TP-Link Releases Patch for CVE-2026-0629, Putting Over 32 VIGI Camera Models at Risk via Password Recovery Flaw

39/69 Wednesday, January 21, 2026 TP-Link has released a security update to address a high-severity vulnerability, tracked as CVE-2026-0629, affecting more than 32 models of VIGI C and VIGI InSight surveillance cameras. The flaw is an authentication bypass vulnerability related to the password recovery function in the device’s web-based management interface, which is widely used […]

ThaiCERT

January 21, 2026

Ransomware Attack on Ingram Micro Exposes Personal Data of More Than 42,000 Individuals

38/69 Wednesday, January 21, 2026 Ingram Micro, a global technology distributor and supply chain services provider, disclosed that it detected a ransomware-related cyberattack on July 3, 2025. The investigation revealed that unauthorized actors accessed and exfiltrated files from the company’s internal systems between July 2 and July 3, 2025. As a result of the incident, […]

ThaiCERT

January 21, 2026

Researchers Discover New “PDFSider” Malware Used to Breach Major Enterprises with Advanced Techniques

37/69 Wednesday, January 21, 2026 Cybersecurity researchers from Resecurity have identified a new malware strain named PDFSider while investigating a security incident at a Fortune 100 financial company. The malware has reportedly been used by multiple threat actors-including the Qilin ransomware group-to gain initial access and maintain long-term persistence within compromised environments. The attack chain […]

ThaiCERT

January 21, 2026

Microsoft Releases Out-of-Band Updates to Fix Remote Desktop Connection and Shutdown Issues

36/69 Tuesday, January 20, 2026 Microsoft has released out-of-band (OOB) updates for Windows 10, Windows 11, and Windows Server to address two critical issues introduced by the January 2026 security updates. The first issue affects Microsoft 365 Cloud PC, Remote Desktop services, and Azure Virtual Desktop, where some users experience credential prompt failures, preventing them […]

ThaiCERT

January 20, 2026

Mustang Panda Uses Venezuela-Related News as Lure to Spread LOTUSLITE Malware

35/69 Tuesday, January 20, 2026 Researchers from the Acronis Threat Research Unit (TRU) have disclosed the discovery of a new cyber-espionage operation that exploits political developments in Venezuela as a lure to trick U.S. government personnel into opening malicious files. The campaign does not rely on advanced exploitation techniques or complex vulnerabilities; instead, it primarily […]

ThaiCERT

January 20, 2026

Hacktivist Group Hijacks Iranian State TV Signal to Broadcast Protest Footage

34/69 Tuesday, January 20, 2026 On January 18, 2026, a major cyber incident occurred in Iran when a group of hacktivists successfully breached and took control of the Badr satellite signal, resulting in the disruption of several Iranian state television channels. The signal hijacking took place at approximately 9:30 p.m. local time and lasted for […]

ThaiCERT

January 20, 2026

Malicious Chrome Extensions Steal Session Cookies and Take Over Enterprise HR/ERP Accounts

33/69 Monday, January 19, 2026 Cybersecurity firm Socket has identified and warned about five malicious Google Chrome extensions with a combined total of more than 2,300 installations. These extensions masqueraded as productivity and security tools for popular enterprise HR and ERP platforms such as Workday, NetSuite, and SAP SuccessFactors, with the goal of stealing authentication […]

ThaiCERT

January 19, 2026

Privilege Escalation Vulnerability Discovered in Google Vertex AI Allows Low-Privilege Users to Become Service Agents

32/69 Monday, January 19, 2026 Cybersecurity researchers have disclosed a high-severity privilege escalation vulnerability in Google’s Vertex AI platform that could allow low-privileged users to escalate their access and take control of Service Agent accounts, which are system-managed identities with elevated permissions. The vulnerability affects Vertex AI Agent Engine and Ray on Vertex AI and […]

ThaiCERT

January 19, 2026

17 Malicious Browser Extensions Discovered, Over 840,000 Installations Linked to Data-Stealing Malware

31/69 Monday, January 19, 2026 A recent report by cybersecurity researchers LayerX and Koi Security has uncovered 17 malicious browser extensions on the Google Chrome Web Store, Firefox Add-ons, and Microsoft Edge Add-ons, with a combined total of more than 840,000 installations. These extensions are part of a malware operation dubbed “GhostPoster,” disguising itself as […]

ThaiCERT

January 19, 2026

Over 91,000 AI Attack Attempts Detected, Targeting Ollama and OpenAI-Related Systems

30/69 Friday, January 16, 2026 Researchers from GreyNoise have revealed the detection of a large-scale wave of cyberattack attempts targeting artificial intelligence (AI) systems, particularly Ollama and infrastructures connected to OpenAI, between October 2025 and January 2026. Honeypots simulating AI servers recorded a total of 91,403 attack sessions. Analysts assess that the primary objective of […]

ThaiCERT

January 16, 2026
1 2 70