CYBER ATTACK

ZerOwl — Find Vulnerabilities Before Hackers Do
Critical cPanel Vulnerability Allows Execution of SQL Commands as Root User

Critical cPanel Vulnerability Allows Execution of SQL Commands as Root User

CYBER ATTACKZerowl

A critical privilege-escalation flaw has been identified in cPanel & WHM that could enable authenticated hosting users to execute arbitrary SQL commands.

Critical Adobe Campaign Flaws Let Unauthenticated Attackers Execute Arbitrary Code

Critical Adobe Campaign Flaws Let Unauthenticated Attackers Execute Arbitrary Code

CYBER ATTACKZerowl

Adobe has issued an urgent security update for Adobe Campaign Classic (ACC), following the revelation of multiple critical vulnerabilities that could.

CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks

CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks

CYBER ATTACKZerowl

The U.S This article explores cisa announced vulnerability. . CISA announced that this vulnerability is being actively exploited and urged organizations.

Botnet Is Hunting Router Ping Tools That Can Turn User Input Into Shell Commands

Botnet Is Hunting Router Ping Tools That Can Turn User Input Into Shell Commands

CYBER ATTACKZerowl

A botnet campaign is probing routers for weak spots in diagnostic features This article explores commands suggesting botnet. . Similar exposure from older.

BINDCLOAK Steals Windows User and Process Tokens to Run Malware With Higher Privileges

BINDCLOAK Steals Windows User and Process Tokens to Run Malware With Higher Privileges

CYBER ATTACKZerowl

A newly discovered Windows backdoor named BINDCLOAK is providing a stealthy method for an East Asia-linked espionage operation to enhance its presence.

Apache NiFi Vulnerabilities Enable Authorization Bypass Attacks

Apache NiFi Vulnerabilities Enable Authorization Bypass Attacks

CYBER ATTACKZerowl

Apache NiFi users should upgrade to version 2.11.0 following the project's disclosure of four security vulnerabilities impacting the NiFi Web API and.

Apache NiFi Vulnerabilities Allow Authorization Bypass and Remote Code Execution

Apache NiFi Vulnerabilities Allow Authorization Bypass and Remote Code Execution

CYBER ATTACKZerowl

Apache NiFi has identified four security vulnerabilities impacting its web API, including authorization-bypass flaws, remote code execution potential, and.

A Malicious GitHub Issue Could Turn Google’s AI Agent Against Its Own CI/CD Pipeline

A Malicious GitHub Issue Could Turn Google’s AI Agent Against Its Own CI/CD Pipeline

CYBER ATTACKZerowl

A groundbreaking practical demonstration of an innovative attack method within a live multi-agent system showcases how one AI agent can exploit another to.

7-Zip Leaves Extracted Malware Without Mark-of-the-Web, Bypassing Windows SmartScreen

7-Zip Leaves Extracted Malware Without Mark-of-the-Web, Bypassing Windows SmartScreen

CYBER ATTACKZerowl

A 7-Zip vulnerability can cause malware extracted from a specially crafted archive to lose Windows' Mark-of-the-Web (MotW) label. This issue has been.

1-Click RCE Flaw in Cursor, VS Code, and Google Antigravity Exposes 50M Developers to Cyberattacks

1-Click RCE Flaw in Cursor, VS Code, and Google Antigravity Exposes 50M Developers to Cyberattacks

CYBER ATTACKZerowl

A critical one-click remote code execution (RCE) vulnerability affects three of the world's most widely used code editors: Cursor, Microsoft Visual Studio.

Shai-Hulud npm Worm Compromises 868 Packages With Over 2 Billion Monthly Installs

Shai-Hulud npm Worm Compromises 868 Packages With Over 2 Billion Monthly Installs

CYBER ATTACKZerowl

Shai-Hulud strikes again: Keyv compromised in new npm supply chain campaign affecting at least 868 packages with 2 billion monthly installs Attackers used.

Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites

Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites

CYBER ATTACKZerowl

The Russian-speaking hacker has been associated with a large-scale operation that has targeted organizations around the world from education, healthcare.

Roblox Malware Streams Victims’ Desktops and Captures Webcam Footage

Roblox Malware Streams Victims’ Desktops and Captures Webcam Footage

CYBER ATTACKZerowl

A popular shortcut has been turned into a serious privacy threat by a malicious campaign of Roblox cheats This article explores malicious campaign roblox.

OWASP Subtractive Security Top 10 Project Released to Identify and Reduce Cyber Risks

OWASP Subtractive Security Top 10 Project Released to Identify and Reduce Cyber Risks

CYBER ATTACKZerowl

OWASP has developed the Subtractive Security Top 10 Project, a security project that aims to remove vulnerabilities, rather than just detect them This.

