Tag: gbhackers
-
JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data
JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution
Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution Threat actors are actively exploiting CVE-2026-6875, a critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform. This vulnerability allows attackers to escape… Delivered by PolitePaul service Go to gbhackers.com
-
Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials
Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials Iran-linked APT42 is escalating its espionage operations with AI-assisted phishing and an expanded TAMECAT backdoor, enabling long-lived access to defense and government identities rather… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell
Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell An ongoing exploitation of two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) devices. These vulnerabilities allowed a threat actor, identified as UTA0533, to… Delivered by PolitePaul service Go to gbhackers.com
-
AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows
AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows AsyncAPI’s npm ecosystem suffered a coordinated supply chain compromise on July 14, 2026, delivering a Miasma‑associated Node.js backdoor through trusted GitHub Actions–driven release workflows… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier
Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier Microsoft will stop delivering feature updates, bug fixes, and security patches for the OneDrive sync app on systems running Windows version 21H2 and earlier… Delivered by PolitePaul service Go to gbhackers.com
-
U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million
U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million U.S. federal prosecutors have unsealed a sweeping indictment charging three Russian nationals and two St. Petersburg–based companies for operating a global “bulletproof hosting” infrastructure. That… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Releases Emergency Windows 11 Update to Fix Intel IPF Driver Performance Issues
Microsoft Releases Emergency Windows 11 Update to Fix Intel IPF Driver Performance Issues Microsoft has released KB5121767, an out-of-band (OOB) cumulative update for Windows 11 versions 22H2 and 21H2. This update addresses a system performance issue related… Delivered by PolitePaul service Go to gbhackers.com
-
LG Monitors Silently Install McAfee Adware on Windows PCs With Full System Access
LG Monitors Silently Install McAfee Adware on Windows PCs With Full System Access Concerns have arisen regarding LG monitors that reportedly trigger the silent installation of an LG companion application on Windows PCs. This installation is followed by… Delivered by PolitePaul service Go to gbhackers.com
-
One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor
One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor A newly disclosed cluster of Microsoft SharePoint Server vulnerabilities is actively being exploited in the wild, allowing attackers to convert a single crafted web… Delivered by PolitePaul service Go to gbhackers.com
-
Citrix Secure Access Client Flaw Lets Low-Privileged Windows Users Gain SYSTEM Privileges
Citrix Secure Access Client Flaw Lets Low-Privileged Windows Users Gain SYSTEM Privileges Cloud Software Group has issued a High-severity security bulletin (CTX696734) disclosing two vulnerabilities in the Citrix Secure Access Client for Windows and the Citrix… Delivered by PolitePaul service Go to gbhackers.com
-
OpenSSL DoS Vulnerability Lets Remote Attackers Exhaust Server Memory With an 11-Byte Payload
OpenSSL DoS Vulnerability Lets Remote Attackers Exhaust Server Memory With an 11-Byte Payload A newly disclosed vulnerability reminds us how deeply our digital infrastructure relies on foundational libraries. The Okta Red Team recently discovered “HollowByte,” a Denial… Delivered by PolitePaul service Go to gbhackers.com
-
EY Data Breach – Hackers Access Third-Party IT Support Platform and Steal Client Tax Documents
EY Data Breach – Hackers Access Third-Party IT Support Platform and Steal Client Tax Documents Ernst & Young LLP (EY) has confirmed a data security incident in which an unauthorized third party breached a third-party IT service management platform… Delivered by PolitePaul service Go to gbhackers.com
-
Critical WordPress Core Flaw Lets Anonymous Hackers Gain Remote Code Execution
Critical WordPress Core Flaw Lets Anonymous Hackers Gain Remote Code Execution A newly disclosed a pre-authentication remote code execution (RCE) vulnerability in WordPress Core, dubbed “wp2shell,” that requires no authentication and affects stock WordPress installations… Delivered by PolitePaul service Go to gbhackers.com
