Posts of last few hours
Please support the site operations by clicking ads.
Threat actors are increasingly impersonating OpenAI’s ChatGPT service in credential-phishing campaigns, exploiting the growing use of generative AI across both enterprise and personal environments. A recently observed campaign uses a fraudulent subscription-payment notice to lure victims into disclosing OpenAI account credentials and potentially payment details through a convincing fake ChatGPT login page. The lure claims […]
The post ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Linux administrators are being urged to patch four newly disclosed local privilege escalation (LPE) vulnerabilities, collectively known as DirtyAH6, TUNderflow, PPPoEject, and DiagSpill. These vulnerabilities can allow attackers to corrupt kernel memory and gain root-level access on affected systems. The vulnerabilities are tracked under the following CVE identifiers: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121, and CVE-2026-74469. They affect […]
The post Linux Kernel Hit by 4 LPE Flaws Enabling Attackers to Gain Root Shell appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Most people can’t tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study. The company analyzed 1,722 participants worldwide, testing their ability to separate human comments from AI-generated ones in a social media setting. Overall, people caught just 40% of the bots placed in front of them. (Source: Surfshark) The bots that slipped by most often weren’t loud or aggressive. … More →
The post Bots with good manners are better at fooling people on social media appeared first on Help Net Security.
More than 100,000 WordPress sites using the Tutor LMS e-learning plugin were exposed to a high-severity remote code execution vulnerability that could allow low-privileged users to take control of vulnerable servers. The vulnerability was discovered on August 23, 2026, by Wordfence Argus, an AI-assisted vulnerability research agent, and validated by the Wordfence Threat Intelligence team. […]
The post Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
MikroTik router owners face a security problem after researchers reproduced a takeover chain that can hand an outsider full administrator control without a password. The attack, MikroTrick, targets exposed RouterOS devices through SSH and can turn a network gateway into an attacker-controlled foothold. The risk is serious because a router handles traffic entering and leaving […]
The post MikroTrick Attack Lets Hackers Gain Full Admin Control of MikroTik Routers Without Login appeared first on Cyber Security News.
A widespread text-message phishing campaign is posing as T-Mobile to pressure customers into visiting fraudulent reward-redemption pages. The messages claim that loyalty points are about to expire, turning an ordinary account reminder into a trap for login details, personal data, payment information, and verification codes. The activity has been tracked since early May 2026 and […]
The post Hackers Use Fake T-Mobile Rewards Expiry Texts to Lure Users to Phishing Sites appeared first on Cyber Security News.
Researchers have identified significant security and privacy risks across 61,500 abandoned Android Internet-of-Things (IoT) companion applications. Their study found that 73.6% of these apps contained at least one potential vulnerability, risky embedded resource, or insecure communication path. Risks in Abandoned IoT Apps Titled “When Apps Outlive Vendors: Security Implications of IoT Abandonware,” the study examines […]
The post Researchers Find Security Risks in 73.6% of 61,500 Abandoned IoT Apps appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Critical Unauthenticated RCE in Check Point Security Management (CVE-2026-91843) Overview Critical stack overflow (CVSS 9.8) in the unauthenticated login process […]
The post Weekly Threat Landscape Digest – Week 38 appeared first on HawkEye.
Latest Blog Posts
- 4 weeks ago
- 2 months 4 weeks ago
- 2 months 4 weeks ago
- 2 months 4 weeks ago
- 3 months ago
- 7 months 3 weeks ago
- 1 year 1 month ago
- 1 year 1 month ago
- 1 year 2 months ago
- 1 year 6 months ago