Docker Users Urged to Update Immediately: DockerDash Vulnerability in AI Assistant “Ask Gordon” Risks Code Execution via Image Metadata

72/69 Thursday, February 5, 2026 Cybersecurity researchers from Noma Labs have disclosed a critical vulnerability named DockerDash affecting Ask Gordon, the AI assistant integrated into Docker Desktop and Docker CLI. The flaw allows attackers to perform Remote Code Execution (RCE) and secretly exfiltrate sensitive data by exploiting how the assistant reads and processes metadata attached […]

ThaiCERT

February 5, 2026

React Native Vulnerability Actively Exploited in the Wild

71/69 Thursday, February 5, 2026 Researchers from vulnerability intelligence firm VulnCheck have revealed that a critical vulnerability in the React Native platform has been actively exploited since late December. The flaw, tracked as CVE-2025-11953, carries a CVSS score of 9.8 (Critical) and affects the widely used @react-native-community/cli package, a key tool for developing React Native […]

ThaiCERT

February 5, 2026

Critical Zero-Day Vulnerabilities in Ivanti EPMM Actively Exploited – Immediate Patching Urged

70/69 Thursday, February 5, 2026 Cybersecurity experts have issued a warning after discovering two newly identified critical vulnerabilities (CVE-2026-1281 and CVE-2026-1340) in Ivanti Endpoint Manager Mobile (EPMM), a platform widely used by large organizations to manage employee mobile devices. These flaws carry a severity score of 9.8 out of 10, as they allow attackers to […]

ThaiCERT

February 5, 2026

Researchers Discover Over 200 Malicious Skills on OpenClaw Distributing Password-Stealing Malware

69/69 Wednesday, February 4, 2026 Security researchers have identified a large number of malicious add-on packages, or “Skills,” targeting OpenClaw-an open-source personal AI assistant formerly known as Moltbot and ClawdBot. These threats were discovered on the official registry (ClawHub) and GitHub between January 27 and February 1. More than 230 harmful Skills were found impersonating […]

ThaiCERT

February 4, 2026

Panera Bread Data Breach Impacts 5.1 Million Accounts, Confirmed by HIBP

68/69 Wednesday, February 4, 2026 Have I Been Pwned (HIBP) has confirmed that the Panera Bread data breach affected approximately 5.1 million user accounts, a figure significantly lower than the 14 million accounts previously claimed by the cybercriminal group ShinyHunters. The group alleged that it had gained access to Panera Bread’s systems and stolen a […]

ThaiCERT

February 4, 2026

APT28 Hackers Exploit Newly Patched Microsoft Office Vulnerability to Target Ukrainian and European Government Agencies

67/69 Wednesday, February 4, 2026 Ukraine’s CERT-UA has identified a new cyberattack campaign carried out by the APT28 hacking group, also known as Fancy Bear, which is linked to Russia. The attackers targeted government agencies and organizations across Europe by distributing phishing emails containing malicious Microsoft Word attachments. These documents referenced “EU COREPER consultations in […]

ThaiCERT

February 4, 2026

Publicly Exposed MongoDB Databases at Risk of Data Deletion and Ransom Extortion Due to Misconfiguration

66/69 Tuesday, February 3, 2026 Researchers from cybersecurity firm Flare have released a report on attacks targeting publicly exposed MongoDB databases, where threat actors scan for misconfigured servers that allow unauthenticated access. The investigation identified more than 208,500 MongoDB servers accessible from the internet, with approximately 3,100 instances lacking any form of protection. Nearly half […]

ThaiCERT

February 3, 2026

SCADA Vulnerability Causes Denial-of-Service, Impacting Industrial System Availability

65/69 Tuesday, February 3, 2026 A security vulnerability has been identified in Mitsubishi Electric Iconics Suite, a widely used Supervisory Control and Data Acquisition (SCADA) software platform deployed across industrial sectors such as energy, automotive, and manufacturing. The vulnerability, tracked as CVE-2025-0921, is rated medium severity (CVSS 6.5) and can be exploited to trigger a […]

ThaiCERT

February 3, 2026

AI Security Startup CEO Shares Near-Miss With Deepfake Job Applicant and Cross-Border Hiring Scam

64/69 Tuesday, February 3, 2026 The threat of deepfake-based job applications is rapidly becoming a critical issue in the cybersecurity landscape. Jason Rebholz, CEO of an AI security startup, revealed that he was nearly deceived by a sophisticated scam believed to be linked to North Korean IT operatives. Despite being a seasoned security professional with […]

ThaiCERT

February 3, 2026

Hackers Use Vishing to Impersonate IT Staff, Steal MFA Tokens, and Access SaaS Systems

63/69 Monday, February 2, 2026 Mandiant has observed an increase in activity from financially motivated cybercriminal groups using tactics similar to those of ShinyHunters. These actors rely on vishing (voice phishing) attacks, calling victims while impersonating IT support staff and convincing employees to visit fake websites to “update” their MFA settings. As a result, attackers […]

ThaiCERT

February 2, 2026
1 2 73