Blue Shield of California Exposes Health Data of 4.7 Million Members to Google

154/68 Friday, April 25, 2025 Blue Shield of California has disclosed a data breach in which Protected Health Information (PHI) of more than 4.7 million members was inadvertently exposed to Google’s analytics and advertising platforms. The breach was due to a misconfiguration of Google Analytics on certain sections of the organization’s website. The incident occurred […]

ThaiCERT

April 25, 2025

Google Ends Cookie Notifications in Chrome and Introduces IP Protection for Incognito Mode

153/68 Friday, April 25, 2025 Google has announced that it will no longer display separate notifications regarding the use of third-party cookies in its Chrome browser, as part of its ongoing Privacy Sandbox initiative. Anthony Chavez, Vice President of Google’s Privacy Sandbox, stated that users can still manage their cookie preferences via Chrome’s privacy and […]

ThaiCERT

April 25, 2025

Hackers Exploit Zoom Remote Control Feature to Steal Cryptocurrency from Victims

151/68 Thursday, April 24, 2025 A hacker group known as Elusive Comet has been exposed for using social engineering tactics, specifically exploiting the Remote Control feature in Zoom to trick victims into granting control of their computers. The group targets high-value cryptocurrency users, according to cybersecurity firm Trail of Bits, which noted that the group’s […]

ThaiCERT

April 24, 2025

Kimsuky Exploits BlueKeep Vulnerability to Target Systems in South Korea and Japan, Focusing on Software, Energy, and Financial Industries

150/68 Wednesday, April 23, 2025 Cybersecurity researchers from AhnLab Security Intelligence Center (ASEC) in South Korea have detected a new cyberattack campaign linked to Kimsuky, a North Korean threat actor. The group is exploiting the BlueKeep vulnerability (CVE-2019-0708) in Microsoft Remote Desktop Services (RDP) to breach systems in South Korea and Japan. This campaign, dubbed […]

ThaiCERT

April 23, 2025

Scallywag Network Exploits WordPress Plugins to Generate 1.4 Million Fake Ad Requests Daily

149/68 Wednesday, April 23, 2025 Cybersecurity firm HUMAN, a leader in bot detection and ad fraud prevention, has uncovered “Scallywag,” a large-scale ad fraud operation embedded within WordPress plugins. The scheme leverages piracy websites and URL shortening services to generate fraudulent traffic. The group utilized four WordPress plugins—Soralink, Yu Idea, WPSafeLink, and Droplink—developed between 2016 […]

ThaiCERT

April 23, 2025

Hackers Target SonicWall SMA Devices Using 2021 Vulnerability Since January 2025

148/68 Tuesday, April 22, 2025 Researchers from Arctic Wolf have issued a warning about an ongoing cyberattack campaign targeting SonicWall Secure Mobile Access (SMA) devices. The attacks, active since January 2025, exploit CVE-2021-20035, a known OS command injection vulnerability in the SMA100 management interface. This flaw allows an authenticated attacker to execute arbitrary system commands […]

ThaiCERT

April 22, 2025

ASUS Confirms Critical Vulnerability in AiCloud Routers, Urges Immediate Firmware Update

146/68 Monday, April 21, 2025 ASUS has issued a security advisory regarding a critical vulnerability in its routers that have the AiCloud feature enabled, tracked as CVE-2025-2492 with a CVSS severity score of 9.2. The flaw stems from improper authentication control, potentially allowing unauthorized remote attackers to take control of the router’s functions. To mitigate […]

ThaiCERT

April 21, 2025

New Android Malware “SuperCard X” Steals Credit Card Data via NFC Relay Attacks

145/68 Monday, April 21, 2025 Cybersecurity firm Cleafy has uncovered a new threat dubbed “SuperCard X”, a Malware-as-a-Service (MaaS) tool targeting Android devices through NFC relay attacks. The malware is designed to steal credit card data and use it for fraudulent transactions at ATMs or point-of-sale (POS) terminals. The campaign has ties to Chinese-speaking threat […]

ThaiCERT

April 21, 2025
1 2 26