CYBERSECURITY

ZerOwl — Find Vulnerabilities Before Hackers Do
Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials

Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials

Cybersecurity researchers have made public information about two security holes in the n8n workflow automation platform that have since been fixed This.

UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours

UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours

A hacker group called UNC6426 used keys stolen from the nx npm package's supply chain last year to completely break into a victim's cloud environment in.

Middle East Conflict Highlights Cloud Resilience Gaps

Middle East Conflict Highlights Cloud Resilience Gaps

In the past two weeks, businesses that relied on the cloud's distributed nature to make sure their data was always available have had to face the truth.

Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days

Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days

Discover how On Tuesday, Microsoft released patches for 84 new security holes that affect different parts of its software. Two of these holes are already.

Meta Disables 150K Accounts Linked to Southeast Asia Scam Centers in Global Crackdown

Meta Disables 150K Accounts Linked to Southeast Asia Scam Centers in Global Crackdown

On Wednesday, Meta said it had disabled more than 150,000 accounts linked to scam centers in Southeast Asia This article explores scam centers southeast.

Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets

Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets

Discover how Cybersecurity researchers have found five harmful Rust crates that pretend to be time-related tools in order to send .env file data to the.

Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices

Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices

SAP has put out security updates to fix two serious security holes that could let hackers run any code they want on affected systems This article explores.

Threat Actors Mass-Scan Salesforce Experience Cloud via Modified AuraInspector Tool

Threat Actors Mass-Scan Salesforce Experience Cloud via Modified AuraInspector Tool

Salesforce has warned that threat actors are becoming more active and are using a modified version of an open-source tool called AuraInspector to take.

The Zero-Day Scramble is Avoidable: A Guide to Attack Surface Reduction

The Zero-Day Scramble is Avoidable: A Guide to Attack Surface Reduction

Discover how You can't choose when the next big security hole will show up. You can decide how much of your environment is visible when it does. The.

Russian Threat Actor Sednit Resurfaces With Sophisticated Toolkit

Russian Threat Actor Sednit Resurfaces With Sophisticated Toolkit

After years of mysteriously avoiding custom malware, Russia's infamous Sednit threat group is back to using a custom toolkit in recent cyber espionage.

New "LeakyLooker" Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Queries

New "LeakyLooker" Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Queries

Cybersecurity researchers have disclosed nine cross-tenant vulnerabilities in Google Looker Studio that could have permitted attackers to run arbitrary.

KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet

KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet

A new malware known as KadNap has been found by cybersecurity researchers This article explores malware known kadnap. . It mainly targets Asus routers in.

How to Stop AI Data Leaks: A Webinar Guide to Auditing Modern Agentic Workflows

How to Stop AI Data Leaks: A Webinar Guide to Auditing Modern Agentic Workflows

Discover how Artificial Intelligence (AI) is now a tool that performs tasks for us rather than merely being a tool we communicate with. We refer to these.

CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively Exploited

CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively Exploited

Based on evidence of active exploitation, the U.S This article explores vulnerability solarwinds web. . Cybersecurity and Infrastructure Security Agency.

APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military

APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military

Two implants known as BEARDSHELL and COVENANT have been seen to be used by the Russian state-sponsored hacking group known as APT28 to enable long-term.

AI is Modifying File-Based Security Regulations

AI is Modifying File-Based Security Regulations

AI is altering file-based security regulations According to Gartner, global information security spending is expected to reach $240 billion in 2026.

White House Cyber Strategy Prioritizes Offense

White House Cyber Strategy Prioritizes Offense

The Trump administration released a notably hawkish vision of American cyber power that blends deregulation at home with deterrence and offense against.

Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials

Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials

In order to install a remote access trojan (RAT) and steal private information from compromised hosts, cybersecurity researchers have found a malicious.

UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work Device

UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work Device

In order to steal millions of dollars in cryptocurrency, a sophisticated cloud compromise campaign targeting a cryptocurrency organization in 2025 is.

Can the Security Platform Finally Deliver for the Mid-Market?

Can the Security Platform Finally Deliver for the Mid-Market?

The goal of mid-market companies is to attain security levels comparable to those of their enterprise counterparts This article explores achieving.

⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware

⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware

Cybersecurity for another week. One more week of "you've got to be kidding me." The attackers were occupied. The defenders were occupied.

Web Server Exploits and Mimikatz Used in Attacks Targeting Asian Critical Infrastructure

Web Server Exploits and Mimikatz Used in Attacks Targeting Asian Critical Infrastructure

As part of a multi-year campaign, a Chinese threat actor has targeted high-value organizations in South, Southeast, and East Asia. Palo Alto Networks Unit.

After ownership is transferred, the Chrome extension becomes malicious, allowing code injection and data theft.

After ownership is transferred, the Chrome extension becomes malicious, allowing code injection and data theft.

Following what appears to be a case of ownership transfer, two Google Chrome extensions have turned malicious, giving attackers a means to harvest.

When Auto-Updates Become Attack Paths

When Auto-Updates Become Attack Paths

The idea that utilizing an application's internal update mechanisms is advantageous is a common pattern in enterprise environments, which is worth.

Trojanized Gaming Tools Spread Java-Based RAT via Browser and Chat Platforms

Trojanized Gaming Tools Spread Java-Based RAT via Browser and Chat Platforms

In order to spread a remote access trojan (RAT), threat actors are tricking unsuspecting users into using trojanized gaming utilities that are distributed.

Whether Were Ready or Not, AI Is Changing Security

Whether Were Ready or Not, AI Is Changing Security

AI was not used by enterprise IT teams to create new security issues This article explores ai used enterprise. . They implemented it in order to manage.

Top 5 this week

Page 13 of 26