• Researchers at MDSec have disclosed a newly patched Elevation of Privilege vulnerability in Microsoft Windows, known as “RegPwn”. Tracked as CVE-2026-24291, this flaw allows a low-privileged user to gain full SYSTEM access by exploiting how Windows handles registry configurations for its built-in Accessibility features.​ Windows Accessibility features, such as the On-Screen Keyboard and Narrator, run […]

    The post Researchers Disclose ‘RegPwn,’ a Windows Registry Weakness Allowing SYSTEM Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Apple on Tuesday released its first round of Background Security Improvements to address a security flaw in WebKit that affects iOS, iPadOS, and macOS. The vulnerability, tracked as CVE-2026-20643 (CVSS score: N/A), has been described as a cross-origin issue in WebKit’s Navigation API that could be exploited to bypass the same-origin policy when processing maliciously crafted web content. The

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly discovered malware campaign is exploiting user trust in Telegram by distributing a trojanized installer through a typosquatted website, telegrgam[.]com. The site closely mimics the official Telegram download portal and delivers a malicious executable named tsetup-x64.6.exe, making it appear legitimate to unsuspecting users. Once downloaded and executed, the installer initiates a multi-stage attack chain while […]

    The post Fake Telegram Download Site Delivers Stealthy In-Memory Malware Loader appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have a detailed a critical security flaw in Fortinet’s FortiClient Enterprise Management Server (EMS). Tracked as CVE-2026-21643, this severe pre-authentication SQL injection vulnerability carries a near-maximum CVSS severity score of 9.1. It allows unauthenticated attackers to execute arbitrary SQL commands and gain total control over the underlying database. The flaw specifically targets multi-tenant […]

    The post FortiClient Hit by Severe SQL Injection Vulnerability Enabling Database Intrusion appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly disclosed vulnerability in AWS Bedrock AgentCore Code Interpreter allows threat actors to bypass network isolation and establish stealthy command-and-control (C2) channels. AWS originally advertised this mode as providing complete isolation without external access, researchers found that it permits outbound DNS queries for A and AAAA records. This structural allowance enables attackers to exfiltrate […]

    The post AWS Bedrock AgentCore Sandbox Bypass Enables Stealthy C2 and Data Exfiltration appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have disclosed a critical security flaw impacting the GNU InetUtils telnet daemon (telnetd) that could be exploited by an unauthenticated remote attacker to execute arbitrary code with elevated privileges. The vulnerability, tracked as CVE-2026-32746, carries a CVSS score of 9.8 out of 10.0. It has been described as a case of out-of-bounds write in the LINEMODE Set

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Attackers are abusing fake court documents and GitHub‑hosted payloads in a focused spear‑phishing campaign that deploys a stealthy Rust‑based COVERT RAT against Argentina’s judicial sector. This operation chains Windows LNK shortcuts, BAT loaders, and PowerShell to quietly fetch and execute a masqueraded payload, msedge_proxy.exe, from GitHub infrastructure. The operation, tracked as “Operation Covert Access,” uses […]

    The post Judicial Targets Hit by COVERT RAT via Court Docs and GitHub Payloads appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Virtually all of the giant reconciliation fund has been doled out, the Pentagon’s acting chief financial officer said Tuesday. 

    “Everything except for $1.3 billion in the $153 billion that's been given to the Department of Defense by the One Big, Beautiful Bill Act has been apportioned and [has] been released to the services and program managers. And so that money is all starting to flow,” Jules Hurst, who is performing the duties of Pentagon comptroller and chief financial officer, said at the McAleese annual defense programs conference in Arlington, Va.

    As Hurst spoke, lawmakers are mulling a $50 billion supplemental to pay for U.S. strikes on Iran and Trump-administration officials were finishing its 2027 budget proposal.

    Asked about reports that some offices hadn’t received reconciliation funds yet, he said, “It's all been released to the services of the program offices. Sometimes it takes time for money to trickle down.”

