• Microsoft has rolled out a fresh security intelligence update for Microsoft Defender Antivirus to help secure Windows 11, Windows 10, and Windows Server images. Released on April 7, 2026, this update equips endpoints with the latest threat detection logic and AI-enhanced cloud protection to defend against emerging malware campaigns. Keeping antimalware solutions up to date […]

    The post New Microsoft Defender Update Issued for Windows 11, Windows 10, and Server Images appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat actors are exploiting a maximum-severity security flaw in Flowise, an open-source artificial intelligence (AI) platform, according to new findings from VulnCheck. The vulnerability in question is CVE-2025-59528 (CVSS score: 10.0), a code injection vulnerability that could result in remote code execution. “The CustomMCP node allows users to input configuration settings for connecting

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft is warning that a fast‑moving threat actor it tracks as Storm‑1175 is aggressively exploiting vulnerabilities in internet‑exposed systems to deliver Medusa ransomware in days and sometimes in under 24 hours. Storm‑1175 is a financially motivated group known for high‑velocity ransomware operations that weaponize recently disclosed, or “N‑day”, vulnerabilities in web‑facing services. The actor focuses […]

    The post Microsoft Warns Storm-1175 Exploiting Web-Facing Vulnerabilities to Deploy Medusa Ransomware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A severe security flaw has been discovered in the Ninja Forms File Upload plugin, a widely utilized WordPress add-on that allows website administrators to accept documents, images, and other media from their visitors. Tracked officially as CVE-2026-0740, this unauthenticated arbitrary file upload vulnerability carries a maximum critical CVSS score of 9.8. With an estimated 50,000 […]

    The post 50,000 WordPress Sites Running Ninja Forms Vulnerable to Critical File Upload RCE appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical zero-day vulnerability in Fortinet products. The agency officially added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on April 6, 2026, indicating that threat actors are actively exploiting it in the wild. The CISA KEV catalog serves as a […]

    The post CISA Alerts Defenders to Actively Exploited Fortinet Zero-Day Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new malware campaign is abusing Reddit to distribute fake “cracked” builds of TradingView Premium that secretly install Vidar and AMOS information‑stealing malware on Windows and macOS systems. The campaign targets users searching for free or pirated versions of TradingView Premium, a popular browser‑based charting and social platform for stock, crypto, and forex traders. Threat […]

    The post Fake TradingView Premium Reddit Posts Spread Vidar and AMOS Stealers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly discovered zero-day vulnerability, dubbed “BlueHammer,” has been publicly disclosed. The flaw, which has been linked to Windows Defender, allows attackers to achieve Local Privilege Escalation (LPE) and potentially gain full administrative access to compromised systems. Because a patch is not yet available from Microsoft, this public release leaves Windows users temporarily exposed to […]

    The post Windows Defender 0-Day Published Online, Giving Attackers Potential Full Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • General Atomics’ has paused all flight tests and opened an investigation after one of its drone wingmen crashed Monday after takeoff, the company said in a news release. 

    One of General Atomics’ YFQ-42A “Dark Merlin” Collaborative Combat Aircraft “experienced a mishap” at its company-owned airport in California around 1 p.m. local time, the news release said. No one was injured in the incident. Flight testing will resume when it is “deemed appropriate,” the company added, providing no timeline. 

    “Flight test operations have been paused temporarily in an abundance of caution,” the news release said. “As with any program, we follow a disciplined investigation process to understand exactly what occurred, and our focus right now is on gathering data and ensuring we learn from this event.”

    General Atomics is competing against Anduril and Northrop Grumman in the Air Force’s collaborative combat aircraft competition. The incident with the drone wingman comes as the service prepares to award an Increment 1 production decision in the next six months. The Defense Department is seeking nearly $1 billion to buy the Air Force’s first CCAs, the 2027 budget documents released on Friday show. 

    The YFQ-42A involved in the crash was one of several production-representative CCAs being made for the Air Force, the company said. 

    “Safety is our top priority, for our people and the public. In this case, established procedures and safeguards worked as intended, and there were no injuries,” said C. Mark Brinkley, a company spokesman. “We’re going to take a close look at what happened, gather all the data, and allow the investigation to guide us moving forward.”

    The Air Force is “aware of the incident and will follow all standard aircraft mishap protocols,” a service spokesperson said in an emailed statement. 

    An Anduril spokesperson said “all of our airplanes are fine.” A Northrop Grumman spokesperson did not immediately return a request for comment. 

    Anduril, General Atomics, and Northrop have all rapidly been developing their own CCA offerings in hopes of winning the Air Force’s contract.

    Last month, Northrop Grumman announced it successfully tested Shield AI’s Hivemind software on its YFQ-48A Talon Blue CCA. 

    In February, Anduril started armed flight testing with its CCA. That same month, the Air Force validated its government-owned Autonomy Government Reference Architecture to use RTX Collins software aboard General Atomics’ YFQ-42 CCA aircraft and Shield AI’s Hivemind onboard Anduril's YFQ-44 CCA. Anduril also completed its first semi-autonomous flight and was able to switch between Shield AI and its own mission autonomy software suites mid-air.

    Rebecca Wasser, the defense lead at Bloomberg Economics, said it was “commendable” of General Atomics to stop flight tests for security and safety reasons. She added that the incident is unlikely to have a major effect on the competition, especially given Defense Secretary Pete Hegseth’s reforms to the military’s testing and evaluation ecosystem.

