CYBER ATTACK

Zero-Day Alert: Claude AI Finds Critical RCE Bugs in Vim and Emacs

Zero-Day Alert: Claude AI Finds Critical RCE Bugs in Vim and Emacs

CYBER ATTACKZerowl

Researchers at Calif showed that a simple conversation with Claude AI was enough to find serious zero-day Remote Code Execution (RCE) flaws in two of the.

WordPress Plugin Vulnerability Exposes Sensitive Data From 800,000+ Sites

WordPress Plugin Vulnerability Exposes Sensitive Data From 800,000+ Sites

CYBER ATTACKZerowl

Smart Slider 3, one of the most popular WordPress slider builder plugins, has a serious security hole that has been found This article explores plugins.

PNG Vulnerabilities Allow Attackers to Crash Systems and Leak Sensitive Data

PNG Vulnerabilities Allow Attackers to Crash Systems and Leak Sensitive Data

CYBER ATTACKZerowl

Researchers have found two serious security holes in libpng, which is the most widely used reference library for working with Portable Network Graphics.

Google Unveils Ransomware Detection and File Recovery for Google Drive

Google Unveils Ransomware Detection and File Recovery for Google Drive

CYBER ATTACKZerowl

Google has officially released its advanced ransomware detection and file restoration features for Google Drive, which were previously only available in.

EvilTokens is a new phishing-as-a-service platform that lets people take over Microsoft accounts.

EvilTokens is a new phishing-as-a-service platform that lets people take over Microsoft accounts.

CYBER ATTACKZerowl

In early 2026, underground cybercrime groups started sharing EvilTokens, a phishing-as-a-service platform. It misuses the legitimate Microsoft device code.

Active Supply Chain Attack Hits Axios NPM Packages

Active Supply Chain Attack Hits Axios NPM Packages

CYBER ATTACKZerowl

The Axios HTTP client, which is very popular and available on the npm registry, has been hit by a serious and complex supply chain attack This article.

Dutch Ministry of Finance Takes Systems Offline Following Cyberattack

Dutch Ministry of Finance Takes Systems Offline Following Cyberattack

CYBER ATTACKZerowl

Several important internal systems have been taken offline by the Dutch Ministry of Finance. On March 19, 2026, security teams found the breach when they.

Cybercriminals Abuse IRS and Tax Filing Lures to Push Malware in New Campaigns

Cybercriminals Abuse IRS and Tax Filing Lures to Push Malware in New Campaigns

CYBER ATTACKZerowl

Every year around tax time, there are a lot of phishing attacks, but 2026 has already seen a bigger and more organized push than in previous years This.

CISA Warns of Citrix NetScaler Vulnerability Actively Exploited in Attacks

CISA Warns of Citrix NetScaler Vulnerability Actively Exploited in Attacks

CYBER ATTACKZerowl

The Cybersecurity and Infrastructure Security Agency (CISA) has sent out an urgent warning about a serious flaw in Citrix NetScaler products This article.

ChatGPT Vulnerability Let Attackers Silently Exfiltrate User Prompts and Other Sensitive Data

ChatGPT Vulnerability Let Attackers Silently Exfiltrate User Prompts and Other Sensitive Data

CYBER ATTACKZerowl

People often give AI assistants very private information, like medical records, financial documents, and proprietary business code This article explores.

CareCloud Data Breach – Hackers Accessed IT Infrastructure and Stole Patient Data

CareCloud Data Breach – Hackers Accessed IT Infrastructure and Stole Patient Data

CYBER ATTACKZerowl

CareCloud has officially announced a major cybersecurity event in which someone gained unauthorized access to its IT infrastructure This article explores.

Apples new macOS Tahoe feature warns users about ClickFix attacks.

Apples new macOS Tahoe feature warns users about ClickFix attacks.

CYBER ATTACKZerowl

Apple adds a new security feature to keep users safe from ClickFix attacks, which are social engineering campaigns This article explores virtualization.

It looks like the Claude Code Source Code from Anthropic was leaked through their npm registry.

It looks like the Claude Code Source Code from Anthropic was leaked through their npm registry.

CYBER ATTACKZerowl

Discover how The full TypeScript source code for Anthropic's proprietary Claude Code tool has been made public by mistake. A security researcher found a.

Notepad++ v8.9.3 Released Addressing cURL Security Vulnerability and Crash Issues

Notepad++ v8.9.3 Released Addressing cURL Security Vulnerability and Crash Issues

CYBER ATTACKZerowl

Notepad++ has officially released version 8.9.3 This article explores notepad stable secure. . This version fixes security holes, improves the program's.

New DeepLoad Malware Uses ClickFix and AI-Generated Evasion to Breach Enterprise Networks

New DeepLoad Malware Uses ClickFix and AI-Generated Evasion to Breach Enterprise Networks

CYBER ATTACKZerowl

DeepLoad, a new type of malware, is going after businesses This article explores malware going. . It gives persistent, credential-stealing access to a.

Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays

Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays

CYBER ATTACKZerowl

RoadK1ll is a reverse tunneling implant that uses Node.js to set up an outbound WebSocket connection from the infected machine to infrastructure.

Claude AI Discovers Zero-Day RCE Vulnerabilities in Vim and Emacs

Claude AI Discovers Zero-Day RCE Vulnerabilities in Vim and Emacs

CYBER ATTACKZerowl

Claude AI from Anthropic found zero-day Remote Code Execution (RCE) bugs in both Vim and GNU Emacs This article explores ai discovered bugs. . The.

ChatGPT Vulnerability Allows Silent Exfiltration of User Prompts and Sensitive Data

ChatGPT Vulnerability Allows Silent Exfiltration of User Prompts and Sensitive Data

CYBER ATTACKZerowl

A serious flaw in ChatGPT's code execution environment let hackers quietly steal user prompts, uploaded files, and other private information This article.

CareCloud Data Breach: Hackers Access IT Systems, Steal Patient Data

CareCloud Data Breach: Hackers Access IT Systems, Steal Patient Data

CYBER ATTACKZerowl

CareCloud, Inc This article explores healthcare data compromised. . has revealed a major cybersecurity issue after an unauthorized third party broke into.

Axios NPM Packages Hacked to Add Bad Code in an Ongoing Supply Chain Attack

Axios NPM Packages Hacked to Add Bad Code in an Ongoing Supply Chain Attack

CYBER ATTACKZerowl

Axios, one of the most popular HTTP clients in the JavaScript ecosystem, has been hit by a complicated supply chain attack This article explores hacked.

Apples macOS Tahoe adds protection against ClickFix attacks.

Apples macOS Tahoe adds protection against ClickFix attacks.

CYBER ATTACKZerowl

macOS Tahoe 26.4 stops bad commands from running in the Terminal app before they do. The feature is meant to stop the rising threat of ClickFix social.

The Notepad++ v8.9.3 update fixes bugs that cause crashes and cURL vulnerabilities.

The Notepad++ v8.9.3 update fixes bugs that cause crashes and cURL vulnerabilities.

CYBER ATTACKZerowl

The popular open-source text and code editor for Windows, Notepad++, has a new version out: 8.9.3 This article explores notepad new version. . The most.

North Korean IT worker is said to have used a stolen identity and an AI resume to trick people into applying for jobs.

North Korean IT worker is said to have used a stolen identity and an AI resume to trick people into applying for jobs.

CYBER ATTACKZerowl

A suspected North Korean spy tried to get a remote job at a cybersecurity company by using a stolen identity, a fake AI-generated resume, and a VoIP phone.

Exposed server shows TheGentlemen ransomware toolkit, victim credentials, and Ngrok tokens.

Exposed server shows TheGentlemen ransomware toolkit, victim credentials, and Ngrok tokens.

CYBER ATTACKZerowl

A poorly set up server on a Russian bulletproof hosting service has made public the full set of tools that a TheGentlemen ransomware affiliate uses to do.

CrySome RAT is a new type of .NET malware that can kill AV and HVNC.

CrySome RAT is a new type of .NET malware that can kill AV and HVNC.

CYBER ATTACKZerowl

Discover how CrySome RAT is made to give you long-term access and full control over a system through a persistent TCP-based command-and-control channel.

The new ClickFix variant uses Rundll32 and WebDAV to get around PowerShell detection.

The new ClickFix variant uses Rundll32 and WebDAV to get around PowerShell detection.

CYBER ATTACKZerowl

A new and more dangerous version of the ClickFix attack method is now actively going after Windows users This article explores threats clickfix attacks.

TeamPCP Supply Chain Attack Allegedly Compromised Databricks Platform

TeamPCP Supply Chain Attack Allegedly Compromised Databricks Platform

CYBER ATTACKZerowl

Databricks is looking into a possible security breach that may have happened during the huge TeamPCP software supply chain attack This article explores.

TA446 Hackers Deploying DarkSword Exploit Kit to Attack iOS Users

TA446 Hackers Deploying DarkSword Exploit Kit to Attack iOS Users

CYBER ATTACKZerowl

TA446, a known threat group, has been caught using the newly discovered exploit kit DarkSword to go after iOS users This article explores ta446 known.

Open VSX’s New Scanner Vulnerability Allows Malicious Extension Goes Live

Open VSX’s New Scanner Vulnerability Allows Malicious Extension Goes Live

CYBER ATTACKZerowl

A serious security hole was recently found in Open VSX, the marketplace for extensions that popular code editors like Cursor and Windsurf use This article.

Top 5 this week

Page 4 of 44