Category: GBHackers

Critical HashiCorp Vault Vulnerabilities Allow Authentication Bypass and DoS Attacks
27
Oct
2025

Critical HashiCorp Vault Vulnerabilities Allow Authentication Bypass and DoS Attacks

HashiCorp has disclosed two critical vulnerabilities in Vault and Vault Enterprise that could enable attackers to bypass authentication mechanisms and…

Coordinated Cyberattacks Seek to Cripple Critical Infrastructure
27
Oct
2025

Coordinated Cyberattacks Seek to Cripple Critical Infrastructure

A sophisticated cyber-sabotage group known as Predatory Sparrow has emerged as one of the most destructive threat actors targeting Iranian…

North Korean Chollima Actors Added BeaverTail and OtterCookie to its Arsenal
27
Oct
2025

North Korean Chollima Actors Added BeaverTail and OtterCookie to its Arsenal

Famous Chollima, a DPRK-aligned threat group, has evolved its arsenal, with BeaverTail and OtterCookie increasingly merging functionalities to steal credentials…

Qilin Ransomware Exploits MSPaint and Notepad to Locate Sensitive Files
27
Oct
2025

Qilin Ransomware Exploits MSPaint and Notepad to Locate Sensitive Files

In the latter half of 2025, the Qilin ransomware group has solidified its standing as a formidable threat, continuing to…

Critical CoPhish Exploit Uses Copilot Studio to Hijack OAuth Tokens
27
Oct
2025

Critical CoPhish Exploit Uses Copilot Studio to Hijack OAuth Tokens

Security researchers at Datadog have uncovered a sophisticated phishing technique that weaponizes Microsoft Copilot Studio to conduct OAuth token theft…

Microsoft Adds Wi-Fi-Based Work Location Auto-Detection to Teams
27
Oct
2025

Microsoft Adds Wi-Fi-Based Work Location Auto-Detection to Teams

Microsoft is preparing to introduce a groundbreaking feature in Teams that will revolutionise how hybrid workers manage their presence information….

WhatsApp 0-Click Exploit Disclosed to Meta at Pwn2Own Security Event
27
Oct
2025

WhatsApp 0-Click Exploit Disclosed to Meta at Pwn2Own Security Event

Cybersecurity researchers from Team Z3 have withdrawn their planned demonstration of a zero-click remote code execution vulnerability in WhatsApp at…

706,000+ BIND 9 DNS Resolvers Exposed to Cache Poisoning
27
Oct
2025

706,000+ BIND 9 DNS Resolvers Exposed to Cache Poisoning

A critical vulnerability affecting more than 706,000 BIND 9 DNS resolvers worldwide has been disclosed with proof-of-concept exploit code now…

Hackers Use ClickFix Technique to Deploy NetSupport RAT Loaders
25
Oct
2025

Hackers Use ClickFix Technique to Deploy NetSupport RAT Loaders

Cybercriminals are increasingly using a technique known as “ClickFix” to deploy the NetSupport remote administration tool (RAT) for malicious purposes….

Hackers Exploit WordPress Arbitrary Installation Vulnerabilities in the Wild
25
Oct
2025

Hackers Exploit WordPress Arbitrary Installation Vulnerabilities in the Wild

Cybersecurity firm Wordfence has uncovered a renewed wave of mass exploitation targeting critical vulnerabilities in two popular WordPress plugins, allowing…

CISA Beware! Hackers Are Actively Exploiting Windows Server Update Services RCE Flaw in the Wild
25
Oct
2025

CISA Beware! Hackers Are Actively Exploiting Windows Server Update Services RCE Flaw in the Wild

Cybersecurity researchers are sounding the alarm after discovering that hackers are actively exploiting a critical remote code execution (RCE) vulnerability…

New RedTiger Tool Targets Gamers and Discord Accounts in the Wild
24
Oct
2025

New RedTiger Tool Targets Gamers and Discord Accounts in the Wild

Gamers face a growing threat from cybercriminals exploiting popular gaming and communication platforms. A dangerous infostealer called RedTiger is now…