CYBER ATTACK

ZerOwl — Find Vulnerabilities Before Hackers Do
Cryptocurrency Scams Target Asia, Combining Malvertising and Pig Butchering with Losses Up to ¥10 Million

Cryptocurrency Scams Target Asia, Combining Malvertising and Pig Butchering with Losses Up to ¥10 Million

CYBER ATTACKZerowl

Currently, users throughout Asia are the target of a sophisticated cryptocurrency scam campaign that heavily and specifically targets Japan. Malvertising.

Targeting corporate networks, critical Ivanti EPMM zero-day vulnerabilities were exploited in the wild.

Targeting corporate networks, critical Ivanti EPMM zero-day vulnerabilities were exploited in the wild.

CYBER ATTACKZerowl

With active exploitation campaigns targeting corporate infrastructure across several nations, two serious zero-day vulnerabilities in Ivanti Endpoint.

Fake CAPTCHA (ClickFix) Attack Chain Causes Enterprise-Wide Malware Infection in Companies

Fake CAPTCHA (ClickFix) Attack Chain Causes Enterprise-Wide Malware Infection in Companies

CYBER ATTACKZerowl

Enterprise networks around the world are seriously threatened by a sophisticated cyberattack campaign that uses "ClickFix" social engineering This article.

Threat Actors Advertising New ‘ClickFix’ Payload That Stores Malware within Browser Cache

Threat Actors Advertising New ‘ClickFix’ Payload That Stores Malware within Browser Cache

CYBER ATTACKZerowl

Researchers studying cybersecurity have discovered a new version of the "ClickFix" social engineering campaign, which uses a more advanced method to avoid.

Microsoft 365 Exchange URL Filtering Update Quarantines Legitimate Emails as Phishing

Microsoft 365 Exchange URL Filtering Update Quarantines Legitimate Emails as Phishing

CYBER ATTACKZerowl

Beginning February 9, 2026, a widespread false-positive storm was caused by a flawed URL filtering rule update in Microsoft Exchange Online This article.

Microsoft 365 Copilot Flaw Allows AI Assistant to Summarize Sensitive Emails

Microsoft 365 Copilot Flaw Allows AI Assistant to Summarize Sensitive Emails

CYBER ATTACKZerowl

By avoiding configured Data Loss Prevention (DLP) policies and summarizing email messages protected by confidentiality sensitivity labels incorrectly, a.

Malware Campaign Delivers Remote Access Backdoor and Fake MetaMask Wallet to Steal Cryptocurrency Funds

Malware Campaign Delivers Remote Access Backdoor and Fake MetaMask Wallet to Steal Cryptocurrency Funds

CYBER ATTACKZerowl

Threat actors from North Korea have started a sophisticated attack campaign aimed at IT specialists working in the fields of artificial intelligence.

ClickFix Abuses Legitimate Homebrew Workflow to Deploy Cuckoo Stealer on macOS for Credential Harvesting

ClickFix Abuses Legitimate Homebrew Workflow to Deploy Cuckoo Stealer on macOS for Credential Harvesting

CYBER ATTACKZerowl

Through phony Homebrew installation pages that install the extensive credential-harvesting malware Cuckoo Stealer, a sophisticated social engineering.

OpenClaw AI Framework v2026.2.17 Released with Anthropic Model Support and Security Fixes

OpenClaw AI Framework v2026.2.17 Released with Anthropic Model Support and Security Fixes

CYBER ATTACKZerowl

Release of the OpenClaw AI Framework v2026.2.17 With major improvements, including support for Anthropic's Claude Sonnet 4.6 model, OpenClaw has released.

New SysUpdate Variant Malware Discovered and Tool Developed to Decrypt Encrypted Linux C2 Traffic

New SysUpdate Variant Malware Discovered and Tool Developed to Decrypt Encrypted Linux C2 Traffic

CYBER ATTACKZerowl

Discover how Targeting Linux systems with sophisticated command-and-control (C2) encryption capabilities, a new SysUpdate malware variant has surfaced as.

ClawHavoc Poisoned OpenClaw’s ClawHub with 1,184 Malicious Skills, Enabling Data Theft and Backdoor Access

ClawHavoc Poisoned OpenClaw’s ClawHub with 1,184 Malicious Skills, Enabling Data Theft and Backdoor Access

CYBER ATTACKZerowl

OpenClaw's official marketplace, ClawHub, was the target of a massive supply chain poisoning campaign called ClawHavoc, which disseminated 1,184 malicious.

16 Common PDF Platform Zero-Day Vulnerabilities Permit Data Exfiltration and Code Execution

16 Common PDF Platform Zero-Day Vulnerabilities Permit Data Exfiltration and Code Execution

CYBER ATTACKZerowl

PDF Zero-Day Vulnerabilities: Apryse WebViewer (formerly PDFTron) and Foxit PDF cloud services have 16 zero-day vulnerabilities that impact millions of.

Single-Character Typo of “&” Instead of “|” Leads to 0-Day RCE in Firefox

Single-Character Typo of “&” Instead of “|” Leads to 0-Day RCE in Firefox

CYBER ATTACKZerowl

0-Day RCE for Firefox A single-character typo in the SpiderMonkey JavaScript engine's WebAssembly garbage collection code led to a critical Remote Code.

Paloalto to Acquire Koi Security for Establishing Agentic Endpoint security

Paloalto to Acquire Koi Security for Establishing Agentic Endpoint security

CYBER ATTACKZerowl

Palo Alto Networks has announced a definitive agreement to acquire Koi Security, a leading innovator in Agentic Endpoint Security This article explores.

