Последние посты

Pentesting News
24 сент., 10:03
Apache Tomcat Update: 12 Security Flaws Fixed in Tomcat 11.0.26https://thecyberexpress.com/apache-tomcat-update-cve-2026-87022/The Cyber ExpressApache Tomcat Update Fixes CVE-2026-87022 And 11 MoreApache Tomcat Update 11.0.26 patches 12 flaws, including CVE-2026-87022 WebSocket smuggling and CVE-2026-86350 HTTP/2 header mix-up.
Pentesting News
24 сент., 09:21
RemControl Android Malware Targets 30+ Banking Apps to Steal PINs and Credentialshttps://gbhackers.com/remcontrol-android-malware/GBHackers Security | #1 Globally Trusted Cyber Security News PlatformRemControl Android Malware Targets 30+ Banking Apps to Steal PINs and CredentialsA newly uncovered Android banking trojan dubbed RemControl is targeting customers of more than 30 financial institutions across Europe, the Middle East, and Canada.
Pentesting News
24 сент., 09:21
cPanel Permissions Flaw Allows Local Users to Read Other Accounts’ Calendar Datahttps://gbhackers.com/cpanel-permissions-flaw/GBHackers Security | #1 Globally Trusted Cyber Security News PlatformcPanel Permissions Flaw Allows Local Users to Read Other Accounts’ Calendar DatacPanel has released patches for CVE-2026-68490, a vulnerability related to incorrect permissions in its CalDAV/CardDAV implementation.
Pentesting News
24 сент., 09:21
New Galago Ransomware Operation Emerges With Links to Panzer Extortion Grouphttps://gbhackers.com/galago-ransomware-operation/GBHackers Security | #1 Globally Trusted Cyber Security News PlatformNew Galago Ransomware Operation Emerges With Links to Panzer Extortion GroupA newly identified ransomware operation tracked as Galago has emerged with apparent operational links to the Panzer ransomware group.
Pentesting News
24 сент., 09:21
GitLab Email Token Lets Attackers Push Code to Main and Execute CI/CD Jobshttps://gbhackers.com/gitlab-email-token/GBHackers Security | #1 Globally Trusted Cyber Security News PlatformGitLab Email Token Lets Attackers Push Code to Main and Execute CI/CD JobsA long-lived GitLab incoming email token embedded in project email addresses for the "Email work item" feature can be exploited to push attacker-controlled code, create merge requests, and trigger CI/CD pipelines using the permissions of the token owner.
Pentesting News
24 сент., 08:09
CLOSEDQUORUM, the malware that asks four AI models what to do nexthttps://securityaffairs.com/199640/malware/closedquorum-the-malware-that-asks-four-ai-models-what-to-do-next.htmlSecurity AffairsCLOSEDQUORUM, the malware that asks four AI models what to do nextCisco Talos finds CLOSEDQUORUM, malware that lets four commercial AI models vote on its next move, with no human operator required.
Pentesting News
24 сент., 07:36
Ofcom Investigates Pornhub Parent Aylo Over Age Checkshttps://thecyberexpress.com/ofcom-probes-pornhub-age-checks/The Cyber ExpressOfcom Probes Pornhub Age Checks Under UK Online Safety ActOfcom is investigating Pornhub age checks under UK Online Safety Act, while separately stepping up enforcement against intimate image abuse.
Pentesting News
24 сент., 07:23
CISA outlines improvement plan for CVE programhttps://cyberscoop.com/cisa-cve-data-quality-white-paper-expert-reaction/CyberScoopCISA outlines improvement plan for CVE programCybersecurity experts express skepticism over CISA’s new CVE data quality white paper, citing unaddressed software identifiers and unreleased baseline metrics.
Pentesting News
22 сент., 18:10
Unmasking EvilTokens: Getting to the root of device code phishinghttps://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/Microsoft NewsUnmasking EvilTokens: Getting to the root of device code phishingEvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption…
Pentesting News
22 сент., 17:12
How a hidden Wi-Fi network name can give away your data to strangers | Kaspersky official bloghttps://www.kaspersky.com/blog/hidden-ssid-dangers-wifi-security-explained/56449/Kaspersky official blogHow a hidden Wi-Fi network name can give away your data to strangersWhy hiding your Wi-Fi network name does more harm than good, and what actually does make your home network more secure.
