• A multi-cluster cyberespionage operation in which attackers used USB-propagated malware, multiple RATs, loaders, and a custom stealer to target a Southeast Asian government organization between June and August 2025. Analysts initially observed USB-borne malware dubbed USBFect (also known as HIUPAN), which spreads through removable drives and deploys the PUBLOAD backdoor for lateral movement. Further telemetry revealed two […]

    The post Hackers Deploy USB Malware, RATs, and Stealers in Southeast Asian Government Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft recently patched a severe Elevation of Privilege (EoP) vulnerability in the Windows Error Reporting (WER) service, officially tracked as CVE-2026-20817. This flaw allows a local attacker with standard user rights to escalate to SYSTEM privileges by exploiting improper permission handling. The vulnerability was so significant that Microsoft chose to remove the affected feature entirely […]

    The post Windows Error Reporting Vulnerability Exposes Systems to Privilege Escalation, Allowing SYSTEM Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sharp rise in PXA Stealer campaigns targeting global financial institutions during the first quarter of 2026. The activity marks a notable shift in the infostealer landscape, with PXA Stealer filling the gap left by the takedowns of major malware families such as Lumma, Rhadamanthys, and RedLine in 2025. Researchers estimate that PXA Stealer activity […]

    The post Phishing ZIP Files Used to Deploy PXA Stealer Targeting Financial Firms appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A China-nexus threat actor known as Red Menshen is planting stealthy backdoors deep inside global telecommunications networks. According to a recent investigation by Rapid7 Labs, this long-term espionage campaign utilises a highly evasive Linux kernel malware called BPFdoor.  Instead of launching noisy, disruptive attacks, these hackers are building dormant sleeper cells in the telecom backbone. […]

    The post Hackers Implant Stealthy BPFdoor Backdoors in Telecom Networks for Persistent Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly discovered macOS infostealer dubbed Infiniti Stealer is being actively distributed through deceptive Cloudflare-style CAPTCHA pages, marking a notable evolution in social engineering attacks targeting Apple users. Initially tracked as “NukeChain” during threat hunting efforts, the malware’s true identity was confirmed after its operator panel became publicly accessible. Unlike traditional malware campaigns that rely on software […]

    The post Fake Cloudflare CAPTCHA Pages Deliver Infiniti Stealer Malware on macOS appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Internet Systems Consortium (ISC) has released a critical security advisory addressing a high-severity vulnerability in its Kea DHCP server software.  Kea is a modern, high-performance DHCP server widely used by enterprise networks and internet service providers to manage network IP allocations. Tracked as CVE-2026-3608, this flaw could allow unauthenticated remote attackers to crash essential […]

    The post ISC Issues Critical Warning Over Kea DHCP Vulnerability That Could Remotely Crash Services appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • ReversingLabs researchers identify a new Ghost campaign using fake npm install logs and progress bars to phish for sudo passwords and steal crypto wallets from developers.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Count the chairman of the Senate Armed Services Committee among the defense-policy experts who say the National Defense Strategy is inadequate in key ways.

    At a Thursday hearing, Sen. Roger Wicker, R-Miss., said the defense policy’s tepid treatment of satellites and nuclear weapons might encourage Chinese and Russian ambitions.

    “It’s no secret that I believe this NDS falls short in several areas,” Wicker told U.S. Strategic and Space Command leaders gathered to testify. “I am particularly concerned that the current strategy does not address space and nuclear threats with anywhere near the urgency they deserve.”

    The NDS makes only passing mention of Russia's efforts “to modernize and diversify” its nuclear arsenal. It mentions space as one of several areas where “direct military threats to the American Homeland have also grown in recent years.”

    Wicker raised concerns about Russia’s reported development of a space-based nuclear anti-satellite weapon, saying it would be a “major game changer.”

    Lawmakers first began warning about such a device in early 2024. A few months later, Biden officials said a suspected Russian testbed satellite had been in orbit for two years, but that the weapon was not operational—a claim Moscow denied. (Find a description of Russian and Chinese concepts of operations here.)

    The Trump administration’s NDS does not mention the weapon, which Adm. Richard Correll, the head of U.S. Strategic Command, said is “very significant” and something the U.S. military must prepare for.

