CYBER ATTACK

Microsoft Exchange Online Mailbox Access Outage Affects Users Globally

Microsoft Exchange Online Mailbox Access Outage Affects Users Globally

CYBER ATTACKZerowl

Discover how Microsoft is looking into a service outage that is affecting Exchange Online users who are having trouble getting to their mailboxes through.

Konni APT Hijacks KakaoTalk Accounts to Spread Malware in Multi-Stage Spear-Phishing Campaign

Konni APT Hijacks KakaoTalk Accounts to Spread Malware in Multi-Stage Spear-Phishing Campaign

CYBER ATTACKZerowl

Konni APT, a threat group, has been caught running a multi-stage attack campaign that starts with targeted spear-phishing emails and ends with taking over.

Google Looker Studio Vulnerabilities Allow Attackers to Exfiltrate Data from Google Services

Google Looker Studio Vulnerabilities Allow Attackers to Exfiltrate Data from Google Services

CYBER ATTACKZerowl

A group of nine new cross-tenant vulnerabilities in Google Looker Studio, known as "LeakyLooker," could have let attackers run any SQL query, steal.

Betterleaks: New Open-Source Tool for Scanning Files, Directories, and Git Repositories

Betterleaks: New Open-Source Tool for Scanning Files, Directories, and Git Repositories

CYBER ATTACKZerowl

Discover how A new open-source tool for scanning secrets is called Zach Rice, who made the Gitleaks project that many people use, made Betterleaks.

Betterleaks – A New Open-Source Tool to Scan Directories, Files, and Git Repositories

Betterleaks – A New Open-Source Tool to Scan Directories, Files, and Git Repositories

CYBER ATTACKZerowl

Better leaks Scan Directories, Files, and Git Repositories with Open-Source Tool Betterleaks is a new open-source secrets scanner made by the same person.

Attackers Abuse Microsoft Teams and Quick Assist to Drop Stealthy A0Backdoor

Attackers Abuse Microsoft Teams and Quick Assist to Drop Stealthy A0Backdoor

CYBER ATTACKZerowl

Discover how A new backdoor called A0Backdoor has been found as part of a planned social-engineering campaign that takes advantage of Microsoft Teams and.

Android 17 Advanced Protection Mode to Block Malicious Service Usage

Android 17 Advanced Protection Mode to Block Malicious Service Usage

CYBER ATTACKZerowl

Advanced Protection Mode for Android 17 Google is getting ready to release Android 17, which will include a full set of new APIs and system features that.

ACRStealer Upgrades With Syscall Evasion and TLS-Based C2 In New Campaign

ACRStealer Upgrades With Syscall Evasion and TLS-Based C2 In New Campaign

CYBER ATTACKZerowl

Security researchers at Proofpoint have found that ACRStealer, a Malware-as-a-Service (MaaS), has gotten a lot of technical improvements This article.

Real-Time Phishing Campaigns Use Fake Shipment Alerts To Steal Banking Data In MEA

Real-Time Phishing Campaigns Use Fake Shipment Alerts To Steal Banking Data In MEA

CYBER ATTACKZerowl

In 2022, Statista says that more than 161 billion packages were sent around the world This article explores phishing fake shipment. . This shows that.

Indirect Prompt Injection Attacks Cause OpenClaw AI Agents to Leak Sensitive Data

Indirect Prompt Injection Attacks Cause OpenClaw AI Agents to Leak Sensitive Data

CYBER ATTACKZerowl

After a warning from China's National Computer Network Emergency Response Technical Team (CNCERT) about dangerous default settings and prompt-injection.

Google Looker Studio Vulnerabilities Enable Attackers to Exfiltrate Data from Google Services

Google Looker Studio Vulnerabilities Enable Attackers to Exfiltrate Data from Google Services

CYBER ATTACKZerowl

Google Looker Studio was affected by nine high‑impact “LeakyLooker” vulnerabilities that could have allowed attackers to exfiltrate or modify data across.

Android 17 launches Advanced Protection Mode to stop bad service exploits.

Android 17 launches Advanced Protection Mode to stop bad service exploits.

CYBER ATTACKZerowl

Android 17 is making Advanced Protection Mode a much stronger defense layer by actively blocking the use of harmful and misdeclared services, especially.

Microsoft Tracks Storm-2561 In Fake VPN Client Credential Theft Scheme

Microsoft Tracks Storm-2561 In Fake VPN Client Credential Theft Scheme

CYBER ATTACKZerowl

Microsoft says that a group of hackers it tracks as Storm-2561 is running a campaign to steal credentials by using fake VPN clients that are pushed.

Konni APT Uses Compromised KakaoTalk Accounts To Launch Multi-Stage Malware Attacks

Konni APT Uses Compromised KakaoTalk Accounts To Launch Multi-Stage Malware Attacks

CYBER ATTACKZerowl

The Konni Advanced Persistent Threat (APT) group has started a new malware distribution campaign that uses hacked KakaoTalk PC messenger accounts to.