    Hurst declined to preview any details on the upcoming White House budget request, which will reportedly ask for $1.5 trillion in defense spending—half again as much as the current year’s record budget

    But he did say the entity known as DOGE, was still “alive and well” in the Pentagon. 

    “They've been a great partner for comptroller, in particular, as we just try to figure out where we have fat,” Hurst said. “We have robust [operations and maintenance] accounts in the FY27 budget, but they're focused on readiness. And so wherever we could, we looked through accounts and services inside the department and we tried to get rid of things that are no longer really necessary…and DOGE is very helpful for that.”

    When asked if the Pentagon could feasibly spend $1.5 trillion in one year, Hurst said yes and that a lot of things were left out to keep the number down. 

    “We had to cut down significantly to get to [$1.5 trillion]. We had more ideas and more concepts on how to spend the money, and then we had to deal with. And so we took a long time to trim that down to the most essential things,” he said. 

    Hurst declined to provide specifics on how the budget would be broken down but said the proportions would mimic the Reagan administration, including “a massive investment in procurement and research development.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Questions about following illegal orders—a frequent theme of the second Trump administration—came up again at a Capitol Hill hearing on Tuesday

    Just days after Defense Secretary Pete Hegseth declared that the U.S. war on Iran would feature “no quarter, no mercy for our enemies”—on its face, a violation of international law—the leader of U.S. Southern Command was pressed by House lawmakers who had questions about attacks on alleged drug-running boats off South America.

    “Has an order been issued to you on ‘no quarter,’ no survivors?” Rep. Eugene Vindman, D-Va., asked Marine Gen. Francis Donovan, alluding to the Sept. 2 “double-tap” attack on the survivors of an initial strike.

    The Law of Armed Conflict considers survivors of a strike to be “out of the fight” and thus off the table as targets. 

    Donovan said he had not been given any direct orders to offer “no quarter,” a term the military uses to describe sparing survivors of an attack who are no longer able to defend themselves. 

    Asked whether he would consider such an order unlawful, Donovan responded that he would not follow an unlawful order.

    “Okay, that’s an unlawful order,” Vindman said. 

    It was a familiar line of questioning, going back to the early days of the administration, when Hegseth and Army Secretary Dan Driscoll were asked about their willingness to follow unlawful orders. It was an unusual query for a confirmation hearing, but one that lawmakers insisted on in light of allegations by one of Trump’s former defense secretaries that he had suggested shooting at unarmed protestors. 

    In his own testimony on Tuesday, Joseph Humire, who is serving unconfirmed in as the Pentagon’s top civilian for homeland defense, said there have been 45 strikes, killing 157 aboard 47 vessels. Legal experts have from the beginning debated whether any of these strikes have been legal, as the Pentagon has offered little evidence that the targets were actively trafficking drugs at the time they were killed. 

    Unlawful orders came up again later in the hearing, as Rep. Chrissy Houlahan, D-Pa., pressed Donovan and his U.S. NORTHCOM counterpart, Air Force Gen. Gregory Guillot, in response to recent Trump comments that he had considered federalizing the November midterm election.

    On March 10, the Democratic National Committee sued the administration to compel a response to whether there are considerations to deploy the military or station armed federal agents outside polling places. 

    Donovan and Guillot were much more clear when asked whether they would deploy troops to stand outside polling locations on election day, an illegal action according to federal law.

    “Congresswoman, I'm aware that doing so is against the law and I will not follow an unlawful order,” Guilott told Houlahan, while Donovan followed up with, “I will commit to the same.”

    Humire said that he was not aware of any direction to deploy troops, but said he would “reserve the decision space” for the president.

    “I hope, Mr. Humire, that you take a look at the law and follow it,” Houlahan said.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In mid-January 2026, Microsoft Defender Experts identified a devious way that cybercriminals are tricking people into giving away…

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