-
New Starland RAT Steals Browser Credentials and Scans for Over 40 Crypto Wallets
New Starland RAT Steals Browser Credentials and Scans for Over 40 Crypto Wallets A financially motivated, Russian-speaking threat actor tracked as UAT-11795, orchestrating a large-scale campaign since at least June 2025. A sophisticated Python-based remote access trojan dubbed… Delivered by PolitePaul service Go to gbhackers.com
-
CISA Warns of Two Fortinet FortiSandbox Flaws Exploited to Execute Commands
CISA Warns of Two Fortinet FortiSandbox Flaws Exploited to Execute Commands The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities in Fortinet FortiSandbox to its Known Exploited Vulnerabilities (KEV) catalog. These… Delivered by PolitePaul service Go to gbhackers.com
-
TP-Link Kasa Camera Flaws Let Attackers Steal Admin Credentials and Geolocation Data
TP-Link Kasa Camera Flaws Let Attackers Steal Admin Credentials and Geolocation Data TP-Link has revealed several serious vulnerabilities affecting its Kasa EC70 and EC71 smart camera models, which could expose users to credential theft and geolocation… Delivered by PolitePaul service Go to gbhackers.com
-
New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure
New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure NadMesh is a new, industrial‑grade Go‑based botnet that weaponizes more than 20 RCE vectors to hijack AI and MCP infrastructure at scale, combining autonomous… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Use Paste-and-Run Commands to Deploy ClickLock Stealer Against Mac Users
Hackers Use Paste-and-Run Commands to Deploy ClickLock Stealer Against Mac Users Hackers are actively targeting macOS users with a newly identified infostealer dubbed “ClickLock Stealer,” leveraging paste-and-run social engineering techniques to bypass Apple’s native security… Delivered by PolitePaul service Go to gbhackers.com
-
GPT-5.6 Codex Reportedly Wipes Files From Home Directories
GPT-5.6 Codex Reportedly Wipes Files From Home Directories Recent reports indicate that GPT-5.6 Codex has unintentionally deleted files in users’ home directories under certain configurations, raising concerns about the risks of running… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft
Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft A macOS-focused information stealer is combining stolen wallet databases with credentials harvested from the Apple Keychain, browsers, and Apple Notes to conduct offline cryptocurrency… Delivered by PolitePaul service Go to gbhackers.com
-
CISA Warns of Actively Exploited Oracle E-Business Suite Flaw
CISA Warns of Actively Exploited Oracle E-Business Suite Flaw The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that attackers are actively exploiting CVE-2026-46817, an improper privilege management vulnerability in Oracle E-Business… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Zoom Workplace Flaw Lets Unauthenticated Attackers Take Over Accounts Remotely
Critical Zoom Workplace Flaw Lets Unauthenticated Attackers Take Over Accounts Remotely Zoom has disclosed a critical vulnerability in its Windows desktop software that could allow unauthenticated attackers to take over user accounts remotely. This issue,… Delivered by PolitePaul service Go to gbhackers.com
-
Dutch Police and Europol Disrupt Global Investment Scam Infrastructure and Arrest Key Suspects
Dutch Police and Europol Disrupt Global Investment Scam Infrastructure and Arrest Key Suspects Dutch police, working with international law-enforcement partners including Europol, have disrupted a sprawling investment-fraud operation alleged to have defrauded victims across multiple countries of… Delivered by PolitePaul service Go to gbhackers.com
-
Splunk Enterprise Flaws Expose Stored Credentials and Allow Arbitrary SPL Searches
Splunk Enterprise Flaws Expose Stored Credentials and Allow Arbitrary SPL Searches Splunk has released security updates for three vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. These vulnerabilities could potentially expose stored credential hashes, enable… Delivered by PolitePaul service Go to gbhackers.com
-
Dell Warns of Critical PowerProtect Data Domain Flaws Allowing Remote Attackers to Take Complete…
Dell Warns of Critical PowerProtect Data Domain Flaws Allowing Remote Attackers to Take Complete… Dell has recently disclosed two critical vulnerabilities in PowerProtect Data Domain appliances that could allow unauthenticated remote attackers to gain complete control of affected… Delivered by PolitePaul service Go to gbhackers.com
-
FaceTime Scammers Combine Credential Theft, Remote-Access Apps, and iOS Exploits for Device Takeover.
