• A new exploitation method has been discovered for the Linux kernel use-after-free (UAF) vulnerability tracked as CVE-2024-50264. The vulnerability was awarded the Pwnie Award 2025 for Best Privilege Escalation due to its complexity and impact on major Linux distributions. Researchers developed innovative techniques to bypass kernel slab allocator and race condition protections, making exploitation much more feasible than […]

    The post New Exploitation Method Discovered for Linux Kernel Use-After-Free Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Dynatrace has confirmed that customer data stored in Salesforce was exposed following a third-party breach involving Salesloft’s Drift application. The incident, which occurred in August 2025, allowed unauthorized access to Salesforce CRM data across multiple companies. Both Salesloft and Salesforce responded by disabling the compromised integrations and notifying affected customers. Incident Overview The breach stemmed […]

    The post Dynatrace Data Breach Exposes Customer Information Stored in Salesforce appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly demonstrated attack technique has revealed a flaw in how Windows Defender manages its update and execution mechanism. By exploiting symbolic links, attackers can hijack Defender’s service folders, gain full control over its executables, and even disable the antivirus entirely. How the Exploit Works Windows Defender stores its executables inside versioned folders under ProgramData\Microsoft\Windows Defender\Platform. […]

    The post Windows Defender Vulnerability Lets Hackers Hijack and Disable Services Using Symbolic Links appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The North Korean-aligned threat group APT37, also known as ScarCruft, Ruby Sleet, and Velvet Chollima, has evolved its cyber warfare capabilities by deploying sophisticated Rust and Python-based malware in recent campaigns targeting Windows systems. Active since 2012, this advanced persistent threat group continues to focus on South Korean individuals connected to the North Korean regime […]

    The post APT37 Deploys New Rust and Python Malware Targeting Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Dynatrace has confirmed it was impacted by a third-party data breach originating from the Salesloft Drift application, resulting in unauthorized access to customer business contact information stored in its Salesforce CRM.

    The company confirmed that the incident was limited to its CRM platform and did not impact any core Dynatrace products, services, or sensitive customer environments.

    The security incident originated in August 2025, when threat actors compromised Salesloft’s Drift application, a popular third-party tool used for customer engagement.

    This compromise allowed the attackers to gain unauthorized access to the Salesforce environments of companies utilizing the app.

    In response to the attack, Salesloft and Salesforce moved to disable the compromised connections and began notifying affected clients, which included the observability giant Dynatrace.

    Dynatrace’s Response And Investigation

    Upon receiving notification of the third-party breach, Dynatrace’s security team took immediate action by disabling the Drift application within its environment to sever the connection and prevent further unauthorized access.

    The company launched a comprehensive investigation, bringing in third-party cybersecurity experts to determine the full scope of the incident.

    The investigation confirmed that the malicious activity was limited exclusively to its Salesforce CRM instance, which the company uses for managing customer relationships and marketing activities.

    Critically, Dynatrace clarified that none of its own products or services were compromised. This includes any systems that house customer data or services that directly interface with customer systems.

    Furthermore, the company reported that it does not utilize the “case function” within Salesforce, meaning no customer support case information was accessible to the attackers.

    Dynatrace assured stakeholders that the incident caused no disruption to its business operations. The data exposed in the breach is limited to business contact information. This includes the first and last names of customer contacts and their associated company identifiers.

    No sensitive credentials, financial details, or other confidential information were accessed. After a period of investigation and remediation, Salesloft notified Dynatrace on September 7th that the secure connections had been re-enabled.

    In light of the exposure of business contact information, Dynatrace has issued guidance to its customers, urging them to exercise increased caution against potential social engineering and phishing campaigns.

    The company emphasized that its employees will never contact customers via phone or email to request passwords, multi-factor authentication (MFA) codes, or other sensitive credentials.

