CYBER ATTACK

ZerOwl — Find Vulnerabilities Before Hackers Do
DeadLock Steals Corporate Data Before Encrypting Systems and Threatening Public Leaks

DeadLock Steals Corporate Data Before Encrypting Systems and Threatening Public Leaks

CYBER ATTACKZerowl

First detected in July 2025, this group has already compiled a list of over 80 organizations on its leak site known as the DeadLock blog This article.

Cybercrime Markets Keep Selling Enterprise Access Despite Forum Takedowns and Arrests

Cybercrime Markets Keep Selling Enterprise Access Despite Forum Takedowns and Arrests

CYBER ATTACKZerowl

Dark web markets persist despite forum closures, arrests, and disruption efforts. Criminal organizations swiftly adapt by utilizing new platforms, replica.

Critical WordPress RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File

Critical WordPress RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File

CYBER ATTACKZerowl

WordPress 7.0.4 has been released, addressing a critical security patch that closes a remote code execution vulnerability impacting sites utilizing the.

Critical VMware vCenter Directory Traversal Flaw Used in Global Attacks

Critical VMware vCenter Directory Traversal Flaw Used in Global Attacks

CYBER ATTACKZerowl

Broadcom VMware vCenter administrators are grappling with an intrusion campaign targeting CVE-2026-59310, a severe directory-traversal vulnerability in.

Critical Adobe Commerce Vulnerabilities Allows Hackers to Execute Arbitrary Code

Critical Adobe Commerce Vulnerabilities Allows Hackers to Execute Arbitrary Code

CYBER ATTACKZerowl

Adobe has released an urgent security update for Adobe Commerce and Magento Open Source, addressing several vulnerabilities that could enable attackers to.

CopyEscape Docker Vulnerability Lets Malicious Containers Overwrite Host Files and Gain Root

CopyEscape Docker Vulnerability Lets Malicious Containers Overwrite Host Files and Gain Root

CYBER ATTACKZerowl

A newly disclosed Docker vulnerability, tracked as CVE-2026-17106 and nicknamed “CopyEscape,” allows malicious containers to overwrite files on the host.

CopyEscape Docker Flaw Lets Malicious Containers Overwrite Host Files and Execute Code

CopyEscape Docker Flaw Lets Malicious Containers Overwrite Host Files and Execute Code

CYBER ATTACKZerowl

A newly disclosed vulnerability, tracked as CVE-2026-17106, enables malicious containers to escape their designated hosts via `docker cp`, overwriting.

CNCMachineRMS Hides Windows APIs With Runtime Hashing and Ships With No Import Table

CNCMachineRMS Hides Windows APIs With Runtime Hashing and Ships With No Import Table

CYBER ATTACKZerowl

Security researchers have discovered CNCMachineRMS, a 1.14 MB x64 remote access trojan (RAT) that is part of a BabaDeda-based infection chain. The final.

Cisco Firewall 0-Day Vulnerability Exploited in the Wild to Trigger DoS Condition

Cisco Firewall 0-Day Vulnerability Exploited in the Wild to Trigger DoS Condition

CYBER ATTACKZerowl

Security teams managing Cisco edge infrastructure must prioritize patching due to a high-priority deadline following Cisco's confirmation of active.

CISA Warns of SonicWall SMA1000 Vulnerabilities Exploited in Attacks to Deploy Ransomware

CISA Warns of SonicWall SMA1000 Vulnerabilities Exploited in Attacks to Deploy Ransomware

CYBER ATTACKZerowl

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that two SonicWall SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are.

CISA Warns of Actively Exploited Metabase Flaw Enabling Admin Account Takeover

CISA Warns of Actively Exploited Metabase Flaw Enabling Admin Account Takeover

CYBER ATTACKZerowl

A critical SQL injection flaw in Metabase, identified as CVE-2026-72898, can enable unauthenticated remote attackers to compromise vulnerable instances.

Chrome Fingerprint Spoofing Makes Kimwolf HTTP/2 Floods Harder to Separate From Real Users

Chrome Fingerprint Spoofing Makes Kimwolf HTTP/2 Floods Harder to Separate From Real Users

CYBER ATTACKZerowl

A newly discovered version of the Kimwolf botnet has introduced sophisticated techniques to evade detection by mimicking legitimate Chrome browsing.

China-linked Hackers Using AI Agents to Attack Taiwan Government Websites

China-linked Hackers Using AI Agents to Attack Taiwan Government Websites

CYBER ATTACKZerowl

China-linked cybercriminals have launched what experts call a groundbreaking fully autonomous cyberattack on a foreign government, using open-source.

CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure

CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure

CYBER ATTACKZerowl

CAV3RN is a modular espionage framework that becomes harder to detect on networks This article explores listed cav3rn associated. . Its latest.

CAV3RN Hides Cyberespionage C2 Behind Google Apps Script and Lets DNS Pick the Route

CAV3RN Hides Cyberespionage C2 Behind Google Apps Script and Lets DNS Pick the Route

CYBER ATTACKZerowl

Project CAV3RN has expanded its cyberespionage toolkit with a new command-and-control (C2) system that conceals traffic through Google Apps Script This.

Blacklight Toolkit Finds Codex, Claude Code, and Cursor Artifacts Exposing Tokens and Session Data

Blacklight Toolkit Finds Codex, Claude Code, and Cursor Artifacts Exposing Tokens and Session Data

CYBER ATTACKZerowl

SpecterOps has released Blacklight, an open-source toolkit designed to identify and detect local artifacts from AI coding agents such as Codex, Claude.

Armored Likho Abuses GitHub as Backup C2 Channel for Audio Surveillance Malware

Armored Likho Abuses GitHub as Backup C2 Channel for Audio Surveillance Malware

CYBER ATTACKZerowl

Discover how Armored Likho, also known as Eagle Werewolf, has initiated a new cyberespionage campaign targeting individuals and organizations in Russia.

Anthropic to Add Invisible Watermarks to All Claude AI Outputs

Anthropic to Add Invisible Watermarks to All Claude AI Outputs

CYBER ATTACKZerowl

Anthropic plans to introduce invisible watermarks and metadata for content created by Claude AI, following its adherence to the European Union's AI Act’s.

737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies

737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies

CYBER ATTACKZerowl

Hundreds of advertised free VPN or proxy tools have been linked to a significant traffic redirection operation This article explores proxy tools linked.

548 Internet-Exposed Building Automation Devices Run End-of-Life Products With No Future Security Patches

548 Internet-Exposed Building Automation Devices Run End-of-Life Products With No Future Security Patches

CYBER ATTACKZerowl

A recent study reveals that 548 internet-connected building automation devices near U.S This article explores bacnet controllers niagara. . These affected.

2.86 Billion Credentials Flood Criminal Markets as Enterprise Access Moves Upmarket

2.86 Billion Credentials Flood Criminal Markets as Enterprise Access Moves Upmarket

CYBER ATTACKZerowl

Stolen login credentials are so prevalent that they can be bought for almost nothing on the black market This article explores logged authentication.

13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts

13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts

CYBER ATTACKZerowl

A new Android fraud operation reveals how quickly a convincing phone call can lead to financial loss. Combining SpyNote, a remote-control tool, with.

Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge

Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge

CYBER ATTACKZerowl

Global malware activity surged significantly over the past week, with remote access trojans (RATs), information stealers, and loaders experiencing notable.

Red Hat ACM Privilege Escalation Vulnerability Lets Attackers Gain Full Cluster-Admin Access

Red Hat ACM Privilege Escalation Vulnerability Lets Attackers Gain Full Cluster-Admin Access

CYBER ATTACKZerowl

Red Hat has identified and disclosed a significant privilege escalation flaw, labeled CVE-2026-10090, impacting the Application Subscription controller.

Payroll Pirates AiTM Phishing Hijacks Microsoft 365 Sessions and Targets Payroll Emails

Payroll Pirates AiTM Phishing Hijacks Microsoft 365 Sessions and Targets Payroll Emails

CYBER ATTACKZerowl

Discover how Cybercriminals are leveraging phishing emails to infiltrate Microsoft 365 accounts and search for payroll-related files. Ref id: [random.

Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID, Bypassing MFA

Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID, Bypassing MFA

CYBER ATTACKZerowl

A new "Pass-the-Passkey" family of attack techniques showcases how systemic implementation flaws in WebAuthn can compromise passkey security, even when.

OpenAI Expands Daybreak Cyber with GPT-5.6 for Exploit Validation, Pentesting, and Red Teaming

OpenAI Expands Daybreak Cyber with GPT-5.6 for Exploit Validation, Pentesting, and Red Teaming

CYBER ATTACKZerowl

OpenAI has expanded its Daybreak program to provide more extensive access to frontier AI models for vetted cybersecurity defenders This article explores.

New ‘Ghostjacking’ Attack Lets Hackers Hijack AI Agents to Run Their Code on Developer Machines

New ‘Ghostjacking’ Attack Lets Hackers Hijack AI Agents to Run Their Code on Developer Machines

CYBER ATTACKZerowl

A novel "Ghostjacking" attack technique has been identified, enabling attackers to manipulate and control AI-driven coding agents via subtle manipulation.

Top 5 this week

Page 6 of 60