FaceTime Scammers Combine Credential Theft, Remote-Access Apps, and iOS Exploits for Device Takeover. Apple-focused scam operations are increasingly using FaceTime as a high-trust social-engineering channel to steal credentials and, in higher-risk cases, prepare victims for device compromise…. Delivered by PolitePaul service Go to gbhackers.com
-
SheetAgent RAT Runs 14 Virtual Machine Checks and Self-Deletes When Analysis Is Detected
SheetAgent RAT Runs 14 Virtual Machine Checks and Self-Deletes When Analysis Is Detected A threat campaign targeting Indian government job seekers is using a recruitment notice for Senior Field Officer positions in the Cabinet Secretariat as a… Delivered by PolitePaul service Go to gbhackers.com
-
11 Malicious NuGet Game Cheat Packages Deploy Pepesoft Windows Surveillance Malware
11 Malicious NuGet Game Cheat Packages Deploy Pepesoft Windows Surveillance Malware 11 malicious NuGet packages masquerading as game cheats, automation bots, and management “panels” that deploy a Windows payload called pepesoft.exe. The packages were published… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Fixes Multiple Windows RDP Flaws Exposing Sensitive Data Over the Network
Microsoft Fixes Multiple Windows RDP Flaws Exposing Sensitive Data Over the Network Microsoft has addressed multiple information-disclosure vulnerabilities in the Windows Remote Desktop Protocol (RDP). This widely used service enables remote administration and access to Windows… Delivered by PolitePaul service Go to gbhackers.com
-
WinFsp Race Condition Flaw Allows Attackers to Gain SYSTEM-Level Access on Windows
WinFsp Race Condition Flaw Allows Attackers to Gain SYSTEM-Level Access on Windows A newly disclosed vulnerability in the Windows File System Proxy (WinFsp) could allow a local attacker to gain SYSTEM-level privileges by exploiting a race… Delivered by PolitePaul service Go to gbhackers.com
-
SAP July 2026 Patch Day Fixes Critical NetWeaver, Approuter, and Commerce Cloud Vulnerabilities
SAP July 2026 Patch Day Fixes Critical NetWeaver, Approuter, and Commerce Cloud Vulnerabilities SAP’s July 2026 Security Patch Day addresses multiple high-impact vulnerabilities across its enterprise products, including a severe memory corruption issue in the SAP NetWeaver… Delivered by PolitePaul service Go to gbhackers.com
-
Pro-Iran Hacktivist Groups Launch DDoS and Hack-and-Leak Attacks Against Critical Infrastructure
Pro-Iran Hacktivist Groups Launch DDoS and Hack-and-Leak Attacks Against Critical Infrastructure A decentralized network of pro-Iran hacktivist groups is intensifying cyber operations against critical infrastructure, government entities, technology providers, and organizations perceived as aligned with… Delivered by PolitePaul service Go to gbhackers.com
-
ShinyHunters Hackers Abuse Salesforce OAuth to Bypass MFA and Exfiltrate CRM Data
ShinyHunters Hackers Abuse Salesforce OAuth to Bypass MFA and Exfiltrate CRM Data A series of high-impact campaigns linked by overlapping tradecraft to ShinyHunters, in which attackers abused trusted Salesforce OAuth relationships to bypass conventional MFA protections,… Delivered by PolitePaul service Go to gbhackers.com
-
ModHeader Chrome Extension Exposes 900,000 Users to Potential Browsing History Theft
ModHeader Chrome Extension Exposes 900,000 Users to Potential Browsing History Theft ModHeader version 7.0.187.0.187.0.18, a popular Chrome extension used for modifying HTTP headers, contained dormant code capable of collecting and exfiltrating browsing history data from… Delivered by PolitePaul service Go to gbhackers.com
-
Critical WordPress OAuth SSO Plugin Flaw Allows Unauthenticated Attackers to Gain Admin Access
Critical WordPress OAuth SSO Plugin Flaw Allows Unauthenticated Attackers to Gain Admin Access A critical authentication bypass vulnerability has been disclosed in the widely used miniOrange OAuth Single Sign-On (SSO) WordPress plugin, carrying a near-maximum CVSS score… Delivered by PolitePaul service Go to gbhackers.com
-
Spear-Phishing Campaign Uses Proton Drive Links and LNK Files to Deliver SpyGlace
Spear-Phishing Campaign Uses Proton Drive Links and LNK Files to Deliver SpyGlace The APT-C-60 threat actor has continued targeting Japanese organizations with a spear-phishing campaign that abuses Proton Drive, Windows shortcut files, trusted developer platforms, and… Delivered by PolitePaul service Go to gbhackers.com
-
CISA Warns of Actively Exploited iCagenda and Balbooa Forms File Upload Flaws
CISA Warns of Actively Exploited iCagenda and Balbooa Forms File Upload Flaws The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two file-upload vulnerabilities, affecting iCagenda and Balbooa Forms, to its Known Exploited Vulnerabilities (KEV)… Delivered by PolitePaul service Go to gbhackers.com
-
BusySnake Stealer Uses Reverse SSH Tunnels and AI-Generated Loaders to Evade Detection
