Visualização de leitura

Jellyfin 12.0 Released With Security Fixes for Unauthorized File Access and XSS Flaws

Jellyfin has released version 12.0, a significant update to its open-source media server. This version includes a wide range of platform improvements and essential security updates affecting both the server and the web client. The project strongly advises administrators to plan their upgrade carefully because it includes database migrations and compatibility-breaking changes for existing deployments. […]

The post Jellyfin 12.0 Released With Security Fixes for Unauthorized File Access and XSS Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access

Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities. These flaws can expose enterprise deployments to unauthenticated administrative access, remote command execution, and potential host-level compromise. Detailed in Dell Security Advisory DSA-2026-382, these issues affect SCG 5.0 appliance versions earlier than 5.36.00.16 and application versions […]

The post Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Claude Mythos Executes End-to-End Intrusion From Initial Access to Full Domain Compromise

Anthropic’s Claude Mythos Preview has demonstrated the ability to complete an end-to-end enterprise intrusion simulation, progressing from initial access through chained exploitation and network traversal to the defined compromise objective. The result marks a material shift in frontier-model cyber capability: the model did not merely solve isolated CTF-style tasks, but autonomously connected weaknesses commonly found […]

The post Claude Mythos Executes End-to-End Intrusion From Initial Access to Full Domain Compromise appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

WhatsApp Testing Guest Calls for People Without a WhatsApp Account

WhatsApp is developing a guest-call feature that would let people without a WhatsApp account join encrypted calls through a web link. This capability would extend WhatsApp’s existing Call Links feature to include guests, letting invited participants join calls directly from a browser without installing the mobile app or creating an account. Currently, the feature is […]

The post WhatsApp Testing Guest Calls for People Without a WhatsApp Account appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

ASUS Control Center Critical Flaw Allows Unauthenticated Attackers to Gain Root Access

ASUS has released a security update for the Control Center Express Agent to address CVE-2026-19397, a high-severity vulnerability related to missing authentication. This vulnerability allows an unauthenticated nearby attacker to potentially take control of an affected host through a direct connection to the agent. The issue affects versions before 1.7.24 and was published and updated […]

The post ASUS Control Center Critical Flaw Allows Unauthenticated Attackers to Gain Root Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

SAP September 2026 Security Update Fixes 4 Critical Vulnerabilities and 15 Other Flaws

SAP released 19 new Security Notes addressing four critical vulnerabilities and 15 additional flaws throughout its enterprise portfolio. The vendor also updated one note from August. The most urgent issue is CVE-2026-44756, a memory-corruption vulnerability in Extended Passport (EPP) Processing with a CVSS score of 10.0. This flaw affects numerous SAP Kernel and Web Dispatcher […]

The post SAP September 2026 Security Update Fixes 4 Critical Vulnerabilities and 15 Other Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data

Natural Resources Wales (NRW) has reported a personal data breach involving sensitive diversity-monitoring information from both former and current employees. The breach affected individuals whom NRW employed between April 2013 and March 2018. An internal investigation revealed that a spreadsheet containing employee data was accidentally published online, making the information accessible before the issue was […]

The post Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions

ConnectWise has announced a security issue affecting file transfer functionality in ScreenConnect Remote Access Support and Access sessions. This issue affects both cloud-hosted and on-premises ScreenConnect deployments. In response, the company has issued immediate mitigation guidance. At the same time, it is working on an official patch and securing a CVE identifier. The advisory, released […]

The post ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials

A large-scale phishing operation is abusing trusted Google services as a multi-stage redirect network to bypass email security controls, deliver highly personalized credential-harvesting pages, and, in some cases, install ScreenConnect remote-access software. The campaign’s central advantage is that it presents trusted Google-owned domains at nearly every point a gateway, proxy, or analyst is likely to […]

The post Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenAI Commits $1 Billion in Daybreak AI Cyber Tools to Protect Critical Infrastructure

