TranslatePress Vulnerability in WordPress Could Allow Administrator Password Reset

471/69 Friday, August 28, 2026 Wordfence has disclosed a Critical vulnerability, CVE-2026-19632, in the TranslatePress plugin for WordPress, which is installed on more than 400,000 websites. The vulnerability has a CVSS severity score of 9.8 and could allow unauthenticated attackers to access the password reset URL for an administrator account, including the reset key and […]

ThaiCERT

August 28, 2026

U.S. Announces Ban on Foreign Energy Infrastructure Equipment Over Cybersecurity Concerns

469/69 Friday, August 28, 2026 U.S. President Donald Trump has signed an executive order declaring a national emergency to protect the security of the country’s electric power infrastructure. The order aims to prohibit the use of certain foreign-made equipment, software, and related systems in the United States due to concerns over cybersecurity threats and national […]

ThaiCERT

August 28, 2026

PaperCut Warns of Zero-Day Vulnerability in NG and MF Actively Exploited, Urges Immediate Access Restriction

470/69 Friday, August 28, 2026 PaperCut has issued an urgent advisory after discovering that attackers are exploiting a vulnerability in PaperCut NG and PaperCut MF, enterprise print management software products. The attacks are being carried out as zero-day exploitation and affect all versions of the products. The company stated that customer environments have already been […]

ThaiCERT

August 28, 2026

Attempts Detected to Exploit Microsoft SharePoint by Chaining Two Vulnerabilities

468/69 Thursday, August 27, 2026 Threat intelligence company Defused disclosed that it detected attempts to attack Microsoft SharePoint by chaining two vulnerabilities: CVE-2026-55040, an authentication bypass vulnerability in JWT token validation, and CVE-2026-63520 in Business Connectivity Services (BCS). When used together, these vulnerabilities could allow code execution on unpatched SharePoint servers. Proof-of-concept (PoC) exploit code […]

ThaiCERT

August 27, 2026

Large-Scale DDoS Attack Disrupts Norway’s Government Digital Services

467/69 Thursday, August 27, 2026 The Norwegian Digitalization Agency, or Digitaliseringsdirektoratet (Digdir), disclosed that Norway’s central government digital infrastructure was affected by a large-scale Distributed Denial-of-Service (DDoS) attack starting at 03:38 CEST on Monday. The attack disrupted services used by government agencies and the public, targeting infrastructure that supports Digdir’s services and its operations provider, […]

ThaiCERT

August 27, 2026

Threat Actors Use npm and Mirror Sites to Host Phishing Pages and Redirect Users

466/69 Thursday, August 27, 2026 Reports indicate that threat actors have abused the npm package registry and websites that mirror package data as hosting locations for malicious HTML files. These webpages are designed to impersonate Cloudflare CAPTCHA verification pages to deceive visitors and redirect them to attacker-controlled websites. The incident is notable because it differs […]

ThaiCERT

August 27, 2026

miniOrange Vulnerabilities Actively Exploited on WordPress, Risking Authentication Bypass

465/69 Wednesday, August 26, 2026 Security researchers have disclosed attacks targeting WordPress websites by exploiting two Critical vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin. The vulnerabilities can be chained to forge SAML responses and bypass authentication, allowing attackers to log in with website administrator privileges. Patchstack has already detected […]

ThaiCERT

August 26, 2026

Warning: WeedHack Malware Hidden in Minecraft Add-ons Imitates Legitimate Websites to Steal Data

463/69 Wednesday, August 26, 2026 Cybersecurity researchers have detected the spread of WeedHack malware targeting gamers. Threat actors created fake websites impersonating providers of Minecraft add-ons or clients. Reports indicate that access to these malicious websites has already been detected and blocked more than 6,000 times. The attackers used search engine optimization poisoning, or SEO […]

ThaiCERT

August 26, 2026

Keycloak Releases Patch for Critical Vulnerability That Could Allow Account Takeover via Password Reset

462/69 Tuesday, August 25, 2026 Security researchers have disclosed a Critical vulnerability, CVE-2026-18963, in Keycloak, an Identity and Access Management (IAM) system. The vulnerability has a CVSS severity score of 9.1 and occurs in the password reset process. It could allow unauthenticated attackers to change passwords and take over user accounts, including administrator accounts, without […]

ThaiCERT

August 25, 2026
1 2 111