• A newly advertised information-stealing malware called Anivia Stealer has surfaced on the dark web, with threat actor ZeroTrace aggressively promoting the C++17-based infostealer as a commercial malware-as-a-service offering. The malware implements sophisticated privilege escalation capabilities, including automatic User Account Control (UAC) bypass functionality, making it a significant threat to Windows-based systems across multiple operating system […]

    The post Anivia Stealer Peddled on Dark Web with UAC Bypass appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In cybersecurity, speed isn’t just a win — it’s a multiplier. The faster you learn about emerging threats, the faster you adapt your defenses, the less damage you suffer, and the more confidently your business keeps scaling. Early threat detection isn’t about preventing a breach someday: it’s about protecting the revenue you’re supposed to earn every day. Companies that treat cybersecurity as a

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The cybersecurity landscape continues to evolve with increasingly sophisticated distribution mechanisms, and one trend gaining alarming momentum is the delivery of infostealer malware through seemingly innocent video game cheats and mod tools.

    These applications, marketed as performance enhancers or gameplay assistants, have become a Trojan horse for credential theft campaigns targeting both casual gamers and professional users.

    The proliferation of these threats underscores a critical vulnerability in user awareness and software verification practices across the gaming community.

    The attack vectors leveraging game cheats have demonstrated remarkable effectiveness, particularly due to the inherent trust users place in gaming resources.

    Threat actors exploit this psychological advantage by embedding malicious payloads within cheat engines, mod managers, and game optimization tools distributed through torrenting platforms, forum boards, and unofficial game communities.

    These infostealer variants specifically target stored credentials, cryptocurrency wallets, browser cookies, and sensitive authentication tokens, making them exceptionally valuable in the underground market.

    Gen Threat Labs analysts identified this emerging malware distribution trend during routine threat monitoring operations in late October 2025, noting an acceleration in infostealer campaigns leveraging gaming platforms as primary delivery channels.

    The research team documented specific variants employing sophisticated evasion techniques to circumvent traditional antivirus detection while maintaining persistent command-and-control communication patterns.

    Infection Mechanism and Persistence Tactics

    The typical infection chain begins when users download compromised cheat software from seemingly reputable gaming forums or torrent sites.

    Upon execution, the infostealer establishes residency through Windows Registry modifications, creating legitimate-appearing startup entries that blend seamlessly with genuine system processes.

    The malware implements a multi-staged approach where initial reconnaissance collects system information and existing credentials, followed by exfiltration to attacker-controlled infrastructure.

    The persistence layer employs scheduled task creation and process injection techniques to maintain access across system reboots. Security researchers observed samples using legitimate Windows utilities for credential dumping, including LSASS memory scraping and SAM database extraction.

    The malware typically communicates with command-and-control servers using encrypted HTTPS channels to report stolen data, receive configuration updates, and download additional payloads.

    Users seeking enhanced gaming experiences should strictly obtain cheats and mods exclusively from official game publishers or well-established, verified community repositories with strong security records.

    Implementing multi-factor authentication, maintaining updated endpoint protection, and deploying behavioral monitoring solutions provide meaningful layers of defense against these evolving threats.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post New Gamaredon Phishing Attack Targeting Govt Entities Exploiting WinRAR Vulnerability appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Active Directory domain join accounts are systematically exposing enterprise environments to compromise, even when administrators follow Microsoft’s official guidance. A comprehensive security analysis reveals that these specialized accounts inherit excessive privileges by default, creating a direct pathway for attackers to escalate access from internal networks to full domain control. During security assessments, domain join accounts […]

    The post Active Directory at Risk Due to Domain-Join Account Misconfigurations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have uncovered a sophisticated evolution in phishing attacks that combines FileFix social engineering with cache smuggling techniques to bypass modern security defenses. This hybrid attack method eliminates the need for malicious code to make web requests, instead extracting payloads directly from the browser’s cache where they were planted through cache smuggling. The technique […]

    The post FileFix + Cache Smuggling: A New Evasion Combo appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The competitive nature of gaming drives millions of players to seek advantages against their opponents. With esports tournaments boasting prize pools exceeding $1.25 million, the stakes have never been higher.

