CYBER ATTACK

Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays

Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays

CYBER ATTACKZerowl

RoadK1ll is a reverse tunneling implant that uses Node.js to set up an outbound WebSocket connection from the infected machine to infrastructure.

Claude AI Discovers Zero-Day RCE Vulnerabilities in Vim and Emacs

Claude AI Discovers Zero-Day RCE Vulnerabilities in Vim and Emacs

CYBER ATTACKZerowl

Claude AI from Anthropic found zero-day Remote Code Execution (RCE) bugs in both Vim and GNU Emacs This article explores ai discovered bugs. . The.

ChatGPT Vulnerability Allows Silent Exfiltration of User Prompts and Sensitive Data

ChatGPT Vulnerability Allows Silent Exfiltration of User Prompts and Sensitive Data

CYBER ATTACKZerowl

A serious flaw in ChatGPT's code execution environment let hackers quietly steal user prompts, uploaded files, and other private information This article.

CareCloud Data Breach: Hackers Access IT Systems, Steal Patient Data

CareCloud Data Breach: Hackers Access IT Systems, Steal Patient Data

CYBER ATTACKZerowl

CareCloud, Inc This article explores healthcare data compromised. . has revealed a major cybersecurity issue after an unauthorized third party broke into.

Axios NPM Packages Hacked to Add Bad Code in an Ongoing Supply Chain Attack

Axios NPM Packages Hacked to Add Bad Code in an Ongoing Supply Chain Attack

CYBER ATTACKZerowl

Axios, one of the most popular HTTP clients in the JavaScript ecosystem, has been hit by a complicated supply chain attack This article explores hacked.

Apples macOS Tahoe adds protection against ClickFix attacks.

Apples macOS Tahoe adds protection against ClickFix attacks.

CYBER ATTACKZerowl

macOS Tahoe 26.4 stops bad commands from running in the Terminal app before they do. The feature is meant to stop the rising threat of ClickFix social.

The Notepad++ v8.9.3 update fixes bugs that cause crashes and cURL vulnerabilities.

The Notepad++ v8.9.3 update fixes bugs that cause crashes and cURL vulnerabilities.

CYBER ATTACKZerowl

The popular open-source text and code editor for Windows, Notepad++, has a new version out: 8.9.3 This article explores notepad new version. . The most.

North Korean IT worker is said to have used a stolen identity and an AI resume to trick people into applying for jobs.

North Korean IT worker is said to have used a stolen identity and an AI resume to trick people into applying for jobs.

CYBER ATTACKZerowl

A suspected North Korean spy tried to get a remote job at a cybersecurity company by using a stolen identity, a fake AI-generated resume, and a VoIP phone.

Exposed server shows TheGentlemen ransomware toolkit, victim credentials, and Ngrok tokens.

Exposed server shows TheGentlemen ransomware toolkit, victim credentials, and Ngrok tokens.

CYBER ATTACKZerowl

A poorly set up server on a Russian bulletproof hosting service has made public the full set of tools that a TheGentlemen ransomware affiliate uses to do.

CrySome RAT is a new type of .NET malware that can kill AV and HVNC.

CrySome RAT is a new type of .NET malware that can kill AV and HVNC.

CYBER ATTACKZerowl

Discover how CrySome RAT is made to give you long-term access and full control over a system through a persistent TCP-based command-and-control channel.

The new ClickFix variant uses Rundll32 and WebDAV to get around PowerShell detection.

The new ClickFix variant uses Rundll32 and WebDAV to get around PowerShell detection.

CYBER ATTACKZerowl

A new and more dangerous version of the ClickFix attack method is now actively going after Windows users This article explores threats clickfix attacks.

TeamPCP Supply Chain Attack Allegedly Compromised Databricks Platform

TeamPCP Supply Chain Attack Allegedly Compromised Databricks Platform

CYBER ATTACKZerowl

Databricks is looking into a possible security breach that may have happened during the huge TeamPCP software supply chain attack This article explores.

TA446 Hackers Deploying DarkSword Exploit Kit to Attack iOS Users

TA446 Hackers Deploying DarkSword Exploit Kit to Attack iOS Users

CYBER ATTACKZerowl

TA446, a known threat group, has been caught using the newly discovered exploit kit DarkSword to go after iOS users This article explores ta446 known.

