CYBER ATTACK

Single-Character Typo of “&” Instead of “|” Leads to 0-Day RCE in Firefox

Single-Character Typo of “&” Instead of “|” Leads to 0-Day RCE in Firefox

CYBER ATTACKZerowl

0-Day RCE for Firefox A single-character typo in the SpiderMonkey JavaScript engine's WebAssembly garbage collection code led to a critical Remote Code.

Paloalto to Acquire Koi Security for Establishing Agentic Endpoint security

Paloalto to Acquire Koi Security for Establishing Agentic Endpoint security

CYBER ATTACKZerowl

Palo Alto Networks has announced a definitive agreement to acquire Koi Security, a leading innovator in Agentic Endpoint Security This article explores.

Palo Alto Networks to Acquire Koi Security to Advance Agentic Endpoint Protection

Palo Alto Networks to Acquire Koi Security to Advance Agentic Endpoint Protection

CYBER ATTACKZerowl

Discover how By purchasing Koi Security, a startup that specializes in shielding endpoints from the threats posed by sophisticated AI agents, Palo Alto.

New ‘CRESCENTHARVEST’ Malware Abuses Iran Protest Narrative For RAT Deployment

New ‘CRESCENTHARVEST’ Malware Abuses Iran Protest Narrative For RAT Deployment

CYBER ATTACKZerowl

CRESCENTHARVEST is a new malware campaign that targets Iranian protest supporters by taking advantage of the country's ongoing geopolitical unrest. This.

CISA Adds Windows Video ActiveX Control RCE Flaw to KEV Catalog Following Active Exploitation

CISA Adds Windows Video ActiveX Control RCE Flaw to KEV Catalog Following Active Exploitation

CYBER ATTACKZerowl

Windows Video ActiveX Control is Added by CISA RCE Error Following proof of active exploitation in the wild, CVE-2008-0015, a long-dormant Microsoft.

Claude Sonnet 4.6 with enhanced coding, computer usage, and a 1M token context window is released by Anthropic.

Claude Sonnet 4.6 with enhanced coding, computer usage, and a 1M token context window is released by Anthropic.

CYBER ATTACKZerowl

Discover how The most powerful mid-tier model to date, Claude Sonnet 4.6, has been formally released by Anthropic. It offers a thorough improvement in.

Notepad++ v8.9.2 Released with “Double-Lock” Update Mechanism Following Recent Hack

Notepad++ v8.9.2 Released with “Double-Lock” Update Mechanism Following Recent Hack

CYBER ATTACKZerowl

Release of Notepad++ v8.9.2 With the release of version v8.9.2, the popular open-source text and code editor has added a significant security feature.

New ‘Foxveil’ Malware Loader Leverages Cloudflare, Netlify, and Discord to Evade Detection

New ‘Foxveil’ Malware Loader Leverages Cloudflare, Netlify, and Discord to Evade Detection

CYBER ATTACKZerowl

The discovery of a new malware loader known as "Foxveil" that actively targets systems via reputable cloud platforms raises questions about how threat.

New “ClickFix” Payload Stores Malware In Browser Cache

New “ClickFix” Payload Stores Malware In Browser Cache

CYBER ATTACKZerowl

Researchers studying cybersecurity have discovered a new threat actor peddling a cunning tool known as "ClickFix." According to this payload-delivery.

Microsoft VS Code Extension with 11M Downloads Expose Developers to One-Click XSS Attacks

Microsoft VS Code Extension with 11M Downloads Expose Developers to One-Click XSS Attacks

CYBER ATTACKZerowl

Downloads for Microsoft VS Code Extension 11M A serious flaw in Microsoft's widely used Visual Studio Code (VS Code) Live Preview extension, which has.

Cybercriminals Exploit Atlassian Cloud For Large-Scale Spam Campaigns Targeting Investors

Cybercriminals Exploit Atlassian Cloud For Large-Scale Spam Campaigns Targeting Investors

CYBER ATTACKZerowl

Cybercriminals have launched extensive spam campaigns aimed at government agencies and investors by taking advantage of Atlassian Jira Cloud. From late.

ClickFix Social Engineering Fuels Matanbuchus 3.0 AstarionRAT Attack

ClickFix Social Engineering Fuels Matanbuchus 3.0 AstarionRAT Attack

CYBER ATTACKZerowl

Cybersecurity researchers discovered a complex attack chain in which the attackers delivered Matanbuchus 3.0 malware via ClickFix social engineering.

CISA Adds Actively Exploited Windows ActiveX RCE Flaw to KEV Catalog

CISA Adds Actively Exploited Windows ActiveX RCE Flaw to KEV Catalog

CYBER ATTACKZerowl

A critical remote code execution (RCE) vulnerability in Microsoft Windows Video ActiveX Control has been added to the U.S This article explores exploits.

New Malware Campaign ‘CRESCENTHARVEST’ Exploits Iran Protest Sentiment to Deploy Information-Stealing RAT

New Malware Campaign ‘CRESCENTHARVEST’ Exploits Iran Protest Sentiment to Deploy Information-Stealing RAT

CYBER ATTACKZerowl

A highly skilled new malware campaign called "CRESCENTHARVEST" has emerged, deliberately taking advantage of Iran's geopolitical instability to target.

