no alarms and no surprises please..
-
ISC Stormcast For Friday, January 9th, 2026 https://isc.sans.edu/podcastdetail/9760, (Fri, Jan 9th)
ISC Stormcast For Friday, January 9th, 2026 https://isc.sans.edu/podcastdetail/9760, (Fri, Jan 9th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
ISC Stormcast For Thursday, January 8th, 2026 https://isc.sans.edu/podcastdetail/9758, (Thu, Jan 8th)
ISC Stormcast For Thursday, January 8th, 2026 https://isc.sans.edu/podcastdetail/9758, (Thu, Jan 8th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Analysis using Gephi with DShield Sensor Data, (Wed, Jan 7th)
Analysis using Gephi with DShield Sensor Data, (Wed, Jan 7th) I’m always looking for new ways of manipulating the data captured by my DShield sensor [1]. This time I used Gephi [2] and Graphiz [3] a popular and powerful tool for visualizing and exploring relationships between nodes, to examine the relationship between the source IP,…
-
A phishing campaign with QR codes rendered using an HTML table, (Wed, Jan 7th)
A phishing campaign with QR codes rendered using an HTML table, (Wed, Jan 7th) Malicious use of QR codes has long been ubiquitous, both in the real world as well as in electronic communication. This is hardly surprising given that a scan of a QR code can lead one to a phishing page as easily…
-
Maximum Severity HPE OneView Flaw Exploited in the Wild
Maximum Severity HPE OneView Flaw Exploited in the Wild Exploitation of CVE-2025-37164 can enable remote code execution on HPE’s IT infrastructure management platform, leading to devastating consequences. Rob Wright Go to gbhackers.com
-
Fake AI Chrome Extensions Steal 900K Users’ Data
Fake AI Chrome Extensions Steal 900K Users’ Data Threat actors ripped off a legitimate AI-powered Chrome extension in order to harvest ChatGPT and DeepSeek data before sending it to a C2 server. Alexander Culafi Go to gbhackers.com
-
ChatGPT’s Memory Feature Supercharges Prompt Injection
ChatGPT’s Memory Feature Supercharges Prompt Injection The “ZombieAgent” exploit makes use of ChatGPT’s long-term memory and advanced capabilities. Nate Nelson, Contributing Writer Go to gbhackers.com
-
Here’s What Cloud Security’s Future Holds for the Year Ahead
Here’s What Cloud Security’s Future Holds for the Year Ahead Here are the top cloud security trends I’m seeing in my crystal ball for the New Year — particularly arming us for AI adoption. Melinda Marks Go to gbhackers.com
-
GitLab Patches Multiple Flaws Allowing Arbitrary Code Execution
GitLab Patches Multiple Flaws Allowing Arbitrary Code Execution Linux administrators are being urged to update promptly after disclosures of multiple vulnerabilities in GitLab, including flaws that could enable cross-site scripting, authorization bypass, and… Go to gbhackers.com
-
BlueDelta Hackers Target Microsoft OWA, Google, and Sophos VPN to Steal Credentials
BlueDelta Hackers Target Microsoft OWA, Google, and Sophos VPN to Steal Credentials A sophisticated credential-harvesting operation conducted by BlueDelta, a Russian state-sponsored threat group linked to the GRU’s Main Directorate, targeted critical infrastructure organizations and research… Go to gbhackers.com
-
Three Malicious NPM Packages Target Developers’ Login Credentials
Three Malicious NPM Packages Target Developers’ Login Credentials Security researchers at Zscaler ThreatLabz have uncovered three malicious npm packages designed to install a sophisticated remote access trojan (RAT) targeting JavaScript developers. The… Go to gbhackers.com
-
Linux Battery Utility Vulnerability Allows Authentication Bypass and System Tampering
Linux Battery Utility Vulnerability Allows Authentication Bypass and System Tampering Linux laptop users are being urged to update after a flaw in a popular battery optimisation tool was found to allow authentication bypass and system tampering. The… Go to gbhackers.com
-
ownCloud Warns Users to Enable MFA After Credential Theft Incident
ownCloud Warns Users to Enable MFA After Credential Theft Incident ownCloud has issued an urgent security advisory urging users to enable Multi-Factor Authentication (MFA) following a credential theft incident reported by threat intelligence firm… Go to gbhackers.com
-
Cisco warns of Identity Service Engine flaw with exploit code
Cisco warns of Identity Service Engine flaw with exploit code Cisco has patched an ISE vulnerability with public proof-of-concept exploit code that can be abused by attackers with admin privileges. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA tags max severity HPE OneView flaw as actively exploited
CISA tags max severity HPE OneView flaw as actively exploited The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged a maximum-severity HPE OneView vulnerability as actively exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
