Monsta FTP Vulnerability Exposes Thousands of Servers

457/68 Tuesday, November 11, 2025 Cybersecurity firm watchTowr has disclosed a critical vulnerability in Monsta FTP, a widely used web-based file management application commonly deployed by organizations and web administrators. The vulnerability, tracked as CVE-2025-34299, is rated Critical and allows attackers to gain access to the system without authentication (pre-auth) and perform remote code execution […]

ThaiCERT

November 11, 2025

QNAP Releases Patches for Seven Zero-Day Vulnerabilities Exploited During Pwn2Own 2025

456/68 Tuesday, November 11, 2025 QNAP, the Taiwan-based network-attached storage (NAS) manufacturer, has issued a major security update to fix seven zero-day vulnerabilities affecting multiple core software components. These vulnerabilities are significant because they were discovered and successfully exploited during the Pwn2Own Ireland 2025 global hacking competition – demonstrating that attackers could compromise affected systems […]

ThaiCERT

November 11, 2025

Warning to VSCode Users: Malicious Extensions Containing “GlassWorm” Malware Steal GitHub Accounts and Crypto Wallets

455/68 Monday, November 10, 2025 Security researchers have revealed that the GlassWorm malware campaign has resurfaced on the OpenVSX platform after being detected last month. This time, the malware is embedded in three Visual Studio Code (VSCode) extensions: These extensions have accumulated over 10,000 downloads. GlassWorm uses transactions on the Solana blockchain to retrieve payloads […]

ThaiCERT

November 10, 2025

Cisco Fixes UCCX Vulnerability Allowing Remote Attackers to Execute Root-Level Commands Without Authentication

454/68 Monday, November 10, 2025 Cisco has released a security update addressing a critical vulnerability in Unified Contact Center Express (UCCX), tracked as CVE-2025-20354, with a CVSS score of 9.8. The flaw stems from improper authentication within the Java Remote Method Invocation (RMI) process, allowing remote attackers to upload malicious files and execute commands on […]

ThaiCERT

November 10, 2025

“Landfall” Spyware Targets Samsung Users via Zero-Day Vulnerability

453/68 Monday, November 10, 2025 A new report from Palo Alto Networks’ Unit 42 reveals the discovery of a new spyware strain called “Landfall,” designed specifically to target Samsung Galaxy devices. The malware is capable of fully compromising infected devices for surveillance, including recording phone calls, tracking device location, silently taking photos, and stealing contacts […]

ThaiCERT

November 10, 2025

Google Warns: New Malware Uses AI to Modify Itself at Runtime to Evade Detection

452/68 Friday, November 7, 2025 Researchers at Google Threat Intelligence Group (GTIG) have warned of an emerging trend in malware that leverages artificial intelligence (AI) at runtime to change its behavior in real time and harvest data from target systems. These capabilities are being used to evade security detections and continuously adapt malware behavior — […]

ThaiCERT

November 7, 2025

CISA Adds Gladinet CentreStack and CWP Control Web Panel Vulnerabilities to Known Exploited Vulnerabilities (KEV) Catalog

451/68 Friday, November 7, 2025 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities affecting Gladinet CentreStack / Triofox and CWP Control Web Panel to its Known Exploited Vulnerabilities (KEV) catalog. CentreStack and Triofox are enterprise solutions for Enterprise File Sharing and hybrid cloud storage, enabling secure access to file servers and SMB/NFS […]

ThaiCERT

November 7, 2025

Gootloader Malware Resurfaces, Using Fake Document Websites and New Evasion Techniques to Bypass Detection

450/68 Friday, November 7, 2025 After seven months of inactivity, the Gootloader malware operation has returned, continuing to use SEO poisoning to manipulate search engine results and promote fake websites that lure users into downloading documents. These sites typically impersonate platforms offering free legal templates or contract forms. When victims search for such documents and […]

ThaiCERT

November 7, 2025

Vulnerabilities in Microsoft Teams Allow Attackers to Impersonate Colleagues and Modify Messages Without Detection

449/68 Thursday, November 6, 2025 Cybersecurity researchers have disclosed four vulnerabilities in Microsoft Teams that could allow attackers to impersonate coworkers, edit messages without being detected, and trick victims into believing that messages come from executives or trusted individuals. The issues were reported to Microsoft in March 2024, with partial fixes released in August 2024 […]

ThaiCERT

November 6, 2025

Google Releases Security Update to Patch Android Vulnerabilities That Could Allow Remote Code Execution

448/68 Thursday, November 6, 2025 Google has released the November 2025 Android security update, addressing two significant vulnerabilities in the System component. One of the flaws is classified as critical, as it could enable Remote Code Execution (RCE) without requiring additional privileges or user interaction. These fixes are included in the Android security patch level […]

ThaiCERT

November 6, 2025
1 2 3 57