Critical LangSmith Account Takeover Vulnerability Puts Users at Risk

Critical LangSmith Account Takeover Vulnerability Puts Users at Risk

CYBER ATTACKZerowl

Critical LangSmith Account Takeover Weakness Miggo Security researchers have found a serious flaw in LangSmith, known as CVE-2026-25750, that could let.

Authorities are cracking down on 45,000 malicious IPs that are powering ransomware attacks.

Authorities are cracking down on 45,000 malicious IPs that are powering ransomware attacks.

CYBER ATTACKZerowl

45000 Bad IPs Are Being Cracked Down on by Authorities Law enforcement agencies from 72 countries have successfully shut down more than 45,000 malicious.

A malicious npm campaign pretends to be Solara Executor in order to steal Discord and crypto wallet information.

A malicious npm campaign pretends to be Solara Executor in order to steal Discord and crypto wallet information.

CYBER ATTACKZerowl

Discover how A new cybersecurity threat has come from the npm ecosystem, where hackers were able to hide a complex information stealer inside packages.

Loblaw Data Breach: Hackers Gain Access to IT Network and Customer Data

Loblaw Data Breach: Hackers Gain Access to IT Network and Customer Data

CYBER ATTACKZerowl

Loblaw Companies Limited, one of Canada's biggest stores, has revealed a data breach after noticing strange activity on part of its internal IT network.

A serious LangSmith vulnerability lets someone take over your account completely.

A serious LangSmith vulnerability lets someone take over your account completely.

CYBER ATTACKZerowl

Discover how Critical LangSmith Vulnerability Account Takeover Researchers at Miggo Security have found a serious flaw (CVE-2026-25750) in LangSmith, a.

Veeam Patches Multiple Critical RCE Vulnerabilities on Backup Server

Veeam Patches Multiple Critical RCE Vulnerabilities on Backup Server

CYBER ATTACKZerowl

Veeam Fixes Security Holes on Backup Server Backup & Replication software has received an important security update that fixes serious flaws that could.

Salesforce Warns of ShinyHunters Group Exploiting Experience Cloud Sites

Salesforce Warns of ShinyHunters Group Exploiting Experience Cloud Sites

CYBER ATTACKZerowl

Salesforce Warns ShinyHunters: There is a serious threat campaign going on right now that is going after Experience Cloud sites that are not set up.

OpenSSH GSSAPI Vulnerability Allow an Attacker to Crash SSH Child Processes

OpenSSH GSSAPI Vulnerability Allow an Attacker to Crash SSH Child Processes

CYBER ATTACKZerowl

Many Linux distributions installed the GSSAPI Key Exchange patch on top of their OpenSSH packages, which had a major security hole This article explores.

Metasploit Pro 5.0.0 Released With Powerful New Modules and Critical Enhancements

Metasploit Pro 5.0.0 Released With Powerful New Modules and Critical Enhancements

CYBER ATTACKZerowl

Metasploit Pro 5.0.0 is out now This article explores metasploit pro centralized. . As hackers keep using new weaknesses to attack, the need for ongoing.

Critical CrackArmor Vulnerabilities Expose 12.6 Million Linux Servers to Complete Root Takeover

Critical CrackArmor Vulnerabilities Expose 12.6 Million Linux Servers to Complete Root Takeover

CYBER ATTACKZerowl

Nine serious security holes have been found in AppArmor, which is a widely used mandatory access control framework for Linux This article explores kernel.

Chrome Zero-Day Vulnerabilities Actively Exploited in the Wild to Execute Malicious Code

Chrome Zero-Day Vulnerabilities Actively Exploited in the Wild to Execute Malicious Code

CYBER ATTACKZerowl

Google has put out an emergency security update for its Chrome browser after confirming that two high-severity zero-day vulnerabilities are being used in.

TA453 and TA473 Drive Iran War-Themed Phishing Across The Middle East

TA453 and TA473 Drive Iran War-Themed Phishing Across The Middle East

CYBER ATTACKZerowl

Discover how The conflict around Iran is now shaping cyber espionage across the region. Since the start of the war in late February 2026, security.

PowerShell and PsExec Used To Steal Data Before INC Ransomware Attack

PowerShell and PsExec Used To Steal Data Before INC Ransomware Attack

CYBER ATTACKZerowl

Recently, Huntress's cybersecurity researchers saw threat actors using INC ransomware after a complicated process of stealing data This article explores.

Handala Expands Destructive Cyber Operations Beyond Israeli Targets

Handala Expands Destructive Cyber Operations Beyond Israeli Targets

CYBER ATTACKZerowl

Handala, an Iranian-linked threat group, is behind a growing number of destructive wiper attacks that are threatening businesses in the US and Israel This.

Top 5 this week

Page 15 of 44