OpenAI says ChatGPT won’t use your health information to train its models
OpenAI says ChatGPT won’t use your health information to train its models OpenAI is rolling out ChatGPT Health, which is a dedicated space for health conversations. Amidst privacy concerns, OpenAI said it won’t use your health data. […] Mayank Parmar Go to bleepingcomputer
-
New GoBruteforcer attack wave targets crypto, blockchain projects
New GoBruteforcer attack wave targets crypto, blockchain projects A new wave of GoBruteforcer botnet malware attacks is targeting databases of cryptocurrency and blockchain projects on exposed servers believed to be configured using AI-generated examples. […] Bill Toulas Go to bleepingcomputer
-
Critical jsPDF flaw lets hackers steal secrets via generated PDFs
Critical jsPDF flaw lets hackers steal secrets via generated PDFs The jsPDF library for generating PDF documents in JavaScript applications is vulnerable to a critical vulnerability that allows an attacker to steal sensitive data from the local filesystem by including it in generated files. […] Bill Toulas Go to bleepingcomputer
-
GitLab Patches Multiple Vulnerabilities that Enables Arbitrary Code Execution
GitLab Patches Multiple Vulnerabilities that Enables Arbitrary Code Execution GitLab has released emergency security patches for multiple versions of its platform, addressing eight vulnerabilities that could enable arbitrary code execution and unauthorized access in self-managed installations. The updated versions 18.7.1, 18.6.3, and 18.5.5 were deployed to GitLab.com on January 7, 2026, with self-hosted customers strongly…
-
Linux Battery Utility Flaw Lets Hackers Bypass Authentication and Tamper System Settings
Linux Battery Utility Flaw Lets Hackers Bypass Authentication and Tamper System Settings A critical security vulnerability has been discovered in TLP, a widely used Linux laptop battery optimization utility, allowing local attackers to bypass authentication controls and manipulate system power settings without authorization. Security researchers from openSUSE identified a severe authentication bypass flaw in the…
-
China Hacked Email Systems Used by US Congressional Staff, New Report
China Hacked Email Systems Used by US Congressional Staff, New Report A sophisticated Chinese hacking group has breached email systems accessed by staffers on critical U.S. House committees, exposing sensitive communications amid escalating cyber tensions between Washington and Beijing. The Financial Times revealed on Wednesday that the intruders, tracked as Salt Typhoon, targeted aides supporting…
-
Top 50 Best Penetration Testing Companies in 2026
Top 50 Best Penetration Testing Companies in 2026 Penetration testing companies serve as vital cybersecurity allies, simulating real-world cyberattacks to expose vulnerabilities in systems, networks, and applications before malicious actors strike. Employing ethical hackers with advanced techniques, they rigorously assess defenses, pinpoint misconfigurations, and evaluate control effectiveness to ensure regulatory compliance and threat resilience. Their…
-
10 Best Web Scanners for Website Security In 2026
10 Best Web Scanners for Website Security In 2026 Securing websites demands top-tier web vulnerability scanners. These powerful tools pinpoint critical flaws like SQL injection, cross-site scripting (XSS), and command injection, keeping your site fortified against attacks. Elite scanners emulate attacker strategies, delivering concrete proof and precise fix instructions. They adeptly navigate contemporary web apps…
-
CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited
CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws impacting Microsoft Office and Hewlett Packard Enterprise (HPE) OneView to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below – CVE-2009-0556 (CVSS score:…
-
Webinar: Learn How AI-Powered Zero Trust Detects Attacks with No Files or Indicators
Webinar: Learn How AI-Powered Zero Trust Detects Attacks with No Files or Indicators Security teams are still catching malware. The problem is what they’re not catching. More attacks today don’t arrive as files. They don’t drop binaries. They don’t trigger classic alerts. Instead, they run quietly through tools that already exist inside the environment —…
-
Black Cat Behind SEO Poisoning Malware Campaign Targeting Popular Software Searches
Black Cat Behind SEO Poisoning Malware Campaign Targeting Popular Software Searches A cybercrime gang known as Black Cat has been attributed to a search engine optimization (SEO) poisoning campaign that employs fraudulent sites advertising popular software to trick users into downloading a backdoor capable of stealing sensitive data. According to a report published by the…
-
Critical n8n Vulnerability (CVSS 10.0) Allows Unauthenticated Attackers to Take Full Control
Critical n8n Vulnerability (CVSS 10.0) Allows Unauthenticated Attackers to Take Full Control Cybersecurity researchers have disclosed details of yet another maximum-severity security flaw in n8n, a popular workflow automation platform, that allows an unauthenticated remote attacker to gain complete control over susceptible instances. The vulnerability, tracked as CVE-2026-21858 (CVSS score: 10.0), has been codenamed Ni8mare…
-
n8n Warns of CVSS 10.0 RCE Vulnerability Affecting Self-Hosted and Cloud Versions
n8n Warns of CVSS 10.0 RCE Vulnerability Affecting Self-Hosted and Cloud Versions Open-source workflow automation platform n8n has warned of a maximum-severity security flaw that, if successfully exploited, could result in authenticated remote code execution (RCE). The vulnerability, which has been assigned the CVE identifier CVE-2026-21877, is rated 10.0 on the CVSS scoring system. “Under…
-
The Wegman’s Supermarket Chain Is Probably Using Facial Recognition
The Wegman’s Supermarket Chain Is Probably Using Facial Recognition The New York City Wegman’s is collecting biometric information about customers. Bruce Schneier Go to bruce schneier
-
Smashing Security podcast #449: How to scam someone in seven days
Smashing Security podcast #449: How to scam someone in seven days Romance scammers have apparently discovered astrology… and Taurus is their secret weapon. In episode 449 of “Smashing Security”, we take a look inside an actual romance-fraud handbook – complete with scripts, personality “types”, corporate jargon, and a seven-day plan to get victims from hello…
-
Weekly Update 485
Weekly Update 485 15 mins and 40 seconds. That’s how long it took to troubleshoot the first tech problem of 2026, and that’s how far you’ll need to skip through this video to hear the audio at normal volume. The problem Scott and I had is analogous to the troubleshooting so many of us do…
-
Attackers Exploit Zero-Day in End-of-Life D-Link Routers
Attackers Exploit Zero-Day in End-of-Life D-Link Routers Hackers are attacking a critical zero-day flaw in unsupported D-Link DSL routers to run arbitrary commands. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
Phishers Exploit Office 365 Users Who Let Their Guard Down
Phishers Exploit Office 365 Users Who Let Their Guard Down Microsoft said that Office 365 tenants with weak configurations and who don’t have strict anti-spoofing protection enabled are especially vulnerable. Alexander Culafi Go to gbhackers.com
-
Lack of MFA is Common Thread in Vast Cloud Credential Heist
Lack of MFA is Common Thread in Vast Cloud Credential Heist An emerging threat actor that goes by “Zestix” used an assortment of infostealers to obtain credentials and breach file-sharing instances of approximately 50 enterprises. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
DDoSia Powers Affiliate-Driven Hacktivist Attacks
DDoSia Powers Affiliate-Driven Hacktivist Attacks Pro-Russian group NoName057(16) uses a custom denial-of-service tool to mobilize volunteers and disrupt government, media, and institutional sites tied to Ukraine and the West. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
Cyberattacks Likely Part of Military Operation in Venezuela
Cyberattacks Likely Part of Military Operation in Venezuela Cyber’s role in the US raid on Venezuela remains a question, though President Trump alluded to “certain expertise” in shutting down the power grid in Caracas. Robert Lemos, Contributing Writer Go to gbhackers.com
-
Veeam Backup Vulnerability Exposes Systems to Root-Level Remote Code Execution
Veeam Backup Vulnerability Exposes Systems to Root-Level Remote Code Execution Veeam has released a critical security update for its Backup & Replication software to address multiple high-severity vulnerabilities. The most concerning of these flaws could allow attackers… Go to gbhackers.com
-
Black Cat Hacker Group Uses Fake Notepad++ Websites to Distribute Malware and Steal Data
Black Cat Hacker Group Uses Fake Notepad++ Websites to Distribute Malware and Steal Data A sophisticated cyberattack campaign orchestrated by the notorious “Black Cat” criminal gang has been uncovered by CNCERT and Microstep Online, revealing a coordinated effort… Go to gbhackers.com
-
Google Warns of High-Risk WebView Vulnerability That Breaks Security Controls
Google Warns of High-Risk WebView Vulnerability That Breaks Security Controls Google released Chrome versions 143.0.7499.192/.193 on January 6, 2026, to patch a high-severity vulnerability in WebView that could allow attackers to bypass important security… Go to gbhackers.com
-
Court Demands OpenAI Hand Over 20M Anonymized ChatGPT Chats in AI Copyright Dispute
