<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:media="http://search.yahoo.com/mrss/"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GBHackers Security | #1 Globally Trusted Cyber Security News Platform</title>
	<atom:link href="https://gbhackers.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://gbhackers.com/</link>
	<description>GBhackers Offering Exclusive Cyber Security News Coverage, New Research papers &#38; Technology Updates.</description>
	<lastBuildDate>Tue, 21 Jul 2026 13:59:10 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://gbhackers.com/wp-content/uploads/2024/09/cropped-gbh-32x32.png</url>
	<title>GBHackers Security | #1 Globally Trusted Cyber Security News Platform</title>
	<link>https://gbhackers.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">236592110</site>	<item>
		<title>Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers</title>
		<link>https://gbhackers.com/amatera-stealer-c2-servers/</link>
					<comments>https://gbhackers.com/amatera-stealer-c2-servers/#respond</comments>
		
		<dc:creator><![CDATA[Mayura Kathir]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 13:51:16 +0000</pubDate>
				<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=192945</guid>

					<description><![CDATA[<p>Hackers are increasingly abusing decentralized infrastructure and legitimate development frameworks to evade detection, with a newly observed campaign leveraging Ethereum smart contracts to conceal command-and-control (C2) endpoints for the Amatera Stealer infostealer. These lures are propagated عبر malicious websites, file-sharing platforms such as Google Drive, MEGA, GoFile, and Wormhole, and spoofed download portals designed to [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/amatera-stealer-c2-servers/">Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/amatera-stealer-c2-servers/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/07/Untitled-design-2026-07-21T192006.349.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">192945</post-id>	</item>
		<item>
		<title>New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops</title>
		<link>https://gbhackers.com/cav3rn-module-replaces-websocket-c2/</link>
					<comments>https://gbhackers.com/cav3rn-module-replaces-websocket-c2/#respond</comments>
		
		<dc:creator><![CDATA[Mayura Kathir]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 13:27:54 +0000</pubDate>
				<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=192934</guid>

					<description><![CDATA[<p>In a significant evolution of the Project CAV3RN tooling, a new .NET Native AOT communication module dubbed AzureCommunication.dll has been deployed to replace the framework’s earlier HTTP/WebSocket C2 component. A stealthy channel that abuses Outlook calendar events over Microsoft Graph and a DNS-based recovery mechanism for Microsoft 365 credentials. This shift reinforces CAV3RN’s positioning as [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/cav3rn-module-replaces-websocket-c2/">New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/cav3rn-module-replaces-websocket-c2/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/07/Untitled-design-2026-07-21T185637.643.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">192934</post-id>	</item>
		<item>
		<title>Trump’s AI Safety Agency Chief Resigns After Just Three Months Leading CAISI</title>
		<link>https://gbhackers.com/trumps-ai-safety-agency-chief-resigns-after-just-three-months/</link>
					<comments>https://gbhackers.com/trumps-ai-safety-agency-chief-resigns-after-just-three-months/#respond</comments>
		
		<dc:creator><![CDATA[Divya]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 13:09:21 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=192928</guid>

					<description><![CDATA[<p>Chris Fall, the director of the U.S. Center for AI Standards and Innovation (CAISI), has resigned just three months after being appointed to lead the Commerce Department agency. This departure raises new uncertainties regarding the Trump administration’s agenda on AI safety, model evaluation, and cybersecurity oversight. The Commerce Department confirmed his resignation on July 20, [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/trumps-ai-safety-agency-chief-resigns-after-just-three-months/">Trump’s AI Safety Agency Chief Resigns After Just Three Months Leading CAISI</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/trumps-ai-safety-agency-chief-resigns-after-just-three-months/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/07/Trumps-AI-Safety-Agency-Chief-Resigns-After-Just-Three-Months-Leading-CAISI-1.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">192928</post-id>	</item>
		<item>
		<title>Craneware Cyberattack Exposes Employee and US Healthcare Customer Data</title>
		<link>https://gbhackers.com/craneware-cyberattack-exposes-employee-data/</link>
					<comments>https://gbhackers.com/craneware-cyberattack-exposes-employee-data/#respond</comments>
		
		<dc:creator><![CDATA[Divya]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 13:01:47 +0000</pubDate>
				<category><![CDATA[Cyber Attack]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=192919</guid>

					<description><![CDATA[<p>Craneware plc, a UK-based provider of healthcare financial performance software, has disclosed that it experienced a cyberattack in which an unauthorized party accessed and extracted data from a portion of its systems. The company revealed that the incident involved employee information and records related to certain customers and partners, including organizations in the US healthcare [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/craneware-cyberattack-exposes-employee-data/">Craneware Cyberattack Exposes Employee and US Healthcare Customer Data</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/craneware-cyberattack-exposes-employee-data/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/07/Craneware-Cyberattack-Exposes-Employee-and-US-Healthcare-Customer-Data-1.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">192919</post-id>	</item>
		<item>
		<title>2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge</title>
		<link>https://gbhackers.com/2026-ransomware-report/</link>
					<comments>https://gbhackers.com/2026-ransomware-report/#respond</comments>
		
		<dc:creator><![CDATA[Mayura Kathir]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 12:40:10 +0000</pubDate>
				<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=192923</guid>

