Skip to content

00110010.com

  • Windows AFD.sys Zero-Day Exploited by Lazarus Hackers to Gain SYSTEM Access

    ·

    Cyber Security News

    Lazarus has expanded its long-running Operation Dream Job campaign by exploiting a Windows zero-day vulnerability that grants attackers SYSTEM-level access and helps neutralize endpoint visibility. This DPRK-linked threat actor is specifically targeting defense, aerospace, and aviation organizations worldwide, with recent activity impacting entities in Europe and India. Check Point Research identified the flaw as CVE-2026-68820, […]

    The post Windows AFD.sys Zero-Day Exploited by Lazarus Hackers to Gain SYSTEM Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

    ·

    SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation. “SAP Commerce Cloud allows an

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

    ·

    The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePlanet. RoguePlanet has been described

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Fake Corporate VPN Test Creates Scheduled Task and Downloads Malware on Windows

    ·

    cyber security, Cyber Security News, Malware, VPN

    An advanced recruitment-themed intrusion campaign attributed to UAC-0145, a cluster that includes subcluster UAC-0002, also tracked as Sandworm, APT44 and Seashell Blizzard. The activity, observed since at least May 2026, begins on job-search platforms. Operators review a candidate’s résumé, contact the individual while impersonating an IT company such as ATLAS Business Group, and move the […]

    The post Fake Corporate VPN Test Creates Scheduled Task and Downloads Malware on Windows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

    ·

    Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker to trigger

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft Patch Tuesday Update August 2026 Fixes Actively Exploited Windows Zero-Day

    ·

    cyber security, Cyber Security News, Microsoft

    Microsoft’s August 2026 Patch Tuesday released fixes for hundreds of vulnerabilities across various products, including Windows, Office, SharePoint, Azure, .NET, PowerShell, Visual Studio Code, and other enterprise solutions. A total of 394 distinct flaws were documented in this release. Among these vulnerabilities, three zero-day issues are particularly noteworthy. One of these is a Windows elevation-of-privilege […]

    The post Microsoft Patch Tuesday Update August 2026 Fixes Actively Exploited Windows Zero-Day appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • DEF CON Attendees Allegedly Jam Plane Wi‑Fi, Launch ‘Evil Twin’ Phishing Attack

    ·

    cyber security, Cyber Security News, WI-Fi

    A Delta Air Lines flight returning travelers from Las Vegas reportedly became the site of a high-altitude Wi-Fi phishing incident when someone on board allegedly disrupted the aircraft’s official internet service and broadcast a fraudulent wireless network. The incident occurred on Monday aboard Delta Flight 591, a Boeing 757 flying from Las Vegas Harry Reid […]

    The post DEF CON Attendees Allegedly Jam Plane Wi‑Fi, Launch ‘Evil Twin’ Phishing Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Zoom Zero-Click ‘Zoomsday’ Flaw Lets Meeting Participants Execute Code on Other Users’ Devices

    ·

    CVE/vulnerability, cyber security, Cyber Security News, Vulnerabilities

    Zoom has released security updates to address four vulnerabilities that could expose meeting participants to significant attacks, including a zero-click remote code execution flaw dubbed “Zoomsday.” The most severe issue, tracked as CVE-2026-53413, affects Zoom’s annotation feature, which allows participants to draw, highlight, and add text during screen sharing sessions. Researchers at A Security indicated […]

    The post Zoom Zero-Click ‘Zoomsday’ Flaw Lets Meeting Participants Execute Code on Other Users’ Devices appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • One ClickFix Lure Can Give Hackers a Persistent Remote Shell Through New CNCMachineRMS RAT

    ·

    cyber security, Cyber Security News

    A ClickFix prompt can end in a remote-access foothold. CNCMachineRMS, an undocumented x64 RAT deployed at the end of a BabaDeda loader chain that turns a user-driven execution event into persistent hands-on-keyboard access. Rather than behaving like a conventional commodity stealer, the 1.14 MB implant is an access platform and second-stage delivery mechanism: its operational […]

    The post One ClickFix Lure Can Give Hackers a Persistent Remote Shell Through New CNCMachineRMS RAT appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Docker CopyEscape Vulnerability Enables Host File Overwrite and Root Code Execution

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    A critical vulnerability in Docker, tracked as CVE-2026-17106 and referred to as “CopyEscape,” allows malicious containers to overwrite files on the host system using the widely utilized `docker cp` command. This flaw can lead to code execution as the local user and, potentially, as root on Linux systems where copy operations are performed with elevated […]

    The post Docker CopyEscape Vulnerability Enables Host File Overwrite and Root Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 … 13 14 15 16 17 … 1,042
Next Page

00110010.com

cybersecurity / defense / intelligence