CYBER ATTACK

Microsoft Releases Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes

Microsoft Releases Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes

CYBER ATTACKZerowl

KB5078127 is an out-of-band (OOB) cumulative update that fixes serious file system compatibility problems for Windows 11 users This article explores

Microsoft Issues Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes

Microsoft Issues Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes

CYBER ATTACKZerowl

After January's monthly security updates, Microsoft released emergency out-of-band (OOB) security patches KB5078127 and KB5078132 to fix critical file

Critical Python PLY Library Vulnerability Enables Remote Code Execution

Critical Python PLY Library Vulnerability Enables Remote Code Execution

CYBER ATTACKZerowl

The Python PLY (Python Lex-Yacc) library has been found to have a serious security flaw that permits remote code execution (RCE) via an undocumented

CISA Releases Secure Connectivity Principles Checklist for OT Network Connectivity

CISA Releases Secure Connectivity Principles Checklist for OT Network Connectivity

CYBER ATTACKZerowl

In partnership with international cybersecurity partners such as the National Cyber Security Centre (NCSC) of the United Kingdom, the Australian Cyber

Backdoor Flaw Hits 20,000 WordPress Sites, Enables Stealthy Admin User Creation

Backdoor Flaw Hits 20,000 WordPress Sites, Enables Stealthy Admin User Creation

CYBER ATTACKZerowl

Over 20,000 active installations of the LA-Studio Element Kit for Elementor WordPress plugin are vulnerable to unauthenticated attacks due to a critical

Attackers Targeting Construction Firms Exploiting Mjobtime App Vulnerability Using MSSQL and IIS POST Request

Attackers Targeting Construction Firms Exploiting Mjobtime App Vulnerability Using MSSQL and IIS POST Request

CYBER ATTACKZerowl

By exploiting flaws in the business software that operates on their job sites, attackers are increasingly focusing on construction companies.

Systems are vulnerable to crashes and data corruption due to an Apache Hadoop vulnerability.

Systems are vulnerable to crashes and data corruption due to an Apache Hadoop vulnerability.

CYBER ATTACKZerowl

A serious flaw in the HDFS native client of Apache Hadoop, a popular distributed storage and processing framework, could allow hackers to cause system

Vulnerabilities in Apache Hadoop Expose Systems Possible Data Corruption or Crashes

Vulnerabilities in Apache Hadoop Expose Systems Possible Data Corruption or Crashes

CYBER ATTACKZerowl

Through maliciously constructed URI inputs, a moderate-severity vulnerability in the Hadoop Distributed File System (HDFS) native client could enable

6.5M Instagram and 48M Gmail were exposed online due to an unprotected database.

6.5M Instagram and 48M Gmail were exposed online due to an unprotected database.

CYBER ATTACKZerowl

An enormous database with 149 million stolen login credentials was found to be publicly accessible online without encryption or password protection This

Microsoft is looking into Windows 11, version 25H2 boot failure issues after the January update.

Microsoft is looking into Windows 11, version 25H2 boot failure issues after the January update.

CYBER ATTACKZerowl

Following reports that the January 2026 security update for Windows 11 is causing critical boot failures on physical devices, Microsoft has initiated an urgent investigation into the serio

A Critical VMware vCenter RCE Vulnerability Is Actively Exploited, CISA Warns

A Critical VMware vCenter RCE Vulnerability Is Actively Exploited, CISA Warns

CYBER ATTACKZerowl

A critical remote code execution (RCE) vulnerability in Broadcom VMware vCenter Server has been added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulne

telnetd Vulnerability Actively Exploited Following Public Proof-of-Concept Release

telnetd Vulnerability Actively Exploited Following Public Proof-of-Concept Release

CYBER ATTACKZerowl

A serious GNU authentication bypass vulnerability Threat actors are actively using the InetUtils telnetd service after a proof-of-concept exploit was made public on January 20, 2026 This a

Microsoft Introduces Winapp CLI to Streamline and Modernize the Development of Windows Applications

Microsoft Introduces Winapp CLI to Streamline and Modernize the Development of Windows Applications

CYBER ATTACKZerowl

The Windows App Development CLI (winapp), a new open-source command-line tool intended to streamline the Windows application development lifecycle across various frameworks and toolchains,

Google Unveils the Much-Awaited @gmail.com Feature for Address Change

Google Unveils the Much-Awaited @gmail.com Feature for Address Change

CYBER ATTACKZerowl

A much-anticipated feature that enables users to modify their Gmail address without losing their account information or access to Google services has started to roll out This article explo

Fix Critical Vulnerabilities in Go 1.25.6 and 1.24.12 to Reduce the Risk of DoS and Memory Exhaustion

Fix Critical Vulnerabilities in Go 1.25.6 and 1.24.12 to Reduce the Risk of DoS and Memory Exhaustion

