• A sophisticated new Android malware family called GhostGrab is actively targeting mobile users with a dual-monetization strategy that combines covert cryptocurrency mining with comprehensive financial data theft. GhostGrab functions as a multifaceted threat that systematically harvests banking credentials, debit card details, personal identification information, and one-time passwords through SMS interception. According to analysis by CYFIRMA, […]

    The post New GhostGrab Android Malware Silently Steals Banking Login Details and Intercept SMS for OTPs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The North Korean-linked threat group BlueNoroff, also known by aliases including Sapphire Sleet, APT38, and Alluring Pisces, continues to evolve its attack tactics while maintaining its primary focus on financial gain. The group has shifted its strategy to employ sophisticated new infiltration methods targeting high-value victims including C-level executives, managers, and blockchain developers within the […]

    The post BlueNoroff Shifts Tactics: Targets C-Suite and Managers with New Infiltration Methods appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new zero-click attack dubbed Shadow Escape exploits the Model Context Protocol (MCP) to silently steal sensitive data via popular AI agents such as ChatGPT, Claude, and Gemini.

    This vulnerability, uncovered by Operant, allows malicious actors to exfiltrate personally identifiable information, including Social Security numbers and medical records, without user interaction or detection by traditional security tools.

    Shadow Escape operates by embedding hidden malicious instructions in seemingly innocuous documents, such as employee onboarding PDFs downloaded from public sources.

    When uploaded to an MCP-enabled AI assistant, these instructions prompt the AI to access connected databases, CRM systems, and file shares, thereby surfacing private data such as names, addresses, credit card details, and protected health information.

    The AI, acting under trusted credentials, then disguises exfiltration as routine tasks, such as performance logging, sending data to external servers linked to the dark web, all within the organization’s firewall and without alerting users or IT teams.

    Data Exfiltration
    Data Exfiltration

    This attack chain unfolds in stages: infiltration via poisoned files, discovery of sensitive records across multiple systems, and covert transmission.

    Unlike prior threats requiring phishing or errors, Shadow Escape leverages MCP’s design for seamless AI-tool integration, turning helpful agents into unwitting vectors for identity theft and fraud.

    First Zero Click Attack Exploits MCP

    Demonstrated in a video by Operant AI, the exploit escalates from a simple query to full data dumps in minutes, affecting healthcare, finance, and retail sectors where AI aids customer service.

    The discovery, revealed during Cybersecurity Awareness Month, highlights MCP’s role in amplifying risks as enterprises adopt agentic AI for efficiency.

    Any MCP-connected system from OpenAI’s ChatGPT to custom Llama-based agents is vulnerable, potentially exposing trillions of records due to widespread default permissions.

    Donna Dodson, former NIST cybersecurity chief, warned that securing MCP and agent identities is “absolutely critical,” especially in high-stakes industries.

    Traditional defenses like data loss prevention fail here, as traffic appears legitimate over encrypted channels. Operant AI estimates massive undetected breaches already occurring, urging immediate audits of AI permissions and integrations.

    To counter Shadow Escape, experts recommend contextual identity access management, document sanitization before upload, real-time tool monitoring, and inline data redaction.

    Operant AI’s MCP Gateway provides runtime controls to block exfiltration at the AI layer. Organizations must treat all external documents as threats, enforce least-privilege access, and implement AI-specific observability across multi-platform deployments.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post First Zero Click Attack Exploits MCP and Connected Popular AI Agents To Exfiltrate Data Silently appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A significant security vulnerability has emerged affecting QNAP’s NetBak PC Agent software through a critical flaw in Microsoft ASP.NET Core. The vulnerability, tracked as CVE-2025-55315, exploits HTTP Request Smuggling techniques to bypass essential security controls and could expose thousands of backup-dependent systems to unauthorized access and data manipulation. Attribute Details CVE ID CVE-2025-55315 Vulnerability Type […]

    The post Critical QNAP .NET Flaw Lets Attackers Bypass Security Protections appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The zero-day exploitation of a now-patched security flaw in Google Chrome led to the distribution of an espionage-related tool from Italian information technology and services provider Memento Labs, according to new findings from Kaspersky. The vulnerability in question is CVE-2025-2783 (CVSS score: 8.3), a case of sandbox escape which the company disclosed in March 2025 as having come under

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Svenska kraftnät, Sweden’s national power grid operator, has confirmed it suffered a significant data breach that exposed certain information to unauthorized parties. The incident, disclosed on October 26, 2025, is linked to the notorious Everest ransomware gang, marking a concerning development in the ongoing wave of cyberattacks targeting critical infrastructure operators across Europe. Critical Infrastructure […]

    The post Sweden’s Power Grid Operator Admits Data Breach Linked to Everest Ransomware Gang appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Trend Micro Research has identified a significant evolution in the aggressive Water Saci malware campaign, revealing a new infection chain that abandons traditional .NET-based delivery methods in favor of sophisticated script-driven techniques. On October 8, 2025, researchers discovered file downloads originating from WhatsApp Web sessions that utilize Visual Basic Script downloaders and PowerShell scripts to […]

    The post Water Saci Hackers Use WhatsApp to Deploy Persistent SORVEPOTEL Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark advisory highlighting two severe vulnerabilities in Veeder-Root’s TLS4B Automatic Tank Gauge System, a critical tool used in fuel storage and management across the energy sector.

