WhatsApp Attack Uses VBScript Files Disguised as Business Documents to Take Control of Systems

340/69 Wednesday, June 24, 2026 Reports have emerged of a cyberattack campaign targeting WhatsApp users in multiple countries around the world, including countries in Asia. Threat actors are sending deceptive messages with malicious VBScript attachments through compromised WhatsApp accounts. The attack abuses the trust associated with people in the victim’s contact list to trick users […]

chanapon

June 24, 2026

Google Adds Android Developer Verification Measures to Reduce the Risk of Installing Malicious Apps

339/69 Tuesday, June 23, 2026 Google has set September 30, 2026, as the start date for enforcing Android developer verification in the first four countries: Brazil, Indonesia, Singapore, and Thailand. Certified Android devices with Google services will check whether an app being installed comes from a developer who has verified their identity and registered the […]

chanapon

June 23, 2026

Salesforce Disables Klue Integration After OAuth Token Theft Affects Some Customer Data

338/69 Tuesday, June 23, 2026 A supply chain attack has been reported targeting organizations using Salesforce, in which attackers compromised the integration of a third-party application called Klue Battlecards to access and steal customer data. Salesforce disabled the application’s integration infrastructure on June 17, 2026, to stop unauthorized access. The company clarified that the incident […]

chanapon

June 23, 2026

AryStinger Botnet Malware Found Taking Over More Than 4,000 Older D-Link Routers for Cyberattack Operations

337/69 Tuesday, June 23, 2026 Cyber threat researchers from XLab have detected a new botnet named AryStinger, which has taken control of more than 4,000 outdated routers worldwide. The malware turns compromised devices into remotely controlled operational nodes for attackers. This incident represents a significant threat because attackers can use these devices to carry out […]

chanapon

June 23, 2026

Gravity SMTP Plugin Vulnerability Exploited on WordPress, Risking Exposure of Sensitive Information

336/69 Monday, June 22, 2026 Security researchers have disclosed that attackers are actively exploiting CVE-2026-4020 in the Gravity SMTP plugin for WordPress, which is installed on more than 100,000 websites. The vulnerability is an Information Disclosure issue that allows unauthenticated attackers to access system configuration data, including API keys, secrets, and OAuth tokens configured for […]

chanapon

June 22, 2026

FortiBleed Exposes Large-Scale Credential Spraying Campaign Targeting Fortinet VPNs Worldwide

335/69 Monday, June 22, 2026 Reports indicate that FortiBleed has exposed a large-scale attack campaign that attempted to log in to Fortinet VPNs through billions of Credential Spraying attempts, resulting in compromises of multiple organizations worldwide. The incident was discovered by Volodymyr “Bob” Diachenko, a researcher from SecurityDiscovery.com, after the attackers’ infrastructure was exposed on […]

chanapon

June 22, 2026

The Gentlemen Ransomware Group Uses GentleKiller Tool to Exploit Driver Vulnerabilities and Disable Security Systems

334/69 Monday, June 22, 2026 ESET has published an investigation into the infrastructure of the Ransomware-as-a-Service group known as The Gentlemen, which has been active since late 2025 and has claimed more than 504 victims. Its primary targets are in Southeast Asia, South America, and Western Europe. What makes this group notable is not only […]

chanapon

June 22, 2026

Microsoft 365 Copilot Vulnerability Could Allow Data Theft Through a Link Click

327/69 Wednesday, June 17, 2026 Security researchers have disclosed a vulnerability in Microsoft 365 Copilot Enterprise Search, known as SearchLeak, which could allow attackers to steal data from emails, files in SharePoint and OneDrive, as well as MFA codes or one-time verification codes. The attack could be carried out by tricking a victim into clicking […]

chanapon

June 17, 2026

Mackay Sugar, Major Australian Sugar Producer, Reports Cyberattack Affecting Operations

326/69 Wednesday, June 17, 2026 Mackay Sugar, one of Australia’s major sugar producers, disclosed that the company experienced a cyberattack on June 10, 2026, which affected some of its operations. Mackay Sugar operates three main sugar mills: Farleigh, Marian, and Racecourse, with an annual raw sugar production capacity of approximately 700,000 tonnes for both domestic […]

chanapon

June 17, 2026

U.S. Authorities Shut Down Deepfake Non-Consensual Intimate Image Websites Under the TAKE IT DOWN Act

325/69 Wednesday, June 17, 2026 The U.S. Department of Justice (DOJ) announced the seizure of the domains CFAKE[.]com and SOCFAKE[.]com, which were used to distribute pornographic images and videos created using artificial intelligence or deepfake technology without the consent of the individuals depicted. This marks the first public domain seizure enforcement action under the TAKE […]

chanapon

June 17, 2026
1 4 5 6 7