LATEST

ZerOwl — Find Vulnerabilities Before Hackers Do
Fake PDFs and Chat Apps Let Patchwork Spy on PCs and Android Phones

Fake PDFs and Chat Apps Let Patchwork Spy on PCs and Android Phones

CYBER ATTACKZerowl

Patchwork, also known as Dropping Elephant, employs fake documents and chat apps to spy on computer and phone users This article explores chat apps spy.

Claude Code RCE Flaw Lets Malicious Pull Requests Execute Commands Without Approval

Claude Code RCE Flaw Lets Malicious Pull Requests Execute Commands Without Approval

CYBER ATTACKZerowl

A recently disclosed vulnerability in Anthropic’s Claude Code could enable an attacker to execute their commands on a developer's workstation by opening.

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Attackers' commands enable Rovo, Atlassian’s Jira and Confluence assistant, to gather data accessible to authenticated users This article explores.

Zbtlink Chinese Router Sold Worldwide Contains a Hidden Backdoor Affecting 20+ Models

Zbtlink Chinese Router Sold Worldwide Contains a Hidden Backdoor Affecting 20+ Models

CYBER ATTACKZerowl

Zbtlink routers sold globally have been identified with a covert remote-control implant that initiates when activated. Indicators of Compromise (IoCs): -.

WSUS Flaw Lets Attackers Turn Enterprise Update Servers Into Malware Delivery Systems

WSUS Flaw Lets Attackers Turn Enterprise Update Servers Into Malware Delivery Systems

CYBER ATTACKZerowl

A compromised Windows Server Update Services (WSUS) deployment could be exploited to distribute attacker-controlled software through an organization’s.

WordPress XSS2Shell Flaw Lets Unauthenticated Attackers Gain Remote Code Execution

WordPress XSS2Shell Flaw Lets Unauthenticated Attackers Gain Remote Code Execution

CYBER ATTACKZerowl

A newly discovered CVE-2026-64638, a pre-authentication cross-site scripting vulnerability in WordPress Core’s login screen that can be escalated to full.

Windows Hello Keys Can Be Borrowed to Bypass PINs and Gain Persistent Entra ID Access

Windows Hello Keys Can Be Borrowed to Bypass PINs and Gain Persistent Entra ID Access

CYBER ATTACKZerowl

A newly discovered technique reveals how attackers can exploit Windows Hello for Business (WHFB) cryptographic keys without needing the victim's PIN or.

UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions

UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions

CYBER ATTACKZerowl

UNC6671 employs data theft campaigns that start with a phone call This article explores passkeycenter com phishing. . Indicators of Compromise (IoCs): -.

Storm-1175 Deploys New StormEncryptor Ransomware, Likely Exploiting N-able Flaw

Storm-1175 Deploys New StormEncryptor Ransomware, Likely Exploiting N-able Flaw

CYBER ATTACKZerowl

Microsoft Threat Intelligence has identified a financially driven threat actor, known as Storm-1175, deploying a previously unreported ransomware family.

SilverFox Hijacks Trusted Software and Kernel Drivers to Disable Security Tools

SilverFox Hijacks Trusted Software and Kernel Drivers to Disable Security Tools

CYBER ATTACKZerowl

SilverFox has expanded its malware toolkit by targeting a Japanese industrial manufacturer through an email campaign disguised as a fake invoice This.

Top 5 this week

Page 30 of 271