Tag: gbhackers
-
Hackers Exploit WinRAR CVE-2025-8088 to Plant Startup Shortcut and Run PowerShell Loader
Hackers Exploit WinRAR CVE-2025-8088 to Plant Startup Shortcut and Run PowerShell Loader Hackers have weaponized a WinRAR path-traversal flaw tracked as CVE-2025-8088 to silently plant a Startup shortcut and run a multi-stage PowerShell loader that maps… Delivered by PolitePaul service Go to gbhackers.com
-
WhatsApp Adds Security Warning Before Users Start Chat With Unknown Numbers
WhatsApp Adds Security Warning Before Users Start Chat With Unknown Numbers WhatsApp has introduced a new proactive security feature that warns users before they start conversations with unknown phone numbers. This update, currently being rolled… Delivered by PolitePaul service Go to gbhackers.com
-
KuinaExtractor Stealer Targets Browser Data, Crypto Wallets, Roblox, Steam, and Discord
KuinaExtractor Stealer Targets Browser Data, Crypto Wallets, Roblox, Steam, and Discord A previously undocumented Rust-based infostealer they call KuinaExtractor, a family that has evolved from a capable early prototype into a hardened, stealth-focused threat now… Delivered by PolitePaul service Go to gbhackers.com
-
Russian Authorities Used Cellebrite UFED to Break Into Human Rights Activist’s iPhone
Russian Authorities Used Cellebrite UFED to Break Into Human Rights Activist’s iPhone Russian authorities leveraged Cellebrite’s Universal Forensic Extraction Device (UFED) to gain access to a detained human rights activist’s iPhone, according to a detailed forensic… Delivered by PolitePaul service Go to gbhackers.com
-
Scammers Abuse Shopify to Send Fake Invoices and Steal Credentials via Fake Support Calls
Scammers Abuse Shopify to Send Fake Invoices and Steal Credentials via Fake Support Calls Scammers are increasingly exploiting Shopify’s ecosystem and its Shop order-tracking app to deliver fraudulent invoices directly into users’ purchase histories, marking a shift from… Delivered by PolitePaul service Go to gbhackers.com
-
Gemini 3.5 Flash Now Supports Agentic Computer Use for Enterprise Automation Tasks
Gemini 3.5 Flash Now Supports Agentic Computer Use for Enterprise Automation Tasks Google has announced a significant enhancement to its AI platform with the release of Gemini 3.5 Flash, which now includes native support for agentic… Delivered by PolitePaul service Go to gbhackers.com
-
Langflow RCE Flaw Lets Attackers Execute Arbitrary Python Code Without Authentication
Langflow RCE Flaw Lets Attackers Execute Arbitrary Python Code Without Authentication A critical unauthenticated remote code execution (RCE) vulnerability in Langflow, tracked as CVE-2026-33017, is being actively exploited in the wild within hours of its… Delivered by PolitePaul service Go to gbhackers.com
-
Shai-Hulud Hades Payload Hits 20 Leo/RStreams npm Packages in Fresh Supply Chain Attack
Shai-Hulud Hades Payload Hits 20 Leo/RStreams npm Packages in Fresh Supply Chain Attack A fresh supply-chain wave by the Shai-Hulud/Hades family that infected 20 npm packages in the Leo/RStreams ecosystem, an AWS-native event streaming SDK widely used… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Abuse Cloudflare-Hosted AWS Phishing Domains to Steal Console Logins
Hackers Abuse Cloudflare-Hosted AWS Phishing Domains to Steal Console Logins A concise but sophisticated phishing campaign that targeted AWS console users by abusing Cloudflare-hosted domains to deliver adversary-in-the-middle (AiTM) credential theft. Each domain served… Delivered by PolitePaul service Go to gbhackers.com
-
Curl 8.21.0 Released With 18 Security Fixes
Curl 8.21.0 Released With 18 Security Fixes The curl project has announced the release of version 8.21.0, marking its 275th release and including a significant security update. This version addresses 18… Delivered by PolitePaul service Go to gbhackers.com
-
Fable 5 AI Model Builds Bootable Windows Kernel in Rust in Just 38 Minutes
Fable 5 AI Model Builds Bootable Windows Kernel in Rust in Just 38 Minutes A newly released AI model, Claude Fable 5, has made a significant advancement in autonomous systems programming by generating a bootable Windows NT-style kernel… Delivered by PolitePaul service Go to gbhackers.com
-
Webmin Stored XSS Vulnerability Lets Attackers Exploit Root Users
Webmin Stored XSS Vulnerability Lets Attackers Exploit Root Users A newly disclosed stored cross-site scripting (XSS) vulnerability in Webmin has raised significant security concerns, as it allows attackers with limited privileges to target… Delivered by PolitePaul service Go to gbhackers.com
-
PoC Released for Microsoft Exchange Server EWS InstallApp SSRF Vulnerability
