Skip to content

ADMIN.FOUNDATION

  • New Kerberos Relay Technique Exploits DNS CNAMEs to Bypass Existing Defenses

    ·

    CVE/vulnerability, cyber security, Cyber Security News, DNS, vulnerability

    A critical vulnerability in Windows Kerberos authentication that enables attackers to conduct credential-relay attacks by exploiting DNS CNAME records. Tracked as CVE-2026-20929, this flaw allows threat actors to force victims into requesting Kerberos service tickets for attacker-controlled systems, facilitating lateral movement and privilege escalation even when NTLM authentication is entirely disabled. CVE ID Vulnerability Name […]

    The post New Kerberos Relay Technique Exploits DNS CNAMEs to Bypass Existing Defenses appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GhostPoster Malware Targets Chrome Users via 17 Rogue Extensions

    ·

    cyber security, Cyber Security News, Malware

    A sophisticated malware campaign has compromised users of Chrome, Firefox, and Edge by deploying 17 malicious extensions that employ advanced steganography techniques to evade detection. Collectively downloaded more than 840,000 times, the GhostPoster operation represents one of the most technically mature and persistent browser extension threats documented to date. The GhostPoster campaign leverages an uncommon […]

    The post GhostPoster Malware Targets Chrome Users via 17 Rogue Extensions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • How Security Teams Use IP Location and DNS History In Cybercrime Investigation

    ·

    cyber security

    In many security teams, a cybercrime investigation often begins without a complete picture. It starts with a small signal. A suspicious login. An unexpected outbound connection. A single alert that does not look right. From that moment, investigators need context. Logs alone show what happened, but not who is behind it or why it matters. […]

    The post How Security Teams Use IP Location and DNS History In Cybercrime Investigation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice

    ·

    Ukrainian and German law enforcement authorities have identified two Ukrainians suspected of working for the Russia-linked ransomware-as-a-service (RaaS) group Black Basta. In addition, the group’s alleged leader, a 35-year-old Russian national named Oleg Evgenievich Nefedov (Нефедов Олег Евгеньевич), has been added to the European Union’s Most Wanted and INTERPOL’s Red Notice lists, authorities

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google Vertex AI Flaw Lets Low-Privilege Users Escalate to Service Agent Roles

    ·

    CVE/vulnerability, cyber security, Cyber Security News, Google, vulnerability

    Security researchers have discovered critical privilege escalation vulnerabilities in Google’s Vertex AI platform that allow attackers with minimal permissions to hijack high-privileged Service Agent accounts. The flaws affect the Vertex AI Agent Engine and Ray on Vertex AI, where default configurations enable low-privileged users to access powerful managed identities with project-wide permissions. As enterprises rapidly […]

    The post Google Vertex AI Flaw Lets Low-Privilege Users Escalate to Service Agent Roles appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • OpenAI to Show Ads in ChatGPT for Logged-In U.S. Adults on Free and Go Plans

    ·

    OpenAI on Friday said it would start showing ads in ChatGPT to logged-in adult U.S. users in both the free and ChatGPT Go tiers in the coming weeks, as the artificial intelligence (AI) company expanded access to its low-cost subscription globally. “You need to know that your data and conversations are protected and never sold to advertisers,” OpenAI said. “And we need to keep a high bar and give

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Critical XSS Vulnerabilities in Meta Conversion API Enable Zero-Click Account Takeover

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability, xss

    Security researchers have uncovered two critical cross-site scripting (XSS) vulnerabilities in Meta’s Conversions API Gateway that could enable attackers to hijack Facebook accounts on a massive scale without any user interaction. The flaws affect Meta-owned domains, including facebook.com and meta.com, as well as potentially 100 million third-party deployments of the open-source gateway infrastructure. Understanding the […]

    The post Critical XSS Vulnerabilities in Meta Conversion API Enable Zero-Click Account Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Researchers Breach StealC Infrastructure, Access Malware Control Panels