Court Demands OpenAI Hand Over 20M Anonymized ChatGPT Chats in AI Copyright Dispute A federal judge has ordered OpenAI to turn over 20 million anonymized ChatGPT conversation logs in a major copyright lawsuit, rejecting the company’s arguments… Go to gbhackers.com
-
Hackers Create Fake DocuSign Login Page to Steal User Credentials
Hackers Create Fake DocuSign Login Page to Steal User Credentials Phishing attacks continue to dominate the cybercrime landscape as threat actors refine their social engineering tactics to evade detection systems. The FBI’s Internet Crime… Go to gbhackers.com
-
OpenAI is rolling out GPT-5.2 “Codex-Max” for some users
OpenAI is rolling out GPT-5.2 “Codex-Max” for some users OpenAI is testing a new model for Codex called “GPT-5.2-Codex-Max,” and it’s already rolling out to users with a subscription. […] Mayank Parmar Go to bleepingcomputer
-
Taiwan says China’s attacks on its energy sector increased tenfold
Taiwan says China’s attacks on its energy sector increased tenfold The National Security Bureau in Taiwan says that China’s attacks on the country’s energy sector increased tenfold in 2025 compared to the previous year. […] Bill Toulas Go to bleepingcomputer
-
Microsoft cancels plans to rate limit Exchange Online bulk emails
Microsoft cancels plans to rate limit Exchange Online bulk emails Microsoft announced today that it has canceled plans to impose a daily limit of 2,000 external recipients on Exchange Online bulk email senders. […] Sergiu Gatlan Go to bleepingcomputer
-
New D-Link flaw in legacy DSL routers actively exploited in attacks
New D-Link flaw in legacy DSL routers actively exploited in attacks Threat actors are exploiting a recently discovered command injection vulnerability that affects multiple D-Link DSL gateway routers that went out of support years ago. […] Bill Toulas Go to bleepingcomputer
-
Kimwolf Android botnet abuses residential proxies to infect internal devices
Kimwolf Android botnet abuses residential proxies to infect internal devices The Kimwolf botnet, an Android variant of the Aisuru malware, has grown to more than two million hosts, most of them infected by exploiting vulnerabilities in residential proxy networks to target devices on internal networks. […] Bill Toulas Go to bleepingcomputer
-
Crimson Collective Claims to have Disconnected Many Brightspeed Home Internet Users
Crimson Collective Claims to have Disconnected Many Brightspeed Home Internet Users Crimson Collective, an emerging extortion group, claims to have breached U.S. fiber broadband provider Brightspeed, stealing data on over 1 million residential customers and disconnecting many from home internet service. The group posted screenshots on Telegram detailing the alleged compromise and urging Brightspeed employees…
-
Top 10 Best Dynamic Malware Analysis Tools in 2026
Top 10 Best Dynamic Malware Analysis Tools in 2026 Dynamic malware analysis tools execute suspicious binaries in isolated sandboxes to capture runtime behaviors file modifications, network traffic, registry changes, and persistence mechanisms. This top 10 list details each tool’s features, strengths, and limitations to guide your selection. ANY.RUN’s Interactive Sandbox leads with real-time analysis mapped…
-
Forcepoint DLP Vulnerability Enables Memory Manipulation and Arbitrary Code Execution
Forcepoint DLP Vulnerability Enables Memory Manipulation and Arbitrary Code Execution A critical security flaw in Forcepoint One DLP Client has been disclosed, allowing attackers to bypass vendor-implemented Python restrictions and execute arbitrary code on enterprise endpoints. The vulnerability, tracked as CVE-2025-14026, undermines the data loss prevention security controls designed to protect sensitive organizational data. The…
-
10 Best Vulnerability Assessment and Penetration Testing (VAPT) Tools in 2026
10 Best Vulnerability Assessment and Penetration Testing (VAPT) Tools in 2026 Vulnerability Assessment and Penetration Testing (VAPT) tools form the cornerstone of any cybersecurity toolkit, enabling organizations to identify, analyze, and remediate vulnerabilities across systems, networks, applications, and IT infrastructure. These tools empower proactive security by exposing weaknesses and attack vectors before threat actors can…
-
Top 10 Best Open Source Firewall in 2026
Top 10 Best Open Source Firewall in 2026 An open-source firewall provides network security by monitoring and controlling traffic based on predefined rules, offering transparency, flexibility, and cost savings through accessible source code that users can modify to suit specific needs. These firewalls function through essential mechanisms like traffic monitoring to analyze incoming and outgoing…
-
Ongoing Attacks Exploiting Critical RCE Vulnerability in Legacy D-Link DSL Routers
