CYBER ATTACK

SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect

SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect

CYBER ATTACKZerowl

SILENTCONNECT is a new type of multi-stage malware loader that has been quietly attacking Windows computers since at least March 2025 This article.

Russian APT Exploits Zimbra XSS to Target Ukrainian Government in ‘Operation GhostMail’

Russian APT Exploits Zimbra XSS to Target Ukrainian Government in ‘Operation GhostMail’

CYBER ATTACKZerowl

A hacker linked to the Russian government has targeted a Ukrainian government agency with a cyberattack that takes advantage of a cross-site scripting.

Russian APT Exploits Zimbra XSS In GhostMail Attacks On Ukrainian Government

Russian APT Exploits Zimbra XSS In GhostMail Attacks On Ukrainian Government

CYBER ATTACKZerowl

Seqrite Labs has found a very specific phishing campaign called "Operation GhostMail." The attack took advantage of a Cross-Site Scripting (XSS) flaw in.

Critical Jenkins Vulnerabilities Enable Remote Code Execution on CI/CD Servers

Critical Jenkins Vulnerabilities Enable Remote Code Execution on CI/CD Servers

CYBER ATTACKZerowl

The Jenkins project has sent out a critical security warning about several flaws in its core automation server and the LoadNinja plugin. These flaws make.

Critical Bamboo Data Center Vulnerability Enables Remote Code Execution

Critical Bamboo Data Center Vulnerability Enables Remote Code Execution

CYBER ATTACKZerowl

Atlassian has fixed a serious remote code execution (RCE) flaw in its Bamboo Data Center platform, which is a popular tool for continuous integration and.

CISA Warns of Cisco Firewall 0-Day Exploited in Ransomware Attacks

CISA Warns of Cisco Firewall 0-Day Exploited in Ransomware Attacks

CYBER ATTACKZerowl

CISA has sent out an urgent warning to businesses about a serious zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) and Cisco.

Authorities Disrupt IoT Botnet Infrastructure Behind Record-Breaking 30 Tbps DDoS Attacks

Authorities Disrupt IoT Botnet Infrastructure Behind Record-Breaking 30 Tbps DDoS Attacks

CYBER ATTACKZerowl

Authorities Mess Up IoT Authorities have successfully taken down the command-and-control (C2) networks that run four huge Internet of Things (IoT) botnets.

Aura Confirms Data Breach Impacting 900,000 Consumer Records

Aura Confirms Data Breach Impacting 900,000 Consumer Records

CYBER ATTACKZerowl

Aura, a company that provides digital security, has confirmed that a targeted social engineering attack led to a data breach that affected about 900,000.

Apex is an AI-powered pentester that attacks apps in black-box mode to find weaknesses.

Apex is an AI-powered pentester that attacks apps in black-box mode to find weaknesses.

CYBER ATTACKZerowl

Apex AI Penetration Testing Agent Apex is an AI-powered penetration testing agent that can work on its own and test live apps in black-box mode. It.

Open Directory Leak Reveals Iran-Linked 15-Node Relay Network

Open Directory Leak Reveals Iran-Linked 15-Node Relay Network

CYBER ATTACKZerowl

Threat actors sometimes make mistakes in operational security that put their whole work environment at risk This article explores relay infrastructure.

Malicious ‘Pyronut’ Package Backdoors Telegram Bots With Remote Code Execution

Malicious ‘Pyronut’ Package Backdoors Telegram Bots With Remote Code Execution

CYBER ATTACKZerowl

Discover how The Python Package Index (PyPI) has found a malicious Python package called pyronut that pretends to be the popular pyrogram framework and.

Horabot Banking Trojan Resurfaces in Mexico With Multi-Stage Phishing and Email Worm Tactics

Horabot Banking Trojan Resurfaces in Mexico With Multi-Stage Phishing and Email Worm Tactics

CYBER ATTACKZerowl

Discover how Horabot, a well-known banking trojan, is back in an active campaign that is targeting users all over Mexico. It uses a multi-stage infection.

Claude Vulnerabilities Allow Data Exfiltration and User Redirection to Malicious Sites

Claude Vulnerabilities Allow Data Exfiltration and User Redirection to Malicious Sites

CYBER ATTACKZerowl

Claude Vulnerabilities Steal Private Information and Send Users to Bad Websites Three linked flaws in Claude.ai, Anthropic's popular AI assistant, let.

CISA Tells Businesses to Protect Microsoft Intune After Stryker Breach

CISA Tells Businesses to Protect Microsoft Intune After Stryker Breach

CYBER ATTACKZerowl

The U.S This article explores misuse endpoint management. . Cybersecurity and Infrastructure Security Agency (CISA) has sent out a new warning telling.

WaterPlum Deploys New ‘StoatWaffle’ Malware in VSCode-Based Supply Chain Campaign

WaterPlum Deploys New ‘StoatWaffle’ Malware in VSCode-Based Supply Chain Campaign

CYBER ATTACKZerowl

WaterPlum, a hacking group linked to North Korea, has released a new piece of malware called StoatWaffle This article explores waterplum hacking group.

