Skip to content

ADMIN.FOUNDATION

  • TP-Link Router Flaw Enables Authentication Bypass Through Password Recovery Mechanism 

    ·

    CVE/vulnerability, Cyber Security News, Vulnerabilities, vulnerability

    TP-Link has disclosed a high-severity authentication bypass vulnerability affecting its VIGI security camera lineup, allowing attackers on local networks to reset administrator passwords without verification.   The flaw lies in the password recovery feature of the local web interface, which is exploited via client-side state manipulation.  The vulnerability (CVE-2026-0629) enables threat actors positioned on the same local area network (LAN) to gain […]

    The post TP-Link Router Flaw Enables Authentication Bypass Through Password Recovery Mechanism  appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion

    ·

    A Telegram-based guarantee marketplace known for advertising a broad range of illicit services appears to be winding down its operations, according to new findings from Elliptic. The blockchain intelligence company said Tudou Guarantee has effectively ceased transactions through its public Telegram groups following a period of significant growth. The marketplace is estimated to have processed

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Discord Exploited to Spread Clipboard Hijacker Stealing Cryptocurrency Funds

    ·

    cyber security, Cyber Security News, Discord

    CloudSEK’s STRIKE team has uncovered a sophisticated cryptocurrency theft operation orchestrated by the threat actor “RedLineCyber,” who deliberately impersonates the notorious RedLine Solutions to establish credibility within underground communities. Rather than collecting comprehensive system data, the malware employs a highly targeted approach: continuously monitoring the Windows clipboard for cryptocurrency wallet addresses and performing silent substitution […]

    The post Discord Exploited to Spread Clipboard Hijacker Stealing Cryptocurrency Funds appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • WhisperPair Vulnerability Allows Attackers to Pair Devices Without User Consent 

    ·

    Bluetooth, CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    Google’s Fast Pair technology has revolutionised Bluetooth connectivity, enabling seamless one-tap pairing across supported accessories and account synchronisation for millions of users.  However, a critical vulnerability discovered in flagship audio accessories threatens the security of hundreds of millions of devices.  Attribute  Details  Vulnerability Name  WhisperPair – Unauthorized Device Pairing Without User Consent  CVE Identifier  CVE-2025-36911  Severity Rating  Critical  […]

    The post WhisperPair Vulnerability Allows Attackers to Pair Devices Without User Consent  appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • SolyxImmortal Malware Abuses Discord to Quietly Harvest Sensitive Information

    ·

    cyber security, Cyber Security News, Malware

    A newly discovered information-stealing malware, SolyxImmortal, has emerged as a persistent surveillance threat targeting Windows users. Distributed through underground Telegram channels, this Python-based implant combines credential theft, document harvesting, keystroke logging, and screen capture capabilities into a continuously running surveillance framework that operates silently in the background. First detected in January 2026, the malware prioritizes […]

    The post SolyxImmortal Malware Abuses Discord to Quietly Harvest Sensitive Information appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Shutdown odds plummet after House and Senate strike bipartisan deal on 2026 funding bills

    ·

    Policy
    Negotiators in both chambers of Congress have reached an agreement to fund every federal agency in fiscal 2026, with appropriators announcing a final deal on Tuesday, giving lawmakers 10 days to get the remaining bills to President Trump’s desk before a shutdown would occur.

    The Senate last week passed a second “minibus” package of spending bills, sending the measure to Trump to clear out half of the 12 annual must-pass appropriations bills. The House has already passed a third package—funding the departments of State and Treasury, and other governmentwide oversight agencies—and the Senate is expected to pass it next week. 

    Lawmakers on Tuesday unveiled the fourth and final minibus, which would fund the departments of Defense, Labor, Health and Human Services, Education, Homeland Security, Transportation and Housing and Urban Development. Those agencies, as well as State and Treasury, are currently funded through a stopgap continuing resolution that is set to expire after Jan. 30. 