Ongoing Attacks Exploiting Critical RCE Vulnerability in Legacy D-Link DSL Routers A newly discovered critical security flaw in legacy D-Link DSL gateway routers has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0625 (CVSS score: 9.3), concerns a case of command injection in the “dnscfg.cgi” endpoint that arises as a result of…
-
Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users
Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users Cybersecurity researchers have discovered two new malicious extensions on the Chrome Web Store that are designed to exfiltrate OpenAI ChatGPT and DeepSeek conversations alongside browsing data to servers under the attackers’ control. The names of the extensions, which collectively have over 900,000 users,…
-
Unpatched Firmware Flaw Exposes TOTOLINK EX200 to Full Remote Device Takeover
Unpatched Firmware Flaw Exposes TOTOLINK EX200 to Full Remote Device Takeover The CERT Coordination Center (CERT/CC) has disclosed details of an unpatched security flaw impacting TOTOLINK EX200 wireless range extender that could allow a remote authenticated attacker to gain full control of the device. The flaw, CVE-2025-65606 (CVSS score: N/A), has been characterized as a…
-
Fake Booking Emails Redirect Hotel Staff to Fake BSoD Pages Delivering DCRat
Fake Booking Emails Redirect Hotel Staff to Fake BSoD Pages Delivering DCRat Source: Securonix Cybersecurity researchers have disclosed details of a new campaign dubbed PHALT#BLYX that has leveraged ClickFix-style lures to display fixes for fake blue screen of death (BSoD) errors in attacks targeting the European hospitality sector. The end goal of the multi-stage campaign…
-
What is Identity Dark Matter?
What is Identity Dark Matter? The Invisible Half of the Identity Universe Identity used to live in one place – an LDAP directory, an HR system, a single IAM portal. Not anymore. Today, identity is fragmented across SaaS, on-prem, IaaS, PaaS, home-grown, and shadow applications. Each of these environments carries its own accounts, permissions, and…
-
A Cyberattack Was Part of the US Assault on Venezuela
A Cyberattack Was Part of the US Assault on Venezuela We don’t have many details: President Donald Trump suggested Saturday that the U.S. used cyberattacks or other technical capabilities to cut power off in Caracas during strikes on the Venezuelan capital that led to the capture of Venezuelan President Nicolás Maduro. If true, it would…
-
ISC Stormcast For Wednesday, January 7th, 2026 https://isc.sans.edu/podcastdetail/9756, (Wed, Jan 7th)
ISC Stormcast For Wednesday, January 7th, 2026 https://isc.sans.edu/podcastdetail/9756, (Wed, Jan 7th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Tool Review: Tailsnitch, (Tue, Jan 6th)
Tool Review: Tailsnitch, (Tue, Jan 6th) In yesterday’s podcast, I mentioned “tailsnitch”, a new tool to audit Tailscale configurations. Tailscale is an easy-to-use overlay to Wireguard. It is probably best compared to STUN servers in VoIP in that it allows devices behind NAT to connect directly to each other. Tailscale just helps negotiate the setup,…
-
Coinbase insider who sold customer data to criminals arrested in India
Coinbase insider who sold customer data to criminals arrested in India Police in India have arrested a former Coinbase customer service agent who is believed to have been bribed by cybercriminal gangs to access sensitive customer information. Read more in my article on the Hot for Security blog. Graham Cluley Go to grahamcluley
-
168: LoD
168: LoD The Legion of Doom (LoD) wasn’t just a “hacker group”, it captured the essence of underground hacking in the 80s/90s. BBSes, phreaking, rival crews, and the crackdowns that changed everything. From those humble beginnings came a legacy that still echoes through modern security culture today. Sponsors Support for this show comes from ThreatLocker®.…
-
Scattered Lapsus$ Hunters Snared in Cyber Researcher Honeypot
Scattered Lapsus$ Hunters Snared in Cyber Researcher Honeypot Scattered Lapsus$ Hunters, also known as ShinyHunters, were drawn in using a realistic, yet mostly fake, dataset. Alexander Culafi Go to gbhackers.com
-
ClickFix Campaign Serves Up Fake Blue Screen of Death
ClickFix Campaign Serves Up Fake Blue Screen of Death Threat actors are using the social engineering technique and a legitimate Microsoft tool to deploy the DCRat remote access Trojan against targets in the hospitality sector. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
Startup Trends Shaking Up Browsers, SOC Automation, AppSec
Startup Trends Shaking Up Browsers, SOC Automation, AppSec In 2025, these startups have reimagined browser security, pioneered application security for AI-generated code, and are building consensus on agentic vs. human costs. Paul Shomo Go to gbhackers.com
-
Hackers Steal $35M in Cryptocurrency Following LastPass Breach
