CYBER ATTACK

CISA Warns of Craft CMS Code Injection Vulnerability Exploited in Attacks

CISA Warns of Craft CMS Code Injection Vulnerability Exploited in Attacks

CYBER ATTACKZerowl

The Known Exploited Vulnerabilities catalog now includes a serious flaw in Craft CMS (CVE-2025-32432) that has been confirmed to be actively used in the.

CISA Warns of Craft CMS Code Injection Flaw Exploited in the Wild

CISA Warns of Craft CMS Code Injection Flaw Exploited in the Wild

CYBER ATTACKZerowl

CISA has warned that a serious Craft CMS vulnerability, tracked as CVE-2025-35939, is now being actively exploited. This means that attackers who don't.

CISA Warns of Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain Exploited in Attacks

CISA Warns of Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain Exploited in Attacks

CYBER ATTACKZerowl

CISA warns that DarkSword iOS exploit chain is linked to Apple vulnerabilities. This is an urgent warning about three serious Apple vulnerabilities that.

$30 IP-KVM Flaws Could Let Attackers Control BIOS Across All Enterprise Networks

$30 IP-KVM Flaws Could Let Attackers Control BIOS Across All Enterprise Networks

CYBER ATTACKZerowl

Nine serious security holes have been found in four popular low-cost IP-KVM devices by researchers who recently did a security assessment. These holes.

New CanisterWorm Malware Targets npm Tokens In Supply Chain Campaign

New CanisterWorm Malware Targets npm Tokens In Supply Chain Campaign

CYBER ATTACKZerowl

Security experts have found a very advanced npm supply chain attack called CanisterWorm This article explores makes wormable threat. . The campaign, which.

Microsoft Emergency Out-of-Band Update for Windows 11 to Fix Microsoft Account Sign-In Failure

Microsoft Emergency Out-of-Band Update for Windows 11 to Fix Microsoft Account Sign-In Failure

CYBER ATTACKZerowl

Microsoft has released an out-of-band (OOB) update for Windows 11 versions 25H2 and 24H2, known as KB5085516, to fix a serious sign-in bug that was caused.

Cybercriminals Infect 7,500 Magento Stores With Hidden Malicious Files

Cybercriminals Infect 7,500 Magento Stores With Hidden Malicious Files

CYBER ATTACKZerowl

A huge campaign to deface websites has successfully hacked more than 7,500 unique Magento e-commerce domains, allowing unauthorized text files to be.

Crunchyroll Data Breach — Threat Actor Claims Exfiltration of 100 GB of User Data

Crunchyroll Data Breach — Threat Actor Claims Exfiltration of 100 GB of User Data

CYBER ATTACKZerowl

A hacker is said to have stolen about 100 GB of personally identifiable information (PII) from Crunchyroll, the Sony-owned anime streaming giant This.

Critical QNAP QVR Pro Flaw Allows Remote Attackers to Access Systems

Critical QNAP QVR Pro Flaw Allows Remote Attackers to Access Systems

CYBER ATTACKZerowl

QNAP has sent out an urgent security warning about a serious flaw in its QVR Pro app that could let attackers from outside the company get full access to.

$30 IP-KVM Flaws Put Businesses at Risk of BIOS-Level Attacks

$30 IP-KVM Flaws Put Businesses at Risk of BIOS-Level Attacks

CYBER ATTACKZerowl

A new wave of security research has found serious flaws in low-cost IP-KVM (Keyboard, Video, Mouse) devices, which is very worrying for businesses This.

Threat Actors Leverage Copyright-Themed Emails to Drop PureLog Stealer

Threat Actors Leverage Copyright-Themed Emails to Drop PureLog Stealer

CYBER ATTACKZerowl

Threat actors are using a complicated, multi-stage malware campaign to spread the PureLog Stealer This article explores malware campaign spread. . This.

Oracle Releases Urgent Patch for Critical RCE Flaw in Identity Manager and Web Services Manager

Oracle Releases Urgent Patch for Critical RCE Flaw in Identity Manager and Web Services Manager

CYBER ATTACKZerowl

Oracle recently sent out an urgent security alert about a serious Remote Code Execution (RCE) flaw that affects both Oracle Identity Manager and Oracle.

Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager

Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager

CYBER ATTACKZerowl

Oracle has sent out an out-of-band Security Alert about a serious remote code execution (RCE) vulnerability, CVE-2026-21992, that affects two widely used.

Windows 11 March Update Breaks Microsoft Teams and OneDrive Sign-Ins

Windows 11 March Update Breaks Microsoft Teams and OneDrive Sign-Ins

CYBER ATTACKZerowl

The March Update for Windows 11 Breaks Teams Microsoft has admitted that a major bug in its March 2026 cumulative update is stopping Windows 11 users from.

New VoidStealer Variant Bypasses Chrome ABE Without Injection or Privilege Escalation

New VoidStealer Variant Bypasses Chrome ABE Without Injection or Privilege Escalation

CYBER ATTACKZerowl

Discover how A new version of the VoidStealer infostealer has gotten a lot of attention from security experts because it was the first malware to get.

Hackers Compromised 7,500+ Magento Websites to Upload Hidden Malicious Files and Steal Data

Hackers Compromised 7,500+ Magento Websites to Upload Hidden Malicious Files and Steal Data

CYBER ATTACKZerowl

Since late February 2026, a large-scale cyberattack has affected more than 7,500 Magento-powered e-commerce sites This article explores attack magento.

Claude Cowork Desktops Anthropic Launches Projects Feature

Claude Cowork Desktops Anthropic Launches Projects Feature

CYBER ATTACKZerowl

Anthropic is adding a new Projects feature to Claude Cowork Desktop This article explores cowork desktop projects. . This feature will help you keep.

Ransomware Actors Expand EDR Killer Tactics Beyond Vulnerable Drivers

Ransomware Actors Expand EDR Killer Tactics Beyond Vulnerable Drivers

CYBER ATTACKZerowl

Ransomware attackers have come up with new ways to get around endpoint security that go beyond just taking advantage of weak drivers This article explores.

Perseus Android Malware Steals User Notes and Enables Full Device Takeover

Perseus Android Malware Steals User Notes and Enables Full Device Takeover

CYBER ATTACKZerowl

Perseus is a new Android banking trojan that has been found in the wild This article explores perseus new android. . It is the next step in the ongoing.

Navia Confirms Data Breach Exposing Sensitive Data of 2.7 Million Users

Navia Confirms Data Breach Exposing Sensitive Data of 2.7 Million Users

CYBER ATTACKZerowl

Navia Benefit Solutions has confirmed that a large-scale data breach has affected about 2.7 million people This article explores navia administered.

Navia Confirms Data Breach – 2.7 Million Users Sensitive Data Exposed

Navia Confirms Data Breach – 2.7 Million Users Sensitive Data Exposed

CYBER ATTACKZerowl

Data Breach at Navia A well-known U.S This article explores data breach navia. . benefits administrator that focuses on consumers has revealed a major.

Microsoft Unveils New Teams Optimizations for Windows App on iOS & Android

Microsoft Unveils New Teams Optimizations for Windows App on iOS & Android

CYBER ATTACKZerowl

Microsoft New Teams Optimizes Windows App on iOS and Android Microsoft has officially announced that new improvements to Microsoft Teams are now available.

Google Chrome Update Fixes 26 Security Flaws, Including RCE Vulnerabilities

Google Chrome Update Fixes 26 Security Flaws, Including RCE Vulnerabilities

CYBER ATTACKZerowl

Google has put out a new stable update for Chrome that fixes 26 security holes, including three serious bugs that could let remote code execution (RCE).

FBI, Thai Partners Target Southeast Asia Scam Centers Behind Cyber Fraud on Americans

FBI, Thai Partners Target Southeast Asia Scam Centers Behind Cyber Fraud on Americans

CYBER ATTACKZerowl

Discover how The fraud doesn't usually tell you it's there. It starts with a friendly message on social media, a text that goes to the wrong number and.

Fake Tools Fuel Vibe-Coded Malware Campaign Targeting Unsuspecting Users

Fake Tools Fuel Vibe-Coded Malware Campaign Targeting Unsuspecting Users

CYBER ATTACKZerowl

Discover how A big malware campaign is using fake software downloads to spread crypto miners, info-stealers, remote access tools, and other harmful.

Critical UNISOC T612 Modem Flaw Enables RCE via Cellular Calls

Critical UNISOC T612 Modem Flaw Enables RCE via Cellular Calls

CYBER ATTACKZerowl

Discover how A serious memory corruption bug in UNISOC's T612 modem family lets hackers run code remotely (RCE) on weak Android devices with just a.

Critical Jenkins Vulnerabilities Expose CI/CD Servers to RCE Attacks

Critical Jenkins Vulnerabilities Expose CI/CD Servers to RCE Attacks

CYBER ATTACKZerowl

Jenkins flaws put CI/CD servers at risk A very important security advisory that talks about several very serious security holes in Jenkins core and the.

Cobra DocGuard Hijacked By Speagle Malware For Sensitive Data Theft

Cobra DocGuard Hijacked By Speagle Malware For Sensitive Data Theft

CYBER ATTACKZerowl

Researchers from Symantec and Carbon Black have found a new infostealer called Speagle that is hard to see This article explores speagle hard malware.

CISA says that the Cisco Secure Firewall Management Center 0-Day is being used in ransomware attacks.

CISA says that the Cisco Secure Firewall Management Center 0-Day is being used in ransomware attacks.

CYBER ATTACKZerowl

CISA warns about a 0-day exploit for Cisco Secure Firewall Management Center An urgent warning has been issued about a serious zero-day flaw in Cisco.

Attackers can run code on the Bamboo Data Center and Server because they are vulnerable.

Attackers can run code on the Bamboo Data Center and Server because they are vulnerable.

CYBER ATTACKZerowl

Vulnerability of Bamboo Data Center and Server Bamboo Data Center, a popular business platform for managing software builds and releases, has fixed a.

Top 5 this week

Page 11 of 44