    However, this competitive spirit has created an opportunity for cybercriminals to exploit unsuspecting players through weaponized game cheats that deliver devastating malware payloads.

    The reality of free game cheats presents a significant security risk that extends far beyond simple detection bans.

    While premium cheats rely on subscription-based models and sophisticated evasion techniques, free alternatives flooding forums, YouTube channels, and file-sharing platforms contain far more sinister purposes.

    Many players searching for free cheats on Fortnite, Apex Legends, Counter-Strike 2, and even casual games like Minecraft and Roblox unknowingly download information stealing malware, Discord token grabbers, or remote access trojans alongside their desired cheating tools.

    Product page for a popular Fortnite cheat (Source – (Source – vxdb.sh)

    Security analyst and researcher vxdb noted a particularly concerning campaign where criminals disguise infostealer malware as legitimate game cheats.

    What makes this threat especially dangerous is that users often receive partially functional cheating tools alongside hidden malware, creating a false sense of legitimacy while data harvesting occurs silently in the background.

    The Traffer Teams Distribution Network

    The orchestration of these malware campaigns relies on organized criminal groups known as Traffer Teams, which manage entire operations from recruitment through monetization.

    These teams operate by recruiting affiliate traffers who distribute malware across popular platforms like YouTube and TikTok.

    The distribution chain typically begins with videos uploaded to stolen or fake YouTube accounts, using Linkvertise services to funnel viewers through advertising obstacles before reaching file-sharing platforms like MediaFire or Meganz.

    A recent investigation by security researcher Eric Parker uncovered a sophisticated campaign where a Traffer Team called LyTeam operated a Google Sites page distributing so-called Valorant skin changers and Roblox executors.

    Upon analysis, the downloaded .dll files were identified as Lumma Stealer malware variants, a notorious information-stealing family designed to harvest browser credentials and cryptocurrency wallets.

    The affiliate structure incentivizes distribution through direct payments or percentage cuts of harvested data logs, creating a profitable ecosystem for cybercriminals.

    Understanding the infection mechanism reveals how these campaigns succeed despite basic security awareness.

    The malware executes with user-level privileges after execution, immediately targeting sensitive data repositories.

    Once installed, the stealer establishes persistence mechanisms that survive system reboots, continuously exfiltrating credentials, cookies, authentication tokens, and wallet information to attacker-controlled servers.

    The modular nature of these malware families allows attackers to deploy additional payloads or activate dormant features as needed, making them particularly adaptable threats.

    Players seeking competitive advantages must recognize that free shortcuts carry substantial risks.

    The safest approach involves scanning suspicious files through VirusTotal before execution, using virtual machines or sandboxed environments for untrusted downloads, and maintaining current antivirus protection across gaming systems.

    Awareness remains the most effective defense against these increasingly sophisticated threats.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Beware of Free Video Game Cheats That Delivers Infostealer Malwares appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Operant AI’s security research team has uncovered Shadow Escape, a dangerous zero-click attack that exploits the Model Context Protocol to steal sensitive data through AI assistants. The attack works with widely used platforms, including ChatGPT, Claude, Gemini, and other AI agents that rely on MCP connections to access organisational systems. Unlike traditional security breaches requiring […]

    The post Zero-Click Exploit Targets MCP and Linked AI Agents to Stealthily Steal Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The New Reality for Lean Security Teams If you’re the first security or IT hire at a fast-growing startup, you’ve likely inherited a mandate that’s both simple and maddeningly complex: secure the business without slowing it down. Most organizations using Google Workspace start with an environment built for collaboration, not resilience. Shared drives, permissive settings, and constant

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Svenska kraftnät, Sweden’s primary electricity transmission system operator, has confirmed a significant data breach on October 26, 2025.

    The incident has drawn attention from cybersecurity experts and government authorities as it involves critical infrastructure responsible for managing the nation’s power distribution network.

    The Swedish power grid operator publicly acknowledged the security incident, revealing that attackers gained unauthorized access to certain sensitive information within their systems.