					<description><![CDATA[<p>Ransomware volumes hit a new peak in 2026, with Black Kite tracking 7,551 publicly disclosed victims, 146 active groups, and a 443% year‑over‑year surge in Qilin activity that reshapes the threat landscape. The data points to a structurally higher operating tempo, a middle‑market pivot, and attacker visibility that often outpaces defenders’ own understanding of their [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/2026-ransomware-report/">2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/2026-ransomware-report/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/07/Untitled-design-2026-07-21T180848.182.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">192923</post-id>	</item>
		<item>
		<title>Microsoft Retires Copilot Podcasts and Removes Access to Previously Created Content</title>
		<link>https://gbhackers.com/microsoft-retires-copilot-podcasts-and-removes-access/</link>
					<comments>https://gbhackers.com/microsoft-retires-copilot-podcasts-and-removes-access/#respond</comments>
		
		<dc:creator><![CDATA[Divya]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 12:23:05 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=192916</guid>

					<description><![CDATA[<p>Microsoft has announced that it will retire the Podcasts feature in its consumer Copilot app on August 18, 2026. This decision will permanently remove the ability to generate new AI-created podcasts, as well as access to all previously created content. This change affects all Copilot customers, including both free users and paid subscribers, and raises [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/microsoft-retires-copilot-podcasts-and-removes-access/">Microsoft Retires Copilot Podcasts and Removes Access to Previously Created Content</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/microsoft-retires-copilot-podcasts-and-removes-access/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/07/391b22f3-de36-4f27-9278-5a50d2f2ad36-1.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">192916</post-id>	</item>
		<item>
		<title>Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries</title>
		<link>https://gbhackers.com/microsoft-defender-xdr-blind-spot/</link>
					<comments>https://gbhackers.com/microsoft-defender-xdr-blind-spot/#respond</comments>
		
		<dc:creator><![CDATA[Divya]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 11:54:05 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=192903</guid>

					<description><![CDATA[<p>Microsoft Defender XDR users may inadvertently overlook command-and-control (C2) traffic when searching for Internet-bound connections due to a specific behavior in how IP addresses are classified. This issue arises from Kusto Query Language (KQL) detections that depend solely on filtering by RemoteIPType == &#8220;Public&#8221; in the DeviceNetworkEvents table. As a result, traffic destined for public [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/microsoft-defender-xdr-blind-spot/">Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/microsoft-defender-xdr-blind-spot/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/07/e0135910-82ff-423c-b451-d3abadc8b4a2-1.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">192903</post-id>	</item>
		<item>
		<title>Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT</title>
		<link>https://gbhackers.com/cruciferra-crypter-to-disable-edr/</link>
					<comments>https://gbhackers.com/cruciferra-crypter-to-disable-edr/#respond</comments>
		
		<dc:creator><![CDATA[Mayura Kathir]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 11:42:40 +0000</pubDate>
				<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=192907</guid>

					<description><![CDATA[<p>Hackers are abusing the Cruciferra crypter-as-a-service to systematically turn off endpoint detection and response (EDR) tools and stealthily deploy XWorm, Remcos, AsyncRAT, and other commodity malware in email-driven campaigns targeting multiple sectors worldwide. By combining BYOVD-based driver abuse, indirect syscalls and a polymorphic encryption engine with more than 90 mix-and-match crypto routines, Cruciferra has rapidly [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/cruciferra-crypter-to-disable-edr/">Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/cruciferra-crypter-to-disable-edr/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/07/Untitled-design-2026-07-21T171015.511.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">192907</post-id>	</item>
		<item>
		<title>Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution</title>
		<link>https://gbhackers.com/hackers-exploit-servicenow-ai-platform-flaw-to-gain-unauthenticated-remote-code-execution/</link>
					<comments>https://gbhackers.com/hackers-exploit-servicenow-ai-platform-flaw-to-gain-unauthenticated-remote-code-execution/#respond</comments>
		
		<dc:creator><![CDATA[Divya]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 10:57:05 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=192870</guid>

					<description><![CDATA[<p>Threat actors are actively exploiting CVE-2026-6875, a critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform. This vulnerability allows attackers to escape a restricted server-side script sandbox and execute code without valid credentials. Reports from Defused indicate observed exploitation activity targeting this flaw. Initially, ServiceNow&#8217;s advisory stated it was not aware of any [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/hackers-exploit-servicenow-ai-platform-flaw-to-gain-unauthenticated-remote-code-execution/">Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/hackers-exploit-servicenow-ai-platform-flaw-to-gain-unauthenticated-remote-code-execution/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/07/07f518c2-2255-4405-b988-00a6c8ab4639-1.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">192870</post-id>	</item>
		<item>
		<title>JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data</title>
		<link>https://gbhackers.com/jadepuffer-deploys-encforge-ransomware/</link>
					<comments>https://gbhackers.com/jadepuffer-deploys-encforge-ransomware/#respond</comments>
		
		<dc:creator><![CDATA[Mayura Kathir]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 10:57:00 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">https://gbhackers.com/?p=192884</guid>

					<description><![CDATA[<p>JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe high‑value AI and ML artifacts across an entire stack. A missing‑authentication bug in the /api/v1/validate/code endpoint that enables unauthenticated arbitrary Python execution on the host. That initial operation chained reconnaissance, credential [&#8230;]</p>
<p>The post <a href="https://gbhackers.com/jadepuffer-deploys-encforge-ransomware/">JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data</a> appeared first on <a href="https://gbhackers.com">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>
]]></description>
		
					<wfw:commentRss>https://gbhackers.com/jadepuffer-deploys-encforge-ransomware/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://gbhackers.com/wp-content/uploads/2026/07/Untitled-design-2026-07-21T162601.795.webp" medium="image"></media:content>
            <post-id xmlns="com-wordpress:feed-additions:1">192884</post-id>	</item>
	</channel>
</rss>