Pentesting News
22 сент., 16:17
Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Dayhttps://securityaffairs.com/199538/hacking/chaotic-eclipse-released-bigdiskbuster-a-poc-for-windows-defender-update-dos-zero-day.htmlSecurity AffairsChaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-DayThe researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability.
Pentesting News
22 сент., 15:23
Critical Linux KVM Flaw Enables Guest-to-Host Escape on ARM64 Systemshttps://gbhackers.com/critical-linux-kvm-flaw/GBHackers Security | #1 Globally Trusted Cyber Security News PlatformCritical Linux KVM Flaw Enables Guest-to-Host Escape on ARM64 SystemsA critical vulnerability in the Linux Kernel-based Virtual Machine (KVM) for ARM64 systems could let attackers escape a virtual machine and gain read and write access to host kernel memory.
Pentesting News
22 сент., 14:33
Another worry for water systems: infostealer exposurehttps://cyberscoop.com/spycloud-study-water-utilities-infostealer-exposure/CyberScoopAnother worry for water systems: infostealer exposureAn exclusive SpyCloud report reveals nearly 1,800 EPA-registered water systems and utilities face active infostealer malware exposure, highlighting widespread supply chain risks.
Pentesting News
22 сент., 13:07
TASK#STOMP PowerShell Backdoor Steals Business Documents and Executes Remote Commandshttps://gbhackers.com/taskstomp-powershell-backdoor/GBHackers Security | #1 Globally Trusted Cyber Security News PlatformTASK#STOMP PowerShell Backdoor Steals Business Documents and Executes Remote CommandsA Windows-focused backdoor dubbed TASK#STOMP that uses VBScript, PowerShell, Scheduled Tasks, and runtime C# compilation to establish resilient persistence.
Pentesting News
22 сент., 13:07
Hackers Exploit Veeam Agent Vulnerability to Gain SYSTEM-Level Access on Windowshttps://gbhackers.com/hackers-exploit-veeam-agent-vulnerability/GBHackers Security | #1 Globally Trusted Cyber Security News PlatformHackers Exploit Veeam Agent Vulnerability to Gain SYSTEM-Level Access on WindowsA newly discovered privilege escalation flaw in Veeam Agent for Microsoft Windows could allow attackers with local access to compromised endpoints to execute commands as NT AUTHORITYSYSTEM.
Pentesting News
22 сент., 13:07
Red Hat OpenShift Flaw Lets Attackers Poison Disconnected Registries With Malicious Releaseshttps://gbhackers.com/red-hat-openshift-flaw/GBHackers Security | #1 Globally Trusted Cyber Security News PlatformRed Hat OpenShift Flaw Lets Attackers Poison Disconnected Registries With Malicious ReleasesRed Hat disclosed an important OpenShift vulnerability that could let attackers bypass release-image signature checks and introduce malicious payloads into disconnected registries.
Pentesting News
22 сент., 13:07
Linux BambooToken Malware Uses MQTT C2 for Remote Shell Access and File Exfiltrationhttps://gbhackers.com/linux-bambootoken-malware/GBHackers Security | #1 Globally Trusted Cyber Security News PlatformLinux BambooToken Malware Uses MQTT C2 for Remote Shell Access and File ExfiltrationA Linux variant of the BambooToken backdoor uses MQTT as its command-and-control channel, enabling operators to profile compromised hosts.
Pentesting News
22 сент., 13:07
Critical MaxKB AI Agent Flaw Lets Prompt Injection Execute System Commandshttps://gbhackers.com/critical-maxkb-ai-agent-flaw/GBHackers Security | #1 Globally Trusted Cyber Security News PlatformCritical MaxKB AI Agent Flaw Lets Prompt Injection Execute System CommandsA critical vulnerability in the MaxKB AI knowledge-base platform could let attackers exploit prompt injection and run operating system commands on vulnerable deployments, including directly on the underlying host in some configurations.
Pentesting News
22 сент., 12:35
Public PoC Exposes Critical Veeam Agent Privilege Escalationhttps://securityaffairs.com/199532/security/public-poc-exposes-critical-veeam-agent-privilege-escalation.htmlSecurity AffairsPublic PoC Exposes Critical Veeam Agent Privilege EscalationA Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation.
Pentesting News
22 сент., 11:03
The Closed Quorum: Inside the first reported autonomous AI C2 implanthttps://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/Cisco TalosThe Closed Quorum: Inside the first reported autonomous AI C2 implantCLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without…
