Visualização de leitura

Jellyfin 12.0 Released With Security Fixes for Unauthorized File Access and XSS Flaws

Jellyfin has released version 12.0, a significant update to its open-source media server. This version includes a wide range of platform improvements and essential security updates affecting both the server and the web client. The project strongly advises administrators to plan their upgrade carefully because it includes database migrations and compatibility-breaking changes for existing deployments. […]

The post Jellyfin 12.0 Released With Security Fixes for Unauthorized File Access and XSS Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access

Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities. These flaws can expose enterprise deployments to unauthenticated administrative access, remote command execution, and potential host-level compromise. Detailed in Dell Security Advisory DSA-2026-382, these issues affect SCG 5.0 appliance versions earlier than 5.36.00.16 and application versions […]

The post Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

WhatsApp Testing Guest Calls for People Without a WhatsApp Account

WhatsApp is developing a guest-call feature that would let people without a WhatsApp account join encrypted calls through a web link. This capability would extend WhatsApp’s existing Call Links feature to include guests, letting invited participants join calls directly from a browser without installing the mobile app or creating an account. Currently, the feature is […]

The post WhatsApp Testing Guest Calls for People Without a WhatsApp Account appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

ASUS Control Center Critical Flaw Allows Unauthenticated Attackers to Gain Root Access

ASUS has released a security update for the Control Center Express Agent to address CVE-2026-19397, a high-severity vulnerability related to missing authentication. This vulnerability allows an unauthenticated nearby attacker to potentially take control of an affected host through a direct connection to the agent. The issue affects versions before 1.7.24 and was published and updated […]

The post ASUS Control Center Critical Flaw Allows Unauthenticated Attackers to Gain Root Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

SAP September 2026 Security Update Fixes 4 Critical Vulnerabilities and 15 Other Flaws

SAP released 19 new Security Notes addressing four critical vulnerabilities and 15 additional flaws throughout its enterprise portfolio. The vendor also updated one note from August. The most urgent issue is CVE-2026-44756, a memory-corruption vulnerability in Extended Passport (EPP) Processing with a CVSS score of 10.0. This flaw affects numerous SAP Kernel and Web Dispatcher […]

The post SAP September 2026 Security Update Fixes 4 Critical Vulnerabilities and 15 Other Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data

Natural Resources Wales (NRW) has reported a personal data breach involving sensitive diversity-monitoring information from both former and current employees. The breach affected individuals whom NRW employed between April 2013 and March 2018. An internal investigation revealed that a spreadsheet containing employee data was accidentally published online, making the information accessible before the issue was […]

The post Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions

ConnectWise has announced a security issue affecting file transfer functionality in ScreenConnect Remote Access Support and Access sessions. This issue affects both cloud-hosted and on-premises ScreenConnect deployments. In response, the company has issued immediate mitigation guidance. At the same time, it is working on an official patch and securing a CVE identifier. The advisory, released […]

The post ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenAI Commits $1 Billion in Daybreak AI Cyber Tools to Protect Critical Infrastructure

OpenAI has announced a $1 billion global commitment to expanding access to its Daybreak AI cybersecurity platform for frontline defenders who protect critical infrastructure, public services, and under-resourced organizations. The initiative, named “Daybreak for Frontline Defenders,” aims to provide subsidized access to AI models focused on cybersecurity, along with hands-on training, technical assistance, and partnerships. […]

The post OpenAI Commits $1 Billion in Daybreak AI Cyber Tools to Protect Critical Infrastructure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenAI Agents Collude on Public Wiki to Share Sandbox Bypass and Evasion Techniques

Researchers have discovered a public wiki message board that they claim was used by autonomous AI agents, identifying themselves as OpenAI systems, to exchange answers to tasks, inspect their operating environment, and discuss methods to circumvent sandbox controls. This finding, published on September 4 by Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts, and Thomas […]

The post OpenAI Agents Collude on Public Wiki to Share Sandbox Bypass and Evasion Techniques appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

