• A critical security flaw has been disclosed in Grist‑Core, an open-source, self-hosted version of the Grist relational spreadsheet-database, that could result in remote code execution. The vulnerability, tracked as CVE-2026-24002 (CVSS score: 9.1), has been codenamed Cellbreak by Cyera Research Labs. “One malicious formula can turn a spreadsheet into a Remote Code Execution (RCE) beachhead,”

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Approximately 6,000 vulnerable SmarterTools SmarterMail installations globally are all exposed to an actively exploited remote code execution vulnerability. The vulnerability, tracked as CVE-2026-23760, poses an immediate threat to organisations relying on SmarterMail for email and collaboration services. The Shadowserver Foundation integrated CVE-2026-23760 detection into their daily vulnerable HTTP scans, flagging susceptible servers based on version […]

    The post Over 6,000 SmarterMail Servers Exposed to Actively Exploited RCE Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Active exploitation of a critical vulnerability in React Server Components, tracked as CVE‑2025‑55182 (React2Shell), targeting companies across multiple industry sectors worldwide. React2Shell affects the Flight protocol, which facilitates client-server communication for React Server Components. The vulnerability stems from insecure deserialization servers accept client data without proper verification, enabling remote code execution under specific conditions. The […]

    The post Attackers Exploit React2Shell Vulnerability to Target IT Sector Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Search engine optimization (SEO) poisoning techniques to trick users into downloading malicious software disguised as legitimate tools. This attack campaign involves manipulating search results to promote fake repositories and archives containing BAT executable files that impersonate popular applications. Once users execute these files, the malware establishes contact with command-and-control (C2) servers to deliver secondary payloads, […]

    The post Hackers Exploit SEO Poisoning to Target Users Seeking Legitimate Tools appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated deepfake-enabled phishing campaign is actively targeting Bitcoin users through fake Zoom and Microsoft Teams calls. The attackers are exploiting video conferencing, Telegram, and AI-generated identities to steal bitcoin and compromise victims’ digital lives. The attack chain begins on Telegram, where victims receive what appears to be a legitimate message or call request from […]

    The post New Deepfake Phishing Attack Targets Bitcoin Users via Zoom and Teams appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A class-action lawsuit filed in San Francisco federal court accuses Meta Platforms of systematically misleading billions of WhatsApp users about the protection of their messages. The complaint alleges that despite marketing claims of unbreakable end-to-end encryption, Meta secretly stores, analyzes, and grants employee access to chat contents through internal tools. Plaintiffs from Australia, Brazil, India, […]

    The post Meta Faces Legal Action Over Claims of Accessing All WhatsApp User Messages appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have discovered a JScript-based command-and-control (C2) framework called PeckBirdy that has been put to use by China-aligned APT actors since 2023 to target multiple environments. The flexible framework has been put to use against Chinese gambling industries and malicious activities targeting Asian government entities and private organizations, according to Trend Micro

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft on Monday issued out-of-band security patches for a high-severity Microsoft Office zero-day vulnerability exploited in attacks. The vulnerability, tracked as CVE-2026-21509, carries a CVSS score of 7.8 out of 10.0. It has been described as a security feature bypass in Microsoft Office. “Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Arizona Democratic Sen. Mark Kelly’s lawyers on Monday urged a federal judge to block the Defense Department from downgrading his retirement rank as a Navy captain and his pay for telling U.S. troops they aren’t required to follow illegal orders. 

    Paul J. Fishman wrote in a 35-page filing that Defense Secretary Pete Hegseth’s attempt to punish Kelly for appearing in the video alongside other members of Congress violates several constitutional rights.  

    “As a decorated combat veteran and member of the Senate Armed Services Committee, Senator Kelly is deeply committed to the necessity of good order and discipline in the armed forces,” Fishman wrote. “He asks this Court to reinforce, not degrade, those principles. 

    “His speech—simply reminding servicemembers of their fundamental obligation not to follow unlawful orders— promotes good order. And discipline does not demand silence —particularly from those no longer serving on active duty.”

    Fishman firmly rejected the Department of Justice’s assertion in a brief filed last week that the federal court system has no authority over the Defense Department’s actions in this instance. 

