Chrome Releases Patch for Multiple Critical Memory Safety Vulnerabilities

399/69 Tuesday, July 21, 2026 Google has released a security update for Chrome to fix seven memory safety vulnerabilities. These include three Critical-severity Use-after-free vulnerabilities in the CameraCapture, GPU, and Network components, as well as three High-severity vulnerabilities in the Cast, Ozone, and Aura components. Google has not stated that any of the vulnerabilities in […]

ThaiCERT

July 21, 2026

ServiceNow Warns of Severe RCE Vulnerability in AI Platform Now Exploited in Attacks

398/69 Tuesday, July 21, 2026 Reports indicate that attackers have begun exploiting CVE-2026-6875 in the ServiceNow AI Platform, according to threat intelligence firm Defused. ServiceNow AI Platform, formerly known as the Now Platform, is an enterprise Platform-as-a-Service (PaaS) solution that helps organizations integrate AI into core business workflows. The vulnerability was discovered and reported by […]

ThaiCERT

July 21, 2026

Hugging Face, Major Open-Source AI Platform, Hacked by Automated AI Agent

397/69 Tuesday, July 21, 2026 Hugging Face, a major open-source AI platform, has disclosed that it was targeted in a cyberattack carried out by an automated AI agent, an incident that highlights a significant irony within the technology industry. The company stated that it detected and responded to a threat targeting its production infrastructure last […]

ThaiCERT

July 21, 2026

Microsoft Warns of Surge in ACR Stealer Attacks Targeting Passwords and Sensitive Data

396/69 Monday, July 20, 2026 Microsoft has observed a surge in attacks involving ACR Stealer, a malware strain designed to steal passwords, cookies, session data, authentication tokens, and important documents stored on users’ devices. Microsoft detected the campaign from late April to mid-June 2026 and believes that ACR Stealer is a Malware-as-a-Service (MaaS) offering linked […]

ThaiCERT

July 20, 2026

Ernst & Young Discloses Data Breach After Support Ticket System Hack

395/69 Monday, July 20, 2026 Ernst & Young (EY) has disclosed a data breach after a third-party support ticket system used by the company’s IT personnel was accessed without authorization. Tickets submitted through the system may have contained documents that included clients’ tax information. EY is one of the world’s largest accounting firms, providing audit, […]

ThaiCERT

July 20, 2026

UAC-0145 Hackers Use ClickFix Technique and Fake Applications to Target Users in Ukraine

394/69 Monday, July 20, 2026 The Computer Emergency Response Team of Ukraine (CERT-UA) has detected a cyberattack operation by the threat group UAC-0145, a subgroup within the Sandworm network linked to Russian intelligence services. In this campaign, the hackers shifted their tactics from using fake installers to deceiving users through the ClickFix technique on compromised […]

ThaiCERT

July 20, 2026

Microsoft Releases July 2026 Patch Tuesday Updates to Fix 622 Vulnerabilities, Including Two Actively Exploited Zero-Days

393/69 Friday, July 17, 2026 Microsoft has released its July 2026 Patch Tuesday updates to fix 622 vulnerabilities across multiple products, including Windows, Microsoft Office, SharePoint Server, SQL Server, Azure, and developer tools. Microsoft stated that the increase in the number of vulnerabilities is partly due to the use of artificial intelligence systems to help […]

ThaiCERT

July 17, 2026

F5 Releases Patches for Multiple NGINX and BIG-IP Vulnerabilities That Could Lead to DoS and Code Execution

392/69 Friday, July 17, 2026 F5 has released an out-of-band security update to address eight vulnerabilities in its NGINX and BIG-IP products. The most severe vulnerability is CVE-2026-42533, which has a CVSS score of 9.2 and is rated Critical. It affects NGINX Plus and NGINX Open Source. Attackers could send specially crafted HTTP requests to […]

ThaiCERT

July 17, 2026

Zoom Warns of Vulnerability That Could Lead to Account Takeover on Windows

391/69 Friday, July 17, 2026 Zoom has issued an advisory for a Critical security vulnerability discovered internally, affecting its applications on Windows as well as software development kits (SDKs). The vulnerability, tracked as CVE-2026-53412, has been rated 9.8 out of 10 in severity. It could allow attackers to exploit the issue over the network and […]

ThaiCERT

July 17, 2026

Progress Confirms ShareFile Zero-Day Vulnerability and Releases Security Patch

390/69 Thursday, July 16, 2026 Progress Software has confirmed that its earlier shutdown of ShareFile Storage Zone Controller was related to a High-severity zero-day vulnerability in the product and has released a security update to address the flaw. Storage Zone Controller is a customer-managed Windows server that allows organizations to store files within their internal […]

ThaiCERT

July 16, 2026
1 2 75