Install
GBHackers Security | #1 Globally Trusted Cyber Security News Platform | GBhackers Offering Exclusive Cyber Security News Coverage, New Research papers & Technology Updates. gbhackers.com GBhackers Offering Exclusive Cyber Security News Coverage, New Research papers & Technology Updates.
- 263articles · 30d
- 3+ day agolatest article
- Aug 15, 2026earliest in window
- 40%with images
- 376avg words
- Computers & Electronics 178
- Science & Technology 159
- Software 127
- Conflict, War & Peace 76
- Crime & Law 70
- Software Dev. 56
- Internet & Telecom 41
- News 24
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- threatsday bulletin
- digital world
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
New AI Workflow Identity Hijacking Attack Lets Hackers Exfiltrate Sensitive Data
3+ day, 23+ hour ago (539+ words) Research published by Noma Labs researcher Sasi Levi reveals that this attack does not rely on prompt injection, stolen credentials, or jailbreaking an AI model. Instead, it exploits a fundamental authorization flaw: AI workflows can process untrusted input from low-privileged…...
Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
3+ day, 22+ hour ago (444+ words) Microsoft Security Research said it has observed the cloud-focused intrusions since May 2026. The campaign begins with a phone call or SMS sent to an employee’s personal device. Posing as IT support, the caller claims the target must urgently update a…...
New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners
3+ day, 20+ hour ago (557+ words) A phishing campaign that moves the credential-harvesting page out of attacker-controlled web infrastructure and into the victim’s browser. Unlike ordinary phishing kits, which host cloned login portals on domains that can eventually be detected and disrupted, this campaign delivers malicious…...
Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security.
4+ day, 19+ min ago (593+ words) The campaigns do not require a macOS vulnerability; instead, they abuse user trust by persuading victims to paste attacker-controlled commands into Terminal, sidestepping traditional file-centric protections. However, Russian-language artifacts observed in some samples do not establish attribution to a particular…...
Infostealers Target Claude, Cursor, Codex and Other AI Agents to Steal Credentials and Sensitive Data
5+ day, 45+ min ago (649+ words) Information-stealing malware is expanding its collection logic to target locally stored data from AI coding agents, including Claude, Cursor, Codex, Cline, Continue, and OpenCode. The shift puts developer credentials, Model Context Protocol configurations, prompt histories, project metadata, and potentially proprietary…...
Massive Redis Cryptojacking Campaign Hijacks Thousands of Linux Servers
5+ day, 2+ hour ago (569+ words) The campaign scans IPv4 address ranges for Redis services exposed to the internet, typically on TCP port 6379, then attempts to interact with instances that allow connections without authentication. Once access is obtained, the attackers use Redis’s administrative CONFIG SET command to…...
Fortinet FortiSandbox Vulnerability Allows Unauthenticated Attackers to Access Sensitive Information
5+ day, 35+ min ago (409+ words) Fortinet has disclosed a critical vulnerability involving improper access control in the FortiSandbox web interfaces. This issue could allow an unauthenticated remote attacker to access sensitive information by sending specially crafted HTTP requests. The vulnerability is tracked as CVE-2026-26084 and…...
Hackers Abuse Google Sheets as C2 in ClickFix Attacks to Steal Cryptocurrency
5+ day, 1+ hour ago (605+ words) The operation marks a significant evolution of ClickFix social engineering: rather than persuading users to execute PowerShell commands or install malware on an operating system, attackers manipulate them into running malicious code inside Chrome itself. The document claims to disclose…...
Hackers Create Domain Admin Account and Disable Security Tools Inside Windows Network
5+ day, 22+ hour ago (596+ words) A newly documented ransomware intrusion attributed to The Gentlemen shows how attackers can convert a foothold in a Windows environment into domain-wide control by elevating accounts, turning off endpoint defenses, and abusing trusted Active Directory infrastructure to distribute ransomware. The…...
Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs
5+ day, 18+ hour ago (634+ words) A human-operated intrusion campaign in which attackers abuse Microsoft Teams external collaboration to impersonate internal IT or helpdesk staff, persuade employees to grant remote control of their PCs, and then move toward critical enterprise infrastructure. The result is a hands-on-keyboard…...