CYBER ATTACK

ZerOwl — Find Vulnerabilities Before Hackers Do
PortSwigger Launches Burp AT Agentic AI to Find and Exploit Web Vulnerabilities

PortSwigger Launches Burp AT Agentic AI to Find and Exploit Web Vulnerabilities

CYBER ATTACKZerowl

PortSwigger introduces Burp AT in public beta, integrating AI capabilities into its widely used Burp Suite Professional platform This article explores.

PHP Patches Three Flaws Enabling SQL Injection, Memory Corruption and Server Crashes

PHP Patches Three Flaws Enabling SQL Injection, Memory Corruption and Server Crashes

CYBER ATTACKZerowl

PHP has patched three security vulnerabilities in its latest updates, including high-severity flaws that can lead to SQL injection and out-of-bounds.

OpenAI Open-Sources Codex Security CLI to Find, Validate, and Fix Code Vulnerabilities

OpenAI Open-Sources Codex Security CLI to Find, Validate, and Fix Code Vulnerabilities

CYBER ATTACKZerowl

OpenAI introduces Codex Security, an open-source command-line interface (CLI) and TypeScript SDK designed to help developers detect, validate, and.

OctLurk Infrastructure Overlaps With Malware Targeting Kazakhstan’s Critical Systems

OctLurk Infrastructure Overlaps With Malware Targeting Kazakhstan’s Critical Systems

CYBER ATTACKZerowl

Security researchers have discovered that the OctLurk malware framework is linked to a separate campaign targeting Kazakhstan's critical infrastructure.

New Backdoors Let Hackers Keylog, Steal Passwords and Control Government Computers

New Backdoors Let Hackers Keylog, Steal Passwords and Control Government Computers

CYBER ATTACKZerowl

In Central Asia, two custom-built backdoors called OctLurk and SilkLurk have compromised government networks This article explores silklurk compromised.

Microsoft Secures Windows KMS Activation With TPM-Based Hardware Trust

Microsoft Secures Windows KMS Activation With TPM-Based Hardware Trust

CYBER ATTACKZerowl

Microsoft has introduced a significant security enhancement to its Key Management Service (KMS) infrastructure, incorporating TPM-based hardware.

Hackers Manipulate PLC Logic and Operator Displays Across U.S. Critical Infrastructure

Hackers Manipulate PLC Logic and Operator Displays Across U.S. Critical Infrastructure

CYBER ATTACKZerowl

Six federal agencies have updated their joint cybersecurity advisory, warning of Iranian-affiliated threat actors exploiting internet-connected.

Google Hardens Chrome Against AI-Era Threats With Faster Security Updates

Google Hardens Chrome Against AI-Era Threats With Faster Security Updates

CYBER ATTACKZerowl

Google's Chrome Security Team has unveiled a comprehensive overhaul of its vulnerability management pipeline, heavily relying on AI to expedite bug.

Golden Chickens TAG-195 Launches TinyEgg and ChonkyChicken Modular Malware

Golden Chickens TAG-195 Launches TinyEgg and ChonkyChicken Modular Malware

CYBER ATTACKZerowl

TAG-195, also known as Golden Chickens or Venom Spider, is a financially motivated MaaS developer closely associated with credential theft and remote.

Flying Eagle Android RAT Runs Across 170 Servers as Leaked Code Spawns Night Dragon

Flying Eagle Android RAT Runs Across 170 Servers as Leaked Code Spawns Night Dragon

CYBER ATTACKZerowl

Discover how Researchers have uncovered a large-scale operation of the Android Remote Access Trojan (RAT) known as Flying Eagle, linked to the leaked.

Fake N26 Support Calls Deploy Copybara Android RAT to Control Banking Apps

Fake N26 Support Calls Deploy Copybara Android RAT to Control Banking Apps

CYBER ATTACKZerowl

Discover how A sophisticated fraud operation targeting N26 users in Italy combines voice phishing with live phishing and remote access trojans to steal.

Dysphoria Maps 155 Router Ports to Turn Infected Devices Into C2 Proxies

Dysphoria Maps 155 Router Ports to Turn Infected Devices Into C2 Proxies

CYBER ATTACKZerowl

Since the first quarter of 2026, cybersecurity researchers at XLAB have been monitoring an increasing botnet family known as Dysphoria. The group’s most.

