CYBER ATTACK

ZerOwl — Find Vulnerabilities Before Hackers Do
Kali Linux Enhances AI-driven Penetration Testing with Local Ollama, 5ire, and MCP Kali Server

Kali Linux Enhances AI-driven Penetration Testing with Local Ollama, 5ire, and MCP Kali Server

CYBER ATTACKZerowl

AI-powered Penetration Testing with Kali Linux The Kali Linux team has released a new version of their expanding LLM-driven security series, which.

Ivanti Desktop and Server Management Vulnerability Allows Attackers to Escalate Privileges

Ivanti Desktop and Server Management Vulnerability Allows Attackers to Escalate Privileges

CYBER ATTACKZerowl

A high-severity vulnerability that could enable a local authenticated attacker to increase their privileges on impacted systems has been fixed by Ivanti's.

iPhone Hacking Toolkit Used by Russian Spies Likely Developed by U.S. Contractor

iPhone Hacking Toolkit Used by Russian Spies Likely Developed by U.S. Contractor

CYBER ATTACKZerowl

A sophisticated iPhone exploit toolkit called "Coruna" is at the center of an escalating controversy after new research revealed that it most likely came.

iPhone Exploit Toolkit Used by Russian Spies Likely Originated from U.S. Contractor

iPhone Exploit Toolkit Used by Russian Spies Likely Originated from U.S. Contractor

CYBER ATTACKZerowl

Russian Spies Used an iPhone Exploit Toolkit Russian spies and Chinese cybercriminals have gained access to a potent iPhone exploit kit called "Coruna,".

Hackers Attack Employees Over Microsoft Teams to Trick Them Into Granting Remote Access

Hackers Attack Employees Over Microsoft Teams to Trick Them Into Granting Remote Access

CYBER ATTACKZerowl

Hackers Target Microsoft Teams After persuading staff members to grant remote access, the attackers are now using a recently discovered malware family.

GhostClaw Mimic as OpenClaw to Steal Everything from Developers

GhostClaw Mimic as OpenClaw to Steal Everything from Developers

CYBER ATTACKZerowl

A rogue npm package that poses as a reliable developer tool has surfaced as part of a dangerous malware campaign that targets software developers This.

Fortinet FortiManager fgtupdates Vulnerability Allows Attackers to Execute Malicious Commands

Fortinet FortiManager fgtupdates Vulnerability Allows Attackers to Execute Malicious Commands

CYBER ATTACKZerowl

A high-severity stack-based buffer overflow vulnerability in Fortinet's FortiManager platform has been made public This article explores vulnerability.

Fake GitHub Repos Push BoryptGrab Stealer To Harvest Browser and Wallet Data

Fake GitHub Repos Push BoryptGrab Stealer To Harvest Browser and Wallet Data

CYBER ATTACKZerowl

Researchers have discovered a new malware campaign that propagates the stealer BoryptGrab by using phony GitHub repositories This article explores malware.

Fake CleanMyMac Website Pushes SHub Stealer To Drain Crypto Wallet Data

Fake CleanMyMac Website Pushes SHub Stealer To Drain Crypto Wallet Data

CYBER ATTACKZerowl

A phony CleanMyMac website is being used by a new macOS malware campaign to trick users into infecting their own computers This article explores.

Critical Pingora Vulnerabilities Expose Cloudflare to Request Smuggling and Cache Poisoning Attacks

Critical Pingora Vulnerabilities Expose Cloudflare to Request Smuggling and Cache Poisoning Attacks

CYBER ATTACKZerowl

Cloudflare has fixed several Pingora vulnerabilities that could allow attackers to smuggle HTTP requests through poison caches and edge proxies, creating.

Cloudflare Pingora Vulnerabilities Allows Request Smuggling & Cache Poisoning Attacks

Cloudflare Pingora Vulnerabilities Allows Request Smuggling & Cache Poisoning Attacks

CYBER ATTACKZerowl

Vulnerabilities in Cloudflare Pingora In order to address three serious vulnerabilities, Cloudflare has released version 0.8.0 of its open-source Pingora.

CISA Warns of Ivanti Endpoint Manager Authentication Bypass Vulnerability Exploited in Attacks

CISA Warns of Ivanti Endpoint Manager Authentication Bypass Vulnerability Exploited in Attacks

CYBER ATTACKZerowl

Following its addition to the Known Exploited Vulnerabilities (KEV) catalog by the Cybersecurity and Infrastructure Security Agency (CISA) on March 9.

Chinese APT Campaign Targets Qatar With PlugX Lures Tied to Middle East Conflict

Chinese APT Campaign Targets Qatar With PlugX Lures Tied to Middle East Conflict

CYBER ATTACKZerowl

Discover how One day after fresh hostilities broke out in the Middle East on March 1, 2026, Camaro Dragon, an advanced persistent threat group with ties.

Iran-Linked Hackers Target U.S. Critical Infrastructure Amid Rising Cyber Threat Activity

Iran-Linked Hackers Target U.S. Critical Infrastructure Amid Rising Cyber Threat Activity

CYBER ATTACKZerowl

Since early February 2026, the Iranian advanced persistent threat group known as Seedworm—also known as MuddyWater, Temp Zagros, and Static Kitten—has.