    “I don't think it changes the nature of the competition and gives an edge to any of the potential CCAs moving forward, Wasser said. “I think the fact that the Department of Defense has relaxed some of its operational testing and evaluation standards at the direction of the secretary, speaks to the fact that I don't think that there's going to be any blowback from the Pentagon about this.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • It's not clear whether Iran has put naval mines in the Strait of Hormuz, but its longstanding ability to do so is part of the reason ships have all but stopped moving through the critical global chokepoint. The time may come for the U.S. Navy's littoral combat ships to demonstrate their long-touted ability to hunt mines.

    According to a March 2026 congressional report, Iran is believed to possess roughly 6,000 naval mines. Although CENTCOM commander Admiral Brad Cooper has said that Iran’s conventional navy has been rendered combat-ineffective, some reports indicate that Iran has deployed mines in the strait. The Islamic Revolutionary Guard Corps Navy has hundreds of speedboats with which to rapidly deploy mines across the narrow waterway. 

    Last fall, the Navy decommissioned the backbone of its minehunting capabilities: the four Avenger-class minesweepers stationed in Bahrain; four more remain elsewhere in the fleet. Purpose-built for mine warfare, the Avengers have wooden hulls wrapped in fiberglass to reduce magnetic signatures that trigger mines. But the Avengers are slow, outdated, lack any meaningful self-defense systems, and can’t launch helicopters or unmanned systems.

    The Avengers were replaced in the Persian Gulf by the long-controversial littoral combat ships: high-speed, agile surface combatants designed for near-shore surface warfare, anti-submarine operations, and mine countermeasures. The Gulf LCSs—all Independence-class vessels—are equipped with minesweeping and mine-hunting capabilities: the LCS Mine Countermeasures Mission Package. The MCM MP supports mine warfare operations using aviation assets and unmanned systems equipped with an array of sensors to detect, localize, and neutralize surface, near-surface, moored, and bottom mines in the littorals. To date, the USS Canberra (LCS 30), USS Santa Barbara (LCS 32), and USS Tulsa (LCS 16) are known to have received the MCM MP. A fourth LCS, the USS Kansas City (LCS 22), is equipped with MCM MP for crew training and relief support. 

    With aluminum hulls, Independence-class LCSs must stay outside minefields, sending in MH-60S Seahawks, unmanned surface vessels (USVs), and unmanned surface vehicles (USVs) to hunt the underwater weapons. 

    USVs can tow the AN/AQS-20 mine-hunting sonar system, which uses sensors to find bottom and moored mines. The USVs can also deploy the unmanned influence sweep system (UISS), which mimics the magnetic and acoustic signature of a ship to detonate mines safely. LCSs can also deploy the Knifefish UUV, which can find buried and proud mines using low-frequency broadband sonar. 

    Crewed MH-60S Seahawks can be equipped with the AN/AES-1 Airborne Laser Mine Detection System (ALMDS), which detects floating and near-surface moored mines, as well as the AN/ASQ-235 Airborne Mine-Neutralization System (AMNS), whose expendable Archerfish UUV can destroy mines.

    How might the U.S. Navy conduct counter-mine operations in the Persian Gulf? As of March, the four remaining Avengers were in Japan. The USS Tulsa and USS Santa Barbara were spotted at port in Malaysia on March 15, reportedly conducting brief logistical stops. The USS Canberra was reportedly in the Indian Ocean around the same time. The absence of these vessels in the Persian Gulf is surely no accident. Moving U.S. warships, particularly the three LCSs, out of port in Bahrain ahead of the conflict was likely a calculated decision to keep these vessels well out of the range of Iranian drones and missiles. Moreover, the U.S. military’s strikes on Iranian vessels in port have demonstrated the vulnerability of ships docked in the Gulf.

    Yet, even if the LCSs are sent to the Persian Gulf, there are concerns around the capability of the LCS MCM MP. The unmanned assets require hours of pre-mission calibration. They cannot operate beyond line of sight ot the LCS. The AN/AQS-20 has struggled to identify g mines, even when tested in the relatively benign waters of Southern California. Perhaps most concerning, the Pentagon’s testing office said in March 2026 that it could not determine the operational effectiveness of the LCS equipped with the MCM MP.  

    Finally, mine-clearing is a slow, deliberate process made even more arduous when occurring in an environment contested by Iranian missiles and drones. Neither the purpose-built Avenger-class nor the LCS equipped with a relatively unproven MCM mission package would likely prove effective without a robust military escort. 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A deception campaign launched by the CIA bought time for U.S. forces to rescue an airman who went down in Iran on Friday, CIA Director John Ratcliffe said in a White House news conference on Monday.

    The CIA deployed human assets and “exquisite technologies” to contribute to the rescue of the weapons systems officer of an F-15E Strike Eagle, Ratcliffe said. The aircraft’s pilot was rescued earlier upon the crash, but Iran was “desperately hunting” for the backseater who ejected further from his wingman and had moved away from the crash site.

    The injured officer was found by the CIA in a mountain crevice but was still invisible to Iranian forces.

    “Following the successful exfiltration on Saturday night, our intelligence reflects that the Iranians were embarrassed and ultimately humiliated by the success of this audacious rescue,” Ratcliffe said.

    At the press conference, President Donald Trump said it was the CIA’s “genius” that contributed to the rescue and that the spy agency had spotted “something moving up the mountain.”

    “This is at night. And they kept the camera on him for 45 minutes,” Trump said, suggesting the CIA had a covert surveillance capability — potentially a drone or satellite — available to track the airman’s movements.

    The public remarks about the mission show how the Trump administration has made it a point to highlight contributions that CIA operatives have made toward its national security efforts.

    Those include operations that targeted the government of ousted Venezuelan leader Nicolás Maduro. The agency has also taken a more public-facing posture, releasing recruitment videos aimed at sourcing in China. And in the months leading up to the Iran war, agency spies had been reportedly tracking the movements of now deceased Ayatollah Ali Khamenei.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