• A cyberattack linked to the notorious threat group ShinyHunters has disrupted a widely used Learning Management System (LMS), impacting educational institutions and students across the United States. According to a Public Service Announcement (PSA) issued by the FBI on May 15, 2026 (Alert I-051526-PSA), the platform has since been restored. However, concerns remain over potential […]

    The post ShinyHunters Takes Responsibility for Attack on Learning Management Platform appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Drupal has issued an alert stating that it intends to release a “core security release” for all supported branches on May 20, 2026, from 5-9 p.m. UTC. “The Drupal Security Team urges you to reserve time for core updates at that time because exploits might be developed within hours or days,” the maintainers of the PHP-based content management system (CMS) said. “Not all configurations are

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • There’s a quiet pattern among the agencies that consistently outperform their competitors. Their client retention rates are higher.…

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Application security posture management (ASPM) has become a foundational capability for software-as-a-service (SaaS) and software companies building increasingly complex, artificial intelligence-assisted applications. As engineering velocity increases and AI-generated code becomes part of everyday development workflows, security teams are under pressure to unify visibility, reduce fragmented tooling, and improve how risk is identified and prioritized across the software […]

    The post What to Look for When Choosing an ASPM Platform  appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers are actively exploiting the Nginx Rift vulnerability affecting NGINX and F5 products, exposing servers to denial-of-service attacks.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly discovered problem with the Apache helicopter’s transmission is plaguing the Army’s fleet, just as funding woes have pushed the service to drastically cut flight hours and rapidly retire older variants of the combat helicopter, Defense One has learned.

    An Army investigation has indicated that “some AH-64E [improved drive system] main transmissions can experience an internal failure resulting in loss of accessory gearbox drive, which can result in loss of tail rotor thrust, electrical power, and hydraulics,” according to an April internal safety document reviewed by Defense One. “The root cause is still under investigation.” 

    The safety document said “all AH-64E series aircraft” are affected, and instructed the service to “ground affected [improved drive system] main transmissions” until more guidance is provided. The service confirmed the investigation, but declined to say when the transmission problem was discovered or how many helicopters were affected. A spokesman for Boeing, the Apache’s manufacturer, declined to comment.

    “The Army has identified a potential transmission issue involving the AH-64E helicopter,” a service spokesperson said in an emailed statement. “We are actively collaborating with the manufacturer to conduct a comprehensive investigation to determine the root cause of the problem.”

    The Apache transmission investigation comes as the Army leans heavily on the combat helicopter for the war in Iran, sends them to foreign militaries, transports celebrities and administration officials in them, and plans to upgrade them into high-tech drone hunters for future conflicts. At the same time, other internal documents reviewed by Defense One revealed that the service’s III Armored Corps is heavily reducing its flight hour program and is quickly divesting the older AH-64D model to overcome funding woes. 

    The AH-64E has been involved in several incidents stateside and abroad in recent months. One Apache pilot said the combination of the helicopter’s transmission problems and the service’s push to reduce some flight hour programs is a brutal combination, particularly amid seemingly continuous maintenance woes. 

    “It's a double-edged sword,” the Apache pilot said. “You're getting less money in these budgets, at the same time, you're having more maintenance problems, which cost more money, but the money's not there.”

    There have been at least three Apache incidents within the last three months.

    In March, an AH-64E, the latest Apache variant, crashed during a training exercise at Fort Rucker, Alabama, leaving two crew members injured, several local media outlets reported. Last month, another Apache made an emergency landing in rural Alabama following an in-flight problem, one local TV station reported. That same month, another Apache crashed at Fort Hood in Texas during a maintenance flight, according to photos and information one pilot provided to Defense One

    Last week, another Apache made a similar precautionary landing outside of Camp Humphreys in South Korea, Stars and Stripes reported. An Army spokesperson declined to confirm a timeline of recent Apache incidents and wouldn’t say whether they were tied to the transmission problems. 

    “While we have gathered some preliminary findings, we are currently withholding these details to prevent any unnecessary speculation while the investigation is still in progress,” an Army spokesperson said in an email.

