DragonForce Exploits SimpleHelp Vulnerabilities to Launch Supply Chain Attacks on MSPs

196/68 Thursday, May 29, 2025 The ransomware group DragonForce has been identified as the actor behind a series of supply chain attacks targeting Managed Service Providers (MSPs). The attackers exploited vulnerabilities in SimpleHelp, a widely used Remote Monitoring and Management (RMM) platform, to breach MSP networks, conduct reconnaissance on client environments, exfiltrate sensitive data, and […]

ThaiCERT

May 29, 2025

Fake AI Ads on Facebook Spread Malware to Steal Personal Data, Researchers Warn

195/68 Thursday, May 29, 2025 Cybersecurity researchers have issued a warning about a large-scale malware campaign spreading across social media platforms, particularly Facebook and LinkedIn. A threat actor known as UNC6032 is exploiting growing public interest in artificial intelligence by distributing fake advertisements promoting AI-powered video generation tools. These ads claim to offer text-to-video AI […]

ThaiCERT

May 29, 2025

Fake TikTok Videos Lure Users into Installing Vidar and StealC Malware

193/68 Wednesday, May 28, 2025 Cybersecurity experts at Trend Micro have uncovered a malicious campaign where cybercriminals are leveraging AI-generated TikTok videos to trick users into executing PowerShell commands that install dangerous malware such as Vidar and StealC. The videos claim to show users how to activate popular software like Windows, Microsoft Office, CapCut, or […]

ThaiCERT

May 28, 2025

Operation ENDGAME Dismantles Global Ransomware Infrastructure

192/68 Tuesday, May 27, 2025 Between May 19–22, 2025, law enforcement agencies from multiple countries carried out Operation ENDGAME, a large-scale coordinated cybercrime takedown led by Europol and Eurojust, aimed at dismantling the global infrastructure used to distribute ransomware. The operation resulted in the seizure of over 300 servers, the shutdown of more than 650 […]

ThaiCERT

May 27, 2025

Hackers Increasingly Abuse Legitimate Remote Access Tools Like ConnectWise in 2025

191/68 Tuesday, May 27, 2025 A May 2025 report by Cofense Intelligence highlights a troubling cybersecurity trend: cybercriminals are increasingly abusing legitimate remote access tools (RATs) such as ConnectWise and Splashtop to infiltrate computer systems. Originally designed for IT professionals, these trusted tools have become double-edged swords — their legitimacy and familiarity allow them to […]

ThaiCERT

May 27, 2025

“Operation RapTor” Leads to Arrest of Over 270 Dark Web Traffickers Across 10 Countries

190/68 Monday, May 26, 2025 Europol, in cooperation with law enforcement agencies from 10 countries, has successfully carried out Operation RapTor, resulting in the arrest of 270 suspects involved in the illegal trade of drugs, weapons, and counterfeit goods on the Dark Web. The suspects were linked to marketplaces such as Nemesis, Bohemia, Kingdom Markets, […]

ThaiCERT

May 26, 2025

Hackers Distribute Winos 4.0 Malware via Fake VPN and Browser Installers

189/68 Monday, May 26, 2025 Cybersecurity researchers have uncovered a new malware campaign where hackers are distributing fake software installers disguised as popular tools such as LetsVPN and QQ Browser to deploy a malicious malware framework known as Winos 4.0. The campaign was first observed by Rapid7 in February 2025 and uses a multi-stage memory-resident […]

ThaiCERT

May 26, 2025

Critical Vulnerability in OpenPGP.js Allows Digital Signature Spoofing in Encrypted Messages

188/68 Friday, May 23, 2025 Security researchers from Codean Labs have disclosed a critical vulnerability in the OpenPGP.js JavaScript library (CVE-2025-47934), an open-source implementation used for encryption and digital signing. The flaw affects versions 5.0.1 to 5.11.2 and 6.0.0 to 6.1.0, and allows attackers to spoof digital signatures in inline-signed or signed+encrypted messages. Detached signatures […]

ThaiCERT

May 23, 2025
1 2 3 31