LATEST

Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability

Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability

Two hacking groups with ties to China have been observed weaponizing the newly disclosed security flaw in React Server Components (RSC) The vulnerability in question is CVE-2025-55182 (CVSS s

Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or Uyghurs

Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or Uyghurs

CrowdStrike says DeepSeek-R1 produces more security vulnerabilities in response to prompts that contain topics deemed politically sensitive by China. The Chinese AI company previously attract

Chinese Cybercrime Group Runs Global SEO Fraud Ring Using Compromised IIS Servers

Chinese Cybercrime Group Runs Global SEO Fraud Ring Using Compromised IIS Servers

DATA BREACHZerowl

Search engine optimization (SEO) fraud has been linked to the Chinese-speaking cybercrime group UAT-8099. Microsoft Internet Information Services (IIS) servers are the intended target of the

China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems

China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems

DATA BREACHZerowl

Tick, a suspected Chinese cyberespionage actor, is also referred to as Bronze Butler, Daserf, REDBALDKNIGHT, Stalker Panda, and Stalker Taurus. It is well-known for its widespread targeting o

China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats

China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats

DATA BREACHZerowl

A new series of attacks that take advantage of an unpatched Windows shortcut vulnerability have been connected to a threat actor with ties to China. Between September and October of 2025, Eur

China Accuses U.S. of Fabricating Volt Typhoon to Hide Its Own Hacking Campaigns

China Accuses U.S. of Fabricating Volt Typhoon to Hide Its Own Hacking Campaigns

CYBER ATTACKZerowl

The National Computer Virus Emergency Response Center (CVERC) of China has strengthened its assertion that Volt Typhoon, a threat actor, is a hoax. The agency then accused the United States o

ChatGPT Atlas Browser Can Be Tricked by Fake URLs into Executing Hidden Commands

ChatGPT Atlas Browser Can Be Tricked by Fake URLs into Executing Hidden Commands

OpenAI ChatGPT Atlas web browser susceptible to prompt injection attack. Attack disguises malicious instructions to look like a URL, but that Atlas treats as high-trust 'user intent' text. Pr

Bridging the Remediation Gap: Introducing Pentera Resolve

Bridging the Remediation Gap: Introducing Pentera Resolve

In addition to identifying risk, the objective is to take continuous, large-scale action on it. Security operations teams, which are already overburdened, are frequently tasked with consolida

Beware the Hidden Costs of Pen Testing

Beware the Hidden Costs of Pen Testing

Pen testing aids businesses in ensuring the security of their IT systems, but it should never be applied universally. Conventional methods can be inflexible, cost your company money and time,

Astaroth Banking Malware Resurfaces in Brazil via Spear-Phishing Attack

Astaroth Banking Malware Resurfaces in Brazil via Spear-Phishing Attack

CYBER ATTACKZerowl

A new spear-phishing campaign targeting Brazil has been found delivering a banking malware called Astaroth (aka Guildma) The malware makes use of obfuscated JavaScript to slip past security g

Top 5 this week

Page 198 of 211