LATEST

ZerOwl — Find Vulnerabilities Before Hackers Do
New Vidar Stealer Campaign Targets User Credentials

New Vidar Stealer Campaign Targets User Credentials

CYBER ATTACKZerowl

A covert operation orchestrated by North Korea's APT37 group has compromised numerous organizations across defense, law enforcement, and academic circles.

New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide

New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide

CYBER ATTACKZerowl

A new cyber threat actor has been identified operating a large-scale, long-running campaign targeting Salesforce Experience Cloud and ServiceNow portals.

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

The threat actor known as HoneyMyte (alias Mustang Panda) has been detected using an updated version of the CoolClient backdoor, which includes a signed.

Multiple TP-Link Vulnerabilities Allow Attackers to Bypass Authentication and Escalate Privileges

Multiple TP-Link Vulnerabilities Allow Attackers to Bypass Authentication and Escalate Privileges

CYBER ATTACKZerowl

TP-Link has acknowledged multiple severe vulnerabilities impacting Aginet networking devices managed by ISPs, including mesh systems, routers, PON units.

Microsoft SharePoint Server Vulnerability Allows Attackers to Inject and Execute Malicious Code Remotely

Microsoft SharePoint Server Vulnerability Allows Attackers to Inject and Execute Malicious Code Remotely

CYBER ATTACKZerowl

A newly disclosed flaw in Microsoft SharePoint Server has rekindled concerns among enterprise IT departments, as security researchers unveil how attackers.

Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and RCE Attacks

Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and RCE Attacks

CYBER ATTACKZerowl

Microsoft has released patches for several Exchange Server vulnerabilities that could lead to denial-of-service, privilege escalation, remote code.

Malicious VS Code Extension Drops Detached Python Payload Outside the Extension Host

Malicious VS Code Extension Drops Detached Python Payload Outside the Extension Host

CYBER ATTACKZerowl

A dangerous VS Code extension called "Solidity Pro" is infiltrating cryptocurrency developers' environments with a sophisticated multi-stage attack.

Magecart Campaign Uses Google Tag Manager To Steal Credit Card Data

Magecart Campaign Uses Google Tag Manager To Steal Credit Card Data

CYBER ATTACKZerowl

A notorious Magecart group is utilizing Google Tag Manager (GTM) to silently inject custom scripts onto e-commerce sites, effectively turning trusted.

HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel

HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel

CYBER ATTACKZerowl

A newly discovered malware framework called HACKERAI C2 Agent is utilizing GitHub Gists as a covert communication channel for attackers to execute.

Fortinet Patches Multiple Authentication Vulnerabilities in FortiWeb, FortiManager, and FortiClient

Fortinet Patches Multiple Authentication Vulnerabilities in FortiWeb, FortiManager, and FortiClient

CYBER ATTACKZerowl

Fortinet has released patches addressing authentication vulnerabilities across its FortiWeb, FortiManager, and FortiClient product lines, urging.

Top 5 this week

Page 14 of 271