CYBER ATTACK

ZerOwl — Find Vulnerabilities Before Hackers Do
Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider

Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider

CYBER ATTACKZerowl

Researchers have identified an exposed attacker-controlled staging server, containing evidence of a widespread intrusion targeting 3BB, the consumer brand.

Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites

Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites

CYBER ATTACKZerowl

Casbaneiro is employing phishing tactics to target online banking users in Latin America This article explores casbaneiro employing phishing. . Indicators.

Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker

Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker

CYBER ATTACKZerowl

Cybercriminals are creating malware traps by using legitimate search queries and gaming videos as bait. Indicators of Compromise (IoCs): - Type.

GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline

GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline

CYBER ATTACKZerowl

GitHub has honored Saif Ghani, a cybersecurity researcher, with a $100,000 bug bounty following the disclosure of CVE-2026-3854, a critical remote code.

Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning

Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning

CYBER ATTACKZerowl

Cyclops Blink has resurfaced, offering attackers a more comprehensive view of corporate networks. However, the affected environment has faced serious.

Critical vBulletin Pre-Auth RCE Flaw Enables Arbitrary PHP Code Execution

Critical vBulletin Pre-Auth RCE Flaw Enables Arbitrary PHP Code Execution

CYBER ATTACKZerowl

A significant vulnerability in vBulletin allows unauthenticated remote attackers to execute arbitrary PHP code on a vulnerable forum server, providing a.

Critical Dell ObjectScale Vulnerabilities Allows Malicious Users to Compromise the Affected system

Critical Dell ObjectScale Vulnerabilities Allows Malicious Users to Compromise the Affected system

CYBER ATTACKZerowl

Dell Technologies has issued a security alert regarding multiple vulnerabilities impacting Dell ObjectScale and Elastic Cloud Storage (ECS).

Critical AWS Flaw Lets Attackers Bypass Port Forwarding Restrictions and Steal IAM Credentials

Critical AWS Flaw Lets Attackers Bypass Port Forwarding Restrictions and Steal IAM Credentials

CYBER ATTACKZerowl

A significant vulnerability in the AWS Systems Manager (SSM) Agent could allow unauthorized attackers to circumvent session port-forwarding restrictions.

Hackers Abuse Windows Mshta.exe in Phishing Attacks to Deploy HTA Malware and Steal Credentials

Hackers Abuse Windows Mshta.exe in Phishing Attacks to Deploy HTA Malware and Steal Credentials

CYBER ATTACKZerowl

Threat actors are exploiting the legitimate mshta.exe utility to execute malicious HTA files in Spanish-language phishing emails, enabling system.

Containing Machine Speed Cyber Attacks Inside AI Infrastructure

Containing Machine Speed Cyber Attacks Inside AI Infrastructure

CYBER ATTACKZerowl

A significant vulnerability in current cybersecurity practices is the assumption that time is on our side. Historically, attacks moved at a slower pace.

CISA Warns of Critical GitLab Path Traversal Flaw Exploited to Read Arbitrary Server Files

CISA Warns of Critical GitLab Path Traversal Flaw Exploited to Read Arbitrary Server Files

CYBER ATTACKZerowl

The U.S This article explores vulnerability impacts gitlab. . Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical GitLab.

Beyond the Perimeter: Building Resilience Against Cloud and SaaS Supply-Chain Attacks

Beyond the Perimeter: Building Resilience Against Cloud and SaaS Supply-Chain Attacks

CYBER ATTACKZerowl

In May and early June 2026, a zero-day vulnerability in Oracle PeopleSoft exposed critical organizations, including the Council of Europe, to potential.

OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE

OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE

CYBER ATTACKZerowl

A swarm of AI agents, attributed to OpenAI, overwhelmed RubyGems with over 2,000 packages in May 2026, exploiting RubyDoc.info for remote code execution.

Windows 11 Security Update KB5124008 Breaks Always-On VPN Connections

Windows 11 Security Update KB5124008 Breaks Always-On VPN Connections

CYBER ATTACKZerowl

Discover how Microsoft's KB5124008 security update, released on September 8, 2026, is causing issues with Windows 11 enterprise clients' Always On VPN.

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

CYBER ATTACKZerowl

Two vulnerabilities in VLC Media Player, CVE-2026-56711 and CVE-2026-73324, could allow attackers to compromise memory or extract sensitive information.