    “Defendants begin from the premise that questions of ‘military discipline’ lie beyond judicial review,” Fishman wrote. “Their claim that this Court is ‘not permitted to address’ Senator Kelly’s challenge disregards reams of precedent reviewing military disciplinary actions and demands an untenable level of deference.”

    Senior Judge Richard J. Leon, who was nominated to the bench by President George W. Bush, had scheduled a hearing on the issue for Wednesday, but postponed that until Feb. 3 due to the snowstorm. 

    Hegseth pursues penalties

    Defense Secretary Pete Hegseth announced earlier this month that he had started the process to downgrade Kelly’s retirement rank and pay, writing in a social media post that his “status as a sitting United States Senator does not exempt him from accountability, and further violations could result in further action.”

    The Defense Department letter of censure to Kelly alleged that his participation in the video undermined the military chain of command, counseled disobedience, created confusion about duty, brought discredit upon the Armed Forces and included conduct unbecoming of an officer. 

    The video at the center of the debate featured Kelly, Michigan Sen. Elissa Slotkin, Colorado Rep. Jason Crow, Pennsylvania Reps. Chris Deluzio and Chrissy Houlahan, and New Hampshire Rep. Maggie Goodlander, all Democrats with backgrounds in the military or intelligence community.

    They said that Americans in those institutions “can” and “must refuse illegal orders.”

    “No one has to carry out orders that violate the law or our Constitution. We know this is hard and that it’s a difficult time to be a public servant,” they said. “But whether you’re serving in the CIA, in the Army, or Navy, or the Air Force, your vigilance is critical.”

    Kelly lawyer’s arguments

    Fishman wrote in his brief that the Trump administration is asking the court to “embrace a novel rule” regarding the First Amendment: “that retired military veterans have no constitutional protection for their speech whenever the Secretary of Defense—in his sole discretion and without even identifying all of the speech at issue—concludes that it ‘risks undermining military discipline and good order.’” 

    The Justice Department's brief from last week, he wrote, erroneously argued that retired military officers can legally face punishment for speaking out against Defense Department policies they oppose.

    “From Alexander Hamilton denouncing President Adams’s fitness to command during the Quasi-War, to modern episodes in which retired generals publicly called for Secretary Rumsfeld’s resignation over the Iraq War, retired officers have long participated forcefully in public debate over military policy,” Fishman wrote. 

    “The same is true today: retired servicemembers, including Members of Congress, have openly criticized presidential decisions ranging from the Afghanistan withdrawal to vaccination requirements,” he added. “Many continue to serve with distinction as legislators, governors, and federal judges. Yet against that backdrop, Defendants assert the power to limit the First Amendment rights of more than two million retired servicemembers, all without judicial review.”

    This story was originally published by Stateline.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • White House press secretary Karoline Leavitt on Monday urged Senate Democrats to advance the government funding package that must become law before the weekend to avoid a partial shutdown, rejecting their proposal to remove the Homeland Security funding bill.

    Democrats in the upper chamber say they are ready to help pass five of the six bills, but insist the Homeland Security spending measure must be stripped and renegotiated to include more constraints on federal immigration enforcement after officers killed a second American citizen in Minnesota this weekend. 

    “We absolutely do not want to see that funding lapse and we want the Senate to move forward with passing the bipartisan appropriations package that was negotiated on a bipartisan basis,” Leavitt said. 

    Negotiators in Congress have reached bipartisan consensus on each of the dozen full-year government spending bills during the last few months, though the final bills still need to clear the Senate and become law.

    Funding for hundreds of programs in those measures lapses Friday at midnight, when the stopgap spending law Congress approved at the end of the last shutdown expires.  

    A partial shutdown would affect the Departments of Defense, Education, Health and Human Services, Homeland Security, Housing and Urban Development, Labor, State, Transportation and Treasury. The Executive Office of the President, Supreme Court and judicial branch would also go without funding if a solution cannot be reached in time. 

    Leavitt said during the briefing that “policy discussions on immigration in Minnesota are happening” and pointed to the phone call that President Donald Trump and Minnesota Democratic Gov. Tim Walz had earlier in the day. 

