Category: GBHackers

BIND 9 Flaw Lets Attackers Crash Servers With Malicious DNS Records
22
Jan
2026

BIND 9 Flaw Lets Attackers Crash Servers With Malicious DNS Records

A critical vulnerability in BIND 9 exposes DNS servers to remote denial-of-service (DoS) attacks. Security firm ISC disclosed CVE-2025-13878 on…

NVIDIA CUDA Toolkit Flaw Allows Command Injection, Arbitrary Code Execution
22
Jan
2026

NVIDIA CUDA Toolkit Flaw Allows Command Injection, Arbitrary Code Execution

NVIDIA has patched critical vulnerabilities in its CUDA Toolkit that expose developers and GPU-accelerated systems to command injection and arbitrary…

Critical Vivotek Flaw Enables Remote Arbitrary Code Execution
22
Jan
2026

Critical Vivotek Flaw Enables Remote Arbitrary Code Execution

Akamai’s Security Intelligence and Response Team (SIRT) uncovered a serious command injection vulnerability in legacy Vivotek IoT camera firmware. Tracked…

New Osiris Ransomware Leverages Living Off the Land and Dual-Use Tools in Attacks
22
Jan
2026

New Osiris Ransomware Leverages Living Off the Land and Dual-Use Tools in Attacks

A newly discovered ransomware family, Osiris, targeted a major foodservice franchisee in Southeast Asia in November 2025. Despite sharing a…

ClearFake malware Exploits Proxy Execution to Run Malicious PowerShell Commands via Trusted Windows Feature
22
Jan
2026

ClearFake malware Exploits Proxy Execution to Run Malicious PowerShell Commands via Trusted Windows Feature

A sophisticated evolution of the ClearFake malware campaign has emerged, deploying advanced evasion techniques that abuse legitimate Windows components to…

New AI-Powered Android Malware Automatically Clicks Ads on Infected Devices
22
Jan
2026

New AI-Powered Android Malware Automatically Clicks Ads on Infected Devices

A sophisticated new Android malware family dubbed “Android.Phantom” that leverages artificial intelligence to automate ad-clicking fraud while establishing a persistent…

New Multi-Stage Windows Malware Disables Microsoft Defender, Deploys Malicious Payloads
22
Jan
2026

New Multi-Stage Windows Malware Disables Microsoft Defender, Deploys Malicious Payloads

A sophisticated multi-stage malware campaign targeting Russian users, leveraging social engineering, legitimate cloud services, and native Windows functionality to achieve…

Malicious PyPI Package Impersonates sympy-dev, Targeting Millions of Users
22
Jan
2026

Malicious PyPI Package Impersonates sympy-dev, Targeting Millions of Users

A dangerous supply-chain attack targeting the Python Package Index (PyPI) that involves a malicious package named sympy-dev impersonating SymPy, one…

New ClickFix Campaign Exploits Fake Verification Pages to Hijack Facebook Sessions
22
Jan
2026

New ClickFix Campaign Exploits Fake Verification Pages to Hijack Facebook Sessions

A sophisticated ClickFix campaign targeting Facebook users has been identified, leveraging social engineering to extract live session credentials directly from…

Cisco Unified Communications Zero-Day RCE Flaw Actively Exploited For Root Shell Access
22
Jan
2026

Cisco Unified Communications Zero-Day RCE Flaw Actively Exploited For Root Shell Access

Cisco has warned customers of a critical zero-day vulnerability affecting several of its Unified Communications products, including Cisco Unified Communications…

Active Exploitation Of Fortinet SSO Flaw Targets Firewalls For Admin Takeover
22
Jan
2026

Active Exploitation Of Fortinet SSO Flaw Targets Firewalls For Admin Takeover

Threat actors actively exploit critical Fortinet vulnerabilities CVE-2025-59718 and CVE-2025-59719 to bypass FortiCloud SSO authentication on firewalls and proxies. These…

Researchers Expose LockBit 5.0 Affiliate Panel and New Encryption Variants
22
Jan
2026

Researchers Expose LockBit 5.0 Affiliate Panel and New Encryption Variants

LockBit 5.0 affiliate panel provide unprecedented visibility into the infrastructure of one of the world’s most notorious ransomware-as-a-service (RaaS) operations….