CYBER ATTACK

FancyBear Server Exposure Reveals Stolen Credentials, 2FA Secrets and NATO-Linked Targets

FancyBear Server Exposure Reveals Stolen Credentials, 2FA Secrets and NATO-Linked Targets

CYBER ATTACKZerowl

FancyBear, a Russian state-linked hacking group, made a big mistake in operational security that gave security researchers an unusually clear picture of.

Critical Telnetd Vulnerability Enables Remote Attacker to Execute Arbitrary Code via Port 23

Critical Telnetd Vulnerability Enables Remote Attacker to Execute Arbitrary Code via Port 23

CYBER ATTACKZerowl

The GNU Inetutils telnetd daemon has a serious buffer overflow flaw. This flaw, which is tracked as CVE-2026-32746, lets an unauthenticated remote.

Apple WebKit flaw lets bad web content get around on iOS and macOS

Apple WebKit flaw lets bad web content get around on iOS and macOS

CYBER ATTACKZerowl

Apple WebKit Vulnerability Lets Bad Web Content Bypass on iOS and macOS Apple has released important security updates to fix a serious WebKit.

Vidar Stealer 2.0 Spreads Through Fake Game Cheats Promoted on GitHub and Reddit

Vidar Stealer 2.0 Spreads Through Fake Game Cheats Promoted on GitHub and Reddit

CYBER ATTACKZerowl

Vidar 2.0, a new version of the Vidar infostealer, is spreading quickly through hundreds of fake game cheat repositories on GitHub and targeted posts on.

Ubuntu Desktop Systems Vulnerability Enables Attackers to Gain Full Root Access

Ubuntu Desktop Systems Vulnerability Enables Attackers to Gain Full Root Access

CYBER ATTACKZerowl

Weaknesses in Ubuntu Desktop Systems A Local Privilege Escalation (LPE) flaw in default installations of Ubuntu Desktop 24.04 and later lets an attacker.

‘RegPwn’ Windows Registry Vulnerability Enables Full System Access to Attackers

‘RegPwn’ Windows Registry Vulnerability Enables Full System Access to Attackers

CYBER ATTACKZerowl

Discover how There is a security hole in the Windows Registry called RegPwn. The "RegPwn" (CVE-2026-24291) Windows vulnerability is a high-severity flaw.

OpenAI Launches GPT-5.4 Mini and Nano, Delivering Answers 2× Faster

OpenAI Launches GPT-5.4 Mini and Nano, Delivering Answers 2× Faster

CYBER ATTACKZerowl

OpenAI has released GPT-5.4 Mini and Nano, two small-footprint models that promise answers that are up to twice as fast as previous GPT-5 Mini models.

Microsoft Teams Support Call Leads to Quick Assist Compromise in New Vishing Attack

Microsoft Teams Support Call Leads to Quick Assist Compromise in New Vishing Attack

CYBER ATTACKZerowl

The Microsoft Detection and Response Team talks about a complex voice phishing (vishing) campaign that broke into a business setting in November 2025 This.

Malicious Telegram Download Site Pushes Multi-Stage Loader With In-Memory Execution

Malicious Telegram Download Site Pushes Multi-Stage Loader With In-Memory Execution

CYBER ATTACKZerowl

Discover how A fake Telegram download site is actively spreading dangerous malware by hiding a malicious installer as a real setup file. The site, which.

Diplomats and Critical Infrastructure Targeted In Boggy Serpens Spy Campaign

Diplomats and Critical Infrastructure Targeted In Boggy Serpens Spy Campaign

CYBER ATTACKZerowl

Boggy Serpens, also known as MuddyWater, is a cyberespionage group that is currently running hacking campaigns against targets all over the world. This.

Critical Telnetd Vulnerability Allows Remote Code Execution Attacks

Critical Telnetd Vulnerability Allows Remote Code Execution Attacks

CYBER ATTACKZerowl

A newly revealed serious security hole in GNU The telnetd daemon in Inetutils could let attackers who aren't logged in take full control of affected.

Critical FortiClient SQL Injection Vulnerability Enables Arbitrary Database Access

Critical FortiClient SQL Injection Vulnerability Enables Arbitrary Database Access

CYBER ATTACKZerowl

FortiClient SQL Injection flaw A serious SQL injection hole in Fortinet's FortiClient Endpoint Management Server (EMS). This serious flaw has a CVSS score.

Boggy Serpens Targets Diplomats and Critical Infrastructure in Multi-Wave Espionage Campaign

Boggy Serpens Targets Diplomats and Critical Infrastructure in Multi-Wave Espionage Campaign

CYBER ATTACKZerowl

The Iranian nation-state group Boggy Serpens, also known as MuddyWater, has greatly increased its cyberespionage activities This article explores.