    Customers are advised to be vigilant and verify that all communications and links originate from trusted Dynatrace domains.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post Dynatrace Confirms Data Breach: Hackers Accessed Customer Data From Salesforce appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Multiple npm packages have been compromised as part of a software supply chain attack after a maintainer’s account was compromised in a phishing attack. The attack targeted Josh Junon (aka Qix), who received an email message that mimicked npm (“support@npmjs[.]help”), urging them to update their update their two-factor authentication (2FA) credentials before September 10, 2025, by clicking on

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers at Silent Push have uncovered a sophisticated Chinese espionage operation linking two prominent threat actors, Salt Typhoon and UNC4841, revealing previously unreported infrastructure used to target government and corporate networks across more than 80 countries. The discovery of 45 malicious domains dating back to 2020 demonstrates the extensive reach and long-term persistence of […]

    The post Chinese Hackers Salt Typhoon and UNC4841 Team Up to Breach Critical Infrastructure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In the largest supply chain attack, hackers compromised 18 popular npm packages, which together account for over two billion downloads per week. The attack, which began on September 8th, involved injecting malicious code designed to steal cryptocurrency from users.

    The compromised packages include widely used libraries such as chalk, debug, ansi-styles, and supports-color. The malicious code was added in new versions of these packages and was engineered to execute on the client-side of websites using them.

    The malware silently intercepts cryptocurrency and Web3 activities within the browser, manipulating wallet interactions and rewriting payment destinations to redirect funds to attacker-controlled accounts.

    The malware operates as a sophisticated in-browser interceptor, targeting both network traffic and application-level APIs. It achieves this by hooking into core browser functions like fetch XMLHttpRequest, as well as interfaces for popular crypto wallets for Ethereum, Solana, and other blockchains, Akidio observed.

    The malicious code works in a series of steps:

    1. Injection and Hooking: It embeds itself into the browser environment and takes control of functions related to web requests and wallet communications.
    2. Scanning for Sensitive Data: The malware actively scans network responses and transaction details for patterns matching cryptocurrency wallet addresses for various blockchains, including Bitcoin, Ethereum, Solana, Tron, Litecoin, and Bitcoin Cash.
    3. Rewriting Wallet Addresses: Upon finding a legitimate address, the malware replaces it with a look-alike address from a hardcoded list belonging to the attackers. This is done using string-matching algorithms to make the swap less noticeable to the user.
    4. Hijacking Transactions: The code alters transaction parameters before the user signs them. This means that even if the user interface displays the correct recipient address, the signed transaction will route funds or grant token approvals to the attackers.

    The maintainer of the compromised packages revealed they fell victim to a phishing attack. An email, seemingly from npm support, was sent from the domain npmjs.help, tricking the developer into revealing their credentials, according to a Hacker News post.

    This domain was registered only three days before the attack on September 5, 2025.

    Phishing Mail compromised the developer

    The maintainer became aware of the compromise and began taking steps to remove the malicious versions of the packages. However, at the time of the report, at least one package, simple-swizzle, remained compromised.

    The incident also revealed that the same attackers may have compromised another package, proto-tinker-wc, using similar methods.

    The following table lists the affected packages and the compromised versions:

    PackageMalicious Version
    backslash0.2.1
    chalk-template1.1.1
    supports-hyperlinks4.1.1
    has-ansi6.0.1
    simple-swizzle0.2.3
    color-string2.1.1
    error-ex1.3.3
    color-name2.0.1
    is-arrayish0.3.3
    slice-ansi7.1.1
    color-convert3.1.1
    wrap-ansi9.0.1
    ansi-regex6.2.1
    supports-color10.2.1
    strip-ansi7.1.1
    chalk5.6.1
    debug4.4.2
    ansi-styles6.2.2

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post Hackers Hijacked 18 Very Popular npm Packages With 2 Billion Weekly Downloads appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers have hijacked 18 extremely popular npm packages, downloaded more than 2 billion times every week, injecting them with sophisticated malware that targets cryptocurrency users and developers. Early on September 8th, a security feed flagged the sudden update of 18 npm packages—including favorites like chalk, debug, chalk-template, and supports-color—with malicious code, as per a report by Aikio. These packages […]

    The post Hackers Hijack 18 Popular npm Packages Downloaded Over 2 Billion Times Weekly appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Venezuelan President Nicolás Maduro made bold claims about cybersecurity during a press conference on September 1, 2025, as he showcased a Huawei smartphone gifted to him by Chinese President Xi Jinping. Holding up the device before international media in Caracas, Maduro declared it “the best phone in the world” and asserted that “the Americans can’t […]

    The post Maduro Hails Huawei Mate X6 Gift From China as ‘Unhackable’ by U.S. appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