Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

GBHackers

20 articles

GBHackers general Microsoft 1d ago

Microsoft to Disable SMS as Primary Entra ID Sign-In Method in 2027

Microsoft will turn off SMS as a primary sign-in method for Microsoft Entra ID workforce tenants on February 1, 2027, accelerating its transition to phishing...

T1566

GBHackers → Details

GBHackers general 1d ago

Vidar Uses Custom Bytecode Interpreter and ARX Stream Ciphers for Per-Build String Obfuscation

Vidar information stealer has introduced a lightweight custom virtual machine and per-build stream-cipher variations to conceal its embedded strings, raising...

T1027

GBHackers → Details

GBHackers general Amazon Palo Alto Networks GitHub 2d ago

AWS Detects and Quarantines Exposed IAM Credentials in Public GitHub Repositories

AWS can automatically quarantine exposed Identity and Access Management (IAM) access keys that appear in public GitHub repositories. This process involves ap...

GBHackers → Details

GBHackers general Microsoft 2d ago

One Stolen Active Directory File Can Expose Credentials for an Entire Windows Domain

A single stolen Active Directory database can turn a limited Windows intrusion into a domain-wide credential compromise. Threat actors that obtain the NTDS.

T1003

GBHackers → Details

GBHackers general Google 2d ago

Google Fined €403 Million for GDPR Violations Over Location Data Processing

Ireland’s Data Protection Commission (DPC) has imposed a €403 million administrative fine on Google Ireland Limited for breaching the EU General Data Protect...

GBHackers → Details

GBHackers general 2d ago

Meta’s Muse AI 0-Day Lets Hackers Hijack Dictation Traffic and Inject Malicious Prompts

A recent proof-of-concept (PoC) developed by security researcher Patrick Wardle reveals a local zero-day vulnerability in the Muse application. This vulnerab...

GBHackers → Details

GBHackers general 2d ago

NightEagle Uses BlueKeep and DCSync to Move Toward Active Directory Domain Controllers

NightEagle, an espionage-focused threat group also tracked as APT-Q-95, has expanded its operations from Asian targets to Russian organizations, using a laye...

GBHackers → Details

GBHackers general Oracle 2d ago

10 Malicious npm Packages Linked to Runtime Malware Campaign With Millions of Downloads

A sophisticated npm supply-chain campaign has been linked to 10 malicious JavaScript packages that collectively recorded millions of downloads while bypassin...

GBHackers → Details

GBHackers general Microsoft Fortinet 2d ago

PAYLOAD Ransomware Abuses Active Directory Group Policy to Disrupt Entire Windows Domain

A ransomware incident in which attackers used Active Directory Group Policy to disrupt operations without deploying a Windows encryptor or leaving malware ru...

GBHackers → Details

GBHackers general Microsoft Linux Intel 2d ago

New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools

A newly identified information-stealing campaign, tracked as Rapuncel, is exploiting a Microsoft-attested kernel driver to terminate up to 145 antivirus (AV)...

GBHackers → Details

GBHackers general Microsoft GitHub Intel 2d ago

BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates

A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence...

T1498

GBHackers → Details

GBHackers general 2d ago

North Korea’s Hangro VPN Certificate Exposes Internal Network and Russia-Linked Infrastructure

North Korea’s Hangro VPN and mail platform has deployed a new certificate hierarchy that exposes an apparent cross-border management environment spanning sys...

GBHackers → Details

GBHackers general Microsoft 2d ago

Hackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords

Threat actors are increasingly abusing Microsoft Teams’ external chat capabilities to impersonate corporate IT help desks. They trick employees into installi...

GBHackers → Details

GBHackers general Amazon F5 2d ago

New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches

Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached sensitive...

GBHackers → Details

GBHackers general Apple SentinelOne 2d ago

Hackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS Backdoors

North Korea-linked threat actor TraderTraitor has expanded its developer-focused intrusion activity beyond cryptocurrency targets, using weaponized Terraform...

GBHackers → Details

GBHackers general Amazon GitHub 2d ago

HEIF Heist Image Flaws Let Attackers Gain RCE Across Meta, Slack and GitHub Enterprise

“HEIF Heist,” a broad class of image-processing attack paths that could allow threat actors to turn malicious HEIF, HEIC, and AVIF uploads into remote code e...

T1190

GBHackers → Details

GBHackers general Microsoft 2d ago

New Remus Infostealer Steals OpenAI and Anthropic API Tokens, Passwords and Crypto Wallets

A newly tracked Windows infostealer dubbed Remus is expanding its credential-theft playbook by targeting API tokens and local usage data tied to AI platforms...

GBHackers → Details

GBHackers general Amazon 2d ago

Exim Mail Server Hit by 4 Security Flaws Enabling SMTP Smuggling and Heap Corruption

Exim maintainers have released version 4.100.

GBHackers → Details

GBHackers general 2d ago

EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials

A newly uncovered EtherHiding campaign has turned the Polygon blockchain into a resilient command-and-control mechanism, allowing operators to rotate malware...

T1059.001

GBHackers → Details

GBHackers general Microsoft Google 3d ago

BragJack Attack Hijacks AI Assistants in 5 Popular Browsers With Zero Clicks

Security researchers have revealed a zero-click attack technique known as BragJack, which could enable a malicious browser extension to hijack built-in AI as...

GBHackers → Details

«Previous page 1 2 3 4 5 ... 47 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA