CYBER ATTACK

Critical Vulnerability in Python PLY Library Enables Remote Code Execution – PoC Published

Critical Vulnerability in Python PLY Library Enables Remote Code Execution – PoC Published

CYBER ATTACKZerowl

The PyPI-distributed version of PLY (Python Lex-Yacc) 3.11 has been found to have a critical vulnerability that permits arbitrary code execution

Windows Vulnerability in the WD Discovery Desktop App Permits Arbitrary Code Execution

Windows Vulnerability in the WD Discovery Desktop App Permits Arbitrary Code Execution

CYBER ATTACKZerowl

Western Digital has revealed a serious security flaw in its Windows desktop program, WD Discovery, which could let hackers run arbitrary code on

China-Aligned APTs Exploit Stolen Certificates in Multi-Vector Attacks Using the PeckBirdy C&C Framework

China-Aligned APTs Exploit Stolen Certificates in Multi-Vector Attacks Using the PeckBirdy C&C Framework

CYBER ATTACKZerowl

Since 2023, hacking groups with ties to China have made PeckBirdy, a dangerous malware framework, their main weapon This article explores peckbirdy

The Indian government is being attacked by APT hackers. GITSHELLPAD Malware and the GOGITTER Tool

The Indian government is being attacked by APT hackers. GITSHELLPAD Malware and the GOGITTER Tool

CYBER ATTACKZerowl

Coordinated attacks against Indian government organizations have been carried out by advanced persistent threat actors operating out of Pakistan,

Cybercriminals Use 7-Zip and Fake Notepad++ Websites to Spread Remote Monitoring Malware

Cybercriminals Use 7-Zip and Fake Notepad++ Websites to Spread Remote Monitoring Malware

CYBER ATTACKZerowl

Cybercriminals are deceiving users by creating phony websites that imitate well-known programs like Notepad++ and 7-Zip This article explores rmm

PoC Released: Over 800K Telnet Servers Are Vulnerable to RCE Attacks

PoC Released: Over 800K Telnet Servers Are Vulnerable to RCE Attacks

CYBER ATTACKZerowl

About 800,000 internet-accessible Telnet instances are vulnerable to unauthenticated remote code execution (RCE) due to a critical authentication bypass.

New DPRK Interview Campaign Leverages Fake Fonts to Deploy Malware

New DPRK Interview Campaign Leverages Fake Fonts to Deploy Malware

CYBER ATTACKZerowl

Software developers are the target of a sophisticated supply chain attack by North Korea's Lazarus Group under the "Fake Font" campaign This article explores

A New Cybersecurity Framework to Safeguard Embedded Systems Is Released by MITRE

A New Cybersecurity Framework to Safeguard Embedded Systems Is Released by MITRE

CYBER ATTACKZerowl

To aid in the security of embedded systems utilized in vital infrastructure and defense technologies throughout the United States, a new Embedded Systems

Hackers from Lazarus are actively targeting European drone manufacturers.

Hackers from Lazarus are actively targeting European drone manufacturers.

CYBER ATTACKZerowl

A new wave of targeted attacks against European drone manufacturers and defense contractors has been initiated by Lazarus, a sophisticated hacking group

A New Instagram Vulnerability Makes Private Posts Visible to Anyone

A New Instagram Vulnerability Makes Private Posts Visible to Anyone

CYBER ATTACKZerowl

Instagram's mobile web interface had a server-side authorization flaw that made it possible for totally unauthenticated users to view private account posts

As PoC is released, more than 800K GNU InetUtils telnetd instances are vulnerable to RCE attacks.

As PoC is released, more than 800K GNU InetUtils telnetd instances are vulnerable to RCE attacks.

CYBER ATTACKZerowl

About 800,000 exposed instances of GNU InetUtils telnetd are susceptible to remote code execution attacks, making it a serious security risk.

Critical Zero-Day Vulnerabilities in NetSupport Manager Turn on Remote Code Execution

Critical Zero-Day Vulnerabilities in NetSupport Manager Turn on Remote Code Execution

CYBER ATTACKZerowl

Two serious authentication bypass vulnerabilities (CVE-2025-34164 and CVE-2025-34165) in NetSupport Manager, a reputable remote access tool used by many

Threat Actors Weaponize LNK Files To Deploy MoonPeak Malware On Windows

Threat Actors Weaponize LNK Files To Deploy MoonPeak Malware On Windows

CYBER ATTACKZerowl

Threat actors associated with the Democratic People's Republic of Korea (DPRK) used LNK shortcut files as a weapon to spread MoonPeak malware, a XenoRAT

‘SyncFuture’ Campaign Weaponizing Legitimate Enterprise Security Software to Deploy Malware

‘SyncFuture’ Campaign Weaponizing Legitimate Enterprise Security Software to Deploy Malware

CYBER ATTACKZerowl

Threat researchers discovered a concerning espionage operation in December 2025 that used sophisticated phishing campaigns to target Indian citizens This

Sandworm APT Group Targeting Poland’s Power Grid with DynoWiper Malware

Sandworm APT Group Targeting Poland’s Power Grid with DynoWiper Malware

CYBER ATTACKZerowl

Poland received concerning news in late December 2025 when its energy infrastructure was the target of what security experts refer to as the biggest

New Phishing Attack Leverages Vercel Hosting Platform to Deliver a Remote Access Tool

New Phishing Attack Leverages Vercel Hosting Platform to Deliver a Remote Access Tool

CYBER ATTACKZerowl

Between November 2025 and January 2026, a sophisticated phishing campaign distributed remote access tools to unwary victims by taking advantage of Vercel's

Microsoft Releases Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes

Microsoft Releases Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes

CYBER ATTACKZerowl

KB5078127 is an out-of-band (OOB) cumulative update that fixes serious file system compatibility problems for Windows 11 users This article explores

Microsoft Issues Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes

Microsoft Issues Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes

CYBER ATTACKZerowl

After January's monthly security updates, Microsoft released emergency out-of-band (OOB) security patches KB5078127 and KB5078132 to fix critical file

Critical Python PLY Library Vulnerability Enables Remote Code Execution

Critical Python PLY Library Vulnerability Enables Remote Code Execution

CYBER ATTACKZerowl

The Python PLY (Python Lex-Yacc) library has been found to have a serious security flaw that permits remote code execution (RCE) via an undocumented

Top 5 this week

Page 41 of 44