OpenAI Scam Network May Have Engaged Hundreds of Targets Across Multiple Fraud Schemes

OpenAI Scam Network May Have Engaged Hundreds of Targets Across Multiple Fraud Schemes

CYBER ATTACKZerowl

The operation may have targeted hundreds of targets and some reports indicated individual victims lost thousands of dollars, the firm said This article.

New Phishing Trends: How SOC Leaders Should Respond

New Phishing Trends: How SOC Leaders Should Respond

CYBER ATTACKZerowl

New Phishing Trends Modern phishing has evolved by leveraging legitimate authentication workflows, trusted infrastructure and encrypted browser sessions.

Joyfill npm Credential Stealer Targets GitHub Tokens, Browser Passwords and Crypto Wallets

Joyfill npm Credential Stealer Targets GitHub Tokens, Browser Passwords and Crypto Wallets

CYBER ATTACKZerowl

July 28, 2026: malicious beta releases of legitimate Joyfill npm packages @joyfill/components and @joyfill/layouts leaked, containing a sophisticated.

How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways

How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways

CYBER ATTACKZerowl

Phishing remains the most common initial access method, accounting for 16% of breaches with an average cost of $4.8 million This article explores phishing.

Hackers Can Weaponize Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers

Hackers Can Weaponize Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers

CYBER ATTACKZerowl

A new proof-of-concept exposes how hackers can leverage Microsoft Copilot in their business email compromise (BEC) and large-scale wire fraud attacks. The.

DarkSword iOS Exploit Kit Spreads Across 180 Web Properties and 27 Hosts

DarkSword iOS Exploit Kit Spreads Across 180 Web Properties and 27 Hosts

CYBER ATTACKZerowl

DarkSword has expanded its operations from a leaked iOS exploit chain into a comprehensive network of malicious web infrastructure. The campaign targets.

Airlock Digital Unveils Agentic AI Control & Governance to Extend Preventative Endpoint Security

Airlock Digital Unveils Agentic AI Control & Governance to Extend Preventative Endpoint Security

CYBER ATTACKZerowl

Airlock Digital unveils Agentic AI Control & Governance at Black Hat USA 2026, expanding its preventative endpoint security solution with insights into.

Six Flowise RCE Flaws Let Attackers Execute Code on AI Workflow Servers

Six Flowise RCE Flaws Let Attackers Execute Code on AI Workflow Servers

CYBER ATTACKZerowl

Flowise's servers are vulnerable to six newly disclosed remote code execution vulnerabilities This article explores flowise servers vulnerable. . These.

Public PoC Released for CUPS Vulnerability Allows Attackers to Gain Root Privileges

Public PoC Released for CUPS Vulnerability Allows Attackers to Gain Root Privileges

CYBER ATTACKZerowl

A public proof-of-concept (PoC) has been released for CVE-2026-39875, an macOS vulnerability in the Common UNIX Printing System (CUPS) that enables an.

PLA-Linked Researchers Use Distilled U.S. AI for Surveillance, Drones and Battlefield Tasks

PLA-Linked Researchers Use Distilled U.S. AI for Surveillance, Drones and Battlefield Tasks

CYBER ATTACKZerowl

Chinese researchers affiliated with the People's Liberation Army (PLA) are reportedly utilizing leading U.S This article explores model officials ai.

OWASP Subtractive Security Top 10 Prioritizes Removing Attack Paths Over Monitoring

OWASP Subtractive Security Top 10 Prioritizes Removing Attack Paths Over Monitoring

CYBER ATTACKZerowl

The OWASP has unveiled the Subtractive Security Top 10, an innovative engineering initiative that pivots cybersecurity strategy from detection to outright.

OpenAI Reveals How Cybercriminals are Using ChatGPT to Run Scam Operation

OpenAI Reveals How Cybercriminals are Using ChatGPT to Run Scam Operation

CYBER ATTACKZerowl

Online scams are evolving into more sophisticated schemes with AI-driven tactics This article explores openai discloses cybercriminals. . Criminal groups.

North Korean Hackers Are Hiding Malware Servers Inside Empty Crypto Transfers

North Korean Hackers Are Hiding Malware Servers Inside Empty Crypto Transfers

CYBER ATTACKZerowl

North Korean-linked attackers are employing a novel method to conceal servers that control malware. This approach embeds a command server address within.

New Passkey Attacks Let Malware Take Over Google Accounts Without User Interaction

New Passkey Attacks Let Malware Take Over Google Accounts Without User Interaction

CYBER ATTACKZerowl

Malicious software lurking on compromised Windows PCs now has the capability to hijack Google’s synced passkeys without requiring any user input.

Top 5 this week

Page 12 of 61