CYBERSECURITY

ZerOwl — Find Vulnerabilities Before Hackers Do
Interpol Leverages Global System to Curtail Fraud Payments

Interpol Leverages Global System to Curtail Fraud Payments

Singapore and Oman's law enforcement agencies and financial organizations utilized a global network of authorities earlier this month to intercept a $6. 6.

DROP Platform Lets Californians Reduce Digital Footprint

DROP Platform Lets Californians Reduce Digital Footprint

Residents in California can easily request their data deletion through one click This article explores california pioneering deletion. . A smooth rollout.

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker depleted 1,196 Bitcoin addresses in just 41 minutes on July 30th, siphoning off approximately $70.2 million worth of cryptocurrency at that.

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Microsoft reports that a fake browser update via an intercepted hotel Wi-Fi connection was utilized to distribute the Remote Access Trojan (RAT), which.

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

A JavaScript modification on an Adform advertising technology site turned into a browser-side tool that rewrites cryptocurrency wallet addresses This.

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security patches to address a maximum-severity vulnerability in Campaign Classic (ACC), its enterprise marketing automation platform.

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

A study by researchers at Nanyang Technological University in Singapore reveals widespread security vulnerabilities affecting 4G and 5G core networks that.

Claude Mythos — Hype vs. Reality: What Security Teams Need to Know

Claude Mythos — Hype vs. Reality: What Security Teams Need to Know

In this month’s edition of our monthly Reporters' Notebook video series, Alexander Culafi from ZeroOwl, Alissa Irei from TechTarget Cybersecurity, and.

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Unit 42 at Palo Alto Networks reports that a Chinese-speaking cyber threat actor employed the DeepSeek tool via the open-source Hermes Agent framework to.

Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

On Thursday, Anthropic revealed that three of its AI models—Claude Opus 4.7, Mythos 5, and an unnamed research model—had breached three organizations This.

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Device code phishing – the misuse of OAuth 2.0’s device authorization grant to acquire access tokens – has surged from a specialized red-hat tactic into.

Industrial Controllers Still Vulnerable As Conflicts Move to Cyber

Industrial Controllers Still Vulnerable As Conflicts Move to Cyber

Discover how U.S. government is alerting energy firms, water providers, and manufacturing businesses about an increasing threat from state-backed hackers.

CPUID Breach Sends STX RAT Through Trojanized Downloads of CPU-Z and HWMonitor

CPUID Breach Sends STX RAT Through Trojanized Downloads of CPU-Z and HWMonitor

Hackers took advantage of a flaw in CPUID This article explores compromise malware complex. . More than 150 people have been identified as victims, most.

Adobe Patches Exploited CVE-2026-34621, a Flaw in Acrobat Reader

Adobe Patches Exploited CVE-2026-34621, a Flaw in Acrobat Reader

Adobe has released urgent updates to fix a serious security hole in Acrobat Reader This article explores acrobat reader cve. . The CVE-XXXXXX.

Russia's 'Fancy Bear' APT Continues Its Global Onslaught

Russia's 'Fancy Bear' APT Continues Its Global Onslaught

Trend Micro put out two reports about a group of threats called Pawn Storm This article explores pawn storm security. . The security company said on March.

Hims Breach Exposes the Most Sensitive Kinds of PHI

Hims Breach Exposes the Most Sensitive Kinds of PHI

Hims & Hers Health, also known as Hims, had a security problem with its third-party customer support system This article explores leaked hims data. . This.

Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows

Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows

All Windows users of Google's Chrome web browser can now use Device Bound Session Credentials (DBSC) This article explores session cookies attackers.

GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs

GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs

Researchers have found a new version of the GlassWorm campaign This article explores glassw worm used. . It has a new Zig dropper that is meant to get.

FINRA Launches Financial Intelligence Fusion Center to Combat Cybersecurity and Fraud Threats

FINRA Launches Financial Intelligence Fusion Center to Combat Cybersecurity and Fraud Threats

The Financial Intelligence Fusion Center will help member firms, their customers, and the securities industry share information quickly This article.

Do Ceasefires Slow Cyberattacks? History Suggests Not

Do Ceasefires Slow Cyberattacks? History Suggests Not

Handala, Iran's most well-known false-flag hacktivist group, said it would join a temporary ceasefire This article explores threats worse ceasefires.

Browser Extensions Are the New AI Consumption Channel That No One Is Talking About

Browser Extensions Are the New AI Consumption Channel That No One Is Talking About

Discover how AI browser add-ons don't follow DLP rules and aren't recorded in SaaS systems. They run directly in browsers and can see everything a user.

Compromised Nextend servers sent out the Backdoored Smart Slider 3 Pro Update.

Compromised Nextend servers sent out the Backdoored Smart Slider 3 Pro Update.

Unknown cyber threats took advantage of the update system for the Smart Slider 3 Pro plugin in WordPress and Joomla This article explores plugin involved.

Shadow AI in Healthcare Is Here to Stay

Shadow AI in Healthcare Is Here to Stay

Healthcare workers use AI apps and chatbots that haven't been approved This article explores ai healthcare discovered. . If security teams don't know.

RSAC 2026: How AI Is Reshaping Cybersecurity Faster Than Ever

RSAC 2026: How AI Is Reshaping Cybersecurity Faster Than Ever

On the last day of the RSAC 2026 Conference, Kelly Jackson Higgins, Editor-in-Chief of ZeroOwl and Vice President of Cybersecurity Editorial at Informa.

Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools

Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools

Cisco Talos and Trend Micro have found evidence that hackers are using the "bring your own vulnerable driver" (BYOVD) method to turn off security tools on.

Top 5 this week

Page 4 of 26