    “Russia has indicated, and has been publicly acknowledged, that they're working on a nuclear capability that could be placed in space,” Correll told lawmakers. “We have to account for it in terms of the architecture that we have and what we can do about it. The department's very focused on that. We do have some options.”

    Gen. Stephen Whiting, head of U.S. Space Command, said that a nuclear anti-satellite weapon would be devastating not only to the U.S., but any country that operates in outer space.  

    “That would be an indiscriminate weapon that, if detonated on orbit, would immediately place at risk every country's space capabilities in low Earth orbit—the United States, China, Russia, Japan, Europe, you name it,” Whiting said. “That would violate the Outer Space Treaty and would not be a development, obviously, that we can tolerate.”

    When asked how soon Russia could field such a nuclear space weapon, neither Correll or Whiting provided a public answer to lawmakers.

    Some senators expressed concern that the Trump administration has so weakened trust in the American “nuclear umbrella” that European leaders are considering launching the kind of atomic-weapons programs they long ago forswore.

    Sen. Jeanne Shaheen, D-N.H., asked Correll whether he was concerned by that development. The Navy admiral responded that he detected “no change” in attitudes from allies.

    “At every opportunity in mil-to-mil engagements, I reinforce our extended deterrence commitment on the part of the United States,” Correll said.

    The National Defense Strategy called for supporting U.S. interests in the Western Hemisphere and said the government would “increase burden-sharing with allies and partners around the world.”

    Similarly, Sen. Elizabeth Warren, D-Mass., told Correll that NATO allies’ refusal to heed President Trump’s requests for help with his war on Iran have made the U.S. government's international relationships look weak to Russia and China.

    Correll told Warren he disagreed with her assessment and said the military relationship with allies remains strong and that China and Russia believe that to be the case, too. 

    Warren told the Navy admiral that his answer lacked “any credibility.”

    “Russia and China watch us insult our allies, then beg for their help, and then our allies don't give that help, and you think Russia and China think ‘there is an alliance that's working just great?,’” Warren said. “It is not only an embarrassment when the President begs and our allies say no, it is a national-security threat, because our enemies take note of that.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Office of the Director of National Intelligence is developing a policy framework and accompanying standards to speed AI adoption for cybersecurity and other tech tools across the intelligence community, as part of a broad cybersecurity and IT modernization effort launched under the Trump administration last year.

    ODNI has also sought to tighten the intelligence community’s cyber posture, including through modernizing networks, standing up a shared authorization repository, pushing a zero-trust model and expanding threat hunting, according to an ODNI official who requested anonymity under ground rules accompanying a news release on the modernization efforts.

    The office, which oversees America’s spy agencies and programs, is also working to align systems and policies across agencies and with the Defense Department, including joint use of classified commercial cloud infrastructure, the official added.

    The update helps highlight a broader push to streamline cybersecurity operations across the nation’s spy agencies. It also shows how AI is becoming a core part of how intelligence offices detect and respond to cyber threats.

    “Protecting our nation’s most sensitive information from those who seek to exploit it, while making sure our intelligence professionals have the tools and access they need to do their jobs, is not optional,” Director of National Intelligence Tulsi Gabbard said in a prepared statement. “It is essential to our national security.”

    Intelligence agencies are a prime target for foreign adversaries and criminal hackers seeking to steal sensitive data, map operations and exploit vulnerabilities in some of the government’s most critical and classified systems. The intelligence community’s tech modernization push has spanned multiple administrations, accelerating over the past decade with the shift to cloud computing and evolving into a broader effort to break down data silos and speed up how intelligence is shared and analyzed.

    This week, Politico reported that Gabbard is seeking to bring In-Q-Tel, the CIA-backed venture firm, under management of ODNI, a move that has sparked pushback from the CIA and others who warn it could disrupt the firm’s independence. The move could also give ODNI more visibility into and coordination over how emerging technologies are developed and deployed across the intelligence enterprise.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A long-term and ongoing campaign attributed to a China-nexus threat actor has embedded itself in telecom networks to conduct espionage against government networks. The strategic positioning activity, which involves implanting and maintaining stealthy access mechanisms within critical environments, has been attributed to Red Menshen, a threat cluster that’s also tracked as Earth Bluecrow,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