CYBER ATTACK

ZerOwl — Find Vulnerabilities Before Hackers Do
$289 Greatness Phishing Kit Offers Ready-Made Lures and Microsoft 365 Token Theft

$289 Greatness Phishing Kit Offers Ready-Made Lures and Microsoft 365 Token Theft

CYBER ATTACKZerowl

Greatness' phishing-as-a-service (PhaaS) service has grown its toolkit, allowing cybercriminals to target Microsoft 365 accounts through sophisticated.

250+ macOS ClickFix Domains Use Browser Fingerprinting to Hide Atomic Stealer Attacks

250+ macOS ClickFix Domains Use Browser Fingerprinting to Hide Atomic Stealer Attacks

CYBER ATTACKZerowl

Atomic Stealer malware is being distributed via deceptive websites that mimic legitimate offerings. This tactic relies on psychological persuasion rather.

Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA

Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA

CYBER ATTACKZerowl

Three distinct Phishing-as-a-Service (PhaaS) platforms—Sneaky 2FA, EvilTokens, and EvilProxy—are actively targeting US organizations to steal Microsoft.

The Gentlemen Ransomware Affiliate Deploys EtherRAT via Ethereum Smart Contract C2

The Gentlemen Ransomware Affiliate Deploys EtherRAT via Ethereum Smart Contract C2

CYBER ATTACKZerowl

Discover how An exposed directory on 193.233.202[. ]17 has revealed a detailed intrusion toolkit linked to suspected affiliate of The Gentlemen ransomware.

QNET SOC Inherits Fully Contained Ransomware Incident After 128-Second Response

QNET SOC Inherits Fully Contained Ransomware Incident After 128-Second Response

CYBER ATTACKZerowl

In just 128 seconds following Microsoft Defender’s automatic isolation of a compromised endpoint, QNET’s security operations center experienced a.

Poison Claude is Selling Cheap AI Tokens Built on Fake Accounts and Free Credits

Poison Claude is Selling Cheap AI Tokens Built on Fake Accounts and Free Credits

CYBER ATTACKZerowl

Discover how A clandestine online service called Poison Claude is profiting from reselling Anthropic’s premium AI models for a substantial discount. This.

One-Click RCE Flaw in Cursor, VS Code, and Google Antigravity Enables Full System Compromise

One-Click RCE Flaw in Cursor, VS Code, and Google Antigravity Enables Full System Compromise

CYBER ATTACKZerowl

A critical one-click remote code execution (RCE) flaw has been identified across three of the world's most popular coding tools: Cursor, Microsoft Visual.

New OVSwrap Flaw Lets Unprivileged Users Corrupt Kernel Credentials and Gain Root

New OVSwrap Flaw Lets Unprivileged Users Corrupt Kernel Credentials and Gain Root

CYBER ATTACKZerowl

A newly disclosed Linux kernel vulnerability, known as OVSwrap, enables unprivileged local users to elevate their privileges by exploiting an integer.

Mythos 5 and GPT-5.6-Sol Agents Went Beyond Their Cyber Test and Targeted the Real World

Mythos 5 and GPT-5.6-Sol Agents Went Beyond Their Cyber Test and Targeted the Real World

CYBER ATTACKZerowl

The UK's AI Security Institute (AISI) revealed a significant cybersecurity breach involving AI agents testing on the live internet. Between July 25-28.

Multiple Veeam ONE Vulnerabilities Allow Code Execution Attacks

Multiple Veeam ONE Vulnerabilities Allow Code Execution Attacks

CYBER ATTACKZerowl

Veeam has released security updates for Veeam ONE 13.1 to address multiple vulnerabilities that could permit attackers to execute code, access sensitive.

Microsoft Awards Record $20 Million to 562 Researchers in Biggest Bug Bounty Year

Microsoft Awards Record $20 Million to 562 Researchers in Biggest Bug Bounty Year

CYBER ATTACKZerowl

Microsoft has awarded over $20 million to 562 cybersecurity experts through its bug bounty program, setting a new record in company history. The Microsoft.

Hackers Turned Microsoft Logins, Zoom Events, and Government Websites Into Attack Tools

Hackers Turned Microsoft Logins, Zoom Events, and Government Websites Into Attack Tools

CYBER ATTACKZerowl

Hackers Leveraged Trustworthy Platforms for Attack Tools In July 2026, cybercriminals demonstrated their capability by exploiting legitimate business.

Hackers Are Turning Trusted ScreenConnect Software Into a Cross-Platform Remote Access Backdoor

Hackers Are Turning Trusted ScreenConnect Software Into a Cross-Platform Remote Access Backdoor

CYBER ATTACKZerowl

The campaign employs fake Zoom updates, business-document attachments, system-check tools, and Adobe update pages to trick users into installing.

