Install
GBHackers Security | #1 Globally Trusted Cyber Security News Platform | GBhackers Offering Exclusive Cyber Security News Coverage, New Research papers & Technology Updates. gbhackers.com GBhackers Offering Exclusive Cyber Security News Coverage, New Research papers & Technology Updates.
- 265articles · 30d
- 3+ day agolatest article
- Aug 15, 2026earliest in window
- 40%with images
- 376avg words
- Computers & Electronics 178
- Science & Technology 161
- Software 129
- Conflict, War & Peace 76
- Crime & Law 70
- Software Dev. 56
- Internet & Telecom 41
- News 26
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- threatsday bulletin
- digital world
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft
3+ day, 14+ hour ago (616+ words) Nearly one in 10 internet-exposed LiteLLM AI gateways accepted the widely documented default master key, sk-1234, or required no authentication, creating a direct path to LLMjacking, sensitive credential exposure, and in vulnerable versions root-level code execution inside the gateway container. Their…...
cPanel EmailTrack SQL Injection Flaw Lets Attackers Execute Code as Root
4+ day, 20+ hour ago (312+ words) cPanel has disclosed CVE-2026-67401, a SQL injection vulnerability in its EmailTrack functionality. This flaw allows an authenticated account holder to create arbitrary files on a server, which can ultimately enable them to execute code with root privileges. The issue, published…...
The Best DNS Security Solutions, Compared and Priced (2026)
5+ day, 17+ hour ago (801+ words) DNS security delivers more blocked attacks per dollar than any other network control when you buy the right shape at the right tier. Published per-user tier: DNSFilter and SafeDNS publish per-user monthly pricing (single-digit dollars, volume breaks); Cloudflare Gateway runs…...
Roundcube Fixes 12 Security Flaws Including Zero-Click XSS and SSRF Bypass
6+ day, 17+ hour ago (524+ words) Roundcube has released security updates 1.6.19 and 1.7.4, which address 12 vulnerabilities affecting its 1.6 LTS and 1.7 Webmail branches. The flaws include a zero-click stored cross-site scripting (XSS) vulnerability, several bypasses of remote content filtering, email header injection bugs, cross-user contact access issues, and…...
Simple Router DNS Tweak Blocks Malware and Phishing Across All Connected Devices
1+ week, 6+ day ago (488+ words) A recent router-level DNS change is gaining attention as a method to reduce exposure to phishing pages and malware across all devices connected to a home network. Cybersecurity expert Luis Catacora has recommended replacing a router’s default DNS resolvers with…...
768 Leaked AWS Keys Still Active With Full Admin Access to Corporate Accounts
3+ week, 1+ day ago (525+ words) A large-scale investigation has uncovered 768 publicly exposed AWS access keys that remain active and grant full administrative privileges to corporate cloud environments, posing a serious risk of account takeover, data theft, infrastructure abuse, and cloud billing fraud. The credentials include…...
Zero-Click Grok Attack Lets Hackers Steal Chat History Using Encrypted Prompt Injection
3+ week, 1+ day ago (548+ words) A newly disclosed prompt-injection technique could turn a routine request to summarize a webpage in xAI’s Grok web chat into a silent data-exfiltration attack, potentially exposing a user’s name, approximate location, subscription tier, and active conversation history. Security researchers at…...
Peer2Profit Turns Employee Devices Into AstroProxy Nodes That Can Expose Internal Networks
3+ week, 2+ day ago (665+ words) Residential proxy networks have become a key enabler for fraud, credential stuffing, account takeover, spam, and large-scale automated abuse. New research shows that PEER2PROFIT, a bandwidth-sharing application, can turn employee or personal devices into commercial proxy exit nodes that are then…...
New CRLF Desync Attack Lets Hackers Steal HTTPOnly Cookies and Hijack Accounts
3+ week, 3+ day ago (424+ words) Security researchers Tom Stacey from PortSwigger and Tobia Righi from TurtleSec have introduced a new category of HTTP request smuggling attacks known as “CRLF-Powered Desync Attacks.” This method exploits a frequently overlooked HTTP header injection vulnerability, which can lead to…...