PoC Released for Microsoft Exchange Server EWS InstallApp SSRF Vulnerability A proof-of-concept exploit has been released for CVE-2026-45502, a server-side request forgery (SSRF) vulnerability in the Microsoft Exchange Server’s Exchange Web Services (EWS) InstallApp… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Abuse Indian Tax Notice Lures to Deliver PE Loader and libsvcs.dll Payload
Hackers Abuse Indian Tax Notice Lures to Deliver PE Loader and libsvcs.dll Payload A targeted malware distribution campaign that abuses a counterfeit Indian Income Tax Department assessment notice to deliver a multi-stage Remote Access Trojan (RAT)-style payload…. Delivered by PolitePaul service Go to gbhackers.com
-
Cisco Unified Communications Manager Flaw Exposes Systems to SSRF Attacks and Root Access
Cisco Unified Communications Manager Flaw Exposes Systems to SSRF Attacks and Root Access Cisco has disclosed a critical server-side request forgery (SSRF) vulnerability affecting its Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition… Delivered by PolitePaul service Go to gbhackers.com
-
Tata Electronics Data Breach Exposes 200,000+ Files Linked to Apple and Tesla, Hackers Claim
Tata Electronics Data Breach Exposes 200,000+ Files Linked to Apple and Tesla, Hackers Claim Tata Electronics has reported a cybersecurity incident following claims from a ransomware-linked threat group that it has exfiltrated and published over 200,000 files related… Delivered by PolitePaul service Go to gbhackers.com
-
Critical FFmpeg Vulnerability Lets Hackers Execute Remote Code via Malicious Media Files
Critical FFmpeg Vulnerability Lets Hackers Execute Remote Code via Malicious Media Files A critical memory corruption vulnerability in FFmpeg has been disclosed, allowing for remote code execution through specially crafted media files. This flaw, tracked as… Delivered by PolitePaul service Go to gbhackers.com
-
Cybercriminals Abuse TDS Infrastructure to Bypass Firewalls and Hide Malicious Destinations
Cybercriminals Abuse TDS Infrastructure to Bypass Firewalls and Hide Malicious Destinations Cybercriminals are increasingly abusing traffic distribution systems (TDSs) to evade defenses, conceal malicious destinations, and funnel victims into phishing, fraud, and malware campaigns. Once… Delivered by PolitePaul service Go to gbhackers.com
-
Critical libssh2 Vulnerability Lets Remote Attackers Execute Code via Crafted SSH Packets
Critical libssh2 Vulnerability Lets Remote Attackers Execute Code via Crafted SSH Packets A critical security vulnerability has been identified in libssh2, a widely used client-side SSH library. This flaw allows remote attackers to execute code by… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Uncovers Parallel Threat Activity From Two Cyberattackers in Single Intrusion
Microsoft Uncovers Parallel Threat Activity From Two Cyberattackers in Single Intrusion Microsoft’s latest incident write-up shows that a single intrusion can mask two parallel threat activity streams, one tied to Storm-2603 and another to an… Delivered by PolitePaul service Go to gbhackers.com
-
LACUNA Chain Ghost Frames Technique Bypasses EDR Call-Stack Detection
LACUNA Chain Ghost Frames Technique Bypasses EDR Call-Stack Detection The LACUNA Chain’s “Ghost Frames” technique introduces a new method for manipulating call stacks that effectively bypasses modern Endpoint Detection and Response (EDR) systems,… Delivered by PolitePaul service Go to gbhackers.com
-
282 iOS Apps Found Leaking LLM API Credentials in Network Traffic
282 iOS Apps Found Leaking LLM API Credentials in Network Traffic Researchers have uncovered a systemic LLM credential exposure problem in the iOS ecosystem, with 282 AI‑powered apps leaking exploitable API credentials and backend access… Delivered by PolitePaul service Go to gbhackers.com
-
Attackers Can Poison AI Research Agents Using Reddit and Wikipedia Content
Attackers Can Poison AI Research Agents Using Reddit and Wikipedia Content Attackers can now manipulate AI “deep-research” agents by discreetly editing Reddit threads and Wikipedia pages. They can insert as little as a 13-word snippet,… Delivered by PolitePaul service Go to gbhackers.com
-
AryStinger Botnet Uses Intranet Scanning and Traffic Tunneling to Hide Attacker Activity
AryStinger Botnet Uses Intranet Scanning and Traffic Tunneling to Hide Attacker Activity A newly analyzed botnet family, AryStinger, weaponizes long‑neglected routers and NAS appliances to build a stealthy reconnaissance and relay infrastructure that helps attackers obscure… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Confirms Windows 11 26H2 Upgrade via Enablement Package for Faster Deployment
