Skip to content

1010.cx

  • Copybara Abuses Android Accessibility for Keylogging, Screen Streaming and Remote Control

    ·

    Android, cyber security, Cyber Security News

    Copybara is being weaponized in a new N26-themed fraud campaign in Italy that chains vishing, a real‑time phishing control kit, and a multi‑stage Android dropper to gain full remote control of victims’ phones via abused Accessibility services. The operator leverages real notifications already present in the legitimate N26 app to build trust, then pushes the […]

    The post Copybara Abuses Android Accessibility for Keylogging, Screen Streaming and Remote Control appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google Chrome 151 Fixes 370 Security Flaws, Including 7 Critical Bugs

    ·

    Chrome, CVE/vulnerability, cyber security, Cyber Security News, Google, Vulnerabilities, vulnerability

    Google has released stable Chrome version 151 updates for Windows, macOS, and Linux, addressing 370 security vulnerabilities. This update includes fixes for seven critical-severity flaws that affect core components of the browser. The new versions are Chrome 151.0.7922.71/.72 for Windows and macOS, and 151.0.7922.71 for Linux. The critical vulnerabilities impact several areas, including Chrome’s compositing […]

    The post Google Chrome 151 Fixes 370 Security Flaws, Including 7 Critical Bugs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • North Korean Hackers Compromise Popular npm Packages to Target Developer Environments

    ·

    cyber security, Cyber Security News

    North Korea–linked operators have quietly turned popular npm packages into a high‑volume access vector for developer and build environments, chaining multiple compromises of axios, debug, chalk, and typo‑crypto into a coordinated software supply‑chain campaign. Amazon’s latest research links four previously separate npm packages incidents into a single long‑horizon operation against the open-source ecosystem. In March […]

    The post North Korean Hackers Compromise Popular npm Packages to Target Developer Environments appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GitLab Patches 13 Security Flaws Enabling Data Exposure, CI/CD Tampering and DoS Attacks

    ·

    CVE/vulnerability, cyber security, Cyber Security News, Vulnerabilities, vulnerability

    GitLab has released security updates for both the Community Edition (CE) and Enterprise Edition (EE), addressing 13 vulnerabilities that could allow unauthorized data exposure, tampering with CI/CD pipelines, bypassing protected branches, and denial-of-service (DoS) attacks. The updates, which were released on July 29, 2026, are available in GitLab versions 19.2.1, 19.1.3, and 19.0.5. GitLab strongly […]

    The post GitLab Patches 13 Security Flaws Enabling Data Exposure, CI/CD Tampering and DoS Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

    ·

    Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a lookalike npm domain and a wallet-draining script pushed into at least 18 packages carrying more than 2 billion weekly downloads between them. The original Aikido and Wiz reports did not attribute the

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Node.js Patches 11 Security Flaws Enabling Memory Exhaustion, File Access and Request Smuggling

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    The Node.js Project has released security updates for the active Node.js versions 22.x, 24.x, and 26.x, addressing 11 vulnerabilities. These vulnerabilities range from high-severity issues, such as HTTP/2 memory corruption and permission-bypass flaws, to lower-severity problems, such as HTTP request smuggling. The security updates are available as Node.js v22.23.2, v24.18.1, and v26.5.1. In addition to […]

    The post Node.js Patches 11 Security Flaws Enabling Memory Exhaustion, File Access and Request Smuggling appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • TA488 Exploits Outlook Half-Click Flaw to Deploy Persistent OWAReaper Backdoor

    ·

    cyber security, Cyber Security News, Outlook

    TA488 has resurfaced with a high‑end half‑click campaign against on‑premises Outlook Web Access (OWA), exploiting CVE‑2026‑42897 to deploy a persistent JavaScript backdoor, OWAReaper, that can survive credential rotation, browser restarts, and full host re‑imaging. The operation exploits CVE‑2026‑42897, a cross‑site scripting flaw in OWA disclosed by Microsoft in May 2026 and confirmed to be actively […]

    The post TA488 Exploits Outlook Half-Click Flaw to Deploy Persistent OWAReaper Backdoor appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

    ·

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Claude Global Outage Hits Users With “529 Overloaded” Error Messages

    ·

    AI, cyber security, Cyber Security News

    Users of Claude experienced service disruptions on Wednesday when Anthropic reported elevated error rates across all Claude models. This incident affected the Claude.ai chatbot, the Claude API at api.anthropic.com, Claude Code, and Claude Cowork, preventing users from submitting prompts or completing API-driven tasks. During the outage, users encountered “529 Overloaded” error messages. The HTTP status […]

    The post Claude Global Outage Hits Users With “529 Overloaded” Error Messages appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft Word Copilot Flaw Lets Hidden Prompts Spread Self-Propagating AI Worms Across Documents

    ·

    CVE/vulnerability, cyber security, Cyber Security News, Microsoft, vulnerability

    Security researcher Håkon Måløy has disclosed a cross-domain prompt injection vulnerability affecting Microsoft Copilot for Word. This vulnerability could allow malicious instructions hidden within documents to alter Copilot-generated content and spread into newly created files. The issue, termed “Context Collapse, Part 3 – AI Worming through Word,” demonstrates how a document can serve as a […]

    The post Microsoft Word Copilot Flaw Lets Hidden Prompts Spread Self-Propagating AI Worms Across Documents appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 … 13 14 15 16 17 … 1,007
Next Page

1010.cx

cybersecurity / defense / intelligence