Malware (Infostealer) Spread Through Pirated Game Installations

497/68 Friday, November 28, 2025 Cybercriminals are exploiting the popularity of Battlefield 6 to trick players into downloading malicious software. According to a report from Bitdefender Labs, a large number of pirated files, fake installers, and counterfeit game trainers are being distributed across file-sharing websites and torrent platforms. Threat actors are impersonating well-known game-cracking groups […]

ThaiCERT

November 28, 2025

Multiple London Local Authorities Report IT Outages Following Cyberattack

496/68 Friday, November 28, 2025 The Royal Borough of Kensington and Chelsea (RBKC) and Westminster City Council (WCC) have disclosed that several of their IT systems became unavailable after suffering a cyberattack, disrupting key public services including customer service centers, communication channels, and online platforms. Both councils have activated emergency response plans to ensure essential […]

ThaiCERT

November 28, 2025

Hackers Begin Using LLM Models to Develop “Intelligent Malware” Capable of Real-Time Evasion

495/68 Friday, November 28, 2025 A new report from the Google Threat Intelligence Group (GTIG) reveals emerging techniques used by threat actors who are experimenting with embedding large language models (LLMs)-such as Google Gemini and Hugging Face models-directly into malware. The goal is to enable malware to rewrite its own code or generate new attack […]

ThaiCERT

November 28, 2025

Critical Firefox Vulnerability Hidden for 6 Months Potentially Affects Over 180 Million Users

494/68 Thursday, November 27, 2025 Security researchers from AISLE have disclosed a severe vulnerability, tracked as CVE-2025-13016, found in the WebAssembly (Wasm) component of the Firefox web browser. The flaw remained undetected for more than six months and stems from a single-line error in Firefox’s Garbage Collection (GC) code. The issue leads to a stack […]

ThaiCERT

November 27, 2025

Delta Dental of Virginia Reports Data Breach Affecting 145,918 Customers

493/68 Thursday, November 27, 2025 Delta Dental of Virginia (DDVA), a major dental insurance provider in the state of Virginia, has disclosed a data breach that resulted in unauthorized access to the personal information of approximately 145,918 customers. The incident stemmed from a compromised employee email account, which allowed attackers to access certain personal data, […]

ThaiCERT

November 27, 2025

FBI Warns of Surge in Bank Impersonation Scams Causing $262 Million in Losses

492/68 Thursday, November 27, 2025 The U.S. Federal Bureau of Investigation (FBI) has issued an urgent public warning following a sharp rise in Account Takeover (ATO) fraud. Since January 2025, cybercriminals have caused more than $262 million in financial losses, with the Internet Crime Complaint Center (IC3) receiving over 5,100 reports. Victims include individuals, businesses, […]

ThaiCERT

November 27, 2025

StealC V2 Malware Hides Inside Blender 3D Model Files, Steals Over 100 Types of Data

491/68 Wednesday, November 26, 2025 Cybercriminals are spreading the StealC V2 information-stealing malware through malicious Blender model files uploaded to 3D asset marketplaces such as CGTrader. The attackers exploit Blender’s ability to automatically run Python scripts (Auto Run), allowing malicious code to execute immediately when a user opens a .blend file. Many users enable this […]

ThaiCERT

November 26, 2025

Harvard University Discloses Data Breach Affecting Students, Alumni, Donors, and Staff

490/68 Wednesday, November 26, 2025 Harvard University has disclosed a data breach affecting its Alumni Affairs and Development (AAD) system, which was compromised through a voice phishing (vishing) attack. The incident allowed unauthorized access to personal information of alumni, donors, students, staff, and related individuals. The breach was detected on November 18, 2025, and Harvard […]

ThaiCERT

November 26, 2025

Warning Issued as ClickFix Attacks Re-emerge Using Fake Windows Update Screens and Steganography-Based Malware Delivery

489/68 Wednesday, November 26, 2025 A new and more sophisticated wave of ClickFix cyberattacks has been detected, leveraging highly convincing full-screen browser windows that mimic authentic Windows Update animations or authentication prompts. These fake screens are used to socially engineer victims into following instructions that ultimately execute malicious commands silently copied into the clipboard and […]

ThaiCERT

November 26, 2025

SonicWall Issues Warning for High-Severity Vulnerability CVE-2025-40601, Urges Immediate Updates

488/68 Tuesday, November 25, 2025 SonicWall has issued a security advisory regarding a high-severity buffer overflow vulnerability in the SonicOS SSLVPN service, identified as CVE-2025-40601 (CVSS 7.5). The flaw allows unauthenticated remote attackers to trigger a Denial-of-Service (DoS) condition, causing Gen7 and Gen8 firewalls to reboot or stop functioning. The vulnerability affects only devices with […]

ThaiCERT

November 25, 2025
1 2 60