Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

GBHackers

20 articles

GBHackers general Aug 29

Hackers Compromise TanStack Query npm Package to Steal Developer Credentials

A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen, an npm package that generates type-safe TanStack Query hooks. Ai...

T1598

GBHackers → Details

GBHackers general Aug 29

Critical Gogs Flaw Enables Remote Code Execution Through Path Traversal

A critical vulnerability in Gogs, the self-hosted Git service, could allow authenticated attackers to execute commands on the server by abusing path traversa...

T1190 1 IOC

GBHackers → Details

GBHackers general Microsoft Cloudflare Aug 29

Hackers Use Fake Cloudflare CAPTCHA to Deploy TerminalFix Reverse Tunnel

A newly documented TerminalFix campaign is using fake Cloudflare CAPTCHA prompts to trick users into manually executing malicious PowerShell commands, ultima...

T1059.001

GBHackers → Details

GBHackers general Proofpoint Aug 29

Chinese Hackers Deploy PackClient RAT via Tax-Themed Phishing Attacks to Steal Data

A Chinese-speaking threat actor tracked as TA4922 is deploying the PackClient remote access trojan via tax-themed phishing campaigns targeting organizations ...

T1566

GBHackers → Details

GBHackers general Aug 28

Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure

Attackers are increasingly treating AI infrastructure as a high-value cloud entry point, exploiting exposed Model Context Protocol (MCP) services, agent fram...

T1078 T1592

GBHackers → Details

GBHackers general Aug 28

700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution

OpenAI’s ExploitGym evaluation environment reportedly became the site of a large-scale, unsanctioned multi-agent campaign after hundreds of models found ways...

T1190 T1598

GBHackers → Details

GBHackers general Oracle Aug 28

Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit

A newly analyzed phishing operation is using server-side polymorphism to generate a distinct credential-harvesting page for virtually every request, undermin...

T1566

GBHackers → Details

GBHackers general WordPress Aug 28

Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover

A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin, which could allow unauthenticated attackers to...

T1556 1 IOC

GBHackers → Details

GBHackers general Amazon ServiceNow Aug 28

ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection

ServiceNow has issued security advisories for four vulnerabilities, including critical flaws in its AI platform. These vulnerabilities could allow unauthenti...

4 IOCs

GBHackers → Details

GBHackers general Aug 28

Suspected Iran-Linked Cyberattack Knocks UK Power Plant Offline for Four Days

A cyber incident reportedly forced a small UK power generation facility offline for about four days in July 2026. While the activity has been linked in repor...

T1598

GBHackers → Details

GBHackers general Aug 28

Researchers Execute Code Inside Fortune 500 Companies via AI Agent llms.txt Files

Security researchers have shown that AI coding agents can be manipulated into installing attacker-controlled packages by following instructions found in orga...

GBHackers → Details

GBHackers general Microsoft Aug 28

BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE Malware

Russian state-linked threat actor BlueDelta has launched a renewed espionage campaign against defense manufacturing, government, and diplomatic organizations...

GBHackers → Details

GBHackers general Amazon Aug 28

Unitree G1 Humanoid Robot Flaws Allow Unauthenticated Root RCE Over Bluetooth

Security researcher Boschko has revealed two vulnerabilities in Unitree’s G1 humanoid robot that can be exploited to achieve unauthenticated remote code exec...

T1190

GBHackers → Details

GBHackers general Aug 28

TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation

A newly emerged ransomware-as-a-service operation named TITAN is advertising an AI-driven extortion platform that it claims can autonomously classify stolen ...

T1588

GBHackers → Details

GBHackers general Aug 28

Prompt Injection Attack Hijacks Claude Code Opus 5 Auto Mode to Execute Malicious Code

A recent demonstration of prompt-injection research has revealed that Claude Code Opus 5, when running in its default Auto Mode, can be manipulated to execut...

GBHackers → Details

GBHackers general Microsoft WordPress Aug 28

Hundreds of WordPress Sites Hijacked to Show Fake reCAPTCHA and Steal Windows Passwords.

Hundreds of compromised WordPress websites are being used in a sophisticated malware-delivery campaign that combines browser persistence, blockchain-hosted p...

GBHackers → Details

GBHackers general Rapid7 Aug 28

Hackers Can Buy Corporate Executives’ Social Security Numbers for Just 25 Cents

Corporate executives’ Social Security numbers (SSNs) are being sold on dark web identity marketplaces for as little as $0.25 per record.

T1598

GBHackers → Details

GBHackers general Microsoft Aug 28

Go Loader Uses Anti-Sandbox Checks and SNOWLIGHT to Execute Fileless VShell RAT in Memory

A Windows malware campaign disguised as a graduate-school resume has been observed delivering the SNOWLIGHT stager and a fileless VShell remote-access trojan...

GBHackers → Details

GBHackers general Intel Aug 28

Leaked University Files Reveal How Russia Trains Hackers for Military Cyber Operations

A cache of leaked internal records has exposed what appears to be a structured Russian military cyber-operator pipeline embedded inside Bauman Moscow State T...

GBHackers → Details

GBHackers general Aug 28

Hackers Use Ethereum Smart Contracts to Keep New GoCaracal Malware Connected

Dark Caracal-linked operators are using Ethereum smart contracts as a resilient fallback mechanism for a newly identified Go-based malware framework called G...

GBHackers → Details

«Previous page 1 ... 17 18 19 20 21 ... 45 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA