Skip to content

1010.cx

  • UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign

    ·

    Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of organizations across professional, legal, and financial services in the U.S. between January and May 2026. The activity has been attributed by Google Mandiant and Google Threat Intelligence Group (GTIG) to a threat actor dubbed UNC3753, which is also known as

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Critical UniFi OS RCE Chain Grants Root Access Without Credentials

    ·

    cyber security, Cyber Security News

    Security Advisory Bulletin 064 describing a critical chain of vulnerabilities in UniFi OS Server that allows unauthenticated remote code execution and full root takeover. The issue combines an authentication-gateway bypass, a path-traversal mismatch, and a command-injection sink in the package-update service. When chained, these flaws let an attacker send a single crafted HTTP request to […]

    The post Critical UniFi OS RCE Chain Grants Root Access Without Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks

    ·

    Microsoft has announced that Visual Studio Code (VS Code) will apply a two-hour delay before extensions for the integrated development environment (IDE) are updated automatically to a newer version in an attempt to tackle software supply chain threats. “When automatic updates are enabled, new versions are auto-updated two hours after they are published, adding an extra layer of protection

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • EDRChoker Tool Abuses Windows QoS Policies to Disrupt Endpoint Security Tools

    ·

    cyber security, Cyber Security News, Tools

    A newly disclosed red-team tool dubbed “EDRChoker” is drawing attention across the cybersecurity community for its novel approach to disrupting Endpoint Detection and Response (EDR) visibility by abusing Windows Policy-based Quality of Service (quality of service). Unlike traditional EDR evasion techniques that rely on firewall manipulation or Windows Filtering Platform (WFP) rule injection, EDRChoker operates […]

    The post EDRChoker Tool Abuses Windows QoS Policies to Disrupt Endpoint Security Tools appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft Warns Claude Code GitHub Action May Expose CI/CD Secrets

    ·

    cyber security, Cyber Security News, GitHub, Microsoft

    Anthropic’s Claude Code GitHub Action could unintentionally expose CI/CD workflow secrets when AI agents process untrusted GitHub content. The risk arises because certain tools the agent uses to read files were not sandboxed like subprocess execution paths such as Bash. In particular, the Read tool was able to access /proc/self/environ and returned environment variables, including […]

    The post Microsoft Warns Claude Code GitHub Action May Expose CI/CD Secrets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers Exploit Claude Code MCP Traffic to Hijack OAuth Authentication Tokens

    ·

    cyber security, Cyber Security News

    Threat researchers have uncovered a novel man-in-the-middle (MitM) attack chain targeting Anthropic’s Claude Code ecosystem, where adversaries hijack Model Context Protocol (MCP) traffic to steal OAuth authentication tokens and persist access to enterprise SaaS platforms. The technique, detailed by Mitiga, abuses weak protections around the local Claude Code configuration file (~/.claude.json), effectively turning it into […]

    The post Hackers Exploit Claude Code MCP Traffic to Hijack OAuth Authentication Tokens appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Free Samsung and LG Smart TV Apps Reportedly Exploit Devices for AI Proxy Traffic

    ·

    cyber security, Cyber Security News

    Free apps available on Samsung, LG, Roku, and other connected TV (CTV) platforms are quietly enrolling users’ smart televisions into a commercial residential proxy network operated by Bright Data, according to a technical investigation published June 5, 2026, by Include Security researcher Buchodi. The embedded SDK, embedded inside partner apps under the guise of a […]

    The post Free Samsung and LG Smart TV Apps Reportedly Exploit Devices for AI Proxy Traffic appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers Exploit 2026 FIFA World Cup With Phishing and Ticket Scams

    ·

    cyber security, Cyber Security News, Phishing

    Cybercriminals are already turning the 2026 FIFA World Cup into a fraud opportunity, using phishing pages, fake online stores, and ticket scams to steal money and personal data. The risk is rising because the tournament will attract huge global demand, fast purchases, and buyers who may act quickly before checking whether a site is real. […]

