CYBER ATTACK

ZerOwl — Find Vulnerabilities Before Hackers Do
Phishing and OAuth Token Flaws Lead to Full Microsoft 365 Compromise

Phishing and OAuth Token Flaws Lead to Full Microsoft 365 Compromise

CYBER ATTACKZerowl

Password resets, contact forms, newsletter signups, and other seemingly innocuous features intended to encourage user interaction are examples of modern.

OpenAI Unveils Trusted Access for Cybersecurity With Enhanced Security Capabilities

OpenAI Unveils Trusted Access for Cybersecurity With Enhanced Security Capabilities

CYBER ATTACKZerowl

OpenAI's Trusted Access for Cyber, an identity-verified framework that boosts cybersecurity while reducing risks from its state-of-the-art models, is a.

Flickr Confirms Data Breach – 35 million Users Data at Risk

Flickr Confirms Data Breach – 35 million Users Data at Risk

CYBER ATTACKZerowl

Flickr Data Breach Due to a vulnerability in the system of a third-party email service provider, Flickr has revealed a possible data breach. The incident.

Dutch Authorities Seized Servers of Windscribe VPN Provider

Dutch Authorities Seized Servers of Windscribe VPN Provider

CYBER ATTACKZerowl

As part of an undisclosed investigation, Dutch authorities confiscated a Windscribe VPN server situated in the Netherlands This article explores.

Chinese APT Group Uses Linux Exploits To Redirect Traffic and Deploy Malicious Software

Chinese APT Group Uses Linux Exploits To Redirect Traffic and Deploy Malicious Software

CYBER ATTACKZerowl

"DKnife" is an extremely complex attack framework that targets Linux-based devices, such as routers and edge devices This article explores dknife attacks.

Spam Campaign Distributes Fake PDFs, Installing Remote Monitoring Tools for Persistent Access

Spam Campaign Distributes Fake PDFs, Installing Remote Monitoring Tools for Persistent Access

CYBER ATTACKZerowl

Discover how Security teams have uncovered an ongoing spam campaign that deceives users into installing remote monitoring and management (RMM) software by.

Phishing Attacks Exploit OAuth Weakness To Breach Microsoft 365

Phishing Attacks Exploit OAuth Weakness To Breach Microsoft 365

CYBER ATTACKZerowl

In contemporary cyberattacks, email continues to be the main initial access vector. In 27% of reported breaches, email was the first attack vector, and.

New Variant Of Odyssey Stealer Malware Plagues macOS Systems

New Variant Of Odyssey Stealer Malware Plagues macOS Systems

CYBER ATTACKZerowl

Users of macOS are being severely impacted by a dangerous new version of the Odyssey Stealer malware. This new wave of attacks is rapidly spreading.

CISA Warns of React Native Community Command Injection Vulnerability Exploited in Attacks

CISA Warns of React Native Community Command Injection Vulnerability Exploited in Attacks

CYBER ATTACKZerowl

Command Injection Error in React Native An OS command injection vulnerability in the React Native Community CLI has been identified as actively exploited.

APT-Q-27 Exploits Weaknesses In Corporate Security To Launch Silent, Undetected Attacks

APT-Q-27 Exploits Weaknesses In Corporate Security To Launch Silent, Undetected Attacks

CYBER ATTACKZerowl

The security team noticed strange activity in a business setting in mid-January 2026, which at first did not seem concerning This article explores source.

Ransomware Gang Goes Full 'Godfather' With Cartel

Ransomware Gang Goes Full 'Godfather' With Cartel

CYBER ATTACKZerowl

The creators of DragonForcea ransomware-as-a-service group that first came to light in 2023seem to be taking a cue from organized crime

Shadow DNS Hacking Routers Internet Traffic Through Compromised Routers

Shadow DNS Hacking Routers Internet Traffic Through Compromised Routers

CYBER ATTACKZerowl

The majority of internet users rely on their routers to properly route traffic never realizing that the web's very signposts could be manipulated.

CISA Warns of Actively Exploited GitLab SSRF Vulnerability in Community and Enterprise Editions

CISA Warns of Actively Exploited GitLab SSRF Vulnerability in Community and Enterprise Editions

CYBER ATTACKZerowl

A new alert regarding an actively exploited Server-Side Request Forgery (SSRF) vulnerability in GitLab Community and Enterprise Editions has been

ValleyRAT Campaign Uses Trojanized LINE Setup To Harvest Credentials

ValleyRAT Campaign Uses Trojanized LINE Setup To Harvest Credentials

CYBER ATTACKZerowl

A phony LINE installer that propagates the ValleyRAT malware, which uses sophisticated evasion techniques to target users who speak Chinese This

Attackers Can Run Any Code Due to the Ingress-NGINX Vulnerability

Attackers Can Run Any Code Due to the Ingress-NGINX Vulnerability

CYBER ATTACKZerowl

The cloud and container security community is concerned about a new high-severity vulnerability in the Kubernetes ingress-nginx controller This

CISA Alerts of Active Attacks Using SolarWinds Web Help Desk Deserialization RCE Exploit

CISA Alerts of Active Attacks Using SolarWinds Web Help Desk Deserialization RCE Exploit

CYBER ATTACKZerowl

A critical remote code execution (RCE) vulnerability in SolarWinds Web Help Desk (WHD) has been added to the Known Exploited Vulnerabilities (KEV)

DoS and SQL injection attacks are made possible by critical Django vulnerabilities.

DoS and SQL injection attacks are made possible by critical Django vulnerabilities.

CYBER ATTACKZerowl

Emergency security patches for six serious flaws affecting several versions of the well-known Python web framework have been released by the Django

Top 5 this week

Page 50 of 61