Posts of last few hours
Please support the site operations by clicking ads.
A newly identified Cyclops Blink variant has resurfaced on compromised Cisco Secure Firewall Management Center (FMC) appliances, adding active internal-network scanning and programmable packet-sniffing capabilities to an already mature modular implant. Assessed with high confidence that the activity has a Russian nexus, with a moderate-confidence link to IRON VIKING also tracked as Sandworm and Seashell […]
The post Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencent’s Sogou Input Method for Windows to deploy the GRAYRABBIT backdoor on targeted systems. Tracked as CVE-2026-51990, the vulnerability chains an insecure custom protocol handler, unrestricted embedded-browser navigation, and an obsolete Chromium build running without sandbox protections. Tencent addressed […]
The post China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Hackers are using a familiar Windows automation tool to hide AsyncRAT, a remote-access trojan, inside a trusted system process. The campaign starts with a deceptive batch file named “Right-click to open Invoice Details.bat,” which can appear harmless to someone expecting an invoice or shared document. Once opened, the file quietly launches PowerShell, rebuilds hidden code […]
The post Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process appeared first on Cyber Security News.
A Casbaneiro banking Trojan campaign targeting users across Latin America, using phishing lures, geofenced delivery infrastructure, and distributed command-and-control (C2) servers to obscure malicious activity. The operation, observed in August 2026, primarily targets victims in Argentina, Peru, Colombia, and Mexico through fake invoice and legal-notice emails carrying links to malicious PDF files. The campaign demonstrates […]
The post Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
A five-stage AsyncRAT campaign that chains a socially engineered batch file, hidden PowerShell execution, AutoIt abuse and process injection to conceal a .NET remote-access trojan inside Microsoft’s legitimate charmap.exe process. The infection begins with a lure named “Right-click to open Invoice Details.bat”, which relies on user interaction to trigger execution. While the precise delivery method […]
The post AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
The Dutch National Cyber Security Center (NCSC) has issued an urgent warning over two critical vulnerabilities in Check Point VPN products, saying it expects large-scale exploitation attempts in the near term. Organizations using affected Check Point gateways, management systems, or Spark Firewall products should deploy the available fixes immediately. Tracked as CVE-2026-85102 and CVE-2026-85103, both […]
The post NCSC Warns of Critical Check Point VPN Flaws as Large-Scale Exploitation Is Expected appeared first on Cyber Security News.
Latest Blog Posts
- 3 weeks 1 day ago
- 2 months 3 weeks ago
- 2 months 3 weeks ago
- 2 months 3 weeks ago
- 2 months 3 weeks ago
- 7 months 2 weeks ago
- 1 year ago
- 1 year ago
- 1 year 2 months ago
- 1 year 5 months ago