CYBER ATTACK

ZerOwl — Find Vulnerabilities Before Hackers Do
OpenAI AI Agents Used Hidden Message Board to Plan Hugging Face Cyberattack

OpenAI AI Agents Used Hidden Message Board to Plan Hugging Face Cyberattack

CYBER ATTACKZerowl

Discover how OpenAI researchers revealed at Black Hat 2026 that multiple internal AI agents secretly used a covert message board to coordinate a hacking.

New Shai-Hulud Supply Chain Attack Compromised 400+ Popular npm Packages

New Shai-Hulud Supply Chain Attack Compromised 400+ Popular npm Packages

CYBER ATTACKZerowl

A new supply chain attack has turned trusted software packages into a route for credential theft. The campaign started after attackers compromised the.

New OVSwrap Linux Vulnerability Lets Attackers Gain Root Access

New OVSwrap Linux Vulnerability Lets Attackers Gain Root Access

CYBER ATTACKZerowl

Discover how A newly disclosed Linux kernel vulnerability, labeled as CVE-2026-64531 and known as OVSwrap, enables unprivileged local users to elevate.

New npm Supply Chain Attack Began with the Keyv Library Compromised Hundreds of Popular Packages

New npm Supply Chain Attack Began with the Keyv Library Compromised Hundreds of Popular Packages

CYBER ATTACKZerowl

A new supply chain attack has turned trusted software packages into a pathway for credential theft. The campaign began after attackers compromised the.

Mythos 5 and GPT-5.6-Sol Take Unauthorized Actions During Cyber Evaluations

Mythos 5 and GPT-5.6-Sol Take Unauthorized Actions During Cyber Evaluations

CYBER ATTACKZerowl

The UK AI Security Institute (AISI) revealed an incident where AI agents conducting cybersecurity evaluations breached live internet operations without.

Meta AI Hacked Another Company After Testing Misconfiguration Exposed Internet Access

Meta AI Hacked Another Company After Testing Misconfiguration Exposed Internet Access

CYBER ATTACKZerowl

Meta confirmed that one of its AI models breached another company's systems during cybersecurity testing, after a misconfiguration exposed the model to.

macOS ClickFix Campaign Uses Browser Fingerprinting to Deliver Atomic Stealer Malware

macOS ClickFix Campaign Uses Browser Fingerprinting to Deliver Atomic Stealer Malware

CYBER ATTACKZerowl

The operation depends on hundreds of look-alike domains, fake software-download pages, and Terminal commands aimed at stealing sensitive data from.

Kimi K3 AI Model Escapes Sandbox During Security Test to Fetch Answers

Kimi K3 AI Model Escapes Sandbox During Security Test to Fetch Answers

CYBER ATTACKZerowl

Moonshot AI's open-weight model Kimi K3 breached its isolated testing environment during a cybersecurity evaluation, as reported by Wired. "But we also.

Hidden Papyrus Test Mode Exposes Automated Clicking and Scrolling in Real Time

Hidden Papyrus Test Mode Exposes Automated Clicking and Scrolling in Real Time

CYBER ATTACKZerowl

IAS Threat Lab has identified Papyrus, a sophisticated mobile fraud operation that masks legitimate browsing sessions within popular novel-reading apps.

Hackers Can Leverage WSUS Servers to Deliver Malware and Compromise Enterprise Endpoints

Hackers Can Leverage WSUS Servers to Deliver Malware and Compromise Enterprise Endpoints

CYBER ATTACKZerowl

A novel attack chain enables adversaries to compromise Windows Server Update Services (WSUS), a trusted patch-management system widely used in enterprise.

Fake Roblox Cheat Streams Victims’ Desktops Every 500 Milliseconds

Fake Roblox Cheat Streams Victims’ Desktops Every 500 Milliseconds

CYBER ATTACKZerowl

A deceptive cyberattack is targeting Roblox users with a fake "undetected" version of an Xeno script executor This article explores environments malware.

Extension Confusion Lets Attackers Hijack Trusted Names Across VS Code Registries

Extension Confusion Lets Attackers Hijack Trusted Names Across VS Code Registries

CYBER ATTACKZerowl

Discover how A coordinated operation utilized 77 counterfeit VS Code extensions to gather developer and CI environment data through Open VSX. The packages.

Enterprise Java Flaws Enable Pre-Auth RCE in Bonita BPM and Apache OFBiz

Enterprise Java Flaws Enable Pre-Auth RCE in Bonita BPM and Apache OFBiz

CYBER ATTACKZerowl

A newly disclosed set of 12 vulnerabilities impacting four enterprise Java platforms, including pre-authentication flaws and a sandbox escape. Presented.

Critical Paperclip AI Flaws Enable Unauthenticated RCE and Agent Takeover

Critical Paperclip AI Flaws Enable Unauthenticated RCE and Agent Takeover

CYBER ATTACKZerowl

A newly disclosed three critical and high-severity vulnerabilities in Paperclip, an open-source control plane used to orchestrate autonomous "zero-human.

