• Hackers are actively exploiting two severe authentication bypass vulnerabilities in Qinglong, a popular open-source task scheduling platform. These flaws allow attackers to execute arbitrary code and deploy resource-draining cryptomining malware on vulnerable servers. Qinglong is a self-hosted task management platform used by developers to automate background tasks using Python, JavaScript, Shell, and TypeScript scripts. With […]

    The post Qinglong Task Scheduler RCE Flaws Exploited in the Wild appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Linux Kernel Vulnerability “Copy Fail” lets attackers gain root access via memory flaw. Patch now or disable algif_aead to stay secure.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has addressed a maximum severity security flaw in Gemini CLI — the “@google/gemini-cli” npm package and the “google-github-actions/run-gemini-cli” GitHub Actions workflow — that could have allowed attackers to execute arbitrary commands on host systems. “The vulnerability allowed an unprivileged external attacker to force their own malicious content to load as Gemini configuration,”

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers have identified a severe supply chain attack targeting the SAP developer ecosystem. A threat group identified as TeamPCP has compromised multiple legitimate SAP npm packages in a new campaign named Mini Shai Hulud. The operation relies on injecting malicious pre-install scripts that execute silently during dependency installation. By leveraging a multi-stage payload, the […]

    The post Compromised SAP npm Packages Found Harvesting Developer and CI/CD Secrets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • SonicWall has released a security advisory detailing three new vulnerabilities affecting its SonicOS software. Disclosed on April 29, 2026, under advisory ID SNWLID-2026-0004, these security flaws open the door for attackers to bypass access controls, manipulate restricted files, and intentionally crash critical firewall infrastructure. The most severe of the three bugs carries a high-severity score, […]

    The post SonicWall SonicOS Flaw Lets Attackers Bypass Access Controls and Crash Firewalls appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly disclosed flaw in ProFTPD is drawing urgent attention because it can let attackers move from a simple SQL injection bug to authentication bypass, privilege escalation, and in some environments even remote code execution. Tracked as CVE-2026-42167, the issue was found in ProFTPD’s mod_sql extension by ZeroPath Research, and MITRE assigned it a CVSS […]

    The post ProFTPD SQL Injection Flaw Opens Door To Remote Code Execution Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers have disclosed a critical zero-day vulnerability in the Linux kernel dubbed “Copy Fail” (CVE-2026-31431), which allows unprivileged local users to gain root access. Using a tiny 732-byte Python script, attackers can exploit a logic flaw present in major Linux distributions released since 2017. Copy Fail is a local privilege escalation (LPE) vulnerability found […]

    The post Linux Kernel 0-Day “Copy Fail” Grants Root Access Across Major Distros Since 2017 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • PocketOS founder says Cursor AI agent deleted its production database in 9 seconds after misusing a root API token, exposing major Railway security flaws.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Marine Corps may take its relationship with tiltrotor aircraft to the next level in the coming years with an attack platform to join the V-22 Osprey transport aircraft it’s been operating for the last two decades.

    The service is looking for aircraft to fill gaps as it prepares to retire its AV-8 Harriers and F/A-18A-C variants, then eventually replace UH-1 Venom and AH-1 Viper attack helicopters. The Army-developed MV-75 Cheyenne II is a possibility, the Corps’ assistant deputy commandant for aviation said Wednesday at the Modern Day Marine conference in Washington, D.C. 

    “So I would say we're exploring every option when it comes to the [Future Attack Strike] program,” Brig. Gen. Bob Finneran said during an update on the state of Marine Corps aviation. “MV-75, or the like, certainly could be one of the options that we look at.”

    With that in mind, Bell-Textron unveiled a miniature model of its tiltrotor aircraft on the conference’s show floor Tuesday, armed with missiles and painted to look like it belongs to Marine Light Attack Squadron 267, which currently flies Venoms and Vipers. 

    “We're just solidifying our top-level requirements and finalizing the request for information back from industry,” Finneran said.

    The Army selected the MV-75 to be its Future Long-Range Assault Aircraft in 2022, announcing earlier this year that it planned to field prototypes to units for testing by the end of the year.

    That timeline is still somewhat flexible, the head of Army aviation told reporters earlier this month, but the service officially brought the airframe into the Army family with a naming ceremony April 17 at the Army Aviation Warfighting Summit in Nashville. 

    Bell’s offering would take the MV-75 from a transport platform—designed to take over troop transport missions from the UH-60 Black Hawk helicopter—to a first-of-its-kind attack tiltrotor that would provide close-air support or launch drones to protect troops on the ground or in the air. 

    The Future Attack Strike program will also explore what comes after the Osprey, Col. Richard Rusnok, who heads Marine aviation’s Cunningham Group, said Wednesday. 