Open VSX’s New Scanner Vulnerability Allows Malicious Extension Goes Live

Open VSX’s New Scanner Vulnerability Allows Malicious Extension Goes Live

CYBER ATTACKZerowl

A serious security hole was recently found in Open VSX, the marketplace for extensions that popular code editors like Cursor and Windsurf use This article.

New Homoglyph Attack Techniques Help Cybercriminals Spoof Trusted Domains

New Homoglyph Attack Techniques Help Cybercriminals Spoof Trusted Domains

CYBER ATTACKZerowl

Cybercriminals have come up with a smart way to fool people: they change real letters in website addresses to characters that look almost the same This.

Hackers break into the Telnyx Python SDK on PyPI to steal cloud and developer credentials.

Hackers break into the Telnyx Python SDK on PyPI to steal cloud and developer credentials.

CYBER ATTACKZerowl

A popular Python package was secretly turned into a weapon, and most of the developers who were affected had no idea it was happening This article.

India to Ban Hikvision, TP-Link, and CCTV Product Sales Starting April

India to Ban Hikvision, TP-Link, and CCTV Product Sales Starting April

CYBER ATTACKZerowl

The Indian government will effectively stop Chinese video surveillance companies like Hikvision, Dahua, and TP-Link from selling internet-connected CCTV.

CanisterWorm Malware Attacking Docker/K8s/Redis to Gain Access and Steal Secrets

CanisterWorm Malware Attacking Docker/K8s/Redis to Gain Access and Steal Secrets

CYBER ATTACKZerowl

Since late 2025, a group of cybercriminals with money on their minds has been quietly breaking into cloud environments This article explores security.

BlankGrabber Stealer Uses Fake Certificate Loader to Hide Malware Delivery Chain

BlankGrabber Stealer Uses Fake Certificate Loader to Hide Malware Delivery Chain

CYBER ATTACKZerowl

A Python-based information thief called BlankGrabber has been caught using a fake certificate loader to hide a multi-stage malware delivery chain This.

VoidLink Framework Signals AI-Assisted Malware Is No Longer Experimental

VoidLink Framework Signals AI-Assisted Malware Is No Longer Experimental

CYBER ATTACKZerowl

In 2025, software development moved toward AI agents that write and test code on their own using structured markdown files This article explores companies.

New “Prompt Poaching” Attack Steals Users’ AI Conversations via Malicious Browser Extensions

New “Prompt Poaching” Attack Steals Users’ AI Conversations via Malicious Browser Extensions

CYBER ATTACKZerowl

Security researchers have looked into dozens of cases where Chrome extensions secretly collected information about how users interacted with AI assistants.

New CanisterWorm Malware Hits Docker, K8s, Redis Environments

New CanisterWorm Malware Hits Docker, K8s, Redis Environments

CYBER ATTACKZerowl

TeamPCP has started a new campaign that will hurt cloud environments This article explores attack trivy vulnerability. . The group is trying to get.

India Set to Ban Sale of Hikvision, TP-Link, CCTV Products From April

India Set to Ban Sale of Hikvision, TP-Link, CCTV Products From April

CYBER ATTACKZerowl

Discover how The Indian government will effectively stop Chinese video surveillance companies like Hikvision, Dahua, and TP-Link from selling.

Espionage Campaign Targets Southeast Asian Government With USB Malware

Espionage Campaign Targets Southeast Asian Government With USB Malware

CYBER ATTACKZerowl

A Southeast Asian government agency has been the target of a very well-planned cyberespionage campaign This article explores cyberespionage campaign.

Critical n8n Vulnerability Let Attackers Achieve Remote Code Execution

Critical n8n Vulnerability Let Attackers Achieve Remote Code Execution

CYBER ATTACKZerowl

A serious security hole in n8n makes host servers vulnerable to Remote Code Execution (RCE) attacks This article explores n8n workflows vulnerability.

Critical Grafana Vulnerabilities Allow Attackers to Execute Code Remotely

Critical Grafana Vulnerabilities Allow Attackers to Execute Code Remotely

CYBER ATTACKZerowl

Two very serious security holes have been fixed in Grafana version 12.4.2 This article explores managed grafana azure. . CVE-2026-27876 is the most.

Top 5 this week

Page 5 of 44