BusySnake Stealer Uses Reverse SSH Tunnels and AI-Generated Loaders to Evade Detection Armored Likho, a previously undocumented threat group also tracked as Eagle Werewolf based on circumstantial evidence, is targeting government institutions and electric-power organizations across… Delivered by PolitePaul service Go to gbhackers.com
-
Debian 13.6 Released With Security Updates for Linux, Apache, Curl, QEMU, and More
Debian 13.6 Released With Security Updates for Linux, Apache, Curl, QEMU, and More The Debian Project has released Debian 13.6, the sixth point update for its stable Debian 13 “trixie” distribution. This update, released on July 11,… Delivered by PolitePaul service Go to gbhackers.com
-
AWS GovCloud Credential Leak Leads CISA to Share Critical Cyber Incident Lessons
AWS GovCloud Credential Leak Leads CISA to Share Critical Cyber Incident Lessons The Cybersecurity and Infrastructure Security Agency (CISA) has disclosed details of an internal security incident involving exposed AWS GovCloud credentials, offering a transparent account… Delivered by PolitePaul service Go to gbhackers.com
-
Top 10 Best Cloud Security Providers – 2026 Review
Top 10 Best Cloud Security Providers – 2026 Review As businesses continue to migrate critical applications and data to the cloud, the traditional security perimeter has dissolved. The responsibility for securing these dynamic,… Delivered by PolitePaul service Go to gbhackers.com
-
Dell BIOS Flaw Lets Attackers Extract Plaintext Passwords Without Brute Force
Dell BIOS Flaw Lets Attackers Extract Plaintext Passwords Without Brute Force A newly disclosed Dell BIOS password-storage flaw can allow attackers with physical access to recover administrator and user passwords from SPI flash dumps in… Delivered by PolitePaul service Go to gbhackers.com
-
Zimbra Releases Security Patch for Stored XSS Vulnerability in Classic Web Client
Zimbra Releases Security Patch for Stored XSS Vulnerability in Classic Web Client Zimbra has released its Daffodil v10.1.19 patch update, addressing a stored cross-site scripting (XSS) vulnerability in the platform’s Classic Web Client. The security issue… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Infect C++ and C# Project Files to Spread Multi-Stage Windows Backdoor
Hackers Infect C++ and C# Project Files to Spread Multi-Stage Windows Backdoor A sophisticated Windows Trojan that compromises software development projects to distribute a multi-stage backdoor, data stealer, clipboard hijacker, cryptominer, and file infector. Documented by Doctor… Delivered by PolitePaul service Go to gbhackers.com
-
New Multi-Stage LNK Attack Targets Hospitality Firms With Node.js Backdoor
New Multi-Stage LNK Attack Targets Hospitality Firms With Node.js Backdoor Hospitality firms are being targeted in an active phishing campaign that uses fake booking-related emails to deliver a multi-stage Node.js backdoor. The attack chain abuses… Delivered by PolitePaul service Go to gbhackers.com
-
Wireshark 4.6.7 Released to Patch 12 Vulnerabilities in SSH, TLS, Wi-Fi and pcapng
Wireshark 4.6.7 Released to Patch 12 Vulnerabilities in SSH, TLS, Wi-Fi and pcapng Wireshark has released version 4.6.74.6.74.6.7, addressing 121212 security flaws across protocol dissectors, capture-file parsers, and its external capture interface. The update resolves issues affecting… Delivered by PolitePaul service Go to gbhackers.com
-
Odyssey Stealer Attacks Macs Worldwide and Replaces Crypto Wallet Apps With Drainers
Odyssey Stealer Attacks Macs Worldwide and Replaces Crypto Wallet Apps With Drainers Odyssey Stealer is driving a large-scale macOS infostealer campaign that now spans more than 100 countries, with operators systematically hijacking cryptocurrency ecosystems by replacing… Delivered by PolitePaul service Go to gbhackers.com
-
Process Parameter Poisoning Technique Hides Shellcode Inside Windows Startup Data
Process Parameter Poisoning Technique Hides Shellcode Inside Windows Startup Data A newly documented Windows injection approach, dubbed Process Parameter Poisoning or P³, uses process startup parameters as an unconventional staging area for shellcode. Implemented… Delivered by PolitePaul service Go to gbhackers.com
-
NetScaler MCP Gateway Secures LLM and Agentic AI Traffic From a Single Platform
NetScaler MCP Gateway Secures LLM and Agentic AI Traffic From a Single Platform Citrix, a Cloud Software Group company, announced major updates to its NetScaler® platform on July 9, 2026, introducing MCP Gateway functionality designed to secure… Delivered by PolitePaul service Go to gbhackers.com
-
Foxit Patches Multiple Use-After-Free Flaws Leading to Remote Code Execution