    Cem Göcgören, Head of Information Security at Svenska kraftnät, stated that the organization is actively investigating the scope and nature of the compromised data.

    Swedish Power Grid Operator Data Breach

    The statement emphasized that while a breach occurred, there are currently no indicators suggesting that the core electricity distribution system itself has been affected or compromised.

    Svenska kraftnät immediately reported the incident to Swedish law enforcement and established communication with relevant government authorities possessing expertise in cybersecurity and critical infrastructure protection.

    This coordinated response reflects standard procedures for addressing breaches involving essential services that affect the entire nation’s energy security and public safety.

    The Everest ransomware gang, a known cybercriminal organization, has publicly claimed responsibility for the attack on Svenska kraftnät.

    This represents another high-profile incident targeting critical infrastructure, adding to growing concerns about ransomware groups specifically targeting essential services.

    The gang’s involvement suggests a calculated approach to compromise organizations managing vital systems that could potentially disrupt national infrastructure if encryption or destruction of data were successful.

    While Swedish authorities have confirmed that the electricity system remains operational and secure, the breach raises questions about the cybersecurity posture of critical infrastructure organizations across Europe.

    Power grid operators face increasing sophistication in cyberattacks, with ransomware groups demonstrating knowledge of how to access sensitive networks while maintaining operational technology systems.

    The incident highlights the distinction between information technology systems and operational technology systems within power utilities.

    Even though operational systems remain secure, compromised data may contain valuable intelligence about network architecture, employee information, or other sensitive details that could be leveraged in future attacks.

    Svenska kraftnät’s swift response and transparency regarding the incident demonstrate best practices in incident communication. By immediately notifying authorities and the public, the operator has maintained trust while investigations continue.

    Energy providers must continue strengthening their cybersecurity defenses, implementing zero-trust architecture, and maintaining robust incident response protocols.

    Swedish authorities will likely conduct a thorough investigation into the breach while implementing additional security measures to prevent similar incidents affecting other critical infrastructure operators across the Nordic region.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Swedish Power Grid Operator Confirms Data Breach Following Everest Ransomware Gang Claim appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has firmly denied claims of a massive Gmail security breach affecting millions of users. The tech giant emphasized that its email service remains secure, with no evidence of a widespread compromise.

    Instead, the misinformation appears to stem from a misinterpretation of existing data leaks involving stolen credentials from various online sources.

    Social media and online forums buzzed with alarm earlier this week after reports surfaced suggesting that hackers had accessed Gmail accounts.

    Users panicked, sharing stories of potential data exposure and urging immediate password changes. However, Google’s security team clarified that these claims are unfounded, attributing the confusion to the nature of infostealer malware databases.

    Infostealer tools, often deployed by cybercriminals, scrape credentials from infected devices worldwide. These databases aggregate stolen login details from countless websites, not just Gmail.

    The recent buzz likely arose from a large compilation of such data being publicized, creating the illusion of a targeted Gmail attack. Experts note this is a common tactic in the cybercrime ecosystem, where old and new breaches get bundled together without context.

    Google’s statement highlighted that no new vulnerability or breach specifically targeting Gmail infrastructure occurred. The company’s robust defenses, including advanced encryption and real-time monitoring, continue to safeguard user accounts.

    This isn’t the first time such misunderstandings have fueled unnecessary fear; similar false alarms have popped up with other major platforms in the past.

    To counter credential theft risks, Google recommends enabling 2-step verification on all accounts, which adds an extra layer of protection beyond passwords.

    The company is also pushing passkeys as a phishing-resistant alternative, allowing seamless logins via biometrics or device security.

    For those whose credentials appear in leaked batches, resetting passwords promptly is crucial. Google actively monitors for large-scale credential exposures and notifies affected users, often automating password resets where possible.

    For more guidance, users can visit Google’s support page on securing accounts against infostealer threats.

    As cybersecurity threats evolve, distinguishing hype from reality becomes essential. Google’s reassurance underscores the importance of verified information in an era of rapid digital news cycles.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Google Denies Claims of Gmail Security Breach Impacting Millions appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