Greatness PhaaS Bypasses Email Security and MFA to Hijack Microsoft 365 Accounts

Greatness PhaaS Bypasses Email Security and MFA to Hijack Microsoft 365 Accounts

CYBER ATTACKZerowl

Gloriousness has surfaced as a phishing-as-a-service platform aimed at stealing Microsoft 365 access during times when organizations mistakenly believe.

Google Blogger Locked Legitimate Websites After Mistaking Them for Malware

Google Blogger Locked Legitimate Websites After Mistaking Them for Malware

CYBER ATTACKZerowl

Thousands of legitimate Blogger website owners were abruptly locked out this week due to a widespread error by Google's automated content-scanning systems.

Django Urges Immediate Upgrade to 6.0.8 and 5.2.17 After Four Security Fixes

Django Urges Immediate Upgrade to 6.0.8 and 5.2.17 After Four Security Fixes

CYBER ATTACKZerowl

Discover how The Django development team has released updates for versions 6.0.8 and 5.2.17 to address four security vulnerabilities in supported Python.

7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen

7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen

CYBER ATTACKZerowl

Windows can safeguard users against suspicious downloads before they run This article explores downloads run zip. . ZIP archives are frequently used in.

45% of C2-Active Malware Bypasses DNS With Direct-to-IP Connections

45% of C2-Active Malware Bypasses DNS With Direct-to-IP Connections

CYBER ATTACKZerowl

Nearly half of malware exhibiting command-and-control traffic connect directly to IP addresses rather than using domain names, as revealed by Unit 42.

15 TP-Link Omada ZTP Flaws Enable Router Hijacking and Root Code Execution

15 TP-Link Omada ZTP Flaws Enable Router Hijacking and Root Code Execution

CYBER ATTACKZerowl

A collection of 15 vulnerabilities in TP-Link’s Omada Zero-Touch Provisioning (ZTP) could allow for attacks on enterprise networks, according to findings.

PoC Exploit Released for macOS CUPS Root Privilege Escalation Flaw

PoC Exploit Released for macOS CUPS Root Privilege Escalation Flaw

CYBER ATTACKZerowl

A proof-of-concept exploit has been released for CVE-2026-39875, a macOS CUPS local privilege-escalation vulnerability that allows an unprivileged user to.

Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds With Automatic Device Isolation

Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds With Automatic Device Isolation

CYBER ATTACKZerowl

Ransomware can quickly escalate into a widespread crisis when attackers leverage trusted Windows tools, such as mshta.exe, to initiate a second-stage.

Microsoft Copilot Flaw Lets Hackers Hijack CEO Accounts and Redirect Wire Transfers

Microsoft Copilot Flaw Lets Hackers Hijack CEO Accounts and Redirect Wire Transfers

CYBER ATTACKZerowl

A proof-of-concept attack demonstrates how a single compromised employee's inbox can escalate to a full CEO account takeover and business email compromise.

Keyv npm Package with 127M Weekly Downloads Compromised in Shai-Hulud Attack

Keyv npm Package with 127M Weekly Downloads Compromised in Shai-Hulud Attack

CYBER ATTACKZerowl

Attackers exploited the compromised GitHub account of keyv's maintainer to push credential-stealing malware across their entire package portfolio on npm.

Django Security Update Fixes Server-Side File Write, XSS, and DoS Flaws

Django Security Update Fixes Server-Side File Write, XSS, and DoS Flaws

CYBER ATTACKZerowl

Django 6.0.8 and 5.2.17 have been released, addressing four vulnerabilities: high-severity server-side file write issues to moderate XSS and low/moderate.

Critical cPanel Vulnerability Allows Execution of SQL Commands as Root User

Critical cPanel Vulnerability Allows Execution of SQL Commands as Root User

CYBER ATTACKZerowl

A critical privilege-escalation flaw has been identified in cPanel & WHM that could enable authenticated hosting users to execute arbitrary SQL commands.

Critical Adobe Campaign Flaws Let Unauthenticated Attackers Execute Arbitrary Code

Critical Adobe Campaign Flaws Let Unauthenticated Attackers Execute Arbitrary Code

CYBER ATTACKZerowl

Adobe has issued an urgent security update for Adobe Campaign Classic (ACC), following the revelation of multiple critical vulnerabilities that could.

CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks

CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks

CYBER ATTACKZerowl

The U.S This article explores cisa announced vulnerability. . CISA announced that this vulnerability is being actively exploited and urged organizations.

Top 5 this week

Page 11 of 61