CYBER ATTACK

Fake Cloudflare CAPTCHA Pages Spread Infiniti Stealer Malware on macOS Systems

Fake Cloudflare CAPTCHA Pages Spread Infiniti Stealer Malware on macOS Systems

CYBER ATTACKZerowl

Infiniti Stealer is a new piece of Mac malware that tricks people into clicking on fake Cloudflare human verification pages This article explores malware.

Important Citrix NetScaler and Gateway Weaknesses Allow Remote Attackers to Expose Confidential Data

Important Citrix NetScaler and Gateway Weaknesses Allow Remote Attackers to Expose Confidential Data

CYBER ATTACKZerowl

Cloud Software Group has sent out an important security bulletin that talks about two new security holes that have been found This article explores cloud.

ISC Warns of High-Severity Kea DHCP Flaw That Can Crash Services Remotely

ISC Warns of High-Severity Kea DHCP Flaw That Can Crash Services Remotely

CYBER ATTACKZerowl

The Internet Systems Consortium (ISC) has put out an important security advisory to let network administrators know about a serious security hole This.

The Claude Chrome Extension 0-Click Vulnerability lets attackers silently add prompts to websites.

The Claude Chrome Extension 0-Click Vulnerability lets attackers silently add prompts to websites.

CYBER ATTACKZerowl

A serious zero-click vulnerability in Anthropic's Claude Chrome Extension put more than 3 million users at risk of silent prompt-injection attacks This.

Anthropics leaked drafts show off a powerful new AI model called Claude Mythos.

Anthropics leaked drafts show off a powerful new AI model called Claude Mythos.

CYBER ATTACKZerowl

Anthropic accidentally made highly sensitive internal documents public, which showed that there is a powerful AI model that hasn't been released yet This.

Phishing Attack Pushes Malware Using Fake VS Code Alerts On GitHub

Phishing Attack Pushes Malware Using Fake VS Code Alerts On GitHub

CYBER ATTACKZerowl

Attackers are using GitHub Discussions to spread false warnings about security holes This article explores attackers using github. . The threat actors are.

ISC Warns of Critical Kea DHCP Flaw Causing Remote Service Crashes

ISC Warns of Critical Kea DHCP Flaw Causing Remote Service Crashes

CYBER ATTACKZerowl

The Internet Systems Consortium has put out a security warning about a serious flaw in its Kea DHCP server This article explores flaw kea dhcp. . If an.

Hackers Use Fake NPM Install Alerts To Distribute RAT Malware In Open Source Ecosystem

Hackers Use Fake NPM Install Alerts To Distribute RAT Malware In Open Source Ecosystem

CYBER ATTACKZerowl

Researchers at ReversingLabs have found a new operation This article explores attack ghost campaign. . The "Ghost campaign" is the name of this new wave.

NVIDIA flaws that are very important Allows RCE and DoS attacks

NVIDIA flaws that are very important Allows RCE and DoS attacks

CYBER ATTACKZerowl

The March 2026 security updates have been released to fix a number of holes in both enterprise and AI software systems. The most worrying problem in this.

New ClickFix Attack Uses Windows Run Dialog Box and macOS Terminal to Spread Malware

New ClickFix Attack Uses Windows Run Dialog Box and macOS Terminal to Spread Malware

CYBER ATTACKZerowl

Discover how The ClickFix social engineering method has come back with a lot of power. It tricks people into running harmful commands that quietly put.

Leak Bazaar Turns Stolen Business Data Into a Structured Criminal Market

Leak Bazaar Turns Stolen Business Data Into a Structured Criminal Market

CYBER ATTACKZerowl

On March 25, 2026, a hacker group called "Snow" from SnowTeam put up an ad on the Russian-speaking TierOne (T1) cybercrime forum This article explores.

The VoidLink Rootkit hides deep inside Linux systems by using eBPF and kernel modules.

The VoidLink Rootkit hides deep inside Linux systems by using eBPF and kernel modules.

CYBER ATTACKZerowl

Discover how VoidLink is a Linux malware framework that runs in the cloud and is written in Zig. It has a modular command-and-control structure with more.

IDrive for Windows Vulnerability Let Attackers Escalate Privileges

IDrive for Windows Vulnerability Let Attackers Escalate Privileges

CYBER ATTACKZerowl

The IDrive Cloud Backup Client for Windows has a serious local privilege escalation flaw that has been found. When the flaw is successfully used, an.

