Website profile

gbhackers.com

GBHackers Security | #1 Globally Trusted Cyber Security News Platform | GBhackers Offering Exclusive Cyber Security News Coverage, New Research papers & Technology Updates. gbhackers.com GBhackers Offering Exclusive Cyber Security News Coverage, New Research papers & Technology Updates.

  • 265articles · 30d
  • 3+ day agolatest article
  • Aug 15, 2026earliest in window
  • 40%with images
  • 376avg words
articles per day
Categories
  • Computers & Electronics 178
  • Science & Technology 161
  • Software 129
  • Conflict, War & Peace 76
  • Crime & Law 70
  • Software Dev. 56
  • Internet & Telecom 41
  • News 26

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

gbhackers.com
gbhackers.com > litellm-ai-gateways

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

3+ day, 14+ hour ago   (616+ words) Nearly one in 10 internet-exposed LiteLLM AI gateways accepted the widely documented default master key, sk-1234, or required no authentication, creating a direct path to LLMjacking, sensitive credential exposure, and in vulnerable versions root-level code execution inside the gateway container. Their…...

gbhackers.com
gbhackers.com > cpanel-emailtrack-sql-injection-flaw

cPanel EmailTrack SQL Injection Flaw Lets Attackers Execute Code as Root

4+ day, 20+ hour ago   (312+ words) cPanel has disclosed CVE-2026-67401, a SQL injection vulnerability in its EmailTrack functionality. This flaw allows an authenticated account holder to create arbitrary files on a server, which can ultimately enable them to execute code with root privileges. The issue, published…...

gbhackers.com
gbhackers.com > the-best-dns-security-solutions-compared-and-priced-2026

The Best DNS Security Solutions, Compared and Priced (2026)

5+ day, 17+ hour ago   (801+ words) DNS security delivers more blocked attacks per dollar than any other network control when you buy the right shape at the right tier. Published per-user tier: DNSFilter and SafeDNS publish per-user monthly pricing (single-digit dollars, volume breaks); Cloudflare Gateway runs…...

gbhackers.com
gbhackers.com > roundcube-fixes-12-security-flaws

Roundcube Fixes 12 Security Flaws Including Zero-Click XSS and SSRF Bypass

6+ day, 17+ hour ago   (524+ words) Roundcube has released security updates 1.6.19 and 1.7.4, which address 12 vulnerabilities affecting its 1.6 LTS and 1.7 Webmail branches. The flaws include a zero-click stored cross-site scripting (XSS) vulnerability, several bypasses of remote content filtering, email header injection bugs, cross-user contact access issues, and…...

gbhackers.com
gbhackers.com > simple-router-dns-tweak-blocks-malware-and-phishing

Simple Router DNS Tweak Blocks Malware and Phishing Across All Connected Devices

1+ week, 6+ day ago   (488+ words) A recent router-level DNS change is gaining attention as a method to reduce exposure to phishing pages and malware across all devices connected to a home network. Cybersecurity expert Luis Catacora has recommended replacing a router’s default DNS resolvers with…...

gbhackers.com
gbhackers.com > 768-leaked-aws-keys-still-active-with-full-admin

768 Leaked AWS Keys Still Active With Full Admin Access to Corporate Accounts

3+ week, 1+ day ago   (525+ words) A large-scale investigation has uncovered 768 publicly exposed AWS access keys that remain active and grant full administrative privileges to corporate cloud environments, posing a serious risk of account takeover, data theft, infrastructure abuse, and cloud billing fraud. The credentials include…...

gbhackers.com
gbhackers.com > zero-click-grok-attack-prompt-injection

Zero-Click Grok Attack Lets Hackers Steal Chat History Using Encrypted Prompt Injection

3+ week, 1+ day ago   (548+ words) A newly disclosed prompt-injection technique could turn a routine request to summarize a webpage in xAI’s Grok web chat into a silent data-exfiltration attack, potentially exposing a user’s name, approximate location, subscription tier, and active conversation history. Security researchers at…...

gbhackers.com
gbhackers.com > peer2profit-proxy-threat

Peer2Profit Turns Employee Devices Into AstroProxy Nodes That Can Expose Internal Networks

3+ week, 2+ day ago   (665+ words) Residential proxy networks have become a key enabler for fraud, credential stuffing, account takeover, spam, and large-scale automated abuse. New research shows that PEER2PROFIT, a bandwidth-sharing application, can turn employee or personal devices into commercial proxy exit nodes that are then…...

gbhackers.com
gbhackers.com > new-crlf-desync-attack

New CRLF Desync Attack Lets Hackers Steal HTTPOnly Cookies and Hijack Accounts

3+ week, 3+ day ago   (424+ words) Security researchers Tom Stacey from PortSwigger and Tobia Righi from TurtleSec have introduced a new category of HTTP request smuggling attacks known as “CRLF-Powered Desync Attacks.” This method exploits a frequently overlooked HTTP header injection vulnerability, which can lead to…...