    Less money, more problems

    The ongoing investigation into the AH-64E’s transmission comes as the Army works through sudden funding challenges that have pushed some units to drastically reduce flying hours and divest the older helicopter variant, internal documents reviewed by Defense One show. 

    Sen. Jack Reed, D-R.I., hinted at the issue during a Senate Armed Services hearing last week, and said the Homeland Security Department’s domestic missions have caused funding headaches for the Army.

    “The Army is facing a nearly two-billion-dollar readiness shortfall, largely because DHS has failed to reimburse the Army for border support missions,” Reed said in his opening statement. “The committee will want to understand what that means in concrete terms. I have received concerning reports about the potential for cancelled training rotations, grounded flight hours, and reduced Guard and Reserve training resources.” 

    One internal memo shows that’s the case for the aviation units of the Army’s III Armored Corps.

    The funding for the III Corps flying hour program was to be decreased by about $46 million, “effective immediately,” due to “operational requirements,” according to an April 26 internal memo reviewed by Defense One

    To meet minimum aviation requirements, the III Corps commander transferred $26.6 million from the funds used for armor training to its aviation units, the memo said. The formation recognizes that the sudden shift in funds comes with risks, according to the memo.

    The III Armored Corps “accepts the secondary effects of degraded combined arms support for Division [Armored Brigade Combat Teams and Combat Training Center] rotations, and the long-term career stagnation for Warrant and Company Grade officers resulting from a constrained [flight hour program],” the memo said. “Rebuilding this combat proficiency is estimated to take 12+ months.”

    III Corps officials will "tightly manage” the flight hour program on a monthly basis, with plans to “restrict all non-essential flying” and to issue waivers for not hitting flight hour minimums, the memo said. 

    Missions that are exempt from the flying-hour restrictions are the Southwest border mission, transportation for the 1st Infantry Division, cadet summer training, and flights tied to the modernization of the AH-64E and divestments of the older D models. 

    While the AH-64D was originally slated to retire by the end of September, the funding woes have sped up the process.

    The Army’s III Corps will "divest all AH-64Ds to achieve cost saving" by June 15, the memo said. Officials must also “cancel all static displays and flyovers for the rest of the fiscal year.” The service was already retiring the older models as part of its Army Transformation Initiative and its pivot to the upgraded Apache models.

    The Apache pilot said the sudden push to reduce time in the cockpit and the persistent mechanical problems with the AH-64E could be a deadly combination. 

    “Aircraft are going to break, that's kind of a given in this life, but it feels like a snowball effect,” the pilot said. “We have lower-hour cockpits and lower-hour piloting commands because they can't get the training they need, and then, in my own personal opinion, you see an uptick in incidents when you see a downtick in flight hours.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Gentlemen ransomware operation has rapidly emerged as one of the most active and scalable cybercrime threats since its public appearance in the second half of 2025. The Gentlemen stands out for its ability to target a wide range of enterprise systems, including Windows, Linux, NAS, BSD, and VMware ESXi environments. This lineage suggests the […]

    The post Gentlemen Ransomware Targets Windows, Linux, NAS, BSD, and ESXi Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enable an attacker to read arbitrary mails from the virtual appliance. “These vulnerabilities could have been exploited to read all mail traffic or as an entry vector into the internal network,”

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Kimsuky Hackers Use LNK and JSE Lures to Target Recruiters, Crypto Users, and Defense Officials. North Korea-linked threat group Kimsuky has launched at least four distinct spear-phishing campaigns in early 2026, targeting recruiters, cryptocurrency users, developers, defense personnel, and academic administrators. Despite using different themes and delivery methods, all campaigns follow a consistent attack chain: […]

    The post Kimsuky Uses LNK, JSE Lures to Target Recruiters, Crypto Users, Defense Officials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly released proof-of-concept (PoC) exploit for CVE-2026-2005 has brought renewed attention to a critical vulnerability in PostgreSQL’s pgcrypto extension, exposing systems to remote code execution (RCE). Security researchers warn that the flaw, rooted in legacy code paths dating back nearly two decades, could allow attackers to escalate privileges and execute arbitrary commands on affected […]

    The post 20-Year-Old PostgreSQL Flaw Gets Public PoC Exploit for Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