CYBER ATTACK

CISA Warns of Ivanti Endpoint Manager Authentication Bypass Vulnerability Exploited in Attacks

CISA Warns of Ivanti Endpoint Manager Authentication Bypass Vulnerability Exploited in Attacks

CYBER ATTACKZerowl

Following its addition to the Known Exploited Vulnerabilities (KEV) catalog by the Cybersecurity and Infrastructure Security Agency (CISA) on March 9.

Chinese APT Campaign Targets Qatar With PlugX Lures Tied to Middle East Conflict

Chinese APT Campaign Targets Qatar With PlugX Lures Tied to Middle East Conflict

CYBER ATTACKZerowl

Discover how One day after fresh hostilities broke out in the Middle East on March 1, 2026, Camaro Dragon, an advanced persistent threat group with ties.

Iran-Linked Hackers Target U.S. Critical Infrastructure Amid Rising Cyber Threat Activity

Iran-Linked Hackers Target U.S. Critical Infrastructure Amid Rising Cyber Threat Activity

CYBER ATTACKZerowl

Since early February 2026, the Iranian advanced persistent threat group known as Seedworm—also known as MuddyWater, Temp Zagros, and Static Kitten—has.

BoryptGrab Stealer Steals Browser and Crypto Wallet Data and Spreads via False GitHub Repositories

BoryptGrab Stealer Steals Browser and Crypto Wallet Data and Spreads via False GitHub Repositories

CYBER ATTACKZerowl

Through a network of phony GitHub repositories, a new data-stealing malware known as BoryptGrab has been covertly propagating throughout Windows systems.

Vietnam-Based Cybercrime Network Enables Fraudulent Account Signups at Scale

Vietnam-Based Cybercrime Network Enables Fraudulent Account Signups at Scale

CYBER ATTACKZerowl

Large-scale fraudulent account registration campaigns that target service providers and online platforms globally have been connected to a vast cybercrime.

Signal Confirms Targeted Phishing Attacks Resulting in Account Takeovers

Signal Confirms Targeted Phishing Attacks Resulting in Account Takeovers

CYBER ATTACKZerowl

Discover how An ongoing wave of targeted phishing campaigns that have successfully taken over the accounts of prominent users, including government.

Microsoft Launches Copilot Cowork, a New AI Feature in Microsoft 365 to Automate Tasks

Microsoft Launches Copilot Cowork, a New AI Feature in Microsoft 365 to Automate Tasks

CYBER ATTACKZerowl

Copilot Cowork, a new AI-powered feature integrated into Microsoft 365 that goes beyond conversational support to autonomous task execution, was unveiled.

MaaS VIP Keylogger Campaign Uses Steganography and In-Memory Execution to Steal Credentials at Scale

MaaS VIP Keylogger Campaign Uses Steganography and In-Memory Execution to Steal Credentials at Scale

CYBER ATTACKZerowl

Organizations and individuals are now seriously threatened by a sophisticated credential-stealing campaign based on a tool known as VIP Keylogger This.

M365Pwned: Red Team GUI Toolkit for Graph API-Based Microsoft 365 Exploitation

M365Pwned: Red Team GUI Toolkit for Graph API-Based Microsoft 365 Exploitation

CYBER ATTACKZerowl

M365Pwned, two WinForms GUI tools created to enumerate, search, and exfiltrate data from Microsoft 365 environments using application-level OAuth tokens.

Transparent Tribe’s ‘Vibeware’ Shift Signals Rise of AI-Generated Malware at Industrial Scale

Transparent Tribe’s ‘Vibeware’ Shift Signals Rise of AI-Generated Malware at Industrial Scale

CYBER ATTACKZerowl

Threat actor APT36, also known as Transparent Tribe, is based in Pakistan and has switched from using well-crafted tools to a new strategy known as.

Hikvision Multiple Products Vulnerability Allows Malicious Users to Escalate Privileges

Hikvision Multiple Products Vulnerability Allows Malicious Users to Escalate Privileges

CYBER ATTACKZerowl

Hikvision Vulnerability of Multiple Products On March 5, 2026, a serious vulnerability impacting several Hikvision products was added to the Known.

Critical Nginx UI Vulnerabilities Allow Attacker to Download a Full System Backup

Critical Nginx UI Vulnerabilities Allow Attacker to Download a Full System Backup

CYBER ATTACKZerowl

Vulnerabilities in the Nginx UI Full system backups can be downloaded and decrypted by unauthorized attackers thanks to a recently identified critical.

Critical ExifTool Flaw Lets Malicious Images Trigger Code Execution on macOS

Critical ExifTool Flaw Lets Malicious Images Trigger Code Execution on macOS

CYBER ATTACKZerowl

Malicious Images Cause Code Execution on macOS Due to an ExifTool Flaw The long-held notion that macOS systems are intrinsically resistant to malware is.

ClipXDaemon Emerges as C2-Less Linux Clipboard Hijacker, Targeting Crypto Wallets in X11 Sessions

ClipXDaemon Emerges as C2-Less Linux Clipboard Hijacker, Targeting Crypto Wallets in X11 Sessions

CYBER ATTACKZerowl

In X11-based desktop environments, a recently identified Linux malware called ClipXDaemon has become a direct financial threat to cryptocurrency users.

