Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

gbhackers.com
gbhackers.com > claude-ai-autonomously-discovers-cryptographic-weaknesses

Claude AI Autonomously Discovers Cryptographic Weaknesses That Escaped Expert Review

4+ hour, 51+ min ago   (428+ words) Researchers at Anthropic reported that Claude Mythos Preview autonomously discovered new cryptographic attacks against the post-quantum signature candidate HAWK and a reduced-round version of AES. This demonstrates that advanced AI models can now contribute to research that was traditionally the…...

gbhackers.com
gbhackers.com > autonomous-ai-breaches-hugging-face-production-systems

Autonomous AI Agent Escapes Sandbox and Breaches Hugging Face Production Systems

4+ hour, 44+ min ago   (487+ words) Hugging Face has reported a sophisticated intrusion that occurred in July 2026. In this incident, an autonomous AI agent escaped from its evaluation sandbox, compromised third-party infrastructure, and later breached production systems by exploiting vulnerabilities in its dataset-processing pipeline. The details…...

gbhackers.com
gbhackers.com > openai-open-sources-codex-security-cli-to-find-vulnerabilities

OpenAI Open-Sources Codex Security CLI to Find, Validate, and Fix Code Vulnerabilities

4+ hour, 25+ min ago   (426+ words) OpenAI has open-sourced Codex Security, a command-line interface and TypeScript SDK designed to help engineering and security teams identify, validate, and remediate vulnerabilities across code repositories. Codex Security positions AI-assisted code review as a repeatable application security workflow rather than…...

gbhackers.com
gbhackers.com > adversarial-prompt-injection

Cybercriminals Use Adversarial Prompt Injection to Evade AI-Powered Security Tools

3+ hour, 55+ min ago   (562+ words) AI’s expanding role in detection, filtering, and automation has made it an attractive attack surface. While adversaries continue to rely heavily on human-centric techniques such as phishing, researchers from Proofpoint highlight a parallel evolution in attack chains leveraging LLM-assisted tooling…...

gbhackers.com
gbhackers.com > nginx-heap-overflow-flaw > amp

NGINX Heap Overflow Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

5+ hour, 17+ min ago   (550+ words) A high-severity heap buffer overflow vulnerability has been identified in the NGINX Stream module’s script engine. This vulnerability may allow unauthenticated remote attackers to crash worker processes or execute arbitrary code. The issue CVE-2026-42533 affects configurations that combine the `ssl_preread` feature…...

gbhackers.com
gbhackers.com > fake-claude-code-installer-3 > amp

Fake Claude Code Installer Delivers MacSync macOS Infostealer Through Google Ads

20+ hour, 8+ min ago   (462+ words) A highly convincing malvertising campaign is targeting macOS users searching for “how to install Claude Code on Mac,” delivering the MacSync infostealer through a trusted-looking workflow that abuses legitimate infrastructure rather than exploiting software vulnerabilities. The attack highlights a growing…...

gbhackers.com
gbhackers.com > critical-teamcity-flaw

Critical TeamCity Flaw Lets Unauthenticated Attackers Execute System Commands

22+ hour, 11+ min ago   (432+ words) The issue impacts every version of the self-hosted continuous integration and continuous delivery platform, making it urgent for organizations that expose TeamCity instances over HTTP or HTTPS to apply patches. JetBrains has released fixes in TeamCity versions 2025.11.7 and 2026.1.3, urging administrators…...

gbhackers.com
gbhackers.com > dysphoria-iot-botnet

Dysphoria IoT Botnet Uses Blockchain Domains and 200,000 Devices for DDoS Attacks

1+ day, 1+ hour ago   (467+ words) Initial samples observed in March 2026 used Ethereum Name Service (ENS) domains such as m3rnbvs5d.eth to retrieve configuration data, even embedding debug strings like “android has no compatible libc library.” By April, newer variants replaced earlier builds and introduced distinct markers…...

gbhackers.com
gbhackers.com > castleloader-campaign-deploys-needlestealer

CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions

21+ hour, 33+ min ago   (453+ words) A significant evolution in the CastleLoader malware ecosystem, with new campaigns deploying the NeedleStealer framework to harvest cryptocurrency wallet seed phrases and hijack browser sessions. The findings expand on earlier research by Huntress and LevelBlue, confirming that CastleLoader remains a…...

gbhackers.com
gbhackers.com > portswigger-launches-burp-at-agentic-ai > amp

PortSwigger Introduces Burp AT Agentic AI for Automated Penetration Testing

1+ day, 1+ hour ago   (455+ words) PortSwigger has launched Burp AT, an agentic AI system that allows penetration testers to delegate web security investigation tasks while maintaining direct control over the testing scope, approvals, and final conclusions. The public beta is currently available for Burp Suite…...