Category: GBHackers

Critical vm2 Flaw Lets Attackers Bypass Sandbox and Execute Arbitrary Code in Node.js
27
Jan
2026

Critical vm2 Flaw Lets Attackers Bypass Sandbox and Execute Arbitrary Code in Node.js

A critical vulnerability in the vm2 JavaScript sandbox library (versions ≤ 3.10.0) enables attackers to bypass sandbox protections and execute…

ShinyHunters Group Targets Over 100 Enterprises, Including Canva, Atlassian, and Epic Games
27
Jan
2026

ShinyHunters Group Targets Over 100 Enterprises, Including Canva, Atlassian, and Epic Games

A surge in infrastructure deployment that mirrors the tactics of SLSH, a predatory alliance uniting three major threat actors: Scattered…

CISA Urges Public to Stay Alert Against Rising Natural Disaster Scams
27
Jan
2026

CISA Urges Public to Stay Alert Against Rising Natural Disaster Scams

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical advisory alerting the public to heightened risks of malicious…

G_Wagon NPM Package Exploits Users to Steal Browser Credentials with Obfuscated Payload
27
Jan
2026

G_Wagon NPM Package Exploits Users to Steal Browser Credentials with Obfuscated Payload

A highly sophisticated infostealer malware disguised as a legitimate npm UI component library has been targeting developers through the ansi-universal-ui…

Attackers Hijack GitHub Desktop Repo to Spread Malware via Official Installer
27
Jan
2026

Attackers Hijack GitHub Desktop Repo to Spread Malware via Official Installer

Threat actors have successfully exploited a design flaw in GitHub’s fork architecture to distribute malware disguised as the legitimate GitHub…

New Phishing Attack Exploits Vercel to Host and Deliver Remote Access Malware
27
Jan
2026

New Phishing Attack Exploits Vercel to Host and Deliver Remote Access Malware

A new phishing campaign abusing the Vercel hosting platform has been active since at least November 2025 and is becoming…

Apache Hadoop Flaw Could Trigger System Crashes or Data Corruption
26
Jan
2026

Apache Hadoop Flaw Could Trigger System Crashes or Data Corruption

A moderate out-of-bounds write vulnerability in Apache Hadoop’s HDFS native client that could allow attackers to trigger system crashes or…

SyncFuture Campaign Abuses Enterprise Security Tools to Deploy Malware
26
Jan
2026

SyncFuture Campaign Abuses Enterprise Security Tools to Deploy Malware

A sophisticated, multi-stage espionage campaign targeting Indian residents through phishing emails impersonating the Income Tax Department. The attack chain, tracked…

Microsoft Issues KB5078127 OOB Patch After Reports of Outlook Freezing and File System Instability
26
Jan
2026

Microsoft Issues KB5078127 OOB Patch After Reports of Outlook Freezing and File System Instability

Microsoft has released two critical out-of-band (OOB) security patches targeting widespread issues affecting Windows 11 users following January’s monthly security…

NetSupport Manager 0-Day Vulnerabilities Enable Remote Code Execution
26
Jan
2026

NetSupport Manager 0-Day Vulnerabilities Enable Remote Code Execution

Two critical 0-day vulnerabilities in NetSupport Manager that, when chained, allow unauthenticated remote code execution (RCE). The vulnerabilities were discovered…

New DPRK Interview Campaign Uses Fake Fonts to Deliver Malware
26
Jan
2026

New DPRK Interview Campaign Uses Fake Fonts to Deliver Malware

A dangerous new iteration of the “Contagious Interview” campaign that weaponizes Microsoft Visual Studio Code task files to distribute sophisticated…

The "Stanley" marketplace listing on a Russian cybercrime forum (Source : varonis).
26
Jan
2026

New Malware Toolkit Redirects Victims to Malicious Sites Without Changing the URL

A dangerous new malware toolkit is being sold on Russian cybercrime forums that can redirect victims to fake websites while…