Chinese-Linked CL-UNK-1068 Espionage Campaign Targets Critical Infrastructure Across Asia

Chinese-Linked CL-UNK-1068 Espionage Campaign Targets Critical Infrastructure Across Asia

CYBER ATTACKZerowl

Since at least 2020, a Chinese-affiliated cyber-espionage group known as CL-UNK-1068 has been secretly attacking vital infrastructure throughout South.

Apache ZooKeeper Vulnerability Allows Attackers to Access Sensitive Data

Apache ZooKeeper Vulnerability Allows Attackers to Access Sensitive Data

CYBER ATTACKZerowl

Two high-impact vulnerabilities that could result in the exposure of sensitive data and possible server impersonation attacks have been addressed by.

ZITADELs 1-Click Vulnerability Allows Attackers to Take Over Entire Systems

ZITADELs 1-Click Vulnerability Allows Attackers to Take Over Entire Systems

CYBER ATTACKZerowl

The open-source identity and access management (IAM) platform ZITADEL, which is frequently utilized by businesses for safe authentication procedures, has.

WiFi Signals Reveal Human Activities Through Walls by Mapping Body Keypoints

WiFi Signals Reveal Human Activities Through Walls by Mapping Body Keypoints

CYBER ATTACKZerowl

There are serious security and surveillance concerns because π RuView, a new open-source edge AI system, is transforming standard WiFi infrastructure into.

New Linux Rootkits Leverage eBPF and io_uring For Stealth

New Linux Rootkits Leverage eBPF and io_uring For Stealth

CYBER ATTACKZerowl

As attackers start abusing contemporary Linux features like eBPF and io_uring instead of relying on outdated kernel module tricks, Linux rootkits are.

Microsoft Warns Fake AI Browser Extensions Compromised Chat Histories Across 20,000+ Enterprise Tenants

Microsoft Warns Fake AI Browser Extensions Compromised Chat Histories Across 20,000+ Enterprise Tenants

CYBER ATTACKZerowl

Over 20,000 business environments have been covertly compromised by a wave of fake AI-powered browser extensions, jeopardizing the chat histories of.

Hackers Exploit Windows Terminal In New ClickFix Malware Attack

Hackers Exploit Windows Terminal In New ClickFix Malware Attack

CYBER ATTACKZerowl

A new ClickFix social engineering campaign that exploits Windows Terminal to run malicious payloads on compromised systems has been discovered by security.

Fake imToken Browser Extension Targets Crypto Wallet Credentials

Fake imToken Browser Extension Targets Crypto Wallet Credentials

CYBER ATTACKZerowl

Security experts have discovered a malicious Chrome extension that poses as the well-known cryptocurrency wallet imToken and is intended to steal users'.

Fake AI Browser Extensions Expose Chat Data Across 20,000 Enterprises

Fake AI Browser Extensions Expose Chat Data Across 20,000 Enterprises

CYBER ATTACKZerowl

Researchers at Microsoft Defender have issued a warning regarding malicious browser extensions that pose as AI assistant tools and surreptitiously gather.

CISA Warns of macOS and iOS Vulnerabilities Exploited in Attacks

CISA Warns of macOS and iOS Vulnerabilities Exploited in Attacks

CYBER ATTACKZerowl

CISA Alerts Users to iOS and macOS Vulnerabilities A critical alert about several Apple vulnerabilities that are currently being actively exploited has.

OpenAI Rolls Out Codex Security in Research Preview for Context‑Aware Vulnerability Detection

OpenAI Rolls Out Codex Security in Research Preview for Context‑Aware Vulnerability Detection

CYBER ATTACKZerowl

Codex Security, an advanced application security agent created to automate vulnerability detection and remediation, has been formally introduced by.

OpenAI Confirms ChatGPT’s Role In Chinese Cyberattack Campaigns

OpenAI Confirms ChatGPT’s Role In Chinese Cyberattack Campaigns

CYBER ATTACKZerowl

A group of threat actors, including those associated with China and Russia, were discovered using ChatGPT to support malicious cyber and influence.

North Korean APT37 Hackers Leverages Novel Malware to Infect Air‑Gapped Systems

North Korean APT37 Hackers Leverages Novel Malware to Infect Air‑Gapped Systems

CYBER ATTACKZerowl

Threat group APT37, which has ties to North Korea, has launched a sophisticated new campaign that uses a new set of malware tools that are specifically.

Microsoft Defender Uncovers Trojanized Gaming Utility Campaign Targeting Users with RATs and Remote Data Theft

Microsoft Defender Uncovers Trojanized Gaming Utility Campaign Targeting Users with RATs and Remote Data Theft

CYBER ATTACKZerowl

By concealing malware inside gaming tools that appear entirely legitimate, cybercriminals have discovered a new method of getting past users' defenses.

Microsoft Defender Expands URL Click Alerts to Include Microsoft Teams for Enhanced Security Visibility

Microsoft Defender Expands URL Click Alerts to Include Microsoft Teams for Enhanced Security Visibility

CYBER ATTACKZerowl

URL Alert Teams for Microsoft Defender By adding Microsoft Defender for Office 365 (MDO) URL click alerts to Microsoft Teams, Microsoft is fortifying its.

Top 5 this week

Page 18 of 44