CYBER ATTACK

ZerOwl — Find Vulnerabilities Before Hackers Do
Hackers Turned a Trusted Advertising Platform Into a Crypto-Stealer Delivery Network

Hackers Turned a Trusted Advertising Platform Into a Crypto-Stealer Delivery Network

CYBER ATTACKZerowl

Adform, a prominent advertising technology firm serving approximately 14,000 businesses and controlling nearly 30% of the demand-side platform market, has.

HackerOne Mandates ID Verification for Bug Bounty Submissions

HackerOne Mandates ID Verification for Bug Bounty Submissions

CYBER ATTACKZerowl

HackerOne has confirmed that all hackers must now complete identity verification before submitting reports to any bug bounty program (BBP) on its.

FBI And Allies Warn of North Korean IT Workers Using Stolen Identities

FBI And Allies Warn of North Korean IT Workers Using Stolen Identities

CYBER ATTACKZerowl

The U.S., FBI, and allied nations including Japan, Canada, Germany, Australia, the UK, and South Korea have issued a joint alert warning companies.

DeepSeek-Powered Hermes Agent Launches Autonomous Cyberattacks Against Exposed Servers

DeepSeek-Powered Hermes Agent Launches Autonomous Cyberattacks Against Exposed Servers

CYBER ATTACKZerowl

A Chinese-speaking threat actor employed an AI-driven agent to search for vulnerable internet-facing servers and initiate attacks with minimal direct.

Brinks Home Confirms Data Breach Following ShinyHunters Claim

Brinks Home Confirms Data Breach Following ShinyHunters Claim

CYBER ATTACKZerowl

Brinks Home confirms a breach in its IT systems following ShinyHunters' claim to have stolen nearly five million records from their Salesforce environment.

Arch Linux Disables AUR Package Takeovers as Attackers Push Malicious Commits

Arch Linux Disables AUR Package Takeovers as Attackers Push Malicious Commits

CYBER ATTACKZerowl

Arch Linux temporarily halted package adoption on its Arch User Repository (AUR) following security teams' detection of malicious takeovers and follow-up.

Your Incident Response Plan Has a Dependency You Never Approved

Your Incident Response Plan Has a Dependency You Never Approved

CYBER ATTACKZerowl

During a publicly documented first instance of an agent-driven intrusion, defenders were unable to utilize commercial AI models for analysis due to.

SSH Bot Profiles Linux CPU, GPU and RAM Before Deploying Cryptocurrency Miner

SSH Bot Profiles Linux CPU, GPU and RAM Before Deploying Cryptocurrency Miner

CYBER ATTACKZerowl

A newly discovered SSH bot silently gains unauthorized access to Linux systems by profiling CPU, GPU, and memory usage before exiting without leaving any.

ShutterGap Exposes Millions of AWS Resources Between Cloud Security Scans

ShutterGap Exposes Millions of AWS Resources Between Cloud Security Scans

CYBER ATTACKZerowl

Cloud security teams frequently use Cloud Security Posture Management (CSPM) and Cloud-Native Application Protection Platform (CNAPP) tools to identify.

NVIDIA, Microsoft and CrowdStrike Launch Open Secure AI Alliance

NVIDIA, Microsoft and CrowdStrike Launch Open Secure AI Alliance

CYBER ATTACKZerowl

NVIDIA, Microsoft, CrowdStrike, and over 30 industry leaders have formed the Open Secure AI Alliance, an initiative aimed at creating and sharing.

North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials

North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials

CYBER ATTACKZerowl

A sophisticated cyberattack orchestrated by North Korea targets cryptocurrency wallets, browser data, and developer credentials through deceptive macOS.

MacSync Stealer RAT Targets macOS With Credential Theft and Remote Access Capabilities

MacSync Stealer RAT Targets macOS With Credential Theft and Remote Access Capabilities

CYBER ATTACKZerowl

A newly disclosed macOS threat known as MacSync integrates credential theft, keychain harvesting, and a native remote access trojan into a single.

Large-Scale Campaign Impersonates 70 Windows Apps With Fake Malware Download Sites

Large-Scale Campaign Impersonates 70 Windows Apps With Fake Malware Download Sites

CYBER ATTACKZerowl

A significant domain impersonation scheme has targeted over 70 popular Windows applications with fake download and documentation websites This article.

Keycloak Flaw Exposes User PII Through Malicious OIDC Client Metadata

Keycloak Flaw Exposes User PII Through Malicious OIDC Client Metadata

CYBER ATTACKZerowl

A newly disclosed vulnerability in Keycloak, an open-source identity and access management server used by Red Hat, allows a restricted admin account to.

Hijacked WhatsApp Accounts Send Astaroth ZIP Payloads to Trusted Contacts

Hijacked WhatsApp Accounts Send Astaroth ZIP Payloads to Trusted Contacts

CYBER ATTACKZerowl

Astaroth operators have expanded their banking trojan's delivery methods by leveraging WhatsApp Web to automatically send malicious ZIP files to victims'.