Ubuntu 24.04.5 LTS Released With Linux 7.0 Kernel and Latest Security Updates

Ubuntu 24.04.5 LTS Released With Linux 7.0 Kernel and Latest Security Updates

CYBER ATTACKZerowl

Discover how Canonical has officially released Ubuntu 24.04.5 LTS, the fifth maintenance update to the "Noble Numbat" long-term support release, featuring.

Top 10 Best CNAPP (Cloud-Native Application Protection) Platforms in 2026

Top 10 Best CNAPP (Cloud-Native Application Protection) Platforms in 2026

CYBER ATTACKZerowl

At the heart of CNAPP lies the umbrella concept, which encapsulates CSPM (posture), CWPP (runtime), CIEM (entitlements), and increasingly DSPM (data) into.

The 8 Best Server Security Solutions for Every Business Size (2026)

The 8 Best Server Security Solutions for Every Business Size (2026)

CYBER ATTACKZerowl

The Ultimate Guide to Server Security for Every Business Size Servers are the heart of databases, applications, and file shares, making them prime targets.

The 8 Best Cloud Security Posture Management (CSPM) Tools for Every Business Size (2026)

The 8 Best Cloud Security Posture Management (CSPM) Tools for Every Business Size (2026)

CYBER ATTACKZerowl

The Best Cloud Security Posture Management (CSPM) Tools for Every Business Size Most cloud breaches stem from misconfigurations, not exotic exploits. The.

The 8 Best Browser Isolation Solutions for Every Business Size (2026)

The 8 Best Browser Isolation Solutions for Every Business Size (2026)

CYBER ATTACKZerowl

Discover how The Best Browser Isolation Solutions for Every Business Size The browser is where most work and most web-based threats occur. Remote browser.

The 7 Best Enterprise Browsers for Every Business Size (2026)

The 7 Best Enterprise Browsers for Every Business Size (2026)

CYBER ATTACKZerowl

The Best Enterprise Browsers for Every Business Size The enterprise browser has become a crucial security control category, adding data-loss prevention.

New IoT Malware Uses Public Linux Exploits to Gain Root and Turn Devices Into DDoS Bots

New IoT Malware Uses Public Linux Exploits to Gain Root and Turn Devices Into DDoS Bots

CYBER ATTACKZerowl

A newly discovered IoT malware family called KATARU is targeting Linux devices via Telnet credential brute-force attacks. Researchers discovered that it.

Microsoft Investigating Microsoft 365 Copilot Access Issues Under Incident CP1470554

Microsoft Investigating Microsoft 365 Copilot Access Issues Under Incident CP1470554

CYBER ATTACKZerowl

Discover how Microsoft is investigating a disruption affecting Microsoft 365 Copilot, where users might encounter difficulties opening the assistant or.

Harley-Davidson Alleged Breach – CL0P Ransomware Adds Motorcycle Maker to the List

Harley-Davidson Alleged Breach – CL0P Ransomware Adds Motorcycle Maker to the List

CYBER ATTACKZerowl

The CL0P ransomware gang reportedly added Harley-Davidson to its public leak site, claiming a breach This article explores harley davidson customers. . As.

Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments

Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments

CYBER ATTACKZerowl

Discover how A massive email fraud scheme utilized fake CEO emails and invoices to trick employees into making nearly $50,000 in payments. Instead, it.

Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement

Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement

CYBER ATTACKZerowl

SloppyRAT is a remote access tool crafted to assist ransomware operators in infiltrating compromised networks. Indicators of compromise (IoCs): - SHA-256.

GuardBreaker Malware Uses Code Comments to Trip AI Security Guardrails and Evade Analysis

GuardBreaker Malware Uses Code Comments to Trip AI Security Guardrails and Evade Analysis

CYBER ATTACKZerowl

Discover how Threat actors are employing a new method to circumvent AI-powered security measures: embedding harmful prompt-injection content within code.

Critical Auth0 AD/LDAP Connector Flaw Lets Attackers Execute Stored XSS in Admin Browsers

Critical Auth0 AD/LDAP Connector Flaw Lets Attackers Execute Stored XSS in Admin Browsers

CYBER ATTACKZerowl

Okta has released updates for three high-severity vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway This article explores.

cPanel ConfigServer Security & Firewall Vulnerability Allows Remote Attacker to Execute Arbitrary Commands

cPanel ConfigServer Security & Firewall Vulnerability Allows Remote Attacker to Execute Arbitrary Commands

CYBER ATTACKZerowl

A critical vulnerability in ConfigServer Security & Firewall (CSF), utilized on cPanel and WHM servers, enables an unauthenticated remote attacker to.

Top 5 this week

Page 2 of 61