    “The V-22 as I said, will remain a relevant platform into the 2050s and then, as we start to complete the FASt program, we will look at the next-generation assault support platform to replace the V-22, that will have many of the same attributes, as far as size as the current V-22 fleet with, obviously, advanced capabilities, to include potential advances in propulsion, sensors and things like that.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Defense Department has spent an estimated $25 billion in 60 days of operations against Iran so far, the Pentagon’s comptroller said during a congressional hearing Wednesday.

    The administration plans to send a supplemental budget request to Congress to cover spent munitions and operational costs once they’re more fully fleshed out, Jay Hurst, the official performing the duties of the Pentagon’s chief financial officer, told House Armed Services Committee lawmakers during testimony on the department’s 2027 budget request. 

    “Okay, interesting…I'm glad you answered that question, because we've been asking for a hell of a long time, and no one's given us the number,” Rep. Adam Smith, D-Wash., told Hurst. “So if you could get those details over to us, that would be great.”

    The hearing also marked the first time Defense Secretary Pete Hegseth and Gen. Dan Caine, the chairman of the Joint Chiefs of Staff, have publicly answered questions from Congress since Operation Epic Fury began Feb. 28. Lawmakers dug into the Pentagon’s most recent budget request, as well as the war with Iran, the blockade of the Strait of Hormuz, and the status of negotiations to end both. 

    “For the first time in over 40 years, we've been presented a budget that accounts for the true cost of American deterrence,” HASC Chairman Rep. Mike Rogers, D-Ala., said of the $1.5 trillion defense spending proposal for fiscal year 2027.

    Increases in acquisition funding, operations and maintenance balance both modernization and readiness, he said, compared to past budgets that made near-term readiness tradeoffs in favor of focusing funding toward new technology. 

    “This will enable us to truly catch up in our modernization efforts, by quickly fielding new munitions, aircraft, ships, land, space and autonomous systems to replenish and expand our arsenal,” Rogers said.

    But there are questions about how that 50-percent increase over last year’s budget will be spent. Last year, Hegseth promised during his first weeks in office that DoD would pass an audit by the end of the second Trump administration, but a Government Accountability Office report released last year found that the Pentagon hadn’t laid enough groundwork to change its accounting processes to meet that milestone.

    “I think last year's bill put us on a good trajectory to get to the point where we can, in fact, innovate faster at scale,” Smith said. “But we’ve got a long way to go. Can the Pentagon really absorb another five, $600 billion, depending on what the supplemental and the reconciliation package are? I don't think so. We need to pay as much attention to how we're spending the money as to how much we're spending, and we never seem to do that.”

    Smith then turned to the Iran war as a core reason to question how the Pentagon will spend the funding increase.

    “And one of the big questions that we need to get answered today is, where is this going? What is the plan to achieve our objectives? We've seen the cost, and the cost is very, very high,” Smith said. “All we keep hearing, on the objectives, is we keep seeing all of the targets that we have struck.”

    While that’s a laudable tactical accomplishment, he said, the stated purpose of the war has been to “fundamentally” change Iran, though the country continues to block the Strait of Hormuz and has not agreed to end its nuclear ambitions or conventional weapons programs.

    “And most disturbingly, the president keeps telling us that it's over. What was it? A week ago, Friday, the President announced that Iran had agreed to give up their nuclear program, to give up their ballistic missile program, to stop support for terrorist groups, to re-open the Strait of Hormuz,” Smith said. “The only problem with that is literally none of that was true. He was completely making it up. Iran hadn't even agreed to meet with us.” 

    Hegseth deflected criticism of the administration’s Iran war strategy to service members, accusing lawmakers who questioned his leadership of spreading propaganda and bristling at the charge that he is leading the U.S. into another “quagmire.”

    “The way you stain the troops when you tell them—two months in, Congressman—you should know better. Shame on you calling this a quagmire, two months into the effort, what they've undertaken, what they've succeeded, the success on the battlefield that could create strategic opportunities, the courage of a president to confront a nuclear Iran—and you call it a quagmire, handing propaganda to our enemies,” Hegseth said.

    But lawmakers clarified that their issue is with the overall strategy, not the performance of the military.

    “Their professionalism and selfless service are not in question and never have been,” Rep. Jim Garamendi, D-Calif., said. “What is in question is the purposes and the strategic direction of this war. Any unvarnished review of what is happening right now in the Middle East would reveal a geopolitical calamity, a strategic blunder resulting in worldwide economic crisis. The result of Trump's war of choice is a serious, self-inflicted wound to America. It will take years and a new administration to recover from the grave damage to our standing in the world, as well as our economy and our military.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