• The construction industry has emerged as a primary target for sophisticated cyber adversaries in 2025, with threat actors including state-sponsored APT groups, ransomware operators, and organized cybercriminal networks actively targeting organizations across the building and construction sector. Nation-state actors from China, Russia, Iran, and North Korea are leveraging the industry’s rapid digital transformation and security […]

    The post APT Groups Target Construction Firms to Steal RDP, SSH, and Citrix Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Intel is pursuing legal action against a former software engineer who the company claims downloaded thousands of confidential files shortly after being fired in July. The incident highlights growing concerns about data security during workforce reductions and employee departures. The Incident Jinfeng Luo, who worked as a software developer at Intel since 2014, lived in […]

    The post Ex-Intel Employee Hid 18,000 Sensitive Documents Prior to Leaving the Company appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical remote code execution vulnerability has been discovered in LangGraph’s checkpoint serialization library, affecting versions before 3.0. The flaw resides in the JsonPlusSerializer component, which is the default serialization protocol used for all checkpointing operations. This vulnerability (CVE-2025-64439) allows attackers to execute arbitrary Python code during the deserialization of malicious payloads. Attribute Details CVE […]

    The post LangGraph Deserialization Flaw Enables Execution of Malicious Python Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Elastic has released a security advisory addressing a significant vulnerability in Elastic Defend that could allow attackers to escalate their privileges on Windows systems. The vulnerability, tracked as CVE-2025-37735, stems from improper preservation of file permissions in the Defend service and poses a serious risk to organizations relying on this endpoint protection platform. Field Details […]

    The post Elastic Defend for Windows Vulnerability Allows Threat Actors to Gain Elevated Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Three critical vulnerabilities in runc, the widely-used container runtime that powers Docker and Kubernetes, have been disclosed, allowing attackers to break out of container isolation and gain root access to host systems. The flaws, identified as CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881, were revealed by a SUSE researcher on November 5, 2025. CVE ID Affected Versions Fixed […]

    The post Hackers Abuse runc Tool to Escape Containers and Compromise Hosts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In early November 2025, a massive data breach at Knownsec, a prominent Chinese cybersecurity firm with government ties, sent shockwaves through the international security community. The incident, reported on November 2, resulted in the theft of over 12,000 classified documents exposing sophisticated state-sponsored cyber weapons, internal hacking tools, and a comprehensive global target list spanning […]

    The post Data Leak Exposes Chinese State-Sponsored Cyber Arsenal and Target Database appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft researchers have unveiled a sophisticated side-channel attack targeting remote language models that could allow adversaries to infer conversation topics from encrypted network traffic. Despite end-to-end encryption via Transport Layer Security (TLS), the attack exploits patterns in packet sizes and timing to classify the subject matter of user prompts sent to AI chatbots. The research […]

    The post New Whisper-Based Attack Reveals User Prompts Hidden Inside Encrypted AI Traffic appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers have discovered an actively exploited remote code execution vulnerability in Monsta FTP, a web-based FTP client used by financial institutions, enterprises, and individual users worldwide. The flaw, now tracked as CVE-2025-34299, affects versions up to 2.11.2 and allows attackers to execute arbitrary code on vulnerable servers without authentication. CVE ID Vulnerability Type Affected […]

    The post Monsta FTP Remote Code Execution Flaw Being Exploited in the Wild appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • HackGPT Enterprise is a new tool made for security teams focuses on being scalable and compliant, meeting the growing need for effective vulnerability assessments.

    The platform supports multi-model AI, including OpenAI’s GPT-4 and local LLMs like Ollama, enabling pattern recognition, anomaly detection, and zero-day vulnerability discovery.

    Developed by Yashab Alam, this cloud-native platform integrates advanced AI and machine learning to automate professional-grade penetration testing.

