CYBER ATTACK

ZerOwl — Find Vulnerabilities Before Hackers Do
Palo Alto Networks Patches 11 New Vulnerabilities Across PAN-OS, GlobalProtect, and Prisma Access

Palo Alto Networks Patches 11 New Vulnerabilities Across PAN-OS, GlobalProtect, and Prisma Access

CYBER ATTACKZerowl

Palo Alto Networks has issued its August 12, 2026 security bulletin, announcing the discovery of 11 new vulnerabilities impacting PAN-OS, GlobalProtect.

Pairing IT Support and Consulting to Accelerate Technology Modernization

Pairing IT Support and Consulting to Accelerate Technology Modernization

CYBER ATTACKZerowl

In today’s dynamic business environment, businesses must prioritize technology modernization to remain competitive. A recent study reveals that 70% of.

New Vidar Stealer Campaign Targets User Credentials

New Vidar Stealer Campaign Targets User Credentials

CYBER ATTACKZerowl

A covert operation orchestrated by North Korea's APT37 group has compromised numerous organizations across defense, law enforcement, and academic circles.

New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide

New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide

CYBER ATTACKZerowl

A new cyber threat actor has been identified operating a large-scale, long-running campaign targeting Salesforce Experience Cloud and ServiceNow portals.

Multiple TP-Link Vulnerabilities Allow Attackers to Bypass Authentication and Escalate Privileges

Multiple TP-Link Vulnerabilities Allow Attackers to Bypass Authentication and Escalate Privileges

CYBER ATTACKZerowl

TP-Link has acknowledged multiple severe vulnerabilities impacting Aginet networking devices managed by ISPs, including mesh systems, routers, PON units.

Microsoft SharePoint Server Vulnerability Allows Attackers to Inject and Execute Malicious Code Remotely

Microsoft SharePoint Server Vulnerability Allows Attackers to Inject and Execute Malicious Code Remotely

CYBER ATTACKZerowl

A newly disclosed flaw in Microsoft SharePoint Server has rekindled concerns among enterprise IT departments, as security researchers unveil how attackers.

Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and RCE Attacks

Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and RCE Attacks

CYBER ATTACKZerowl

Microsoft has released patches for several Exchange Server vulnerabilities that could lead to denial-of-service, privilege escalation, remote code.

Malicious VS Code Extension Drops Detached Python Payload Outside the Extension Host

Malicious VS Code Extension Drops Detached Python Payload Outside the Extension Host

CYBER ATTACKZerowl

A dangerous VS Code extension called "Solidity Pro" is infiltrating cryptocurrency developers' environments with a sophisticated multi-stage attack.

Magecart Campaign Uses Google Tag Manager To Steal Credit Card Data

Magecart Campaign Uses Google Tag Manager To Steal Credit Card Data

CYBER ATTACKZerowl

A notorious Magecart group is utilizing Google Tag Manager (GTM) to silently inject custom scripts onto e-commerce sites, effectively turning trusted.

HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel

HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel

CYBER ATTACKZerowl

A newly discovered malware framework called HACKERAI C2 Agent is utilizing GitHub Gists as a covert communication channel for attackers to execute.

Fortinet Patches Multiple Authentication Vulnerabilities in FortiWeb, FortiManager, and FortiClient

Fortinet Patches Multiple Authentication Vulnerabilities in FortiWeb, FortiManager, and FortiClient

CYBER ATTACKZerowl

Fortinet has released patches addressing authentication vulnerabilities across its FortiWeb, FortiManager, and FortiClient product lines, urging.

Eclipse Ransomware Launches RaaS Platform Targeting Windows, Linux, and ESXi Infrastructure

Eclipse Ransomware Launches RaaS Platform Targeting Windows, Linux, and ESXi Infrastructure

CYBER ATTACKZerowl

A cybercriminal gang known as EclipseSupport is promoting a new Ransomware-as-a-Service (RaaS) operation called Eclipse Ransomware on forums This article.

Dysphoria Botnet Compromises 296,000 IoT Devices for DDoS and Residential Proxy Operations

Dysphoria Botnet Compromises 296,000 IoT Devices for DDoS and Residential Proxy Operations

CYBER ATTACKZerowl

A Special Report has identified approximately 296,000 internet-connected devices compromised by the Dysphoria botnet, marking an expansion of an IoT.

DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling

DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling

CYBER ATTACKZerowl

A new DCRat operation employs an old trick: it uses SVG files to hide malicious software within phishing emails. The scheme starts with fake notifications.

Cybercriminals Can Now Rent Malware That Re-Encrypts Itself to Keep Evading Antivirus

Cybercriminals Can Now Rent Malware That Re-Encrypts Itself to Keep Evading Antivirus

CYBER ATTACKZerowl

Cybercriminals are renting tools that help disguise their malicious software and evade detection This article explores cruciferra crypter service.

Citrix NetScaler Heap Overflow Flaw Lets Remote Attackers Execute Code as Root – PoC Released

Citrix NetScaler Heap Overflow Flaw Lets Remote Attackers Execute Code as Root – PoC Released

CYBER ATTACKZerowl

A working proof-of-concept exploit has been developed to demonstrate how a pre-authentication heap overflow in Citrix NetScaler ADC and Gateway can be.

CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks

CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks

CYBER ATTACKZerowl

The U.S This article explores windows vulnerability known. . Cybersecurity and Infrastructure Security Agency has added a Microsoft Windows vulnerability.

Bring Your Own EDR Attack Turns SentinelOne Into PPL-Protected Trojan Horse to Shield Malware

Bring Your Own EDR Attack Turns SentinelOne Into PPL-Protected Trojan Horse to Shield Malware

CYBER ATTACKZerowl

A "Bring Your Own EDR" attack leverages trusted SentinelOne components to transform endpoint protection into a potent malware shield This article explores.

Apple Urges Mercenary Spyware Targets to Enable Lockdown Mode Immediately

Apple Urges Mercenary Spyware Targets to Enable Lockdown Mode Immediately

CYBER ATTACKZerowl

Apple quietly introduced a new batch of high-confidence "Apple Threat Notification" alerts to select iPhone users across 110 countries. According to.

AI Token Jacking Lets Hackers Steal API Keys and Rack Up Nearly $1 Million in Charges

AI Token Jacking Lets Hackers Steal API Keys and Rack Up Nearly $1 Million in Charges

CYBER ATTACKZerowl

AI credentials are becoming targets for cybercriminals This article explores ai credentials targets. . A new tactic called AI token jacking allows.

Agentic AI Models Rebuild Malware and Pivot Attack Paths Across Real-World Intrusions

Agentic AI Models Rebuild Malware and Pivot Attack Paths Across Real-World Intrusions

CYBER ATTACKZerowl

Four recent disclosures highlight a concerning trend in cybersecurity risk as AI agents continue to evolve and adapt after repeated failures. OpenAI.

Zoom Zero-Click Vulnerabilities Allow Meeting Participants to Hijack Other Users’ Devices

Zoom Zero-Click Vulnerabilities Allow Meeting Participants to Hijack Other Users’ Devices

CYBER ATTACKZerowl

Zoom has released patches addressing four newly disclosed vulnerabilities that allow a malicious participant to remotely execute code on another.

Zoom Zero-Click Flaw Lets Meeting Participants Take Over Devices Without User Interaction

Zoom Zero-Click Flaw Lets Meeting Participants Take Over Devices Without User Interaction

CYBER ATTACKZerowl

Zoom has addressed four security vulnerabilities that could enable remote code execution, crash other attendees' clients, or access sensitive files This.

Windows AFD.sys 0-Day Actively Exploited by Lazarus Hackers to Deploy FudModule Rootkit

Windows AFD.sys 0-Day Actively Exploited by Lazarus Hackers to Deploy FudModule Rootkit

CYBER ATTACKZerowl

North Korea's Lazarus group has been identified as responsible for exploiting a Windows kernel zero-day vulnerability to deploy an updated version of its.

Why Container Image Security Is Important in 2026

Why Container Image Security Is Important in 2026

CYBER ATTACKZerowl

Modern application development increasingly necessitates containers for streamlined progress, but they can also present security risks This article.

Trump Signs Memo Authorizing Private Firms for Cyber Operations Against Foreign Criminals

Trump Signs Memo Authorizing Private Firms for Cyber Operations Against Foreign Criminals

CYBER ATTACKZerowl

President Donald Trump has issued a presidential directive that allows businesses to engage in government-led cybersecurity efforts against foreign.

ShieldBreak Windows Defender Zero-Day Bypasses Microsoft Patch to Gain SYSTEM Access

ShieldBreak Windows Defender Zero-Day Bypasses Microsoft Patch to Gain SYSTEM Access

CYBER ATTACKZerowl

Nightmare-Eclipse, also known as Chaotic Eclipse, has unveiled ShieldBreak, a new Windows zero-day exploit targeting the RoguePlanet privilege-escalation.

Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals

Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals

CYBER ATTACKZerowl

Discover how Sandworm Cyber Threats Target IT Professionals A group linked to Sandworm is using fake job interviews as a tactic to trick IT professionals.

RovoBlast Flaw Lets One Click Force Atlassian AI to Leak Enterprise Data

RovoBlast Flaw Lets One Click Force Atlassian AI to Leak Enterprise Data

CYBER ATTACKZerowl

A newly discovered vulnerability in Atlassian's Rovo enterprise AI assistant allows attackers to turn a single malicious link into a route for exposing.

Top 5 this week

Page 4 of 60