Category: GBHackers

SolarWinds Web Help Desk Vulnerability Enables Privilege Escalation
23
Sep
2025

SolarWinds Web Help Desk Vulnerability Enables Privilege Escalation

A critical vulnerability in SolarWinds Web Help Desk (WHD) could allow attackers to escalate privileges and execute arbitrary code on…

New npm Malware Steals Browser Passwords via Steganographic QR Code
23
Sep
2025

New npm Malware Steals Browser Passwords via Steganographic QR Code

A novel npm package named fezbox has been uncovered by the Socket Threat Research Team as a sophisticated malware delivery…

Hackers Hijacking IIS Servers Using Malicious BadIIS Module to Serve Malicious Content
23
Sep
2025

Hackers Hijacking IIS Servers Using Malicious BadIIS Module to Serve Malicious Content

Leveraging a native IIS module named BadIIS, attackers manipulated search engine crawler traffic to poison search results and redirect legitimate…

U.S. Secret Service Shuts Down 300 SIM Servers and 100K SIM Cards Disabling Cell Towers
23
Sep
2025

U.S. Secret Service Shuts Down 300 SIM Servers and 100K SIM Cards Disabling Cell Towers

The U.S. Secret Service has dismantled a sophisticated network of electronic devices scattered across the New York tri-state area. These…

Threat Actors Breach Enterprise Infrastructure Within 18 Minutes of Initial Access
23
Sep
2025

Threat Actors Breach Enterprise Infrastructure Within 18 Minutes of Initial Access

Attackers are accelerating their foothold in corporate networks: over the past three months (June 1 to August 31, 2025), the…

2/3 of Organizations Fear Identity Attacks, But Blind Spots Remain
23
Sep
2025

2/3 of Organizations Fear Identity Attacks, But Blind Spots Remain

Austin, Texas, USA, September 23rd, 2025, CyberNewsWire New SpyCloud 2025 Identity Threat Report reveals dangerous disconnect between perceived security readiness…

Microsoft Publishes Guide for Certificate-Based Authentication in Windows Admin Center
23
Sep
2025

Microsoft Publishes Guide for Certificate-Based Authentication in Windows Admin Center

Microsoft has released comprehensive guidance for implementing certificate-based authentication in Windows Admin Center (WAC), providing administrators with enhanced security through…

Zloader Malware Used as Gateway for Ransomware Deployment in Corporate Networks
23
Sep
2025

Zloader Malware Used as Gateway for Ransomware Deployment in Corporate Networks

Zloader, a sophisticated Zeus-based modular trojan that first emerged in 2015, has undergone a significant transformation from its original banking-focused…

Beware of Fake Online Speedtest Apps with Hidden JavaScript Code
23
Sep
2025

Beware of Fake Online Speedtest Apps with Hidden JavaScript Code

These fake online speedtest applications prey on users seeking to measure their internet performance, yet they harbor hidden payloads that…

Russia Leveraging Cyber-Attacks as a Strategic Weapon Against Key Industries in Major Nations
23
Sep
2025

Russia Leveraging Cyber-Attacks as a Strategic Weapon Against Key Industries in Major Nations

In 2024, as the Russia-Ukraine war prolongs and military and economic cooperation between North Korea and Russia deepens, cyberspace has…

GitHub Introduces npm Security with Stronger Authentication and Trusted Publishing
23
Sep
2025

GitHub Introduces npm Security with Stronger Authentication and Trusted Publishing

Open source software powers much of today’s technology, enabling developers around the world to build and share tools, libraries, and…

Massive 22.2 Tbps DDoS Attack Sets New World Record
23
Sep
2025

Massive 22.2 Tbps DDoS Attack Sets New World Record

Cloudflare announced today that it has successfully mitigated the largest distributed denial-of-service (DDoS) attack ever recorded. The hyper-volumetric assault peaked…