Visualização normal

Hoje — 11 de Setembro de 2026Stream principal

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to distribute malware at scale. The cluster, tracked as CL-CRI-1171, is linked to more than 10,000 distinct samples of a custom loader called OfferLoader, indicating a distribution pipeline far larger than the individual intrusions initially observed. Rather than relying on a […]

The post Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also for large language model-powered tools increasingly used to triage suspicious code. ESET researchers linked the activity to Russia-aligned threat actor UAC-0099, which used the method during an attack against an organization in Ukraine. The group inserted a safety-sensitive, weapon-related request […]

The post Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks

A newly observed IoT malware family dubbed KATARU targets internet-exposed devices through Telnet credential brute-forcing, then attempts to gain root privileges with publicly available Linux kernel exploits before enrolling compromised systems in a DDoS botnet. The sample combines familiar Mirai-style flooding functions with encrypted command-and-control, broad persistence logic, anti-analysis checks and decoy network activity designed […]

The post New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ontem — 10 de Setembro de 2026Stream principal

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted the widely documented default master key, sk-1234, or required no authentication, creating a direct path to LLMjacking, sensitive credential exposure, and in vulnerable versions root-level code execution inside the gateway container. Their internet scan of 3,074 publicly reachable instances found that 294 systems, or 9.6%, accepted […]

The post Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto VI by pushing fraudulent “leaked” game downloads that install a layered malware bundle that steals browser credentials, Discord tokens, gaming-session data, and cryptocurrency-related information. A Chaos ransomware variant used as a wiper, and an unexpected Yandex Browser installer. The campaign demonstrates how cybercriminals are turning one […]

The post Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out of attacker-controlled web infrastructure and into the victim’s browser. Unlike ordinary phishing kits, which host cloned login portals on domains that can eventually be detected and disrupted, this campaign delivers malicious content assembled only after a user follows the attack chain. A blob URL is a […]

The post New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts

Threat actors are impersonating corporate IT helpdesk staff in an active social-engineering campaign that hijacks Microsoft 365 identities, establishes MFA persistence, and systematically collects data from SharePoint, OneDrive, and Exchange Online. Microsoft Security Research said it has observed the cloud-focused intrusions since May 2026. The activity is marked by unusual sign-ins, attacker-added authentication methods, extensive […]

The post Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Antes de ontemStream principal

Iran-Linked Hackers Use Fake LinkedIn Job Offers to Deploy NodeRabbit and PollCat RATs

Iran-linked cyberespionage group Mirage Kitten is targeting software engineers with fake recruiter outreach on LinkedIn and job-search platforms. Using trojanized coding assessments to deploy two previously undocumented cross-platform remote access trojans: NodeRabbit and PollCat. The campaign targets developer workstations across Windows, Linux, and macOS, with victims identified in aviation, aerospace, and fintech organizations in Egypt, […]

The post Iran-Linked Hackers Use Fake LinkedIn Job Offers to Deploy NodeRabbit and PollCat RATs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical ArangoDB Bugs Expose Entire Databases and Enable Remote Code Execution as Root

Two critical ArangoDB vulnerabilities can allow unauthenticated attackers to access protected database APIs and, after obtaining valid database access, escalate to root-level code execution on affected hosts. Security researchers reported the vulnerabilities to ArangoDB on August 23, 2026. Patches shipped on August 31, followed by GitHub Security Advisories published on September 6: GHSA-rrgq-978q-36mq for the […]

The post Critical ArangoDB Bugs Expose Entire Databases and Enable Remote Code Execution as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks

GoldFactory has expanded the evasion capabilities of its Gigabud Android banking trojan by deploying Vwork, a weaponized fork of the open-source Shelter application. The companion tool abuses Android Work Profile isolation to clone banking apps into a separate managed environment, weakening the link between malware signals detected in a victim’s personal profile and fraudulent activity […]

The post GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Weaponize Agentic AI to Automate Reconnaissance, Exploitation and Post-Exploitation

Threat actors are increasingly operationalizing agentic artificial intelligence to compress cyberattack timelines, automating reconnaissance, vulnerability research, exploit development and credential theft with far less hands-on-keyboard activity. However, current evidence points to semi-autonomous, human-supervised attack chains rather than fully independent AI-driven intrusions in the wild. Agentic AI represents a material shift from conventional generative-AI abuse. Rather […]

