GBHackers On Security

GBHackers On Security

Publication
0 followers

Security news site covering daily hacking news and cyberattack updates.

NightSpire Ransomware Abuses RDP for Stealthy Persistence
NewsMay 26, 2026

NightSpire Ransomware Abuses RDP for Stealthy Persistence

NightSpire ransomware, first identified in early 2025, has quickly become a high‑profile threat by combining double‑extortion tactics with stealthy persistence mechanisms. Between March and June 2025 the group compromised at least 64 organizations across 33 countries, using legitimate remote‑administration tools...

By GBHackers On Security
Gamaredon Deploys GammaDrop, GammaLoad in Phishing Campaigns
NewsMay 18, 2026

Gamaredon Deploys GammaDrop, GammaLoad in Phishing Campaigns

Gamaredon, the Russian‑linked espionage group targeting Ukraine, has intensified its phishing campaign by leveraging the WinRAR directory‑traversal flaw CVE‑2025‑8088. The group distributes RAR (and now ARJ) archives that embed a VBScript downloader called GammaDrop, which drops a second‑stage HTA payload...

By GBHackers On Security
Paper Werewolf APT Spreads EchoGather RAT via Fake Adobe Installer
NewsMay 18, 2026

Paper Werewolf APT Spreads EchoGather RAT via Fake Adobe Installer

The Russian‑language threat group Paper Werewolf (aka GOFFEE) launched a new wave of attacks against Russian industrial, financial and transport firms in March‑April 2026. The campaign begins with a phishing PDF that auto‑downloads a fake Adobe Reader installer, which silently...

By GBHackers On Security
Hackers Abuse Cloudflare Storage to Exfiltrate Network Files
NewsMay 18, 2026

Hackers Abuse Cloudflare Storage to Exfiltrate Network Files

Researchers at Oasis Security uncovered a sophisticated cyber‑espionage campaign targeting multiple Malaysian organizations. The attackers leveraged an Azure virtual machine to run custom Python, Laravel, and C# tools that enumerated networks, accessed internal databases, and harvested Active Directory credentials. Data...

By GBHackers On Security
Critical Marimo RCE Flaw Could Let Attackers Execute Malicious Code Remotely
NewsMay 18, 2026

Critical Marimo RCE Flaw Could Let Attackers Execute Malicious Code Remotely

A critical remote code execution flaw (CVE‑2026‑39987) has been discovered in the Marimo Python notebook framework. The vulnerability resides in the /terminal/ws WebSocket endpoint, which fails to enforce authentication and spawns a system‑level shell for any requester. All Marimo versions...

By GBHackers On Security
OtterCookie Malware Steals Dev Secrets, SSH Keys, Cloud Credentials, and Tokens
NewsMay 18, 2026

OtterCookie Malware Steals Dev Secrets, SSH Keys, Cloud Credentials, and Tokens

OtterCookie is a newly identified Node.js‑based remote‑access trojan that leverages persistent Socket.IO connections to monitor infected workstations in real time. Unlike earlier malware such as BeaverTail, it captures live developer activity—including clipboard data, keystrokes, screenshots, SSH keys, cloud credentials, and...

By GBHackers On Security
Gunra Ransomware Expands RaaS After Conti Locker Shift
NewsMay 15, 2026

Gunra Ransomware Expands RaaS After Conti Locker Shift

Gunra ransomware has transitioned from a Conti‑derived locker to a standalone Ransomware‑as‑a‑Service platform, expanding its operational reach. The shift, announced after its initial 2025 attacks on South Korean firms, now powers an affiliate network that can brand the payload and...

By GBHackers On Security
OrBit Rootkit Targets Linux to Steal SSH and Sudo Credentials
NewsMay 15, 2026

OrBit Rootkit Targets Linux to Steal SSH and Sudo Credentials

The OrBit Linux rootkit, first identified in 2022, has been quietly evolving while remaining active in the wild. Built on the open‑source Medusa LD_PRELOAD framework, attackers now deploy two main variants—Lineage A with full credential‑stealing and network‑hiding features, and a slimmer...

By GBHackers On Security
TeamPCP, BreachForums Launch $1K Supply-Chain Attack Contest
NewsMay 14, 2026

TeamPCP, BreachForums Launch $1K Supply-Chain Attack Contest

TeamPCP and BreachForums have launched a $1,000 Monero‑rewarded contest that challenges hackers to compromise open‑source packages using the Shai‑Hulud tool. Participants submit proof of access and compete on a leaderboard that scores based on download volume of the infected packages....

By GBHackers On Security
Chinese APT Exploits Microsoft Exchange to Breach Energy Sector Network
NewsMay 14, 2026

Chinese APT Exploits Microsoft Exchange to Breach Energy Sector Network

Chinese state‑aligned APT group FamousSparrow breached a major Azerbaijani energy firm by exploiting the ProxyNotShell chain on an unpatched Microsoft Exchange server on Dec. 25, 2025. The attackers deployed the Deed RAT via a LogMeIn Hamachi DLL sideloading technique and later attempted a...

By GBHackers On Security
New Malware Framework Enables Screen Control and UAC Bypass
NewsMay 14, 2026

New Malware Framework Enables Screen Control and UAC Bypass

Researchers uncovered TencShell, a sophisticated malware framework built on the open‑source Rshell C2 tool and repurposed for stealthy post‑exploitation. In April 2026, Cato CTRL blocked an attack on a global manufacturing firm in India after the implant delivered Donut shellcode hidden...

By GBHackers On Security
170 Npm Packages Hijacked to Steal GitHub, AWS & Kubernetes Secrets
NewsMay 14, 2026

170 Npm Packages Hijacked to Steal GitHub, AWS & Kubernetes Secrets

Hackers compromised more than 170 npm packages and two PyPI libraries, which together see over 200 million weekly downloads, to harvest developer and cloud credentials. The malicious packages embed pre‑install scripts that download obfuscated payloads, extract GitHub Actions tokens, npm publishing...

By GBHackers On Security
Microsoft Research: AI Can Generate Realistic Command-Line and Process Telemetry
NewsMay 14, 2026

Microsoft Research: AI Can Generate Realistic Command-Line and Process Telemetry

Microsoft Research unveiled an AI system that converts attacker tactics from frameworks like MITRE ATT&CK into realistic command‑line and process telemetry. The approach uses prompt‑engineered generation, multi‑agent workflows, and reinforcement‑learning‑with‑verifiable‑rewards to synthesize logs that closely mimic real attack behavior. Evaluations show...

By GBHackers On Security
Vidar Stealer Campaign Evades EDR to Steal Credentials
NewsMay 12, 2026

Vidar Stealer Campaign Evades EDR to Steal Credentials

A new Vidar Stealer campaign uses malicious LNK shortcuts, environment‑variable string reconstruction, and layered PowerShell‑to‑Python payloads to bypass endpoint detection and response (EDR) tools. The chain starts with spear‑phishing ZIP archives, launches cmd.exe, then PowerShell to download an obfuscated batch...

By GBHackers On Security
GBHackers On Security | Pulse