Skip to content

1010.cx

  • Apache NiFi Flaw Enable Security Bypass and Memory Corruption

    ·

    CVE/vulnerability, cyber security, Cyber Security News, Vulnerabilities, vulnerability

    Apache NiFi has issued security advisories for four vulnerabilities affecting its web API. These include an authorization bypass that could allow unauthorized deletion of Parameter Context assets, and a high-severity issue that results in excessive memory consumption through specially crafted gzip-compressed HTTP requests. The vulnerabilities impact Apache NiFi versions from 1.5.0 through 2.10.0, depending on […]

    The post Apache NiFi Flaw Enable Security Bypass and Memory Corruption appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • OctLurk-Linked Hackers Deploy BINDCLOAK Backdoor Against Middle East Governments

    ·

    cyber security, Cyber Security News

    The published Part 2 of a two-part technical analysis exposing BINDCLOAK, a previously undocumented modular backdoor deployed against government entities in the Middle East by an East Asia-linked threat actor tracked as OctLurk. The disclosure follows Part 1, which detailed the TELESHIM backdoor and the MIXEDKEY loader used earlier in the same multi-stage intrusion chain. […]

    The post OctLurk-Linked Hackers Deploy BINDCLOAK Backdoor Against Middle East Governments appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Critical Check Point Flaw Lets Unauthenticated Attackers Execute Commands on Management Servers

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    Check Point has disclosed a high-severity authentication bypass vulnerability that could allow unauthenticated attackers to execute arbitrary commands on vulnerable Security Management Servers and Multi-Domain Security Management Servers (MDS). This vulnerability is tracked as CVE-2026-18574 and is detailed in Check Point Security Alert sk185222. It affects multiple legacy and current versions of their management platform. […]

    The post Critical Check Point Flaw Lets Unauthenticated Attackers Execute Commands on Management Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

    ·

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • cPanel Database Privilege Escalation Flaw Enables Full Administrative Access

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    CVE-2026-58048 is a critical privilege-escalation vulnerability in the database management functionality of cPanel & WHM. This flaw allows an authenticated cPanel user to execute arbitrary database commands with full administrative privileges. cPanel Database Privilege Escalation Flaw All supported versions of cPanel & WHM before the recently released security updates are affected. As WebPros states, an […]

    The post cPanel Database Privilege Escalation Flaw Enables Full Administrative Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • ChocoShell Steals Microsoft 365 Tokens and Browser Sessions From Travelers

    ·

    cyber security, Cyber Security News, Microsoft

    ChocoShell is a PowerShell-based infostealer used in Microsoft’s newly disclosed “CaptiveCrunch” campaign to steal Microsoft 365 tokens, browser sessions, and Wi‑Fi credentials from travelers connecting to compromised hospitality networks worldwide. The operation, dubbed “CaptiveCrunch,” poisons DNS and HTTP flows on guest networks so that travelers attempting to reach legitimate Microsoft 365 or update endpoints are […]

    The post ChocoShell Steals Microsoft 365 Tokens and Browser Sessions From Travelers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • NullReceiver Is Harder to Discover but Still Exposes a Reusable Attacker Wallet

    ·

    cyber security, Cyber Security News

    NullReceiver is a lean, stealth-focused evolution of DPRK’s blockchain C2 tradecraft that hides a reusable attacker wallet behind ordinary-looking Ethereum transfers, while still exposing just enough bytes to resolve a live command server. Two trojanized npm packages, bianira-ui@1.27.0 and fluid-type-ui@2.0.8, both Tailwind CSS plugin lookalikes, implement a new blockchain-based C2 resolution technique we’re calling NullReceiver. […]

    The post NullReceiver Is Harder to Discover but Still Exposes a Reusable Attacker Wallet appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Apple Removes Telegram From App Store Worldwide

    ·

    Apple, cyber security, Cyber Security News, Telegram

    Telegram Messenger was temporarily removed from Apple’s App Store in several countries late Monday, preventing new users from downloading the messaging platform and blocking reinstalls for users who had previously deleted the app.   This global delisting caused widespread confusion on the social media platform X, where users shared screenshots of App Store messages that read, […]

    The post Apple Removes Telegram From App Store Worldwide appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Thermo Fisher DNA Analysis Software Flaw Lets Attackers Secretly Alter Test Data

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    Thermo Fisher Scientific has released security updates for a high-severity flaw in its Applied Biosystems Human Identification (HID) software. This vulnerability could allow nearly undetectable manipulation of DNA test data files before analysis. The issue, tracked as CVE-2026-17583, carries a CVSS v4 score of 8.2 and affects .fsa and .hid file outputs used in forensic […]

    The post Thermo Fisher DNA Analysis Software Flaw Lets Attackers Secretly Alter Test Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Malware Can Steal Google’s Synced Passkeys Without Password or Fingerprint

    ·

    cyber security, Cyber Security News, Google

    Security researchers have revealed a series of attacks that could enable malware on a compromised Windows device to hijack accounts protected by Google-synced passkeys. This can occur without stealing a password, capturing a fingerprint, or requiring the victim to unlock their device. In research published on August 23, 2023, Palo Alto Networks’ Unit 42 detailed […]

    The post Malware Can Steal Google’s Synced Passkeys Without Password or Fingerprint appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 2 3 4 5 6 … 1,007
Next Page

1010.cx

cybersecurity / defense / intelligence