Install
GBHackers Security | #1 Globally Trusted Cyber Security News Platform | GBhackers Offering Exclusive Cyber Security News Coverage, New Research papers & Technology Updates. gbhackers.com GBhackers Offering Exclusive Cyber Security News Coverage, New Research papers & Technology Updates.
- 262articles · 30d
- 4+ day agolatest article
- Aug 17, 2026earliest in window
- 40%with images
- 375avg words
- Computers & Electronics 177
- Science & Technology 158
- Software 127
- Conflict, War & Peace 76
- Crime & Law 70
- Software Dev. 55
- Internet & Telecom 41
- News 24
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- threatsday bulletin
- digital world
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
New AI Workflow Identity Hijacking Attack Lets Hackers Exfiltrate Sensitive Data
4+ day, 9+ hour ago (539+ words) Research published by Noma Labs researcher Sasi Levi reveals that this attack does not rely on prompt injection, stolen credentials, or jailbreaking an AI model. Instead, it exploits a fundamental authorization flaw: AI workflows can process untrusted input from low-privileged…...
Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft
4+ day, 4+ hour ago (616+ words) Nearly one in 10 internet-exposed LiteLLM AI gateways accepted the widely documented default master key, sk-1234, or required no authentication, creating a direct path to LLMjacking, sensitive credential exposure, and in vulnerable versions root-level code execution inside the gateway container. Their…...
Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts
4+ day, 8+ hour ago (444+ words) Microsoft Security Research said it has observed the cloud-focused intrusions since May 2026. The campaign begins with a phone call or SMS sent to an employee’s personal device. Posing as IT support, the caller claims the target must urgently update a…...
ChatGPT Flaw Could Let Attackers Steal Gmail Data Across User Accounts
5+ day, 7+ hour ago (549+ words) Security researchers have revealed a recently patched flaw in ChatGPT’s isolation system that could have allowed attackers to access data from a victim’s connected Gmail account and send it to a separate ChatGPT account through a hidden cross-account channel. Check…...
Massive Redis Cryptojacking Campaign Hijacks Thousands of Linux Servers
5+ day, 12+ hour ago (569+ words) The campaign scans IPv4 address ranges for Redis services exposed to the internet, typically on TCP port 6379, then attempts to interact with instances that allow connections without authentication. Once access is obtained, the attackers use Redis’s administrative CONFIG SET command to…...
SAP September 2026 Security Update Fixes 4 Critical Vulnerabilities and 15 Other Flaws
6+ day, 7+ hour ago (372+ words) SAP released 19 new Security Notes addressing four critical vulnerabilities and 15 additional flaws throughout its enterprise portfolio. The vendor also updated one note from August. The most urgent issue is CVE-2026-44756, a memory-corruption vulnerability in Extended Passport (EPP) Processing with a…...
Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials
1+ week, 5+ hour ago (632+ words) The campaign’s central advantage is that it presents trusted Google-owned domains at nearly every point a gateway, proxy, or analyst is likely to inspect. Rather than relying on a malicious URL evading detection, the actors use legitimate redirect and tracking…...
Critical N-able N-central Flaw Enables Pre-Auth Remote Code Execution
1+ week, 9+ hour ago (379+ words) N-able has released a security update to address CVE-2026-86218, a critical-severity vulnerability in its N-central remote monitoring and management platform. This vulnerability could enable pre-authenticated remote code execution on an affected server. The issue is fixed in N-central version 2026.3 Hotfix…...
Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe
1+ week, 2+ day ago (461+ words) The activity, documented by PolySwarm, targeted entities in Romania, Spain, and Turkey between late September 2025 and early April 2026. New variants identified during June and July 2026 show that the group continues refining its phishing lures, malware execution chain, and command-and-control (C2) methods....
Hackers Hide Reverse Shell Traffic Behind Signed Apps and AWS API Gateway
1+ week, 5+ day ago (526+ words) Threat actors are using a layered fake IT-support campaign to obtain remote access, deploy a malicious MSI package and conceal hands-on-keyboard activity behind legitimate signed applications and AWS API Gateway infrastructure. Once inside the victim environment, the attacker downloads a…...