Foxit Patches Multiple Use-After-Free Flaws Leading to Remote Code Execution Foxit has released critical security updates to address multiple use-after-free vulnerabilities that could lead to remote code execution (RCE) in its widely used PDF… Delivered by PolitePaul service Go to gbhackers.com
-
GhostApproval Attack Impacts Amazon Q, Claude Code, Cursor, Google Antigravity, and Windsurf
GhostApproval Attack Impacts Amazon Q, Claude Code, Cursor, Google Antigravity, and Windsurf A newly disclosed vulnerability pattern known as “GhostApproval” is exposing significant flaws in the trust boundary of leading AI coding assistants, including Amazon Q… Delivered by PolitePaul service Go to gbhackers.com
-
RedHook Abuses Accessibility Service to Enable Developer Options and Wireless Debugging
RedHook Abuses Accessibility Service to Enable Developer Options and Wireless Debugging RedHook, an Android Remote Access Trojan (RAT) first profiled in July 2025, has resurfaced with a markedly more dangerous capability: autonomous abuse of Android’s… Delivered by PolitePaul service Go to gbhackers.com
-
Nike Alleged Breach: Threat Actors Claim Leak of Millions of Customer Records
Nike Alleged Breach: Threat Actors Claim Leak of Millions of Customer Records A threat actor on a prominent cybercrime forum has claimed responsibility for leaking data allegedly belonging to Nike and Alcon, posting the purported datasets… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Entra Passkey Enrollment Abused in Operator-Controlled Vishing Campaign
Microsoft Entra Passkey Enrollment Abused in Operator-Controlled Vishing Campaign A focused vishing campaign that weaponizes Microsoft Entra passkey enrollment as a social-engineering vector to enable account takeover and downstream data extortion. The threat… Delivered by PolitePaul service Go to gbhackers.com
-
US Cyber Agency Uses Anthropic Mythos to Audit Government Code for Bugs
US Cyber Agency Uses Anthropic Mythos to Audit Government Code for Bugs The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has started using Anthropic’s advanced AI model, Mythos, to audit government software for vulnerabilities. This marks… Delivered by PolitePaul service Go to gbhackers.com
-
Windows 11 26H2 Enables Backup Policy to Restore User Apps and Settings
Windows 11 26H2 Enables Backup Policy to Restore User Apps and Settings Microsoft has confirmed a significant policy change in the upcoming Windows 11 version 26H2. This update introduces a new default behavior for Windows settings… Delivered by PolitePaul service Go to gbhackers.com
-
Thousands of MCP Servers Found Vulnerable to File Access and Injection Attacks
Thousands of MCP Servers Found Vulnerable to File Access and Injection Attacks Thousands of Model Context Protocol (MCP) servers, widely used to connect large language models (LLMs) to external systems, have been found vulnerable to critical… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Introduces Execution Containers to Secure AI Agents on Windows
Microsoft Introduces Execution Containers to Secure AI Agents on Windows Microsoft has introduced a new security architecture to safeguard autonomous AI agents on Windows, unveiling the Microsoft Execution Containers (MXC) SDK at Build 2026…. Delivered by PolitePaul service Go to gbhackers.com
-
Kazuar Backdoor Uses DLL Side-Loading and PowerShell Loaders for Stealthy Execution
Kazuar Backdoor Uses DLL Side-Loading and PowerShell Loaders for Stealthy Execution Turla’s Kazuar backdoor has re-emerged as a technically sophisticated persistence and reconnaissance tool that combines DLL side-loading with PowerShell-based loaders to achieve stealthy execution… Delivered by PolitePaul service Go to gbhackers.com
-
FIFA World Cup Phishing Scam Uses Fake Reward Pages to Steal Credit Card Data
FIFA World Cup Phishing Scam Uses Fake Reward Pages to Steal Credit Card Data A sophisticated email phishing campaign exploiting the global excitement around the 2026 FIFA World Cup is deceiving fans with counterfeit reward pages designed to… Delivered by PolitePaul service Go to gbhackers.com
-
SilverFox Campaign Turns ValleyRAT Into Multi-Stage Malware With Rootkit Capabilities
SilverFox Campaign Turns ValleyRAT Into Multi-Stage Malware With Rootkit Capabilities The SilverFox advanced persistent threat (APT) group has escalated its offensive toolkit by transforming ValleyRAT from a conventional remote access trojan into an eight-stage… Delivered by PolitePaul service Go to gbhackers.com
-
PHP TLS Flaw Lets Remote Server Trigger DoS and Crash Entire FPM Process
PHP TLS Flaw Lets Remote Server Trigger DoS and Crash Entire FPM Process A newly disclosed high-severity vulnerability in PHP, tracked as CVE-2026-12184, poses a significant risk to web applications by allowing a remotely triggerable denial-of-service (DoS)… Delivered by PolitePaul service Go to gbhackers.com
-
IBM WebSphere Application Server Hit by Critical XSS and Path Traversal Vulnerabilities
