GeoServer Pre-Auth SQL Injection Flaw Lets Attackers Gain Remote Code Execution
A newly disclosed SQL injection vulnerability in GeoServer allows remote attackers to execute operating system commands on backend PostgreSQL hosts under hig...
20 articles
A newly disclosed SQL injection vulnerability in GeoServer allows remote attackers to execute operating system commands on backend PostgreSQL hosts under hig...
The ChainDrop campaign has exposed a gap in modern software supply-chain defenses: malware no longer needs a durable npm publishing token or even an npm inst...
Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from Aug...
A newly identified Linux botnet dubbed Evooo1Bot is targeting vulnerable internet-facing routers, edge appliances, cameras, and enterprise systems, combining...
A newly surfaced criminal AI service named MessiahGPT is being marketed on BreachForums as an unrestricted offensive model capable of generating ransomware, ...
A compact, custom-built Windows backdoor that impersonates Realtek software, persists through WMI, and conceals its command-and-control address inside what a...
Shell has launched a cybersecurity investigation following claims by the Cl0p ransomware operation that it stole 89GB of corporate information from the multi...
Defused, a threat intelligence provider, reported exploitation attempts targeting CVE-2026-58231, a critical unauthenticated remote code execution vulnerabil...
A threat actor using the alias “TheHatman” is allegedly selling large corporate employee directories that were allegedly extracted from Microsoft Azure and E...
Microsoft will make passkeys the default authentication experience in Entra ID beginning September 1, 2026, and will fully retire its native SMS and voice mu...
A newly disclosed universal deserialization gadget chain shows how a single unsafe Marshal.load operation can reportedly produce remote command execution in ...
A newly disclosed Windows attack technique, dubbed “Download More RAM,” can undermine Virtualization-Based Security (VBS), bypass Hypervisor-Protected Code I...
Microsoft is reshaping its consumer and productivity AI strategy with a major update to its Copilot application, merging personal chat histories and generate...
Selidan, USA, August 14th, 2026, CyberNewswire New report examines suspicious Reddit activity, coordinated YouTube content and BBB Scam Tracker entries influ...
Four incidents involving OpenAI, Anthropic, Meta and the UK AI Security Institute (AISI) describe AI agents reaching systems belonging to other organizations...
A newly disclosed, unpatched SQL injection vulnerability in GeoServer is currently being actively tested across the internet. Researchers have issued warning...
The Dysphoria botnet has expanded into a major Internet of Things threat, with a new Shadowserver Special Report identifying approximately 296,000 compromise...
A newly analyzed DarkCrystal RAT (DCRat) campaign shows how threat actors are turning an apparently harmless SVG attachment into a full malware-delivery mech...
A growing underground market is turning mature malware-evasion techniques into subscription products. An analysis of 24 active crypting-service vendors shows...
Security researchers have introduced a new technique called “Bring Your Own EDR” (BYOEDR) that exploits legitimate SentinelOne components to bypass Windows P...