CYBER ATTACK

Threat Actors Using Fake Google Forms Site to Harvest Google Logins

Threat Actors Using Fake Google Forms Site to Harvest Google Logins

CYBER ATTACKZerowl

Job seekers are being targeted by a new phishing campaign that uses phony Google Forms websites to steal login information. The campaign deceives victims.

CISA Issues a Honeywell Warning Vulnerabilities in CCTV Products Cause Account Takeovers

CISA Issues a Honeywell Warning Vulnerabilities in CCTV Products Cause Account Takeovers

CYBER ATTACKZerowl

On February 17, 2026, a critical advisory warning was released under advisory ICSA-26-048-04 about a serious vulnerability affecting Honeywell CCTV.

Microsoft Defender Unveils Centralized Script Library with Copilot Analysis for Enhanced Live Response

Microsoft Defender Unveils Centralized Script Library with Copilot Analysis for Enhanced Live Response

CYBER ATTACKZerowl

Microsoft Defender Centralized Script Library: To completely change the way security analysts handle the scripts and tools they use during live response.

Microsoft Defender Launches Centralized Script Library with Copilot-Powered Analysis

Microsoft Defender Launches Centralized Script Library with Copilot-Powered Analysis

CYBER ATTACKZerowl

A revolutionary update to Microsoft's Defender platform has been released, bringing centralized library management for live response operations. This.

Fake CAPTCHA ClickFix Attack Triggers Enterprise Malware Outbreak

Fake CAPTCHA ClickFix Attack Triggers Enterprise Malware Outbreak

CYBER ATTACKZerowl

An entire corporate network can be covertly exposed by a single employee action, according to a recent incident response investigation. After learning.

Crypto Scams Sweep Asia, Blending Malvertising and Pig Butchering Tactics

Crypto Scams Sweep Asia, Blending Malvertising and Pig Butchering Tactics

CYBER ATTACKZerowl

Discover how Researchers studying cybersecurity are alerting people to a massive cryptocurrency scam that is sweeping through Asia, especially Japan, and.

AI Dev Tool Cline’s npm Token Hijacked by Hackers for 8 Hours

AI Dev Tool Cline’s npm Token Hijacked by Hackers for 8 Hours

CYBER ATTACKZerowl

The Cline CLI npm package was briefly but alarmingly accessible to attackers through a compromised publish token, exposing developers who installed it.

Advanced Crypto Mining Malware Proliferates via Air-Gapped Systems and External Drives

Advanced Crypto Mining Malware Proliferates via Air-Gapped Systems and External Drives

CYBER ATTACKZerowl

A sophisticated cryptocurrency mining campaign has surfaced that can compromise even air-gapped environments by using external storage devices to target.

Researchers Uncover New SysUpdate Malware Variant Targeting Linux Systems

Researchers Uncover New SysUpdate Malware Variant Targeting Linux Systems

CYBER ATTACKZerowl

During a digital forensics and incident response (DFIR) engagement, LevelBlue researchers discovered a new SysUpdate malware variant that targets Linux.

Hackers Abuse nslookup.exe to Stage Payloads via DNS in ClickFix Attacks

Hackers Abuse nslookup.exe to Stage Payloads via DNS in ClickFix Attacks

CYBER ATTACKZerowl

The "ClickFix" social engineering technique has been improved by cybercriminals, who now use covert exploitation of nslookup.exe to deliver payloads.

Attackers Use Counterfeit Wallets and Backdoors in Cryptocurrency Theft Operations

Attackers Use Counterfeit Wallets and Backdoors in Cryptocurrency Theft Operations

CYBER ATTACKZerowl

An ongoing campaign of financial theft and cyber-espionage targeting developers in the Web3, cryptocurrency, and artificial intelligence sectors has been.

OpenAI Launches EVMbench for Blockchain Vulnerability Detection and Exploitation

OpenAI Launches EVMbench for Blockchain Vulnerability Detection and Exploitation

CYBER ATTACKZerowl

EVMbench, a new benchmark developed by OpenAI and Paradigm, is intended to assess AI agents' abilities to identify, address, and even take advantage of.

Hackers Launch Sophisticated Multi-Stage Phishing Campaign Targeting Booking.com Partners and Travelers

Hackers Launch Sophisticated Multi-Stage Phishing Campaign Targeting Booking.com Partners and Travelers

CYBER ATTACKZerowl

A well-planned, two-step phishing campaign is being used by a recently discovered cybercrime operation to target travelers and hotel employees. According.

Hackers Can Leverage Grok and Copilot for Stealthy Malware Communication and Control

Hackers Can Leverage Grok and Copilot for Stealthy Malware Communication and Control

CYBER ATTACKZerowl

Copilot and Grok for Malware Communication An innovative attack method that turns popular AI assistants—more especially, Microsoft Copilot and Grok from.

“Foxveil” Malware Evades Detection By Leveraging Cloudflare, Netlify, and Discord

“Foxveil” Malware Evades Detection By Leveraging Cloudflare, Netlify, and Discord

CYBER ATTACKZerowl

Researchers at Cato CTRL have discovered "Foxveil," a new malware loader that has been in use since August 2025 and conceals payloads on reputable.

