Fire Ant Uses Cisco IOS XR Routers to Capture Traffic and Hide Attack Activity

480/69 Wednesday, September 2, 2026 Security researchers have disclosed attacks by the Fire Ant group targeting infrastructure used by organizations to connect and manage networks, including Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. The attackers used these systems to maintain access, capture network traffic and credentials, and pivot to other connected […]

ThaiCERT

September 2, 2026

Hackers Steal Identity and Vehicle Registration Data from Latvia’s Road Traffic Safety Authority

479/69 Wednesday, September 2, 2026 Latvia’s Road Traffic Safety Directorate (CSDD) disclosed a data breach after attackers gained access to the agency’s systems and stole data belonging to approximately 1.2 million individuals and around 200,000 legal entities. The number of affected individuals represents roughly two-thirds of Latvia’s population. CERT.LV stated that the attackers obtained the […]

ThaiCERT

September 2, 2026

ValleyRAT Malware Hidden in Adware to Compromise Systems and Steal User Data

478/69 Wednesday, September 2, 2026 Researchers from Kaspersky have discovered a new cyberattack campaign in which the dangerous ValleyRAT malware is bundled with adware to evade detection. Initial findings indicate that the Silver Fox threat group is behind the campaign, with the objective of stealing sensitive information and gaining control of victims’ systems. The attack […]

ThaiCERT

September 2, 2026

Anthropic Warns Infostealer Malware Is Stealing Claude Sessions, Risking Unauthorized Account Access

477/69 Tuesday, September 1, 2026 Anthropic has warned Claude users after finding cases where infostealer malware on users’ computers stole login sessions and used those sessions to access Claude accounts and consume account usage quotas without authorization. The incident was not caused by malware directly related to Claude or installed through the Claude service. Instead, […]

ThaiCERT

September 1, 2026

FulcrumSec Claims Theft of Manchester Airports Group Data After API Credentials Found in Client-Side JavaScript

476/69 Tuesday, September 1, 2026 Manchester Airports Group (MAG), the operator of Manchester, London Stansted, and East Midlands airports, disclosed a data breach on August 27, 2026, stating that the incident affected approximately 8.7 million customers, most of whom had only their email addresses exposed. The affected data was related to bookings for parking, lounges, […]

ThaiCERT

September 1, 2026

Warning: TerminalFix Campaign Delivers Malware Through Fake CAPTCHA Pages

475/69 Tuesday, September 1, 2026 Microsoft’s security research team has warned about the spread of a new cyberattack campaign named TerminalFix, an evolution of the ClickFix technique, targeting organizations across multiple sectors. The attack tricks users into copying malicious commands and running them in Windows Terminal or PowerShell through fake Cloudflare CAPTCHA verification pages hosted […]

ThaiCERT

September 1, 2026

Critical Vulnerabilities Warned in WPMU DEV Dashboard, Pods, and GiveWP WordPress Plugins

474/69 Monday, August 31, 2026 Reports have disclosed Critical vulnerabilities in several WordPress plugins, including WPMU DEV Dashboard, Pods, and GiveWP. The vulnerabilities have CVSS severity scores ranging from 9.8 to 10.0 and could lead to authentication bypass, privilege escalation, user password changes, or command execution on servers, depending on the affected plugin and the […]

ThaiCERT

August 31, 2026

Brave Introduces Feature to Help Users Hide Real Email Addresses and Prevent Tracking in Version 1.94

472/69 Monday, August 31, 2026 The Brave web browser has introduced a new Email Aliases feature in version 1.94, allowing users to create disposable email addresses for signing up for services on various websites. Messages sent to these aliases are forwarded to the user’s primary email address. This development helps close a privacy gap, as […]

ThaiCERT

August 31, 2026

TranslatePress Vulnerability in WordPress Could Allow Administrator Password Reset

471/69 Friday, August 28, 2026 Wordfence has disclosed a Critical vulnerability, CVE-2026-19632, in the TranslatePress plugin for WordPress, which is installed on more than 400,000 websites. The vulnerability has a CVSS severity score of 9.8 and could allow unauthenticated attackers to access the password reset URL for an administrator account, including the reset key and […]

ThaiCERT

August 28, 2026
1 2 82