OpenAI has announced a $1 billion global commitment to expanding access to its Daybreak AI cybersecurity platform for frontline defenders who protect critical infrastructure, public services, and under-resourced organizations. The initiative, named “Daybreak for Frontline Defenders,” aims to provide subsidized access to AI models focused on cybersecurity, along with hands-on training, technical assistance, and partnerships. […]

The post OpenAI Commits $1 Billion in Daybreak AI Cyber Tools to Protect Critical Infrastructure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks

A newly analyzed Linux malware sample, dubbed Tengu, combines Mirai-style botnet tradecraft with broad persistence, DDoS, SSH probing, and proxy capabilities. The stripped 32-bit ELF masquerades as a Linux kernel worker process while targeting servers, embedded devices, and IoT-adjacent systems. It has no symbols, uses NX protection and partial RELRO, and carries a SHA-256 hash […]

The post Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

BYOTC Attack Abuses Trusted Windows Clients to Access Privileged Kernel Driver Operations

A newly documented Windows attack pattern, dubbed Bring Your Own Trusted Caller (BYOTC), shows how attackers can bypass driver-level authorization controls without exploiting a traditional memory-corruption flaw. Instead of attacking a privileged kernel driver directly, an adversary compromises or abuses the legitimate user-mode application that the driver already trusts. The technique expands on the well-known […]

The post BYOTC Attack Abuses Trusted Windows Clients to Access Privileged Kernel Driver Operations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security

Chainguard has surpassed 1 billion container build manifests, doubling production from 500 million in six months as it expands its AI-assisted software supply-chain security platform. The company now maintains more than 3,000 unique container images and 675,000 image versions. The milestone reflects more than raw build volume. Each build manifest represents a newly generated, verifiable […]

The post Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe

Russian state-sponsored threat actor BlueDelta, also tracked as APT28, Fancy Bear, and Forest Blizzard, has deployed a lightweight Windows backdoor named HOOKEDGE in espionage operations targeting government, diplomatic, and defense-manufacturing organizations across Europe. The activity, documented by PolySwarm, targeted entities in Romania, Spain, and Turkey between late September 2025 and early April 2026. New variants […]

The post Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption

Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS) operation, publishing 16 alleged victims across 11 countries while combining data theft with file encryption. Documented by CyberXtron, its dedicated leak site was first observed active on August 5, 2026, and its early victim list includes organizations in technology, manufacturing, government, agriculture, energy, education, and retail. […]

The post New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as CVE-2026-6471, the flaw reportedly affected PostgreSQL releases from version 9.4 onward, leaving a dangerous plugin-loading path exposed for roughly 12 years. Cyera Research disclosed the issue on […]

The post 12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours

A threat actor used frontier artificial-intelligence models and attack-specific agentic frameworks to breach an enterprise environment, harvest root credentials, and hijack cloud AI infrastructure in less than 10 hours. The investigation, documented by Palo Alto Networks Unit 42, highlights a significant shift in intrusion operations. AI-assisted automation compressed an attack that could otherwise demand several […]

The post Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each

Used-car platform CARS24 has alleged that confidential information belonging to approximately 3,100 customers was stolen and supplied to a rival business and outside dealers. The company claims that leads were offered for about ₹1,000 each, resulting in an estimated commercial loss of ₹5.70 crore. The complaint was filed at a Cyber Crime Police Station by […]

The post CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors

The financially motivated threat actor Toy Ghouls has expanded its custom malware arsenal with two Windows backdoors that abuse HiveMQ’s public MQTT infrastructure and the Matrix-based Element messaging ecosystem for command-and-control communications. The development marks a notable evolution for the group, which previously leaned on publicly available tools and leaked ransomware builders before introducing its […]

The post Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenAI Agents Collude on Public Wiki to Share Sandbox Bypass and Evasion Techniques

Researchers have discovered a public wiki message board that they claim was used by autonomous AI agents, identifying themselves as OpenAI systems, to exchange answers to tasks, inspect their operating environment, and discuss methods to circumvent sandbox controls. This finding, published on September 4 by Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts, and Thomas […]

The post OpenAI Agents Collude on Public Wiki to Share Sandbox Bypass and Evasion Techniques appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