Posts of last few hours
Please support the site operations by clicking ads.
Anthropic’s Claude Haiku 5.5 model, designed for quick, repetitive workloads and speed-sensitive tasks, is now better at finding vulnerabilities and writing exploits than its predecessor. The company has given it stricter cybersecurity safeguards than Haiku 4.5, though lighter ones than its more advanced models, whose offensive skills remain well ahead. Cybersecurity capabilities and safeguards Anthropic measured the model’s offensive abilities with its cybersecurity safeguards switched off. In a test involving known flaws in Chrome’s V8 … More →
The post Anthropic’s new budget model gets much better at ignoring hidden commands appeared first on Help Net Security.
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise iPhones and harvest cryptocurrency wallet secrets. Censys researchers uncovered delivery infrastructure, implants, wallet injection modules, and reseller controls. At the same time, a separate production-server capture contained 11 victim recovery phrases, 179 device loot directories, and 75 control-plane accounts. The […]
The post Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw that could allow a man-in-the-middle attacker to bypass SSH host-key authentication under certain deployment conditions. The release, dated October 6, 2026, fixes CVE-2026-16516, a critical ECDSA host-key validation issue affecting wolfSSH up to version 1.5.0. Additionally, it resolves a high-severity […]
The post wolfSSH Patches 5 Security Vulnerabilities, Including Critical SSH Authentication Bypass appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Gitea has released version 28.0.0, addressing 20 vulnerabilities related to authentication bypass, unauthorized workflow execution, server-side request forgery, stored cross-site scripting, and denial of service. Announced on September 30, 2026, this release removes the historical “1.” version prefix. Maintainers have urged administrators to upgrade promptly to mitigate vulnerabilities affecting repository access, automation, and outbound connections. […]
The post Critical Gitea Vulnerabilities Allow Attackers to Bypass Authentication and Execute Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Day Three of Pwn2Own Ireland 2026 wrapsup with 17 attempts scheduled, roughly $1.33 million on the board.
The headliner is the Google Pixel 10, which draws three separate attempts: Xint at 11:15 AM, Ikotas Labs at 2:00 PM, and the Valsamaras/Ken Gannon (Djini.ai)/Valsamara team closing things out at 6:30 PM — by far the single biggest payday in play all week. The Samsung Galaxy S26 gets one more run too, from BunkyoWesterns at 4:15 PM. Smart Home stays busy with three attempts on the Philips Hue Bridge Pro and two closing attempts on Home Assistant Green, while AI Infrastructure sees two more shots at Oracle's Autonomous AI Database plus a single run at Chroma. Printers round things out with steady, lower-stakes attempts on the Brother, Canon, and Lexmark targets — and with Team MAMMOTH's 7:00 PM attempt as the last scheduled slot, the Master of Pwn title could still be unsettled heading into the final hour.
Stay tuned for live results as we have them.
FAILURE - Unfortunately, Polina Smirnova (@moe_hw), Mikhail Evdokimov (@konatabrk) and Mate Zombor (@r4bbit_zm) of White Noise Clubm couldn't get their exploit of the Garmin Index BPM working within the time allotted
SUCCESS / COLLISION - Results are in! Nikolaos Mourousias (@deltaclock) and Bruno Halltari (@BrunoModificato) of OtterSec successfully exploited the Oracle Autonomous AI Database with 4 bug chain of 3 collisions and 1 zero-day winning them $6,250 and 2.5 Master of Pwn points
SUCCESS / COLLISION - Sina Kheirkhah (@SinSinology) and Aaron Christophel (@ATC1441) of Summoning Team (@SummoningTeam) collided through the walls of the Philips Hue Bridge Pro with a 5 bug, full collision, securing a $5k payout and 2.5 Master of Pwn Points