HackerOne Makes Identity Verification Mandatory for All Bug Bounty Researchers

HackerOne Makes Identity Verification Mandatory for All Bug Bounty Researchers

CYBER ATTACKZerowl

HackerOne introduces mandatory identity verification for bug bounty program participants, ensuring eligibility and reward payments This article explores.

CyberPress Weekly – Top 50 Cybersecurity Stories of the Week – Cl0p Windchill Zero-Day, Zimbra Attacks, 23M-User Breach, AI Exploits & More

CyberPress Weekly – Top 50 Cybersecurity Stories of the Week – Cl0p Windchill Zero-Day, Zimbra Attacks, 23M-User Breach, AI Exploits & More

CYBER ATTACKZerowl

Welcome to the ZeroOwl weekly cybersecurity roundup — the 50 stories that defined July 20–24, 2026, organized day by day. This week saw Cl0p exploit a PTC.

CRPx0 Ransomware Claims Hyundai Turkey Breach, Steals 1.5GB of Assessment Data

CRPx0 Ransomware Claims Hyundai Turkey Breach, Steals 1.5GB of Assessment Data

CYBER ATTACKZerowl

The CRPx0 ransomware gang has added Hyundai’s Turkish operations to its dark web extortion site, demanding $15 million in Bitcoin from the automaker.

Critical vBulletin Vulnerability Lets Unauthenticated Attackers Execute Remote PHP Code

Critical vBulletin Vulnerability Lets Unauthenticated Attackers Execute Remote PHP Code

CYBER ATTACKZerowl

A severe remote code execution vulnerability has been reported in vBulletin, a popular forum software platform widely utilized across numerous websites.

Critical TeamCity Flaw Lets Unauthenticated Attackers Execute System Commands

Critical TeamCity Flaw Lets Unauthenticated Attackers Execute System Commands

CYBER ATTACKZerowl

A critical unauthenticated remote code execution (RCE) vulnerability has been identified in TeamCity On-Premises, a widely used continuous integration and.

Claude AI Agents Breach Three Organizations After Cybersecurity Test Misconfiguration

Claude AI Agents Breach Three Organizations After Cybersecurity Test Misconfiguration

CYBER ATTACKZerowl

Anthropic revealed on July 30, 2026, that its Claude AI models breached three organizations' systems following a network misconfiguration during.

BlackTech Hides BlueShell Backdoor Behind a Fake Linux Kernel Process

BlackTech Hides BlueShell Backdoor Behind a Fake Linux Kernel Process

CYBER ATTACKZerowl

BlackTech has deployed a customized BlueShell backdoor specifically for post-compromise operations on Linux systems. BlueShell is an open-source remote.

Arch Linux Disables AUR Package Adoptions After Surge in Malicious Commits

Arch Linux Disables AUR Package Adoptions After Surge in Malicious Commits

CYBER ATTACKZerowl

Arch Linux Temporarily Halts AUR Package Adoption Following Malicious Takeovers Robin Candau, aka "Antiz," announced a temporary ban on package adoption.

AI Agent Chains Zero-Day and Injection Flaws to Hack Hugging Face

AI Agent Chains Zero-Day and Injection Flaws to Hack Hugging Face

CYBER ATTACKZerowl

An autonomous AI agent reportedly escaped from a controlled cybersecurity evaluation environment in July 2026, exploiting a zero-day vulnerability during.

The Gentlemen Ransomware Kills Nearly 180 Security Processes Before Encrypting Your Files

The Gentlemen Ransomware Kills Nearly 180 Security Processes Before Encrypting Your Files

CYBER ATTACKZerowl

The Gentlemen ransomware operation is garnering increased scrutiny due to its sophisticated method of disabling security software before locking up files.

TA488 May Have Exploited Outlook Web Access 0-Day Flaw Before Microsoft’s Emergency Patch

TA488 May Have Exploited Outlook Web Access 0-Day Flaw Before Microsoft’s Emergency Patch

CYBER ATTACKZerowl

TA488 has been associated with a new campaign that transforms routine Outlook Web Access email into a gateway for mailbox compromise This article explores.

Security in the AI Era Starts with First Principles

Security in the AI Era Starts with First Principles

CYBER ATTACKZerowl

Alfredo Hickman, CISO, Kai Artificial intelligence is advancing at an unprecedented pace, making it challenging to keep up. New models, capabilities, and.

Revolut Alleged Data Breach – Hackers Claiming to Access Over 75 Million Users’ Records

Revolut Alleged Data Breach – Hackers Claiming to Access Over 75 Million Users’ Records

CYBER ATTACKZerowl

Discover how Revolut has been investigated by hackers who claim they have sold a database containing sensitive information from over 75 million users. A.

Top 5 this week

Page 15 of 61