Posts of last few hours
Please support the site operations by clicking ads.
A Windows-focused backdoor dubbed TASK#STOMP that uses VBScript, PowerShell, Scheduled Tasks, and runtime C# compilation to establish resilient persistence and continuously steal business documents. The implant also captures screenshots, extracts saved Wi-Fi passwords, harvests clipboard data, and executes arbitrary commands received from its operators. While the original delivery method is unconfirmed, the location is consistent […]
The post TASK#STOMP PowerShell Backdoor Steals Business Documents and Executes Remote Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Hackers are using convincing copies of trusted websites to turn an ordinary browser visit into a full Windows compromise. The campaign pairs targeted phishing emails with a chained set of previously unknown flaws in Google Chrome and Microsoft Windows, giving attackers a quiet path from a fake page to malware on a victim’s device. The […]
The post Hackers Clone Legitimate Websites to Silently Trigger Chrome and Windows Zero-Day Exploits appeared first on Cyber Security News.
A newly discovered privilege escalation flaw in Veeam Agent for Microsoft Windows could allow attackers with local access to compromised endpoints to execute commands as NT AUTHORITY\SYSTEM. Public proof-of-concept (PoC) code for CVE-2026-32996 was released on September 14, increasing the urgency for organizations to patch affected Veeam deployments. CVE-2026-32996 impacts Veeam Agent for Microsoft Windows […]
The post Hackers Exploit Veeam Agent Vulnerability to Gain SYSTEM-Level Access on Windows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
ANY.RUN researchers investigated CSuite, a phishing and remote-access operation that combines credential theft, Microsoft 365 session hijacking, and the abuse of legitimate management tools. The campaign showed a strong US focus, with 60% of identified victim organizations based in the United States. By blending trusted business services with legitimate remote-access software, CSuite can give attackers […]
The post CSuite Targets US and EU Organizations with Device-Code Phishing and Remote Access appeared first on ANY.RUN's Cybersecurity Blog.
Red Hat disclosed an important OpenShift vulnerability that could let attackers bypass release-image signature checks and introduce malicious payloads into disconnected registries. This issue, tracked as CVE-2026-75939, affects the `openshift/oc-mirror` tool and has a preliminary CVSS v3.1 score of 7.4. Administrators use `oc-mirror` to retrieve release images from upstream sources and then copy them to […]
The post Red Hat OpenShift Flaw Lets Attackers Poison Disconnected Registries With Malicious Releases appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Aikido Security has unveiled Altar-1, an open-weight artificial intelligence model designed to run defensive cybersecurity workloads entirely inside an organization’s own infrastructure. The model aims to help security teams use advanced AI for vulnerability discovery and penetration testing without sending source code, internal documentation, or security findings to external cloud-based inference services. Altar-1 is built […]
The post Aikido Security Unveils Altar-1 Open-Weight AI for Cybersecurity Defense appeared first on Cyber Security News.
A Linux variant of the BambooToken backdoor uses MQTT as its command-and-control channel, enabling operators to profile compromised hosts, execute shell commands, and transfer files through broker-mediated topics. Analysis of a statically linked x86-64 ELF sample shows that its configuration, task routing, and network payloads are obfuscated with separate XOR routines. The examined sample, SHA-256 […]
The post Linux BambooToken Malware Uses MQTT C2 for Remote Shell Access and File Exfiltration appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Latest Blog Posts
- 1 month ago
- 3 months ago
- 3 months ago
- 3 months ago
- 3 months ago
- 7 months 3 weeks ago
- 1 year 1 month ago
- 1 year 1 month ago
- 1 year 2 months ago
- 1 year 6 months ago