CYBER ATTACK

ZerOwl — Find Vulnerabilities Before Hackers Do
25 Cloud Password Manager Vulnerabilities Permit Unauthorized Access and Changes

25 Cloud Password Manager Vulnerabilities Permit Unauthorized Access and Changes

CYBER ATTACKZerowl

Vulnerability of Password Managers ETH Zurich researchers have found 25 significant flaws in Dashlane, LastPass, and Bitwarden, the three most popular.

ZeroDayRAT Malware Strikes Android and iOS Devices for Real-Time Spying

ZeroDayRAT Malware Strikes Android and iOS Devices for Real-Time Spying

CYBER ATTACKZerowl

Discover how Since February 2, 2026, ZeroDayRAT, a powerful mobile spyware platform, has been freely available on Telegram channels. In addition to.

LockBit Ransomware Unleashes Devastating 5.0 Version Targeting Windows, Linux, and ESXi

LockBit Ransomware Unleashes Devastating 5.0 Version Targeting Windows, Linux, and ESXi

CYBER ATTACKZerowl

The most recent iteration of the LockBit ransomware, version 5.0, now targets Linux, ESXi, and Windows systems This article explores lockbit ransomware.

Clickfix Variant ‘Matryoshka’ Deployed To Steal Data From macOS Systems

Clickfix Variant ‘Matryoshka’ Deployed To Steal Data From macOS Systems

CYBER ATTACKZerowl

A new evolution in the “ClickFix” social engineering campaign targeting macOS users This article explores clickfix style attacks. . This latest variant.

25 Cloud Password Manager Flaws That Permit Unauthorized Access and Data Manipulation

25 Cloud Password Manager Flaws That Permit Unauthorized Access and Data Manipulation

CYBER ATTACKZerowl

About 60 million people use cloud-based password managers like Dashlane, LastPass, and Bitwarden globally This article explores vulnerabilities systems.

New Clickfix Variant ‘Matryoshka’ Attacking Users to Deploy macOS Stealer Malware

New Clickfix Variant ‘Matryoshka’ Attacking Users to Deploy macOS Stealer Malware

CYBER ATTACKZerowl

A sophisticated social engineering campaign has surfaced that targets macOS users and uses an advanced ClickFix attack technique to deploy a dangerous.

Joomla Novarain/Tassos Framework Vulnerabilities Enables SQL injection and Unauthenticated File Read

Joomla Novarain/Tassos Framework Vulnerabilities Enables SQL injection and Unauthenticated File Read

CYBER ATTACKZerowl

Flaws in the Joomla Novarain/Tassos Framework Critical security flaws in websites running the Novarain/Tassos Framework allow for unauthenticated file.

Hackers Can Use Summarize with AI Buttons as Weapons to Include Memory Prompts in AI Suggestions

Hackers Can Use Summarize with AI Buttons as Weapons to Include Memory Prompts in AI Suggestions

CYBER ATTACKZerowl

AI Recommendation Poisoning is a new security technique that targets users of AI assistants This article explores ai compromised microsoft. . On seemingly.

Microsoft Windows 11 KB5077181 Update Triggers Infinite Restart Loop on Some Devices

Microsoft Windows 11 KB5077181 Update Triggers Infinite Restart Loop on Some Devices

CYBER ATTACKZerowl

Devices running Windows 11 versions 24H2 (OS build 26200.7840) and 25H2 (OS build 26100.7840) are experiencing severe boot failures due to Microsoft's.

LockBit’s New 5.0 Version Attacking Windows, Linux and ESXI Systems

LockBit’s New 5.0 Version Attacking Windows, Linux and ESXI Systems

CYBER ATTACKZerowl

Discover how A new and dangerous variant of the LockBit ransomware has surfaced, posing a threat to businesses globally and targeting a variety of.

Critical Joomla Novarain/Tassos Framework Flaws Enable SQL Injection and Unauthenticated File Read

Critical Joomla Novarain/Tassos Framework Flaws Enable SQL Injection and Unauthenticated File Read

CYBER ATTACKZerowl

Newly discovered vulnerabilities pose a serious threat to Joomla sites that use extensions with the Novarain/Tassos Framework. Through SSD Secure.

Critical CleanTalk Plugin Flaw Allows Authorization Bypass on WordPress via Reverse DNS

Critical CleanTalk Plugin Flaw Allows Authorization Bypass on WordPress via Reverse DNS

CYBER ATTACKZerowl

The CleanTalk Spam Protection plugin for WordPress has a serious flaw that allows hackers to get around authorization and take over websites. This.

Rhysida Ransomware Delivered via Fake PuTTY and Google Authenticator

Rhysida Ransomware Delivered via Fake PuTTY and Google Authenticator

CYBER ATTACKZerowl

Operators of the Rhysida ransomware launch their attacks by imitating well-known programs like Google Authenticator and PuTTY on phony websites This.

Phishing Attacks Leverage Zoom, Teams, Google Meet Invites

Phishing Attacks Leverage Zoom, Teams, Google Meet Invites

CYBER ATTACKZerowl

an increase in phishing attempts that take advantage of people's faith in video conferencing platforms such as Zoom, Microsoft Teams, and Google Meet.