Hackers Steal $35M in Cryptocurrency Following LastPass Breach Russian cybercriminals have laundered over $35 million in stolen cryptocurrency linked to the devastating 2022 LastPass breach, according to new forensic analysis by blockchain… Go to gbhackers.com
-
Attackers Leverage FortiWeb Vulnerabilities to Deploy Sliver C2 for Long-Term Access
Attackers Leverage FortiWeb Vulnerabilities to Deploy Sliver C2 for Long-Term Access Threat researchers have uncovered a sophisticated attack campaign targeting FortiWeb web application firewalls across multiple continents, with adversaries deploying the Sliver command-and-control framework to… Go to gbhackers.com
-
Kimwolf Botnet Exploits 2 Million Devices to Build a Global Proxy Infrastructure
Kimwolf Botnet Exploits 2 Million Devices to Build a Global Proxy Infrastructure A massive new botnet dubbed “Kimwolf” has infected over 2 million devices globally, transforming innocent users’ home internet connections into secret proxy nodes for… Go to gbhackers.com
-
ProfileHound: Post-Escalation Tool Designed to Achieve Red Team Objectives
ProfileHound: Post-Escalation Tool Designed to Achieve Red Team Objectives ProfileHound emerges as a specialized post-exploitation instrument for offensive security professionals seeking to identify high-value targets within Active Directory environments. The tool addresses a… Go to gbhackers.com
-
GHOSTCREW: AI-Powered Red Team Toolkit Integrating Metasploit, Nmap, and More
GHOSTCREW: AI-Powered Red Team Toolkit Integrating Metasploit, Nmap, and More A new open-source tool is bridging the gap between artificial intelligence and offensive security operations. GHOSTCREW is an advanced AI red team assistant that leverages Large… Go to gbhackers.com
-
Cloud file-sharing sites targeted for corporate data theft attacks
Cloud file-sharing sites targeted for corporate data theft attacks A threat actor known as Zestix has been offering to corporate data stolen from dozens of companies likely after breaching their ShareFile, Nextcloud, and OwnCloud instances. […] Bill Toulas Go to bleepingcomputer
-
ClickFix attack uses fake Windows BSOD screens to push malware
ClickFix attack uses fake Windows BSOD screens to push malware A new ClickFix social engineering campaign is targeting the hospitality sector in Europe, using fake Windows Blue Screen of Death (BSOD) screens to trick users into manually compiling and executing malware on their systems. […] Bill Toulas Go to bleepingcomputer
-
US broadband provider Brightspeed investigates breach claims
US broadband provider Brightspeed investigates breach claims Brightspeed, one of the largest fiber broadband companies in the United States, is investigating security breach and data theft claims made by the Crimson Collective extortion gang. […] Sergiu Gatlan Go to bleepingcomputer
-
VSCode IDE forks expose users to “recommended extension” attacks
VSCode IDE forks expose users to “recommended extension” attacks Popular AI-powered integrated development environment solutions, such as Cursor, Windsurf, Google Antigravity, and Trae, recommend extensions that are non-existent in the OpenVSX registry, allowing threat actors to claim the namespace and upload malicious extensions. […] Bill Toulas Go to bleepingcomputer
-
Ledger customers impacted by third-party Global-e data breach
Ledger customers impacted by third-party Global-e data breach Ledger is informing some customers that their personal data has been exposed after hackers breached the systems of third-party payment processor Global-e. […] Bill Toulas Go to bleepingcomputer
-
New ClickFix Attack Uses Fake Windows BSOD Screens to Trick Users into Executing Malicious Code
New ClickFix Attack Uses Fake Windows BSOD Screens to Trick Users into Executing Malicious Code A sophisticated malware campaign called PHALTBLYX has emerged, combining social engineering deception with advanced evasion techniques to compromise hospitality sector organizations. The attack chain begins with phishing emails impersonating Booking.com, featuring urgent reservation cancellation alerts with large financial charges displayed…
-
New Sophisticated Phishing Attack Mimic as Google Support to Steal Logins
New Sophisticated Phishing Attack Mimic as Google Support to Steal Logins Cybersecurity researchers have uncovered a dangerous new phishing campaign that tricks users into surrendering their credentials by impersonating legitimate Google support and notifications. The attack combines vishing (voice phishing), spoofed domains, and Google’s own trusted infrastructure to achieve exceptional success rates against organizations worldwide.…
-
Threat Actors Allegedly Promoting New ‘Brutus’ Brute-Force Tool Targeting Fortinet Services