DPRK Hackers Use EtherHiding Smart Contracts as Resilient Malware Command Channels

DPRK Hackers Use EtherHiding Smart Contracts as Resilient Malware Command Channels

CYBER ATTACKZerowl

DPRK-linked threat actors are exploiting Ethereum smart contracts as a resilient command-and-control (C2) infrastructure in a sophisticated macOS malware.

Digitally Signed CastleLoader Installers Strip Mark-of-the-Web and Inject Payloads Into Memory

Digitally Signed CastleLoader Installers Strip Mark-of-the-Web and Inject Payloads Into Memory

CYBER ATTACKZerowl

Arctic Wolf Labs has discovered new CastleLoader campaigns employing digitally signed installers, Mark-of-the-Web (MotW) removal, and in-memory shellcode.

Cybercriminals Weaponize Published Data Leaks for Personalized Blackmail Emails

Cybercriminals Weaponize Published Data Leaks for Personalized Blackmail Emails

CYBER ATTACKZerowl

Cybercriminals are leveraging stolen email addresses from data breaches linked to the ShinyHunters hacking group to create more believable sextortion.

Critical TeamCity Flaw Lets Unauthenticated Attackers Execute Commands Remotely

Critical TeamCity Flaw Lets Unauthenticated Attackers Execute Commands Remotely

CYBER ATTACKZerowl

A significant remote code execution vulnerability exists in JetBrains TeamCity On-Premises, allowing unauthenticated compromise of servers This article.

Critical SolarWinds Flaw Lets Attackers Bypass Web Help Desk SAML Login

Critical SolarWinds Flaw Lets Attackers Bypass Web Help Desk SAML Login

CYBER ATTACKZerowl

SolarWinds has addressed a significant security flaw in its Web Help Desk platform, which could permit attackers to circumvent SAML-based authentication.

Critical PHP Vulnerabilities Enable SQL Injection, Stack Overflow, and Memory Corruption

Critical PHP Vulnerabilities Enable SQL Injection, Stack Overflow, and Memory Corruption

CYBER ATTACKZerowl

The PHP development team has identified three critical security vulnerabilities impacting core extensions, with patches released in versions 8.2.33.

Critical Four libssh2 Flaws Let Malicious SSH Servers Corrupt Client Memory

Critical Four libssh2 Flaws Let Malicious SSH Servers Corrupt Client Memory

CYBER ATTACKZerowl

A newly disclosed four high-severity vulnerabilities in libssh2, the widely used SSH library embedded in countless client applications, tools, and DevOps.

Critical Adobe Campaign Classic Flaws Enable Remote Code Execution and File Theft

Critical Adobe Campaign Classic Flaws Enable Remote Code Execution and File Theft

CYBER ATTACKZerowl

Adobe has released an urgent security update to address two significant vulnerabilities in Adobe Campaign Classic, allowing attackers to execute arbitrary.

CISA Warns Hackers Are Targeting Internet-Exposed PLCs at Water Utilities

CISA Warns Hackers Are Targeting Internet-Exposed PLCs at Water Utilities

CYBER ATTACKZerowl

The Cybersecurity and Infrastructure Security Agency (CISA) issued a critical alert on July 30, 2026, warning of escalating attacks against programmable.

Chrome Extension Collects Conversations Across Nine AI Platforms With No Off Switch

Chrome Extension Collects Conversations Across Nine AI Platforms With No Off Switch

CYBER ATTACKZerowl

A Chrome extension with approximately 100,000 users has been caught silently exfiltrating full AI chat conversations to a remote server, even when users.

Check Point SmartConsole Zero-Day Lets Unauthenticated Attackers Gain Full Admin Access

Check Point SmartConsole Zero-Day Lets Unauthenticated Attackers Gain Full Admin Access

CYBER ATTACKZerowl

A significant security bypass vulnerability exists within Check Point's SmartConsole management platform, enabling unauthenticated attackers to gain full.

Top 5 this week

Page 16 of 61