Tag: cyber
-
Weekly Cybersecurity Newsletter Top 50 Biggest Cybersecurity Stories SonicWall Zero-Day, Cl0p Windchill Attack, AI-Weaponized Threats, Data Breaches More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from July 2024, 2026. It was a heavy week: Cl0p turned internet-exposed Windchill servers into a global data-theft campaign, attackers rode SonicWall SMA zero-days to root, a Bluetooth flaw put 2 million cars at […]…
-
Rep. Bacon warns CISA cuts weaken U.S. cyber defenses
First seen on scworld.com Jump to article: www.scworld.com/analysis/rep-bacon-warns-cisa-cuts-weaken-u-s-cyber-defenses
-
Hackers Use Stealer Logs to Bypass MFA and Launch Ransomware Attacks
Infostealer malware has now become the invisible thread linking petty credential theft to full-blown ransomware campaigns. Attackers no longer bother forcing their way through firewalls when infostealers have already unlocked the front door for them. Documented by DarkOwl, a stealer log archive generated by infostealer malware that silently harvests browser-saved passwords, session cookies, cryptocurrency wallet data,…
-
Cyberresilienz im Zeitalter von KI: Wie sicher ist das IoT wirklich?
Die Bedrohungslage im Bereich der Cybersicherheit verändert sich rasant. Das Bundesamt für Sicherheit in der Informationstechnik (BSI) warnt aktuell, dass künstliche Intelligenz die Geschwindigkeit, Skalierung und Automatisierung von Cyberangriffen erheblich erhöht und Unternehmen ihre Sicherheitsstrategien entsprechend anpassen müssen [1]. Vor diesem Hintergrund gewinnt der Cyber Resilience Act (CRA) der Europäischen Union zusätzlich an Bedeutung und……
-
Google Launches Unified Cryptonym-Based Naming System for Threat Actors
Google Threat Intelligence Group (GTIG) has introduced a unified cryptonym-based naming system for cyber threat actors, aiming to simplify attribution, improve analyst workflows, and eliminate inconsistencies between legacy tracking conventions used across Google’s security teams. The initiative follows the integration of Mandiant and Google’s Threat Analysis Group (TAG) into GTIG. Before the merger, both organizations…
-
Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials
Tags: business, communications, credentials, crypto, cyber, data, email, infection, malware, phishing, powershellA sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials, cookies, payment data, and cryptocurrency wallet information from victims. Documented by Seqrite, the campaign uses two distinct phishing themes that both lead to the same infection chain. One email impersonates UPS Forwarding Hub, referencing fake…
-
Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Hide Attacks
Six federal agencies have updated a joint advisory warning that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. critical infrastructure, manipulating human-machine interface (HMI) displays so operators cannot visually detect the intrusion. The advisory, first issued in April 2026 and revised on July 22, 2026, is cosigned…
-
US House Votes to Extend Cyber Sharing Law for 10 Years
Lawmakers Advance 10-Year Renewal of Key Cyber Law, Setting Up Looming Senate Fight. The U.S. House of Representatives passed a fiscal year 2027 defense authorization bill with a provision extending the Cybersecurity Information Sharing Act of 2015 through 2036. The decade-long renewal faces an uphill climb in the Senate. First seen on govinfosecurity.com Jump to…
-
Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry
Tags: cyberThe new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government. First seen on therecord.media Jump to article: therecord.media/andy-burnham-liz-lloyd-cyber-policy-uk
-
Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers
Tel Aviv, Israel, July 24th, 2026, CyberNewswire One week after disclosing that Anthropic’s Claude Tag Slack integration could be driven by plain >>@Claude<< text, Tego AI today published a second piece of research on the Claude ecosystem. This one focuses on Claude Code, Anthropic's agentic command-line coding tool. Cloning an ordinary repository and starting Claude…
-
Foxit PDF Reader Flaw Lets Local Attackers Gain SYSTEM Privileges via DLL Sideloading
A recently disclosed vulnerability in Foxit PDF Reader may allow a local attacker with existing code execution to elevate their privileges to NT AUTHORITY\SYSTEM. This issue, tracked as CVE-2026-57239, affects Foxit PDF Reader installations prior to version 2026.2 and arises from the insecure handling of an updater workflow triggered by a user-writable file in the…
-
Cl0p Targets Internet-Exposed Windchill Servers in Global Engineering Data-Theft Campaign
Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM deployments in a global data-theft campaign targeting high-value engineering environments. Observed post-exploitation activity includes filesystem enumeration via files such as “flst.txt,” followed by staging and exfiltration of sensitive engineering and product design data. This chaining enables unauthenticated remote code execution, allowing attackers to deploy…
-
Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos
An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, admitted to charges including aggravated identity theft, wire fraud, computer fraud, conspiracy to commit computer fraud, and…
-
GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments
At a glance Malware family GoSerpent backdoor, plus McMx, Stowaway, ThumbcacheService, and TmcLoader/TmcPayload Threat actor Unconfirmed. Kaspersky notes First seen on securityonline.info Jump to article: securityonline.info/goserpent-backdoor/
-
Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Hunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence. Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a live cyber-espionage operation. Instead of recovering malware after the fact, the team found exposed staging servers…
-
SectopRAT Gives Attackers Remote Access to Passwords, Credit Cards, Cookies and Corporate Files
