New DLL Hijacking Technique Let Attackers Bypass Windows Security Mechanisms

DLL hijacking is a technique where a malicious DLL (Dynamic Link Library) is placed in a directory that a vulnerable application searches before the legitimate one.  When the application is launched, it unknowingly loads the malicious DLL instead, allowing attackers to:- Recently, the cybersecurity researchers at a multi-layered incident response company, Security Joes, discovered a […]

The post New DLL Hijacking Technique Let Attackers Bypass Windows Security Mechanisms appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.

January 2, 2024
Read More >>

Multiple Flaws in Google Kubernetes Engine Let Attackers Escalate Privileges

Google Kubernetes Engine (GEK) has been detected with two flaws that a threat actor can utilize to create significant damage in case the threat actor already has access inside the Kubernetes cluster. The first issue was associated with FluentBit with default configuration. FluentBit is GKE’s logging agent that runs by default on all the clusters. […]

The post Multiple Flaws in Google Kubernetes Engine Let Attackers Escalate Privileges appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.

January 2, 2024
Read More >>

CLZero: Fuzzing HTTP/1.1 CL.0 Request Smuggling Attack Vectors

CLZero is a strong program that helps security experts and penetration testers find and use attack vectors for HTTP/1.1 CL.0 Request Smuggling. Request smuggling is a major security hole in web applications that can let hackers in and cause data to leak, among other bad things. CLZero was based on the tool Smuggler and uses […]

January 2, 2024
Read More >>

KnowsMore: Active Directory and Password Analysis Tool

KnowsMore is a powerful program made for people who work in network security and Active Directory control. There are many tools it comes with that let you look at and control Active Directory settings, BloodHound data, NTDS hashes, and crack passwords. Users can import and connect important data, check the strength of passwords, look for […]

January 2, 2024
Read More >>

10 Most Common Types of Cyber Attacks in 2023

Cyber attacks are evolving rapidly with advancements in technology, as threat actors exploit new vulnerabilities in:- The rise of the following sophisticated techniques demonstrates a growing level of complexity:- Moreover, the expansion of Internet of Things (IoT) devices provides new attack surfaces to the threat actors.  Since threat actors are continuously adapting, that’s why the […]

The post 10 Most Common Types of Cyber Attacks in 2023 appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.

January 2, 2024
Read More >>

Top 3 Cybersecurity Trends for SME Business Leaders in 2024

As Cynet’s COO, my team and I get to work closely with risk management executives at small-to-medium enterprises (SMEs) around the world. In this article, I’ll condense our collaboration’s insights into three key trends for 2024, backed up by data and research from all areas of cybersecurity practice. These emerging patterns pertain to organizations of […]

January 2, 2024
Read More >>

650,000+ Malicious Domains Registered Resembling ChatGPT

Hackers abuse the ChatGPT name for malicious domains to exploit the credibility associated with the ChatGPT model, deceiving users into trusting fraudulent websites.  Leveraging the model’s reputation enables them to trick individuals into:- H2 2023’s ransomware from ESET highlight isn’t typical, as it’s the “MOVEit hack” by the Russian ransomware group Cl0p, and here below, […]

The post 650,000+ Malicious Domains Registered Resembling ChatGPT appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.

January 2, 2024
Read More >>

New Medusa Stealer Attacking Users to Steal Login Credentials

While the world celebrated Christmas, the cybercrime underworld feasted on a different kind of treat: the release of Meduza 2.2, a significantly upgraded password stealer poised to wreak havoc on unsuspecting victims.  Cybersecurity researchers at Resecurity uncovered the details of New Medusa Stealer malware. Resecurity is a cybersecurity company specializing in endpoint protection, risk management, […]

The post New Medusa Stealer Attacking Users to Steal Login Credentials appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.

December 29, 2023
Read More >>

BestEDROfTheMarket: A User-Mode EDR Evasion Lab for Learning and Testing

Little AV/EDR Evasion Lab for training & learning purposes. (????️ under construction..)​ BestEDROfTheMarket is a naive user-mode EDR (Endpoint Detection and Response) project, designed to serve as a testing ground for understanding and bypassing EDR’s user-mode detection methods that are frequently used by these security solutions.These techniques are mainly based on a dynamic analysis of the […]

December 28, 2023
Read More >>

Chinese Hackers Exploit New Zero-Day in Barracuda’s ESG to Deploy Backdoor

Barracuda Email Security Gateway (ESG) Appliance has been discovered with an Arbitrary code Execution vulnerability exploited by a China Nexus threat actor tracked as UNC4841. Additionally, the vulnerability targeted only a limited number of ESG devices.  However, Barracuda has deployed a security update to all the active ESGs to address this vulnerability, and has been […]

The post Chinese Hackers Exploit New Zero-Day in Barracuda’s ESG to Deploy Backdoor appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.

December 28, 2023
Read More >>