Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

GBHackers

20 articles

GBHackers general Apple Intel Aug 10

Apple Private Cloud Compute Path Traversal Flaw Lets Attackers Write Files as Root

Security researcher Drinor Selmanaj has disclosed a path traversal vulnerability (CVE-2026-20685) in Apple’s Private Cloud Compute (PCC) that allows a privil...

1 IOC

GBHackers → Details

GBHackers general Aug 10

Ransomware Attackers Compromise Multiple Employees Inside the Same Company

Ransomware operations are increasingly targeting the people behind critical business processes, not just privileged IT administrators. Over a one-month obser...

GBHackers → Details

GBHackers general Aug 10

Claude Opus 5 Most Resistant to Indirect Prompt Injection Attacks, With Just 2% Success Rate

Anthropic’s Claude Opus 5 has significantly reduced the likelihood of a successful indirect prompt injection (IPI) attack, bringing it down to 2% over 15 att...

GBHackers → Details

GBHackers general Microsoft Intel Aug 10

North Korean Hackers Explore AI Transcription for Stolen Calls and Meetings

North Korea-linked Kimsuky operators are expanding their artificial intelligence capabilities, with newly observed evidence showing experimentation with loca...

T1566

GBHackers → Details

GBHackers general Aug 10

Claude-Powered AI Agent Exploits API Authorization Flaw to Hack Gym Booking System

An Australian AI agent powered by Anthropic’s Claude reportedly exploited an authorization flaw in a gym booking platform, allowing it to book classes outsid...

GBHackers → Details

GBHackers general Microsoft Aug 10

Payroll Pirates Abuse Microsoft Graph to Find HR and Finance Staff After Account Compromise

A widespread phishing operation that compromises Microsoft 365 accounts through adversary-in-the-middle (AiTM) infrastructure, then uses Microsoft Graph to i...

T1566 T1557

GBHackers → Details

GBHackers general Apple Aug 10

Claude Code Child Process Can Read Its Own OAuth Token From macOS Keychain

A macOS Keychain implementation weakness in Anthropic’s Claude Code CLI could allow any process running as the logged-in user including a Claude Code-spawned...

T1555

GBHackers → Details

GBHackers general Aug 10

Metabase 0-Day Flaw Exploited in Attack to Inject Arbitrary SQL and Steal Database Credentials

Metabase has reported a critical security incident involving a zero-day vulnerability that is actively being exploited. This vulnerability affects self-hoste...

GBHackers → Details

GBHackers general Aug 10

New CSS Bomb Attacks Let Hackers Steal Passwords and Tokens From Webmail Users

Security researcher Gareth Heyes has revealed techniques for webmail attacks that exploit HTML and CSS, the technologies used to format emails, to manipulate...

GBHackers → Details

GBHackers general Aug 10

Levi Strauss Hit by Cyberattack, Hackers Use Social Engineering to Steal Corporate Data

Levi Strauss & Co. has reported a cybersecurity incident in which an unauthorized third party used social engineering techniques to compromise three employee...

T1204 T1041

GBHackers → Details

GBHackers general Fortinet Aug 10

The Best Intrusion Detection & Prevention (IDS/IPS) Tools, Compared and Priced (2026)

This market runs from $0 to seven figures, and the free options power half the paid ones — so price comparisons here reward honesty.

GBHackers → Details

GBHackers general Google Aug 10

Cybersecurity Newsletter Weekly – Top 50 Biggest Cybersecurity Stories – $70M Bitcoin Heist,Google Passkey Theft, Copilot CEO Fraud,Chrome 151 & Claude Exploits & More

Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from Aug...

GBHackers → Details

GBHackers general WordPress Aug 8

WordPress XSS2Shell Flaw Enables Attackers to Achieve Remote Code Execution

WordPress has patched a high-severity vulnerability, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that begins as an unauthenticated cross-site scriptin...

T1190 1 IOC

GBHackers → Details

GBHackers general Aug 8

Bugtraq Is Back: The Original Full Disclosure Mailing List Is Live Again

Sophia Antipolis, France, August 7th, 2026, CyberNewswire At DEF CON 34 in Las Vegas, security researcher Jonathan Brossard, known in the community as endraz...

GBHackers → Details

GBHackers general Linux Docker Aug 8

18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Root and Escape Containers

SCTPhantom, tracked as CVE-2026-64564, is a high-severity Linux kernel use-after-free vulnerability in the Stream Control Transmission Protocol (SCTP) Dynami...

T1592 1 IOC

GBHackers → Details

GBHackers general Microsoft Apple Zoom Aug 8

Fake Zoom Installer Uses .NET Downloader to Deploy Overlord RAT on macOS

A cross-platform malware campaign that disguises itself as a legitimate Zoom installer to deploy Overlord, an open-source remote access trojan (RAT), on both...

GBHackers → Details

GBHackers general Apple Aug 8

Critical macOS RCE Vulnerability Allows Attackers to Gain Root Access Without Password

Apple has shipped emergency macOS updates to close a critical vulnerability in Screen Sharing, tracked as CVE-2026-65400, which allows unauthenticated remote...

1 IOC

GBHackers → Details

GBHackers general Aug 8

Russian Hackers Use AI Slopsquatting to Publish 700+ Malicious npm Packages

A large-scale supply chain attack has hit the npm registry, with a suspected Russian threat actor publishing more than 700 malicious packages in just 48 hour...

T1195

GBHackers → Details

GBHackers general Microsoft Intel Aug 8

Storm-1175 Launches StormEncryptor Ransomware Attacks Using N-able Security Flaw

Microsoft Threat Intelligence has identified a new ransomware campaign attributed to the financially motivated threat actor Storm-1175 that began deploying a...

GBHackers → Details

GBHackers general Microsoft Aug 7

Windows Hello Key Abuse Lets Attackers Access Microsoft Entra ID Accounts

Security researcher has disclosed a technique involving Windows Hello for Business (WHFB) that could allow attackers with access to an active Windows user se...

GBHackers → Details

«Previous page 1 ... 33 34 35 36 37 ... 47 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA