SAP Patches Critical Vulnerability in SQL Anywhere Monitor

463/68 Thursday, November 13, 2025 SAP has released its November 2025 security updates, addressing a total of 19 vulnerabilities — including one Critical flaw (CVSS 10.0), tracked as CVE-2025-42890, affecting SQL Anywhere Monitor (Non-GUI). The vulnerability stems from insecure key and secret management due to hardcoded credentials embedded directly in the code. This flaw allows […]

ThaiCERT

November 13, 2025

“Fantasy Hub” – A New Android Malware Targeting Banking Apps and Stealing Personal Data

462/68 Thursday, November 13, 2025 Cybersecurity researchers from Zimperium have uncovered a new Android malware called Fantasy Hub, a Remote Access Trojan (RAT) currently being sold openly on Russian-language Telegram channels under a Malware-as-a-Service (MaaS) model. The malware is designed for data theft and full device control, capable of collecting sensitive information such as SMS […]

ThaiCERT

November 13, 2025

Hackers Use Google Find Hub to Wipe Android Devices Remotely

461/68 Wednesday, November 12, 2025 Security researchers have discovered an advanced threat actor (APT) abusing the Google Find Hub (Android’s Find My Device) service to locate victims via GPS and remotely trigger factory resets to erase devices, thereby covering their tracks. After wiping devices, attackers sever victims’ accounts from services-especially messaging apps-and then use the […]

ThaiCERT

November 12, 2025

Hackers Exploit Triofox Vulnerability to Deploy Remote Access Tools via Antivirus Feature

460/68 Wednesday, November 12, 2025 Cybersecurity firm Mandiant (Google) has identified active exploitation of an n-day vulnerability in Gladinet Triofox, a secure enterprise file-sharing and remote access platform, shortly after a patch was released. The critical flaw, tracked as CVE-2025-12480 with a CVSS score of 9.1, allows attackers to bypass authentication and gain access to […]

ThaiCERT

November 12, 2025

OWASP Top 10 2025 Highlights Supply Chain Risks and Misconfiguration of Systems

459/68 Wednesday, November 12, 2025 OWASP (Open Web Application Security Project) has announced the 2025 edition of the Top 10 Web Application Security Risks, marking a significant update since the 2021 release. The changes reflect a major shift in the threat landscape: the new list emphasizes risks arising from software supply chains and system design/configuration […]

ThaiCERT

November 12, 2025

Phishing Campaign via SMS and iMessage Masquerades as “Find My iPhone” to Steal Apple IDs

458/68 Tuesday, November 11, 2025 The National Cyber Security Centre of Switzerland (NCSC) has issued a warning to iPhone users about a new phishing scam that pretends to notify victims that their lost device has been found. Attackers send SMS or iMessage texts using contact information that the owner previously entered into the Find My […]

ThaiCERT

November 11, 2025

Monsta FTP Vulnerability Exposes Thousands of Servers

457/68 Tuesday, November 11, 2025 Cybersecurity firm watchTowr has disclosed a critical vulnerability in Monsta FTP, a widely used web-based file management application commonly deployed by organizations and web administrators. The vulnerability, tracked as CVE-2025-34299, is rated Critical and allows attackers to gain access to the system without authentication (pre-auth) and perform remote code execution […]

ThaiCERT

November 11, 2025

QNAP Releases Patches for Seven Zero-Day Vulnerabilities Exploited During Pwn2Own 2025

456/68 Tuesday, November 11, 2025 QNAP, the Taiwan-based network-attached storage (NAS) manufacturer, has issued a major security update to fix seven zero-day vulnerabilities affecting multiple core software components. These vulnerabilities are significant because they were discovered and successfully exploited during the Pwn2Own Ireland 2025 global hacking competition – demonstrating that attackers could compromise affected systems […]

ThaiCERT

November 11, 2025

Warning to VSCode Users: Malicious Extensions Containing “GlassWorm” Malware Steal GitHub Accounts and Crypto Wallets

455/68 Monday, November 10, 2025 Security researchers have revealed that the GlassWorm malware campaign has resurfaced on the OpenVSX platform after being detected last month. This time, the malware is embedded in three Visual Studio Code (VSCode) extensions: These extensions have accumulated over 10,000 downloads. GlassWorm uses transactions on the Solana blockchain to retrieve payloads […]

ThaiCERT

November 10, 2025

Cisco Fixes UCCX Vulnerability Allowing Remote Attackers to Execute Root-Level Commands Without Authentication

454/68 Monday, November 10, 2025 Cisco has released a security update addressing a critical vulnerability in Unified Contact Center Express (UCCX), tracked as CVE-2025-20354, with a CVSS score of 9.8. The flaw stems from improper authentication within the Java Remote Method Invocation (RMI) process, allowing remote attackers to upload malicious files and execute commands on […]

ThaiCERT

November 10, 2025
1 2 3 57