Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

GBHackers

20 articles

GBHackers general Microsoft Google 1d ago

Chinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits

A third Chinese threat actor has been linked to phishing campaigns that cloned trusted websites and chained Chrome and Windows zero-day exploits to deploy a ...

T1566

GBHackers → Details

GBHackers general SAP 1d ago

D-Link DIR-822A Router Vulnerability Scores CVSS 10.0 With Public PoC Available

D-Link has announced a critical stack-based buffer overflow vulnerability affecting the non-US DIR-822A router, identified as CVE-2026-86296. This vulnerabil...

1 IOC

GBHackers → Details

GBHackers general 2d ago

CISA Flags Actively Exploited Flaw in Zyxel GS1900 Switches

The U.S.

1 IOC

GBHackers → Details

GBHackers general GitHub 2d ago

Hackers Compromise 65 GitHub Repositories and Poison npm Package With Hidden Backdoor

Threat actors have compromised at least 65 public GitHub repositories in a software supply-chain campaign that abused npm trusted publishing to distribute a ...

GBHackers → Details

GBHackers general WordPress 2d ago

Hackers Exploit WordPress CVE-2026-63030 and CVE-2026-60137 to Steal Government Data

A suspected Chinese-speaking threat actor has exploited the critical WordPress “wp2shell” vulnerability chain to compromise government and small-business tar...

2 IOCs

GBHackers → Details

GBHackers general Microsoft 2d ago

Windows 11 26H1 Security Update Expands Secure Boot Certificate Protection

Microsoft has released the cumulative security update for September 2026 for Windows 11 version 26H1. This update expands the range of systems that can autom...

GBHackers → Details

GBHackers general Microsoft 2d ago

Microsoft to Disable SMS as Primary Entra ID Sign-In Method in 2027

Microsoft will turn off SMS as a primary sign-in method for Microsoft Entra ID workforce tenants on February 1, 2027, accelerating its transition to phishing...

T1566

GBHackers → Details

GBHackers general 2d ago

Vidar Uses Custom Bytecode Interpreter and ARX Stream Ciphers for Per-Build String Obfuscation

Vidar information stealer has introduced a lightweight custom virtual machine and per-build stream-cipher variations to conceal its embedded strings, raising...

T1027

GBHackers → Details

GBHackers general Amazon Palo Alto Networks GitHub 2d ago

AWS Detects and Quarantines Exposed IAM Credentials in Public GitHub Repositories

AWS can automatically quarantine exposed Identity and Access Management (IAM) access keys that appear in public GitHub repositories. This process involves ap...

GBHackers → Details

GBHackers general Microsoft 2d ago

One Stolen Active Directory File Can Expose Credentials for an Entire Windows Domain

A single stolen Active Directory database can turn a limited Windows intrusion into a domain-wide credential compromise. Threat actors that obtain the NTDS.

T1003

GBHackers → Details

GBHackers general Google 2d ago

Google Fined €403 Million for GDPR Violations Over Location Data Processing

Ireland’s Data Protection Commission (DPC) has imposed a €403 million administrative fine on Google Ireland Limited for breaching the EU General Data Protect...

GBHackers → Details

GBHackers general 2d ago

Meta’s Muse AI 0-Day Lets Hackers Hijack Dictation Traffic and Inject Malicious Prompts

A recent proof-of-concept (PoC) developed by security researcher Patrick Wardle reveals a local zero-day vulnerability in the Muse application. This vulnerab...

GBHackers → Details

GBHackers general 2d ago

NightEagle Uses BlueKeep and DCSync to Move Toward Active Directory Domain Controllers

NightEagle, an espionage-focused threat group also tracked as APT-Q-95, has expanded its operations from Asian targets to Russian organizations, using a laye...

GBHackers → Details

GBHackers general Oracle 2d ago

10 Malicious npm Packages Linked to Runtime Malware Campaign With Millions of Downloads

A sophisticated npm supply-chain campaign has been linked to 10 malicious JavaScript packages that collectively recorded millions of downloads while bypassin...

GBHackers → Details

GBHackers general Microsoft Fortinet 2d ago

PAYLOAD Ransomware Abuses Active Directory Group Policy to Disrupt Entire Windows Domain

A ransomware incident in which attackers used Active Directory Group Policy to disrupt operations without deploying a Windows encryptor or leaving malware ru...

GBHackers → Details

GBHackers general Microsoft Linux Intel 2d ago

New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools

A newly identified information-stealing campaign, tracked as Rapuncel, is exploiting a Microsoft-attested kernel driver to terminate up to 145 antivirus (AV)...

GBHackers → Details

GBHackers general Microsoft GitHub Intel 2d ago

BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates

A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence...

T1498

GBHackers → Details

GBHackers general 2d ago

North Korea’s Hangro VPN Certificate Exposes Internal Network and Russia-Linked Infrastructure

North Korea’s Hangro VPN and mail platform has deployed a new certificate hierarchy that exposes an apparent cross-border management environment spanning sys...

GBHackers → Details

GBHackers general Microsoft 2d ago

Hackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords

Threat actors are increasingly abusing Microsoft Teams’ external chat capabilities to impersonate corporate IT help desks. They trick employees into installi...

GBHackers → Details

GBHackers general Amazon F5 2d ago

New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches

Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached sensitive...

GBHackers → Details

«Previous page 1 2 3 4 5 ... 47 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA