Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

GBHackers

20 articles

GBHackers general 8h ago

NightEagle Uses BlueKeep and DCSync to Move Toward Active Directory Domain Controllers

NightEagle, an espionage-focused threat group also tracked as APT-Q-95, has expanded its operations from Asian targets to Russian organizations, using a laye...

GBHackers → Details

GBHackers general Oracle 8h ago

10 Malicious npm Packages Linked to Runtime Malware Campaign With Millions of Downloads

A sophisticated npm supply-chain campaign has been linked to 10 malicious JavaScript packages that collectively recorded millions of downloads while bypassin...

GBHackers → Details

GBHackers general Microsoft Fortinet 9h ago

PAYLOAD Ransomware Abuses Active Directory Group Policy to Disrupt Entire Windows Domain

A ransomware incident in which attackers used Active Directory Group Policy to disrupt operations without deploying a Windows encryptor or leaving malware ru...

GBHackers → Details

GBHackers general Microsoft Linux Intel 9h ago

New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools

A newly identified information-stealing campaign, tracked as Rapuncel, is exploiting a Microsoft-attested kernel driver to terminate up to 145 antivirus (AV)...

GBHackers → Details

GBHackers general Microsoft GitHub Intel 10h ago

BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates

A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence...

T1498

GBHackers → Details

GBHackers general 11h ago

North Korea’s Hangro VPN Certificate Exposes Internal Network and Russia-Linked Infrastructure

North Korea’s Hangro VPN and mail platform has deployed a new certificate hierarchy that exposes an apparent cross-border management environment spanning sys...

GBHackers → Details

GBHackers general Microsoft 12h ago

Hackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords

Threat actors are increasingly abusing Microsoft Teams’ external chat capabilities to impersonate corporate IT help desks. They trick employees into installi...

GBHackers → Details

GBHackers general Amazon F5 12h ago

New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches

Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached sensitive...

GBHackers → Details

GBHackers general Apple SentinelOne 12h ago

Hackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS Backdoors

North Korea-linked threat actor TraderTraitor has expanded its developer-focused intrusion activity beyond cryptocurrency targets, using weaponized Terraform...

GBHackers → Details

GBHackers general Amazon GitHub 13h ago

HEIF Heist Image Flaws Let Attackers Gain RCE Across Meta, Slack and GitHub Enterprise

“HEIF Heist,” a broad class of image-processing attack paths that could allow threat actors to turn malicious HEIF, HEIC, and AVIF uploads into remote code e...

T1190

GBHackers → Details

GBHackers general Microsoft 14h ago

New Remus Infostealer Steals OpenAI and Anthropic API Tokens, Passwords and Crypto Wallets

A newly tracked Windows infostealer dubbed Remus is expanding its credential-theft playbook by targeting API tokens and local usage data tied to AI platforms...

GBHackers → Details

GBHackers general Amazon 14h ago

Exim Mail Server Hit by 4 Security Flaws Enabling SMTP Smuggling and Heap Corruption

Exim maintainers have released version 4.100.

GBHackers → Details

GBHackers general 15h ago

EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials

A newly uncovered EtherHiding campaign has turned the Polygon blockchain into a resilient command-and-control mechanism, allowing operators to rotate malware...

T1059.001

GBHackers → Details

GBHackers general Microsoft Google 15h ago

BragJack Attack Hijacks AI Assistants in 5 Popular Browsers With Zero Clicks

Security researchers have revealed a zero-click attack technique known as BragJack, which could enable a malicious browser extension to hijack built-in AI as...

GBHackers → Details

GBHackers general Amazon GitHub 16h ago

Hackers Exploit TanStack Supply Chain Attack to Steal 170 Private CrowdSec Repositories

Threat actors linked to the TanStack npm supply chain compromise allegedly used a stolen GitHub OAuth token to clone about 170 private CrowdSec repositories,...

T1195

GBHackers → Details

GBHackers general 16h ago

Hackers Abuse Critical cPanel Authentication Bypass to Compromise Hosting Servers

Threat actors rapidly exploited a critical authentication bypass in cPanel and WHM to compromise internet-facing hosting servers, with Japanese telemetry dat...

T1556 1 IOC

GBHackers → Details

GBHackers general WordPress 16h ago

Click2Shell WordPress Flaw Lets Hackers Execute PHP Code and Take Over Websites

A recently disclosed WordPress vulnerability, known as Click2Shell, could let attackers execute remote PHP code on vulnerable sites after convincing a logged...

GBHackers → Details

GBHackers general Google Intel 2d ago

Google Gemini AI Hacked 3 Real Companies After Cybersecurity Test Exposed It to Internet

Google has confirmed that its Gemini artificial intelligence model accidentally accessed protected systems belonging to three real companies during a cyberse...

GBHackers → Details

GBHackers general 2d ago

North Korean WaterPlum Hackers Target IT Professionals With Fake Job Interviews to Steal Crypto

North Korean threat actors, known as WaterPlum (also referred to as Contagious Interview), have infected at least 30,000 devices in over 100 countries by lur...

GBHackers → Details

GBHackers general Google Intel 2d ago

AI-Powered RatHat Android Trojan Steals Bank Credentials, PINs and MFA Codes

Researchers have identified a new Android banking Trojan called RatHat that utilizes artificial intelligence to automate device compromise and steal financia...

GBHackers → Details

1 2 3 ... 45 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA