CYBER ATTACK

Hackers Sending Fake ChatGPT Invites to Android Users to Spread Malware

Hackers Sending Fake ChatGPT Invites to Android Users to Spread Malware

CYBER ATTACKZerowl

Cybercriminals have set their sights on Android users through a well-crafted phishing scheme that disguises malicious applications as beta-testing.

More than 511,000 Microsoft IIS instances that are no longer supported are now online.

More than 511,000 Microsoft IIS instances that are no longer supported are now online.

CYBER ATTACKZerowl

An enormous attack surface that includes old Microsoft Internet Information Services (IIS) servers This article explores iis daily vulnerable. . On March.

Trivy Supply Chain Attack Spreads Through Compromised Docker Hub Images

Trivy Supply Chain Attack Spreads Through Compromised Docker Hub Images

CYBER ATTACKZerowl

A major supply chain attack is growing in the cybersecurity world. After a recent breach of the GitHub aquasecurity/trivy-action repository, Socket's.

Oblivion RAT Masquerades As Play Store Updates In Expanding Android Spyware Campaign

Oblivion RAT Masquerades As Play Store Updates In Expanding Android Spyware Campaign

CYBER ATTACKZerowl

Oblivion RAT is a new Android remote access trojan that has appeared on cybercrime forums This article explores makes iverify malware. . It is a very.

Oblivion RAT Turns Fake Play Store Updates Into a Full-Service Android Spyware Operation

Oblivion RAT Turns Fake Play Store Updates Into a Full-Service Android Spyware Operation

CYBER ATTACKZerowl

A new Android remote access trojan called Oblivion RAT has appeared on cybercrime networks as a full malware-as-a-service (MaaS) platform, turning fake.

MacOS Stealer MioLab Adds ClickFix Delivery, Wallet Theft and Team API Tools

MacOS Stealer MioLab Adds ClickFix Delivery, Wallet Theft and Team API Tools

CYBER ATTACKZerowl

MioLab, also known as Nova, is a highly advanced macOS infostealer that is now one of the most advanced Malware-as-a-Service (MaaS) platforms that targets.

Libyan Oil Refinery Hit in Long-Running Espionage Campaign Using AsyncRAT

Libyan Oil Refinery Hit in Long-Running Espionage Campaign Using AsyncRAT

CYBER ATTACKZerowl

Between November 2025 and February 2026, a coordinated spying campaign hit a Libyan oil refinery, a telecom company, and a government agency This article.

Critical NetScaler ADC and Gateway Vulnerabilities Enable Remote Attacks on Affected Systems

Critical NetScaler ADC and Gateway Vulnerabilities Enable Remote Attacks on Affected Systems

CYBER ATTACKZerowl

Cloud Software Group has put out urgent security patches for NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) This.

Trivy Vulnerability Scanner Breached To Inject Credential-Stealing Scripts

Trivy Vulnerability Scanner Breached To Inject Credential-Stealing Scripts

CYBER ATTACKZerowl

This March, the Trivy ecosystem had its second big security breach. The first was a supply-chain attack that made the official GitHub Action used to run.

Over 511,000 End-of-Life Microsoft IIS Servers Exposed Online

Over 511,000 End-of-Life Microsoft IIS Servers Exposed Online

CYBER ATTACKZerowl

Researchers have found a huge global security risk that comes from using old Microsoft Internet Information Services (IIS) servers This article explores.

New CanisterWorm Steals npm Tokens and Spreads Through Compromised Publisher Accounts

New CanisterWorm Steals npm Tokens and Spreads Through Compromised Publisher Accounts

CYBER ATTACKZerowl

CanisterWorm is a self-propagating malware campaign that is bringing a new wave of supply chain attacks to the npm ecosystem. The threat, which is.

LAPSUS$ Hackers Claim Breach of AstraZeneca’s Internal Systems

LAPSUS$ Hackers Claim Breach of AstraZeneca’s Internal Systems

CYBER ATTACKZerowl

The supposed AstraZeneca data breach shows that the LAPSUS$ hacking group is back in action. They are now quietly selling claims of deep access to source.

Hackers Exploit Quest KACE SMA Flaw to Steal Credentials

Hackers Exploit Quest KACE SMA Flaw to Steal Credentials

CYBER ATTACKZerowl

According to new research, hackers are actively using a serious flaw in Quest KACE Systems Management Appliance (SMA) to get into systems without.

Crunchyroll Breach: Hackers Claim 100GB of User Data Stolen

Crunchyroll Breach: Hackers Claim 100GB of User Data Stolen

CYBER ATTACKZerowl

After a breach involving its outsourcing partner, Telus, a threat actor is said to have stolen about 100 GB of private user data from Crunchyroll, the.

Copyright-Themed Lures Deliver Multi-Stage PureLog Stealer in New Credential Theft Campaign

Copyright-Themed Lures Deliver Multi-Stage PureLog Stealer in New Credential Theft Campaign

CYBER ATTACKZerowl

A new malware campaign is going after businesses in the healthcare, government, education, and hospitality sectors This article explores purelog stealer.

