Skip to content

ADMIN.FOUNDATION

  • BTMob Uses Custom Phishing Apps to Turn Android Users Into Remote-Controlled Fraud Victims

    ·

    Android, cyber security, Cyber Security News, Phishing

    BTMOB has evolved beyond a conventional Android banking trojan into a turnkey fraud platform that lets criminals build branded phishing apps, remotely operate infected phones, and automate theft. Its emergence illustrates how leaked malware source code and low-code tooling are turning mobile fraud into a scalable franchise. The malicious lnat-tv-pro.apk sample connected to server[.]yaarsa[.]com/con over […]

    The post BTMob Uses Custom Phishing Apps to Turn Android Users Into Remote-Controlled Fraud Victims appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • French Tax Authority Cyberattack Exposes Tax Data of 678,000 Individuals and Businesses

    ·

    cyber security, Cyber Security News, Data Breach

    France’s Directorate General of Public Finances (DGFiP) has reported a cyberattack that resulted in unauthorized access to and extraction of tax and cadastral data for approximately 678,000 individuals and professional entities. According to a press release from the French Ministry of Economy and Finance, issued on August 14, 2026, the intrusions occurred during June and […]

    The post French Tax Authority Cyberattack Exposes Tax Data of 678,000 Individuals and Businesses appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

    ·

    A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has named the City Forum campaign after a domain tied to the attacker’s IP address, traces back to one server: 158.220.87.79, hosted on a

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

    ·

    Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below – ubnuler ubnlder ri18nr reaker rakier orakw joxn

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Apple Addresses 28 Security Flaws Across macOS, iOS, and iPadOS

    ·

    Apple, CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    Apple has released security updates for iPhones, iPads, and Macs to address 28 vulnerabilities across its latest operating systems. These updates, issued on August 17, 2026, include iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and security fixes for older devices with iOS 18.7.10 and iPadOS 18.7.10. The patches impact a wide range of supported Apple […]

    The post Apple Addresses 28 Security Flaws Across macOS, iOS, and iPadOS appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Asruex Trojan Found Embedded in GEEKOM Mini PC Realtek Ethernet Driver

    ·

    cyber security, Cyber Security News

    GEEKOM has confirmed that a malware-flagged Realtek LAN driver package was previously accessible through an outdated support page for its mini PCs, raising fresh supply-chain security concerns around vendor-hosted driver downloads. The company said the affected file was confined to a legacy resource, not its current support portal or factory-installed Windows images. The incident came […]

    The post Asruex Trojan Found Embedded in GEEKOM Mini PC Realtek Ethernet Driver appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • AI Agents Gain Unintended Internet Access During Cybersecurity Evaluations

    ·

    Cyber Security News

    AI security evaluation firm has disclosed that several frontier AI models unintentionally accessed and acted against real internet-connected systems during controlled cybersecurity testing. This issue, which has since been resolved, stemmed from a single evaluation scenario in which internet access was permitted and a fictional target name overlapped with a real domain. Irregular stated that […]

    The post AI Agents Gain Unintended Internet Access During Cybersecurity Evaluations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, tracked as CVE-2025-62593, is a code injection flaw in the Ray Project, a widely used open-source distributed computing framework often deployed for artificial intelligence workloads, machine learning development, data processing, and scalable Python […]

    The post CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • JWR Phishing-as-a-Service Kit Uses WebSockets and AES to Run Real-Time Banking Fraud

    ·

    cyber security, Cyber Security News, Phishing

    JWR, an undocumented phishing-as-a-service (PhaaS) framework that turns conventional credential theft into an operator-led, real-time banking and payment fraud operation. Rather than waiting for a victim to submit a form, JWR streams keystrokes to an attacker over an AES-CTR-encrypted WebSocket channel, allowing the operator to react while card numbers, passwords and one-time codes are still […]

    The post JWR Phishing-as-a-Service Kit Uses WebSockets and AES to Run Real-Time Banking Fraud appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

    ·

    SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by email on August 16 from security@safepal.com, with the subject line “[Important] Your SafePal Order

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 2 3 4 5 … 1,042
Next Page

ADMIN.FOUNDATION

cybersecurity / defense / intelligence