GBHackers Security | #1 Globally Trusted Cyber Security News Platform GBhackers Offering Exclusive Cyber Security News Coverage, New Research papers & Technology Updates.
- Sidewinder Hackers Exploit LNK Files to Deploy Malicious Scriptsby Mayura Kathir on September 12, 2025 at 8:38 am
In a striking evolution of its tactics, the Sidewinder advanced persistent threat (APT) groupāalso known as APT-C-24 or āRattlesnakeāāhas adopted a novel delivery mechanism leveraging Windows shortcut (LNK) files to orchestrate complex, multi-stage intrusions across South Asia. Active since at least 2012 and targeting governments, energy utilities, military installations, and mining operations in Pakistan, Afghanistan, The post Sidewinder Hackers Exploit LNK Files to Deploy Malicious Scripts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- Axios Vulnerability Enables Attackers to Crash Node.js Applications via Data Handle Abuseby Divya on September 12, 2025 at 8:33 am
A critical security vulnerability has been discovered in the popular Axios HTTP client library that allows attackers to crash Node.js applications through malicious data URL handling. The flaw, tracked asĀ CVE-2025-58754, affects all versions of Axios before 1.11.0 and has been assigned a CVSS 3.1 score of 7.5, indicating high severity. Vulnerability Mechanics The vulnerability stems The post Axios Vulnerability Enables Attackers to Crash Node.js Applications via Data Handle Abuse appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- LAPSUS$ Hunters 4.0 Announce Permanent Shutdownby Mayura Kathir on September 12, 2025 at 7:34 am
In a startling development on September 8, the Telegram channel āscattered LAPSUS$ hunters 4.0ā declared its intention to āgo darkā after taunting law enforcement for repeated missteps. With an audacious message aimed squarely at the FBI and French authorities, the group claimed victory in evading capture and vowed that no future activity would follow their The post LAPSUS$ Hunters 4.0 Announce Permanent Shutdown appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- Microsoft to Deprecate VBScript in Windows, Urges Developers to Update Projectsby Divya on September 12, 2025 at 7:21 am
Microsoft announced the phased deprecation of VBScript in Windows, significantly impacting VBA developers who rely on VBScript libraries for regular expressions and external script execution. The company outlined a comprehensive timeline and provided migration guidance to help developers future-proof their projects. Three-Phase Deprecation Timeline VBScript deprecation will occur in three distinct phases over the coming The post Microsoft to Deprecate VBScript in Windows, Urges Developers to Update Projects appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- Apple Warns of Mercenary Spyware Attacks Targeting User Devicesby Divya on September 12, 2025 at 7:11 am
Apple has issued urgent warnings about sophisticated spyware attacks targeting specific users worldwide, including journalists, activists, politicians, and diplomats. Mercenary spyware attacks differ significantly from regular cybercriminal activity. These attacks cost millions of dollars and target only a small number of individuals based on their profession or status. The attacks are often linked to state The post Apple Warns of Mercenary Spyware Attacks Targeting User Devices appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- New K2 Think AI Model Falls to Jailbreak in Record Timeby Mayura Kathir on September 12, 2025 at 6:35 am
A groundbreaking vulnerability has emerged in the newly released K2 Think AI model from UAEās Mohamed bin Zayed University of Artificial Intelligence (MBZUAI) in collaboration with G42. Security researchers have successfully jailbroken the advanced reasoning system within hours of its public release, exposing a critical flaw that transforms the modelās transparency features into an attack The post New K2 Think AI Model Falls to Jailbreak in Record Time appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- New ToneShell Variant Uses Task Scheduler COM Service to Maintain Persistenceby Mayura Kathir on September 12, 2025 at 5:55 am
The latest ToneShell variant introduces a notable advancement in its persistence strategy by leveraging the Windows Task Scheduler COM service. This lightweight backdoor, traditionally delivered through DLL sideloading techniques, now incorporates enhanced persistence mechanisms and sophisticated anti-analysis capabilities that pose significant challenges to security teams. Cybersecurity researchers have identified a new variant of the ToneShell The post New ToneShell Variant Uses Task Scheduler COM Service to Maintain Persistence appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- VirtualBox 7.2.2 Update Released with Fix for Guest GUI Crashesby Divya on September 12, 2025 at 5:51 am
Oracle has released VirtualBox 7.2.2, a critical maintenance update that addresses multiple GUI crashes and stability issues affecting users across Windows, Linux, and macOS platforms. Released on September 10, 2025, this update represents a significant improvement in the virtualization softwareās reliability and user experience. Critical GUI Crash Fixes Implemented The most significant improvements in VirtualBox The post VirtualBox 7.2.2 Update Released with Fix for Guest GUI Crashes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- Daikin Security Gateway Vulnerability Allows Unauthorized System Accessby Divya on September 12, 2025 at 5:37 am
A critical security flaw in Daikin Security Gateway systems has been discovered that could enable attackers to bypass authentication and gain unauthorized access to industrial control systems. The vulnerability, tracked asĀ CVE-2025-10127, affects organizations worldwide that rely on Daikinās security infrastructure for protecting critical energy sector operations. Critical Authentication Bypass Discovered The vulnerability stems from a The post Daikin Security Gateway Vulnerability Allows Unauthorized System Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- New VMScape Spectre-BTI Attack Targets Isolation Flaws in AMD and Intel CPUsby Divya on September 12, 2025 at 5:23 am
Cybersecurity researchers at ETH Zurich have disclosed a critical new Spectre-based attack calledĀ VMSCAPEĀ that exploits incomplete branch predictor isolation in virtualized cloud environments. The attack, tracked asĀ CVE-2025-40300, affects multiple generations of AMD and Intel processors and enables malicious virtual machines to steal sensitive data from hypervisor processes. Attack Methodology and Impact VMSCAPE represents the first practical The post New VMScape Spectre-BTI Attack Targets Isolation Flaws in AMD and Intel CPUs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.