LATEST

ZerOwl — Find Vulnerabilities Before Hackers Do
Red Hat ACM Privilege Escalation Vulnerability Lets Attackers Gain Full Cluster-Admin Access

Red Hat ACM Privilege Escalation Vulnerability Lets Attackers Gain Full Cluster-Admin Access

CYBER ATTACKZerowl

Red Hat has identified and disclosed a significant privilege escalation flaw, labeled CVE-2026-10090, impacting the Application Subscription controller.

Payroll Pirates AiTM Phishing Hijacks Microsoft 365 Sessions and Targets Payroll Emails

Payroll Pirates AiTM Phishing Hijacks Microsoft 365 Sessions and Targets Payroll Emails

CYBER ATTACKZerowl

Discover how Cybercriminals are leveraging phishing emails to infiltrate Microsoft 365 accounts and search for payroll-related files. Ref id: [random.

Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID, Bypassing MFA

Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID, Bypassing MFA

CYBER ATTACKZerowl

A new "Pass-the-Passkey" family of attack techniques showcases how systemic implementation flaws in WebAuthn can compromise passkey security, even when.

OpenAI Expands Daybreak Cyber with GPT-5.6 for Exploit Validation, Pentesting, and Red Teaming

OpenAI Expands Daybreak Cyber with GPT-5.6 for Exploit Validation, Pentesting, and Red Teaming

CYBER ATTACKZerowl

OpenAI has expanded its Daybreak program to provide more extensive access to frontier AI models for vetted cybersecurity defenders This article explores.

New ‘Ghostjacking’ Attack Lets Hackers Hijack AI Agents to Run Their Code on Developer Machines

New ‘Ghostjacking’ Attack Lets Hackers Hijack AI Agents to Run Their Code on Developer Machines

CYBER ATTACKZerowl

A novel "Ghostjacking" attack technique has been identified, enabling attackers to manipulate and control AI-driven coding agents via subtle manipulation.

Multiple ClamAV Vulnerabilities Allow Remote Attacker to Trigger DoS Condition

Multiple ClamAV Vulnerabilities Allow Remote Attacker to Trigger DoS Condition

CYBER ATTACKZerowl

Cisco has revealed multiple high-severity vulnerabilities in ClamAV that could disrupt antivirus scans and cause denial-of-service conditions This article.

Mozilla Revokes Firefox and Thunderbird GPG Signing Key After Accidental GitHub Commit

Mozilla Revokes Firefox and Thunderbird GPG Signing Key After Accidental GitHub Commit

CYBER ATTACKZerowl

Mozilla has rotated and revoked an unauthorized GPG key used in Firefox and Thunderbird release artifacts after unencrypted copies of the previous key.

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

A malicious tool server can quietly steal SSH keys, environment secrets, source code, and customer data without sending any obvious harmful instructions.

LiteLLM Package Compromise Can Expand Into Repositories, Clusters, Registries and Cloud Accounts

LiteLLM Package Compromise Can Expand Into Repositories, Clusters, Registries and Cloud Accounts

CYBER ATTACKZerowl

A supply chain breach involving LiteLLM underscores how a fleeting malicious package can lead to long-term vulnerabilities across cloud environments.

Top 5 this week

Page 24 of 271