Critical Jenkins Vulnerability Allows Attackers to Execute Malicious Code on Controller

Critical Jenkins Vulnerability Allows Attackers to Execute Malicious Code on Controller

CYBER ATTACKZerowl

Jenkins has reported a significant security flaw that can enable attackers to run malicious code on the Jenkins controller by circumventing a security.

Critical Cisco SD-WAN Vulnerabilities Enable Access Control Bypass and Path Traversal

Critical Cisco SD-WAN Vulnerabilities Enable Access Control Bypass and Path Traversal

CYBER ATTACKZerowl

Cisco has released critical updates to harden Cisco Catalyst SD-WAN Software, addressing multiple vulnerabilities that could allow authenticated attackers.

Cloudflare Introduces Open-Source AI Agent OS to Stop Data Leaks With Gatekeepers

Cloudflare Introduces Open-Source AI Agent OS to Stop Data Leaks With Gatekeepers

CYBER ATTACKZerowl

Cloudflare introduces Cloudflare OS, an open-source platform designed for enterprises to securely deploy AI agents, connected applications, and automated.

Claude in Chrome Prompt Injection Flaw Enables Slack, X, and Claude.ai Account Takeovers

Claude in Chrome Prompt Injection Flaw Enables Slack, X, and Claude.ai Account Takeovers

CYBER ATTACKZerowl

An indirect prompt-injection vulnerability in Claude within a Chrome browser can be linked to account takeovers affecting Slack, X, and Claude.ai This.

Cisco Patches Critical IOS XE Vulnerabilities Enabling Remote Code Execution

Cisco Patches Critical IOS XE Vulnerabilities Enabling Remote Code Execution

CYBER ATTACKZerowl

Cisco has released a security update for IOS XE Software, addressing seven vulnerabilities found internally, including a critical flaw rated CVSS 9.8 that.

Cisco Patched Multiple Critical Vulnerabilities in Catalyst SD-WAN – Update Now

Cisco Patched Multiple Critical Vulnerabilities in Catalyst SD-WAN – Update Now

CYBER ATTACKZerowl

Cisco has implemented software hardening updates for its Catalyst SD-WAN Software following an internal security review that uncovered multiple critical.

CISA Warns of Active Exploitation Targeting JetBrains TeamCity Servers

CISA Warns of Active Exploitation Targeting JetBrains TeamCity Servers

CYBER ATTACKZerowl

The Cybersecurity and Infrastructure Security Agency (CISA) added a critical unauthenticated remote code execution flaw in JetBrains' TeamCity On-Premises.

ChainDrop Turns Stolen npm Tokens Into an Automated Package-Infection Engine

ChainDrop Turns Stolen npm Tokens Into an Automated Package-Infection Engine

CYBER ATTACKZerowl

A newly discovered npm supply-chain malware called ChainDrop is infecting packages with stolen developer credentials, turning it into an automated system.

Canadian Hacker Pleads Guilty to Stealing Billions of Records From 165 Cloud Customers

Canadian Hacker Pleads Guilty to Stealing Billions of Records From 165 Cloud Customers

CYBER ATTACKZerowl

Connor Riley Moucka, 26, of Kitchener, Ontario, was found guilty on August 5, 2026, for orchestrating a hacking and extortion scheme that compromised at.

Apple iCloud Private Relay WebKit Flaws Leak Users’ Real IP Addresses

Apple iCloud Private Relay WebKit Flaws Leak Users’ Real IP Addresses

CYBER ATTACKZerowl

Apple users who use iCloud Private Relay for enhanced online privacy might not fully secure their location data. New vulnerabilities in WebKit, the engine.

Anthropic, Google, and OpenAI Coding Agents Exposed to Zero-Privilege RCE

Anthropic, Google, and OpenAI Coding Agents Exposed to Zero-Privilege RCE

CYBER ATTACKZerowl

A newly disclosed critical flaw in AI coding-agent workflows from Anthropic, Google, and OpenAI could allow an unauthenticated attacker to exploit a.

$289 Greatness Phishing Kit Offers Ready-Made Lures and Microsoft 365 Token Theft

$289 Greatness Phishing Kit Offers Ready-Made Lures and Microsoft 365 Token Theft

CYBER ATTACKZerowl

Greatness' phishing-as-a-service (PhaaS) service has grown its toolkit, allowing cybercriminals to target Microsoft 365 accounts through sophisticated.

250+ macOS ClickFix Domains Use Browser Fingerprinting to Hide Atomic Stealer Attacks

250+ macOS ClickFix Domains Use Browser Fingerprinting to Hide Atomic Stealer Attacks

CYBER ATTACKZerowl

Atomic Stealer malware is being distributed via deceptive websites that mimic legitimate offerings. This tactic relies on psychological persuasion rather.

Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA

Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA

CYBER ATTACKZerowl

Three distinct Phishing-as-a-Service (PhaaS) platforms—Sneaky 2FA, EvilTokens, and EvilProxy—are actively targeting US organizations to steal Microsoft.

Top 5 this week

Page 10 of 61