LATEST

ZerOwl — Find Vulnerabilities Before Hackers Do
Nigeria Arrests RaccoonO365 Phishing Developer Linked to Microsoft 365 Attacks

Nigeria Arrests RaccoonO365 Phishing Developer Linked to Microsoft 365 Attacks

Three "high-profile internet fraud suspects" are detained by Nigerian authorities. They are accused of participating in phishing attacks directed at large corporations. Okitipi Samuel, aka Mo

New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards

New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards

Affected vendors include ASRock, ASUSTeK Computer, GIGABYTE, and MSI. A disparity in the DMA protection status is the cause of the vulnerability. If the vulnerability is successfully exploite

New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory

New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory

MongoDB has been found to have a high-severity security flaw that could let unauthorized users read uninitialized heap memory. The vulnerability affects MongoDB

New MacSync macOS Stealer Uses Signed App to Bypass Apple Gatekeeper

New MacSync macOS Stealer Uses Signed App to Bypass Apple Gatekeeper

A notarized, digitally signed Swift application is used to deliver a new version of MacSync. In order to get around Apple's Gatekeeper checks, it is posing as a messaging app installer. It ha

MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide

MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide

Sensitive information can be remotely leaked by an unauthorized attacker thanks to a MongoDB vulnerability. The zlib message decompression implementation is the source of the issue. The vulne

LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds

LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds

In 2022, LastPass experienced a significant hack that gave hackers access to its users' personal data. Bad actors have been able to exploit weak master passwords thanks to the encrypted vault

Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App

Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App

A new campaign that disseminates Android malware has been connected to a North Korean threat actor. The campaign makes use of QR codes that are hosted on phishing websites that imitate the lo

Italy Fines Apple €98.6 Million Over ATT Rules Limiting App Store Competition

Italy Fines Apple €98.6 Million Over ATT Rules Limiting App Store Competition

Competition in the App Store was limited by Apple's App Tracking Transparency (ATT) privacy framework. According to the Italian Competition Authority, the company was able to "unilaterally im

Top 5 this week

Page 267 of 270