Category: GBHackers

HPE OneView Vulnerability Allows Remote Code Execution Attacks
19
Dec
2025

HPE OneView Vulnerability Allows Remote Code Execution Attacks

A severe security vulnerability has been discovered in Hewlett Packard Enterprise OneView software, threatening enterprise infrastructure across data centers and…

APT35 Leak Reveals Spreadsheets Containing Domains, Payments, and Server Information
19
Dec
2025

APT35 Leak Reveals Spreadsheets Containing Domains, Payments, and Server Information

Iranian cyber unit Charming Kitten, officially designated APT35, has long been dismissed as a noisy but relatively unsophisticated threat actor…

Beware of Malicious Scripts in Weaponized PDF Purchase Orders
19
Dec
2025

Beware of Malicious Scripts in Weaponized PDF Purchase Orders

A sophisticated phishing campaign utilizing a weaponized PDF document named “NEW Purchase Order # 52177236.pdf” has been identified, employing legitimate…

New Lazarus and Kimsuky Infrastructure Discovered with Active Tools and Tunneling Nodes
19
Dec
2025

New Lazarus and Kimsuky Infrastructure Discovered with Active Tools and Tunneling Nodes

Security researchers from Hunt.io and Acronis Threat Research Unit have uncovered a sophisticated network of operational infrastructure controlled by North…

RansomHouse RaaS Enhances Double Extortion with Data Theft and Encryption
19
Dec
2025

RansomHouse RaaS Enhances Double Extortion with Data Theft and Encryption

RansomHouse, a ransomware-as-a-service (RaaS) operation managed by the threat group Jolly Scorpius, has significantly enhanced its encryption capabilities, marking a…

Kimwolf Android Botnet Compromises 1.8 Million Devices Worldwide
18
Dec
2025

Kimwolf Android Botnet Compromises 1.8 Million Devices Worldwide

A newly discovered Android botnet dubbed “Kimwolf” has silently compromised over 1.8 million devices globally, primarily targeting Android TV boxes…

Cybercriminals Registering Fake Shopping Domains to Target Users This Holiday Season
18
Dec
2025

Cybercriminals Registering Fake Shopping Domains to Target Users This Holiday Season

As the global holiday shopping season reaches its peak, cybersecurity researchers have uncovered a massive, industrialized operation designed to defraud…

Phantom Stealer Targeting Users to Steal Sensitive Data
18
Dec
2025

Phantom Stealer Targeting Users to Steal Sensitive Data

Sophisticated malware employs a multi-stage infection chain and advanced evasion techniques to exfiltrate sensitive information. Phantom, a sophisticated stealer malware…

Critical Apache Commons Text Flaw Lets Hackers Execute Remote Code
18
Dec
2025

Critical Apache Commons Text Flaw Lets Hackers Execute Remote Code

A critical remote code execution vulnerability has been discovered in Apache Commons Text, affecting all versions prior to 1.10.0. The…

Chinese Ink Dragon Breaches European Government Networks, Affecting Asia and South America
18
Dec
2025

Chinese Ink Dragon Breaches European Government Networks, Affecting Asia and South America

Ink Dragon, a Chinese espionage group, has significantly expanded its operational reach from Southeast Asia and South America into European…

Hackers Actively Exploit SonicWall SMA1000 Zero-Day to Escalate Privileges
18
Dec
2025

Hackers Actively Exploit SonicWall SMA1000 Zero-Day to Escalate Privileges

SonicWall has issued an urgent security advisory warning of active exploitation of a local privilege escalation vulnerability affecting its SMA1000…

New Reports Reveal WAFs Are Ineffective Against Latest React2Shell Exploit
18
Dec
2025

New Reports Reveal WAFs Are Ineffective Against Latest React2Shell Exploit

TEL AVIV, Israel, Dec. 17, 2025 Miggo Security has released a comprehensive benchmark study revealing critical gaps in Web Application Firewall…