IBM WebSphere Application Server Hit by Critical XSS and Path Traversal Vulnerabilities IBM has disclosed several security vulnerabilities in its WebSphere Application Server that put enterprise environments at risk of cross-site scripting (XSS) and path-traversal attacks…. Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Warns Windows 11 Enterprise Devices May Boot to Black Screen After Updates
Microsoft Warns Windows 11 Enterprise Devices May Boot to Black Screen After Updates Microsoft has issued a warning to enterprise administrators about a critical issue affecting Windows 11 systems. This problem may cause devices to boot to… Delivered by PolitePaul service Go to gbhackers.com
-
Parrot 7.3 released With new menu system and smoother day-to-day use
Parrot 7.3 released With new menu system and smoother day-to-day use Parrot 7.3 arrives focused on refinement rather than a tool glut, rebuilding all editions to deliver perceptible gains on modern hardware and a smoother… Delivered by PolitePaul service Go to gbhackers.com
-
Verified X Sponsored Ad Spreads Mac Malware While ConsentFix Hijacks Microsoft 365 Accounts
Verified X Sponsored Ad Spreads Mac Malware While ConsentFix Hijacks Microsoft 365 Accounts A Mac-targeting ClickFix campaign amplified through a verified X sponsored ad, and a novel browser-based hijack technique called ConsentFix that exfiltrates Microsoft 365 session… Delivered by PolitePaul service Go to gbhackers.com
-
TimbreStealer Malware Targets Mexico Companies With Advanced Evasion Techniques
TimbreStealer Malware Targets Mexico Companies With Advanced Evasion Techniques A new campaign linked to the TimbreStealer information stealer that specifically targets Mexican companies, employing layered evasion and sophisticated runtime tricks to frustrate detection… Delivered by PolitePaul service Go to gbhackers.com
-
Avalon Malware Uses Legal Document Lure to Deliver CrownX Ransomware Capabilities
Avalon Malware Uses Legal Document Lure to Deliver CrownX Ransomware Capabilities A previously undocumented malware framework, tracked as Avalon, that uses a spoofed legal-document lure and a multi-stage, fileless-oriented chain to deliver a ransomware component… Delivered by PolitePaul service Go to gbhackers.com
-
Armored Likho APT Deploys BusySnake Stealer Against Government and Power Sector Targets
Armored Likho APT Deploys BusySnake Stealer Against Government and Power Sector Targets A focused phishing campaign operated by a previously unreported APT we’ve named Armored Likho (also tracked under the provisional alias Eagle Werewolf). The group… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Use Fake API Documentation to Trick AI Agents Into Sending Crypto Payments
Hackers Use Fake API Documentation to Trick AI Agents Into Sending Crypto Payments Hackers are now weaponizing documentation and site metadata to mislead autonomous AI agents into executing cryptocurrency payments. The attack leverages indirect prompt injection (IPI): malicious… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Exchange SSRF Vulnerability Lets Low-Privileged Attackers Read Arbitrary Files
Microsoft Exchange SSRF Vulnerability Lets Low-Privileged Attackers Read Arbitrary Files A newly disclosed vulnerability in Microsoft Exchange, identified as CVE-2026-45504 (CVSS score: 8.8), exposes a critical server-side request forgery (SSRF) flaw. This issue allows… Delivered by PolitePaul service Go to gbhackers.com
-
Fake Google and Cloudflare Verification Pages Spread StealC, HijackLoader, and NetSupport Malware
Fake Google and Cloudflare Verification Pages Spread StealC, HijackLoader, and NetSupport Malware Threat actors are currently exploiting sophisticated ClickFix social engineering campaigns that mimic Google and Cloudflare verification systems to distribute several high-impact malware families, including… Delivered by PolitePaul service Go to gbhackers.com
-
Alibaba Reportedly Bans Claude Code Over Alleged Backdoor Risk in AI Coding Tool
Alibaba Reportedly Bans Claude Code Over Alleged Backdoor Risk in AI Coding Tool Alibaba is reportedly preparing to ban the use of Anthropic’s Claude Code across its internal environments starting July 10. This decision comes in light… Delivered by PolitePaul service Go to gbhackers.com
-
Anthropic Unveils Cyber Jailbreak Severity Framework for Claude Fable 5 Safeguards
Anthropic Unveils Cyber Jailbreak Severity Framework for Claude Fable 5 Safeguards Anthropic has provided detailed technical insights into the cybersecurity safeguards of its redeployed Claude Fable 5 model. Alongside this, they have introduced a proposed… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Use Geofenced Webpages to Deliver Ousaban Banking Trojan in Spain and Portugal