    The new package marks yet another breakthrough between Republicans and Democrats in both the House and Senate. The key agencies of the bill would be funded at the following levels: 

    • Defense: $838.7 billion, a less than 1% increase
    • HHS (not including the Food and Drug Administration): $116.8 billion, a less than 1% decrease
    • Education: $79 billion, essentially flat funded
    • HUD: $77.3 billion
    • DHS: $64.4 billion, a 1% decrease 
    • Transportation: $25.1 billion, a less than 1% decrease
    • Social Security Administration: $12.3 billion, essentially flat funded 
    • Labor: $13.7 billion, a 1% increase

    Like the other three spending packages, the measure largely rejects the drastic funding cuts Trump and House Republicans had sought. Most agencies and programs avoided receiving anything other than a minor haircut. 

    “This latest funding package continues Congress’s forceful rejection of extreme cuts to federal programs proposed by the Trump administration,” said House Appropriations Committee Ranking Member Rosa DeLauro, D-Conn. “Where the White House attempted to eliminate entire programs, we chose to increase their funding. Where the administration proposed slashing resources, we chose to sustain funding at current levels.”

    Democratic lawmakers have repeatedly called it critical to pass full-year appropriations bills to avoid ceding power to the Trump administration in making funding choices. Agencies operated under a full-year CR in fiscal 2025, providing more flexibility to the White House. 

    Rep. Tom Cole, R-Okla., who chairs the House spending panel, said the package demonstrated that lawmakers could still work together to get important work done. 

    “At a time when many believed completing the FY26 process was out of reach, we’ve shown that challenges are opportunities,” Cole said. “It’s time to get it across the finish line.”

    The House is expected to approve the measure this week. The Senate would then take it up next week, when it returns from recess. Lawmakers will have to pass the bill and Trump would then have to sign it into law by Jan. 30 to avoid the second shutdown of the fiscal year. 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Critical AVEVA Software Flaws Allow Remote Code Execution With SYSTEM Privileges

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    AVEVA has disclosed seven critical and high-severity vulnerabilities in its Process Optimization software (formerly ROMeo) that could enable attackers to execute remote code with SYSTEM privileges and completely compromise industrial control systems. The security bulletin, published on January 13, 2026, affects AVEVA Process Optimization version 2024.1 and all prior versions. The most severe vulnerability, tracked […]

    The post Critical AVEVA Software Flaws Allow Remote Code Execution With SYSTEM Privileges appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google Gemini Flaw Allows Access to Private Meeting Details Through Calendar Events

    ·

    CVE/vulnerability, cyber security, Cyber Security News, Google, vulnerability

    A harmless-looking Google Calendar invite has revealed a new frontier in the exploitation of artificial intelligence (AI).  Security researchers at Miggo discovered a vulnerability in Google Gemini’s integration with Google Calendar that allowed attackers to bypass privacy controls and exfiltrate sensitive meeting data without any user interaction.   Gemini, Google’s AI assistant, interacts with Calendar to help users […]

    The post Google Gemini Flaw Allows Access to Private Meeting Details Through Calendar Events appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google Ads Exploited to Deliver TamperedChef Through Malicious PDF Editor

    ·

    cyber security, Cyber Security News

    A sophisticated malvertising campaign tracked as TamperedChef has compromised over 100 organizations across 19 countries by distributing weaponized PDF editing software through Google Ads. Sophos Managed Detection and Response (MDR) teams discovered the operation in September 2025, revealing a multi-layered attack infrastructure designed to steal browser credentials and establish persistent backdoor access on Windows systems. […]

    The post Google Ads Exploited to Deliver TamperedChef Through Malicious PDF Editor appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cloudflare Zero-Day Flaw Allows Attackers to Bypass Security and Access Any Host

    ·

    Cloudflare, CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    A critical zero-day vulnerability in Cloudflare’s Web Application Firewall (WAF) allowed attackers to bypass security controls and directly access protected origin servers. Security researchers from FearsOff discovered on October 9, 2025, that requests targeting a specific certificate-validation path could completely circumvent customer-configured WAF rules designed to block unauthorized traffic. The Hidden Backdoor in Certificate Validation […]

    The post Cloudflare Zero-Day Flaw Allows Attackers to Bypass Security and Access Any Host appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 … 566 567 568 569 570 … 1,059
Next Page

ADMIN.FOUNDATION

cybersecurity / defense / intelligence