Skip to content

00110010.com

  • Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

    ·

    Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. “While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • HoneyMyte Upgrades CoolClient With Windows Kernel Rootkit to Hide Malware and C2 Connections

    ·

    cyber security, Cyber Security News, Malware, Windows

    HoneyMyte, the China-aligned espionage group also tracked as Mustang Panda, has upgraded its CoolClient backdoor with a signed Windows kernel-mode rootkit that can conceal malware artifacts and command-and-control infrastructure from security tools. The development marks a notable escalation in the group’s post-compromise tradecraft, moving protection and evasion below the user-mode layer where many endpoint inspection […]

    The post HoneyMyte Upgrades CoolClient With Windows Kernel Rootkit to Hide Malware and C2 Connections appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Malicious Google Apps Script Profiles Crypto Victims Before Delivering Signed Windows Malware

    ·

    cyber security, Cyber Security News, Google, Malware, Windows

    A targeted cryptocurrency intrusion has exposed how Google-hosted Apps Script pages can be weaponized to profile prospective victims before delivering signed Windows malware. The campaign used a fake Web3 recruitment process to deploy a three-payload stack: NeedleStealer, an unclassified Rust infostealer, and a custom Go RAT with hidden VNC capabilities. A fake recruiter initiated contact […]

    The post Malicious Google Apps Script Profiles Crypto Victims Before Delivering Signed Windows Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

    ·

    Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GeoServer Pre-Auth SQL Injection Flaw Lets Attackers Gain Remote Code Execution

    ·

    CVE/vulnerability, cyber security, Cyber Security News, vulnerability

    A newly disclosed SQL injection vulnerability in GeoServer allows remote attackers to execute operating system commands on backend PostgreSQL hosts under high-risk configurations. This flaw, detailed on August 14, 2026, affects the GeoTools code used by GeoServer to translate Common Query Language (CQL) filters into SQL queries for PostGIS-backed data stores. Reports indicate that exploitation […]

    The post GeoServer Pre-Auth SQL Injection Flaw Lets Attackers Gain Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • ChainDrop Publishes Initial Malware Without Stealing a Long-Lived npm Token

    ·

    cyber security, Cyber Security News, Malware

    The ChainDrop campaign has exposed a gap in modern software supply-chain defenses: malware no longer needs a durable npm publishing token or even an npm install event to spread through developer environments. The self-propagating npm worm, also tracked as a Mini Shai-Hulud variant, turned compromised publisher and CI identities into a distribution mechanism while establishing […]

    The post ChainDrop Publishes Initial Malware Without Stealing a Long-Lived npm Token appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Weekly Recap! – Top 50 Biggest Cybersecurity Stories of the Week: Apple Spyware, Zoom Zero-Click RCE, VMware vCenter Exploits, Microsoft Patch Day & More

    ·

    Cyber Security News

    Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from August 10–14, 2026. Zero-days set the tone: a Zoom ‘Zoomsday’ zero-click flaw could run code on other participants’ devices, the ShieldBreak zero-day bypassed a Windows Defender patch, and Microsoft’s Patch Tuesday fixed an […]

    The post Weekly Recap! – Top 50 Biggest Cybersecurity Stories of the Week: Apple Spyware, Zoom Zero-Click RCE, VMware vCenter Exploits, Microsoft Patch Day & More appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Evooo1Bot Turns Compromised Routers Into DDoS Bots and Anonymous Proxy Nodes

    ·

    Botnet, cyber security, Cyber Security News, DDOS

    A newly identified Linux botnet dubbed Evooo1Bot is targeting vulnerable internet-facing routers, edge appliances, cameras, and enterprise systems, combining Mirai-derived DDoS capabilities with proxy relaying, credential theft, SSH brute forcing, and exploit-driven propagation. FortiGuard Labs observed activity beginning in July 2026, with operators using a modular toolset that elevates compromised devices from disposable DDoS nodes […]

    The post Evooo1Bot Turns Compromised Routers Into DDoS Bots and Anonymous Proxy Nodes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • MessiahGPT Unrestricted AI Model Lets Hackers Generate Ransomware and Phishing Kits

    ·

    cyber security, Cyber Security News, Ransomware

    A newly surfaced criminal AI service named MessiahGPT is being marketed on BreachForums as an unrestricted offensive model capable of generating ransomware, phishing kits, stealers, crypters, rootkits, and social-engineering content on demand. The Trellix Advanced Research Center has reported that this service operates through the domain messiahgpt[.]de and promotes an associated Telegram community, marking a […]

    The post MessiahGPT Unrestricted AI Model Lets Hackers Generate Ransomware and Phishing Kits appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • 12 KB Backdoor Masquerades as Realtek Software and Hides C2 in Windows Whitespace

    ·

    cyber security, Cyber Security News, Windows

    A compact, custom-built Windows backdoor that impersonates Realtek software, persists through WMI, and conceals its command-and-control address inside what appears to be an almost empty desktop.ini file. At just 12,288 bytes, the x64 implant was observed on a single domain-joined Windows 7 SP1 workstation, a low-prevalence footprint that researchers assess may indicate selective targeting rather […]

    The post 12 KB Backdoor Masquerades as Realtek Software and Hides C2 in Windows Whitespace appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 2 3 4 5 6 … 1,041
Next Page

00110010.com

cybersecurity / defense / intelligence