ShipMonk Data Breach Exposes Personal Data of 67,000 Additional Trezor Customers

Trezor has revealed that a data breach involving its fulfillment provider, ShipMonk, exposed personal and order information of approximately 67,000 additional US customers. This significantly broadens the scope of an incident initially reported in August. The newly identified data pertains to Trezor orders processed during a prior partnership with ShipMonk, which lasted from November 2019 […]

The post ShipMonk Data Breach Exposes Personal Data of 67,000 Additional Trezor Customers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud

Microsoft is developing a new security feature for Teams messaging that will obscure QR codes sent by external users. This measure aims to help organizations reduce phishing and fraud risks associated with malicious QR code campaigns. Listed under Microsoft 365 Roadmap ID 570439, this feature is currently in development and is scheduled for rollout in […]

The post Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution

A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly […]

The post MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution

Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin, allowing them to upload PHP backdoors and gain remote code execution. This flaw, tracked as CVE-2026-14894, affects Super Forms versions 6.3.313 and earlier. Administrators are urged to upgrade to version 6.3.314 immediately. Super Forms WordPress Flaw Wordfence disclosed this unauthenticated arbitrary […]

The post Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Plex Urges Users to Update Media Server as Multiple Security Flaws Are Discovered

Plex has urged users to promptly update their Plex Media Server and Plex Desktop software following the release of fixes for several undisclosed security issues in older versions. The recommended versions are Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The company advises that all server owners and desktop users upgrade to the latest release […]

The post Plex Urges Users to Update Media Server as Multiple Security Flaws Are Discovered appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft

TP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administrator credentials from captured login traffic. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh component and […]

The post TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks

Microsoft will start automatically enabling Memory Integrity protection on eligible Windows devices through quality updates beginning in October 2026. This change aims to strengthen defenses against kernel-level attacks by ensuring that only trusted kernel-mode code and drivers can run on supported systems. Memory Integrity is a security feature built on Virtualization-based Security (VBS), a Windows […]

The post Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New $7 SweepLED Gadget Detects Hidden Cameras With 94% Accuracy in 5 Seconds

Researchers have developed SweepLED, a smartphone-based hidden-camera detection system that uses a low-cost LED accessory and computer vision to identify concealed lenses in under five seconds. The system is detailed in the research paper titled “Hide-and-Sweep: Detecting Concealed Cameras via LED Illumination Sweeps.” It is designed to help users identify covert cameras hidden in common […]

The post New $7 SweepLED Gadget Detects Hidden Cameras With 94% Accuracy in 5 Seconds appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Avast Antivirus Zero-Day PoC Lets Attackers Dump SAM Database and Gain SYSTEM Shell

A public proof-of-concept (PoC) repository has revealed a local privilege escalation zero-day vulnerability in GenDigital’s Avast Antivirus. This vulnerability allows an attacker to dump the Windows Security Account Manager (SAM) database and launch a shell running as NT AUTHORITY\SYSTEM. The researcher behind the repository, known as MSNightmare, claims that the issue affects fully patched installations […]

The post Avast Antivirus Zero-Day PoC Lets Attackers Dump SAM Database and Gain SYSTEM Shell appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover

A high-severity vulnerability affecting over 5 million active WordPress installations could allow unauthenticated attackers to exploit stored SQL injection vulnerabilities, leading to remote code execution and complete website takeover. This issue, tracked as CVE-2026-19949, impacts the widely used All-in-One WP Migration and Backup plugin developed by ServMask. Wordfence has rated the vulnerability 8.8 out of […]

The post WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Sangoma Switchvox RCE Flaw Actively Exploited in Wild via Unauthenticated SQL Injection

Security researchers have reported active exploitation attempts targeting a critical vulnerability in Sangoma Switchvox, allowing unauthenticated attackers to execute code remotely via SQL injection. This vulnerability, tracked as CVE-2026-9586, affects internet-exposed Switchvox enterprise VoIP systems and was addressed in Switchvox version 8.4.0.2. Sangoma Switchvox RCE Flaw Zach Hanley, a researcher at Horizon3.ai, revealed that this […]

The post Sangoma Switchvox RCE Flaw Actively Exploited in Wild via Unauthenticated SQL Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