CYBER ATTACKZerowl

Go 1.25.6 and 1.24.12 are emergency point releases that the Go programming language team released to fix six serious security vulnerabilities This article explores release go1. . These upd

New AWS Console Supply Chain Attack Lets Attackers Hijack AWS GitHub Repositories

New AWS Console Supply Chain Attack Lets Attackers Hijack AWS GitHub Repositories

CYBER ATTACKZerowl

Key AWS-owned GitHub repositories, including the popular AWS JavaScript SDK that powers the AWS Console itself, were taken over by unauthenticated attackers due to a crucial misconfigurati

NSA Issues Implementation Guidelines for Zero Trust

NSA Issues Implementation Guidelines for Zero Trust

CYBER ATTACKZerowl

The first two publications in the National Security Agency's Zero Trust Implementation Guidelines series, which offer helpful advice to assist organizations in implementing Zero Trust secu

Google Project Zero Unveils a Complex Zero-Click Exploit Chain Aimed at the Pixel 9

Google Project Zero Unveils a Complex Zero-Click Exploit Chain Aimed at the Pixel 9

CYBER ATTACKZerowl

Project Zero has revealed a complex zero-click exploit chain that targets the Pixel 9 smartphone, proving that extremely sophisticated attacks are still feasible even in the face of contem

Go Programming Language 1.26 Fixes Several Memory-Depleting Vulnerabilities

Go Programming Language 1.26 Fixes Several Memory-Depleting Vulnerabilities

CYBER ATTACKZerowl

For versions 1.25.6 and 1.24.12, the Go programming language team has released security updates that fix six serious flaws, including denial-of-service attacks, memory exhaustion, and arbi

UAT-8837 Hackers Target Organizations Using Open-Source Tools to Steal Sensitive Data

UAT-8837 Hackers Target Organizations Using Open-Source Tools to Steal Sensitive Data

CYBER ATTACKZerowl

UAT-8837 is a suspected China-nexus advanced persistent threat (APT) group that the researcher has identified This article explores exploited uat 8837. . Its primary goal is to obtain init

New Malware Targets 200,000+ U.S. Bank Employees to Steal Login Credentials

New Malware Targets 200,000+ U.S. Bank Employees to Steal Login Credentials

CYBER ATTACKZerowl

A sophisticated keylogger attack that targeted the employee store of one of the biggest banks in America has been discovered by cybersecurity researchers, putting over 200,000 employees at

New AWS Console Supply Chain Attack Sees Hackers Hijack AWS GitHub Repositories

New AWS Console Supply Chain Attack Sees Hackers Hijack AWS GitHub Repositories

CYBER ATTACKZerowl

Researchers have discovered CodeBreach, a serious flaw that allows the full takeover of important AWS GitHub repositories, endangering the AWS Console supply chain This article explores sd

Azure Identity Token Vulnerability Enables Windows Admin Center Tenant-Wide Compromise

Azure Identity Token Vulnerability Enables Windows Admin Center Tenant-Wide Compromise

CYBER ATTACKZerowl

Attackers with local administrator access were able to circumvent authentication procedures and obtain unauthorized access to any machine within the same Azure tenant due to a critical vul

China Accuses U.S. of Fabricating Volt Typhoon to Hide Its Own Hacking Campaigns

China Accuses U.S. of Fabricating Volt Typhoon to Hide Its Own Hacking Campaigns

CYBER ATTACKZerowl

The National Computer Virus Emergency Response Center (CVERC) of China has strengthened its assertion that Volt Typhoon, a threat actor, is a hoax. The agency then accused the United States o

Astaroth Banking Malware Resurfaces in Brazil via Spear-Phishing Attack

Astaroth Banking Malware Resurfaces in Brazil via Spear-Phishing Attack

CYBER ATTACKZerowl

A new spear-phishing campaign targeting Brazil has been found delivering a banking malware called Astaroth (aka Guildma) The malware makes use of obfuscated JavaScript to slip past security g

Warning: Over 2,000 Palo Alto Networks Devices Hacked in Ongoing Attack Campaign

Warning: Over 2,000 Palo Alto Networks Devices Hacked in Ongoing Attack Campaign

CYBER ATTACKZerowl

It is estimated that a campaign abusing the recently revealed security flaws compromised up to 2,000 Palo Alto Networks devices. The vulnerabilities in question are a combination of privilege

U.S. Sanctions Chinese Cybersecurity Firm Over Treasury Hack Tied to Silk Typhoon

U.S. Sanctions Chinese Cybersecurity Firm Over Treasury Hack Tied to Silk Typhoon

CYBER ATTACKZerowl

A Chinese cybersecurity firm and a cyber actor based in Shanghai have been subject to sanctions by the U.S. Treasury Department's Office of Foreign Assets Control. Yin Kecheng, who is associa

Top 5 this week

Page 42 of 44