• Group-IB security researchers have uncovered a sophisticated new Android malware family dubbed “Wonderland” that represents a significant evolution in SMS-stealing threats targeting users across Uzbekistan. Unlike previous regional malware that relied on straightforward one-way data exfiltration, Wonderland implements bidirectional WebSocket-based command-and-control communication, transforming infected devices into remotely controlled agents capable of executing arbitrary commands in […]

    The post Wonderland Android Malware Targets OTPs Through Two-Way SMS Hijacking appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat actors have been observed leveraging malicious dropper apps masquerading as legitimate applications to deliver an Android SMS stealer dubbed Wonderland in mobile attacks targeting users in Uzbekistan. “Previously, users received ‘pure’ Trojan APKs that acted as malware immediately upon installation,” Group-IB said in an analysis published last week. “Now, adversaries increasingly deploy

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat hunters have discerned new activity associated with an Iranian threat actor known as Infy (aka Prince of Persia), nearly five years after the hacking group was observed targeting victims in Sweden, the Netherlands, and Turkey. “The scale of Prince of Persia’s activity is more significant than we originally anticipated,” Tomer Bar, vice president of security research at SafeBreach, said

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Learn how DevOps and DevSecOps strengthen cybersecurity through automation, CI/CD, and secure DevOps development services.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • US authorities have charged Zahid Hasan with running TechTreek, a $2.9 million online marketplace selling fake ID templates. The investigation, involving the FBI and Bangladesh police, uncovered a global scheme selling fraudulent passports and social security cards to over 1,400 customers.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Department of Justice (DoJ) this week announced the indictment of 54 individuals in connection with a multi-million dollar ATM jackpotting scheme. The large-scale conspiracy involved deploying malware named Ploutus to hack into automated teller machines (ATMs) across the U.S. and force them to dispense cash. The indicted members are alleged to be part of Tren de Aragua (TdA, Spanish for

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A 29-year-old Bangladeshi man has been indicted on federal charges for operating online marketplaces that sold fraudulent identity document templates to customers worldwide, U.S. authorities announced. Zahid Hasan of Dhaka, Bangladesh, faces nine federal counts, including six counts of transferring false identification documents, two counts of false passport use, and one count of social security […]

    The post Bangladeshi Operator of Fake ID Marketplaces Charged in International Fraud Case appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Shadowserver Foundation has identified over 25,000 internet-facing Fortinet devices globally with FortiCloud Single Sign-On (SSO) functionality enabled, raising concerns about potential exposure to critical authentication bypass vulnerabilities. The non-profit security organization recently added fingerprinting capabilities for these systems to its Device Identification reporting service, alerting network administrators to verify their security posture immediately. Mass […]

    The post 25,000+ FortiCloud SSO-Enabled Systems Vulnerable to Remote Exploitation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft Teams users worldwide experienced significant service disruptions on December 20, 2025, as the collaboration platform encountered widespread issues affecting messaging functionality and other critical service operations. The company has acknowledged the incident and is actively investigating the root cause. According to Microsoft 365 Status updates, users reported experiencing delays in message delivery and problems […]

    The post Microsoft Teams Outage Causes Global Messaging Delays and Service Interruptions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • More firms have been tapped to compete for the historic 151-billion Golden Dome contract vehicle, with the number of awards to develop related technology more than doubling as of Thursday evening. 

    The Missile Defense Agency made an additional 1,086 awards out of 2,463 offers received for the multiple-award indefinite-delivery/quantity contract dubbed Scalable Homeland Innovative Enterprise Layered Defense, or SHIELD. The latest round of awards follows the initial announcement that the Pentagon had identified 1,014 companies for MDA’s Golden Dome missile defense efforts. Experts said the first award was one of the largest potential contracts of all time, and between the two announcements, 2,100 awardees have been identified. The list of the latest defense firms in the competition is available here.

    “This contract encompasses a broad range of work areas that allows for the rapid delivery of innovative capabilities to the warfighter with increased speed and agility, leveraging artificial intelligence and machine learning enabled applications where pertinent, and maximizing use of digital engineering, open systems architectures, model-based systems engineering, and agile processes in the acquisition, development, and sustainment of these capabilities,” the Pentagon said in its Thursday announcement.

    The latest list of awardees includes prime contractors such as Lockheed Martin, Northrop Grumman, and RTX’s Raytheon.

    Thursday’s announcement came the same day as a new executive order from President Donald Trump, which stated that establishing new technology for a missile defense shield across the country was key to “securing and defending American vital national and economic security interests” in space. 

    Trump’s executive order, titled “Ensuring American Space Superiority,” mostly focused on space exploration but also points to his Jan. 27 presidential action establishing the Golden Dome initiative and sets a goal of developing and demonstrating next-generation missile defense technologies by 2028. 

    The Pentagon has acknowledged that work for the SHIELD contract vehicle will likely take a decade. Companies will not be paid based on this month’s awards, but rather once orders for the Golden Dome-related technology are placed.

    “If all options are exercised, work will continue through December 2035,” the announcement said. “No funds will be obligated on the base IDIQ award; funds will be obligated at the order level.”

    Most of the architecture for the ambitious and sprawling Golden Dome initiative—which has been pitched by the president as a one-stop defense against ICBMs, hypersonic missiles, drones, and other advanced aerial threats—has been kept secret. One key component of the architecture that’s been acknowledged is space-based interceptors, which would destroy an incoming missile during various flight stages. 

    Last month, the Space Force awarded multiple contracts to several companies under a competitive but secret “other transaction agreement,” which kept the winners' identities out of public view. The service is also seeking prototype proposals for a space-based “kinetic midcourse interceptor,” which would destroy a missile mid-flight by direct collision, versus an explosive warhead.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