Skip to content

1010.cx

  • Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages

    ·

    Cyber Attack, Cyber-Attacks, cybersecurity, Malware, npm, Security, Shai-hulud, Supply Chain, Worm
    Shai-Hulud npm worm spreads through Keyv and hundreds of packages with 2 billion monthly downloads, stealing npm, GitHub, cloud and CI credentials in real time.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

    ·

    The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. “Greatness supports AiTM [adversary-in-the-middle] credential and

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Airlock Digital Unveils Agentic AI Control & Governance to Extend Preventative Endpoint Security

    ·

    Press Release

    Atlanta, GA, August 4th, 2026, CyberNewswire Airlock Digital announces Agentic AI Control & Governance, extending its preventative endpoint security solution with visibility into trusted AI agent behavior and governance over what trusted agents are allowed to do on endpoints.  Airlock Digital, a leader in preventative endpoint security, today announced Agentic AI Control & Governance at […]

    The post Airlock Digital Unveils Agentic AI Control & Governance to Extend Preventative Endpoint Security appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Mallory Unifies Threat Intelligence, Exposure Context, and Response Into One Architecture for Security Teams

    ·

    Press Release

    Las Vegas, United States, August 4th, 2026, CyberNewswire As AI-assisted attackers compress exploitation timelines to hours, Mallory turns live adversary intelligence into prioritized, policy-governed action across the tools security teams already run Mallory, the AI-native Threat and Exposure Management platform, today introduced a unified context and intelligence layer for security teams. The architecture has three […]

    The post Mallory Unifies Threat Intelligence, Exposure Context, and Response Into One Architecture for Security Teams appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Airlock Digital Unveils Agentic AI Control & Governance to Extend Preventative Endpoint Security

    ·

    Malware, Press Release, Product Launch
    Atlanta, GA, 4th August 2026, CyberNewswire

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Mallory Unifies Threat Intelligence, Exposure Context, and Response Into One Architecture for Security Teams

    ·

    Press Release, Product Launch
    Las Vegas, United States, 4th August 2026, CyberNewswire

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Six Flowise Vulnerabilities Enable Remote Code Execution on AI Workflow Servers

    ·

    AI, cyber security, Cyber Security News, Vulnerabilities

    Six newly disclosed vulnerabilities in Flowise, a popular open‑source platform for building AI agents and LLM workflows, allow unauthenticated and low‑privileged attackers to achieve remote code execution (RCE) on self‑hosted and cloud AI workflow servers running vulnerable versions. These flaws collectively expose organizations to full server compromise, data exfiltration, and AI pipeline manipulation if instances […]

    The post Six Flowise Vulnerabilities Enable Remote Code Execution on AI Workflow Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • DarkSword Server Combines iPhone Exploits With Fake Apple ID Login Page

    ·

    cyber security, Cyber Security News, iphone

    DarkSword’s leaked iOS exploit chain is now powering a fast‑moving server cluster that marries one‑click Safari exploitation with a convincing fake Apple ID login page, putting millions of iPhone users at risk of seamless device compromise and credential theft. Originally disclosed by Google Threat Intelligence Group, iVerify, and Lookout, the kit was later leaked to […]

    The post DarkSword Server Combines iPhone Exploits With Fake Apple ID Login Page appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

    ·

    A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later reported at least 868 packages

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Fake Xeno Roblox Cheats Deliver Java RAT That Steals Discord and Gaming Accounts

    ·

    cyber security, Cyber Security News

    Fake Roblox cheat tools are once again being weaponized, with a newly observed campaign distributing a sophisticated Java-based remote access trojan (RAT) disguised as an “undetected” version of the popular Xeno script executor. Security researchers warn that the operation specifically targets gamers through Discord communities and underground forums, leveraging trust in widely used cheat utilities […]

    The post Fake Xeno Roblox Cheats Deliver Java RAT That Steals Discord and Gaming Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

1 2 3 … 1,007
Next Page

1010.cx

cybersecurity / defense / intelligence