    Its machine learning capabilities correlate threats, score risks using CVSS standards, and prioritize exploits, streamlining what was once a labor-intensive process.​

    CategoryKey FeaturesDescription
    Advanced AI EngineMulti-Model Support, Machine Learning, Zero-Day Detection, Risk Intelligence, Automated ReportingSupports OpenAI GPT-4, local LLMs like Ollama, TensorFlow, and PyTorch for pattern recognition, anomaly detection, behavioral analysis, ML-powered vulnerability discovery, CVSS scoring, impact assessment, exploit prioritization, and AI-generated executive summaries with compliance mapping.
    Enterprise Security & ComplianceAuthentication, Authorization, Compliance, Audit Logging, Data ProtectionIncludes RBAC with LDAP/Active Directory integration, role-based permissions for Admin, Lead, Senior, Pentester, and Analyst roles, support for OWASP, NIST, ISO27001, SOC2, and PCI-DSS frameworks, comprehensive activity tracking, and AES-256-GCM encryption with JWT tokens and secure sessions.
    Cloud-Native ArchitectureMicroservices, Service Discovery, Load Balancing, Multi-Cloud, High AvailabilityUtilizes Docker containers orchestrated by Kubernetes, Consul-based service registry, Nginx reverse proxy with auto-scaling, deployment support for AWS, Azure, and GCP, and features like circuit breakers, health checks, and failover for reliability.
    Performance & ScalabilityParallel Processing, Multi-Layer Caching, Database, Real-Time, Auto-ScalingEmploys Celery for distributed tasks, Redis with memory caching and TTL management, PostgreSQL with connection pooling and replication, WebSocket for live dashboard updates, and adaptive worker pools to handle workload demands.
    Enterprise Reporting & AnalyticsDynamic Reports, Real-Time Dashboards, Log Analytics, Executive Summaries, Compliance ReportsOffers exports in HTML, PDF, JSON, XML, and CSV formats; Prometheus + Grafana for monitoring; ELK stack (Elasticsearch + Kibana) for logs; AI-generated business impact assessments; and framework-specific compliance documentation.

    At its core, HackGPT follows an enhanced six-phase penetration testing methodology. Phase one automates OSINT reconnaissance with tools like theHarvester and Shodan, aggregating data from multi-cloud environments such as AWS and Azure.

    Scanning in phase two employs parallel processing with Nmap and Nuclei for service fingerprinting and vulnerability correlation.

    Subsequent phases handle assessment, safe exploitation via Metasploit, reporting, and retesting, all with built-in compliance mapping to OWASP, NIST, and PCI-DSS frameworks.

    Enterprise security features include RBAC with LDAP integration, AES-256 encryption, and audit logging to ensure robust data protection.​

    HackGPT’s microservices architecture, built on Docker and Kubernetes, supports high availability and multi-cloud deployments across AWS, Azure, and GCP.

    Performance is optimized with Celery for task distribution, Redis caching, and PostgreSQL databases, allowing real-time dashboards via WebSockets and analytics through Prometheus and Grafana.

    Deployment is straightforward: clone the GitHub repo, run the installer, and choose modes like standalone, API server, or full stack with docker-compose.

    Interfaces range from CLI for interactive assessments to a web dashboard for monitoring and voice commands for quick operations.​

    For enterprises, HackGPT reduces manual effort, enhances accuracy in threat detection, and generates dynamic reports in HTML, PDF, or JSON formats. It integrates with SIEM systems and supports custom AI models, making it adaptable for advanced users.

    Recent recognitions place it among the top AI cybersecurity tools of 2025, highlighting its role in proactive defense.​ HackGPT can be cloned from GitHub.

    Looking ahead, the roadmap includes version 2.1 in Q3 2025 with threat hunting and SIEM integrations, progressing to fully autonomous assessments in version 3.0 by Q1 2026.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post HackGPT: AI-Powered Penetration Testing Platform Includes GPT-4 and Other AI Engine’s appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • “We’re cooked,” one Army aviator said recently, describing the reactions of fellow students at the service’s helicopter flight school to Sikorsky’s new uncrewed Black Hawk. “Why are we even doing this, for real?”