SUCCESS - Brother what? Brother exploited! Lucas Van Haaren (vhash, @LucasVanHaaren) and Hugo Leclercq (0xnasu) of FuzzingLabs (@FuzzingLabs) exploited Brother MFC-L8970CDW with a single zero-day earning $20,000 and 2 Master of Pwn points
SUCCESS / COLLISION - Results are in and Tim Becker (@tjbecker) and Yves Bieri (@yves_bieri) of Xint (@xint_official) have secured their lead in the race to the Master of Pwn with their successful remote exploit of Google Pixel 10 through a single bug collision, earning them $150,000 and 15 - Master of Pwn points
SUCCESS / COLLISION - Boom chaka laka! Ben Koo (@kiddo_pwn) and Evangelos Daravigkas (@freddo_1337) of Team DDOS exploitted confirmed with a 5 bug chain, including 1 zero-day targeting Home Assistant Green with a pay out in $4,500 and 2 Master of Pwn points #Pwn2Own
SUCCESS / COLLISION - $6000 and 2.5 Master of Pwn points secured by Connor Laidlaw & Matthew Keeley of Platform Security for successfully targeting Oracle Autonomous AI Database through a 5 bugs - 4 collisions and 1 unique chain #Pwn2Own
SUCCESS - Canon Ball!!!! Sina Kheirkhah (@SinSinology) and Aaron Christophel (@ATC1441) of Summoning Team (@SummoningTeam) exploited Canon imageFORCE 1643F Multifunction Copier with a bug chain of 4 unique bugs winning total of $5,000 and 2 Master of Pwn points
SUCCESS / COLLISION - Bye bye bridge @_McCaulay exploited the Philips Hue Bridge Pro winning $5,000 and 2 Master of Pwn points with a 4 bug collision #Pwn2Own
SUCCESS / COLLISION - $300,000!!!!! and 30 Master of Pwn points officially makes Ikotas Labs, Inc. the Master of Pwn as they jump to the top of the leader board after they chained multiple issues together to successfully exploit the Google Pixel 10 #Pwn2Own
SUCCESS - 2 unique bugs and down went the Lexmark CX532adwe as Cong Thanh (@ExLuck99), Duc Hieu (@gr4ss341) and Nam Dung (@greengrass19000) earned $5,000 and 2 Master of Pwn points in their successful exploit attempt #Pwn2Own
SUCCESS / COLLISION - Howdy Buckaroos, the very own BunkyoWesterns (@BunkyoWesterns) succeed in their remote lasso-ing of the Samsung Galaxy S26, with their 2 bug chain, 1 collission + 1 unique, earning them $8250 and 3.75 Master of Pwn points #Pwn2Own #P2OIreland
SUCCESS / COLLISION Booya! Cens-ational exploit by Dimitrios Valsamaras (@Ch0pin), Ken Gannon / 伊藤 剣 (@yogehi) using http://Djini.ai from Mobile Hacking Lab, Tenia Valsamara (@ir3l14) from CENSUS Labs targeting Google Pixel 10 - Remote in the Mobile Phone category for a total of $112,500 and 22.50 Master of Pwn points with a 2 bug chain, 1 collission and 1 zero-day #Pwn2Own
SUCCESS - A Mammoth of a bug chain of 6 zero days closes out #Pwn2OwnIreland by Chulhan Park, Mingeun Kim, SeokHun Lee, Inhyung Lee, Sehyun Baek, Nayeon Lee, Junseok Kim of Team MAMMOTH targeting Home Assistant Green in the Smart Home category for a total of $7500 and 3 Master of Pwn points #Pwn2Own
Thousands of hijacked servers have been looking up their command and control (C2) server in a poem posted on GitHub, according to Black Lotus Labs. The malware reading it, dubbed PoeLLM, breaks into exposed AI services and open-source tools, mines cryptocurrency on them and uses them to hunt for new victims. The researchers call the campaign Canto Incognito and believe it is the work of an Italian-speaking threat actor who appears to be in it … More →
The post Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers appeared first on Help Net Security.
Latest Blog Posts
- 3 hours 23 minutes ago
- 3 hours 23 minutes ago
- 3 hours 23 minutes ago
- 3 hours 24 minutes ago
- 3 hours 24 minutes ago
- 3 hours 24 minutes ago
- 3 hours 24 minutes ago
- 3 hours 24 minutes ago
- 3 hours 24 minutes ago
- 3 hours 24 minutes ago