Microsoft Confirms Windows 11 26H2 Upgrade via Enablement Package for Faster Deployment Microsoft has announced that the upcoming Windows 11 version 26H2 will be delivered using an enablement package model. This approach aligns with their goal… Delivered by PolitePaul service Go to gbhackers.com
-
Texas TPWD Vendor Breach Exposes 3 Million Customer Records
Texas TPWD Vendor Breach Exposes 3 Million Customer Records Texas Cyber Command has disclosed a massive third-party data breach affecting the Texas Parks and Wildlife Department (TPWD), exposing the personal records of exactly… Delivered by PolitePaul service Go to gbhackers.com
-
Vidar Infostealer Bypasses Google Chrome’s ABE Encryption via APC Injection
Vidar Infostealer Bypasses Google Chrome’s ABE Encryption via APC Injection A sophisticated evasion technique developed by Vidar infostealer operators successfully bypasses Google Chrome’s Application-Bound Encryption (ABE). Introduced in 2024, ABE was designed to protect… Delivered by PolitePaul service Go to gbhackers.com
-
AutoJack Exploit Chain Hits Microsoft AutoGen Studio With Zero-Click RCE Attack
AutoJack Exploit Chain Hits Microsoft AutoGen Studio With Zero-Click RCE Attack A critical exploit chain dubbed AutoJack that allows a single malicious web page to hijack Microsoft’s AutoGen Studio browsing agent and silently execute arbitrary code on… Delivered by PolitePaul service Go to gbhackers.com
-
Gentlemen RaaS Unifies HexKiller, ThrottleBlood, and HavocKiller in New Evasion Suite
Gentlemen RaaS Unifies HexKiller, ThrottleBlood, and HavocKiller in New Evasion Suite An analysis of the Gentlemen ransomware-as-a-service (RaaS) operation has revealed a sophisticated, centralized approach to neutralizing endpoint detection and response (EDR) solutions. This unified defense… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Chrome Extension Vulnerabilities Let Attackers Easily Compromise Browsers
Critical Chrome Extension Vulnerabilities Let Attackers Easily Compromise Browsers A critical security flaws in widely used Chrome extensions, exposing millions of users to the risk of full browser compromise. The vulnerabilities, named “MaXSS”… Delivered by PolitePaul service Go to gbhackers.com
-
UEFI DBX Update Guidance Targets Vulnerable Vendor-Signed Boot Applications
UEFI DBX Update Guidance Targets Vulnerable Vendor-Signed Boot Applications A recently disclosed vulnerability inc, which affects UEFI applications signed by multiple vendors, has prompted urgent recommendations to update the UEFI Forbidden Signature Database… Delivered by PolitePaul service Go to gbhackers.com
-
SmartApeSG Hackers Abuse Okendo Reviews Widget in E-Commerce Supply Chain Attack
SmartApeSG Hackers Abuse Okendo Reviews Widget in E-Commerce Supply Chain Attack A supply-chain style compromise in the Okendo Reviews widget that enabled the SmartApeSG threat actor to deliver staged JavaScript loaders across a wide e-commerce… Delivered by PolitePaul service Go to gbhackers.com
-
Node.js Releases Security Updates for 12 Vulnerabilities, Two Rated High Severity
Node.js Releases Security Updates for 12 Vulnerabilities, Two Rated High Severity Node.js has announced critical security updates that address 12 vulnerabilities across its supported release lines. Among these, two high-severity flaws could lead to denial-of-service… Delivered by PolitePaul service Go to gbhackers.com
-
CISA Issues Alert on Critical Splunk Enterprise Bug Under Active Exploitation
CISA Issues Alert on Critical Splunk Enterprise Bug Under Active Exploitation CISA has issued an urgent alert regarding a critical vulnerability in Splunk Enterprise, tracked as CVE-2026-20253, which is now listed in the Known Exploited… Delivered by PolitePaul service Go to gbhackers.com
-
HazyBeacon Abuses AWS Lambda Function URLs for Stealthy Command-and-Control Operations
HazyBeacon Abuses AWS Lambda Function URLs for Stealthy Command-and-Control Operations HazyBeacon is a stealthy cloud-native malware campaign identified as CL-STA-1020. It is exploiting Amazon Web Services (AWS) Lambda Function URLs to create covert command-and-control… Delivered by PolitePaul service Go to gbhackers.com
-
Windows 11 June Patch Triggers Microsoft Office Startup Issues
Windows 11 June Patch Triggers Microsoft Office Startup Issues Microsoft’s June 2026 cumulative update for Windows 11 (KB5095051, OS Build 28000.2269) introduces an unexpected application compatibility issue that may disrupt enterprise workflows, as… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Could Abuse SQL Server 2025 AI Features to Steal Sensitive Data
Hackers Could Abuse SQL Server 2025 AI Features to Steal Sensitive Data A new security analysis has revealed that Microsoft SQL Server 2025’s native AI capabilities can be repurposed by attackers to stealthily exfiltrate sensitive data… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Exploit WordPress SMTP Plugin With 100,000+ Installs to Steal Sensitive Data
