CYBERSECURITY

ZerOwl — Find Vulnerabilities Before Hackers Do
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM releases remained on PyPI for approximately 40 minutes in March, carrying credential-stealing code that could harvest cloud keys.

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

Cybercriminals disrupted a steam turbine and water treatment systems at a Polish CHP facility by infiltrating their private cellular network, which the.

Enterprise Defenses Recovered at the Edge and Collapsed Inside

Enterprise Defenses Recovered at the Edge and Collapsed Inside

Defenses in enterprises focus on detecting noisy intrusions This article explores intrusions picus labs. . In Picus Labs' Blue Report 2026, over 338.

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

Cisco has issued a warning about a newly discovered vulnerability affecting the Secure Firewall Adaptive Security Appliance (ASA) Software and Secure.

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Cybercriminals are now actively exploiting a newly patched vulnerability in Broadcom's VMware vCenter software, as revealed by recent research conducted.

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe has released patches addressing multiple critical security flaws affecting ColdFusion, Commerce, and Campaign Classic This article explores.

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

A large collection of 737 free virtual private network (VPN) and proxy tools has been discovered, primarily targeting Russian speakers who are looking for.

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

Windows Plug and Play can be exploited to obtain signed vendor software on an emulated USB device, allowing for privileged installation components to be.

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

The cybersecurity team developed a new cryptocurrency firm, posted job openings for developers, and recruited three individuals believed to be affiliated.

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

A malicious tool server can quietly steal SSH keys, environment secrets, source code, and customer data without sending any obvious harmful instructions.

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

South Korea's and the United States' cybersecurity and intelligence agencies issued a warning about Gunra ransomware assaults that target critical.

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

A rogue SIM card can commandeer its host device, including electric-vehicle chargers, industrial routers, and car telematics units. Of the six involved.

OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause

OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause

OpenAI has suspended certain "internal operations" related to its upcoming artificial intelligence (AI) model Astra following an internal assessment.

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Attackers' commands enable Rovo, Atlassian’s Jira and Confluence assistant, to gather data accessible to authenticated users This article explores.

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The U.S This article explores loadmaster reported exploited. . Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical security.

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

Discover how An array of 77 extensions on the Open VSX marketplace has been identified as imitating genuine developer tools, thereby sharing details about.

N-central Attackers Reach Managed Systems and Persist After Server Access Is Revoked

N-central Attackers Reach Managed Systems and Persist After Server Access Is Revoked

N-able has released an update for N-central, part of its efforts to address threats linked to a recently discovered vulnerability in RMM software. The.

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has warned of a severe security flaw impacting its business intelligence and data visualization software package, which has been exploited as a.

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

A recent analysis reveals that the cybercrime group known as TeamPCP has been operating on the dark web since 2020, indicating their presence for years.

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

On Wednesday, Connor Riley Moucka was found guilty by a federal court in Seattle of committing computer fraud, wire fraud, aggravated identity theft, and.

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Cybersecurity experts have identified six undisclosed services promoting unauthorized access to artificial intelligence models across dark web forums and.

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Security researcher Malcolm Stagg unveiled a new attack category called NatJack that exploits network address translation (NAT) state to intercept active.

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

Kali365 is exploiting a legitimate Microsoft login as a means to access corporate data This article explores kali365 exploiting legitimate. . Once access.

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

An unauthorized GitHub issue raised by a user without repository permissions allowed malicious code execution on CI runners associated with Anthropic and.

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

A newly patched security flaw affecting on-premise versions of JetBrains TeamCity has been actively exploited in the wild, as reported by the U.S This.

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

HashiCorp, Veeam, and the Django Software Foundation have addressed 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and.

Top 5 this week

Page 2 of 26