Skip to content

1010.cx

  • Cybercriminals Exploit Chinese Guarantee Markets to Sell Stolen Credentials

    ·

    cyber security, Cyber Security News

    Chinese-language “guarantee” marketplaces hosted mainly on Telegram have become a core conduit for buying, selling, and laundering stolen credentials and a wide range of criminal services. These platforms modeled explicitly on consumer escrow systems such as Alipay’s 担保交易 (dānbǎo jiāoyì) operate as third-party guarantors: the marketplace operator holds buyer funds in escrow, releases them only […]

    The post Cybercriminals Exploit Chinese Guarantee Markets to Sell Stolen Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers Abuse VMware-Signed Binary to Deploy NIGHTFORGE Loader

    ·

    cyber security, Cyber Security News

    Two closely related espionage campaigns targeting Cambodian government organizations that abuse a legitimate VMware-signed binary to sideload a custom loader dubbed NIGHTFORGE, which in turn deploys a Havoc Demon implant in memory. TRU attributes both operations to a previously unreported cluster it calls Khmer Shadow, based on targeting, lure construction and shared infrastructure; the activity […]

    The post Hackers Abuse VMware-Signed Binary to Deploy NIGHTFORGE Loader appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers Exploit AWS CloudTrail and Google Cloud Logging to Hide Attacks and Steal Logs

    ·

    AWS, cyber security, Cyber Security News

    Threat actors increasingly abuse Amazon Web Services (AWS) CloudTrail and Google Cloud Logging to evade detection, poison or exfiltrate logs, and in some cases maintain long-term visibility into victim environments. The techniques are simple in concept, powerful in effect, and evade many orgs that assume logs themselves are sacrosanct. At the core of these attacks […]

    The post Hackers Exploit AWS CloudTrail and Google Cloud Logging to Hide Attacks and Steal Logs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks

    ·

    GitHub has announced what it said are “breaking changes” coming to npm version 12, one of which turns off install scripts by default to combat software supply chain threats. The changes aim to combat attack techniques that abuse the “npm install” command to trigger the execution of malicious code using npm lifecycle hooks. “Npm install” is used to download and install all the necessary

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GitLab Patches Multiple Vulnerabilities Allowing Account Takeover

    ·

    CVE/vulnerability, cyber security, Cyber Security News, GitLab, vulnerability

    GitLab has released security updates for GitLab CE/EE and EE that patch multiple vulnerabilities, including several high‑impact flaws that could lead to account takeover, data exposure, and denial of service if left unpatched. Administrators are strongly advised to upgrade to GitLab 19.0.2, 18.11.5, or 18.10.8, as applicable, to fully mitigate these issues. GitLab Patches Multiple […]

    The post GitLab Patches Multiple Vulnerabilities Allowing Account Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • China-Linked JDY Botnet Hijacks 1,500+ IoT Devices for Rapid Exploits

    ·

    Botnet, cyber security, Cyber Security News, IoT

    A significant resurgence of the JDY botnet, a covert reconnaissance network tied to China-nexus threat activity. Once a component of the larger KV-botnet ecosystem, JDY has expanded to more than 1,500 compromised small office/home office (SOHO) and Internet of Things (IoT) devices and now functions as a high-performance, centrally controlled scanner that accelerates vulnerability discovery […]

    The post China-Linked JDY Botnet Hijacks 1,500+ IoT Devices for Rapid Exploits appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • PoC Exploit Released for Linux Kernel Guest-to-Host Escape Vulnerability

    ·

    CVE/vulnerability, cyber security, Cyber Security News, Linux, PoC, vulnerability

    A proof-of-concept (PoC) exploit has been publicly released for a critical Linux kernel vulnerability, tracked as CVE-2026-46316, enabling guest-to-host escape in KVM/arm64 environments. The flaw, dubbed “ITScape” by security researcher Hyunwoo Kim (V4bel), affects the Kernel-based Virtual Machine (KVM) subsystem and allows a malicious guest virtual machine to execute arbitrary commands on the host with […]

    The post PoC Exploit Released for Linux Kernel Guest-to-Host Escape Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Ivanti Command Injection Flaw Exploited After PoC Code Release

    ·

    CVE/vulnerability, cyber security, Cyber Security News, PoC, vulnerability

    Ivanti Sentry is facing active exploitation attempts following the public release of proof-of-concept (PoC) code targeting a critical OS command injection vulnerability tracked as CVE-2026-10520. The flaw, along with a second critical issue (CVE-2026-10523), was disclosed by Ivanti on June 9, 2026, with both affecting multiple versions of the Sentry mobile device management gateway. Although […]

    The post Ivanti Command Injection Flaw Exploited After PoC Code Release appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Anthropic’s Claude Fable 5 AI Model Jailbroken for Stack Exploit Creation

    ·

    AI, cyber security, Cyber Security News

    Anthropic’s latest AI release, Claude Fable 5, is facing scrutiny after claims emerged that researchers have successfully jailbroken the model to generate sensitive and potentially harmful outputs, including guidance relevant to exploit development and illicit activities. The development raises fresh concerns over the effectiveness of safety guardrails in advanced large language models (LLMs), particularly those […]

    The post Anthropic’s Claude Fable 5 AI Model Jailbroken for Stack Exploit Creation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Mystery GPS outages traced to Russian satellite

    ·

    Threats
    Occasional bursts of energy from a Russian missile-detection satellite have been briefly disrupting satellite navigation across large parts of Europe, a pattern that may indicate a “qualitative escalation in GNSS [global navigation satellite system] interference.” 

    At least 75 times between 2019 and 2026, University of Texas researchers observed 10-second bursts of high-powered radio signals at 1558.5 MHz: the frequency used by GPS and European navigation satellites to transmit signals to Earth. The bursts disrupted GPS antennas from Romania to Greenland, the researchers write in a paper published this month in the journal Navigation.

    The origin of the pulses was a mystery. The vast size of the affected area ruled out ground- and even aircraft-based jammers, so the interference was coming from space. 

    Solar flares can disrupt satellite-location services, but unevenly. The disruptions were far more uniform. 

    “Clearly, the effects of solar radio bursts manifest differently in the IGS data compared to the transient phenomenon studied here,” they write.

    The researchers created a mathematical formula for pinpointing the origin based on how intensely the radio signals hit different antennas across the affected area. The equation pointed to just one likely source: Russia’s Cosmos 2546 satellite. It was launched in May 2020, months after the first disruptions were detected, but it is part of the Edinaya Kosmicheskaya Sistema, a constellation of early missile warning satellites. They fly in the Molniya orbit, whose highly elliptical path keeps them over the high north for most of the time.

    The researchers conclude that the radio bursts appear to be intentional, but too short to have any real effect. They offer no specific theory about Russia’s intentions.

    But officials have become increasingly concerned about Russian space activity, including the possible orbiting of a nuclear weapon that could break GPS.

    “It is unclear exactly what is happening, but it does appear to be a space-based jammer,” said Victoria Samson, the chief director of space security and stability at the Secure World Foundation. “I would guess that the reason why Russia is using its early-warning constellation for this is that it is at the right position and altitude to cover the area that Russia would want to interfere with GPS. It is possible that Russia was willing to risk using its early-warning constellation for this because it was fairly confident that the interference would not be detected; as it was, this has been going on since 2019 and was only discovered in the past several years."

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 … 24 25 26 27 28 … 880
Next Page

1010.cx

cybersecurity / defense / intelligence