Hackers Exploit WordPress SMTP Plugin With 100,000+ Installs to Steal Sensitive Data Threat actors are actively exploiting a critical security flaw in the widely used Gravity SMTP WordPress plugin to extract sensitive configuration data, including API… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Confirms RoguePlanet Zero-Day Exploit Targeting Defender
Microsoft Confirms RoguePlanet Zero-Day Exploit Targeting Defender Microsoft has confirmed a newly disclosed zero-day vulnerability, tracked as CVE-2026-50656, affecting Microsoft Defender, following the public release of a proof-of-concept (PoC) exploit dubbed… Delivered by PolitePaul service Go to gbhackers.com
-
Splunk AI Toolkit Vulnerability Allows Arbitrary OS Command Execution
Splunk AI Toolkit Vulnerability Allows Arbitrary OS Command Execution Splunk has disclosed a critical security vulnerability in its AI Toolkit that could allow authenticated administrators to execute arbitrary operating system commands on affected… Delivered by PolitePaul service Go to gbhackers.com
-
Attackers Exploit Cloud Logging Platforms to Hide Malicious Activity
Attackers Exploit Cloud Logging Platforms to Hide Malicious Activity Attackers are increasingly targeting cloud logging platforms to evade detection and maintain persistent visibility into compromised environments. The report highlights how critical services such as… Delivered by PolitePaul service Go to gbhackers.com
-
7-Year-Old OpenBSD Security Flaw Exposes Systems to Full PAP Authentication Bypass
7-Year-Old OpenBSD Security Flaw Exposes Systems to Full PAP Authentication Bypass A significant authentication flaw has been discovered in the PPP stack of OpenBSD, allowing attackers to bypass the Password Authentication Protocol (PAP) validation and… Delivered by PolitePaul service Go to gbhackers.com
-
SprySOCKS Windows Backdoor Uses Kernel Driver to Hide Processes, Files, and Network Traffic
SprySOCKS Windows Backdoor Uses Kernel Driver to Hide Processes, Files, and Network Traffic Windows variants of SprySOCKS, a backdoor long associated with FishMonger (aka Earth Lusca/TAG-22), expanding a toolset that was until now Linux-only. The two Windows… Delivered by PolitePaul service Go to gbhackers.com
-
CISA Issues Alert on Oracle PeopleSoft Vulnerability Exploited by Ransomware Groups
CISA Issues Alert on Oracle PeopleSoft Vulnerability Exploited by Ransomware Groups The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding the active exploitation of a critical vulnerability in Oracle PeopleSoft… Delivered by PolitePaul service Go to gbhackers.com
-
Steam Workshop Malware Campaign Uses Wallpaper Engine to Steal Accounts and Infect Gamers
Steam Workshop Malware Campaign Uses Wallpaper Engine to Steal Accounts and Infect Gamers A sophisticated malware campaign has been abusing Steam Workshop’s sharing model to distribute backdoors, infostealers and crypto miners hidden inside Wallpaper Engine packages, primarily… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Abuse Compromised WordPress Sites to Deliver GULoader Through EtherHiding Chain
Hackers Abuse Compromised WordPress Sites to Deliver GULoader Through EtherHiding Chain In April 2026, incident responders traced a sophisticated intrusion that abused compromised WordPress sites to deliver GULoader via an EtherHiding → ClickFix → UNC-chain…. Delivered by PolitePaul service Go to gbhackers.com
-
Ghostwriter APT Uses Fake Gmail Login Panels to Steal Passwords and 2FA Codes
Ghostwriter APT Uses Fake Gmail Login Panels to Steal Passwords and 2FA Codes Ghostwriter (UNC1151) has escalated its long-standing phishing operations by deploying convincing fake Gmail login panels that harvest both passwords and two-factor authentication (2FA) codes,… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Abuse Microsoft OAuth Device Code Flow to Take Over Microsoft 365 Accounts
Hackers Abuse Microsoft OAuth Device Code Flow to Take Over Microsoft 365 Accounts An active campaign in which attackers are abusing Microsoft’s OAuth 2.0 Device Authorization Grant (device code) flow to take over Microsoft 365 accounts. Rather… Delivered by PolitePaul service Go to gbhackers.com
-
OptinMonster Plugin Vulnerability Exposes 1.2 Million WordPress Sites to Cyberattacks
OptinMonster Plugin Vulnerability Exposes 1.2 Million WordPress Sites to Cyberattacks A large-scale supply chain attack targeting the popular OptinMonster WordPress plugin has exposed more than 1.2 million websites to active compromise. The campaign also affects… Delivered by PolitePaul service Go to gbhackers.com
-
