LATEST

ZerOwl — Find Vulnerabilities Before Hackers Do
Anthropic, Google, and OpenAI Coding Agents Exposed to Zero-Privilege RCE

Anthropic, Google, and OpenAI Coding Agents Exposed to Zero-Privilege RCE

CYBER ATTACKZerowl

A newly disclosed critical flaw in AI coding-agent workflows from Anthropic, Google, and OpenAI could allow an unauthenticated attacker to exploit a.

$289 Greatness Phishing Kit Offers Ready-Made Lures and Microsoft 365 Token Theft

$289 Greatness Phishing Kit Offers Ready-Made Lures and Microsoft 365 Token Theft

CYBER ATTACKZerowl

Greatness' phishing-as-a-service (PhaaS) service has grown its toolkit, allowing cybercriminals to target Microsoft 365 accounts through sophisticated.

250+ macOS ClickFix Domains Use Browser Fingerprinting to Hide Atomic Stealer Attacks

250+ macOS ClickFix Domains Use Browser Fingerprinting to Hide Atomic Stealer Attacks

CYBER ATTACKZerowl

Atomic Stealer malware is being distributed via deceptive websites that mimic legitimate offerings. This tactic relies on psychological persuasion rather.

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

HashiCorp, Veeam, and the Django Software Foundation have addressed 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and.

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

Discover how Cybersecurity researchers have identified an advanced evolution of the EtherHiding blockchain-based command-and-control (C2) technique that.

Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA

Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA

CYBER ATTACKZerowl

Three distinct Phishing-as-a-Service (PhaaS) platforms—Sneaky 2FA, EvilTokens, and EvilProxy—are actively targeting US organizations to steal Microsoft.

The Gentlemen Ransomware Affiliate Deploys EtherRAT via Ethereum Smart Contract C2

The Gentlemen Ransomware Affiliate Deploys EtherRAT via Ethereum Smart Contract C2

CYBER ATTACKZerowl

Discover how An exposed directory on 193.233.202[. ]17 has revealed a detailed intrusion toolkit linked to suspected affiliate of The Gentlemen ransomware.

QNET SOC Inherits Fully Contained Ransomware Incident After 128-Second Response

QNET SOC Inherits Fully Contained Ransomware Incident After 128-Second Response

CYBER ATTACKZerowl

In just 128 seconds following Microsoft Defender’s automatic isolation of a compromised endpoint, QNET’s security operations center experienced a.

Poison Claude is Selling Cheap AI Tokens Built on Fake Accounts and Free Credits

Poison Claude is Selling Cheap AI Tokens Built on Fake Accounts and Free Credits

CYBER ATTACKZerowl

Discover how A clandestine online service called Poison Claude is profiting from reselling Anthropic’s premium AI models for a substantial discount. This.

Top 5 this week

Page 38 of 271