GBHackers Security | #1 Globally Trusted Cyber Security News Platform GBhackers Offering Exclusive Cyber Security News Coverage, New Research papers & Technology Updates.
- Lyrie.ai Joins First Batch of Anthropicâs Cyber Verification Programby CyberNewswire on May 11, 2026 at 2:59 pm
Dubai, UAE, May 11th, 2026, CyberNewswire Dubai-founded OTT Cybersecurity LLC also unveils the Agent Trust Protocol (ATP), the first open cryptographic standard for AI agent identity, scope, and action verification â slated for IETF submission. OTT Cybersecurity LLC, the company behind Lyrie.ai, today announced two milestones that together position the company as foundational infrastructure for The post Lyrie.ai Joins First Batch of Anthropicâs Cyber Verification Program appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- fsnotify Maintainer Access Change Sparks Supply Chain Security Concernsby Mayura Kathir on May 11, 2026 at 1:17 pm
A dispute over maintainer access in the widely used Go library fsnotify has triggered temporary supply chain concerns after contributors were removed from the projectâs GitHub organization and recent releases came under scrutiny. While no evidence suggests that any version of fsnotify has been compromised, the incident highlights how governance ambiguity in critical open source projects can The post fsnotify Maintainer Access Change Sparks Supply Chain Security Concerns appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- cPanel and WHM Servers Targeted in Attacks Exploiting CVE-2026-41940by Divya on May 11, 2026 at 12:30 pm
A critical authentication bypass vulnerability affecting cPanel and WHM servers, identified as CVE-2026-41940, is currently under active exploitation by a highly sophisticated and elusive cybercriminal syndicate known as Mr_Rot13. The vulnerability carries a maximum severity CVSS score of 9.8, allowing unauthenticated remote attackers to completely bypass standard authentication protocols and gain full administrator privileges over The post cPanel and WHM Servers Targeted in Attacks Exploiting CVE-2026-41940 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- Python Infostealer Hides in GitHub Releases to Bypass Detectionby Mayura Kathir on May 11, 2026 at 12:09 pm
A stealthy Python-based infostealer campaign that abuses GitHub Releases to host payloads and maintain long-term, lowâvisibility access to victim systems. The operation, dubbed âOperation HumanitarianBaitâ in some reporting, appears designed for cyberespionage against Russianâspeaking targets using humanitarianâthemed lures and a PEâless Python architecture. The campaign starts with phishing emails that deliver a RAR archive containing The post Python Infostealer Hides in GitHub Releases to Bypass Detection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- PHP SOAP Extension Flaw Could Let Attackers Execute Code Remotelyby Divya on May 11, 2026 at 12:08 pm
Recently disclosed vulnerabilities in PHP, particularly within its widely used SOAP extension, have raised significant alarms across the cybersecurity community. Among the newly identified flaws is a high-severity vulnerability that could permit attackers to achieve Remote Code Execution (RCE) on affected servers. Several other moderate-severity flaws, including Use-After-Free (UAF) bugs, NULL pointer dereferences, and out-of-bounds The post PHP SOAP Extension Flaw Could Let Attackers Execute Code Remotely appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- Fake Claude Campaign Uses PlugX-Style DLL Sideloading Chainby Mayura Kathir on May 11, 2026 at 10:59 am
Hackers are abusing a fake Claude AI download site to deliver a PlugXâstyle DLL sideloading chain that ultimately deploys a new Windows backdoor dubbed âBeagle.â The campaign blends malvertising, a trojanized installer, and signed security software components to achieve stealthy persistence and remote control. Attackers registered claude-pro[.]com, a site that visually imitates Anthropicâs legitimate Claude The post Fake Claude Campaign Uses PlugX-Style DLL Sideloading Chain appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- Microsoft 365 Copilot Flaws Could Let Attackers Access Sensitive Databy Divya on May 11, 2026 at 10:26 am
Microsoft has disclosed a trio of critical information disclosure vulnerabilities affecting Microsoft 365 Copilot and Copilot Chat in Microsoft Edge. Released on May 7, 2026, these security flaws pose a substantial risk to enterprise data privacy and corporate confidentiality. If successfully exploited, malicious actors could bypass established security boundaries to access sensitive information processed, summarized, The post Microsoft 365 Copilot Flaws Could Let Attackers Access Sensitive Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- Trending Hugging Face Repo With 200K Downloads Spreads Windows Malwareby Mayura Kathir on May 11, 2026 at 10:22 am
A malicious Hugging Face repository, Open-OSS/privacy-filter, that abused the platformâs trust and trending algorithm to deliver a sophisticated Rust-based infostealer to Windows users. The project briefly reached the #1 trending position with roughly 244,000 downloads and hundreds of likes before Hugging Face took it down, strongly suggesting the threat actor artificially boosted its popularity to The post Trending Hugging Face Repo With 200K Downloads Spreads Windows Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- Sandboxie Escape Flaw Could Let Attackers Gain SYSTEM-Level Privilegesby Divya on May 11, 2026 at 10:01 am
Security researchers have exposed critical sandbox escape vulnerabilities in Sandboxie and Sandboxie-Plus that allow attackers to gain full SYSTEM-level privileges. We strongly urge users to update to version 1.17.5, which was recently patched, to mitigate these severe execution threats. A series of catastrophic security vulnerabilities has been exposed in Sandboxie and Sandboxie-Plus, allowing threat actors The post Sandboxie Escape Flaw Could Let Attackers Gain SYSTEM-Level Privileges appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- PoC Exploit Released for Android Zero-Click Flaw Enabling Remote Shell Accessby Divya on May 11, 2026 at 9:32 am
Public references indicate that a GitHub proof-of-concept is now circulating for CVE-2026-0073, the critical Android flaw documented in Googleâs May 2026 security bulletin, raising the urgency for defenders with wireless ADB enabled on test or production devices. Google and multiple security reports describe the issue as a no-interaction remote code execution vulnerability in Androidâs adbd The post PoC Exploit Released for Android Zero-Click Flaw Enabling Remote Shell Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
