    As the Army races to realize the promise of unmanned aircraft—more platforms, more flexibility, less risk to aircrew—it is shrinking the units that fly and maintain the helicopters that have long been central to the service’s way of war. Some pilots worry that their careers and expertise will be lost in the transition, even as some express optimism that the Army’s new contractor-run training approach will make tomorrow’s smaller aviation community better than ever.

    The Army has said it will will cut 6,500 of its 30,000 active-duty aviation-community soldiers over the next two years, mostly by removing one aerial cavalry squadron from each active-duty combat aviation brigade, as part of the effort to build “a leaner, more lethal force by infusing technology, cutting obsolete systems,” as Secretary Dan Driscoll and the service’s top uniformed leader Gen. Randy George put it in a May 1 letter.

    Panels are already scrutinizing the skills of pilots and other aircrew, some of whom may choose to leave their jobs, Maj. Gen. Clair Gil, who leads the service’s flight school, told reporters at the Association of the United States Army’s annual conference in Washington, D.C., last month.

    At the same time, Sikorsky isn’t slowing down. The defense company announced last week it taught an enlisted soldier, not a pilot, how to fly one of its autonomous helicopters. The sergeant oversaw the software-flown helicopter’s more than 70-nautical-mile cargo mission from a tablet. It took him less than an hour to learn the program.

    Current Army aviators are trying their best to stay optimistic, but fear that decades-worth of experience will be lost in the culling.

    “I’d like to believe the future won’t include completely offloading aerial resupply and air assault missions to unmanned aircraft, but maybe that’s my bias,” the aviator said in a message. “I think the bigger challenge is integrating technology (inevitable) to reduce risk to soldiers without losing the generational knowledge required to fly these complex systems.”

    But the Army doesn’t just want fewer pilots, it wants better-qualified ones; and it's looking to the defense industry for a solution. The service plans to turn its longtime entry-level helicopter education into a new contractor-owned and -operated model called Flight School Next. Officials and contractors said the new model will offer a simplified approach to training, develop better aviator skills, and save money by taking helicopters, instructors, and maintenance out of the service’s hands.

    While some current and former pilots are skeptical about the Army’s broader aviation strategy, they viewed a flight-school revamp as a much-needed opportunity for the military to reinvest in its future aviators and make training more efficient and competitive.

    “When you have our current experience to compare it to, you have to imagine that there's a better way,” the aviator said. “The Army has a reputation for saying ‘Hey, if we need 1,000 pilots, sure as shit, you're going to give me 1,000 pilots.’ But are those all pilots that we want to be walking across the graduation stage with? I can tell you, on a personal level, that I don't feel that right now.”

    Keeping it simple

    The deadly Jan. 29 collision of an Army UH-60 Black Hawk and a commercial airliner outside Washington, D.C., further increased scrutiny on pilots amid rising mishap rates.  

    There were 17 class-A mishaps, the term for the service’s deadliest and costliest incidents, in fiscal year 2024 alone—the most the service has seen since 2007. Army leaders have repeatedly said declining aviator skills has been a factor.

    “One of the things that we've noticed over the last couple years is our accident trends are moving in the wrong direction,” Gil said, saying senior leaders identified shortcomings among some aviators and told him, “‘We have a very talented population that's coming out. They're inexperienced, they're very good at systems operations. They're not very good at flying fundamentals.’”

    He said that’s partly because the helicopter used to train new Army pilots since 2015—the twin-engine Airbus UH-72 Lakota—doesn’t allow aviators to practice certain techniques. 

    “We're looking at single-engine trainers. Those are aircraft that we've flown in flight school for years before we went to the current UH-72. Where we trained maneuvers like auto-rotations and things we call stuck-pedal or anti-torque maneuvers—things that we don't train in a dual-engine aircraft. This is going to give us an opportunity to go back to that,” Gil said at AUSA. 

    And, he added: “A single-engine, two-bladed aircraft is going to be fundamentally cheaper to operate than a twin-engine, four-bladed aircraft.”

