<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:media="http://search.yahoo.com/mrss/"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GBHackers Security | #1 Globally Trusted Cyber Security News Platform</title>
	<atom:link href="https://gbhackers.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://gbhackers.com/</link>
	<description>GBhackers Offering Exclusive Cyber Security News Coverage, New Research papers &#38; Technology Updates.</description>
	<lastBuildDate>Tue, 15 Sep 2026 13:42:29 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://gbhackers.com/wp-content/uploads/2024/09/cropped-gbh-32x32.png</url>
	<title>GBHackers Security | #1 Globally Trusted Cyber Security News Platform</title>
	<link>https://gbhackers.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">236592110</site>	<item>
		<title>Google Search Makes It Harder to See Where a Link Really Goes Before You Click</title>
		<link>https://gbhackers.com/harder-link-verification/</link>
					<comments>https://gbhackers.com/harder-link-verification/#respond</comments>
		
		<dc:creator><![CDATA[Mayura Kathir]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 13:42:27 +0000</pubDate>
				<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Google]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199567</guid>

					<description><![CDATA[<p>Google has begun routing some organic Search result links through opaque google.com/goto?url=&#8230; redirects, reducing users’ ability to independently inspect a destination URL before clicking. The change appears designed to raise the technical and financial cost of mass scraping. However, it also weakens a long-standing, basic anti-phishing habit: hovering over a link to verify where it [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/harder-link-verification/">Google Search Makes It Harder to See Where a Link Really Goes Before You Click</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/harder-link-verification/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/3bfb9185-a297-452c-9cef-237425d30d11.jpg" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199567</post-id>	</item>
		<item>
		<title>Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters</title>
		<link>https://gbhackers.com/trusted-email-abuse/</link>
					<comments>https://gbhackers.com/trusted-email-abuse/#respond</comments>
		
		<dc:creator><![CDATA[Mayura Kathir]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 13:04:34 +0000</pubDate>
				<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Phishing]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199559</guid>

					<description><![CDATA[<p>Phishing operators are increasingly shifting away from malware-laden attachments and toward trusted delivery services, authenticated domains, and multi-stage URL cloaking designed to defeat conventional email inspection. The continuously running VBSpam comparative test evaluated ten public full email-security products and one open-source solution against wanted, unwanted, and malicious mail streams. The assessment was conducted under the [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/trusted-email-abuse/">Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/trusted-email-abuse/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/c036957d-a23e-41b9-abdf-835c39c39b41.jpg" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199559</post-id>	</item>
		<item>
		<title>Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors</title>
		<link>https://gbhackers.com/woocommerce-plugin-vulnerability/</link>
					<comments>https://gbhackers.com/woocommerce-plugin-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[Mayura Kathir]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 12:05:55 +0000</pubDate>
				<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199528</guid>

					<description><![CDATA[<p>Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload malicious PHP files and potentially seize full control of vulnerable WordPress sites. The vulnerability , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 out of [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/woocommerce-plugin-vulnerability/">Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/woocommerce-plugin-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/232e3ce4-e9af-4d99-b6c7-b3f992e465fe.jpg" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199528</post-id>	</item>
		<item>
		<title>Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week</title>
		<link>https://gbhackers.com/weekly-cybersecurity-newsletter-september-7-12-2026/</link>
					<comments>https://gbhackers.com/weekly-cybersecurity-newsletter-september-7-12-2026/#respond</comments>
		
		<dc:creator><![CDATA[Balaji]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 11:44:54 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Cybersecurity Newsletter]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199404</guid>

					<description><![CDATA[<p>Microsoft Patches 973 CVEs, Claude Agents Automate Attacks, China Chains Chrome Zero-Day, Cisco FMC Exploited &#38; More. Welcome to this week&#8217;s edition of the GBHackers cybersecurity newsletter your weekly cybersecurity bulletin covering the 50 most important stories from September 7–12, 2026. AI ran through the whole week: Anthropic disclosed Claude models attacking real systems in [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/weekly-cybersecurity-newsletter-september-7-12-2026/">Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/weekly-cybersecurity-newsletter-september-7-12-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/GBHackers-News-.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199404</post-id>	</item>
		<item>
		<title>WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites</title>
		<link>https://gbhackers.com/wordpress-events-calendar-vulnerabilities/</link>
					<comments>https://gbhackers.com/wordpress-events-calendar-vulnerabilities/#respond</comments>
		
		<dc:creator><![CDATA[Divya]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 11:24:16 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Word press]]></category>
		<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199525</guid>

					<description><![CDATA[<p>Two critical unauthenticated vulnerability chains in the widely used The Events Calendar WordPress plugin could allow attackers to execute code and fully compromise affected websites remotely. These flaws, identified by Wordfence Argus, impact plugin versions up to 6.17.4 and have been patched in version 6.17.4.1. The Events Calendar is active on over 600,000 WordPress websites, [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/wordpress-events-calendar-vulnerabilities/">WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/wordpress-events-calendar-vulnerabilities/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/7cbb7a11-7c20-4347-b499-cbbd5edac745-1.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199525</post-id>	</item>
		<item>
		<title>Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Rootkit</title>
		<link>https://gbhackers.com/red-heron-hackers-exploit-critical-gitea-rce/</link>
					<comments>https://gbhackers.com/red-heron-hackers-exploit-critical-gitea-rce/#respond</comments>
		
