LATEST

ZerOwl — Find Vulnerabilities Before Hackers Do
New npm Supply Chain Attack Began with the Keyv Library Compromised Hundreds of Popular Packages

New npm Supply Chain Attack Began with the Keyv Library Compromised Hundreds of Popular Packages

CYBER ATTACKZerowl

A new supply chain attack has turned trusted software packages into a pathway for credential theft. The campaign began after attackers compromised the.

Mythos 5 and GPT-5.6-Sol Take Unauthorized Actions During Cyber Evaluations

Mythos 5 and GPT-5.6-Sol Take Unauthorized Actions During Cyber Evaluations

CYBER ATTACKZerowl

The UK AI Security Institute (AISI) revealed an incident where AI agents conducting cybersecurity evaluations breached live internet operations without.

Meta AI Hacked Another Company After Testing Misconfiguration Exposed Internet Access

Meta AI Hacked Another Company After Testing Misconfiguration Exposed Internet Access

CYBER ATTACKZerowl

Meta confirmed that one of its AI models breached another company's systems during cybersecurity testing, after a misconfiguration exposed the model to.

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Security researcher Malcolm Stagg unveiled a new attack category called NatJack that exploits network address translation (NAT) state to intercept active.

macOS ClickFix Campaign Uses Browser Fingerprinting to Deliver Atomic Stealer Malware

macOS ClickFix Campaign Uses Browser Fingerprinting to Deliver Atomic Stealer Malware

CYBER ATTACKZerowl

The operation depends on hundreds of look-alike domains, fake software-download pages, and Terminal commands aimed at stealing sensitive data from.

Kimi K3 AI Model Escapes Sandbox During Security Test to Fetch Answers

Kimi K3 AI Model Escapes Sandbox During Security Test to Fetch Answers

CYBER ATTACKZerowl

Moonshot AI's open-weight model Kimi K3 breached its isolated testing environment during a cybersecurity evaluation, as reported by Wired. "But we also.

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

Kali365 is exploiting a legitimate Microsoft login as a means to access corporate data This article explores kali365 exploiting legitimate. . Once access.

Hidden Papyrus Test Mode Exposes Automated Clicking and Scrolling in Real Time

Hidden Papyrus Test Mode Exposes Automated Clicking and Scrolling in Real Time

CYBER ATTACKZerowl

IAS Threat Lab has identified Papyrus, a sophisticated mobile fraud operation that masks legitimate browsing sessions within popular novel-reading apps.

Hackers Can Leverage WSUS Servers to Deliver Malware and Compromise Enterprise Endpoints

Hackers Can Leverage WSUS Servers to Deliver Malware and Compromise Enterprise Endpoints

CYBER ATTACKZerowl

A novel attack chain enables adversaries to compromise Windows Server Update Services (WSUS), a trusted patch-management system widely used in enterprise.

Top 5 this week

Page 35 of 271