Tag: Security

soc

Microsoft Unveils New Guidance to Detect and Defend Against Trivy Supply Chain Attack

Aqua Security’s vulnerability scanner, Trivy, suffered a sophisticated CI/CD supply chain compromise. The threat actor, identified as TeamPCP, leveraged prior incomplete remediation to inject credential-stealing malware into official releases. This incident, tracked as CVE-2026-33634, successfully weaponized a trusted security tool against the organizations relying on it to stay safe. This visualizes the attack propagation timeline […]

The post Microsoft Unveils New Guidance to Detect and Defend Against Trivy Supply Chain Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Mehr lesen →
soc

Fake VS Code Security Alerts on GitHub Spread Malware in Massive Phishing Attack

A large-scale phishing campaign is actively targeting developers on GitHub by abusing the platform’s Discussions feature to distribute fake Visual Studio Code (VS Code) security alerts. The campaign appears highly coordinated, with thousands of near-identical posts discovered across multiple repositories, indicating automated mass exploitation rather than isolated abuse. Attackers are creating GitHub Discussions with alarming […]

The post Fake VS Code Security Alerts on GitHub Spread Malware in Massive Phishing Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Mehr lesen →
soc

Cisco Secure Firewall Vulnerability Exposes Systems to Remote Code Execution by Attackers

Cisco has released critical security updates to address a maximum-severity vulnerability affecting its Secure Firewall Management Center (FMC) Software. Tracked under the identifier CVE-2026-20131, this flaw carries a perfect CVSS base score of 10.0 and allows unauthenticated, remote attackers to execute arbitrary code. The situation is particularly urgent as the company has confirmed that threat […]

The post Cisco Secure Firewall Vulnerability Exposes Systems to Remote Code Execution by Attackers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Mehr lesen →
soc

Node.js Releases Urgent Patches for Multiple Vulnerabilities Exposing Systems to DoS and Crashes

The Node.js project issued a critical security update for its Long-Term Support (LTS) branch, marking version 20.20.2 ‘Iron’ as a security release. This urgent patch addresses seven distinct vulnerabilities impacting TLS error handling, HTTP/2 flow control, cryptographic timing, and permission models. Several of these issues can be exploited remotely without authentication, posing an immediate risk […]

The post Node.js Releases Urgent Patches for Multiple Vulnerabilities Exposing Systems to DoS and Crashes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Mehr lesen →
security

Apple Patches (almost) everything again. March 2026 edition., (Wed, Mar 25th)

Apple released the next version of its operating system, patching 85 different vulnerabilities across all of them. None of the vulnerabilities are currently being exploited. The last three macOS „generations“ are covered, as are the last two versions of iOS/iPadOS. For tvOS, watchOS, and visionOS, only the current version received patches. This update also includes the recently released Background Security Improvements. Some older watchOS versions received updates, but these updates do not address any security issues.

Mehr lesen →
soc

TeamPCP’s Checkmarx GitHub Actions Attack: What You Need to Know

TeamPCP’s Checkmarx GitHub Actions Attack: What You Need to Know A supply chain incident becomes far more dangerous when it stops looking like a single breach and starts behaving like a multiplier. That is what made the TeamPCP campaign stand out in March 2026. The compromise of Checkmarx GitHub Actions and developer tooling became one […]

Mehr lesen →
soc

GoHarbor Issues Urgent Patch for Harbor Flaw Allowing Full Registry Compromise

A critical security flaw in GoHarbor’s Harbor container registry exposes organizations to severe supply chain attacks. Tracked as CVE-2026-4404, this vulnerability stems from hardcoded default credentials that remain active unless manually altered by an administrator. Harbor functions as an open-source, OCI-compliant registry project designed to store, sign, and manage container images. Because it plays a […]

The post GoHarbor Issues Urgent Patch for Harbor Flaw Allowing Full Registry Compromise appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Mehr lesen →