Skip to content

ADMIN.FOUNDATION

  • 24 Malware Crypter Sellers Turn EDR Evasion and In-Memory Execution Into Paid Services

    ·

    cyber security, Cyber Security News, Malware

    A growing underground market is turning mature malware-evasion techniques into subscription products. An analysis of 24 active crypting-service vendors shows that customers can now buy payload obfuscation, in-memory execution, anti-analysis controls, process injection, persistence, and rapid “re-crypting” as packaged services rather than develop them internally. Crypting traditionally refers to encrypting or obfuscating a customer-supplied malicious […]

    The post 24 Malware Crypter Sellers Turn EDR Evasion and In-Memory Execution Into Paid Services appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • New Bring Your Own EDR Attack Turns SentinelOne Into Trojan Horse to Bypass Windows PPL

    ·

    cyber security, Cyber Security News, vulnerability, Windows

    Security researchers have introduced a new technique called “Bring Your Own EDR” (BYOEDR) that exploits legitimate SentinelOne components to bypass Windows Protected Process Light (PPL) protections, allowing the execution of unsigned code within highly secured processes. This research, presented by Akamai at DEF CON 34, demonstrates how trusted endpoint detection and response (EDR) software can […]

    The post New Bring Your Own EDR Attack Turns SentinelOne Into Trojan Horse to Bypass Windows PPL appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud

    ·

    The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. “Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim’s browser into a full remote-control

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • New DRAM Scrambling Attack Unlocks AMD CPU PSP, SMM and Microcode

    ·

    cyber security, Cyber Security News

    Security researcher Christopher Domas has released a proof-of-concept project called “skitter-creek-bath-salts,” which demonstrates a vulnerability in AMD’s DRAM-controller configuration that could compromise hardware-enforced memory isolation. This technique, tested on AMD Family 16h processors, manipulates address-translation behavior in the memory-controller layer, allowing access to data typically protected from the operating system, the kernel, and even ring-0 […]

    The post New DRAM Scrambling Attack Unlocks AMD CPU PSP, SMM and Microcode appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Apple Warns iPhone Users in 110 Countries of Mercenary Spyware Attacks

    ·

    Apple, cyber security, Cyber Security News, vulnerability

    Apple has issued a new set of high-confidence Apple Threat Notification alerts, warning selected iPhone users in 110 countries that they may be targets of government-grade mercenary spyware. These notifications are not routine phishing messages or general security advisories. According to Apple, these alerts are sent when internal threat intelligence indicates that a sophisticated and […]

    The post Apple Warns iPhone Users in 110 Countries of Mercenary Spyware Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • PATCHCORD Infrastructure Hosts SuperShell C2 for Remote Commands and Webshell Management

    ·

    cyber security, Cyber Security News

    A newly uncovered espionage operation targeting Afghan telecom providers and South Asian critical infrastructure has exposed a layered attacker ecosystem built around custom implants, spoofed delivery portals, cloud-backed command-and-control channels. The campaign began with sector-specific social-engineering lures, including a malicious Inno Setup package named TMS_AfghanTelecom.exe, distributed within a ZIP archive masquerading as Afghan Telecom’s telecom-management […]

    The post PATCHCORD Infrastructure Hosts SuperShell C2 for Remote Commands and Webshell Management appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers Steal One AI Key, Resell the Compute, and Leave Victims With a Million-Dollar Bill

    ·

    AI, cyber security, Cyber Security News

    A rapidly expanding financial cybercrime model called AI token jacking, where threat actors steal developer API keys for popular AI platforms, consume the victim’s allocated model capacity, and resell that compute through gray-market proxy services. The term “token” in this context does not refer to a browser session token. It refers to the metered units […]

    The post Hackers Steal One AI Key, Resell the Compute, and Leave Victims With a Million-Dollar Bill appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Fortinet FortiWeb and FortiClient Flaws Let Unauthenticated Attackers Gain Access and Execute Arbitrary Code

    ·

    CVE/vulnerability, cyber security, Cyber Security News, Vulnerabilities, vulnerability

    Fortinet has released security updates to address high-severity vulnerabilities in FortiWeb and FortiClient for Windows. These vulnerabilities could allow unauthenticated attackers to access appliance administration interfaces or execute arbitrary code. The flaws CVE-2026-26035 and CVE-2026-70465 were disclosed as part of an August 2026 patch release that addressed eight security issues across various Fortinet products. The […]

    The post Fortinet FortiWeb and FortiClient Flaws Let Unauthenticated Attackers Gain Access and Execute Arbitrary Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Aeternum Hides Malware Commands on Polygon Blockchain Where Server Takedowns Can’t Erase Them

    ·

    cyber security, Cyber Security News, Malware

    A newly analyzed malware operation called Aeternum is turning the public Polygon blockchain into a command-and-control (C2) channel, allowing attackers to distribute botnet instructions without relying on a conventional server or domain. The design shifts a core defensive assumption: seizing infrastructure may disrupt payload hosting, but it cannot remove commands that have already been committed […]

    The post Aeternum Hides Malware Commands on Polygon Blockchain Where Server Takedowns Can’t Erase Them appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Trezor Shipping Provider Data Breach Exposes Personal Data of 13,689 Customers

    ·

    cyber security, Cyber Security News, Data Breach, vulnerability

    Hardware wallet manufacturer Trezor has recently disclosed a data breach at ShipMonk, a third-party shipping provider. This breach exposed the personal information of 13,689 customers. Importantly, Trezor’s internal systems, hardware wallets, private keys, wallet backups, and cryptocurrency holdings were not compromised. However, the leaked data poses significant risks to affected users, particularly regarding phishing and […]

    The post Trezor Shipping Provider Data Breach Exposes Personal Data of 13,689 Customers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 … 8 9 10 11 12 … 1,044
Next Page

ADMIN.FOUNDATION

cybersecurity / defense / intelligence