Matanbuchus 3.0 Returns with ClickFix Social Engineering and Silent MSI Installations to Deploy AstarionRAT

Matanbuchus 3.0 Returns with ClickFix Social Engineering and Silent MSI Installations to Deploy AstarionRAT

CYBER ATTACKZerowl

After a nearly year-long break, the premium malware-as-a-service loader Matanbuchus reappeared in February 2026 This article explores premium malware.

Malicious Triton App Fork Emerges On GitHub, Posing Threat To Cybersecurity

Malicious Triton App Fork Emerges On GitHub, Posing Threat To Cybersecurity

CYBER ATTACKZerowl

A malicious fork of the well-known macOS app Triton was recently discovered on GitHub, which has caused concern in the cybersecurity community. The app's.

Hackers Exploit QR Codes To Spread Phishing and Malware Across Mobile Phones

Hackers Exploit QR Codes To Spread Phishing and Malware Across Mobile Phones

CYBER ATTACKZerowl

Because they make it simple for people to access websites, make payments, and download apps, QR codes have become commonplace in daily life This article.

Dell Zero-Day Actively Abused by China-Linked Threat Actors to Install Malware

Dell Zero-Day Actively Abused by China-Linked Threat Actors to Install Malware

CYBER ATTACKZerowl

Since mid-2024, Chinese state-sponsored hackers have been focusing on a critical zero-day vulnerability in Dell RecoverPoint for Virtual Machines This.

Dell 0-Day Vulnerability Exploited by Chinese Hackers Since mid-2024 to Deploy Malware

Dell 0-Day Vulnerability Exploited by Chinese Hackers Since mid-2024 to Deploy Malware

CYBER ATTACKZerowl

Dell's Zero-Day Vulnerability Dell RecoverPoint for Virtual Machines is the target of a serious zero-day exploitation campaign. The vulnerability.

Cybercriminals Leverage Atlassian Cloud for Spam Campaigns Redirecting Targets to Fraudulent Investment Schemes

Cybercriminals Leverage Atlassian Cloud for Spam Campaigns Redirecting Targets to Fraudulent Investment Schemes

CYBER ATTACKZerowl

Using Atlassian Cloud's reliable infrastructure, cybercriminals have started a sophisticated spam campaign. Attackers are successfully evading.

Critical Windows Admin Center Vulnerability Allows Privilege Escalation

Critical Windows Admin Center Vulnerability Allows Privilege Escalation

CYBER ATTACKZerowl

Admin Center Vulnerability in Windows CVE-2026-26119 is a critical security update that fixes a high-severity elevation of privilege vulnerability in.

Critical Log Poisoning Vulnerability in OpenClaw AI Allows Content Manipulation

Critical Log Poisoning Vulnerability in OpenClaw AI Allows Content Manipulation

CYBER ATTACKZerowl

Organizations are vulnerable to indirect prompt injection attacks due to a critical "log poisoning" vulnerability in the popular OpenClaw AI assistant.

Keenadu Android Backdoor Spreads Through Google Play to Gain Remote Control Access by Infecting Firmware

Keenadu Android Backdoor Spreads Through Google Play to Gain Remote Control Access by Infecting Firmware

CYBER ATTACKZerowl

Android malware from Keenadu An advanced new Android backdoor that allows attackers to take remote control of victims' phones and tablets by infecting.

As a malicious fork of a legitimate Triton app appears on GitHub, malware is out in the wild.

As a malicious fork of a legitimate Triton app appears on GitHub, malware is out in the wild.

CYBER ATTACKZerowl

On GitHub, a malicious fork of the trustworthy macOS app Triton has emerged, using open-source repositories to spread malware This article explores.

Phishing attacks and malicious apps are distributed across mobile devices via QR codes.

Phishing attacks and malicious apps are distributed across mobile devices via QR codes.

CYBER ATTACKZerowl

Although QR codes are now commonly used to pay bills, open links, and log in, their speed also allows attackers to quickly lure victims from the real.

Washington Hotel Located in Japan Suffers Ransomware Attack

Washington Hotel Located in Japan Suffers Ransomware Attack

CYBER ATTACKZerowl

Japan's Washington Hotel Suffers Attack by Ransomware The hotel acknowledged that a ransomware attack had compromised a number of its servers, causing.

US Law Firm Accuses Lenovo of Bulk Data Transfers to China

US Law Firm Accuses Lenovo of Bulk Data Transfers to China

CYBER ATTACKZerowl

A U.S This article explores alleging lenovo violated. . law firm has filed a proposed class action alleging that Lenovo violated the Justice Department's.

Phishing Kit Hosted on Legitimate Cloud and CDN Platforms Targeting Microsoft and Google Users

Phishing Kit Hosted on Legitimate Cloud and CDN Platforms Targeting Microsoft and Google Users

CYBER ATTACKZerowl

Phishing kit infrastructure is increasingly being hosted on reputable cloud and CDN platforms instead of newly registered domains, according to ANY.RUN.

India’s Largest Pharmacy Exposes Customer Personal Details and Access to Internal Systems

India’s Largest Pharmacy Exposes Customer Personal Details and Access to Internal Systems

CYBER ATTACKZerowl

India's Biggest Pharmacy Reveals A significant flaw in a Zota Healthcare division's platform exposed private client and internal system information.

Top 5 this week

Page 25 of 44