• A novel WhatsApp account-takeover campaign dubbed “GhostPairing Attack” has emerged, enabling threat actors to gain complete access to victim accounts without stealing passwords or conducting SIM swaps. Security researchers at Gen have uncovered the sophisticated social engineering scheme that exploits WhatsApp’s legitimate device pairing feature to compromise accounts across multiple countries silently. The GhostPairing Attack […]

    The post GhostPairing Attack Exposes WhatsApp Accounts to Full Takeover via Phone Numbers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • US auto loan service 700Credit confirms a data breach exposed names, addresses, and Social Security numbers of dealership customers. Free credit monitoring is offered.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new partnership between a European chipmaker and software firm aims to ease the difficult  task of creating defense systems with encryption strong enough to withstand attacks by tomorrow’s quantum computers.

    SEALSQ, which specializes in “quantum-safe” chips, and Airmod, a French company that specializes in secure electronics for aerospace and drones, say they can help companies produce the larger, more energy-intensive software that meets standards for quantum-safe hardware and software environments, as defined by the National Institute of Standards and Technology, or NIST. 

    Under a deal announced Monday, the partners will use Airmod’s middleware software to help clients turn “months of complex cryptographic integration into days” by allowing clients to bridge more easily apply software from previous applications into new ones. 

    The standards reflect growing concern and certainty among a broad range of computer and security professionals that engineers—most likely in either China or the United States—will announce the development of a quantum computer capable of breaking Shor’s algorithm before 2035. This is the encryption standard that runs at the heart of most of the world’s financial transactions, web surfing, and device-to-device communication (such as drone operation). Whoever wins the race would essentially have a backdoor into private transactions and communications all over the world.

    In 2022, China claimed it had already reached that threshold, much to the skepticism of many U.S. national security officials and quantum computing experts from around the world. But China is ahead of the United States in many areas of quantum sensing and computing research; it  has also been exfiltrating encrypted data that could be unlocked after a quantum breakthrough.

    The new standards mean that many companies will effectively phase out chips that exist in much common computer hardware, as well as the applications running on that hardware, replacing both with quantum-safe versions—at least, that’s the hope.

    “What does it mean to implement the new generation of algorithms? There is a certain urgency for [many businesses to] understand a bit better,” Gweltas Radenac, IoT security business director at SEALSQ, told Defense One in an exclusive interview.

    But he pointed out that computer and software applications today are so complex and interconnected that a company that believes it has done all it needs to do to meet new standards may still be vulnerable to side-channel attacks in addition to more direct remote attacks.

    A bigger challenge, which the partnership seeks to address, is that the new encryption protocols are much larger than the previous ones. This makes it harder to write applications for them, and the process of designing applications is more energy-intensive.

    That has particularly bad ramifications for the emerging defense startup industry focused on the delivery of new drones. Ukraine, the leader in this field, often has to rely on components that are easily procured in large numbers, including chips from China, and needs to design and deploy them quickly in the face of rapidly changing electronic warfare tactics.

    Jean-Marc Prichard, head of sales and marketing at Airmod, said the company is trying to address both the high costs of designing quantum-safe algorithms and the larger concern of China’s dominance in many types of chips. This includes many of the less sophisticated ones that are part of connected devices like drones. The company is also looking for ways to move production closer to customers, and can already do so for some production aspects, such as embedding customer-specific data on the chip at a location that meets stronger security requirements.

    “So if a U.S. customer wants to have his own data to be injected in the secure chip, we can offer a service where it's done on the U.S. footprint, for instance,” he said.

    The partnership news comes as Europe reinvests in its own chip foundries under its own version of a Chips Act, a 2023 effort to “strengthen the semiconductor ecosystem in the EU,” according to the European Commission. The effort accelerated in March, when nine EU members agreed to join the coalition. 

    Meanwhile NIST, the preeminent global standards body for computer security, shed key researchers in May and has faced budgetary hurdles even before Donald Trump’s administration took over. Since January, NIST researchers have worried that government cutbacks hurt travel and research budgets, which they worried could reduce U.S. influence in setting international standards.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The security vulnerability known as React2Shell is being exploited by threat actors to deliver malware families like KSwapDoor and ZnDoor, according to findings from Palo Alto Networks Unit 42 and NTT Security. “KSwapDoor is a professionally engineered remote access tool designed with stealth in mind,” Justin Moore, senior manager of threat intel research at Palo Alto Networks Unit 42, said in a

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers at Rapid7 Labs have uncovered a sophisticated new threat: SantaStealer, a malware-as-a-service information stealer actively promoted on Telegram channels and underground hacker forums. The malware, which recently rebranded from “BluelineStealer,” is scheduled for release before the end of 2025 and represents a growing threat to users worldwide due to its ability to exfiltrate […]

    The post SantaStealer Malware Steals Sensitive Files, Credentials, and Crypto Wallet Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical local privilege escalation vulnerability in the JumpCloud Remote Assist for Windows agent allows any low-privileged user on a Windows system to gain NT AUTHORITY\SYSTEM privileges or crash the machine. Tracked as CVE-2025-34352, the flaw affects JumpCloud Remote Assist for Windows versions prior to 0.317.0 and has been rated High severity (CVSS v4.0: 8.5). JumpCloud is a widely used cloud-based Directory-as-a-Service and […]

    The post JumpCloud Remote Assist Windows Agent Vulnerability Allows Privilege Escalation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has announced that it’s discontinuing its dark web report tool in February 2026, less than two years after it was launched as a way for users to monitor if their personal information is found on the dark web. To that end, scans for new dark web breaches will be stopped on January 15, 2026, and the feature will cease to exist effective February 16, 2026. “While the report offered general

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Jaguar Land Rover (JLR) has officially confirmed that a major cyberattack in August resulted in the theft of sensitive personal data belonging to current and former employees. This disclosure marks the luxury automaker’s first public admission regarding the full scope of the incident, following a month-long production shutdown that cost the company hundreds of millions […]

    The post Jaguar Land Rover Confirms August Cyberattack Led to Employee Data Theft appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A popular browser extension promoted as a free and secure VPN has been discovered secretly capturing user conversations across multiple AI chatbot platforms including ChatGPT, Claude, Gemini, and Microsoft Copilot raising fresh concerns over privacy and data exploitation in the age of generative AI. Researchers using the Wings agentic‑AI risk engine uncovered that Urban VPN […]

    The post Chrome Extension with 6M+ Users Found Collecting AI Chatbot Inputs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A Google Chrome extension with a “Featured” badge and six million users has been observed silently gathering every prompt entered by users into artificial intelligence (AI)-powered chatbots like OpenAI ChatGPT, Anthropic Claude, Microsoft Copilot, DeepSeek, Google Gemini, xAI Grok, Meta AI, and Perplexity. The extension in question is Urban VPN Proxy, which has a 4.7 rating on the Google Chrome

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