CYBER ATTACK

How to Scale Early Threat Detection in Your SOC without Extra Staff

How to Scale Early Threat Detection in Your SOC without Extra Staff

CYBER ATTACKZerowl

Scaling Up Early Threat Detection in Your SOC Early detection isn't just a good idea; it's the main thing that keeps a small incident from turning into a.

Gogs Vulnerability Lets Attackers Quietly Overwrite Big File Storage Objects

Gogs Vulnerability Lets Attackers Quietly Overwrite Big File Storage Objects

CYBER ATTACKZerowl

Gogs Vulnerability Overwrites Large File Storage Objects A serious security hole has been found in a well-known open-source Git service that people host.

Vietnam-Based Fraud Network Powers Large-Scale Account Signup Abuse

Vietnam-Based Fraud Network Powers Large-Scale Account Signup Abuse

CYBER ATTACKZerowl

Okta Threat Intelligence and researchers from the University of Cyprus have found that a lot of fake account registrations are coming from a big.

Red Alert App Trojan Targets Israeli Users, Steals Sensitive Data Through SMS

Red Alert App Trojan Targets Israeli Users, Steals Sensitive Data Through SMS

CYBER ATTACKZerowl

A recent targeted cyberattack is using the trusted Red Alert rocket warning app to spread spyware to Israeli users. On March 1, 2026, the Acronis Threat.

Microsoft .NET 0-Day Vulnerability Enables Denial-of-Service Attacks

Microsoft .NET 0-Day Vulnerability Enables Denial-of-Service Attacks

CYBER ATTACKZerowl

Microsoft .NET 0-Day Flaw A new .NET Framework security flaw, CVE-2026-26127, has been made public, and an emergency update has been released to fix it.

Instagram Suffers Global Outage, Users Unable to Post or Send Messages

Instagram Suffers Global Outage, Users Unable to Post or Send Messages

CYBER ATTACKZerowl

On March 11, 2026, Instagram went down all over the world, making it impossible for thousands of users to use basic features like posting, loading feeds.

Critical Microsoft Office Vulnerability Enables Remote Code Execution Attacks

Critical Microsoft Office Vulnerability Enables Remote Code Execution Attacks

CYBER ATTACKZerowl

Discover how Microsoft has revealed a serious security hole in Microsoft Office that could let hackers run harmful code on affected computers. The flaw.

BlackSanta EDR Killer Malware Attacks HR Workflows in a Multi-Layered Way

BlackSanta EDR Killer Malware Attacks HR Workflows in a Multi-Layered Way

CYBER ATTACKZerowl

Threat actors are now targeting human resources (HR) departments with a complicated malware attack in a scary new campaign. BlackSanta is the name of the.

Zoom Workplace for Windows Vulnerabilities Allow Privilege Escalation

Zoom Workplace for Windows Vulnerabilities Allow Privilege Escalation

CYBER ATTACKZerowl

On March 10, 2026, Zoom put out four security bulletins that revealed several weaknesses in its Windows-based client suite This article explores zoom.

ScamAgent- AI Agent Built by Researchers that Run Fully Autonomous Scam Calls

ScamAgent- AI Agent Built by Researchers that Run Fully Autonomous Scam Calls

CYBER ATTACKZerowl

Sanket Badhe, a researcher at Rutgers University, created ScamAgent, an autonomous, multi-turn AI framework that shows how large language models (LLMs).

SAP Security Update – Patch for Multiple Vulnerabilities that Enable Remote Code Execution

SAP Security Update – Patch for Multiple Vulnerabilities that Enable Remote Code Execution

CYBER ATTACKZerowl

On its March 2026 Patch Day, SAP released 15 new security notes that fixed a number of flaws in its products, including two critical-rated ones that could.

SAP Releases Security Update to Patch Multiple Remote Code Execution Vulnerabilities

SAP Releases Security Update to Patch Multiple Remote Code Execution Vulnerabilities

CYBER ATTACKZerowl

The release covers a wide range of core platforms, including SAP NetWeaver, S/4HANA, Business One, Business Warehouse, and a number of industry and client.

OpenAI to Acquire Promptfoo to Fix Vulnerabilities in AI Systems

OpenAI to Acquire Promptfoo to Fix Vulnerabilities in AI Systems

CYBER ATTACKZerowl

OpenAI Acquire Promptfoo OpenAI has announced its acquisition of Promptfoo, an artificial intelligence security platform designed to help enterprises find.

OpenAI Acquires Promptfoo to Strengthen AI Security and Fix System Vulnerabilities

OpenAI Acquires Promptfoo to Strengthen AI Security and Fix System Vulnerabilities

CYBER ATTACKZerowl

OpenAI has said that it wants to buy Promptfoo, an AI security testing platform that finds and fixes problems in large language model (LLM) applications.