CISA Warns of Craft CMS Code Injection Vulnerability Exploited in Attacks

CISA Warns of Craft CMS Code Injection Vulnerability Exploited in Attacks

CYBER ATTACKZerowl

The Known Exploited Vulnerabilities catalog now includes a serious flaw in Craft CMS (CVE-2025-32432) that has been confirmed to be actively used in the.

CISA Warns of Craft CMS Code Injection Flaw Exploited in the Wild

CISA Warns of Craft CMS Code Injection Flaw Exploited in the Wild

CYBER ATTACKZerowl

CISA has warned that a serious Craft CMS vulnerability, tracked as CVE-2025-35939, is now being actively exploited. This means that attackers who don't.

CISA Warns of Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain Exploited in Attacks

CISA Warns of Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain Exploited in Attacks

CYBER ATTACKZerowl

CISA warns that DarkSword iOS exploit chain is linked to Apple vulnerabilities. This is an urgent warning about three serious Apple vulnerabilities that.

$30 IP-KVM Flaws Could Let Attackers Control BIOS Across All Enterprise Networks

$30 IP-KVM Flaws Could Let Attackers Control BIOS Across All Enterprise Networks

CYBER ATTACKZerowl

Nine serious security holes have been found in four popular low-cost IP-KVM devices by researchers who recently did a security assessment. These holes.

New CanisterWorm Malware Targets npm Tokens In Supply Chain Campaign

New CanisterWorm Malware Targets npm Tokens In Supply Chain Campaign

CYBER ATTACKZerowl

Security experts have found a very advanced npm supply chain attack called CanisterWorm This article explores makes wormable threat. . The campaign, which.

Microsoft Emergency Out-of-Band Update for Windows 11 to Fix Microsoft Account Sign-In Failure

Microsoft Emergency Out-of-Band Update for Windows 11 to Fix Microsoft Account Sign-In Failure

CYBER ATTACKZerowl

Microsoft has released an out-of-band (OOB) update for Windows 11 versions 25H2 and 24H2, known as KB5085516, to fix a serious sign-in bug that was caused.

Cybercriminals Infect 7,500 Magento Stores With Hidden Malicious Files

Cybercriminals Infect 7,500 Magento Stores With Hidden Malicious Files

CYBER ATTACKZerowl

A huge campaign to deface websites has successfully hacked more than 7,500 unique Magento e-commerce domains, allowing unauthorized text files to be.

Crunchyroll Data Breach — Threat Actor Claims Exfiltration of 100 GB of User Data

Crunchyroll Data Breach — Threat Actor Claims Exfiltration of 100 GB of User Data

CYBER ATTACKZerowl

A hacker is said to have stolen about 100 GB of personally identifiable information (PII) from Crunchyroll, the Sony-owned anime streaming giant This.

Critical QNAP QVR Pro Flaw Allows Remote Attackers to Access Systems

Critical QNAP QVR Pro Flaw Allows Remote Attackers to Access Systems

CYBER ATTACKZerowl

QNAP has sent out an urgent security warning about a serious flaw in its QVR Pro app that could let attackers from outside the company get full access to.

$30 IP-KVM Flaws Put Businesses at Risk of BIOS-Level Attacks

$30 IP-KVM Flaws Put Businesses at Risk of BIOS-Level Attacks

CYBER ATTACKZerowl

A new wave of security research has found serious flaws in low-cost IP-KVM (Keyboard, Video, Mouse) devices, which is very worrying for businesses This.

Threat Actors Leverage Copyright-Themed Emails to Drop PureLog Stealer

Threat Actors Leverage Copyright-Themed Emails to Drop PureLog Stealer

CYBER ATTACKZerowl

Threat actors are using a complicated, multi-stage malware campaign to spread the PureLog Stealer This article explores malware campaign spread. . This.

Oracle Releases Urgent Patch for Critical RCE Flaw in Identity Manager and Web Services Manager

Oracle Releases Urgent Patch for Critical RCE Flaw in Identity Manager and Web Services Manager

CYBER ATTACKZerowl

Oracle recently sent out an urgent security alert about a serious Remote Code Execution (RCE) flaw that affects both Oracle Identity Manager and Oracle.

Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager

Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager

CYBER ATTACKZerowl

Oracle has sent out an out-of-band Security Alert about a serious remote code execution (RCE) vulnerability, CVE-2026-21992, that affects two widely used.

Windows 11 March Update Breaks Microsoft Teams and OneDrive Sign-Ins

Windows 11 March Update Breaks Microsoft Teams and OneDrive Sign-Ins

CYBER ATTACKZerowl

The March Update for Windows 11 Breaks Teams Microsoft has admitted that a major bug in its March 2026 cumulative update is stopping Windows 11 users from.

New VoidStealer Variant Bypasses Chrome ABE Without Injection or Privilege Escalation

New VoidStealer Variant Bypasses Chrome ABE Without Injection or Privilege Escalation

CYBER ATTACKZerowl

Discover how A new version of the VoidStealer infostealer has gotten a lot of attention from security experts because it was the first malware to get.

Top 5 this week

Page 10 of 44