Rhysida and Interlock Ransomware Groups Linked to Initial Access Brokers and Crypter Ecosystem
Rhysida and Interlock Ransomware Groups Linked to Initial Access Brokers and Crypter Ecosystem Rhysida and Interlock sit inside the same ransomware supply chain, but their latest observed behavior shows a more nuanced relationship than simple code reuse…. Delivered by PolitePaul service Go to gbhackers.com
-
New DPAPISnoop Tool Enables Extraction of CREDHIST Hashes From Windows Systems
New DPAPISnoop Tool Enables Extraction of CREDHIST Hashes From Windows Systems A newly enhanced version of the open-source DPAPISnoop tool is drawing attention in the security community after researchers demonstrated its ability to extract offline-crackable… Delivered by PolitePaul service Go to gbhackers.com
-
SearchJack Adware Campaign Exposes 758,000 Users to Privacy and Phishing Risks
SearchJack Adware Campaign Exposes 758,000 Users to Privacy and Phishing Risks A coordinated campaign of 23 seemingly legitimate Chrome extensions tracked as “SearchJack” has quietly hijacked the default search settings of roughly 758,000 users, routing… Delivered by PolitePaul service Go to gbhackers.com
-
SHADOWBYT3$ Allegedly Claims Nintendo Breach and Theft of Sensitive Data
SHADOWBYT3$ Allegedly Claims Nintendo Breach and Theft of Sensitive Data Threat intelligence sources have flagged a potential cybersecurity incident involving Nintendo after threat actor “SHADOWBYT3$” allegedly claimed responsibility for breaching internal systems and exfiltrating… Delivered by PolitePaul service Go to gbhackers.com
-
Palo Alto Warns GlobalProtect VPN Flaw Is Being Actively Exploited
Palo Alto Warns GlobalProtect VPN Flaw Is Being Actively Exploited Palo Alto Networks has issued an urgent warning after confirming active exploitation of a GlobalProtect VPN vulnerability, tracked as CVE-2026-0257, impacting PAN-OS deployments with… Delivered by PolitePaul service Go to gbhackers.com
-
PromptSnatcher Browser Extensions Abuse AI Platforms to Capture Full Chat Conversations
PromptSnatcher Browser Extensions Abuse AI Platforms to Capture Full Chat Conversations PromptSnatcher (internal identifier: Panel 231) is a modern, stealthy data collection operation embedded inside two browser extensions that masquerade as ad‑blockers while harvesting full… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Splunk Enterprise Pre-Auth RCE Chain Exposes Databases
Critical Splunk Enterprise Pre-Auth RCE Chain Exposes Databases A critical pre-authentication remote code execution (RCE) vulnerability in Splunk Enterprise has been disclosed, carrying a near-perfect CVSS score of 9.8. Tracked as CVE-2026-20253, the… Delivered by PolitePaul service Go to gbhackers.com
-
New Agentjacking Attack Hijacks AI Coding Agents to Execute Malicious Code
New Agentjacking Attack Hijacks AI Coding Agents to Execute Malicious Code A newly disclosed Agentjacking attack class can silently weaponize AI coding agents against the very developers who rely on them, requiring no phishing, no… Delivered by PolitePaul service Go to gbhackers.com
-
Anthropic Blocks Fable 5 and Mythos 5 Following U.S. National Security Directive
Anthropic Blocks Fable 5 and Mythos 5 Following U.S. National Security Directive Anthropic has disabled all access to its Fable 5 and Mythos 5 artificial intelligence models following a sudden export-control directive from the United States… Delivered by PolitePaul service Go to gbhackers.com
-
Malicious 152 Chrome Extensions Caught Spoofing Google Organic Search Traffic
Malicious 152 Chrome Extensions Caught Spoofing Google Organic Search Traffic A massive, coordinated network of 152 malicious Google Chrome browser extensions has been dismantled after researchers caught the operation generating fake organic Google search… Delivered by PolitePaul service Go to gbhackers.com
-
GRU-Linked APT28 Uses MooBot Botnet and Compromised EdgeRouters for Cyber Operations
GRU-Linked APT28 Uses MooBot Botnet and Compromised EdgeRouters for Cyber Operations A notable operational pivot by the GRU-linked intrusion set APT28 (aka Fancy Bear, Sofacy, Forest Blizzard, Pawn Storm) that combines the MooBot botnet and… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Use Typosquatted npm Packages to Target Web3 Projects and Crypto Wallet Operators
Hackers Use Typosquatted npm Packages to Target Web3 Projects and Crypto Wallet Operators Hackers have been using typosquatting npm packages to weaponize the trust Web3 teams place in open-source dependencies, turning routine installs into a path for… Delivered by PolitePaul service Go to gbhackers.com
-
Attackers Can Exploit Microsoft Outlook and Word Flaws to Run Malicious Code