    Defense companies have been eager to pitch their ideas for Flight School Next. Leonardo and Boeing are teaming up to offer a “turnkey, innovative approach” using Leonardo’s AW119T training helicopter and Boeing’s experience with the AH-64 Apache.

    Defense contractor Bell has pitched its single-engine 505 helicopter and the expert instructors at its Bell Training Academy in Fort Worth, Texas, as a possible solution.

    “Not only do we believe we have the right aircraft for this program…but also Bell has been training pilots, including Army pilots, for a long, long time. We trained the first Army pilots in 1946,” Matthew Dorram, capture lead for Flight School Next for Bell, said in an interview on the sidelines of AUSA.

    Several contractors are reportedly vying for the contract with single-engine training helicopters, including MD Helicopters, Enstrom, and at least two teams, including Boeing and Leonardo and Robinson and M1 Support Systems. Airbus, who is also making an offer for the new contract, has defended its UH-72 Lakota helicopters from the Army’s criticisms, saying its stability and autopilot features can be easily toggled off for a more rigorous training experience.

    “With its unmatched safety record, superior training versatility, the UH-72A Lakota remains the premier platform for preparing America’s next generation of Army aviators,” the company said in a July statement.

    Lowering costs, raising morale

    Problems with the Army’s training system are perhaps exemplified by the recent news that maintenance woes will extend new aviators’ required decade of service to 12 years or even more.

    In July, Army officials announced that flight school at Fort Rucker, Alabama, was moving slowly, “largely due to maintenance challenges with the AH-64 Apache helicopter.” Flight school students from the 2023 group were still waiting to finish their courses while the Army Aviation Center of Excellence was waiting to receive the class of 2026. Instead of starting the 10-year service clock after graduating flight school, officials announced they were moving it forward to begin after completion of Initial Entry Rotary Wing training.

    “This means it may be over two years before some students graduate flight school, so their 10-year ADSO grows to 12 or 12 and a half years, at no fault of the soldier,” said Kenneth Hawley, the center’s organization and personnel force development director, in the news release.

    It’s hard to keep spirits high when training pilots are grounded, the Army aviator said. 

    “The sentiment broadly among current flight school students right now is that flight school is dealing with a multitude of maintenance, timing, and aircraft issues,” the aviator said. “Morale, specifically in the Apache course, is rock-bottom.”

    Older veterans, like Dan McClinton, have also seen concerning trends in Army flight school. The retired Apache pilot and 1987 flight school attendee said the Army made poor choices with helicopter training in the past, speculating the service was prioritizing costs, not quality.

    “There's always a desire to do more with less, because it's a money game,” McClinton said, but added he seemed less worried about the cost-savings angle of Flight School Next. 

    “It's not like they're doing that solely for the reason to save money, it just happens to save money,” McClinton said. “Because if the Army had to buy all those helicopters, obviously the cost would be a lot more. So, they're putting that on the contractor.”

    While both McClinton and the Army aviator in flight school remained optimistic about changes to flight school, they expressed some skepticism about the Army’s inevitable pivot to unmanned systems.

    “I understand, you know, technology is changing and I'm fully on board with trying to take advantage of technology when you can, but I am concerned that they may be going too far, too fast,” McClinton said. 

    At AUSA, Boeing announced it was designing a tiltrotor drone wingman concept to support the Army’s helicopter fleet, with company officials saying it comes as service leaders evolve the Apache’s role in battle.

    Unmanned technology will evolve. But until they’re fully replaced, Army aviators say they’re focusing on becoming the best pilots the service still, hopefully, needs.

    “It’s a really interesting time,” the aviator said. “We will look back at this year for Army aviation and think of it as a really pivotal time in the future of this transformation that we're in the midst of. Because, at the same time that we are focusing on those unmanned systems and we recognize the value they’re playing in the modern battlefield, we're still trying to provide good, extensive training for the pilots that we have.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