• A critical security vulnerability was discovered when a complete 4-terabyte SQL Server backup belonging to Ernst & Young (EY), one of the world’s Big Four accounting firms, was found publicly accessible on Microsoft Azure. The exposure was identified by security researchers during routine internet mapping operations and has since been remediated following responsible disclosure protocols. […]

    The post Massive 4TB EY Database Backup Found Publicly Accessible on Azure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Russian-linked attackers have intensified their targeting of Ukrainian organizations through sophisticated intrusions that rely heavily on legitimate Windows tools rather than malware. The attackers demonstrated remarkable restraint in their malware deployment, instead leveraging living-off-the-land tactics and dual-use tools to evade detection while accomplishing their objectives. A recent investigation by our Threat Hunter Team revealed two […]

    The post Russian Hackers Target Government with Stealthy “Living-Off-the-Land” Tactics appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In response to escalating threats of credential theft, Google, through its Mandiant cybersecurity division, has unveiled a detailed guide to help defenders monitor and secure privileged accounts across modern IT environments.

    This resource emphasizes practical strategies to mitigate risks posed by stolen credentials, which accounted for 16% of intrusions in 2024, according to Mandiant’s M-Trends report.

    As cloud migrations expand attack surfaces with human and non-human identities, the guide positions privileged access management (PAM) as a cornerstone of organizational resilience.

    The guide highlights how adversaries increasingly exploit privileged accounts for initial access, lateral movement, and mission completion, often via infostealer malware or social engineering enhanced by AI.

    Stolen credentials enable breaches with a median dwell time of 11 days, underscoring the need for an assume-breach mindset.

    Google’s Guide for Defenders

    Mandiant structures its recommendations around three pillars: prevention through securing access pathways, detection via visibility engineering, and response with rapid remediation tactics.

    Prevention starts with defining privileged accounts broadly, encompassing service accounts, API keys, and developers’ cloud access beyond traditional domain admins.

    It advocates tiering accounts by impact (T0 for crown jewels like domain controllers, T1 for core platforms, T2 for workstations) and mapping dependencies like jump servers.

    Organizations are urged to advance PAM maturity from uninitiated (manual, spreadsheet-based tracking) to an iterative, automated, analytics-driven approach.

    Key controls include multifactor authentication (MFA) on all admin paths, just-in-time/just-enough administration (JIT/JEA), and privileged access workstations (PAWs) on segmented networks.

    Dedicated PAM tools like CyberArk or Google’s own Privileged Access Manager are recommended for vaulting credentials, enforcing rotations, and session recording.

    For detection, the guide stresses high-fidelity monitoring in tools like Google SecOps, distinguishing privileged anomalies from general IAM abuse through behavioral analytics and machine learning.

    Specific hunts target brute-force on Tier-0 accounts, GPO modifications, and service account deviations. In incidents, immediate isolation network pulls, token revocation pairs with coordinated credential resets via PAM.

    Remediation involves enterprise-wide password rotations and forensics on attack paths, including malware scans on developer systems. Recovery planning covers hardening virtualization (e.g., ESXi Lockdown Mode) and backups with immutable storage.

    By integrating SoD, zero-standing privileges, and automated responses, the guide equips defenders to shrink blast radii and comply with standards like NIST and PCI DSS.

    Released amid rising insider and third-party risks, this framework empowers security teams to protect the “keys to the kingdom” effectively.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Google Unveils Guide for Defenders to Monitor Privileged User Accounts appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has released comprehensive guidance on protecting privileged accounts, recognizing that stolen credentials have become one of the most dangerous attack vectors facing modern organizations. The new recommendations address how attackers increasingly exploit these “keys to the kingdom” to breach sensitive systems and steal valuable data. According to recent threat intelligence, stolen credentials now rank […]

    The post Google Publishes New Guide to Help Defenders Monitor Privileged Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new remote access trojan called Atroposia has emerged as one of the most concerning threats in the cybercriminal underground, offering an unprecedented combination of stealth capabilities and attack features.

