Fake Performance Evaluation Emails Deliver GuLoader and Remcos RAT Malware

24/69 Wednesday, January 14, 2026 The AhnLab Security Intelligence Center (ASEC) has identified a cyberattack campaign leveraging social engineering techniques to create psychological pressure through phishing emails. The emails use subject lines related to monthly performance evaluation reports and reference potential employee layoffs, aiming to induce panic and prompt recipients to urgently open the attached […]

ThaiCERT

January 14, 2026

Everest Ransomware Claims Breach of Nissan, Allegedly Stealing Over 900 GB of Data

23/69 Wednesday, January 14, 2026 The Everest ransomware group has claimed that it breached the systems of Nissan Motor Corporation and exfiltrated approximately 900 GB of internal data. According to the attackers, the stolen data includes internal documents and screenshots from various corporate systems. The group published these claims on its dark web leak site […]

ThaiCERT

January 14, 2026

Hackers Use Browser-in-the-Browser (BitB) Technique to Create Fake Login Windows and Steal Facebook Credentials

22/69 Wednesday, January 14, 2026 Over the past six months, cybersecurity experts at Trellix have observed a significant increase in attacks targeting Facebook users using a technique known as Browser-in-the-Browser (BitB). This technique was originally introduced by security researcher mr.d0x in 2022. Attackers create fake login pop-up windows that closely mimic the real Facebook login […]

ThaiCERT

January 14, 2026

Spain Dismantles Cybercrime Network, Arrests 34 Suspects Linked to Black Axe Using Money Mule Accounts

21/69 Tuesday, January 13, 2026 Spanish authorities, in cooperation with the Bavarian State Police and Europol, have dismantled a major cybercrime network, arresting 34 suspects linked to the notorious Black Axe criminal organization. Raids were carried out in key locations including Seville, Madrid, and Barcelona, where law enforcement seized cash, electronic devices, vehicles, and froze […]

ThaiCERT

January 13, 2026

Cybercrime Involving Cryptocurrency Reaches Record High in 2025

20/69 Tuesday, January 13, 2026 Cryptocurrency transactions linked to illicit activity reached an all-time high in 2025, according to blockchain analytics data. Crypto addresses associated with criminal activity received at least USD 154 billion, representing a 162% increase year over year. This surge highlights a clear shift in cybercrime from purely financial motives toward broader […]

ThaiCERT

January 13, 2026

FBI Warns: Kimsuky Hackers Use QR Codes to Breach Systems and Bypass Organizational MFA

19/69 Tuesday, January 13, 2026 The FBI has issued a warning about a new tactic used by the hacker group Kimsuky (also known as APT43), which is actively targeting government agencies and educational institutions. The group is using a technique known as Quishing-phishing via QR codes. In these attacks, hackers send spear-phishing emails containing QR […]

ThaiCERT

January 13, 2026

MuddyWater Uses RustyWater RAT in Spear-Phishing Campaign Targeting Middle Eastern Organizations

18/69 Monday, January 12, 2026 The threat group MuddyWater has launched attacks against diplomatic, financial, telecommunications, and maritime transportation organizations in the Middle East using the RustyWater malware. The campaign relies on spear-phishing emails disguised as cybersecurity safety guidance, with a malicious Microsoft Word document attached. When victims open the document and click “Enable Content,” […]

ThaiCERT

January 12, 2026

BreachForums Database Leak Exposes Over 324,000 User Accounts

17/69 Monday, January 12, 2026 The well-known hacking forum BreachForums, a platform used for buying, selling, and sharing stolen data—as well as trading access to corporate networks and other cybercrime services-has suffered a data breach, with its user database table leaked online. The incident affects the latest incarnation of BreachForums, which has been repeatedly taken […]

ThaiCERT

January 12, 2026

APT Group APT28 Targets Energy Agencies and International Policy Organizations

16/69 Monday, January 12, 2026 Security researchers have observed renewed activity from the threat group APT28 (also known as BlueDelta), In this campaign, the group has focused on stealing high-value credentials, primarily targeting personnel in energy and nuclear research organizations in Turkey, as well as officials in European institutions and agencies in North Macedonia and […]

ThaiCERT

January 12, 2026

Cisco Releases Patch for CVE-2026-20029 in ISE, Risk of Sensitive Data Exposure via Web Management Interface

15/69 Friday, January 9, 2026 Cisco has released a security update to address CVE-2026-20029 affecting Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), which are used for network access control and identity management. The vulnerability is caused by improper handling of XML input processing in the Web Management Interface, allowing an attacker […]

ThaiCERT

January 9, 2026
1 2 68