New SnappyClient Implant Enables Remote Access, Data Theft, and Stealth

New SnappyClient Implant Enables Remote Access, Data Theft, and Stealth

CYBER ATTACKZerowl

In December 2025, security researchers at Zscaler ThreatLabz found a new command-and-control (C2) framework implant called SnappyClient This article.

New SnappyClient Implant Combines Remote Access, Data Theft and Advanced Evasion

New SnappyClient Implant Combines Remote Access, Data Theft and Advanced Evasion

CYBER ATTACKZerowl

Discover how A new piece of malware called SnappyClient is a big threat to Windows users. It combines remote access, data theft, and advanced evasion.

Malware Operators Hijack Network Devices For DDoS Attacks and Crypto Mining

Malware Operators Hijack Network Devices For DDoS Attacks and Crypto Mining

CYBER ATTACKZerowl

As hackers focus more on network infrastructure instead of traditional endpoints, the attack surface of businesses is changing quickly. Researchers in the.

Iran-Linked Cyber Operations Merge With Electronic Warfare As Regional Tensions Surge

Iran-Linked Cyber Operations Merge With Electronic Warfare As Regional Tensions Surge

CYBER ATTACKZerowl

A joint US-Israeli military operation began strikes inside Iran on February 28, 2026 This article explores world cyber escalation. . This started a huge.

Iran-Linked Botnet Exposed After Open Directory Leak Reveals 15-Node Relay Network

Iran-Linked Botnet Exposed After Open Directory Leak Reveals 15-Node Relay Network

CYBER ATTACKZerowl

Discover how A threat actor with ties to Iran has had their entire working infrastructure exposed after carelessly leaving an open directory on their own.

Hackers Exploit OpenWebUI Servers to Deploy AI-Powered Payloads

Hackers Exploit OpenWebUI Servers to Deploy AI-Powered Payloads

CYBER ATTACKZerowl

Hackers are using poorly set up OpenWebUI servers to spread AI-generated payloads that steal credentials and mine cryptocurrency on both Linux and Windows.

Claude Vulnerabilities Allow Data Exfiltration and Malicious Redirects

Claude Vulnerabilities Allow Data Exfiltration and Malicious Redirects

CYBER ATTACKZerowl

Security researchers have revealed a serious multi-stage attack chain that affects Anthropic's Claude.ai platform This article explores redirect.

CISA Warns of Microsoft SharePoint Vulnerability Exploited in Attacks

CISA Warns of Microsoft SharePoint Vulnerability Exploited in Attacks

CYBER ATTACKZerowl

CISA warns that Microsoft SharePoint is vulnerable to attacks A serious security hole in Microsoft SharePoint has been found to be actively used, and on.

Backdoored Open VSX Extension Used GitHub Downloader to Install RAT and Stealer

Backdoored Open VSX Extension Used GitHub Downloader to Install RAT and Stealer

CYBER ATTACKZerowl

A well-known code editor extension on the Open VSX registry was found to have hidden malware that quietly downloads and runs a remote access trojan (RAT).

UIDAI Launches Bug Bounty Programme to Strengthen Aadhaar Security

UIDAI Launches Bug Bounty Programme to Strengthen Aadhaar Security

CYBER ATTACKZerowl

UIDAI Bug Bounty Program Makes Aadhaar More Secure The Unique Identification Authority of India (UIDAI) has officially started its first organized Bug.

UIDAI Launches Bug Bounty Program to Boost Aadhaar Security

UIDAI Launches Bug Bounty Program to Boost Aadhaar Security

CYBER ATTACKZerowl

The Unique Identification Authority of India (UIDAI) has started its first structured bug bounty program as part of its ongoing work to make the Aadhaar.

ScreenConnect Vulnerability Allows Hackers to Extract Unique Machine Keys and Hijack Sessions

ScreenConnect Vulnerability Allows Hackers to Extract Unique Machine Keys and Hijack Sessions

CYBER ATTACKZerowl

ConnectWise has sent out an urgent security alert for its ScreenConnect remote desktop software This article explores keys screenconnect vulnerability.

New Malware Campaigns Turn Network Devices Into DDoS Nodes and Crypto-Mining Bots

New Malware Campaigns Turn Network Devices Into DDoS Nodes and Crypto-Mining Bots

CYBER ATTACKZerowl

Another blow to network security. Two new types of malware have appeared that can quietly turn routers, IoT devices, and enterprise network equipment into.

LeakNet Scales Ransomware Operations With ClickFix Lures and Stealthy Deno Loader

LeakNet Scales Ransomware Operations With ClickFix Lures and Stealthy Deno Loader

CYBER ATTACKZerowl

LeakNet is a ransomware group that has been quietly working on a more dangerous way to attack This article explores leaknet ransomware. . The group used.

ForceMemo Hijacks GitHub Accounts, Backdoors Hundreds of Python Repos via Force-Push

ForceMemo Hijacks GitHub Accounts, Backdoors Hundreds of Python Repos via Force-Push

CYBER ATTACKZerowl

ForceMemo is a new malware campaign that is quietly hacking hundreds of GitHub accounts and adding hidden harmful code to Python repositories, leaving.

Top 5 this week

Page 12 of 44