Skip to content

ADMIN.FOUNDATION

  • Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI

    ·

    AI, cyber security, Cyber Security News

    A newly disclosed vulnerability known as Plugin4Shell reveals a supply chain weakness in major AI coding agents. This flaw allows attackers to replace trusted, SHA-pinned plugins with malicious code, enabling remote code execution without user interaction. Researchers Or Nevo, Dor Granat, and Niv Hoffman have identified that the issue impacts Anthropic Claude Code, OpenAI Codex, […]

    The post Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

    ·

    A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. “The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,”

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers Exploit MikroTik Vulnerabilities to Take Over MikroTik Routers Without Authentication

    ·

    cyber security, Cyber Security News, Vulnerabilities

    Attackers are actively exploiting a critical vulnerability chain dubbed MikroTrick to seize full administrative control of internet-exposed MikroTik RouterOS devices without valid credentials. CERT Polska disclosed six RouterOS vulnerabilities on September 5, 2026, warning that two critical vulnerabilities could be chained to take over publicly reachable routers. The Polish national CSIRT said it had confirmed […]

    The post Hackers Exploit MikroTik Vulnerabilities to Take Over MikroTik Routers Without Authentication appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • 12 Best Multi-Cloud Security Platforms Compared (2026): Features & Pricing

    ·

    Cyber Security News, Top 10

    Quick Answer: Multi-cloud doesn’t just triple your attack surface it triples your billing surface, and vendors price the same workload differently per provider. Wiz and Prisma Cloud sell one-contract parity; Microsoft publishes rates that now extend to AWS/GCP connectors; Fortinet and Check Point bundle into fabric ELAs; Aviatrix bills the network layer everyone else ignores. […]

    The post 12 Best Multi-Cloud Security Platforms Compared (2026): Features & Pricing appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • 12 Best CDR Solutions Compared (2026): Features & Pricing

    ·

    Cyber Security News, Top 10

    Quick Answer: Cloud detection has a real free floor Falco (OSS, on this list in its own right) plus usage-priced native services (GuardDuty-class) so paid CDR must justify itself on correlation and response speed. CrowdStrike, Wiz, and Palo Alto bill CDR inside platform units; Sysdig monetizes the Falco lineage; specialists Permiso (identity), Stream.Security (real-time model), […]

    The post 12 Best CDR Solutions Compared (2026): Features & Pricing appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • 12 Best SSPM Tools Compared (2026): Features & Pricing

    ·

    Cyber Security News, Top 10

    Quick Answer: SSPM bills two ways per employee (predictable, punishes big headcount) or per connected app (bounded, punishes SaaS sprawl) and your estate’s shape decides which is cheaper. AppOmni and Obsidian quote enterprise depth; CrowdStrike (Adaptive Shield) turned the pioneer into a Falcon module; Nudge, Wing, and Grip run discovery-led free/low tiers that reset entry […]

    The post 12 Best SSPM Tools Compared (2026): Features & Pricing appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • WordPress 7.1.1 Fixes 11 Security Flaws Including Stored XSS and Path Traversal

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    WordPress has released version 7.1.1, a maintenance and security update that addresses 11 vulnerabilities affecting core platform components, themes, REST API functionality, comments, XML-RPC, and plugin management. Site administrators are strongly urged to update immediately due to the potential impacts of stored cross-site scripting, authenticated path traversal, authorization bypasses, and information disclosure flaws. This release […]

    The post WordPress 7.1.1 Fixes 11 Security Flaws Including Stored XSS and Path Traversal appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Scammers Tell T-Mobile Users Their Rewards Are Expiring to Trick Them Into Clicking Phishing Links

    ·

    cyber security, Cyber Security News, Phishing

    A large-scale SMS phishing campaign is impersonating T-Mobile and warning recipients that their “rewards points” are about to expire, using fabricated balances, urgent deadlines, and lookalike redemption links to steal sensitive information. Security researchers have tracked the operation since early May 2026 and continue to observe new message variants despite a decline from its peak […]

    The post Scammers Tell T-Mobile Users Their Rewards Are Expiring to Trick Them Into Clicking Phishing Links appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

    ·

    Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. “Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites

    ·

    cyber security, Cyber Security News, Malware

    A suspected supply-chain compromise involving Brevo has exposed visitors and WordPress administrators across more than 100,000 websites to malware. Attackers allegedly abused Brevo-hosted JavaScript assets, signup forms, unsubscribe pages and chat widgets to distribute a WordPress backdoor and ClickFix social-engineering payloads. Brevo, formerly Sendinblue, disclosed a separate security incident on September 10 involving an SAML […]

    The post Hackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 2 3 4 5 … 1,126
Next Page

ADMIN.FOUNDATION

cybersecurity / defense / intelligence