Skip to content

ADMIN.FOUNDATION

  • Android Malware Spotted Subscribing Victims to Paid Services Without Consent

    ·

    Android, Cyber Attack, Cyber Crime, cybersecurity, Fraud, Malware, Privacy, SCAM, Scams and Fraud, Security, Zimperium, zLabs
    Cybersecurity researchers expose a 10-month global Android malware campaign using fake apps to secretly charge users through premium SMS bills.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft Defender Zero-Day Vulnerabilities Actively Exploited in the Wild

    ·

    cyber security, Cyber Security News, Vulnerabilities

    Microsoft has disclosed two new zero-day vulnerabilities in Microsoft Defender that are actively being exploited in the wild, raising concerns among security professionals and enterprise users. The vulnerabilities, tracked as CVE-2026-41091 and CVE-2026-45498, were officially released on May 19, 2026, and both have confirmed exploitation activity according to Microsoft’s security advisory. The most critical of […]

    The post Microsoft Defender Zero-Day Vulnerabilities Actively Exploited in the Wild appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Discord Enables End-to-End Encryption by Default Across Voice and Video Features

    ·

    cyber security, Cyber Security News

    Discord has officially enabled end-to-end encryption (E2EE) by default for all voice and video communications across its platform, marking a significant shift in user privacy and secure communications. The announcement, made on May 18, 2026, confirms that every voice and video call on Discord, across desktop, mobile, web browsers, and gaming consoles, is now protected […]

    The post Discord Enables End-to-End Encryption by Default Across Voice and Video Features appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft Warns of Two Actively Exploited Defender Vulnerabilities

    ·

    Microsoft has disclosed that a privilege escalation and a denial-of-service flaw in Defender has come under active exploitation in the wild. The former, tracked as CVE-2026-41091, is rated 7.8 on the CVSS scoring system. Successful exploitation of the flaw could allow an attacker to gain SYSTEM privileges. “Improper link resolution before file access (‘link following’) in Microsoft Defender

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google Chrome Security Flaws Could Let Attackers Execute Code Remotely

    ·

    Chrome, CVE/vulnerability, cyber security, Cyber Security News, Google, vulnerability

    Google has released a critical security update for its Chrome browser, addressing multiple vulnerabilities that could allow attackers to execute arbitrary code on affected systems. The update, now rolling out to users globally, upgrades Chrome to version 148.0.7778.178/179 for Windows and macOS, and 148.0.7778.178 for Linux. According to the official Chrome Releases blog, the latest […]

    The post Google Chrome Security Flaws Could Let Attackers Execute Code Remotely appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • When Identity is the Attack Path

    ·

    Consider a cached access key on a single Windows machine. It got there the way most cached credentials do – a user logged in, and the key stored itself automatically. Standard AWS behavior. No one misconfigured anything or violated a policy. Yet that single key, which was easily accessible to a minor-league attacker, could have opened a path to some 98% of entities in the company’s cloud

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Fake Microsoft Teams Downloads Spread ValleyRAT Malware

    ·

    cyber security, Cyber Security News, Malware

    Hackers are actively distributing a sophisticated ValleyRAT malware variant through fake Microsoft Teams download pages, leveraging social engineering and multi-stage execution techniques to evade detection. The campaign, first observed in mid-April on the X platform, uses fraudulent domains such as teams-securecall[.]com and teamszs[.]com. These sites closely mimic the official Microsoft Teams download page, tricking users […]

    The post Fake Microsoft Teams Downloads Spread ValleyRAT Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft’s Retired IE Tool MSHTA Now Being Used in Fileless Malware Attacks

    ·

    Cyber Attack, cybersecurity, Fileless, LOLBIN, Malware, Microsoft, MSHTA, Security, vulnerability
    Despite Internet Explorer’s retirement, hackers are abusing the legacy MSHTA utility in stealthy fileless malware attacks targeting Windows users.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • TamperedChef Malware Hides in Signed Apps to Drop Stealers and RATs

    ·

    cyber security, Cyber Security News, Malware

    A large-scale malware campaign dubbed “TamperedChef” is leveraging trojanized productivity applications such as PDF editors, calendar tools, and file converters to silently deploy information stealers and remote access trojans (RATs), according to recent threat intelligence findings. Security researchers have identified multiple activity clusters linked to this evolving threat, including CL-CRI-1089, CL-UNK-1090, and CL-UNK-1110. While these […]

    The post TamperedChef Malware Hides in Signed Apps to Drop Stealers and RATs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • New NGINX 0-Day RCE “nginx-poolslip” Threatens Millions of Servers

    ·

    CVE/vulnerability, cyber security, Cyber Security News, Vulnerabilities, vulnerability, zeroday

    A newly discovered zero-day vulnerability in NGINX, dubbed “nginx-poolslip,” is raising serious concerns across the global cybersecurity community, as it exposes millions of servers to potential remote code execution (RCE) attacks. The vulnerability affects NGINX version 1.31.0, the latest stable release of the widely used web server software that powers an estimated 30–40% of all […]

    The post New NGINX 0-Day RCE “nginx-poolslip” Threatens Millions of Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 … 274 275 276 277 278 … 1,078
Next Page

ADMIN.FOUNDATION

cybersecurity / defense / intelligence