All-in-One WP Migration and Backup Vulnerability Could Allow Code Execution on WordPress Websites

486/69 Friday, September 4, 2026 Reports have disclosed a vulnerability in the All-in-One WP Migration and Backup plugin for WordPress, tracked as CVE-2026-19949, with a CVSS score of 8.8. The flaw is a Second-Order SQL Injection vulnerability affecting version 7.109 and earlier. The plugin is used on more than 5 million websites, and reports indicate […]

ThaiCERT

September 4, 2026

SonicWall Patches Two Zero-Day Vulnerabilities in SMA 1000 VPN After Active Exploitation Confirmed

485/69 Friday, September 4, 2026 SonicWall has released security updates to address two zero-day vulnerabilities in SMA 1000 VPN appliances after confirming that the flaws have been exploited in attacks. The first vulnerability, CVE-2026-83548, has a CVSS score of 10.0 and is a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the Appliance WorkPlace interface. It […]

ThaiCERT

September 4, 2026

Preparing for Impact: OpenAI Confirms Astra AI Model Can Automatically Find Zero-Day Vulnerabilities and Generate Exploit Code

484/69 Friday, September 4, 2026 OpenAI has classified its new artificial intelligence (AI) model, Astra, at the highest cybersecurity risk level, Critical, under its Preparedness Framework. This marks the first model from the organization to reach this level. The assessment indicates that the system is capable of finding zero-day vulnerabilities and systematically developing exploit code […]

ThaiCERT

September 4, 2026

WatchGuard Patches Five Critical Vulnerabilities in Fireware OS and Dimension That Could Lead to Code Execution and Administrator Account Takeover

483/69 Thursday, September 3, 2026 WatchGuard has released patches to address more than 20 vulnerabilities in Fireware OS and WatchGuard Dimension, including five Critical vulnerabilities that could lead to remote code execution (RCE) or administrator account takeover. The five Critical vulnerabilities have CVSS scores of 9.3 and have been fixed in Fireware OS versions 2026.2.2, […]

ThaiCERT

September 3, 2026

Aesto Health Reports Data Breach Affecting Health Information of More Than 9.5 Million People After AWS Infrastructure Accessed

482/69 Thursday, September 3, 2026 Aesto Health, a U.S.-based healthcare technology company, disclosed a data breach affecting the personal and health information of more than 9.5 million people after attackers gained access to parts of the company’s infrastructure on Amazon Web Services (AWS). Aesto Health provides services for managing and protecting Electronic Health Records (EHRs) […]

ThaiCERT

September 3, 2026

Phishing Campaign Impersonates Adobe to Trick Users into Installing Faronics Deploy for System Takeover

481/69 Thursday, September 3, 2026 Cybersecurity researchers from Huntress detected a phishing campaign impersonating business documents, invoices, or tax documents to target users in organizations. More than 457 computers were targeted between July 21 and August 20. The threat actors abused Faronics Deploy, a legitimate cloud-based endpoint management platform, as the main channel to take […]

ThaiCERT

September 3, 2026

Fire Ant Uses Cisco IOS XR Routers to Capture Traffic and Hide Attack Activity

480/69 Wednesday, September 2, 2026 Security researchers have disclosed attacks by the Fire Ant group targeting infrastructure used by organizations to connect and manage networks, including Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. The attackers used these systems to maintain access, capture network traffic and credentials, and pivot to other connected […]

ThaiCERT

September 2, 2026

Hackers Steal Identity and Vehicle Registration Data from Latvia’s Road Traffic Safety Authority

479/69 Wednesday, September 2, 2026 Latvia’s Road Traffic Safety Directorate (CSDD) disclosed a data breach after attackers gained access to the agency’s systems and stole data belonging to approximately 1.2 million individuals and around 200,000 legal entities. The number of affected individuals represents roughly two-thirds of Latvia’s population. CERT.LV stated that the attackers obtained the […]

ThaiCERT

September 2, 2026

ValleyRAT Malware Hidden in Adware to Compromise Systems and Steal User Data

478/69 Wednesday, September 2, 2026 Researchers from Kaspersky have discovered a new cyberattack campaign in which the dangerous ValleyRAT malware is bundled with adware to evade detection. Initial findings indicate that the Silver Fox threat group is behind the campaign, with the objective of stealing sensitive information and gaining control of victims’ systems. The attack […]

ThaiCERT

September 2, 2026

Anthropic Warns Infostealer Malware Is Stealing Claude Sessions, Risking Unauthorized Account Access

477/69 Tuesday, September 1, 2026 Anthropic has warned Claude users after finding cases where infostealer malware on users’ computers stole login sessions and used those sessions to access Claude accounts and consume account usage quotas without authorization. The incident was not caused by malware directly related to Claude or installed through the Claude service. Instead, […]

ThaiCERT

September 1, 2026
1 2 83