Most Dangerous Injection Attacks in 2026 Since you are in the industry, especially in the network and admin team, you need to know a few vulnerabilities, such as injection attacks to stay alert from them. Each attack or vulnerability has a different method, most importantly injection-type attacks. To understand that and to take a…
-
5 Best Bug Bounty Platforms for White-Hat Hackers – 2026
5 Best Bug Bounty Platforms for White-Hat Hackers – 2026 Bug bounty platforms form a cornerstone of modern cybersecurity, empowering organizations to crowdsource vulnerability discovery from skilled external researchers. These programs reward private individuals for uncovering flaws in web apps, vulnerability management systems, and more through effective crowdsourced testing. White-hat hackers can flex their expertise…
-
Your personal information is on the dark web. What happens next?
Your personal information is on the dark web. What happens next? If your data is on the dark web, it’s probably only a matter of time before it’s abused for fraud or account hijacking. Here’s what to do. Go to eset
-
PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces
PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of new cyber attacks targeting its defense forces with malware known as PLUGGYAPE between October and December 2025. The activity has been attributed with medium confidence to a Russian hacking group tracked as…
-
Long-Running Web Skimming Campaign Steals Credit Cards From Online Checkout Pages
Long-Running Web Skimming Campaign Steals Credit Cards From Online Checkout Pages Cybersecurity researchers have discovered a major web skimming campaign that has been active since January 2022, targeting several major payment networks like American Express, Diners Club, Discover, JCB Co., Ltd., Mastercard, and UnionPay. “Enterprise organizations that are clients of these payment providers are the…
-
Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool
Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool Cybersecurity researchers have disclosed details of a malicious Google Chrome extension that’s capable of stealing API keys associated with MEXC, a centralized cryptocurrency exchange (CEX) available in over 170 countries, while masquerading as a tool to automate trading on the platform. The extension,…
-
[Webinar] Securing Agentic AI: From MCPs and Tool Access to Shadow API Key Sprawl
[Webinar] Securing Agentic AI: From MCPs and Tool Access to Shadow API Key Sprawl AI agents are no longer just writing code. They are executing it. Tools like Copilot, Claude Code, and Codex can now build, test, and deploy software end-to-end in minutes. That speed is reshaping engineering—but it’s also creating a security gap most…
-
New Advanced Linux VoidLink Malware Targets Cloud and container Environments
New Advanced Linux VoidLink Malware Targets Cloud and container Environments Cybersecurity researchers have disclosed details of a previously undocumented and feature-rich malware framework codenamed VoidLink that’s specifically designed for long-term, stealthy access to Linux-based cloud environments According to a new report from Check Point Research, the cloud-native Linux malware framework comprises an array of custom…
-
1980s Hacker Manifesto
1980s Hacker Manifesto Forty years ago, The Mentor—Loyd Blankenship—published “The Conscience of a Hacker” in Phrack. You bet your ass we’re all alike… we’ve been spoon-fed baby food at school when we hungered for steak… the bits of meat that you did let slip through were pre-chewed and tasteless. We’ve been dominated by sadists, or…
-
ISC Stormcast For Wednesday, January 14th, 2026 https://isc.sans.edu/podcastdetail/9766, (Wed, Jan 14th)
ISC Stormcast For Wednesday, January 14th, 2026 https://isc.sans.edu/podcastdetail/9766, (Wed, Jan 14th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
January 2026 Microsoft Patch Tuesday Summary, (Tue, Jan 13th)
January 2026 Microsoft Patch Tuesday Summary, (Tue, Jan 13th) Today, Microsoft released patches for 113 vulnerabilities. One of these vulnerabilities affected the Edge browser and was patched upstream by Chromium. Eight of the vulnerabilities are rated critical. One has been disclosed before today, and one is already being exploited. Five of the critical vulnerabilities affect…
-
Taiwan Endures Greater Cyber Pressure From China
Taiwan Endures Greater Cyber Pressure From China Chinese cyberattacks on Taiwan’s critical infrastructure — including energy utilities and hospitals — rose 6% in 2025, averaging 2.63 million attacks a day. Robert Lemos, Contributing Writer Go to gbhackers.com
-
The AI Fix #83: ChatGPT Health, Victorian LLMs, and the biggest AI bluffers
The AI Fix #83: ChatGPT Health, Victorian LLMs, and the biggest AI bluffers In episode 83 of The AI Fix, Graham reveals he’s taken up lying to LLMs, and shows how a journalist exposed AI bluffers with a made-up idiom. Meanwhile Mark invents a “Godwin’s Law” for AI, and explains how to ruin any LLM…
-
Hackers get hacked, as BreachForums database is leaked
Hackers get hacked, as BreachForums database is leaked Have you ever stolen data, traded a hacking tool, or just lurked on a dark web forum believing that you are anonymous? If so, I might have some unsettling news for you. Read more in my article on the Hot for Security blog. Graham Cluley Go to…
-
CISO Succession Crisis Highlights How Turnover Amplifies Security Risks
CISO Succession Crisis Highlights How Turnover Amplifies Security Risks When cybersecurity leadership turns over too fast, risk does not reset. It compounds. Joan Goodchild Go to gbhackers.com
-
Who Decides Who Doesn’t Deserve Privacy?
Who Decides Who Doesn’t Deserve Privacy? Remember the Ashley Madison data breach? That was now more than a decade ago, yet it arguably remains the single most noteworthy data breach of all time. There are many reasons for this accolade, but chief among them is that by virtue of the site being expressly designed to…
-
‘Most Severe AI Vulnerability to Date’ Hits ServiceNow
‘Most Severe AI Vulnerability to Date’ Hits ServiceNow ServiceNow tacked agentic AI onto a largely unguarded legacy chatbot, exposing customers’ data and connected systems. Nate Nelson, Contributing Writer Go to gbhackers.com
-
Shadow#Reactor Uses Text Files to Deliver Remcos RAT
Shadow#Reactor Uses Text Files to Deliver Remcos RAT Attackers use a sophisticated delivery mechanism of text-only files for RAT deployment, showcasing a clever way to bypass defensive tools and rely on the target’s own utilities. Alexander Culafi Go to gbhackers.com