OpenClaw Founder Peter Steinberger Officially Joins OpenAI

OpenClaw Founder Peter Steinberger Officially Joins OpenAI

CYBER ATTACKZerowl

Peter Steinberger, the founder of OpenClaw, has officially joined OpenAI, establishing a noteworthy partnership between open-source innovation and one of.

OpenClaw Founder Makes High-Profile Move to OpenAI

OpenClaw Founder Makes High-Profile Move to OpenAI

CYBER ATTACKZerowl

On February 14, 2026, Peter Steinberger, the creator of the open-source AI agent project OpenClaw, declared his intention to join OpenAI in order to.

Lotus Blossom Hackers Compromised Official Hosting Infrastructure of Notepad++

Lotus Blossom Hackers Compromised Official Hosting Infrastructure of Notepad++

CYBER ATTACKZerowl

Between June and December 2025, the state-sponsored threat group Lotus Blossom successfully gained access to Notepad++'s official hosting infrastructure.

Lotus Blossom Hackers Breach Notepad++ Hosting Infrastructure

Lotus Blossom Hackers Breach Notepad++ Hosting Infrastructure

CYBER ATTACKZerowl

Lotus Blossom, a state-sponsored threat group, was able to successfully breach Notepad++'s official hosting infrastructure between June and December 2025.

FileZen File Transfer App Vulnerability Enables Arbitrary Command Execution

FileZen File Transfer App Vulnerability Enables Arbitrary Command Execution

CYBER ATTACKZerowl

Vulnerability in the FileZen File Transfer App The file transfer solution from Soliton Systems K.K This article explores vulnerability filezen. . has been.

Systems Are at Risk of Remote Code Execution Attacks Due to a Critical Airleader Vulnerability

Systems Are at Risk of Remote Code Execution Attacks Due to a Critical Airleader Vulnerability

CYBER ATTACKZerowl

The vulnerability of air leaders Several critical infrastructure sectors are concerned about a recently discovered vulnerability in an industrial control.

Critical FileZen File Transfer Flaw Allows Arbitrary Command Execution

Critical FileZen File Transfer Flaw Allows Arbitrary Command Execution

CYBER ATTACKZerowl

FileZen, a well-known file transfer program from Japan's Soliton Systems K.K., has a serious flaw that allows authenticated attackers to run arbitrary.

Critical BeyondTrust Vulnerability Exploited in the Wild to Gain Full Domain Control

Critical BeyondTrust Vulnerability Exploited in the Wild to Gain Full Domain Control

CYBER ATTACKZerowl

The BeyondTrust Vulnerability Exploit In the wild, a critical vulnerability known as CVE-2026-1731 is being actively exploited, giving attackers complete.

Critical Airleader Flaw Exposes Systems to Remote Code Execution Attacks

Critical Airleader Flaw Exposes Systems to Remote Code Execution Attacks

CYBER ATTACKZerowl

Industrial control systems (ICS) are at serious risk of remote code execution (RCE) attacks due to a critical security flaw in the Airleader Master.

CISA Alerts on Critical ZLAN ICS Flaws Enabling Full Device Takeover

CISA Alerts on Critical ZLAN ICS Flaws Enabling Full Device Takeover

CYBER ATTACKZerowl

ICSA-26-041-02, a critical advisory published by the U.S This article explores highlights flaws zlan5143d. . Cybersecurity and Infrastructure Security.

Attackers in the wild are actively taking advantage of a Chrome 0-Day vulnerability.

Attackers in the wild are actively taking advantage of a Chrome 0-Day vulnerability.

CYBER ATTACKZerowl

Exploited Chrome 0-Day Vulnerability Google has confirmed active exploitation in the wild by patching a high-severity zero-day vulnerability in Chrome.

Researchers Warn of Fresh ClickFix Attack Wave Exploiting Windows Users

Researchers Warn of Fresh ClickFix Attack Wave Exploiting Windows Users

CYBER ATTACKZerowl

Security researchers are alerting people to a new malware campaign that uses a misleading verification technique called ClickFix to target Windows users.

Phishing Lures Spread XWorm Remote Access Trojan

Phishing Lures Spread XWorm Remote Access Trojan

CYBER ATTACKZerowl

The XWorm Remote Access Trojan (RAT) is being spread by a new cyber-espionage campaign using a Microsoft Office vulnerability and well-crafted phishing.

Google Chrome Zero-Day Flaw Under Active Exploitation by Threat Actors

Google Chrome Zero-Day Flaw Under Active Exploitation by Threat Actors

CYBER ATTACKZerowl

Google confirmed active exploitation in the wild by quickly patching a high-severity zero-day vulnerability in Chrome This article explores vulnerability.

Attackers Can Take Complete Domain Control by Actively Exploiting a Critical BeyondTrust Flaw

Attackers Can Take Complete Domain Control by Actively Exploiting a Critical BeyondTrust Flaw

CYBER ATTACKZerowl

The cybersecurity company Arctic Wolf has found that self-hosted BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) deployments are.

Researchers Uncover OysterLoader, an Advanced Obfuscated Loader Powering Rhysida Attacks

Researchers Uncover OysterLoader, an Advanced Obfuscated Loader Powering Rhysida Attacks

CYBER ATTACKZerowl

OysterLoader, a multi-stage downloader associated with ransomware intrusions and widespread data theft, is a sophisticated malware loader. The malware.

Top 5 this week

Page 43 of 61