CYBER ATTACK

Cisco Source Code and Data Leak Allegedly Claimed by ShinyHunters

Cisco Source Code and Data Leak Allegedly Claimed by ShinyHunters

CYBER ATTACKZerowl

ShinyHunters, a well-known group of hackers, has taken credit for three separate data breaches that affected Cisco Systems, Inc This article explores.

CISA Alerts on Chrome Zero-Day Exploit Actively Used in Attacks

CISA Alerts on Chrome Zero-Day Exploit Actively Used in Attacks

CYBER ATTACKZerowl

The U.S This article explores flaw google chrome. . Cybersecurity and Infrastructure Security Agency (CISA) has sent out an urgent alert about a serious.

XLoader Malware Upgrades Obfuscation Tactics and Hides C2 Traffic Behind Decoy Servers

XLoader Malware Upgrades Obfuscation Tactics and Hides C2 Traffic Behind Decoy Servers

CYBER ATTACKZerowl

X loader is a type of malware that steals passwords, cookies, and other private data from computers that have been infected This article explores loader.

Windows 11 Emergency Update Fixes Installation Loop Issue

Windows 11 Emergency Update Fixes Installation Loop Issue

CYBER ATTACKZerowl

On March 31, 2026, Microsoft released an out-of-band emergency patch to fix a serious installation problem that was affecting millions of Windows 11 users.

TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Entities

TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Entities

CYBER ATTACKZerowl

Government agencies, the military, and operators of critical infrastructure all use TrueConf, a popular video conferencing platform This article explores.

New npm Supply Chain Attack Uses undicy-http to Deploy Screen-Streaming RAT and Browser Injector

New npm Supply Chain Attack Uses undicy-http to Deploy Screen-Streaming RAT and Browser Injector

CYBER ATTACKZerowl

The Node.js developer community has been infected by a malicious package called undicy-http This article explores linked lofygang threat. . This package.

Mercor AI Confirms Data Breach Following Lapsus$ Claims of 4TB Data Theft

Mercor AI Confirms Data Breach Following Lapsus$ Claims of 4TB Data Theft

CYBER ATTACKZerowl

The hacking group Lapsus$ has put Mercor's platform data up for auction on the dark web, where interested buyers can "make an offer." Threat actors say.

Malicious Telnyx Python Package On PyPI Targets Developer Credentials

Malicious Telnyx Python Package On PyPI Targets Developer Credentials

CYBER ATTACKZerowl

TeamPCP put two bad copies of Telnyx's official Python SDK on PyPI. The attack was set up so that it would automatically start when the library was.

Emerging Homoglyph Techniques Let Attackers Spoof Legitimate Websites

Emerging Homoglyph Techniques Let Attackers Spoof Legitimate Websites

CYBER ATTACKZerowl

Homograph attacks are common because people can't tell the difference between similar characters This article explores credentials homoglyph attacks.

CrewAI Vulnerabilities Allow Attackers to Bypass Sandboxes and Compromise Systems

CrewAI Vulnerabilities Allow Attackers to Bypass Sandboxes and Compromise Systems

CYBER ATTACKZerowl

CrewAI, a necessary tool for running multi-agent AI systems, has been found to have a number of serious security holes This article explores docker crewai.

Hackers use Telegram-based ResokerRAT, which has screenshot and persistence features.

Hackers use Telegram-based ResokerRAT, which has screenshot and persistence features.

CYBER ATTACKZerowl

ResokerRAT is a new type of remote access trojan that has been found This article explores createmutexw api malware. . It uses Telegram's bot API as its.

New ANY.RUN macOS Sandbox Helps SOC Teams Analyze Apple Threats Faster

New ANY.RUN macOS Sandbox Helps SOC Teams Analyze Apple Threats Faster

CYBER ATTACKZerowl

Virtual machines for macOS are now part of ANY.RUN's interactive sandbox platform This article explores miolab stealer macos. . Enterprise Suite users can.

Zero-Day Alert: Claude AI Finds Critical RCE Bugs in Vim and Emacs

Zero-Day Alert: Claude AI Finds Critical RCE Bugs in Vim and Emacs

CYBER ATTACKZerowl

Researchers at Calif showed that a simple conversation with Claude AI was enough to find serious zero-day Remote Code Execution (RCE) flaws in two of the.

