Category: GBHackers

Researchers Warn of ‘Smiao Network’ Cyber Threat Against Taiwan’s Federal Staff
22
May
2025

Researchers Warn of ‘Smiao Network’ Cyber Threat Against Taiwan’s Federal Staff

The Foundation for Defense of Democracies (FDD) and cybersecurity firm TeamT5 has exposed an intricate Chinese intelligence operation, dubbed the…

Cityworks Zero-Day Vulnerability Used by UAT-638 Hackers to Infect IIS Servers with Shell Malware
22
May
2025

Cityworks Zero-Day Vulnerability Used by UAT-638 Hackers to Infect IIS Servers with Shell Malware

Cisco Talos has uncovered active exploitation of a zero-day remote-code-execution vulnerability, identified as CVE-2025-0994, in Cityworks, a widely used asset…

Hackers Deploy Weaponized npm Packages to Target React and Node.js JavaScript Frameworks
22
May
2025

Hackers Deploy Weaponized npm Packages to Target React and Node.js JavaScript Frameworks

Socket’s Threat Research Team, a series of malicious npm packages have been found lurking in the JavaScript ecosystem for over…

Linux Kernel Zero-Day SMB Vulnerability Discovered via ChatGPT
22
May
2025

Linux Kernel Zero-Day SMB Vulnerability Discovered via ChatGPT

Security researcher has discovered a zero-day vulnerability (CVE-2025-37899) in the Linux kernel’s SMB server implementation using OpenAI’s o3 language model….

Cisco Unified Intelligence Center Vulnerability Allows Privilege Escalation
22
May
2025

Cisco Unified Intelligence Center Vulnerability Allows Privilege Escalation

Cisco has disclosed two security vulnerabilities in its Unified Intelligence Center that could allow authenticated remote attackers to escalate privileges….

New NIST Security Metric Aims to Pinpoint Exploited Vulnerabilities
22
May
2025

New NIST Security Metric Aims to Pinpoint Exploited Vulnerabilities

Researchers from the National Institute of Standards and Technology (NIST) and the Cybersecurity and Infrastructure Security Agency (CISA) have introduced…

Attackers Exploit BIND DNS Server Vulnerability to Crash Servers Using Malicious Packets
22
May
2025

Attackers Exploit BIND DNS Server Vulnerability to Crash Servers Using Malicious Packets

The vulnerability in BIND DNS server software allowed attackers to crash DNS servers by sending specifically crafted malicious packets. This…

Grafana Zero-Day Vulnerability Allows Attackers to Redirect Users to Malicious Sites
22
May
2025

Grafana Zero-Day Vulnerability Allows Attackers to Redirect Users to Malicious Sites

The High-severity cross-site scripting (XSS) vulnerability has been discovered in Grafana, prompting the immediate release of security patches across all…

Cisco Identity Services RADIUS Vulnerability Allows Attackers to Trigger Denial of Service Condition
22
May
2025

Cisco Identity Services RADIUS Vulnerability Allows Attackers to Trigger Denial of Service Condition

Cisco has disclosed a significant security vulnerability in its Identity Services Engine (ISE) that could enable unauthenticated remote attackers to…

Several GitLab Vulnerabilities Enable Attackers to Launch DoS Attacks
22
May
2025

Several GitLab Vulnerabilities Enable Attackers to Launch DoS Attacks

GitLab has issued critical security patches addressing 11 vulnerabilities across its Community Edition (CE) and Enterprise Edition (EE) platforms, with…

Hackers Exploit PyBitmessage Library to Evade Antivirus and Network Security Detection
22
May
2025

Hackers Exploit PyBitmessage Library to Evade Antivirus and Network Security Detection

The AhnLab Security Intelligence Center (ASEC) has uncovered a new strain of backdoor malware being distributed alongside a Monero coin…

Versa Concerto 0-Day Flaw Enables Remote Code Execution by Bypassing Authentication
22
May
2025

Versa Concerto 0-Day Flaw Enables Remote Code Execution by Bypassing Authentication

Security researchers have uncovered multiple critical vulnerabilities in Versa Concerto, a widely deployed network security and SD-WAN orchestration platform used…