Posts of last few hours
Please support the site operations by clicking ads.
Cybercriminals are rapidly rotating lure domains, cloud storage buckets and command-and-control channels, but one infrastructure component is proving far harder to replace: the bulletproof hosting network that delivers the initial fake verification page. Five months of monitoring linked four distinct malware delivery chains to AS202412, operated by OMEGATECH LTD, making the ASN not individual domains […]
The post Cybercriminals Abandon Domains but Keep the Hosting Networks Behind Malware Campaigns appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
SolarWinds has released SolarWinds Observability Self-Hosted version 2026.2.3 to address two critical remote code execution (RCE) vulnerabilities. These vulnerabilities could allow unauthenticated attackers to compromise exposed deployments under specific configurations. The vulnerabilities are tracked as CVE-2026-28324 and CVE-2026-28325, with CVSS severity scores of 9.8 and 8.8, respectively. This update was released on September 22, 2026, […]
The post SolarWinds Observability Flaws Let Unauthenticated Attackers Execute Remote Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
NVIDIA released a security update for its Infrastructure Controller software for Linux, addressing 14 vulnerabilities that could let attackers access sensitive system information, execute code, alter data, or disrupt affected environments. The update, published in NVIDIA’s September 2026 Infrastructure Controller security bulletin, affects versions 0 through 1.9. NVIDIA recommends that organizations clone or update the […]
The post NVIDIA Fixes Linux Component Flaws That Could Expose Sensitive System Information appeared first on Cyber Security News.
EvilTokens turns a Microsoft sign-in into a route to corporate email fraud. The phishing kit, first seen in February 2026, tricks people into approving an attacker’s login through a real device code process without handing over a password. The lure usually arrives as an urgent email about an invoice, shared file, document signature or expiring […]
The post The Phishing Kit That Turned Microsoft’s Login Flow Into an AI-Powered Fraud Machine appeared first on Cyber Security News.
Latest Blog Posts
- 1 month ago
- 3 months ago
- 3 months ago
- 3 months ago
- 3 months ago
- 7 months 3 weeks ago
- 1 year 1 month ago
- 1 year 1 month ago
- 1 year 2 months ago
- 1 year 6 months ago