    The post Hackers Exploit 2026 FIFA World Cup With Phishing and Ticket Scams appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • New ChatGPT Lockdown Mode Aims to Block Prompt Injection and Data Exfiltration Attacks

    ·

    ChatGPT, cyber security, Cyber Security News, OpenAI, vulnerability

    OpenAI this week introduced Lockdown Mode, a security-focused setting for ChatGPT designed to reduce the risk of data exfiltration from prompt-injection attacks. The feature is rolling out to eligible personal accounts (Free, Go, Plus, Pro) and self-serve ChatGPT Business workspaces, and managed-workspace administrators can assign a Lockdown Mode role to members. Prompt injection is a […]

    The post New ChatGPT Lockdown Mode Aims to Block Prompt Injection and Data Exfiltration Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • House lawmakers want the Navy to deploy drone boats faster

    ·

    Policy
    The Navy would have to detail its plans to buy and use seagoing drones under a suite of provisions in the House Armed Services Committee’s draft 2027 defense policy bill. 

    The bill, which passed out of committee late Thursday, would require service leaders to devise a plan to buy, sustain, and operate small unmanned surface vessels—ones weighing less than 50 metric tons and no more than 50 feet long. 

    The plan would have to include a detailed inventory of each acquired USV, the types of missions the Navy would use USVs for, how they would work with crewed vessels, and how they would be integrated with current command and control, intelligence, surveillance, and reconnaissance, and logistics infrastructure.

    The bill would also require the Navy to develop plan to “accelerate procurement and integration of commercially available sUSVs.”

    The committee wrote in direct reporting language that buying more commercially available “technologies and platforms could enhance fleet readiness, reduce developmental timelines, and lower overall costs compared to government designs” especially amid “the increased demand from multiple geographic Combatant Commands for additional sUSVs to meet a variety of urgent mission needs.” 

    The provisions would also require the Navy to submit a report to identify obstacles to buying commercially available small USVs . 

    The proposals come just weeks after the Navy released its latest 30-year shipbuilding plan, which outlined its intentions to include hundreds of unmanned surface vessels in its hull count. They also come as the Pentagon prepares to spend more on unmanned vessels. 

    A separate requirement targets operational autonomy, tasking the Navy with certifying that procured drone boats can function “during periods in which communications capabilities are denied, degraded, intermittent, or limited; and (2) during periods in which positioning, navigation, and timing capabilities are degraded or unavailable,” according to the bill. 

    “The Secretary of the Navy would also be required to develop and implement a strategy for the integration of unmanned surface vessels naval force design and joint maritime operations. The Secretary of the Navy would be required to submit a report to the congressional defense committees not later than 210 days after the date of the enactment of this Act on the strategy for unmanned surface vessel integration and provide an annual brief on integration efforts thereafter.”

    Like the Navy’s shipbuilding plan, the HASC’s draft of the 2027 National Defense Authorization Act notes undersea drones’ usefulness in maritime operations and pushes the Navy to adopt and integrate the extra-large unmanned underwater drones that have already been tested. 

    “The Committee further encourages the Secretary of the Navy to accelerate adoption of the XLUUV platforms selected through the Combat Autonomous Maritime Platform program’s 2025 competitive process to transition these systems from experimentation to operational deployment and to equip priority commands with the capabilities required to meet Fleet demands,” lawmakers wrote. “Therefore, the committee directs the Secretary of the Navy to provide a briefing to the House Committee on Armed Services not later than March 1, 2027, outlining plans to accelerate the adoption and fielding of XLUUVs and associated payloads utilizing existing production contracts,” including fielding timelines. 

    The bill also includes a requirement for the head of Special Operations Command to brief Congress by Dec. 1 on the need for a “hybrid-electric amphibious seaplane” which could “provide a viable solution by enabling fixed-wing aircraft to operate from waterways, runways, and unimproved surfaces with increased combat radius, reduced fuel consumption, and lower acoustic and thermal signatures.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 … 35 36 37 38 39 … 880
Next Page

1010.cx

cybersecurity / defense / intelligence