The post Hackers Weaponize Agentic AI to Automate Reconnaissance, Exploitation and Post-Exploitation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Claude Mythos Executes End-to-End Intrusion From Initial Access to Full Domain Compromise

Anthropic’s Claude Mythos Preview has demonstrated the ability to complete an end-to-end enterprise intrusion simulation, progressing from initial access through chained exploitation and network traversal to the defined compromise objective. The result marks a material shift in frontier-model cyber capability: the model did not merely solve isolated CTF-style tasks, but autonomously connected weaknesses commonly found […]

The post Claude Mythos Executes End-to-End Intrusion From Initial Access to Full Domain Compromise appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials

A large-scale phishing operation is abusing trusted Google services as a multi-stage redirect network to bypass email security controls, deliver highly personalized credential-harvesting pages, and, in some cases, install ScreenConnect remote-access software. The campaign’s central advantage is that it presents trusted Google-owned domains at nearly every point a gateway, proxy, or analyst is likely to […]

The post Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks

A newly analyzed Linux malware sample, dubbed Tengu, combines Mirai-style botnet tradecraft with broad persistence, DDoS, SSH probing, and proxy capabilities. The stripped 32-bit ELF masquerades as a Linux kernel worker process while targeting servers, embedded devices, and IoT-adjacent systems. It has no symbols, uses NX protection and partial RELRO, and carries a SHA-256 hash […]

The post Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

BYOTC Attack Abuses Trusted Windows Clients to Access Privileged Kernel Driver Operations

A newly documented Windows attack pattern, dubbed Bring Your Own Trusted Caller (BYOTC), shows how attackers can bypass driver-level authorization controls without exploiting a traditional memory-corruption flaw. Instead of attacking a privileged kernel driver directly, an adversary compromises or abuses the legitimate user-mode application that the driver already trusts. The technique expands on the well-known […]

The post BYOTC Attack Abuses Trusted Windows Clients to Access Privileged Kernel Driver Operations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors

The financially motivated threat actor Toy Ghouls has expanded its custom malware arsenal with two Windows backdoors that abuse HiveMQ’s public MQTT infrastructure and the Matrix-based Element messaging ecosystem for command-and-control communications. The development marks a notable evolution for the group, which previously leaned on publicly available tools and leaked ransomware builders before introducing its […]

The post Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft

A major upgrade to the Python-based NodeStealer malware, transforming the Facebook-focused infostealer into a broader spyware platform capable of logging keystrokes, monitoring clipboard data, capturing screenshots, and harvesting extensive Facebook profile information. The newly observed variant, identified in August 2026, also expands browser and local data theft, using a split Telegram command-and-control (C2) design to […]

The post NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Abuse AI-Era ASCII Smuggling to Hide Phishing Content in Millions of Emails

Threat actors have repurposed an AI prompt-injection technique known as ASCII smuggling to evade email security controls at massive scale, hiding invisible Unicode characters within financial phishing lures. Microsoft observed the activity reach more than 2.3 million messages per day, demonstrating how techniques first popularized in AI-security research can quickly migrate into conventional phishing operations. […]

The post Hackers Abuse AI-Era ASCII Smuggling to Hide Phishing Content in Millions of Emails appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Chinese-Speaking Hackers Use Claude, Qwen and DeepSeek AI Agents to Attack Government Systems

Chinese-speaking threat operators have been observed using Claude, Qwen and DeepSeek-powered AI agents as operational components in a second intrusion campaign targeting government, political, education and industrial organizations across Asia. The campaign is distinct from an earlier operation reported in July that used Claude Code and DeepSeek against government and financial-sector targets. In this newer […]

The post Chinese-Speaking Hackers Use Claude, Qwen and DeepSeek AI Agents to Attack Government Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials

A Microsoft 365 email security-control bypass that lets attackers submit unauthenticated messages posing as internal users by leaving one SMTP field blank. The technique targets Exchange Online’s RejectDirectSend setting and does not represent a vulnerability in Microsoft software or in ReliaQuest systems; instead, it exposes a limitation in how the control evaluates Direct Send traffic. […]

The post Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