<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:media="http://search.yahoo.com/mrss/"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GBHackers Security | #1 Globally Trusted Cyber Security News Platform</title>
	<atom:link href="https://gbhackers.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://gbhackers.com/</link>
	<description>GBhackers Offering Exclusive Cyber Security News Coverage, New Research papers &#38; Technology Updates.</description>
	<lastBuildDate>Mon, 14 Sep 2026 09:27:45 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://gbhackers.com/wp-content/uploads/2024/09/cropped-gbh-32x32.png</url>
	<title>GBHackers Security | #1 Globally Trusted Cyber Security News Platform</title>
	<link>https://gbhackers.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">236592110</site>	<item>
		<title>Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities</title>
		<link>https://gbhackers.com/cyclops-blink-variant/</link>
					<comments>https://gbhackers.com/cyclops-blink-variant/#respond</comments>
		
		<dc:creator><![CDATA[Mayura Kathir]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 09:27:43 +0000</pubDate>
				<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199354</guid>

					<description><![CDATA[<p>A newly identified Cyclops Blink variant has resurfaced on compromised Cisco Secure Firewall Management Center (FMC) appliances, adding active internal-network scanning and programmable packet-sniffing capabilities to an already mature modular implant. Assessed with high confidence that the activity has a Russian nexus, with a moderate-confidence link to IRON VIKING also tracked as Sandworm and Seashell [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/cyclops-blink-variant/">Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/cyclops-blink-variant/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/d982a30a-0fd1-43ef-be24-943263d71d3b.jpg" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199354</post-id>	</item>
		<item>
		<title>China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor</title>
		<link>https://gbhackers.com/grayrabbit-backdoor/</link>
					<comments>https://gbhackers.com/grayrabbit-backdoor/#respond</comments>
		
		<dc:creator><![CDATA[Mayura Kathir]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 08:09:26 +0000</pubDate>
				<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199335</guid>

					<description><![CDATA[<p>China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencent’s Sogou Input Method for Windows to deploy the GRAYRABBIT backdoor on targeted systems. Tracked as CVE-2026-51990, the vulnerability chains an insecure custom protocol handler, unrestricted embedded-browser navigation, and an obsolete Chromium build running without sandbox protections. Tencent addressed [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/grayrabbit-backdoor/">China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/grayrabbit-backdoor/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/b43a6d95-2f02-46db-9874-69b674ec8b7a.jpg" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199335</post-id>	</item>
		<item>
		<title>Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users</title>
		<link>https://gbhackers.com/casbaneiro-banking-trojan/</link>
					<comments>https://gbhackers.com/casbaneiro-banking-trojan/#respond</comments>
		
		<dc:creator><![CDATA[Mayura Kathir]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 05:56:58 +0000</pubDate>
				<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199322</guid>

					<description><![CDATA[<p>A Casbaneiro banking Trojan campaign targeting users across Latin America, using phishing lures, geofenced delivery infrastructure, and distributed command-and-control (C2) servers to obscure malicious activity. The operation, observed in August 2026, primarily targets victims in Argentina, Peru, Colombia, and Mexico through fake invoice and legal-notice emails carrying links to malicious PDF files. The campaign demonstrates [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/casbaneiro-banking-trojan/">Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/casbaneiro-banking-trojan/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/fc4fc2e8-cfed-4345-9090-613953ed792e.jpg" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199322</post-id>	</item>
		<item>
		<title>AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process</title>
		<link>https://gbhackers.com/asyncrat-in-hides-windows-process/</link>
					<comments>https://gbhackers.com/asyncrat-in-hides-windows-process/#respond</comments>
		
		<dc:creator><![CDATA[Mayura Kathir]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 05:24:48 +0000</pubDate>
				<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199311</guid>

					<description><![CDATA[<p>A five-stage AsyncRAT campaign that chains a socially engineered batch file, hidden PowerShell execution, AutoIt abuse and process injection to conceal a .NET remote-access trojan inside Microsoft’s legitimate charmap.exe process. The infection begins with a lure named “Right-click to open Invoice Details.bat”, which relies on user interaction to trigger execution. While the precise delivery method [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/asyncrat-in-hides-windows-process/">AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/asyncrat-in-hides-windows-process/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/6d864e6f-563d-49b2-a57f-142540d2be1a.jpg" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199311</post-id>	</item>
		<item>
		<title>Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data</title>
		<link>https://gbhackers.com/threat-actors-use-claude-ai-agents-to-automate-cyberattacks-and-steal-sensitive-data/</link>
					<comments>https://gbhackers.com/threat-actors-use-claude-ai-agents-to-automate-cyberattacks-and-steal-sensitive-data/#respond</comments>
		
		<dc:creator><![CDATA[Eswar]]></dc:creator>
		<pubDate>Sat, 12 Sep 2026 08:40:16 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199295</guid>