Attackers Can Exploit Microsoft Outlook and Word Flaws to Run Malicious Code Microsoft has disclosed a set of critical remote code execution (RCE) vulnerabilities affecting Outlook and Word that could allow attackers to execute arbitrary code… Delivered by PolitePaul service Go to gbhackers.com
-
Palo Alto PAN-OS Flaw Lets Attackers Run Arbitrary Commands With Root Privileges
Palo Alto PAN-OS Flaw Lets Attackers Run Arbitrary Commands With Root Privileges Palo Alto Networks has released patches for three new PAN-OS vulnerabilities that could allow authenticated administrators or users to execute arbitrary commands with root… Delivered by PolitePaul service Go to gbhackers.com
-
OnyxC2 Stealer Uses Cloudflare-Fronted C2 to Exfiltrate Browser Data and Credentials
OnyxC2 Stealer Uses Cloudflare-Fronted C2 to Exfiltrate Browser Data and Credentials A new commercial-grade information stealer, marketed as OnyxC2, surfaced on cybercrime forums in early 2026 and demonstrates how commodity malware is increasingly packaged as… Delivered by PolitePaul service Go to gbhackers.com
-
Tchap Messenger Hack Exposes Data of Over 73,000 French Government Employees
Tchap Messenger Hack Exposes Data of Over 73,000 French Government Employees A suspected cyberattack targeting Tchap, the secure messaging platform used by French government agencies, has reportedly exposed sensitive data belonging to more than 73,000… Delivered by PolitePaul service Go to gbhackers.com
-
Weaponized DMG Files Deliver macOS Infostealer Malware
Weaponized DMG Files Deliver macOS Infostealer Malware A recent surge in macOS-targeted campaigns shows threat actors favoring weaponized disk images (.dmg) as the primary delivery mechanism for infostealer malware. Attackers are… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Use Residential Proxies Networks to Evade Detection
Hackers Use Residential Proxies Networks to Evade Detection The impact of residential proxies across our customer base by compiling billions of DNS resolutions and the associated network telemetry. The Kimwolf Botnet inside our enterprise customer… Delivered by PolitePaul service Go to gbhackers.com
-
BLUERABBIT Backdoor Encrypts Files, Wipes Windows Systems
BLUERABBIT Backdoor Encrypts Files, Wipes Windows Systems A new Golang-based backdoor dubbed BLUERABBIT has been observed performing combined data theft, file encryption and destructive disk wiping against Windows hosts. First seen in… Delivered by PolitePaul service Go to gbhackers.com
-
Cybercriminals Exploit Chinese Guarantee Markets to Sell Stolen Credentials
Cybercriminals Exploit Chinese Guarantee Markets to Sell Stolen Credentials Chinese-language “guarantee” marketplaces hosted mainly on Telegram have become a core conduit for buying, selling, and laundering stolen credentials and a wide range of… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Abuse VMware-Signed Binary to Deploy NIGHTFORGE Loader
Hackers Abuse VMware-Signed Binary to Deploy NIGHTFORGE Loader Two closely related espionage campaigns targeting Cambodian government organizations that abuse a legitimate VMware-signed binary to sideload a custom loader dubbed NIGHTFORGE, which in… Delivered by PolitePaul service Go to gbhackers.com
-
CISA Issues Alert on Actively Exploited Google Chromium Zero-Day Flaw
CISA Issues Alert on Actively Exploited Google Chromium Zero-Day Flaw CISA has issued a new warning about an actively exploited zero-day vulnerability in Google Chromium that could allow attackers to execute arbitrary code through… Delivered by PolitePaul service Go to gbhackers.com
-
Tax Phishing Emails Deliver In-Memory Malware to Windows Systems
Tax Phishing Emails Deliver In-Memory Malware to Windows Systems Cybercriminals are leveraging tax-themed phishing emails to deploy sophisticated in-memory malware on Windows systems, bypassing traditional disk-based detection mechanisms. The attack cascade begins when… Delivered by PolitePaul service Go to gbhackers.com
-
Malicious npm Package ‘dbmux’ Targets Developers
Malicious npm Package ‘dbmux’ Targets Developers Malware was discovered in the npm package dbmux. Any computer with this package installed or running should be considered fully compromised. The GitHub Advisory (GHSA-62wx-5f55-w8g2)… Delivered by PolitePaul service Go to gbhackers.com
-
Windows BitLocker 0-Day Flaw Enables Security Feature Bypass Attacks
Windows BitLocker 0-Day Flaw Enables Security Feature Bypass Attacks Microsoft has disclosed a newly identified zero-day vulnerability in Windows BitLocker that could allow attackers to bypass one of the operating system’s core disk… Delivered by PolitePaul service Go to gbhackers.com
-
Windows Defender Zero-Day “RoguePlanet” Lets Attackers Gain SYSTEM Privileges
