Skip to content

ADMIN.FOUNDATION

  • Iran-Linked Hackers Target Oman Ministries in Webshell and Data Theft Campaign

    ·

    cyber security, Cyber Security News

    Iran-linked operators have mounted a broad espionage operation against multiple Omani ministries, abusing exposed webshells, SQL escalation scripts, and a poorly secured C2 server to steal judicial and identity data at scale. Attacker’s own open directory strongly suggests a Ministry of Intelligence and Security (MOIS) nexus compromised a mailbox , but there are not enough unique […]

    The post Iran-Linked Hackers Target Oman Ministries in Webshell and Data Theft Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Zero-Auth Vulnerability Enables Cross-Tenant Access at DoD Contractor

    ·

    CVE/vulnerability, Cyber Security News, vulnerability

    A severe authorization vulnerability was recently discovered in Schemata, an AI-powered virtual training platform serving the United States Department of Defense. Security researcher Alex Schapiro, utilizing the open-source AI hacking agent Strix, identified a critical lack of API authorization. Backed by Andreessen Horowitz, Schemata holds active government contracts to provide immersive 3D simulations for various […]

    The post Zero-Auth Vulnerability Enables Cross-Tenant Access at DoD Contractor appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Malicious OpenClaw Skill Targets Agentic AI Workflows to Deploy RATs and Stealers

    ·

    AI, cyber security, Cyber Security News

    OpenClaw’s agent “skill” ecosystem to deliver both Remcos RAT and a cross‑platform stealer called GhostLoader by hiding malware inside a deceptive DeepSeek integration called “DeepSeek‑Claw.” The campaign shows how agentic AI workflows with high local privileges can be quietly hijacked through manipulated installation instructions rather than classic exploit chains. OpenClaw, formerly known as Clawdbot and […]

    The post Malicious OpenClaw Skill Targets Agentic AI Workflows to Deploy RATs and Stealers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution

    ·

    Palo Alto Networks has released an advisory warning that a critical buffer overflow vulnerability in its PAN-OS software has been exploited in the wild. The vulnerability, tracked as CVE-2026-0300, has been described as a case of unauthenticated remote code execution. It carries a CVSS score of 9.3 if the User-ID Authentication Portal is configured to enable access from the internet or any

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Vimeo Confirms Breach Exposing 119,000 Unique User Email Addresses

    ·

    cyber security, Cyber Security News, Data Breach

    Video hosting platform Vimeo has confirmed a data breach that exposed approximately 119,000 unique user email addresses, attributing the incident to a security compromise at Anodot, a third-party analytics vendor integrated with its systems. The breach came to light after the ShinyHunters extortion group listed Vimeo on its “pay or leak” portal in April 2026, […]

    The post Vimeo Confirms Breach Exposing 119,000 Unique User Email Addresses appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Remus Infostealer Adopts Lumma-Style Browser Key Theft to Bypass App-Bound Encryption

    ·

    cyber security, Cyber Security News

    Remus is a newly observed 64-bit infostealer that closely tracks the Lumma Stealer codebase while adding EtherHiding-based C2 resolution and a refined Application‑Bound Encryption (ABE) bypass for Chromium browsers. The first Remus activity dates back to early 2026, shortly after Lumma’s core operators were doxxed between August and October 2025, suggesting either a rebrand or […]

    The post Remus Infostealer Adopts Lumma-Style Browser Key Theft to Bypass App-Bound Encryption appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Attackers Bypass Azure AD Conditional Access Using Phantom Device Registration

    ·

    Azure, cyber security, Cyber Security News, vulnerability

    A recent authorized red team operation by Howler Cell has demonstrated a critical attack path that completely bypasses Microsoft Entra ID (Azure AD) Conditional Access. Azure Conditional Access acts as the primary gatekeeper for cloud identity security, enforcing access rules based on user location, device compliance, and calculated risk scores. However, by starting with a […]

    The post Attackers Bypass Azure AD Conditional Access Using Phantom Device Registration appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Ransomware Gangs Escalate Attacks on Aviation and Aerospace Sector

    ·

    cyber security, Cyber Security News, Ransomware

    Ransomware and data extortion groups are increasingly targeting the aviation and aerospace sector, exploiting interconnected systems, shared platforms, and identity-based access models to cause operational disruption and data compromise. Cyber risk across aviation has shifted beyond traditional IT incidents toward ransomware attacks, credential theft, and platform-level compromise. The aviation ecosystem relies heavily on shared IT […]

    The post Ransomware Gangs Escalate Attacks on Aviation and Aerospace Sector appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Critical Palo Alto Firewall Vulnerability Enables Attackers to Gain Root Privileges

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    Palo Alto Networks has issued an urgent security advisory concerning a critical vulnerability affecting its PAN-OS software. Tracked as CVE-2026-0300, this high-severity security flaw carries a CVSS 4.0 base score of 9.3 and is currently experiencing limited active exploitation in the wild. The vulnerability allows unauthenticated, remote attackers to execute arbitrary code with full root […]

    The post Critical Palo Alto Firewall Vulnerability Enables Attackers to Gain Root Privileges appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Air Force wants AI in its air-ops command-and-control system

    ·

    Defense Systems
    The Air Force is in the early stages of improving its command-and-control system for regional air, space, and cyber forces.

    The Next-Generation Air Operations Center Weapon System effort aims to upgrade the Air Operations Center (AOC) Weapon System to bring AI-powered tools to planners and operators at combatant commands. Since February, the Air Force has released a request for information and two sets of Q&As.

    The contract is managed by the Air Operations Center Program Office of Kessel Run, the Air Force software factory now housed under the service's Portfolio Acquisition Executive for command, control, communications and battle management. Postings on Sam.gov indicate that the service wants a fast, flexible acquisition plan, perhaps through the use of other transaction agreements.

    The RFI calls for a prime contractor to work as a systems integrator. Several of the documents, such as the statement of need, have not been publicly disclosed.

    Some technical requirements include: IL6 or higher for cloud, Secret or higher for edge computing, and a continuity of operations/disconnected state requirement.

    The solicitation will include a requirement for a top-secret facility clearance. The Air Force expects to release a bidder’s library with the draft solicitation.

    The documents ask industry to suggest ways to meet program objectives. They also ask about agreement structures, including an OTA.

    In Q&A documents released Tuesday, the Air Force again said it was considering all acquisition strategies.

    An OTA with follow-on production is one approach that could bring the speed and flexibility the Air Force is looking for. But a traditional procurement will likely be used for sustainment, according to the Q&A.

    No procurement timeline has been given, but the Air Force has signaled it wants a competitive field. Industry is already pressing the program office on that point.

    One question submitted by a prospective offeror asked how the government would ensure a level playing field and avoid "carve outs and pay-to-play relationships with a small group of vendors."

    The Air Force response was brief: "The government is engaging with industry as part of market research and seeks to maximize competition for this requirement."

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 … 315 316 317 318 319 … 1,076
Next Page

ADMIN.FOUNDATION

cybersecurity / defense / intelligence