LATEST

ZerOwl — Find Vulnerabilities Before Hackers Do
Claude Code Makes Auto Mode Default, Blocking 89% of Dangerous Commands

Claude Code Makes Auto Mode Default, Blocking 89% of Dangerous Commands

CYBER ATTACKZerowl

Anthropic is altering default permission settings in Claude Code, aiming to enhance AI classifiers' reliability for detecting dangerous commands more.

Claude AI Agent Autonomously Hacks Gym Website Without User Permission

Claude AI Agent Autonomously Hacks Gym Website Without User Permission

CYBER ATTACKZerowl

An Australian gym's booking software was exploited by an autonomous AI cyberattack orchestrated by a Claude-powered agent on the OpenClaw framework This.

CISA Warns of Actively Exploited Critical SonicWall SMA1000 SSRF Flaw in Zero-Day Attacks

CISA Warns of Actively Exploited Critical SonicWall SMA1000 SSRF Flaw in Zero-Day Attacks

CYBER ATTACKZerowl

The U.S This article explores vulnerability sonicwall sma1000. . Cybersecurity and Infrastructure Security Agency (CISA) has added a critical.

Chinese-speaking Hacking Group Attacking Users With Fake DeepSeek Page to Deliver Malware

Chinese-speaking Hacking Group Attacking Users With Fake DeepSeek Page to Deliver Malware

CYBER ATTACKZerowl

Discover how Chinese hackers are luring Windows users into downloading fake software pages that mimic popular AI tools like DeepSeek and Quark Cloud.

BDThemes WordPress Supply Chain Attack Creates Rogue Admins and Deploys Webshells

BDThemes WordPress Supply Chain Attack Creates Rogue Admins and Deploys Webshells

CYBER ATTACKZerowl

BdThemes, a popular WordPress plugin provider, has fallen victim to a supply chain compromise that allows attackers to create rogue administrator accounts.

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

A rogue SIM card can commandeer its host device, including electric-vehicle chargers, industrial routers, and car telematics units. Of the six involved.

WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution

WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution

CYBER ATTACKZerowl

A critical vulnerability chain in WordPress Core, known as XSS2Shell, enables full remote code execution via a single failed login attempt on any active.

Windows 11’s Built-In Weather App Reportedly Consumes 1.2GB of RAM for Showing Forecasts

Windows 11’s Built-In Weather App Reportedly Consumes 1.2GB of RAM for Showing Forecasts

CYBER ATTACKZerowl

The default Windows 11 Weather app, installed on millions of users' taskbars, has come under scrutiny following independent testing that revealed it.

Top 5 this week

Page 26 of 271