    This modular malware operates as a turnkey criminal toolkit designed specifically to lower the technical barrier for threat actors of varying skill levels.

    Priced aggressively at approximately $200 monthly or $900 for six months, Atroposia democratizes sophisticated cyberattacks in ways previously reserved for advanced persistent threat groups.

    Atroposia portal (Source – Varonis)

    The malware represents a troubling trend in how modern cybercriminals bundle multiple offensive capabilities into user-friendly platforms.

    Similar to contemporaneous tools like SpamGPT and MatrixPDF, Atroposia packages hidden remote desktop takeover, credential harvesting, cryptocurrency wallet theft, DNS hijacking, and vulnerability scanning alongside encrypted command-and-control communications.

    Its intuitive control panel and plugin builder architecture mean even operators with minimal technical expertise can orchestrate complex intrusions against enterprise environments.

    The threat landscape shifted notably when Varonis researchers identified Atroposia circulating across underground forums.

    Varonis analysts noted the malware automatically escalates privileges through User Access Control bypass mechanisms and installs multiple persistence techniques to maintain access across system reboots.

    These capabilities allow attackers to blend seamlessly into compromised systems, evade antivirus software, and maintain long-term presence without triggering security alerts.

    Hidden Remote Desktop Access and System Persistence

    Atroposia’s most insidious feature centers on its hidden remote desktop protocol implementation, branded as HRDP Connect.

    Atroposia key features (Source – Varonis)

    This functionality spawns covert desktop sessions in the background, creating invisible shadow logins that grant attackers complete system interaction capabilities.

    When attackers exploit this feature, victims see no on-screen indication of remote control, allowing intruders to surveil activities, access sensitive documents, manipulate workflows, and piggyback on authenticated sessions without detection.

    The legitimate user remains entirely unaware of the intrusion occurring in real time.

    The hidden RDP capability bypasses traditional remote access monitoring systems since it doesn’t generate standard remote desktop notifications or logged-in user prompts.

    Attackers can conduct espionage and data theft activities while operating under the guise of legitimate user sessions.

    Combined with Atroposia’s dedicated file manager providing complete remote file system access, operators can exfiltrate sensitive data through fileless techniques that minimize on-disk footprints and evade data loss prevention systems.

    The malware’s Grabber module can automatically hunt files by extension or keyword, compress them into password-protected archives, and extract data entirely in memory, leaving minimal forensic traces.

    The emergence of Atroposia exemplifies how cybercrime continues evolving into a service industry where sophisticated attack capabilities no longer depend on threat actor expertise but rather financial access and market availability.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post New Atroposia RAT with Stealthy Remote Desktop, Vulnerability Scanner and Persistence Mechanisms appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The campaign leverages judicial document themes to distribute Hijackloader malware, which subsequently deploys PureHVNC remote access trojan (RAT)—marking the first observed instance where this combination has been used against Spanish-speaking users in Latin America. The campaign represents a significant tactical shift for threat actors operating in the region. Hijackloader, previously documented in campaigns targeting CrowdStrike […]

    The post PureHVNC RAT Distributed via Weaponized Judicial Documents appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat intelligence researchers have identified a new ransomware-as-a-service (RaaS) operation called The Gentlemen’s RaaS, being actively recruited on underground hacking forums by an operator using the handle zeta88. The cross-platform threat represents a significant evolution in ransomware capabilities, offering attackers specialized encryption lockers for Windows, Linux, and ESXi systems coded in both Go and C […]

    The post New ‘Gentlemen’ RaaS Appears on Hacking Forums, Targeting Windows, Linux and ESXi appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has announced a significant security initiative that will fundamentally change how Chrome handles unsecured web connections.

    Beginning with Chrome 154’s release in October 2026, the browser will enable the “Always Use Secure Connections” feature by default, requiring users to approve access to any public website lacking HTTPS encryption before proceeding.

    This strategic shift represents a critical advancement in browser security, addressing a persistent vulnerability that attackers continue to exploit.

