LATEST

ZerOwl — Find Vulnerabilities Before Hackers Do
Active Attacks Exploit Gladinet's Hard-Coded Keys for Unauthorized Access and Code Execution

Active Attacks Exploit Gladinet's Hard-Coded Keys for Unauthorized Access and Code Execution

A new actively exploited vulnerability in Gladinet's CentreStack and Triofox products. The use of hard-coded cryptographic keys could allow threat actors to decrypt or forge access tickets. A

5 Threats That Reshaped Web Security This Year [2025]

5 Threats That Reshaped Web Security This Year [2025]

Defensive strategies had to be fundamentally rethought due to supply chain compromises, AI-powered attacks, and evolving injection techniques. A coordinated JavaScript injection campaign that

3,000 YouTube Videos Exposed as Malware Traps in Massive Ghost Network Operation

3,000 YouTube Videos Exposed as Malware Traps in Massive Ghost Network Operation

DATA BREACHZerowl

It has been noted that a network of YouTube accounts promotes videos that result in the download of malware. To date, the network has released over 3,000 malicious videos; since the beginning

2025 Cybersecurity Reality Check: Breaches Hidden, Attack Surfaces Growing, and AI Misperceptions Rising

2025 Cybersecurity Reality Check: Breaches Hidden, Attack Surfaces Growing, and AI Misperceptions Rising

DATA BREACHZerowl

The current state of cyber defense is starkly depicted in Bitdefender's 2025 Cybersecurity Assessment Report. Even when they felt that disclosure was required, 58% of security professionals w

13-Year-Old Redis Flaw Exposed: CVSS 10.0 Vulnerability Lets Attackers Run Code Remotely

13-Year-Old Redis Flaw Exposed: CVSS 10.0 Vulnerability Lets Attackers Run Code Remotely

GENERALZerowl

A maximum-severity security vulnerability in Redis's in-memory database software has been made public. RediShell, also known as CVE-2025-49844, is a vulnerability with a CVSS score of

Warning: Over 2,000 Palo Alto Networks Devices Hacked in Ongoing Attack Campaign

Warning: Over 2,000 Palo Alto Networks Devices Hacked in Ongoing Attack Campaign

CYBER ATTACKZerowl

It is estimated that a campaign abusing the recently revealed security flaws compromised up to 2,000 Palo Alto Networks devices. The vulnerabilities in question are a combination of privilege

U.S. Sanctions Chinese Cybersecurity Firm Over Treasury Hack Tied to Silk Typhoon

U.S. Sanctions Chinese Cybersecurity Firm Over Treasury Hack Tied to Silk Typhoon

CYBER ATTACKZerowl

A Chinese cybersecurity firm and a cyber actor based in Shanghai have been subject to sanctions by the U.S. Treasury Department's Office of Foreign Assets Control. Yin Kecheng, who is associa

U.S. Agencies Warn of Rising Iranian Cyber Attacks on Defense, OT Networks, and Critical Infrastructure

U.S. Agencies Warn of Rising Iranian Cyber Attacks on Defense, OT Networks, and Critical Infrastructure

CYBER ATTACKZerowl

Iranian state-sponsored or affiliated threat actors may launch cyberattacks, according to U.S. cybersecurity and intelligence agencies. According to the agencies, there is currently no proof

Top 5 this week

Page 260 of 271