    ·

    cyber security, Cyber Security News, Malware, vulnerability

    Criminal infrastructure often fails for the same reasons it succeeds: it is rushed, reused, and poorly secured. Security researchers recently demonstrated this vulnerability by exploiting the very malware infrastructure designed to steal victims’ credentials. StealC Malware and Its Infrastructure Weaknesses StealC is an infostealer malware distributed under a Malware-as-a-Service (MaaS) model since early 2023. The […]

    The post Researchers Breach StealC Infrastructure, Access Malware Control Panels appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Windows 11 January Update Sparks Widespread Shutdown Complaints

    ·

    cyber security, Cyber Security News, Windows

    Microsoft’s latest security update for Windows 11 has triggered an unexpected problem affecting enterprise users: PCs equipped with Secure Launch are unable to shut down or hibernate properly. Instead of powering off, affected devices restart automatically, disrupting workflows and forcing users to work around the issue until a fix arrives. Secure Launch Devices Face Shutdown […]

    The post Windows 11 January Update Sparks Widespread Shutdown Complaints appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Trump’s ‘battleship’ could be most expensive US warship in history

    ·

    Defense Systems
    The first Trump-class “battleship” ordered up by the White House could cost as much as $22 billion, and could cut into the Navy’s plans for next-generation destroyers, Congressional researchers said Thursday.

    An early analysis by the Congressional Budget Office indicates that the BBG(X) could cost between $15 billion and $22 billion, depending on weight and other decisions, CBO analyst Eric Labs said during a presentation at the Surface Navy Association symposium outside Washington, D.C.

    “You're talking about a lead ship in the range of $18 to $19 billion for the 35,000-ton displacement, north of $20 billion if the displacement ends up being higher,” Labs said.

    That would make the BBG(X), which Trump announced in December, one of the most expensive ships in U.S. history—more than the $13 billion aircraft carrier Ford, which came in 30 percent over budget. 

    Labs speculated that subsequent Trump-class warships could cost somewhere between $10 billion and $15 billion, depending on the size of the vessels and under ideal labor conditions. In his presentation, he noted that the U.S. shipbuilding workforce, which has not grown since 1990, is too small to handle even the Navy’s current plans.

    “There's a lot of reasons to think that those numbers are not going to be correct. I think it's a starting point,” Labs said. “There are a number of factors that are going to play in that lead me to conclude that the ship might be more expensive than what I've said so far … and there's reasons to think why they could be less expensive.”

    The vessel is pitched as a cornerstone of the president’s “Golden Fleet,” announced after the Navy cancelled its Constellation frigate program in November and subsequent launched a new frigate effort. 

    Congressional researchers also wonder what the battleship program means for the Navy’s next-generation guided missile destroyer, or DDG(X), program. Navy officials have suggested that the former will replace the latter: “The battleship took the DDG(X) concept and it's put that on steroids, under the assumption that the counter-targeting efforts of the Navy will protect it and make it survivable,” Chief of Naval Operations Adm. Daryl Caudle said on Wednesday.

    But what happens if a future administration cancels a giant warship that many naval experts have called impractical?

    “I think it's worth asking the question if at some point, for some reason, there's a change of heart on the battleship program a few years from now, then what will be the impact of the time loss on the DDG(X),” Ronald O’Rourke, a naval affairs analyst for the Congressional Research Service, said during Thursday’s presentation

    The DDG(X) and the Constellation frigate programs have been under heavy scrutiny for inaccurate cost estimates and running behind schedule. To avoid similar pitfalls, O’Rourke said, Congress should also consider whether the starts of both the BBG(X) and the frigate programs have received sufficient analysis—particularly since their announcement caught some service officials off guard.

    “It's at least worth asking the question and understanding whether the program came first and the analysis came later or not,” he said. 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 … 577 578 579 580 581 … 1,066
Next Page

ADMIN.FOUNDATION

cybersecurity / defense / intelligence