BoryptGrab Stealer Steals Browser and Crypto Wallet Data and Spreads via False GitHub Repositories

BoryptGrab Stealer Steals Browser and Crypto Wallet Data and Spreads via False GitHub Repositories

CYBER ATTACKZerowl

Through a network of phony GitHub repositories, a new data-stealing malware known as BoryptGrab has been covertly propagating throughout Windows systems.

Vietnam-Based Cybercrime Network Enables Fraudulent Account Signups at Scale

Vietnam-Based Cybercrime Network Enables Fraudulent Account Signups at Scale

CYBER ATTACKZerowl

Large-scale fraudulent account registration campaigns that target service providers and online platforms globally have been connected to a vast cybercrime.

Signal Confirms Targeted Phishing Attacks Resulting in Account Takeovers

Signal Confirms Targeted Phishing Attacks Resulting in Account Takeovers

CYBER ATTACKZerowl

Discover how An ongoing wave of targeted phishing campaigns that have successfully taken over the accounts of prominent users, including government.

Microsoft Launches Copilot Cowork, a New AI Feature in Microsoft 365 to Automate Tasks

Microsoft Launches Copilot Cowork, a New AI Feature in Microsoft 365 to Automate Tasks

CYBER ATTACKZerowl

Copilot Cowork, a new AI-powered feature integrated into Microsoft 365 that goes beyond conversational support to autonomous task execution, was unveiled.

MaaS VIP Keylogger Campaign Uses Steganography and In-Memory Execution to Steal Credentials at Scale

MaaS VIP Keylogger Campaign Uses Steganography and In-Memory Execution to Steal Credentials at Scale

CYBER ATTACKZerowl

Organizations and individuals are now seriously threatened by a sophisticated credential-stealing campaign based on a tool known as VIP Keylogger This.

M365Pwned: Red Team GUI Toolkit for Graph API-Based Microsoft 365 Exploitation

M365Pwned: Red Team GUI Toolkit for Graph API-Based Microsoft 365 Exploitation

CYBER ATTACKZerowl

M365Pwned, two WinForms GUI tools created to enumerate, search, and exfiltrate data from Microsoft 365 environments using application-level OAuth tokens.

Transparent Tribe’s ‘Vibeware’ Shift Signals Rise of AI-Generated Malware at Industrial Scale

Transparent Tribe’s ‘Vibeware’ Shift Signals Rise of AI-Generated Malware at Industrial Scale

CYBER ATTACKZerowl

Threat actor APT36, also known as Transparent Tribe, is based in Pakistan and has switched from using well-crafted tools to a new strategy known as.

Hikvision Multiple Products Vulnerability Allows Malicious Users to Escalate Privileges

Hikvision Multiple Products Vulnerability Allows Malicious Users to Escalate Privileges

CYBER ATTACKZerowl

Hikvision Vulnerability of Multiple Products On March 5, 2026, a serious vulnerability impacting several Hikvision products was added to the Known.

Critical Nginx UI Vulnerabilities Allow Attacker to Download a Full System Backup

Critical Nginx UI Vulnerabilities Allow Attacker to Download a Full System Backup

CYBER ATTACKZerowl

Vulnerabilities in the Nginx UI Full system backups can be downloaded and decrypted by unauthorized attackers thanks to a recently identified critical.

Critical ExifTool Flaw Lets Malicious Images Trigger Code Execution on macOS

Critical ExifTool Flaw Lets Malicious Images Trigger Code Execution on macOS

CYBER ATTACKZerowl

Malicious Images Cause Code Execution on macOS Due to an ExifTool Flaw The long-held notion that macOS systems are intrinsically resistant to malware is.

ClipXDaemon Emerges as C2-Less Linux Clipboard Hijacker, Targeting Crypto Wallets in X11 Sessions

ClipXDaemon Emerges as C2-Less Linux Clipboard Hijacker, Targeting Crypto Wallets in X11 Sessions

CYBER ATTACKZerowl

In X11-based desktop environments, a recently identified Linux malware called ClipXDaemon has become a direct financial threat to cryptocurrency users.

Chinese-Linked CL-UNK-1068 Espionage Campaign Targets Critical Infrastructure Across Asia

Chinese-Linked CL-UNK-1068 Espionage Campaign Targets Critical Infrastructure Across Asia

CYBER ATTACKZerowl

Since at least 2020, a Chinese-affiliated cyber-espionage group known as CL-UNK-1068 has been secretly attacking vital infrastructure throughout South.

Apache ZooKeeper Vulnerability Allows Attackers to Access Sensitive Data

Apache ZooKeeper Vulnerability Allows Attackers to Access Sensitive Data

CYBER ATTACKZerowl

Two high-impact vulnerabilities that could result in the exposure of sensitive data and possible server impersonation attacks have been addressed by.

ZITADELs 1-Click Vulnerability Allows Attackers to Take Over Entire Systems

ZITADELs 1-Click Vulnerability Allows Attackers to Take Over Entire Systems

CYBER ATTACKZerowl

The open-source identity and access management (IAM) platform ZITADEL, which is frequently utilized by businesses for safe authentication procedures, has.

Top 5 this week

Page 34 of 61