Hackers Use Geofenced Webpages to Deliver Ousaban Banking Trojan in Spain and Portugal A targeted phishing campaign delivering the Ousaban banking Trojan to users in Spain and Portugal, notable for its use of geofenced webpages, layered evasion… Delivered by PolitePaul service Go to gbhackers.com
-
JADEPUFFER Agentic Ransomware Uses LLM to Automate Database Extortion
JADEPUFFER Agentic Ransomware Uses LLM to Automate Database Extortion The first instance of agentic ransomware: JADEPUFFER, an LLM-driven extortion operation that automated an end-to-end database-crippling campaign. The actor gained execution on an internet-facing… Delivered by PolitePaul service Go to gbhackers.com
-
Apple Hide My Email Vulnerability Lets Attackers Reveal Users’ Real Email Addresses
Apple Hide My Email Vulnerability Lets Attackers Reveal Users’ Real Email Addresses Apple’s Hide My Email privacy feature currently faces a significant flaw that may expose users’ real email addresses, compromising one of iCloud+’s core anonymity… Delivered by PolitePaul service Go to gbhackers.com
-
ValleyRAT Uses RC4 Encryption, Donut Shellcode, and rundll32 Injection for Stealth
ValleyRAT Uses RC4 Encryption, Donut Shellcode, and rundll32 Injection for Stealth A recent surge in ValleyRAT activity that combines RC4-encrypted payloads, Donut-generated shellcode, and in-memory execution via suspended rundll32 processes to evade detection. First named… Delivered by PolitePaul service Go to gbhackers.com
-
JetBrains Patches Critical Hub Authentication Bypass and Account Takeover Vulnerabilities
JetBrains Patches Critical Hub Authentication Bypass and Account Takeover Vulnerabilities JetBrains has released patches for several critical vulnerabilities in JetBrains Hub that could allow for full authentication bypass, account takeover, and unauthorized privilege escalation… Delivered by PolitePaul service Go to gbhackers.com
-
RedLine Infostealer Thread Reveals Hidden Maritime Phishing and BEC Infrastructure
RedLine Infostealer Thread Reveals Hidden Maritime Phishing and BEC Infrastructure A routine threat-feed alert for a RedLine Stealer command-and-control (C2) IP morphed into a full-scale pivot investigation that exposed a tailored maritime spear‑phishing and… Delivered by PolitePaul service Go to gbhackers.com
-
The Gentlemen Ransomware Targets Large Corporations and Critical Infrastructure Worldwide
The Gentlemen Ransomware Targets Large Corporations and Critical Infrastructure Worldwide The Gentlemen ransomware group has emerged in 2026 as a highly adaptive and technically sophisticated ransomware-as-a-service (RaaS) operation targeting large corporations and critical infrastructure… Delivered by PolitePaul service Go to gbhackers.com
-
Fluentd Security Flaws Enable Remote Code Execution, SSRF, DoS, and Credential Exposure
Fluentd Security Flaws Enable Remote Code Execution, SSRF, DoS, and Credential Exposure Fluentd, a widely used open-source data collector for unified logging, has reported several high-impact vulnerabilities that could enable attackers to achieve remote code execution… Delivered by PolitePaul service Go to gbhackers.com
-
Glitch SPY RAT Abuses Android Accessibility Service for Full Device Control
Glitch SPY RAT Abuses Android Accessibility Service for Full Device Control An emerging Android remote-access trojan platform, tracked as Glitch SPY, that leverages a fraudulent Polish apartment-rental website to trick victims into sideloading a malicious… Delivered by PolitePaul service Go to gbhackers.com
-
New RustDuck Botnet Targets IoT Devices and Servers With Weak Passwords and RCE Exploits
New RustDuck Botnet Targets IoT Devices and Servers With Weak Passwords and RCE Exploits A sophisticated new botnet family dubbed RustDuck emerged in early 2026, leveraging a two-stage Loader and Core architecture to compromise IoT devices, routers, and… Delivered by PolitePaul service Go to gbhackers.com
-
Japan Hotel Industry Targeted With TONResolver RAT and Guest Complaint Phishing Emails
Japan Hotel Industry Targeted With TONResolver RAT and Guest Complaint Phishing Emails Japan’s hotel sector is the latest target of a sophisticated phishing and remote-access trojan (RAT) campaign that leverages guest-complaint lures and an unusual resilience… Delivered by PolitePaul service Go to gbhackers.com
-
Boss Scam Uses DLL Sideloading to Hijack WhatsApp Web and Defraud Enterprises
Boss Scam Uses DLL Sideloading to Hijack WhatsApp Web and Defraud Enterprises The new “Boss Scam” is a sharp escalation in CEO fraud: attackers now combine impersonation, Windows DLL sideloading, and WhatsApp Web session theft to… Delivered by PolitePaul service Go to gbhackers.com
-
Kali Linux 2026.2 Release With new Hacking Tool and With Updated Desktop Environments
Kali Linux 2026.2 Release With new Hacking Tool and With Updated Desktop Environments Kali Linux 2026.2 arrives on schedule in the final week of Q2 with a pragmatic blend of desktop environment refreshes, infrastructure hardening, and practical… Delivered by PolitePaul service Go to gbhackers.com
