Posts of last few hours
Threat actors impersonated Gen executives and major consulting firms in a targeted business email compromise-style operation that used forged non-disclosure agreements to isolate a legal employee and pressure the company into transferring €626,735.45 to a Hong Kong entity. Dubbed Phantom Deal, the campaign shows how financially motivated actors can abuse legitimate M&A processes, corporate history […]
The post Fake Acquisition Scam Uses Forged NDAs to Demand €626,000 Corporate Payment. appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Google has introduced Gemini 3.8 Flash, available to developers today, and a gated sibling, Gemini 3.8 Flash Cyber, reserved for vetted security teams. “Our 3rd Flash release in just 6 wks,” Google CEO Sundar Pichai said on X, adding that it makes sizable gains over 3.7 Flash in software engineering, agentic work, and multi-step reasoning. On the DeepSWE v1.1 benchmark, Google says it beats most larger frontier models at solving complex engineering problems end to … More →
The post Google’s Gemini 3.8 Flash takes on bigger AI models at a lower cost appeared first on Help Net Security.
A malicious ScreenConnect campaign in which rogue remote-access clients do more than provide attackers with hands-on control: modified clients can automatically push a multi-stage VBScript malware chain to newly connected Windows endpoints. Once deployed, the clients repeatedly spawned wscript.exe to execute four scripts 1.vbs, 2.vbs, 3.vbs, and 4.vbs from ScreenConnect-related temporary locations. The behavior is […]
The post Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
QR code phishing, widely known as “quishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images rather than placing clickable links directly in emails. The shift is helping attackers bypass traditional secure email gateways and move victims from managed corporate devices to less-protected smartphones. The company recorded an average of […]
The post QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Microsoft will start automatically enabling Memory Integrity protection on eligible Windows devices through quality updates beginning in October 2026. This change aims to strengthen defenses against kernel-level attacks by ensuring that only trusted kernel-mode code and drivers can run on supported systems. Memory Integrity is a security feature built on Virtualization-based Security (VBS), a Windows […]
The post Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Researchers have developed SweepLED, a smartphone-based hidden-camera detection system that uses a low-cost LED accessory and computer vision to identify concealed lenses in under five seconds. The system is detailed in the research paper titled “Hide-and-Sweep: Detecting Concealed Cameras via LED Illumination Sweeps.” It is designed to help users identify covert cameras hidden in common […]
The post New $7 SweepLED Gadget Detects Hidden Cameras With 94% Accuracy in 5 Seconds appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
A public proof-of-concept (PoC) repository has revealed a local privilege escalation zero-day vulnerability in GenDigital’s Avast Antivirus. This vulnerability allows an attacker to dump the Windows Security Account Manager (SAM) database and launch a shell running as NT AUTHORITY\SYSTEM. The researcher behind the repository, known as MSNightmare, claims that the issue affects fully patched installations […]
The post Avast Antivirus Zero-Day PoC Lets Attackers Dump SAM Database and Gain SYSTEM Shell appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
QR-code phishing, commonly known as quishing, is evolving beyond image-based payloads. Threat actors are now rendering scannable QR codes directly from HTML tables or text within email bodies, leaving no image attachment, embedded bitmap, or <img> element for traditional email scanners to inspect. The technique targets a structural blind spot in Secure Email Gateways (SEGs). […]
The post HTML-Rendered QR Phishing Evades Image Extraction and OCR-Based Email Scanning appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Latest Blog Posts
- 1 week 4 days ago
- 2 months 1 week ago
- 2 months 1 week ago
- 2 months 1 week ago
- 2 months 1 week ago
- 7 months ago
- 1 year ago
- 1 year ago
- 1 year 1 month ago
- 1 year 5 months ago