Threat Actors Allegedly Promoting New ‘Brutus’ Brute-Force Tool Targeting Fortinet Services A threat actor operating under the moniker “RedTeam” has begun advertising a new brute-force attack tool, “Brutus,” designed to target Fortinet services, according to recent dark web intelligence. The tool is priced at $1,500, signaling growing interest in automated credential-stuffing attacks against enterprise infrastructure.…
-
Top 20 Best Endpoint Management Tools – 2026
Top 20 Best Endpoint Management Tools – 2026 Endpoint management has become essential for modern IT, securing and optimizing devices across hybrid and remote environments. With distributed workforces expanding, demand for robust endpoint management tools reaches new heights in 2026. This guide ranks the top 20 endpoint management tools for 2026, detailing specs, standout features,…
-
Threat Actors Hacked Global Companies via Leaked Cloud Credentials from Infostealer Infections
Threat Actors Hacked Global Companies via Leaked Cloud Credentials from Infostealer Infections Dozens of major global enterprises have been breached through a surprisingly simple yet devastating attack vector: stolen credentials extracted from infostealer malware. A threat actor operating under the nickname “Zestix” and his alias “Sentap” has been systematically accessing corporate cloud storage platforms, including…
-
New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commands
New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commands A new critical security vulnerability has been disclosed in n8n, an open-source workflow automation platform, that could enable an authenticated attacker to execute arbitrary system commands on the underlying host. The vulnerability, tracked as CVE-2025-68668, is rated 9.9 on the CVSS scoring system. It…
-
Critical AdonisJS Bodyparser Flaw (CVSS 9.2) Enables Arbitrary File Write on Servers
Critical AdonisJS Bodyparser Flaw (CVSS 9.2) Enables Arbitrary File Write on Servers Users of the “@adonisjs/bodyparser” npm package are being advised to update to the latest version following the disclosure of a critical security vulnerability that, if successfully exploited, could allow a remote attacker to write arbitrary files on the server. Tracked as CVE-2026-21440 (CVSS…
-
Russia-Aligned Hackers Abuse Viber to Target Ukrainian Military and Government
Russia-Aligned Hackers Abuse Viber to Target Ukrainian Military and Government The Russia-aligned threat actor known as UAC-0184 has been observed targeting Ukrainian military and government entities by leveraging the Viber messaging platform to deliver malicious ZIP archives. “This organization has continued to conduct high-intensity intelligence gathering activities against Ukrainian military and government departments in 2025,”…
-
Kimwolf Android Botnet Infects Over 2 Million Devices via Exposed ADB and Proxy Networks
Kimwolf Android Botnet Infects Over 2 Million Devices via Exposed ADB and Proxy Networks The botnet known as Kimwolf has infected more than 2 million Android devices by tunneling through residential proxy networks, according to findings from Synthient. “Key actors involved in the Kimwolf botnet are observed monetizing the botnet through app installs, selling residential…
-
⚡ Weekly Recap: IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & More
⚡ Weekly Recap: IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & More The year opened without a reset. The same pressure carried over, and in some places it tightened. Systems people assume are boring or stable are showing up in the wrong places. Attacks moved quietly, reused familiar paths, and kept working longer than…
-
Telegram Hosting World’s Largest Darknet Market
Telegram Hosting World’s Largest Darknet Market Wired is reporting on Chinese darknet markets on Telegram. The ecosystem of marketplaces for Chinese-speaking crypto scammers hosted on the messaging service Telegram have now grown to be bigger than ever before, according to a new analysis from the crypto tracing firm Elliptic. Despite a brief drop after Telegram…
-
ISC Stormcast For Tuesday, January 6th, 2026 https://isc.sans.edu/podcastdetail/9754, (Tue, Jan 6th)
ISC Stormcast For Tuesday, January 6th, 2026 https://isc.sans.edu/podcastdetail/9754, (Tue, Jan 6th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Risks of OOB Access via IP KVM Devices, (Mon, Jan 5th)
Risks of OOB Access via IP KVM Devices, (Mon, Jan 5th) Recently, a new “breed” of IP-based KVM devices has been released. In the past, IP-based KVM devices required dedicated “server-grade” hardware using IPMI. They often cost several $100 per server, and are only available for specific systems that support the respective add-on cards. These…
-
Critical ‘MongoBleed’ Bug Under Active Attack, Patch Now
