Posts of last few hours
Please support the site operations by clicking ads.
A newly identified device-code phishing kit dubbed GhostCode exploits Microsoft Entra device enrollment to maintain access after stolen tokens are revoked. GhostCode begins with business-email social engineering rather than a conventional credential-harvesting page. Operators impersonated procurement staff from legitimate organizations, including BJ’s Wholesale Club, and submitted benign inquiries through Salesforce contact forms. Once a sales […]
The post GhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
VectraRAT, a previously undocumented Malware-as-a-Service platform that combines remote-access trojan capabilities with automated credential theft and a silent Windows privilege-escalation chain. Unlike the large number of commodity RATs that recycle leaked AsyncRAT, XWorm, or QuasarRAT code, VectraRAT appears to be a purpose-built, full-stack product maintained by a single developer. The platform is rented rather than […]
The post VectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Security researchers have revealed two vulnerabilities in TP-Link’s Tapo C200 smart camera that could enable nearby network attackers to bypass administrator authentication or disrupt the device’s management service. Khoi Tran and Thai Do from OPSWAT Unit 515 discovered these vulnerabilities, tracked as CVE-2026-15315 and CVE-2026-15316, during the company’s Critical Infrastructure Cybersecurity Graduate Fellowship Program. TP-Link […]
The post TP-Link Tapo Camera Flaw Lets Attackers Gain Admin Access Without Password appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Chinese-speaking threat actors are continuing to rely on Noodle RAT, a cross-platform remote access trojan designed to maintain covert access to compromised Windows workstations and Linux servers. Also tracked as ANGRYREBEL and Nood RAT, the malware has been active since at least mid-2016 but was long mistaken for variants of Gh0st RAT, Rekoobe, and other […]
The post Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Stamford, CT, September 16th, 2026, CyberNewswire Now in early access, AxoDetect runs Sigma rules in stream alerts travel to the SIEM, and full-fidelity logs land in AxoLake, a low-cost security data lake Detection engineers do not need more detections. They need their existing detections to fire earlier, on cleaner data, without paying SIEM ingest rates […]
The post Axoflow Launches AxoDetect, Bringing Detection Into the Pipeline and Making the SIEM Optional appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
A large-scale SMS phishing campaign linked to the Smishing Triad is using a sophisticated phishing kit dubbed JWR to harvest payment-card data, one-time passwords, online-banking credentials, identity information, and digital-wallet logins. Group-IB attributed the activity to an operator sub-cluster tracked as Outsider, which appears to operate as a customer within the wider phishing-as-a-service ecosystem rather […]
The post Smishing Triad Hackers Use JWR Phishing Kit to Steal Cards, OTPs and Bank Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CenterPoint Energy has confirmed that an unauthorized third party accessed personal information belonging to some of its customers by compromising one of the utility provider’s external systems. The Houston-based energy company disclosed the incident in a Form 8-K filing with the U.S. Securities and Exchange Commission dated September 14, 2026. CenterPoint learned of the potential […]
The post CenterPoint Energy Confirms Data Breach Exposing Customers’ Personal Information appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
A critical local privilege escalation vulnerability in Parallels Desktop could allow an unprivileged macOS user or a malicious process to gain root-level access to the host system. The issue, tracked as CVE-2026-90894, was disclosed by Yuval Moravchick from JFrog’s Vulnerability Research team and has been named “ParaShells.” This flaw was demonstrated against Parallels Desktop version […]
The post Parallels Desktop Flaw Lets Unprivileged Mac Users Gain Root Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Latest Blog Posts
- 3 weeks 3 days ago
- 2 months 3 weeks ago
- 2 months 3 weeks ago
- 2 months 3 weeks ago
- 2 months 3 weeks ago
- 7 months 2 weeks ago
- 1 year 1 month ago
- 1 year 1 month ago
- 1 year 2 months ago
- 1 year 6 months ago