WordPress Plugin Vulnerability Exposes Sensitive Data From 800,000+ Sites

WordPress Plugin Vulnerability Exposes Sensitive Data From 800,000+ Sites

CYBER ATTACKZerowl

Smart Slider 3, one of the most popular WordPress slider builder plugins, has a serious security hole that has been found This article explores plugins.

PNG Vulnerabilities Allow Attackers to Crash Systems and Leak Sensitive Data

PNG Vulnerabilities Allow Attackers to Crash Systems and Leak Sensitive Data

CYBER ATTACKZerowl

Researchers have found two serious security holes in libpng, which is the most widely used reference library for working with Portable Network Graphics.

Google Unveils Ransomware Detection and File Recovery for Google Drive

Google Unveils Ransomware Detection and File Recovery for Google Drive

CYBER ATTACKZerowl

Google has officially released its advanced ransomware detection and file restoration features for Google Drive, which were previously only available in.

EvilTokens is a new phishing-as-a-service platform that lets people take over Microsoft accounts.

EvilTokens is a new phishing-as-a-service platform that lets people take over Microsoft accounts.

CYBER ATTACKZerowl

In early 2026, underground cybercrime groups started sharing EvilTokens, a phishing-as-a-service platform. It misuses the legitimate Microsoft device code.

Active Supply Chain Attack Hits Axios NPM Packages

Active Supply Chain Attack Hits Axios NPM Packages

CYBER ATTACKZerowl

The Axios HTTP client, which is very popular and available on the npm registry, has been hit by a serious and complex supply chain attack This article.

Dutch Ministry of Finance Takes Systems Offline Following Cyberattack

Dutch Ministry of Finance Takes Systems Offline Following Cyberattack

CYBER ATTACKZerowl

Several important internal systems have been taken offline by the Dutch Ministry of Finance. On March 19, 2026, security teams found the breach when they.

Cybercriminals Abuse IRS and Tax Filing Lures to Push Malware in New Campaigns

Cybercriminals Abuse IRS and Tax Filing Lures to Push Malware in New Campaigns

CYBER ATTACKZerowl

Every year around tax time, there are a lot of phishing attacks, but 2026 has already seen a bigger and more organized push than in previous years This.

CISA Warns of Citrix NetScaler Vulnerability Actively Exploited in Attacks

CISA Warns of Citrix NetScaler Vulnerability Actively Exploited in Attacks

CYBER ATTACKZerowl

The Cybersecurity and Infrastructure Security Agency (CISA) has sent out an urgent warning about a serious flaw in Citrix NetScaler products This article.

ChatGPT Vulnerability Let Attackers Silently Exfiltrate User Prompts and Other Sensitive Data

ChatGPT Vulnerability Let Attackers Silently Exfiltrate User Prompts and Other Sensitive Data

CYBER ATTACKZerowl

People often give AI assistants very private information, like medical records, financial documents, and proprietary business code This article explores.

CareCloud Data Breach – Hackers Accessed IT Infrastructure and Stole Patient Data

CareCloud Data Breach – Hackers Accessed IT Infrastructure and Stole Patient Data

CYBER ATTACKZerowl

CareCloud has officially announced a major cybersecurity event in which someone gained unauthorized access to its IT infrastructure This article explores.

Apples new macOS Tahoe feature warns users about ClickFix attacks.

Apples new macOS Tahoe feature warns users about ClickFix attacks.

CYBER ATTACKZerowl

Apple adds a new security feature to keep users safe from ClickFix attacks, which are social engineering campaigns This article explores virtualization.

It looks like the Claude Code Source Code from Anthropic was leaked through their npm registry.

It looks like the Claude Code Source Code from Anthropic was leaked through their npm registry.

CYBER ATTACKZerowl

Discover how The full TypeScript source code for Anthropic's proprietary Claude Code tool has been made public by mistake. A security researcher found a.

Notepad++ v8.9.3 Released Addressing cURL Security Vulnerability and Crash Issues

Notepad++ v8.9.3 Released Addressing cURL Security Vulnerability and Crash Issues

CYBER ATTACKZerowl

Notepad++ has officially released version 8.9.3 This article explores notepad stable secure. . This version fixes security holes, improves the program's.

New DeepLoad Malware Uses ClickFix and AI-Generated Evasion to Breach Enterprise Networks

New DeepLoad Malware Uses ClickFix and AI-Generated Evasion to Breach Enterprise Networks

CYBER ATTACKZerowl

DeepLoad, a new type of malware, is going after businesses This article explores malware going. . It gives persistent, credential-stealing access to a.

Top 5 this week

Page 4 of 44