    These flaws, if exploited, could enable attackers to run arbitrary system-level commands on affected devices, potentially leading to widespread disruptions in critical infrastructure.

    The primary vulnerability has a CVSS v4 score of 9.4, making it highly exploitable remotely and low-complexity, especially for those with basic credentials.

    Veeder-Root, a U.S.-based company with global deployments, urges immediate upgrades to mitigate these risks, as reported by researcher Pedro Umbelino of Bitsight.

    The vulnerabilities stem from flaws in the system’s handling of commands and time values, exposing Linux-based consoles to manipulation.

    Discovered in systems deployed worldwide for monitoring underground storage tanks, they underscore ongoing challenges in securing industrial control systems (ICS) against sophisticated threats.

    CISA emphasizes that these issues affect energy operations, where downtime could cascade into fuel supply interruptions or safety hazards.

    Vulnerability Breakdown

    The TLS4B system, versions prior to 11.A, suffers from a command injection flaw and an integer overflow related to the 2038 Unix epoch problem.

    The command injection (CWE-77) arises in the SOAP-based web services interface, allowing authenticated remote attackers to inject malicious elements and execute Linux shell commands.

    This could grant full system access, enabling data theft or further network compromise.

    A secondary integer overflow (CWE-190) mishandles time values beyond the 2038 rollover, resetting the clock to 1901 and causing authentication failures, log corruption, and halted leak detection.

    Attackers could exploit this for denial-of-service (DoS) by tampering with system time, locking out administrators, and disrupting operations.

    CVE IDDescriptionAffected ProductsCVSS v3.1 Score (Vector)CVSS v4 Score (Vector)
    CVE-2025-58428Command Injection (CWE-77) via SOAP interface; enables RCE and shell access.TLS4B (prior to 11.A)9.9 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)9.4 (AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
    CVE-2025-55067Integer Overflow (CWE-190) in Unix time handling; triggers DoS and functional disruptions.TLS4B (prior to 11.A)7.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H)7.1 (AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N)

    Mitigations

    Exploitation could yield remote command execution, lateral movement, administrative lockouts, and DoS conditions, severely impacting energy infrastructure reliability.

    With low barriers to entry requiring only valid credentials, these flaws heighten risks for unpatched systems.

    Veeder-Root recommends upgrading to TLS4B version 11.A for the command injection fix; for the overflow issue, a patch is in development, so users should follow network security best practices like isolating devices and securing ports.

    CISA advises minimizing internet exposure, deploying firewalls, and using VPNs for remote access while conducting thorough risk assessments.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post CISA Warns Of Critical Veeder-Root Vulnerabilities Let Attackers Execute System-level Commands appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft is enhancing Windows 11’s stability with a new feature that prompts users for a quick memory diagnostic scan following blue screen of death (BSOD) incidents.

    This proactive tool aims to detect and mitigate memory corruption issues that often lead to unexpected restarts, potentially reducing future system crashes.

    Announced in recent Windows Insider builds, the update reflects Microsoft’s ongoing efforts to refine OS diagnostics amid rising reports of hardware-related failures.

    The system triggers a notification upon login after a bugcheck, which is a critical kernel or driver error causing a BSOD. Users see a prompt suggesting a “quick memory scan,” scheduling the Windows Memory Diagnostic tool to run during the next reboot.

    This scan typically lasts under five minutes, allowing the PC to boot into Windows afterward.

    Windows Memory Diagnostics dialog
    Windows Memory Diagnostics dialog

    If memory problems are identified and addressed, a post-reboot alert informs the user of the resolution. In early testing, all bugcheck codes activate the prompt to gather data on memory-crash correlations.

    Not every device supports this yet; it’s unavailable on Arm64-based systems, on systems with Administrator Protection enabled, or on BitLocker setups without Secure Boot.

    The feature debuted in Insider Preview Build 26220.6982 for the Dev Channel and Build 26120.6982 for Beta, via update KB5067109.

    Microsoft plans to narrow triggers to specific error types in future releases, improving precision without overwhelming users.

    This aligns with broader Windows 11 updates, including AI enhancements like Copilot integrations. As PCs handle more demanding tasks, such tools could prevent data loss and downtime, especially for professionals reliant on stable systems.

    The initiative underscores memory issues as a common BSOD culprit, urging timely hardware checks. With rollout expanding, Windows users may soon experience fewer frustrating interruptions.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Windows Introduces Quick Memory Scan Feature During Restart After BSOD Crashes appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical security alert regarding serious vulnerabilities in Veeder-Root’s TLS4B Automatic Tank Gauge System. Released on October 23, 2025, the alert warns that attackers could exploit these flaws to take control of industrial systems used worldwide, particularly in the energy sector. Two Critical Vulnerabilities Discovered Security […]

    The post CISA Alerts on Critical Veeder-Root Flaws Allowing Attackers to Execute System Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