Skip to content

1010.cx

  • Hackers Abuse Cloudflare-Hosted AWS Phishing Domains to Steal Console Logins

    ·

    AWS, Cloudflare, cyber security, Cyber Security News, Phishing

    A concise but sophisticated phishing campaign that targeted AWS console users by abusing Cloudflare-hosted domains to deliver adversary-in-the-middle (AiTM) credential theft. Each domain served an almost identical clone of the AWS console sign-in page and implemented a server-driven flow that dynamically branched into email, SMS, or authenticator-app MFA challenges, enabling real-time capture of second factors. […]

    The post Hackers Abuse Cloudflare-Hosted AWS Phishing Domains to Steal Console Logins appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns

    ·

    A new, stealthy backdoor named Mistic has been deployed as part of suspected financially motivated attacks aimed at multiple organizations spanning insurance, education, IT, and professional services sectors since April 2026. According to Symantec and Carbon Black’s Threat Hunter Team, the backdoor, also tracked as MLTBackdoor, is said to be linked to an initial access broker (IAB) named

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • RIMPAC kicks off in Hawaii with a focus on experimentation

    ·

    Science & Tech
    JOINT BASE PEARL HARBOR-HICKAM, Hawaii—The 30th iteration of RIMPAC will feature 30 to 35 experiments that involve unmanned systems, the Pacific Fleet’s second-in-command said Wednesday.

    The experiments are “a major part” of this year’s edition of the biennial Exercise Rim of the Pacific, Vice Adm. Jeffrey Jablon told reporters at a press conference. He declined to provide specifics.

    Along with the drones, RIMPAC also  includes 30 countries, 31 surface ships, five submarines, and nearly 200 aircraft, Jablon said. While the theme is “partners: integrated and prepared,” he said his top priorities for each of the 30,000 participants are “safety, environmental stewardship, and professionalism.”

    Though deterring China while getting ready to defend against a potential attack is a major focus for U.S. Indo-Pacific Command, Jablon said RIMPAC “is not about any one particular country or a deterrent for any one particular country.”

    And the war with Iran “had no impact” on RIMPAC, Jablon said. “The United States is contributing the same number of forces that we normally contribute.”

    Jablon is serving as the commander of the combined task force for RIMPAC. Underscoring the partnership aspect of the exercise, the deputy commander is a Chilean navy officer, the vice commander is a Japan Maritime Self-Defense Force officer, the maritime component commander is a Korean navy officer, and the air component commander is a Royal Canadian Navy officer.

    The exercise will end with the sinking of two decommissioned U.S. Navy ships.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google Chrome Update Patches 18 Security Flaws, Including Critical WebGL and Autofill Vulnerabilities

    ·

    Chrome, CVE/vulnerability, cyber security, Cyber Security News, Google, Vulnerabilities, vulnerability

    Google has released Chrome version 149.0.7827.196/197 for Windows and macOS, and version 149.0.7827.196 for Linux. This update addresses 18 security vulnerabilities, including several critical memory safety flaws in the WebGL and Autofill components. The announcement was made on June 23, 2026, and the update is being rolled out gradually over the coming days and weeks. […]

    The post Google Chrome Update Patches 18 Security Flaws, Including Critical WebGL and Autofill Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • DPRK-Linked macOS Implant Uses LaunchAgent Persistence and Python Stealer Module

    ·

    cyber security, Cyber Security News, macOS, Python

    The binary tracked as macOS.Gaslight as a Rust-based macOS implant and infostealer whose most novel features are analyst-directed prompt injection and a hardened Telegram-based command-and-control (C2) channel. We assess with high confidence that macOS.Gaslight aligns with DPRK-linked macOS activity clustered around BONZAI and AIRPIPE signatures. macOS.Gaslight is ad hoc signed, carries the identifier endpoint-macos-aarch64-5555494492fc075f441637fb9d894913dde3a2ea, and […]

    The post DPRK-Linked macOS Implant Uses LaunchAgent Persistence and Python Stealer Module appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft WinRE Vulnerability Allows Hackers to Bypass UEFI/BIOS Password Enforcement

    ·

    CVE/vulnerability, cyber security, Cyber Security News, Microsoft, vulnerability, Windows

    A newly disclosed vulnerability in the Microsoft Windows Recovery Environment (WinRE) could allow attackers to bypass UEFI and BIOS password protections, exposing systems to unauthorized access even when firmware-level security controls are active. This issue, tracked under CERT/CC VU#226679 and associated with CVE-2026-45585, affects Windows 10 and Windows 11 systems that use WinRE for recovery […]

    The post Microsoft WinRE Vulnerability Allows Hackers to Bypass UEFI/BIOS Password Enforcement appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers Use Malicious Chrome Extension to Break Out of Browser Sandbox

    ·

    Chrome, cyber security, Cyber Security News

    A sophisticated malware campaign that combined a phishing lure, an obfuscated Windows JavaScript dropper, a malicious Google Chrome extension and a Native Messaging Host to effectively break the browser sandbox and execute arbitrary PowerShell commands on infected Windows machines. The attack chain shows how legitimate platform features signed executables, enterprise extension deployment policies and Chrome’s […]

    The post Hackers Use Malicious Chrome Extension to Break Out of Browser Sandbox appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Alibaba Accused of Illicitly Accessing Claude AI Models Using 25,000 Fraudulent Accounts

    ·

    AI, cyber security, Cyber Security News

    Anthropic has accused the Chinese technology conglomerate Alibaba of orchestrating a large-scale, coordinated operation to extract capabilities from its Claude AI models illegally. The company describes this incident as the largest adversarial distillation attack recorded to date. The allegations, outlined in a formal letter dated June 10, 2026, were addressed to U.S. Senate Banking Committee […]

    The post Alibaba Accused of Illicitly Accessing Claude AI Models Using 25,000 Fraudulent Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cisco Catalyst SD-WAN Manager Zero-Day Exploited to Gain Root Access via Malicious CSV Upload

    ·

    cyber security, Cyber Security News, vulnerability, Zero-Day, zeroday

    Cisco Catalyst SD-WAN Manager instances are currently being targeted in a zero-day exploitation campaign that allows attackers to escalate their privileges to root through a malicious CSV upload mechanism. Mandiant reported this information on June 24, 2026. The vulnerability, identified as CVE-2026-20245, affects Cisco Catalyst SD-WAN controllers and stems from improper validation of file uploads […]

    The post Cisco Catalyst SD-WAN Manager Zero-Day Exploited to Gain Root Access via Malicious CSV Upload appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access

    ·

    An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google-owned Mandiant. The vulnerability, tracked as CVE-2026-20245 (CVSS score: 7.8), allows an authenticated, local attacker to execute arbitrary commands with elevated privileges

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

1 2 3 … 893
Next Page

1010.cx

cybersecurity / defense / intelligence