RansomHouse Malware Upgrades Its New “Mario” Tool With Multi-Layer Encryption, Making Recovery More Difficult

539/68 Monday, December 22, 2025 RansomHouse, a ransomware group operating under a Ransomware-as-a-Service (RaaS) model, has been observed upgrading its file-encryption tool from a single-stage process to a more complex multi-layer encryption scheme. The new approach uses two encryption keys-a 32-byte primary key and an 8-byte secondary key-significantly increasing encryption complexity, reducing the chances of […]

ThaiCERT

December 22, 2025

ATM Jackpotting Network Dismantled: U.S. Department of Justice Charges 54 Individuals

538/68 Monday, December 22, 2025 The U.S. Department of Justice (DoJ) has announced criminal charges against 54 individuals involved in a nationwide ATM jackpotting scheme that caused millions of dollars in losses. Investigators have linked the operation to the transnational criminal organization Tren de Aragua (TdA). The defendants face multiple charges, including fraud, money laundering, […]

ThaiCERT

December 22, 2025

North Korea Amasses Over $2 Billion in Stolen Cryptocurrency as Fake IT Worker Scheme Exposed — Amazon Blocks More Than 1,800 Cases

537/68 Monday, December 22, 2025 A recent report from Chainalysis, a leading blockchain analytics firm, reveals alarming figures for 2025, stating that North Korean hackers have stolen at least USD 2 billion in cryptocurrency, marking a significant increase from 2024. A major contributor was the attack on the Bybit platform, which alone resulted in losses […]

ThaiCERT

December 22, 2025

SonicWall Warns of Actively Exploited Zero-Day Vulnerabilities in SMA1000, Urges Immediate Patching

536/68 Friday, December 19, 2025 SonicWall has issued a security advisory urging customers to immediately apply security patches for SMA1000 (Appliance Management Console) devices after Google Threat Intelligence reported active zero-day exploitation involving two vulnerabilities. The attack chain begins with a critical pre-authentication deserialization vulnerability, CVE-2025-23006, which allows remote compromise without authentication, followed by CVE-2025-40602, […]

ThaiCERT

December 19, 2025

Askul Confirms Data Breach Affecting Over 700,000 Records Following Ransomware Attack

535/68 Friday, December 19, 2025 Askul, a major Japanese e-commerce and logistics provider, has confirmed that it detected a ransomware attack on October 19, 2025, during which attackers gained access to the company’s infrastructure and exfiltrated sensitive data. The incident disrupted order processing, delivery services, and automated logistics systems, causing service outages before partial operations […]

ThaiCERT

December 19, 2025

New “Kimwolf” Botnet Enslaves Over 1.8 Million Android TVs, Launching Massive Global DDoS Attacks

534/68 Friday, December 19, 2025 Security researchers from QiAnXin XLab have identified a large-scale botnet named “Kimwolf”, which has compromised more than 1.8 million Android-based devices worldwide, including Android TV boxes, digital set-top boxes, and tablets. The infections are especially prevalent among low-cost consumer devices commonly used in households. What makes Kimwolf particularly alarming is […]

ThaiCERT

December 19, 2025

GhostPoster Malware Hides Malicious Code in Logos of 17 Firefox Extensions

533/68 Thursday, December 18, 2025 Cybersecurity researchers have uncovered a new malware campaign dubbed “GhostPoster”, which was distributed through 17 Firefox browser extensions with a combined total of more than 50,000 downloads. The malware uses steganography to conceal malicious JavaScript code inside the image files used as extension logos, allowing it to evade browser security […]

ThaiCERT

December 18, 2025

Cyberattack Disrupts Petróleos de Venezuela (PDVSA), Temporarily Affecting Export Operations

532/68 Thursday, December 18, 2025 Venezuela’s state-owned oil company, Petróleos de Venezuela (PDVSA), disclosed that it experienced a cyberattack last week that affected certain systems related to export operations. The company stated, however, that the incident was limited to administrative systems and did not impact core operations or oil production processes. PDVSA emphasized that, thanks […]

ThaiCERT

December 18, 2025

New Android Malware “Cellik” Found Hidden in Google Play Apps, Capable of Full-Spectrum Data Theft

531/68 Thursday, December 18, 2025 A newly discovered Android malware named “Cellik” has been identified operating as a Malware-as-a-Service (MaaS) offering on underground markets, with subscription prices starting at approximately $150 per month. According to cybersecurity firm iVerify, one of Cellik’s most concerning capabilities is its ability to take any legitimate application from the Google […]

ThaiCERT

December 18, 2025

Critical Vulnerability Found in JumpCloud Remote Assist on Windows, Allowing SYSTEM-Level Takeover

530/68 Wednesday, December 17, 2025 Security researchers have warned of a serious vulnerability in JumpCloud Remote Assist for Windows, tracked as CVE-2025-34352 with a CVSS score of 8.5. The flaw allows a low-privileged local user to escalate privileges to SYSTEM, enabling full compromise of the affected endpoint. The issue stems from insecure handling of temporary […]

ThaiCERT

December 17, 2025
1 9 10 11 73