Microsoft Patch Tuesday March 2026 – 78 Vulnerabilities Fixed, Including One 0-day

Microsoft Patch Tuesday March 2026 – 78 Vulnerabilities Fixed, Including One 0-day

CYBER ATTACKZerowl

On March 10, 2026, Microsoft released its Patch Tuesday security update for March 2026 This article explores vulnerability cve 2026. . It fixed 78.

Malformed ZIP Files Allow Attackers to Bypass Antivirus and EDR Detection

Malformed ZIP Files Allow Attackers to Bypass Antivirus and EDR Detection

CYBER ATTACKZerowl

A new vulnerability that enables attackers to conceal malicious files inside specially constructed ZIP archives and potentially get around antivirus and.

Kali Linux Enhances AI-driven Penetration Testing with Local Ollama, 5ire, and MCP Kali Server

Kali Linux Enhances AI-driven Penetration Testing with Local Ollama, 5ire, and MCP Kali Server

CYBER ATTACKZerowl

AI-powered Penetration Testing with Kali Linux The Kali Linux team has released a new version of their expanding LLM-driven security series, which.

Ivanti Desktop and Server Management Vulnerability Allows Attackers to Escalate Privileges

Ivanti Desktop and Server Management Vulnerability Allows Attackers to Escalate Privileges

CYBER ATTACKZerowl

A high-severity vulnerability that could enable a local authenticated attacker to increase their privileges on impacted systems has been fixed by Ivanti's.

iPhone Hacking Toolkit Used by Russian Spies Likely Developed by U.S. Contractor

iPhone Hacking Toolkit Used by Russian Spies Likely Developed by U.S. Contractor

CYBER ATTACKZerowl

A sophisticated iPhone exploit toolkit called "Coruna" is at the center of an escalating controversy after new research revealed that it most likely came.

iPhone Exploit Toolkit Used by Russian Spies Likely Originated from U.S. Contractor

iPhone Exploit Toolkit Used by Russian Spies Likely Originated from U.S. Contractor

CYBER ATTACKZerowl

Russian Spies Used an iPhone Exploit Toolkit Russian spies and Chinese cybercriminals have gained access to a potent iPhone exploit kit called "Coruna,".

Hackers Attack Employees Over Microsoft Teams to Trick Them Into Granting Remote Access

Hackers Attack Employees Over Microsoft Teams to Trick Them Into Granting Remote Access

CYBER ATTACKZerowl

Hackers Target Microsoft Teams After persuading staff members to grant remote access, the attackers are now using a recently discovered malware family.

GhostClaw Mimic as OpenClaw to Steal Everything from Developers

GhostClaw Mimic as OpenClaw to Steal Everything from Developers

CYBER ATTACKZerowl

A rogue npm package that poses as a reliable developer tool has surfaced as part of a dangerous malware campaign that targets software developers This.

Fortinet FortiManager fgtupdates Vulnerability Allows Attackers to Execute Malicious Commands

Fortinet FortiManager fgtupdates Vulnerability Allows Attackers to Execute Malicious Commands

CYBER ATTACKZerowl

A high-severity stack-based buffer overflow vulnerability in Fortinet's FortiManager platform has been made public This article explores vulnerability.

Fake GitHub Repos Push BoryptGrab Stealer To Harvest Browser and Wallet Data

Fake GitHub Repos Push BoryptGrab Stealer To Harvest Browser and Wallet Data

CYBER ATTACKZerowl

Researchers have discovered a new malware campaign that propagates the stealer BoryptGrab by using phony GitHub repositories This article explores malware.

Fake CleanMyMac Website Pushes SHub Stealer To Drain Crypto Wallet Data

Fake CleanMyMac Website Pushes SHub Stealer To Drain Crypto Wallet Data

CYBER ATTACKZerowl

A phony CleanMyMac website is being used by a new macOS malware campaign to trick users into infecting their own computers This article explores.

Critical Pingora Vulnerabilities Expose Cloudflare to Request Smuggling and Cache Poisoning Attacks

Critical Pingora Vulnerabilities Expose Cloudflare to Request Smuggling and Cache Poisoning Attacks

CYBER ATTACKZerowl

Cloudflare has fixed several Pingora vulnerabilities that could allow attackers to smuggle HTTP requests through poison caches and edge proxies, creating.

Cloudflare Pingora Vulnerabilities Allows Request Smuggling & Cache Poisoning Attacks

Cloudflare Pingora Vulnerabilities Allows Request Smuggling & Cache Poisoning Attacks

CYBER ATTACKZerowl

Vulnerabilities in Cloudflare Pingora In order to address three serious vulnerabilities, Cloudflare has released version 0.8.0 of its open-source Pingora.

Top 5 this week

Page 17 of 44