Attackers Abuse Court Documents, GitHub Payloads to Infect Judicial Targets With COVERT RAT

Attackers Abuse Court Documents, GitHub Payloads to Infect Judicial Targets With COVERT RAT

CYBER ATTACKZerowl

A new wave of targeted attacks is quietly hitting Argentina's judicial system This article explores hitting argentina judicial. . They use fake court.

Apple WebKit Vulnerability Allows Malicious Content Bypass on iOS and macOS

Apple WebKit Vulnerability Allows Malicious Content Bypass on iOS and macOS

CYBER ATTACKZerowl

Apple has put out emergency security updates to fix a serious WebKit flaw that makes iPhone, iPad, and Mac users vulnerable to advanced web-based attacks.

Critical ‘RegPwn’ Vulnerability Lets Attackers Gain SYSTEM Access on Windows

Critical ‘RegPwn’ Vulnerability Lets Attackers Gain SYSTEM Access on Windows

CYBER ATTACKZerowl

MDSec researchers have revealed a new Windows vulnerability called "RegPwn" that lets attackers go from being a low-privileged user to having full SYSTEM.

Critical FortiClient SQL Injection Flaw Allows Unauthorized Database Access

Critical FortiClient SQL Injection Flaw Allows Unauthorized Database Access

CYBER ATTACKZerowl

A serious security hole in Fortinet's FortiClient Enterprise Management Server (EMS) is causing a lot of worry in business settings, especially those that.

Credential-Stealing npm Malware Found In Popular React Native Packages

Credential-Stealing npm Malware Found In Popular React Native Packages

CYBER ATTACKZerowl

Researchers found a coordinated supply chain attack on two popular React Native npm packages on March 16, 2026. The infected releases add an install-time.

AWS Bedrock AgentCore Flaw Enables Stealthy C2 Channels and Data Theft

AWS Bedrock AgentCore Flaw Enables Stealthy C2 Channels and Data Theft

CYBER ATTACKZerowl

Researchers have shown a way to get around the sandbox isolation of AWS Bedrock AgentCore Code Interpreter, which has raised serious concerns about a.

Glassworm Attacks Popular React Native Packages with npm Malware That Steals Credentials

Glassworm Attacks Popular React Native Packages with npm Malware That Steals Credentials

CYBER ATTACKZerowl

On March 16, 2026, a coordinated supply chain attack hit the developer community This article explores backdoored popular react. . A hacker known as.

UK’s Companies House WebFiling Flaw Exposed Private Director Data for Five Months

UK’s Companies House WebFiling Flaw Exposed Private Director Data for Five Months

CYBER ATTACKZerowl

The UK government's official business register, Companies House, has found a serious security hole in its WebFiling service This article explores agency.

To Beat Alert Overload, Stop Wasting Time on False Positives

To Beat Alert Overload, Stop Wasting Time on False Positives

CYBER ATTACKZerowl

Stop wasting time on false positives to avoid alert overload This article explores suspicious alerts prioritized. . At first glance, false positives in.

Simple Custom Font Rendering Can Poison ChatGPT, Claude, Gemini, and Other AI Systems

Simple Custom Font Rendering Can Poison ChatGPT, Claude, Gemini, and Other AI Systems

CYBER ATTACKZerowl

A new way to attack that takes advantage of a basic flaw in AI web assistants: the difference between what a browser shows a user and what an AI tool.

New Windows 11 25H2/24H2 Update Fixes Bluetooth Devices Visibility Issues

New Windows 11 25H2/24H2 Update Fixes Bluetooth Devices Visibility Issues

CYBER ATTACKZerowl

The Windows 11 25H2/24H2 Update fixes problems with Bluetooth devices not being able to see each other This article explores bluetooth fix microsoft.

New Alert: Hackers Hijack Corporate M365 Accounts with OAuth Device Codes

New Alert: Hackers Hijack Corporate M365 Accounts with OAuth Device Codes

CYBER ATTACKZerowl

Recently, ANY.RUN, a top provider of interactive malware analysis and threat intelligence solutions, has seen a rise in phishing activity that takes.

Kubernetes CSI Driver for NFS Vulnerability Lets Attackers Delete or Modify NFS Server Directories

Kubernetes CSI Driver for NFS Vulnerability Lets Attackers Delete or Modify NFS Server Directories

CYBER ATTACKZerowl

Kubernetes CSI Driver NFS Security Hole The Kubernetes Container Storage Interface (CSI) Driver for NFS has a path traversal vulnerability that could let.

Attackers Use SEO Poisoning and Signed Trojans to Steal VPN Credentials

Attackers Use SEO Poisoning and Signed Trojans to Steal VPN Credentials

CYBER ATTACKZerowl

Storm-2561 is a financially motivated hacker who has been stealing credentials since May 2025 This article explores storm 2561 uses. . They do this by.

Top 5 this week

Page 13 of 44