Windows Defender Zero-Day “RoguePlanet” Lets Attackers Gain SYSTEM Privileges A newly disclosed zero-day vulnerability dubbed “RoguePlanet” is affecting Microsoft Defender, allowing attackers to escalate privileges and obtain full SYSTEM-level access on vulnerable Windows… Delivered by PolitePaul service Go to gbhackers.com
-
Ghost-Sender Flaw Exposes Exchange Online Users to Sender Spoofing Attacks
Ghost-Sender Flaw Exposes Exchange Online Users to Sender Spoofing Attacks A newly disclosed “Ghost-Sender” flaw is exposing Microsoft Exchange Online environments to large-scale email spoofing attacks, allowing threat actors to bypass standard email authentication… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Entra Agent ID Logs Expose Suspicious Assistive Agent Activity
Microsoft Entra Agent ID Logs Expose Suspicious Assistive Agent Activity Microsoft Entra Agent ID logs have exposed a subtle but consequential threat vector: assistive agents using the OAuth On-Behalf-Of (OBO) flow to act with… Delivered by PolitePaul service Go to gbhackers.com
-
Linux Kernel Flaw Allows Local Attackers to Gain Root Privileges
Linux Kernel Flaw Allows Local Attackers to Gain Root Privileges A newly disclosed Linux kernel vulnerability tracked as CVE-2026-23111 allows local attackers to escalate privileges to root by exploiting a use-after-free flaw in the… Delivered by PolitePaul service Go to gbhackers.com
-
Top 10 Best Zero Trust Network Access (ZTNA) Solutions 2026
Top 10 Best Zero Trust Network Access (ZTNA) Solutions 2026 In 2026, the traditional network perimeter is obsolete. With the widespread adoption of remote and hybrid work models, multi-cloud environments, and a proliferation of… Delivered by PolitePaul service Go to gbhackers.com
-
WhatsApp Blocks Pegasus Spyware Campaign Linked to NSO Group
WhatsApp Blocks Pegasus Spyware Campaign Linked to NSO Group WhatsApp has disrupted a new spyware campaign linked to the NSO Group, the controversial surveillance vendor behind Pegasus, while simultaneously seeking legal action against… Delivered by PolitePaul service Go to gbhackers.com
-
Internet Explorer WebBrowser Control Abuse Lets Attackers Convert Clicks Into RCE
Internet Explorer WebBrowser Control Abuse Lets Attackers Convert Clicks Into RCE Internet Explorer’s legacy WebBrowser control can be abused to turn seemingly harmless user clicks into full remote code execution (RCE), even on systems that… Delivered by PolitePaul service Go to gbhackers.com
-
Lucid Stealer Hits 18 Browsers, Crypto Wallets, and Discord Tokens
Lucid Stealer Hits 18 Browsers, Crypto Wallets, and Discord Tokens A new, fully featured Lucid Stealer build that combines large-scale credential theft with hidden remote access. The sample, distributed through Telegram-linked underground channels, is… Delivered by PolitePaul service Go to gbhackers.com
-
China-Linked OP-512 Targets IIS Servers With Unique Web Shell Framework
China-Linked OP-512 Targets IIS Servers With Unique Web Shell Framework A suspected China-linked espionage cluster dubbed OP-512 after rapidly correlating many low-fidelity events into a single high-priority incident that human analysts then validated. OP-512… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Redis Vulnerability Could Let Attackers Execute Code and Hijack Servers
Critical Redis Vulnerability Could Let Attackers Execute Code and Hijack Servers A critical vulnerability in Redis, tracked as CVE-2026-23631 and dubbed “DarkReplica,” exposes authenticated deployments to remote code execution (RCE) through a complex use-after-free (UAF)… Delivered by PolitePaul service Go to gbhackers.com
-
Instagram Patches Account Recovery Flaw Leaking User Contact Information
Instagram Patches Account Recovery Flaw Leaking User Contact Information A critical logic flaw in Instagram’s web-based account recovery workflow exposed unredacted user contact information, including full email addresses and phone numbers, before Meta… Delivered by PolitePaul service Go to gbhackers.com
-
China-Linked Espionage Cluster Deploys Custom ASPX/ASHX Shells on IIS
China-Linked Espionage Cluster Deploys Custom ASPX/ASHX Shells on IIS A previously disclosed China-linked threat cluster, tracked as OP-512, has been observed deploying a purpose-built web shell framework to compromise Internet Information Services (IIS)… Delivered by PolitePaul service Go to gbhackers.com
-
CISA Alerts on Actively Exploited SolarWinds Serv-U Denial-of-Service Flaw
CISA Alerts on Actively Exploited SolarWinds Serv-U Denial-of-Service Flaw The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical vulnerability in SolarWinds Serv-U to its Known Exploited Vulnerabilities (KEV) catalog…. Delivered by PolitePaul service Go to gbhackers.com
-
