Skip to content

ADMIN.FOUNDATION

  • VaultJacking Attack Exposes Google Password Vaults via Single PIN

    ·

    cyber security, Cyber Security News

    A newly disclosed phishing technique dubbed “VaultJacking” is raising serious concerns across the cybersecurity community after researchers demonstrated how a single captured Google Password Manager (GPM) PIN can expose an entire user credential vault. The attack shows that even passkeys widely promoted as phishing-resistant can be indirectly compromised when attackers target the underlying sync infrastructure […]

    The post VaultJacking Attack Exposes Google Password Vaults via Single PIN appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Top 10 Best Mobile Application Security Testing (MAST) Tools in 2026

    ·

    Cyber Security News, Top 10

    As mobile usage continues to dominate the digital landscape, securing mobile applications has never been more critical. The year 2026 brings new challenges to the table: sophisticated AI-driven cyberattacks, complex vulnerabilities, and the rapid evolution of continuous integration workflows. For enterprises and developers, relying on outdated security measures is no longer a viable strategy; proactive […]

    The post Top 10 Best Mobile Application Security Testing (MAST) Tools in 2026 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Gitea Container Registry Vulnerability Could Lead to Private Image Exposure

    ·

    CVE/vulnerability, cyber security, Cyber Security News, Vulnerabilities, vulnerability

    A critical vulnerability, tracked as CVE-2026-27771, has been discovered in Gitea’s built-in container registry, allowing unauthenticated remote attackers to access private container images without credentials. This flaw poses a serious risk as it can expose sensitive application data, including source code, secrets, and infrastructure configurations. Due to its severity and ease of exploitation, security experts […]

    The post Gitea Container Registry Vulnerability Could Lead to Private Image Exposure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • AI-Generated npm Malware Leaks Hacker’s Private GitHub Token

    ·

    AI, cyber security, Cyber Security News, GitHub, Malware

    A newly discovered malicious npm package is drawing attention across the cybersecurity community after inadvertently exposing its own operator’s private GitHub token. Identified by OX Security researchers, the package, named mouse5212-super-formatter, operates as an infostealer that silently exfiltrates sensitive files from compromised systems while masquerading as a legitimate development utility. The package, which has already reached […]

    The post AI-Generated npm Malware Leaks Hacker’s Private GitHub Token appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Critical Notepad++ Flaw Could Enable Remote Code Execution Attacks

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    Notepad++ has released version 8.9.6.1 to address multiple security vulnerabilities, including critical flaws that could allow arbitrary code execution under specific conditions. The update, published on May 26, 2026, patches three vulnerabilities tracked as CVE-2026-48770, CVE-2026-48778, and CVE-2026-48800. These issues affect versions up to 8.9.6 and highlight risks tied to improper handling of configuration files. […]

    The post Critical Notepad++ Flaw Could Enable Remote Code Execution Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • ClearFake Abuses BSC Testnet Contracts for Resilient C2 Operations

    ·

    cyber security, Cyber Security News

    Threat actors behind the ClearFake campaign have adopted a novel and highly resilient command-and-control (C2) architecture by leveraging BNB Smart Chain (BSC) testnet smart contracts, creating an infrastructure that is effectively immune to traditional takedown efforts. Unlike conventional malware campaigns that depend on easily disruptable infrastructure such as hosting providers or registrars, this approach embeds […]

    The post ClearFake Abuses BSC Testnet Contracts for Resilient C2 Operations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • How the Pentagon plans to spend $50 billion on drone warfare

    ·

    Science & Tech
    CAMP ATTERBURY, Indiana—A countdown began as a gaggle of defense officials, soldiers, drone makers, and reporters watched screens in a windowless operations center. Suddenly, a LUCAS drone appeared, moving at rocket speed and showing off a new low-level capability before it crashed through a cement structure on the test range. It was a vivid demonstration of just how quickly the FLM-136 drone is evolving—and of how swiftly Pentagon leaders want to spend the $50 billion they have requested this year for drone development and production.

    The path to spend that money quickly and well is paved with steps that Pentagon leaders have already taken. They have expanded the list of drones that unit commanders can easily buy, Emil Michael, defense undersecretary for research and engineering, said at the SOF Week event in Tampa last week. 

    “What was happening is we had this highly distributed drone sort of purchasing that all happened in small blocks, all in about the department, which has some goodness to that, because units can experiment on their own. But they had to buy from this small Blue List that never grew. Very hard for a vendor to get on that blue list,” he said.

    That will enable larger purchases of existing drones, Michael’s deputy James Mazol told reporters at Camp Atterbury as he described the Defense Autonomous Warfare Group’s plans to spend the $50 billion—more than 200 times its 2026 budget and more than the GDP of many nations.

    “Some of it is actually buying platforms en masse. Now there's a lot of actual platforms that can be part of that, that exist and just need to be scaled up”—meaning produced in larger quantities, Mazol said. 

    But the money will also go to bring in new companies, help them develop their systems, and bulk up their production.

    Autonomous surface vessel maker Saronic is a “good example of that,” said Mazol. “They have an unmanned surface vessel that has gone through…all this experimentation. They've built this body of evidence. And, you know, they're helping the Navy procure that in large quantities.”

    Meanwhile, defense officials are looking to Ukraine to foster new technology. 

    In March, when the Pentagon held “Gauntlet 1” of its Drone Dominance trials, the top performers included Ukrainian Defense Drones and a partnership of Ukraine’s SkyFall and a UK company—both examples of the sort of defense startup that can move quickly from launching to actually filling Pentagon orders. 

    The technology readiness experiment, or T-REX, was one of a series of rapid joint-service prototyping events begun in 2023. It also debuted a number of small startups like SplashOne Robotics, who are looking to partner with Ukraine. SplashOne showed off a quadcopter that shoots at other drones using autonomous targeting software called Gunner. Founder Jeff Wright said they “have game” against a variety of Russian one-way-attackers–the SuperCam 350, Orlan10, Molynia and even hard-to-hit Geran-2 drones.

    And more Pentagon commands are building up their ability to experiment with and procure drones. U.S. Southern Command has established an autonomous-warfare unit whose initial focus is building a data network to enable more effective use of drones.

    “We don't talk about robots at SAWC,” or SOUTHCOM Autonomous Warfare Command, said  Gen. Frank Donovan, who leads SOUTHCOM. “We talk about the data environment, the different data layers that we need at the very forward edge so our [special operations forces] and our conventional force teammates…can actually plug into that data network. Whatever robot shows up with the capability, they can leverage it instantaneously.”

    Donovan emphasized that he isn’t looking to a single company to create that environment, but instead wants open architectures that can connect many companies’ tools and products.

    “We can match the robots to the environment. Whether it swims, it flies, it has feet, whatever it does, we have to make it do what we want it to do when we want to do it,” he said at the SOF Week.

    Donovan’s message to vendors was blunt: it doesn’t matter how impressive your drone or counter-drone capability is if you put too many restrictions on how it connects, or the data it gives away. 

    “If it’s great only if you use it this way, only if you use my service stack, and only if you connect it to this or that, it’s unacceptable across the board.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Roundcube Webmail Vulnerability Allows Hackers to Execute Malicious SQL Queries

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    Roundcube Webmail users are being urged to update their systems immediately after the disclosure of multiple security vulnerabilities, including a critical pre-authentication SQL injection flaw that allows attackers to execute malicious database queries without requiring login access. The vulnerabilities were patched in newly released versions 1.6.16 and 1.7.1, published on May 24, 2026, as part […]

    The post Roundcube Webmail Vulnerability Allows Hackers to Execute Malicious SQL Queries appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware

    ·

    A new campaign orchestrated by a previously undocumented threat actor has targeted cryptocurrency organizations with an aim to facilitate digital asset theft using recruitment-themed social engineering and bespoke macOS malware. “These campaigns leveraged sophisticated social engineering techniques, custom macOS malware, and deep targeting of CI/CD infrastructure,” Wiz researchers Shira Ayal,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers Spread VIP Keylogger via Fake Business Emails

    ·

    cyber security, Cyber Security News

    Hackers are actively deploying VIP Keylogger through phishing emails disguised as routine business documents, using multi‑layered loaders, steganography, and in‑memory execution to quietly steal credentials and other sensitive data from compromised systems. Recent VIP Keylogger campaigns rely heavily on social engineering, with phishing emails crafted to look like legitimate bank payment notifications, procurement orders, logistics […]

    The post Hackers Spread VIP Keylogger via Fake Business Emails appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 … 260 261 262 263 264 … 1,080
Next Page

ADMIN.FOUNDATION

cybersecurity / defense / intelligence