-
Malicious Chromium Extension Spoofs Perplexity AI to Hijack Browser Searches
Malicious Chromium Extension Spoofs Perplexity AI to Hijack Browser Searches A malicious Chromium extension that impersonated the Perplexity AI brand to intercept browser searches and capture keystrokes before delivering users to legitimate search results…. Delivered by PolitePaul service Go to gbhackers.com
-
Mustang Panda Targets India’s Government and Energy Sectors With ZOHOMURK and MINIRECON
Mustang Panda Targets India’s Government and Energy Sectors With ZOHOMURK and MINIRECON Two concurrent espionage campaigns by Mustang Panda targeting Indian government and energy-sector organisations, deploying a novel malware suite that includes SHARDLOADER, MINIRECON and ZOHOMURK…. Delivered by PolitePaul service Go to gbhackers.com
-
New Windows Injection Technique Hijacks Win32k Callback Dispatch to Execute Shellcode
New Windows Injection Technique Hijacks Win32k Callback Dispatch to Execute Shellcode A newly documented injection technique abuses the kernel-to-user callback dispatch path used by the Windows graphical subsystem (win32k.sys) to achieve remote code execution while… Delivered by PolitePaul service Go to gbhackers.com
-
Langflow RCE Vulnerability Exploited to Deploy Monero Cryptominer on Exposed AI Servers
Langflow RCE Vulnerability Exploited to Deploy Monero Cryptominer on Exposed AI Servers Threat actors are actively exploiting CVE-2026-33017, a critical unauthenticated remote code execution (RCE) vulnerability in Langflow, to compromise internet-exposed AI application servers and silently… Delivered by PolitePaul service Go to gbhackers.com
-
ClawHavoc Attack Hits ClawHub With 1,184 Malicious Skills and 247,000 Installations
ClawHavoc Attack Hits ClawHub With 1,184 Malicious Skills and 247,000 Installations The AI-agent ecosystem experienced its largest supply-chain compromise to date when ClawHavoc detonated across ClawHub, the official skill marketplace for OpenClaw. Our full AIG-powered… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Hoppscotch Vulnerability Lets Attackers Overwrite JWT_SECRET and Forge Admin Tokens
Critical Hoppscotch Vulnerability Lets Attackers Overwrite JWT_SECRET and Forge Admin Tokens A critical security vulnerability, identified as CVE-2026-50160, has been discovered in the self-hosted Hoppscotch backend. This vulnerability allows unauthenticated attackers to overwrite sensitive configuration… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Dell Wyse Management Suite Vulnerabilities Let Attackers Execute Remote Code
Critical Dell Wyse Management Suite Vulnerabilities Let Attackers Execute Remote Code Dell Technologies has disclosed several critical vulnerabilities in its Wyse Management Suite (WMS) that could enable remote attackers to execute arbitrary code and fully… Delivered by PolitePaul service Go to gbhackers.com
-
Claude Mythos 5 Redeployed to Help U.S. Organizations Strengthen Cyber Defense
Claude Mythos 5 Redeployed to Help U.S. Organizations Strengthen Cyber Defense Anthropic has officially restored access to its Claude Mythos 5 artificial intelligence model for a select group of U.S. organizations tasked with defending critical… Delivered by PolitePaul service Go to gbhackers.com
-
Cloud Bucket Hijacking Lets Attackers Silently Exfiltrate AWS, Google Cloud Data
Cloud Bucket Hijacking Lets Attackers Silently Exfiltrate AWS, Google Cloud Data A critical cloud storage attack technique that exploits a fundamental architectural vulnerability shared across all major cloud service providers. The technique, dubbed cloud bucket hijacking,… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Linux Kernel Flaw Allows Unprivileged Users to Gain Full Root Access
Critical Linux Kernel Flaw Allows Unprivileged Users to Gain Full Root Access A newly disclosed flaw in the Linux kernel’s traffic-control subsystem, now assigned CVE-2026-46331 and referred to as “Pedit COW,” has been found to grant… Delivered by PolitePaul service Go to gbhackers.com
-
Amazon Q Developer Vulnerability Allows Code Execution via Malicious Repositories
Amazon Q Developer Vulnerability Allows Code Execution via Malicious Repositories A critical security flaw discovered in the Amazon Q Developer Extension for Visual Studio Code (VS Code) left developers vulnerable to arbitrary code execution… Delivered by PolitePaul service Go to gbhackers.com
-
Linux Kernel DirtyClone Vulnerability Lets Local Attackers Gain Root Privileges
Linux Kernel DirtyClone Vulnerability Lets Local Attackers Gain Root Privileges A critical Local Privilege Escalation flaw has been uncovered within the Linux kernel, allowing unprivileged local users to seamlessly gain root access by manipulating… Delivered by PolitePaul service Go to gbhackers.com