ClawHavoc Uses 1,184 Malevolent Skills to Destroy OpenClaws ClawHub

ClawHavoc Uses 1,184 Malevolent Skills to Destroy OpenClaws ClawHub

CYBER ATTACKZerowl

ClawHub, the official skill marketplace for OpenClaw, an open-source AI agent formerly known as ClawdBot and Moltbot, has been compromised by a massive.

Cryptocurrency Scams Target Asia, Combining Malvertising and Pig Butchering with Losses Up to ¥10 Million

Cryptocurrency Scams Target Asia, Combining Malvertising and Pig Butchering with Losses Up to ¥10 Million

CYBER ATTACKZerowl

Currently, users throughout Asia are the target of a sophisticated cryptocurrency scam campaign that heavily and specifically targets Japan. Malvertising.

Targeting corporate networks, critical Ivanti EPMM zero-day vulnerabilities were exploited in the wild.

Targeting corporate networks, critical Ivanti EPMM zero-day vulnerabilities were exploited in the wild.

CYBER ATTACKZerowl

With active exploitation campaigns targeting corporate infrastructure across several nations, two serious zero-day vulnerabilities in Ivanti Endpoint.

Fake CAPTCHA (ClickFix) Attack Chain Causes Enterprise-Wide Malware Infection in Companies

Fake CAPTCHA (ClickFix) Attack Chain Causes Enterprise-Wide Malware Infection in Companies

CYBER ATTACKZerowl

Enterprise networks around the world are seriously threatened by a sophisticated cyberattack campaign that uses "ClickFix" social engineering This article.

Threat Actors Advertising New ‘ClickFix’ Payload That Stores Malware within Browser Cache

Threat Actors Advertising New ‘ClickFix’ Payload That Stores Malware within Browser Cache

CYBER ATTACKZerowl

Researchers studying cybersecurity have discovered a new version of the "ClickFix" social engineering campaign, which uses a more advanced method to avoid.

Microsoft 365 Exchange URL Filtering Update Quarantines Legitimate Emails as Phishing

Microsoft 365 Exchange URL Filtering Update Quarantines Legitimate Emails as Phishing

CYBER ATTACKZerowl

Beginning February 9, 2026, a widespread false-positive storm was caused by a flawed URL filtering rule update in Microsoft Exchange Online This article.

Microsoft 365 Copilot Flaw Allows AI Assistant to Summarize Sensitive Emails

Microsoft 365 Copilot Flaw Allows AI Assistant to Summarize Sensitive Emails

CYBER ATTACKZerowl

By avoiding configured Data Loss Prevention (DLP) policies and summarizing email messages protected by confidentiality sensitivity labels incorrectly, a.

Malware Campaign Delivers Remote Access Backdoor and Fake MetaMask Wallet to Steal Cryptocurrency Funds

Malware Campaign Delivers Remote Access Backdoor and Fake MetaMask Wallet to Steal Cryptocurrency Funds

CYBER ATTACKZerowl

Threat actors from North Korea have started a sophisticated attack campaign aimed at IT specialists working in the fields of artificial intelligence.

ClickFix Abuses Legitimate Homebrew Workflow to Deploy Cuckoo Stealer on macOS for Credential Harvesting

ClickFix Abuses Legitimate Homebrew Workflow to Deploy Cuckoo Stealer on macOS for Credential Harvesting

CYBER ATTACKZerowl

Through phony Homebrew installation pages that install the extensive credential-harvesting malware Cuckoo Stealer, a sophisticated social engineering.

OpenClaw AI Framework v2026.2.17 Released with Anthropic Model Support and Security Fixes

OpenClaw AI Framework v2026.2.17 Released with Anthropic Model Support and Security Fixes

CYBER ATTACKZerowl

Release of the OpenClaw AI Framework v2026.2.17 With major improvements, including support for Anthropic's Claude Sonnet 4.6 model, OpenClaw has released.

New SysUpdate Variant Malware Discovered and Tool Developed to Decrypt Encrypted Linux C2 Traffic

New SysUpdate Variant Malware Discovered and Tool Developed to Decrypt Encrypted Linux C2 Traffic

CYBER ATTACKZerowl

Discover how Targeting Linux systems with sophisticated command-and-control (C2) encryption capabilities, a new SysUpdate malware variant has surfaced as.

ClawHavoc Poisoned OpenClaw’s ClawHub with 1,184 Malicious Skills, Enabling Data Theft and Backdoor Access

ClawHavoc Poisoned OpenClaw’s ClawHub with 1,184 Malicious Skills, Enabling Data Theft and Backdoor Access

CYBER ATTACKZerowl

OpenClaw's official marketplace, ClawHub, was the target of a massive supply chain poisoning campaign called ClawHavoc, which disseminated 1,184 malicious.

16 Common PDF Platform Zero-Day Vulnerabilities Permit Data Exfiltration and Code Execution

16 Common PDF Platform Zero-Day Vulnerabilities Permit Data Exfiltration and Code Execution

CYBER ATTACKZerowl

PDF Zero-Day Vulnerabilities: Apryse WebViewer (formerly PDFTron) and Foxit PDF cloud services have 16 zero-day vulnerabilities that impact millions of.

Top 5 this week

Page 24 of 44