Palo Alto Networks to Acquire Koi Security to Advance Agentic Endpoint Protection

Palo Alto Networks to Acquire Koi Security to Advance Agentic Endpoint Protection

CYBER ATTACKZerowl

Discover how By purchasing Koi Security, a startup that specializes in shielding endpoints from the threats posed by sophisticated AI agents, Palo Alto.

New ‘CRESCENTHARVEST’ Malware Abuses Iran Protest Narrative For RAT Deployment

New ‘CRESCENTHARVEST’ Malware Abuses Iran Protest Narrative For RAT Deployment

CYBER ATTACKZerowl

CRESCENTHARVEST is a new malware campaign that targets Iranian protest supporters by taking advantage of the country's ongoing geopolitical unrest. This.

CISA Adds Windows Video ActiveX Control RCE Flaw to KEV Catalog Following Active Exploitation

CISA Adds Windows Video ActiveX Control RCE Flaw to KEV Catalog Following Active Exploitation

CYBER ATTACKZerowl

Windows Video ActiveX Control is Added by CISA RCE Error Following proof of active exploitation in the wild, CVE-2008-0015, a long-dormant Microsoft.

Claude Sonnet 4.6 with enhanced coding, computer usage, and a 1M token context window is released by Anthropic.

Claude Sonnet 4.6 with enhanced coding, computer usage, and a 1M token context window is released by Anthropic.

CYBER ATTACKZerowl

Discover how The most powerful mid-tier model to date, Claude Sonnet 4.6, has been formally released by Anthropic. It offers a thorough improvement in.

Notepad++ v8.9.2 Released with “Double-Lock” Update Mechanism Following Recent Hack

Notepad++ v8.9.2 Released with “Double-Lock” Update Mechanism Following Recent Hack

CYBER ATTACKZerowl

Release of Notepad++ v8.9.2 With the release of version v8.9.2, the popular open-source text and code editor has added a significant security feature.

New ‘Foxveil’ Malware Loader Leverages Cloudflare, Netlify, and Discord to Evade Detection

New ‘Foxveil’ Malware Loader Leverages Cloudflare, Netlify, and Discord to Evade Detection

CYBER ATTACKZerowl

The discovery of a new malware loader known as "Foxveil" that actively targets systems via reputable cloud platforms raises questions about how threat.

New “ClickFix” Payload Stores Malware In Browser Cache

New “ClickFix” Payload Stores Malware In Browser Cache

CYBER ATTACKZerowl

Researchers studying cybersecurity have discovered a new threat actor peddling a cunning tool known as "ClickFix." According to this payload-delivery.

Microsoft VS Code Extension with 11M Downloads Expose Developers to One-Click XSS Attacks

Microsoft VS Code Extension with 11M Downloads Expose Developers to One-Click XSS Attacks

CYBER ATTACKZerowl

Downloads for Microsoft VS Code Extension 11M A serious flaw in Microsoft's widely used Visual Studio Code (VS Code) Live Preview extension, which has.

Cybercriminals Exploit Atlassian Cloud For Large-Scale Spam Campaigns Targeting Investors

Cybercriminals Exploit Atlassian Cloud For Large-Scale Spam Campaigns Targeting Investors

CYBER ATTACKZerowl

Cybercriminals have launched extensive spam campaigns aimed at government agencies and investors by taking advantage of Atlassian Jira Cloud. From late.

ClickFix Social Engineering Fuels Matanbuchus 3.0 AstarionRAT Attack

ClickFix Social Engineering Fuels Matanbuchus 3.0 AstarionRAT Attack

CYBER ATTACKZerowl

Cybersecurity researchers discovered a complex attack chain in which the attackers delivered Matanbuchus 3.0 malware via ClickFix social engineering.

CISA Adds Actively Exploited Windows ActiveX RCE Flaw to KEV Catalog

CISA Adds Actively Exploited Windows ActiveX RCE Flaw to KEV Catalog

CYBER ATTACKZerowl

A critical remote code execution (RCE) vulnerability in Microsoft Windows Video ActiveX Control has been added to the U.S This article explores exploits.

New Malware Campaign ‘CRESCENTHARVEST’ Exploits Iran Protest Sentiment to Deploy Information-Stealing RAT

New Malware Campaign ‘CRESCENTHARVEST’ Exploits Iran Protest Sentiment to Deploy Information-Stealing RAT

CYBER ATTACKZerowl

A highly skilled new malware campaign called "CRESCENTHARVEST" has emerged, deliberately taking advantage of Iran's geopolitical instability to target.

Matanbuchus 3.0 Returns with ClickFix Social Engineering and Silent MSI Installations to Deploy AstarionRAT

Matanbuchus 3.0 Returns with ClickFix Social Engineering and Silent MSI Installations to Deploy AstarionRAT

CYBER ATTACKZerowl

After a nearly year-long break, the premium malware-as-a-service loader Matanbuchus reappeared in February 2026 This article explores premium malware.

Malicious Triton App Fork Emerges On GitHub, Posing Threat To Cybersecurity

Malicious Triton App Fork Emerges On GitHub, Posing Threat To Cybersecurity

CYBER ATTACKZerowl

A malicious fork of the well-known macOS app Triton was recently discovered on GitHub, which has caused concern in the cybersecurity community. The app's.

Hackers Exploit QR Codes To Spread Phishing and Malware Across Mobile Phones

Hackers Exploit QR Codes To Spread Phishing and Malware Across Mobile Phones

CYBER ATTACKZerowl

Because they make it simple for people to access websites, make payments, and download apps, QR codes have become commonplace in daily life This article.

Top 5 this week

Page 41 of 61