LATEST

ZerOwl — Find Vulnerabilities Before Hackers Do
Credential-Stealing npm Malware Found In Popular React Native Packages

Credential-Stealing npm Malware Found In Popular React Native Packages

CYBER ATTACKZerowl

Researchers found a coordinated supply chain attack on two popular React Native npm packages on March 16, 2026. The infected releases add an install-time.

AWS Bedrock AgentCore Flaw Enables Stealthy C2 Channels and Data Theft

AWS Bedrock AgentCore Flaw Enables Stealthy C2 Channels and Data Theft

CYBER ATTACKZerowl

Researchers have shown a way to get around the sandbox isolation of AWS Bedrock AgentCore Code Interpreter, which has raised serious concerns about a.

Apple fixes a WebKit flaw that lets you bypass the same-origin policy on iOS and macOS.

Apple fixes a WebKit flaw that lets you bypass the same-origin policy on iOS and macOS.

On Tuesday, Apple released the first set of Background Security Improvements to fix a security hole in WebKit that affects iOS, iPadOS, and macOS This.

More Attackers Are Logging In, Not Breaking In

More Attackers Are Logging In, Not Breaking In

Credential theft is now the main way that attackers get into business networks This article explores credential theft especially. . They are using stolen.

Less Lucrative Ransomware Market Makes Attackers Alter Methods

Less Lucrative Ransomware Market Makes Attackers Alter Methods

As the amount of money people pay for ransomware goes down, threat actors are changing how they use built-in tools This article explores ransomware.

Glassworm Attacks Popular React Native Packages with npm Malware That Steals Credentials

Glassworm Attacks Popular React Native Packages with npm Malware That Steals Credentials

CYBER ATTACKZerowl

On March 16, 2026, a coordinated supply chain attack hit the developer community This article explores backdoored popular react. . A hacker known as.

Warlock Ransomware Group Augments Post-Exploitation Activities

Warlock Ransomware Group Augments Post-Exploitation Activities

Researchers at Trend Micro say that Warlock, also known as Water Manaul, has kept the same way of getting into systems during attacks in the second half.

UK’s Companies House WebFiling Flaw Exposed Private Director Data for Five Months

UK’s Companies House WebFiling Flaw Exposed Private Director Data for Five Months

CYBER ATTACKZerowl

The UK government's official business register, Companies House, has found a serious security hole in its WebFiling service This article explores agency.

To Beat Alert Overload, Stop Wasting Time on False Positives

To Beat Alert Overload, Stop Wasting Time on False Positives

CYBER ATTACKZerowl

Stop wasting time on false positives to avoid alert overload This article explores suspicious alerts prioritized. . At first glance, false positives in.

Simple Custom Font Rendering Can Poison ChatGPT, Claude, Gemini, and Other AI Systems

Simple Custom Font Rendering Can Poison ChatGPT, Claude, Gemini, and Other AI Systems

CYBER ATTACKZerowl

A new way to attack that takes advantage of a basic flaw in AI web assistants: the difference between what a browser shows a user and what an AI tool.

Top 5 this week

Page 131 of 278