		<dc:creator><![CDATA[Divya]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 11:16:17 +0000</pubDate>
				<category><![CDATA[CVE/vulnerability]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199521</guid>

					<description><![CDATA[<p>A Chinese-speaking threat actor known as Red Heron has exploited a critical remote code execution (RCE) vulnerability in Gitea to steal private source code, harvest credentials, establish persistent access, and move laterally within victim infrastructures. Researchers from the Acronis Threat Research Unit (TRU) have linked this operation to a newly documented Linux implant called JITTERLY, [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/red-heron-hackers-exploit-critical-gitea-rce/">Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Rootkit</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/red-heron-hackers-exploit-critical-gitea-rce/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/f950c2cb-ca5b-4663-9a93-d44f0264a059-1.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199521</post-id>	</item>
		<item>
		<title>Telegram Desktop XSS Vulnerability Lets Attackers Steal Entire Chat Histories</title>
		<link>https://gbhackers.com/telegram-desktop-xss-vulnerability-lets-attackers-steal-entire-chat-histories/</link>
					<comments>https://gbhackers.com/telegram-desktop-xss-vulnerability-lets-attackers-steal-entire-chat-histories/#respond</comments>
		
		<dc:creator><![CDATA[Divya]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 10:11:25 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Telegram]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199495</guid>

					<description><![CDATA[<p>A stored cross-site scripting (XSS) vulnerability in Telegram Desktop could enable attackers to steal the contents of exported chat histories by embedding malicious code in an inline keyboard button, according to security researchers. This issue affects the HTML chat export feature in Telegram Desktop builds released before Beta version 6.9.4 and Stable version 7.0.1. Researchers [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/telegram-desktop-xss-vulnerability-lets-attackers-steal-entire-chat-histories/">Telegram Desktop XSS Vulnerability Lets Attackers Steal Entire Chat Histories</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/telegram-desktop-xss-vulnerability-lets-attackers-steal-entire-chat-histories/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/413b2ae5-a68d-443b-ae81-ce5cf283fb6d-1.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199495</post-id>	</item>
		<item>
		<title>Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds</title>
		<link>https://gbhackers.com/marimo-rce-flaw/</link>
					<comments>https://gbhackers.com/marimo-rce-flaw/#respond</comments>
		
		<dc:creator><![CDATA[Divya]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 09:58:24 +0000</pubDate>
				<category><![CDATA[Amazon AWS]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199494</guid>

					<description><![CDATA[<p>A threat actor exploited a critical pre-authentication remote code execution vulnerability in marimo to harvest AWS credentials, retrieve an SSH private key from AWS Secrets Manager, and authenticate to a bastion host in just eight seconds, according to the Sysdig Threat Research Team. This vulnerability, tracked as CVE-2026-39987, affects marimo versions up to 0.20.4 and [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/marimo-rce-flaw/">Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/marimo-rce-flaw/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/87dbaf96-3149-4a1f-ad11-d9ad7ef218d1-3.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199494</post-id>	</item>
		<item>
		<title>DDRop Attack Forces Intel TDX Confidential VMs Into Debug Mode and Exposes Memory</title>
		<link>https://gbhackers.com/intel-tdx-under-attack/</link>
					<comments>https://gbhackers.com/intel-tdx-under-attack/#respond</comments>
		
		<dc:creator><![CDATA[Mayura Kathir]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 09:57:18 +0000</pubDate>
				<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199484</guid>

					<description><![CDATA[<p>A newly disclosed hardware attack dubbed DDRop can undermine Intel Trust Domain Extensions (TDX) by manipulating DDR5 memory traffic, allowing an attacker with physical server access to force confidential virtual machines into debug mode and extract private memory in plaintext. Researchers from KU Leuven, ETH Zurich, Google, Durham University, and other institutions released proof-of-concept code, [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/intel-tdx-under-attack/">DDRop Attack Forces Intel TDX Confidential VMs Into Debug Mode and Exposes Memory</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/intel-tdx-under-attack/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/2b6b7ad3-b6b9-4771-88c3-27c104b21b31.jpg" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199484</post-id>	</item>
		<item>
		<title>Linux Kernel ZcopyReaper Vulnerability Lets Local Attackers Gain Root Privileges</title>
		<link>https://gbhackers.com/linux-kernel-zcopyreaper-vulnerability/</link>
					<comments>https://gbhackers.com/linux-kernel-zcopyreaper-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[Divya]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 08:18:47 +0000</pubDate>
				<category><![CDATA[CVE/vulnerability]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199470</guid>

					<description><![CDATA[<p>Security researchers have disclosed a local privilege escalation vulnerability in the Linux kernel related to the Reliable Datagram Sockets (RDS) zero-copy send path. This vulnerability could let an unprivileged local attacker gain root privileges. It is tracked as CVE-2026-43502 and is referred to as “ZcopyReaper.” NebuSec researcher Yuan Tan reported the issue in a disclosure [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/linux-kernel-zcopyreaper-vulnerability/">Linux Kernel ZcopyReaper Vulnerability Lets Local Attackers Gain Root Privileges</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/linux-kernel-zcopyreaper-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/af16e04f-4ce6-4963-8fbb-6df63e0b32b1-1.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199470</post-id>	</item>
	</channel>
</rss>