SectopRAT is at the center of a highly targeted malvertising campaign abusing Anthropic’s Claude platform to deliver a stealthy, HVNC”‘enabled RAT that gives attackers deep, persistent access to victims’ passwords, credit cards, cookies and corporate files. The artifact masqueraded as a genuine Claude Desktop installer but redirected victims to claude.ai.download-app[.]us and then to downloading-api.it[.]com/html/claude/win, where…
-
Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From Visitors
Researchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaign First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hotel-wifi-dns-poisoning/
-
Golden Chickens Launches Four Modular Malware Families to Steal Chrome Credentials and Hijack Browser Sessions
Golden Chickens, tracked as TAG-195 and also known as Venom Spider, has launched four new modular malware families designed to enhance credential theft, browser session hijacking, and post-exploitation flexibility. The newly identified families TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator mark a clear architectural evolution in the group’s malware-as-a-service (MaaS) ecosystem, signaling a shift…
-
SourTrade Browser-Assembled Malware Defeats Hash-Based Detection by Design
SourTrade turns the browser itself into a malware build system, deliberately sidestepping the industry’s reliance on hash-based file fingerprints and traditional network-centric detection. SourTrade has been active since late 2024, abusing programmatic ads to reach retail traders and crypto investors in 12 geographies across APAC, LATAM, Africa, and Western markets, including Japan, Thailand, South Korea,…
-
Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code
Tags: apache, authentication, cve, cyber, flaw, injection, remote-code-execution, service, sql, vulnerabilityApache Syncope has released versions 4.1.24.1, 4.1.24.1.2, and 4.0.74.0.7 to address six security vulnerabilities affecting the 4.1, 4.0, and 3.0 release branches. These vulnerabilities include a self-service privilege escalation bug, multiple post-authentication remote code execution (RCE) pathways, authenticated server-side request forgery (SSRF), and SQL injection issues. Apache Syncope Flaws CVE-2026-62183 affects deployments that utilize the…
-
Hotel Wi-Fi DNS Poisoning Attacks Hijack Microsoft 365 Accounts Without Phishing
Adversaries are silently hijacking Microsoft 365 accounts by compromising hotel and conference-center Wi-Fi gateways and poisoning DNS no phishing emails, malicious attachments, or endpoint malware required. ReliaQuest assesses that the tradecraft closely mirrors prior APT28-linked router campaigns, extending them into captive-portal infrastructure used by traveling corporate staff. Since at least June 2026, threat actors have…
-
Google Chrome 150 Update Fixes Four High-Severity Security Vulnerabilities
Google Chrome version 150.0.7871.186 has addressed four high-severity vulnerabilities that affect core browser components, including Codecs, WebMCP, Blink, and Input. While Google has not reported any evidence indicating that these vulnerabilities are actively being exploited, the company has restricted access to technical bug reports and related information until a majority of Chrome users receive the…
-
Lampion Malware Targets Portuguese Users With Multistage Phishing and 750MB RAT Payload
A highly targeted Lampion malware campaign abusing localized phishing lures to compromise users in Portugal. The activity reflects a continued evolution of the Brazilian-origin banking trojan, first documented in 2019, which has consistently focused on Portuguese-speaking victims rather than domestic Brazilian targets. In the latest campaign, attackers leverage convincing financial-themed phishing emails masquerading as routine…
-
Claude Cowork Sandbox Escape Flaw Lets Attackers Access SSH Keys and Cloud Credentials
A newly revealed sandbox escape vulnerability affecting Anthropic’s Claude Cowork could allow untrusted content processed by the AI agent to access sensitive files on a macOS host. This includes SSH private keys, cloud credentials, and other data that are available to the logged-in user. Security researcher Oren Yomtov from Accomplish has named this attack path…
-
Top 10 Best 24/7 Security Monitoring Companies in 2026
A comprehensive and proactive security posture is non-negotiable for organizations in 2026. With a rapidly evolving threat landscape and a global shortage of cybersecurity talent, relying on an internal team alone to provide round-the-clock protection is often unfeasible. 24/7 security monitoring companies fill this critical gap by serving as an extension of an organization’s security…
-
Attackers Abuse Microsoft Teams to Impersonate IT Support and Steal Corporate Access
Attackers are increasingly abusing Microsoft Teams to impersonate internal IT support and trick employees into handing over remote access and corporate credentials, even as traditional email phishing volumes tied to major platforms like Tycoon2FA decline. Microsoft’s recent email threat landscape data for Q2 2026 shows a sharp downstream impact from the March disruption of the…
-
Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day to Steal 90 Days of Emails
Tags: advisory, cyber, cybersecurity, defense, email, espionage, exploit, government, group, hacker, russia, technology, threat, vulnerability, zero-dayRussian state-supported threat actors, known as LAUNDRY BEAR, have exploited a zero-day vulnerability in the Zimbra Collaboration Suite to steal up to 909,090 days’ worth of emails from targeted organizations across Western countries. A joint cybersecurity advisory, AA26-204A, issued on July 23, 2026, warns that this espionage-focused group has targeted government, defense, energy, technology, education,…
-
Hackers Weaponize Notepad++ Plugins to Silently Infect Windows Systems
CERT-UA has issued a warning regarding the UAC-0099 threat cluster, which has revised its malware delivery method by exploiting the legitimate Notepad++ application to load a malicious DLL disguised as a plugin. This campaign, observed since mid-summer 2026, introduces two newly identified tools, LUNCHPOKE and BURNYBEAR, along with an updated MATCHBOIL.V2 loader. This activity highlights…

