Skip to content

ADMIN.FOUNDATION

  • FreePBX Security Flaw Lets Attackers Access User Portals

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    A critical security vulnerability has been discovered in FreePBX, a widely used open-source PBX platform, allowing unauthenticated attackers to access user portals under certain conditions. The flaw, tracked as CVE-2026-46376, carries a CVSS v4 base score of 9.1 and affects the User Control Panel (UCP) via the “userman” module. FreePBX Security Flaw According to an […]

    The post FreePBX Security Flaw Lets Attackers Access User Portals appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • DevilNFC Malware Traps Android Users in NFC Relay Attacks

    ·

    Android, cyber security, Cyber Security News, Malware

    A newly identified Android malware family named DevilNFC is raising concern among cybersecurity researchers for its advanced use of kiosk mode to trap victims during NFC relay attacks. These malware families mark a significant evolution in NFC relay threats. Unlike earlier campaigns dominated by Chinese-speaking Malware-as-a-Service ecosystems, DevilNFC and NFCMultiPay are developed by independent regional […]

    The post DevilNFC Malware Traps Android Users in NFC Relay Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Mini Shai-Hulud Attack Hits npm Ecosystem, Compromising Over 600 Packages

    ·

    Cyber Attack, cyber security, Cyber Security News

    A large-scale supply chain attack targeting the npm ecosystem has resurfaced with a new variant of the Mini Shai-Hulud malware, compromising more than 600 packages and introducing advanced evasion techniques, including forged Sigstore provenance. The attack primarily targeted the widely used @antv ecosystem but quickly spread to other popular libraries and developer tools. The attack […]

    The post Mini Shai-Hulud Attack Hits npm Ecosystem, Compromising Over 600 Packages appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Single-Letter Go Module Typosquat Drops DNS-Based Backdoor

    ·

    cyber security, Cyber Security News

    A newly uncovered software supply chain attack targeting Go developers demonstrates how a single-character typo can silently introduce a persistent backdoor. A malicious Go module, github.com/shopsprint/decimal, designed to impersonate the widely trusted github.com/shopspring/decimal library used for high-precision arithmetic in financial and analytics applications. The legitimate package is heavily adopted across the Go ecosystem, with more than 38,000 known […]

    The post Single-Letter Go Module Typosquat Drops DNS-Based Backdoor appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • PoC Exploit Released for DirtyDecrypt Linux Kernel Vulnerability

    ·

    CVE/vulnerability, cyber security, Cyber Security News, Linux, PoC, vulnerability

    PoC exploit code for the DirtyDecrypt (DirtyCBC) Linux kernel vulnerability has been released publicly, turning a previously theoretical local privilege escalation into a practical, copy‑paste exploit path to root on specific Linux distributions. DirtyDecrypt (also called DirtyCBC) is a local privilege escalation (LPE) in the Linux kernel’s RxGK security layer for the RxRPC transport used by […]

    The post PoC Exploit Released for DirtyDecrypt Linux Kernel Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers Exploit MSHTA to Deploy LummaStealer and Amatera Malware

    ·

    cyber security, Cyber Security News, Malware

    Hackers are increasingly abusing the legacy Microsoft HTML Application Host (MSHTA) utility to deliver commodity malware such as LummaStealer and Amatera. Despite being tied to Internet Explorer, which was retired in 2022, MSHTA remains default in Windows, making it an attractive Living-off-the-Land binary (LOLBIN) for stealthy attacks. MSHTA allows execution of VBScript and JavaScript from […]

    The post Hackers Exploit MSHTA to Deploy LummaStealer and Amatera Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GitHub Source Code Reportedly Compromised, TeamPCP Claims Breach

    ·

    cyber security, Cyber Security News, GitHub, vulnerability

    A threat actor group known as TeamPCP has claimed responsibility for a significant breach involving GitHub’s internal systems, alleging the theft of sensitive source code and proprietary organizational data. The group is currently offering the allegedly stolen dataset for sale on underground cybercrime forums, with asking prices reportedly exceeding $50,000. According to posts shared on […]

    The post GitHub Source Code Reportedly Compromised, TeamPCP Claims Breach appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

    ·

    Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compromised. It said the scope of the incident is limited to the Grafana Labs GitHub environment, which includes public and private source code along with internal GitHub repositories. “After the initial assessment, we found that in addition to source

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos

    ·

    GitHub on Tuesday said it’s investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP listed the platform’s source code and internal organizations for sale on a cybercrime forum. “While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • ‘Everybody is going underground’: CENTCOM head calls for new tech to hit buried targets

    ·

    Threats
    More money to counter drones and attack underground targets is necessary for future fights, the head of U.S. Central Command said on Thursday, as lawmakers praised and grilled the four-star admiral about the war in Iran.

    In his first House Armed Services Committee appearance since the Iran war began, Adm. Brad Cooper said the U.S. military has changed even in the past eight weeks, leaning on LUCAS drones as well as land-attack missiles and finding cheaper ways to fight off Iranian drones and other weapons. 

    But when asked by Rep. John McGuire, R-Va., what additional support was needed, the four-star admiral had a wish list ready.

    “I’d put three things: more electronic warfare, keep counter-UAS on the leading edge—tactics change very quickly—and we need to invest more in hard and deeply buried targets,” Cooper said. “Everybody is going underground.” 

    A CENTCOM spokesperson later told Defense One the CENTCOM commander was referring to munitions that can destroy more hidden and hardened targets. 

    Cooper’s HASC appearance followed his testimony before the Senate last week, when some members criticized the administration’s shifting justifications for the war. Nor wereHouse Democrats reticent to criticize the conflict’s launch and conduct by  the White House.

    Rep. John Garamendi, D-Calif., criticized Cooper and Daniel Zimmerman, the Pentagon’s assistant international security affairs secretary, for the Trump administration’s continued military operations despite an avowed May 5 ceasefire and the legal limits on wars without Congressional approval. Garamendi said that U.S. forces fired on Iranian tankers after the administration said it halted military actions.  

    “It's incredible to me that this department has such disregard for the Congress and the U.S. Constitution, that the U.S. military forces are not still engaged in hostilities and still deployed against the war and ignoring the War Powers Act and the Constitution,” Garamendi said. “The fact of the matter is that hostilities continue.”

    In one exchange, Rep. Seth Moulton, D-Mass., peppered Cooper with rapid-fire questions—including whether the military’s war plan had anticipatedrising gas and oil prices, the closure of the Strait of Hormuz, and the lack of a nuclear deal. 

    “We achieved all our military objectives, we're presently in a ceasefire, we're executing a blockade, and we're prepared for a broad range of contingencies,” Cooper said.

    “Well, it doesn't seem to be going well,” Moulton replied. “And I would like to know, how many more Americans have to ask to die for this mistake?”

    “I think it's an entirely inappropriate statement from you, sir,” Cooper said. “With all due respect.” 

    Other members, such as Rep. Joe Wilson, R-S.C., praised the admiral’s leadership and the “remarkable” military achievements.

    Lawmakers also asked for updates regarding the investigation into the Feb. 28 airstrike on an Iranian girl’s school, which preliminary inquiries reportedly show the U.S. was responsible. 

    Cooper said that investigation “is coming to the end” and said he was committed to releasing an unclassified version to the public.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 … 279 280 281 282 283 … 1,078
Next Page

ADMIN.FOUNDATION

cybersecurity / defense / intelligence