    “But that should not be at the expense of government funding for the American people, which would include FEMA funding,” Leavitt said. “And we are in the midst of the storm that took place over the weekend and many Americans are still being impacted by that.”

    The Homeland Security appropriations bill funds numerous programs in addition to Immigration and Customs Enforcement and Customs and Border Protection. The Coast Guard, Federal Emergency Management Agency, National Flood Insurance Fund, Secret Service and Transportation Security Administration are among the other agencies that rely on the bill for budget authority. 

    Schumer demands removal of DHS bill 

    Senate Minority Leader Chuck Schumer, D-N.Y., wrote in a statement that Majority Leader John Thune, R-S.D., should remove the Homeland Security funding bill from the larger package before the deadline to avoid a lapse in funding. 

    “The responsibility to prevent a partial government shutdown is on Leader Thune and Senate Republicans,” he wrote. “If Leader Thune puts those five bills on the floor this week, we can pass them right away. If not, Republicans will again be responsible for another government shutdown.”

    Senate Appropriations Chairwoman Susan Collins, R-Maine, in a brief floor speech urged lawmakers from both political parties to vote to advance the full funding package, calling the possibility of another shutdown “harmful, unnecessary and disastrous.”

    “I hope we can come together in a constructive way to get this done and to ensure that we do not lurch into a dangerous and detrimental government shutdown,” she said. 

    Collins did acknowledge the killing of Alex Pretti over the weekend, saying his “tragic death” had “refocused attention on the Homeland Security bill and I recognize that and share the concerns.” 

    “I do want to point out to my colleagues that there are many safeguards that have been put in this bill that I would encourage them to review,” Collins added without going into detail. “And that the vast majority of the funding in this bill, more than 80%, is for non-immigration and non-border security functions.” 

    A Senate Republican aide, who wasn’t authorized to speak publicly, said GOP leaders are “determined to not have another government shutdown.” 

    “We will move forward as planned and hope Democrats can find a path forward to join us,” the aide added. 

    A Senate Democratic leadership aide said that “Republicans and the White House have reached out but have not yet raised any realistic solutions.”

    ‘Government shutdowns do not help anyone’

    Senate Homeland Security Appropriations Subcommittee Chairwoman Katie Britt, R-Ala., wrote in a social media post that the array of programs in that bill “are critical to keeping Americans safe and must be funded.”

    “We know from recent history that government shutdowns do not help anyone and are not in the best interest of the American people,” Britt wrote, referring to the shutdown of historic length that ended Nov. 12. “As we approach a government funding deadline, I remain committed to finding a pathway forward.”

    Senate Homeland Security Appropriations Subcommittee ranking member Chris Murphy, D-Conn., said Sunday on CNN’s “State of the Union with Jake Tapper & Dana Bash” that he couldn’t “vote to fund this lawless Department of Homeland Security.” 

    “And remember, it's not just in Minnesota. They're violating the law all over the country,” Murphy said. “I spent last week in Texas where they are locking up 2-year-old and 3-year-old kids who are here in the United States legally, just for the purpose of traumatizing them.”

    Fetterman, Shaheen part ways

    Pennsylvania Democratic Sen. John Fetterman appeared to be the only member of his party in that chamber to support the entire package, writing in a statement he “will never vote to shut our government down, especially our Defense Department.”

    “I reject the calls to defund or abolish ICE. I strongly disagree with many strategies and practices ICE deployed in Minneapolis, and believe that must change,” Fetterman wrote. “I want a conversation on the DHS appropriations bill and support stripping it from the minibus. It is unlikely that will happen and our country will suffer another shutdown.”

    New Hampshire Democratic Sen. Jeanne Shaheen backed the strategy of pulling out the Homeland Security spending bill and allowing the other five government funding bills to become law before the shutdown deadline.

    “The Senate then needs to have a real bipartisan discussion about what additional reforms we need to put in place to prevent tragedies like Minneapolis from happening across the country,” Shaheen wrote in a social media post. “I will vote against DHS’s funding until additional reforms are in place.”

    This story was originally published by Stateline.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