LATEST

ASD Warns of Ongoing BADCANDY Attacks Exploiting Cisco IOS XE Vulnerability

ASD Warns of Ongoing BADCANDY Attacks Exploiting Cisco IOS XE Vulnerability

DATA BREACHZerowl

A bulletin about persistent cyberattacks targeting unpatched Cisco IOS XE devices in the nation was released by the Australian Signals Directorate (ASD). According to the intelligence agency,

Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild

Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild

Security updates for iOS, iPadOS, macOS, tvOS, watchOS, visionOS, and its Safari web browser were made available by Apple on Friday. Two security vulnerabilities that have reportedly been exp

Analysing ClickFix: 3 Reasons Why Copy/Paste Attacks Are Driving Security Breaches

Analysing ClickFix: 3 Reasons Why Copy/Paste Attacks Are Driving Security Breaches

DATA BREACHZerowl

ClickFix attacks require the user to resolve a challenge or issue within the browser. By copying malicious code from the page clipboard and executing it locally, they deceive users into execu

Amazon Uncovers Attacks Exploited Cisco ISE and Citrix NetScaler as Zero-Day Flaws

Amazon Uncovers Attacks Exploited Cisco ISE and Citrix NetScaler as Zero-Day Flaws

Two then-zero-day security holes in Cisco and Citrix products were exploited by an advanced threat actor. Amazon's MadPot honeypot network detected the attacks. The activity resulted in the d

Active Exploits Hit Dassault and XWiki — CISA Confirms Critical Flaws Under Attack

Active Exploits Hit Dassault and XWiki — CISA Confirms Critical Flaws Under Attack

Threat actors are taking advantage of security holes in XWiki and Dassault Systèmes DELMIA Apriso. Alerts have been released by VulnCheck and the U.S. Cybersecurity and Infrastructure Securit

Active Directory Under Siege: Why Critical Infrastructure Needs Stronger Security

Active Directory Under Siege: Why Critical Infrastructure Needs Stronger Security

DATA BREACHZerowl

For more than 90% of Fortune 1000 companies, Active Directory continues to be the foundation for authentication. AD is the source of authentication and authorization for all applications, use

Active Attacks Exploit Gladinet's Hard-Coded Keys for Unauthorized Access and Code Execution

Active Attacks Exploit Gladinet's Hard-Coded Keys for Unauthorized Access and Code Execution

A new actively exploited vulnerability in Gladinet's CentreStack and Triofox products. The use of hard-coded cryptographic keys could allow threat actors to decrypt or forge access tickets. A

5 Threats That Reshaped Web Security This Year [2025]

5 Threats That Reshaped Web Security This Year [2025]

Defensive strategies had to be fundamentally rethought due to supply chain compromises, AI-powered attacks, and evolving injection techniques. A coordinated JavaScript injection campaign that

3,000 YouTube Videos Exposed as Malware Traps in Massive Ghost Network Operation

3,000 YouTube Videos Exposed as Malware Traps in Massive Ghost Network Operation

DATA BREACHZerowl

It has been noted that a network of YouTube accounts promotes videos that result in the download of malware. To date, the network has released over 3,000 malicious videos; since the beginning

2025 Cybersecurity Reality Check: Breaches Hidden, Attack Surfaces Growing, and AI Misperceptions Rising

2025 Cybersecurity Reality Check: Breaches Hidden, Attack Surfaces Growing, and AI Misperceptions Rising

DATA BREACHZerowl

The current state of cyber defense is starkly depicted in Bitdefender's 2025 Cybersecurity Assessment Report. Even when they felt that disclosure was required, 58% of security professionals w

Top 5 this week

Page 199 of 211