News Feed imported from gbhackers.
GBHackers Security | #1 Globally Trusted Cyber Security News Platform GBhackers Offering Exclusive Cyber Security News Coverage, New Research papers & Technology Updates.
- Windows Hello Key Abuse Lets Attackers Access Microsoft Entra ID Accountsby Divya on August 7, 2026 at 12:50 PM
Security researcher has disclosed a technique involving Windows Hello for Business (WHFB) that could allow attackers with access to an active Windows user session to authenticate to Microsoft Entra ID services without needing the victim’s PIN, biometric verification, or password. Mollema’s research demonstrates how attackers can effectively “borrow” the cryptographic key that underlies Windows Hello The post Windows Hello Key Abuse Lets Attackers Access Microsoft Entra ID Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- New NatJack NAT Attack Lets Hackers Hijack TCP Connections and DNS Responsesby Divya on August 7, 2026 at 11:04 AM
A newly disclosed attack class, NatJack, reveals significant weaknesses in the implementation of Network Address Translation (NAT) across modern network infrastructures. This vulnerability allows attackers to hijack TCP connections, tamper with DNS responses, and disrupt traffic flow. NatJack specifically targets the NAT state table, highlighting that traditional assumptions about cooperative network behavior are no longer The post New NatJack NAT Attack Lets Hackers Hijack TCP Connections and DNS Responses appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flawsby Divya on August 7, 2026 at 10:53 AM
Google has released Chrome version 151.0.7922.108/.109 for Windows and macOS, and version 151.0.7922.108 for Linux. This update delivers 41 security fixes across various components of the browser, including rendering, graphics, JavaScript, user interface (UI), media, and authentication. The Stable channel update began rolling out on August 6 and will reach users over the next several The post Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- Claude Code RCE Flaw Lets Malicious Pull Requests Execute Code on Developer Systemsby Divya on August 7, 2026 at 10:08 AM
A malicious pull request has the potential to turn Claude Code’s project-scoped Model Context Protocol (MCP) configuration into a trigger for code execution, which could expose developer secrets before a reviewer has a chance to evaluate the code. Anthropic reportedly aligns this behavior with its workspace trust model, establishing the security boundary at the initial The post Claude Code RCE Flaw Lets Malicious Pull Requests Execute Code on Developer Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
- Enterprise Java Vulnerabilities Enable Pre-Auth RCE in Bonita BPM and Apache OFBizby Divya on August 7, 2026 at 8:54 AM
Security research presented at Black Hat 2026 has identified 12 vulnerabilities across four enterprise Java platforms, including two critical pre-authentication remote code execution (RCE) chains affecting Bonita BPM and Apache OFBiz. Researchers Lidor Ben Shitrit and Assaf Levkovich demonstrated how seemingly minor middleware vulnerabilities, such as differences in URL parsing, incomplete servlet protections, hardcoded cryptographic The post Enterprise Java Vulnerabilities Enable Pre-Auth RCE in Bonita BPM and Apache OFBiz appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.




