Skip to content

ADMIN.FOUNDATION

  • CISA Warns Hackers Are Actively Exploiting VMware vCenter Path Traversal Flaw

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Broadcom VMware vCenter to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability, tracked as CVE-2026-59310, is a path traversal flaw that enables arbitrary code execution in affected vCenter deployments. VMware vCenter Path Traversal Flaw CVE-2026-59310 impacts the VMware vCenter Syslog Server […]

    The post CISA Warns Hackers Are Actively Exploiting VMware vCenter Path Traversal Flaw appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Fake Claude Install Guide Steals Mac Passwords and Turns Trusted Crypto Wallet Apps Into Phishing Traps

    ·

    cyber security, Cyber Security News, macOS

    A Google-sponsored search result for Claude installation instructions is being used to deliver a sophisticated macOS stealer and remote-access trojan (RAT) named MacSync. The campaign abuses a legitimate Claude shared-conversation page on the claude.ai domain, demonstrating how trusted AI-hosting infrastructure can be weaponized to bypass users’ normal phishing instincts. The intrusion investigated by Huntress began […]

    The post Fake Claude Install Guide Steals Mac Passwords and Turns Trusted Crypto Wallet Apps Into Phishing Traps appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix

    ·

    cyber security, Cyber Security News, Malware, Wordpress

    A large-scale malware operation called StopAndProtect is exploiting thousands of compromised WordPress websites to distribute ransomware, steal files, harvest credentials, and remotely monitor victims through deceptive ClickFix CAPTCHA prompts. Researchers first identified the campaign in mid-May 2026. They discovered that the operation utilizes a broad range of criminal tools rather than relying on a single […]

    The post Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cl0p Hackers Exploit PTC Windchill Vulnerability to Deploy Custom Web Shell and Steal Data

    ·

    cyber security, Cyber Security News, vulnerability

    The Cl0p ransomware and extortion operation is likely exploiting a critical PTC Windchill vulnerability to deploy a purpose-built Java web shell that can harvest credentials, map engineering data vaults, and exfiltrate files without requiring additional attacker tooling. Tracked as CVE-2026-12569, the vulnerability is a CVSS 9.3 remote code execution issue affecting PTC Windchill PDMlink and […]

    The post Cl0p Hackers Exploit PTC Windchill Vulnerability to Deploy Custom Web Shell and Steal Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Medusa Ransomware Attacks 300+ Critical Infrastructure Organizations Using Double Extortion

    ·

    cyber security, Cyber Security News, Ransomware

    Medusa ransomware operators have compromised over 500 organizations across critical infrastructure sectors, according to a joint advisory issued by the FBI, CISA, and the U.S. Department of Health and Human Services (HHS) as part of their #StopRansomware initiative. An update released on August 18, 2026, provides expanded intelligence based on FBI investigations conducted as recently […]

    The post Medusa Ransomware Attacks 300+ Critical Infrastructure Organizations Using Double Extortion appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Critical Microsoft Copilot CoSnitch Flaw Lets Hackers Steal Sensitive Data With One Click

    ·

    CVE/vulnerability, cyber security, Cyber Security News, Vulnerabilities, vulnerability

    A critical one-click vulnerability in Microsoft Copilot Personal, tracked as CVE-2026-24301 and dubbed CoSnitch. This flaw could enable an attacker to trigger malicious Copilot prompts, access data from connected OAuth applications, and silently transmit that information to an attacker-controlled server. Microsoft addressed this issue on August 18, 2026, following Varonis’s responsible disclosure in December 2025. […]

    The post Critical Microsoft Copilot CoSnitch Flaw Lets Hackers Steal Sensitive Data With One Click appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

    ·

    Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim’s Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

    ·

    Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim’s Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

    ·

    Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts. According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows –

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

    ·

    Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts. According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows –

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

1 2 3 … 1,042
Next Page

ADMIN.FOUNDATION

cybersecurity / defense / intelligence