Critical ‘MongoBleed’ Bug Under Active Attack, Patch Now A memory leak security vulnerability allows unauthenticated attackers to extract passwords and tokens from MongoDB servers. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
US Cyber Pros Plead Guilty Over BlackCat Ransomware Activity
US Cyber Pros Plead Guilty Over BlackCat Ransomware Activity Two US citizens pleaded guilty to working as ALPHV/BlackCat ransomware affiliates in 2023, and both were previously employed by prominent security firms. Alexander Culafi Go to gbhackers.com
-
RondoDox Botnet Expands Scope With React2Shell Exploitation
RondoDox Botnet Expands Scope With React2Shell Exploitation Recent attacks are targeting Next.js servers and pose a significant threat of cryptomining, botnet payloads, and other malicious activity to IoT networks and enterprises. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
Eaton Vulnerabilities Let Attackers Execute Arbitrary Code On the Host System
Eaton Vulnerabilities Let Attackers Execute Arbitrary Code On the Host System A critical security advisory addressing multiple vulnerabilities discovered in the Eaton UPS Companion (EUC) software. These security flaws, if exploited, could allow attackers to execute arbitrary code on the host system, potentially giving them complete control over affected devices. The advisory, identified as ETN-VA-2025-1026, highlights…
-
Threat Actor Allegedly Claim Leak of NordVPN Salesforce Database with Source Codes
Threat Actor Allegedly Claim Leak of NordVPN Salesforce Database with Source Codes A threat actor operating under the identifier 1011 has publicly claimed to have obtained and leaked sensitive data from NordVPN’s development infrastructure on a dark web forum. The breach reportedly exposes over ten database source codes, along with critical authentication credentials that could…
-
GHOSTCREW – AI-based Red Team Toolkit for Penetration Testing Invoking Metasploit, Nmap and Other Tools
GHOSTCREW – AI-based Red Team Toolkit for Penetration Testing Invoking Metasploit, Nmap and Other Tools GHOSTCREW emerges as a game-changing open-source toolkit for red teamers and penetration testers. This AI-powered assistant leverages large language models, integrates the MCP protocol, and supports the optional RAG architecture to orchestrate security tools via natural-language prompts. Developed by GH05TCREW,…
-
Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data
Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data QNAP has patched multiple security vulnerabilities in its License Center application that could allow attackers to access sensitive information or disrupt services on affected NAS devices. The issues, tracked as CVE-2025-52871 and CVE-2025-53597, were disclosed on January 3, 2026. QNAP rated the flaws as Moderate severity and confirmed that the issues have been resolved in the latest…
-
Hackers Trapped in Resecurity’s Honeypot During Targeted Attack on Employee Network
Hackers Trapped in Resecurity’s Honeypot During Targeted Attack on Employee Network Resecurity deploys synthetic data honeypots to outsmart threat actors, turning reconnaissance into actionable intelligence. A recent operation not only trapped an Egyptian-linked hacker but also duped the ShinyHunters group into false breach claims. Resecurity has refined deception technologies for counterintelligence, mimicking enterprise environments to…
-
ISC Stormcast For Monday, January 5th, 2026 https://isc.sans.edu/podcastdetail/9752, (Mon, Jan 5th)
ISC Stormcast For Monday, January 5th, 2026 https://isc.sans.edu/podcastdetail/9752, (Mon, Jan 5th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Cryptocurrency Scam Emails and Web Pages As We Enter 2026, (Sun, Jan 4th)
Cryptocurrency Scam Emails and Web Pages As We Enter 2026, (Sun, Jan 4th) Introduction In October 2025, a work colleague documented a cryptocurrency scam using a fake chatbot. After investigating this, I was able to receive messages from the campaign, and these emails have continued to land in my honeypot account since then. This diary documents…
-
Finnish Authorities Arrest Two Sailors in Probe Into Undersea Cable Disruption
Finnish Authorities Arrest Two Sailors in Probe Into Undersea Cable Disruption Finnish authorities have detained a cargo vessel suspected of damaging an undersea telecommunications cable connecting Helsinki to Estonia. The incident has raised fresh concerns… Go to gbhackers.com
-
Hackers claim to hack Resecurity, firm says it was a honeypot
Hackers claim to hack Resecurity, firm says it was a honeypot The ShinyHunters hacking group claims it breached the systems of cybersecurity firm Resecurity and stole internal data, while Resecurity says the attackers only accessed a deliberately deployed honeypot containing fake information used to monitor their activity. […] Lawrence Abrams Go to bleepingcomputer