ForcedLeak Vulnerability in Salesforce Agentforce Risks CRM Data Exposure via Prompt Injection

371/68 Monday, September 29, 2025 Researchers from Noma Labs have disclosed a critical vulnerability in Salesforce Agentforce, dubbed “ForcedLeak” (CVSS 9.4), which could be exploited through indirect prompt injection attacks to gain access to sensitive CRM data. The flaw affects organizations that have enabled the Web-to-Lead feature, stemming from insufficient AI context validation, over-compliance with […]

ThaiCERT

September 29, 2025

Hackers Spread Oyster Malware Through Fake Microsoft Teams Installer

369/68 Monday, September 29, 2025 Cybersecurity experts have discovered an attack in which hackers used SEO poisoning and search engine ads to promote fraudulent websites offering downloads of Microsoft Teams. Once installed, the victim’s computer becomes infected with the Oyster malware, providing attackers with an initial foothold into the organization’s network. The Oyster malware-also known […]

ThaiCERT

September 29, 2025

Nation-State Hackers Exploit Vulnerability in Libraesva Email Security Gateway

367/68 Friday, September 26, 2025 Italian company Libraesva, developer of the Email Security Gateway (ESG) solution, has issued a security advisory regarding vulnerability CVE-2025-59689, which has been actively exploited by nation-state hackers through specially crafted compressed email attachments. The flaw allows attackers to execute command injection on the system under a non-privileged user account. The […]

ThaiCERT

September 26, 2025

Alert: Hackers Using Fake Websites to Target Python Developers via PyPI

366/68 Friday, September 26, 2025 The Python Software Foundation (PSF) has issued a warning about a new phishing campaign targeting Python developers and project maintainers. Threat actors have created fake websites impersonating the Python Package Index (PyPI) – the official repository for Python packages – tricking users into verifying their account credentials under the guise […]

ThaiCERT

September 26, 2025

Researchers Warn of BadIIS Using SEO Poisoning to Redirect Users to Spam and Gambling Sites

365/68 Thursday, September 25, 2025 Security researchers have warned that the Operation Rewrite campaign is deploying BadIIS malware to conduct SEO poisoning attacks, targeting East Asia and Southeast Asia, particularly Vietnam. The goal is to manipulate search engine rankings, tricking users into visiting compromised websites that then redirect them to spam sites or unwanted content […]

ThaiCERT

September 25, 2025

SolarWinds Releases Hotfix for CVE-2025-26399 in Web Help Desk

364/68 Thursday, September 25, 2025 SolarWinds has released a hotfix to address a critical vulnerability tracked as CVE-2025-26399 (CVSS 9.8) affecting Web Help Desk. If successfully exploited, the flaw could allow attackers to perform remote code execution (RCE) on affected servers. The vulnerability stems from the deserialization of untrusted data within the AjaxProxy module and […]

ThaiCERT

September 25, 2025

U.S. Secret Service Seizes 300 SIM Servers to Thwart Threats During UN Assembly

363/68 Thursday, September 25, 2025 The U.S. Secret Service announced on Tuesday that it had seized a network of illegal electronic devices deployed across the New York area, which had been used to threaten U.S. government officials and posed a serious national security risk. The operation resulted in the confiscation of over 300 SIM servers […]

ThaiCERT

September 25, 2025

Malware Discovered in Verified Steam Game Causes Over $150,000 in Losses

362/68 Wednesday, September 24, 2025 The Steam gaming platform has once again become a vector for cyberattacks after it was discovered that the verified game BlockBlasters was secretly embedding cryptodrainer malware designed to steal digital assets. Attackers employed a strategy of releasing what appeared to be a safe game with positive reviews at first, only […]

ThaiCERT

September 24, 2025
1 2 45