    Despite over a decade of progress toward universal HTTPS adoption, approximately 95 to 99 percent of Chrome navigations now use secure connections, leaving a small but significant percentage of traffic exposed to interception and manipulation attacks. The danger of unencrypted HTTP connections extends beyond mere data exposure.

    Understanding the Security Threat

    Attackers positioned between users and websites, known as man-in-the-middle actors, can hijack HTTP navigations entirely, redirecting users to malicious resources without detection.

    This method of attack has proven highly effective in real-world scenarios, with documented cases of commercial surveillance vendors and state-sponsored threat actors using HTTP interception to deliver zero-day exploits and compromise targeted devices.

    Unlike HTTPS sites that display “Not Secure” warnings, many HTTP sites immediately redirect to HTTPS, rendering the user completely unaware that an attack opportunity existed.

    setting warns users before accessing a site without HTTPS
    Setting warns users before accessing a site without HTTPS

    The Chrome Security team states that any unencrypted navigation, even at a small percentage, poses a potential risk to attackers.

     Because these threats are not theoretical but actively exploited through readily available interception tools, the security implications justify aggressive mitigation strategies.

    Google’s rollout strategy demonstrates careful consideration of user experience and the complexities of real-world deployment.

    In April 2026, Chrome 147 will enable the feature exclusively for the over one billion users who have voluntarily opted into Enhanced Safe Browsing protections.

    This initial phase provides a testing environment to validate warning frequency and user behavior before broader deployment.

    HTTPS adoption expressed as a percentage of main frame page loads
    HTTPS adoption expressed as a percentage of mainframe page loads

    Chrome 141 already conducted a pilot program, revealing that the median user encounters fewer than 1 warning per week, with even heavy internet users experiencing fewer than 3 warnings.

    This data contradicts assumptions about disruptive notification frequency, providing confidence for full-scale implementation.

    A particularly thoughtful aspect of this initiative involves differentiating between public and private sites.

    While Google will enforce strict HTTPS requirements for public websites, the implementation acknowledges that private sites, including local network devices and internal corporate systems, present reduced attack surfaces.

    When analyzing platform statistics excluding private site traffic, HTTPS adoption rates approach 97 to 99 percent across all systems, indicating that most remaining HTTP usage concentrates on private infrastructure where obtaining trusted HTTPS certificates remains technically complicated.

    “Always Use Secure Connections,” available at chrome://settings/security
    “Always Use Secure Connections,” available at chrome://settings/security

    Website developers and IT professionals should immediately enable the “Always Use Secure Connections” setting to identify potentially affected sites.

    Organizations managing Chrome deployments can reference Google’s comprehensive adoption guide to understand warning conditions and mitigation strategies.

    Many HTTP-using organizations simply haven’t prioritized HTTPS migration, while others depend on HTTP for local network device configuration, a scenario now addressable through Chrome’s new local network access permission system.

    Users retain full control, remaining able to disable warnings through settings if necessary, though Google strongly encourages adopting secure connections as standard practice moving forward.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Chrome to Alert Users “Always Use Secure Connections” While Opening Public HTTP Sites appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical vulnerability discovered in Google Messages for Wear OS has exposed millions of smartwatch users to a significant security risk. Identified as CVE-2025-12080, the flaw allows any installed application to send text messages on behalf of the user without requiring permissions, confirmation, or user interaction. Security researcher Gabriele Digregorio discovered the vulnerability in March […]

    The post Google Wear OS Flaw Lets Any App Send Texts on Behalf of Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Fraudulent investment platforms impersonating legitimate cryptocurrency and forex exchanges have emerged as the primary financial threat across Asia, with organized crime groups operating at unprecedented scale. These sophisticated scams leverage social engineering tactics to deceive victims into transferring funds to attacker-controlled systems, blurring the lines between legitimate trading and criminal enterprise. The threat extends far […]

    The post Cybercriminals Launch Flood of Fake Forex Platforms to Harvest Logins appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