Hackers Plant Stealthy BPFdoor Backdoors in Telecom Networks for Long-Term Access

Hackers Plant Stealthy BPFdoor Backdoors in Telecom Networks for Long-Term Access

CYBER ATTACKZerowl

Red Menshen has put some of the most secret digital sleeper cells ever found into the infrastructure of global telecommunications This article explores.

GhostClaw AI Assisted Malware Attacking macOS Users to Deploy Credential-Stealing Payloads

GhostClaw AI Assisted Malware Attacking macOS Users to Deploy Credential-Stealing Payloads

CYBER ATTACKZerowl

GhostClaw is a new malware campaign that is actively going after macOS users through fake GitHub repositories and AI-assisted development workflows This.

CISA warns that attackers are using the Langflow Code Injection vulnerability.

CISA warns that attackers are using the Langflow Code Injection vulnerability.

CYBER ATTACKZerowl

Langflow is a well-known open-source, low-code interface that is made just for making workflows for multi-agent AI and large language models This article.

Tax Audit Phishing Campaign Tied to Silver Fox Shifts From RATs to Python Stealers

Tax Audit Phishing Campaign Tied to Silver Fox Shifts From RATs to Python Stealers

CYBER ATTACKZerowl

Since early 2025, a China-based hacker group called Silver Fox, also known as Void Arachne, has changed the way it attacks a lot This article explores.

New Torg Grabber Stealer Moves From Telegram Exfiltration to Encrypted REST API C2

New Torg Grabber Stealer Moves From Telegram Exfiltration to Encrypted REST API C2

CYBER ATTACKZerowl

Torg Grabber is a new Malware-as-a-Service (MaaS) tool that steals credentials This article explores grabber new malware. . It started as a simple way to.

Fake Screenshot Lures Used to Spread Multi-Stage Malware to Web3 Support Staff

Fake Screenshot Lures Used to Spread Multi-Stage Malware to Web3 Support Staff

CYBER ATTACKZerowl

The threat group APT-Q-27 has been actively attacking Web3 customer support teams This article explores windows protection victim. . The attackers use.

Synology DiskStation Manager Vulnerability Allow Remote Attackers to Execute Arbitrary Commands

Synology DiskStation Manager Vulnerability Allow Remote Attackers to Execute Arbitrary Commands

CYBER ATTACKZerowl

A serious flaw in DiskStation Manager lets hackers from outside the network run any command they want This article explores telnet service vulnerability.

Microsoft Entra ID New Feature Removes MFA Limitations for Users

Microsoft Entra ID New Feature Removes MFA Limitations for Users

CYBER ATTACKZerowl

Discover how Microsoft has said that external multifactor authentication for Microsoft Entra ID is now available to everyone. This release gets rid of the.

Cisco Secure Firewall Vulnerability Allows Remote Code Execution as Root User

Cisco Secure Firewall Vulnerability Allows Remote Code Execution as Root User

CYBER ATTACKZerowl

Cisco has put out an urgent security alert about a serious flaw in its Secure Firewall Management Center (FMC) software This article explores cisco urgent.

CISA says that the Langflow code injection flaw is being used in the wild.

CISA says that the Langflow code injection flaw is being used in the wild.

CYBER ATTACKZerowl

Langflow is a well-known framework for making workflows for large language models (LLMs) This article explores langflow development environments. . CISA's.

OpenAI Launches AI Safety Bug Bounty to Detect AI-Specific Vulnerabilities

OpenAI Launches AI Safety Bug Bounty to Detect AI-Specific Vulnerabilities

CYBER ATTACKZerowl

OpenAI has started a public Safety Bug Bounty program to find AI abuse and safety issues in all of its products This article explores openai safetybug.

New Kiss Loader Malware Uses Early Bird APC Injection in Emerging Attack Campaign

New Kiss Loader Malware Uses Early Bird APC Injection in Emerging Attack Campaign

CYBER ATTACKZerowl

Kiss Loader is a new type of malware loader that uses advanced code injection methods to get into Windows systems without raising any alarms This article.

Mirai Botnet Growth Spurs Massive DDoS Attacks and Proxy Exploits

Mirai Botnet Growth Spurs Massive DDoS Attacks and Proxy Exploits

CYBER ATTACKZerowl

Botnet activity has gone up a lot in the past year. Security researchers have been keeping track of record-breaking distributed denial-of-service (DDoS).

Fake npm Install Messages Hide RAT Malware in New Open Source Supply Chain Campaign

Fake npm Install Messages Hide RAT Malware in New Open Source Supply Chain Campaign

CYBER ATTACKZerowl

Through the npm package registry, a new software supply chain campaign is going after developers This article explores packages attack. . Security.

Top 5 this week

Page 7 of 44