Critical UniFi OS Auth Bypass Flaws Lead to Unauthenticated Root RCE
Critical UniFi OS Auth Bypass Flaws Lead to Unauthenticated Root RCE Ubiquiti has addressed three critical vulnerabilities within the UniFi OS Server that attackers can chain together to achieve unauthenticated remote code execution (RCE) with… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Weaponize Trusted Tools to Deploy Notorious Malware
Hackers Weaponize Trusted Tools to Deploy Notorious Malware Attackers are leaning harder on legitimate, preinstalled, or widely used system tools to deliver and operate notorious malware families, creating a stealthy, high-velocity threat… Delivered by PolitePaul service Go to gbhackers.com
-
UNC3753 Targets US Law Firms with Vishing, RMM Tools, and Physical Break-Ins
UNC3753 Targets US Law Firms with Vishing, RMM Tools, and Physical Break-Ins Threat cluster UNC3753, widely tracked as Silent Ransom Group or Luna Moth, is actively targeting professional, legal, and financial services in the United States…. Delivered by PolitePaul service Go to gbhackers.com
-
Malspam Campaign Abuses DoubleClick to Deploy Stealthy .NET Loader
Malspam Campaign Abuses DoubleClick to Deploy Stealthy .NET Loader A sophisticated new malspam campaign is actively exploiting Google’s DoubleClick ad-tracking infrastructure to bypass enterprise email security gateways. Discovered by researchers at Huntress, the… Delivered by PolitePaul service Go to gbhackers.com
-
Hugging Face Transformers Security Flaw Allows Remote Code Execution
Hugging Face Transformers Security Flaw Allows Remote Code Execution A critical security flaw in Hugging Face Transformers, tracked as CVE-2026-4372, has exposed millions of machine learning workflows to silent remote code execution (RCE)… Delivered by PolitePaul service Go to gbhackers.com
-
New Gafgyt Variant Targets Linux Systems With Modular Spread Tactics
New Gafgyt Variant Targets Linux Systems With Modular Spread Tactics A new Gafgyt-family botnet, tracked as C0XMO, marks a notable technical shift in IoT malware design: the separation of scanning and propagation into distinct… Delivered by PolitePaul service Go to gbhackers.com
-
AI-Powered Worm Leverages Stolen Compute to Target Linux, Windows, and IoT Devices
AI-Powered Worm Leverages Stolen Compute to Target Linux, Windows, and IoT Devices AI-powered malware is moving from theory to reality, with new proof-of-concept worms showing how large language models (LLMs) can autonomously compromise mixed networks of… Delivered by PolitePaul service Go to gbhackers.com
-
New SHub Stealer Variant Targets Major Browsers and Crypto Wallets
New SHub Stealer Variant Targets Major Browsers and Crypto Wallets Threat actors have resurfaced with an upgraded SHub stealer for macOS, now branded “Reaper,” and they’re using a stealthy distribution trick that should worry… Delivered by PolitePaul service Go to gbhackers.com
-
Malicious Browser Add-Ons Target Major AI Chatbot Users
Malicious Browser Add-Ons Target Major AI Chatbot Users Malicious browser add-ons are actively harvesting conversations and personal data from users of major AI platforms including ChatGPT, Claude, Copilot, Gemini, and DeepSeek. The threat… Delivered by PolitePaul service Go to gbhackers.com
-
Phishing Attacks Pivot to Infostealer Malware Over Fake Login Pages
Phishing Attacks Pivot to Infostealer Malware Over Fake Login Pages Cybercriminal tactics are evolving as phishing campaigns increasingly shift away from fake login pages toward infostealer malware designed to quietly harvest sensitive data from… Delivered by PolitePaul service Go to gbhackers.com
-
Proofpoint: TA4922 Deploys New RAT and Loader Arsenal
Proofpoint: TA4922 Deploys New RAT and Loader Arsenal A rapidly evolving threat cluster tracked as TA4922, a Chinese-speaking cybercriminal actor deploying a diverse and expanding malware arsenal that now includes Atlas RAT,… Delivered by PolitePaul service Go to gbhackers.com
-
PoC Exploit Released for Cisco Unified Communications Manager Security Vulnerability
PoC Exploit Released for Cisco Unified Communications Manager Security Vulnerability A proof-of-concept (PoC) exploit has been released for a critical server-side request forgery (SSRF) vulnerability impacting Cisco Unified Communications Manager (Unified CM) and Unified… Delivered by PolitePaul service Go to gbhackers.com
-
Stock Exchange Executive’s Outlook Targeted in Credential Theft Attack
Stock Exchange Executive’s Outlook Targeted in Credential Theft Attack A prolonged and highly targeted espionage campaign has been uncovered involving the compromise of a senior executive’s Microsoft Outlook account at a major global… Delivered by PolitePaul service Go to gbhackers.com