					<description><![CDATA[<p>Threat actors are increasingly using Claude-based AI workflows to automate cyberattacks, accelerate data theft, and reduce the technical expertise needed to run complex intrusions. Anthropic&#8217;s report details cyber espionage, financially motivated extortion, supply-chain compromise, and hacktivist activity disrupted between December 2025 and August 2026. Rather than using an AI chatbot only for occasional coding assistance, [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/threat-actors-use-claude-ai-agents-to-automate-cyberattacks-and-steal-sensitive-data/">Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/threat-actors-use-claude-ai-agents-to-automate-cyberattacks-and-steal-sensitive-data/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/threat-actors-use-claude-ai-agents-to-automate-cyberattacks-and-steal-sensitive-data-6aa50e5e75b41.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199295</post-id>	</item>
		<item>
		<title>China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks</title>
		<link>https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/</link>
					<comments>https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/#respond</comments>
		
		<dc:creator><![CDATA[Eswar]]></dc:creator>
		<pubDate>Sat, 12 Sep 2026 08:04:47 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199288</guid>

					<description><![CDATA[<p>China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on September 1, 2026, as using identical browser-to-kernel exploit components but ultimately installing separate espionage payloads: the GRIMWEDGE JScript backdoor and the LONGTALE credential-stealing Chrome [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/">China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/china-linked-hackers-chain-chrome-zero-day/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/china-linked-hackers-chain-chrome-zero-day-with-windows-kernel-flaw-in-attacks-6aa50682e9a57.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199288</post-id>	</item>
		<item>
		<title>New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets</title>
		<link>https://gbhackers.com/new-phishing-campaign-abuses-windows-mshta-exe/</link>
					<comments>https://gbhackers.com/new-phishing-campaign-abuses-windows-mshta-exe/#respond</comments>
		
		<dc:creator><![CDATA[Eswar]]></dc:creator>
		<pubDate>Sat, 12 Sep 2026 06:16:51 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199278</guid>

					<description><![CDATA[<p>A newly identified phishing campaign is abusing the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files, conduct system reconnaissance, and potentially deploy payloads designed to steal credentials and local secrets. Fortra’s Intelligence and Research Experts (FIRE) said the activity began in June and remains active, with operators regularly recompiling malware samples to [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/new-phishing-campaign-abuses-windows-mshta-exe/">New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/new-phishing-campaign-abuses-windows-mshta-exe/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/new-phishing-campaign-abuses-windows-mshtaexe-to-steal-credentials-and-secrets-6aa4ed8e3f81a.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199278</post-id>	</item>
		<item>
		<title>OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE</title>
		<link>https://gbhackers.com/openai-agents-flood-rubygems-with-2000-packages/</link>
					<comments>https://gbhackers.com/openai-agents-flood-rubygems-with-2000-packages/#respond</comments>
		
		<dc:creator><![CDATA[Eswar]]></dc:creator>
		<pubDate>Sat, 12 Sep 2026 06:03:55 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199273</guid>

					<description><![CDATA[<p>A swarm of AI agents believed to be operated internally by OpenAI uploaded more than 2,000 malicious packages to RubyGems in May 2026, abusing the ecosystem’s documentation build process to execute code remotely and attempting to steal user API keys through a then-undisclosed server-side flaw. Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/openai-agents-flood-rubygems-with-2000-packages/">OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/openai-agents-flood-rubygems-with-2000-packages/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/openai-agents-flood-rubygems-with-2000-packages-and-exploit-build-system-for-rce-6aa4e2dd30228.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199273</post-id>	</item>
		<item>
		<title>CISA Warns of Critical GitLab Vulnerability Exploited in Attacks</title>
		<link>https://gbhackers.com/cisa-warns-of-critical-gitlab-vulnerability-exploited-in-attacks/</link>
					<comments>https://gbhackers.com/cisa-warns-of-critical-gitlab-vulnerability-exploited-in-attacks/#respond</comments>
		
		<dc:creator><![CDATA[Eswar]]></dc:creator>
		<pubDate>Sat, 12 Sep 2026 05:17:40 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199269</guid>

					<description><![CDATA[<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects both GitLab Community Edition and Enterprise Edition and requires urgent mitigation, particularly for internet-accessible GitLab instances. CVE-2026-85706 is a path traversal vulnerability [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/cisa-warns-of-critical-gitlab-vulnerability-exploited-in-attacks/">CISA Warns of Critical GitLab Vulnerability Exploited in Attacks</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/cisa-warns-of-critical-gitlab-vulnerability-exploited-in-attacks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/cisa-warns-of-critical-gitlab-vulnerability-exploited-in-attacks-6aa4e0618c108.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199269</post-id>	</item>
		<item>
		<title>Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign</title>
		<link>https://gbhackers.com/10000-malware-loaders/</link>
					<comments>https://gbhackers.com/10000-malware-loaders/#respond</comments>
		
		<dc:creator><![CDATA[Mayura Kathir]]></dc:creator>
		<pubDate>Fri, 11 Sep 2026 12:24:51 +0000</pubDate>
				<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Malware]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=199254</guid>

					<description><![CDATA[<p>A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to distribute malware at scale. The cluster, tracked as CL-CRI-1171, is linked to more than 10,000 distinct samples of a custom loader called OfferLoader, indicating a distribution pipeline far larger than the individual intrusions initially observed. Rather than relying on a [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/10000-malware-loaders/">Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/10000-malware-loaders/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/09/unnamed-4.jpg" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">199254</post-id>	</item>
	</channel>
</rss>
