CYBER ATTACK

ZerOwl — Find Vulnerabilities Before Hackers Do
Multiple ClamAV Vulnerabilities Allow Remote Attacker to Trigger DoS Condition

Multiple ClamAV Vulnerabilities Allow Remote Attacker to Trigger DoS Condition

CYBER ATTACKZerowl

Cisco has revealed multiple high-severity vulnerabilities in ClamAV that could disrupt antivirus scans and cause denial-of-service conditions This article.

Mozilla Revokes Firefox and Thunderbird GPG Signing Key After Accidental GitHub Commit

Mozilla Revokes Firefox and Thunderbird GPG Signing Key After Accidental GitHub Commit

CYBER ATTACKZerowl

Mozilla has rotated and revoked an unauthorized GPG key used in Firefox and Thunderbird release artifacts after unencrypted copies of the previous key.

LiteLLM Package Compromise Can Expand Into Repositories, Clusters, Registries and Cloud Accounts

LiteLLM Package Compromise Can Expand Into Repositories, Clusters, Registries and Cloud Accounts

CYBER ATTACKZerowl

A supply chain breach involving LiteLLM underscores how a fleeting malicious package can lead to long-term vulnerabilities across cloud environments.

Kimsuky Uses Local LLMs, AI-Generated Lures and GitHub C2 to Deploy AsyncRAT

Kimsuky Uses Local LLMs, AI-Generated Lures and GitHub C2 to Deploy AsyncRAT

CYBER ATTACKZerowl

Kimsuky has been spotted combining polished AI-generated documents with traditional phishing techniques to spread AsyncRAT, a remote-access trojan This.

HP ThinPro TPM Flaw Lets Physical Attackers Extract LUKS Disk Encryption Keys

HP ThinPro TPM Flaw Lets Physical Attackers Extract LUKS Disk Encryption Keys

CYBER ATTACKZerowl

Physical attackers can exploit vulnerabilities in HP ThinPro’s TPM-backed disk encryption system by modifying unencrypted boot files, enabling extraction.

Horizon3 Accelerates Partner-Led Growth with $20 Million Ecosystem Investment

Horizon3 Accelerates Partner-Led Growth with $20 Million Ecosystem Investment

CYBER ATTACKZerowl

Horizon3 Invests $20 Million in Partner Ecosystem Expansion, Focusing on Proactive Security Services Modern cybersecurity operations are under increasing.

Hackers Actively Scanning to Exploit VMware VCenter Vulnerabilities

Hackers Actively Scanning to Exploit VMware VCenter Vulnerabilities

CYBER ATTACKZerowl

Attackers are probing VMware vCenter after critical vulnerabilities were revealed, with DefusedCyber’s honeypots noting heightened vCenter fingerprinting.

Fake GoogleTranslate Chrome Extension Lets Attackers Remotely Control Your Browsers

Fake GoogleTranslate Chrome Extension Lets Attackers Remotely Control Your Browsers

CYBER ATTACKZerowl

A malicious Chrome extension posing as GoogleTranslate enables threat actors to steal sensitive information, live-stream web sessions, and remotely.

ErrTraffic MaaS Hides Malware Infrastructure in Polygon Blockchain Smart Contracts

ErrTraffic MaaS Hides Malware Infrastructure in Polygon Blockchain Smart Contracts

CYBER ATTACKZerowl

The attack combines ClickFix social engineering, blockchain-based EtherHiding, and dynamic infrastructure delivery to make detection and takedown more.

Critical Rancher Flaw Lets Authenticated Users Take Over All Managed Kubernetes Clusters

Critical Rancher Flaw Lets Authenticated Users Take Over All Managed Kubernetes Clusters

CYBER ATTACKZerowl

SUSE has addressed a critical privilege escalation vulnerability within Rancher that could enable a low-privileged authenticated user to gain.

Critical Copeland XWEB Pro Flaw Lets Remote Attackers Take Control of Refrigeration Systems

Critical Copeland XWEB Pro Flaw Lets Remote Attackers Take Control of Refrigeration Systems

CYBER ATTACKZerowl

A newly reported set of 23 vulnerabilities has been identified in Copeland’s XWEB Pro commercial refrigeration controller lineup, including an.

Compromised FortiGate VPN Opens First Step in Multi-Network Polish Energy Attack

Compromised FortiGate VPN Opens First Step in Multi-Network Polish Energy Attack

CYBER ATTACKZerowl

The energy sector in Poland was recently targeted by an attack that started with a compromised remote-access device, revealing how such vulnerabilities.

Claude Code Makes Auto Mode Default, Blocking 89% of Dangerous Commands

Claude Code Makes Auto Mode Default, Blocking 89% of Dangerous Commands

CYBER ATTACKZerowl

Anthropic is altering default permission settings in Claude Code, aiming to enhance AI classifiers' reliability for detecting dangerous commands more.

Claude AI Agent Autonomously Hacks Gym Website Without User Permission

Claude AI Agent Autonomously Hacks Gym Website Without User Permission

CYBER ATTACKZerowl

An Australian gym's booking software was exploited by an autonomous AI cyberattack orchestrated by a Claude-powered agent on the OpenClaw framework This.

CISA Warns of Actively Exploited Critical SonicWall SMA1000 SSRF Flaw in Zero-Day Attacks

CISA Warns of Actively Exploited Critical SonicWall SMA1000 SSRF Flaw in Zero-Day Attacks

CYBER ATTACKZerowl

The U.S This article explores vulnerability sonicwall sma1000. . Cybersecurity and Infrastructure Security Agency (CISA) has added a critical.

Chinese-speaking Hacking Group Attacking Users With Fake DeepSeek Page to Deliver Malware

Chinese-speaking Hacking Group Attacking Users With Fake DeepSeek Page to Deliver Malware

CYBER ATTACKZerowl

Discover how Chinese hackers are luring Windows users into downloading fake software pages that mimic popular AI tools like DeepSeek and Quark Cloud.

BDThemes WordPress Supply Chain Attack Creates Rogue Admins and Deploys Webshells

BDThemes WordPress Supply Chain Attack Creates Rogue Admins and Deploys Webshells

CYBER ATTACKZerowl

BdThemes, a popular WordPress plugin provider, has fallen victim to a supply chain compromise that allows attackers to create rogue administrator accounts.

WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution

WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution

CYBER ATTACKZerowl

A critical vulnerability chain in WordPress Core, known as XSS2Shell, enables full remote code execution via a single failed login attempt on any active.

Windows 11’s Built-In Weather App Reportedly Consumes 1.2GB of RAM for Showing Forecasts

Windows 11’s Built-In Weather App Reportedly Consumes 1.2GB of RAM for Showing Forecasts

CYBER ATTACKZerowl

The default Windows 11 Weather app, installed on millions of users' taskbars, has come under scrutiny following independent testing that revealed it.

Weekly Cybersecurity Newsletter — Top 50 Cybersecurity Stories of the Week (August 3–7, 2026)

Weekly Cybersecurity Newsletter — Top 50 Cybersecurity Stories of the Week (August 3–7, 2026)

CYBER ATTACKZerowl

Welcome to this edition of the ZeroOwl weekly cybersecurity newsletter — your cybersecurity bulletin covering the 50 most important stories from August 3.

Weekly Cyber Security Newsletter — OWASP Top 10 for LLM, Cisco IOS XE Flaw, and 1-Click Cursor RCE +20 Stories

Weekly Cyber Security Newsletter — OWASP Top 10 for LLM, Cisco IOS XE Flaw, and 1-Click Cursor RCE +20 Stories

CYBER ATTACKZerowl

This week's roundup highlights the exploitation of Apache Tomcat and SonicWall SMA vulnerabilities, a nearly two-decade-old Linux kernel flaw, critical.

Shai-Hulud Returns With Self-Propagating npm Worm Targeting Developer Credentials

Shai-Hulud Returns With Self-Propagating npm Worm Targeting Developer Credentials

CYBER ATTACKZerowl

A campaign was identified on August 4, 2026, targeting the maintainer of Keyv, a popular JavaScript key-value storage library This article explores.

Payroll Pirates AiTM Campaign Hijacks Microsoft 365 Sessions to Hunt Payroll and Finance Mailboxes

Payroll Pirates AiTM Campaign Hijacks Microsoft 365 Sessions to Hunt Payroll and Finance Mailboxes

CYBER ATTACKZerowl

Discover how Arctic Wolf has detected an ongoing Microsoft 365 phishing campaign targeting organizations within healthcare, education, manufacturing.

New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response

New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response

CYBER ATTACKZerowl

A supply chain attack on BdThemes WordPress plugins exposed administrators to account takeover, webshell deployment, and persistent backdoors This article.

Microsoft to Launch New Security Detection Report in Teams

Microsoft to Launch New Security Detection Report in Teams

CYBER ATTACKZerowl

Microsoft is set to introduce a new Security Detection Report within the Teams admin center, providing administrators with an eagerly awaited.

Metabase Zero-Day Attack Lets Hackers Gain Admin Access and Steal Database Credentials

Metabase Zero-Day Attack Lets Hackers Gain Admin Access and Steal Database Credentials

CYBER ATTACKZerowl

A severe unauthenticated SQL injection vulnerability in Metabase has been exploited by attackers for maximum privileges and credential theft across.

Malware Abuses Windows Hello for Business Key to Authenticate Microsoft Entra ID

Malware Abuses Windows Hello for Business Key to Authenticate Microsoft Entra ID

CYBER ATTACKZerowl

A newly revealed technique demonstrates how malware in a compromised Windows user session can exploit the Windows Hello for Business (WHFB) system's.

Levi Strauss Cyberattack Uses Social Engineering to Breach Employee Computers

Levi Strauss Cyberattack Uses Social Engineering to Breach Employee Computers

CYBER ATTACKZerowl

Levi Strauss & Co This article explores method intrusion phishing. . Levi Strauss Cyberattack Utilizes Social Engineering for Infiltration Levi Strauss.

Top 5 this week

Page 7 of 60