CareCloud Discloses Data Breach Affecting 345,000 People After AWS-Hosted System Attack

419/69 Tuesday, August 4, 2026 CareCloud, a healthcare technology company based in New Jersey, United States, has disclosed a data breach affecting approximately 345,000 people after attackers stole medical and financial data from systems hosted by the company on Amazon Web Services (AWS). CareCloud provides Electronic Health Records (EHR), practice management systems, revenue cycle management, […]

ThaiCERT

August 4, 2026

CrowdStrike Says AI Has Become Both a Weapon and a Target in Modern Cyberattacks

418/69 Tuesday, August 4, 2026 CrowdStrike has released its annual threat report, stating that artificial intelligence (AI) has shifted from being a tool for cyber defense to becoming both a weapon and a target for attackers. AI-driven activity now clearly exceeds human-generated activity. On average, for every one human-generated signal, there are 2.5 AI-generated signals. […]

ThaiCERT

August 4, 2026

Ruby on Rails Releases Patch for Critical Active Storage Vulnerability That Could Allow File Reading and Code Execution on Servers

417/69 Monday, August 3, 2026 Ruby on Rails has released a security update to fix a Critical vulnerability in Active Storage, tracked as CVE-2026-66066, with a CVSS score of 9.5. The vulnerability could allow unauthenticated attackers to read files on affected servers and may lead to remote code execution or lateral movement if attackers can […]

ThaiCERT

August 3, 2026

Coldcard Hardware Wallet Vulnerability Linked to Bitcoin Theft Worth More Than USD 70 Million

416/69 Monday, August 3, 2026 Reports on July 30 indicated that attackers transferred Bitcoin from 1,196 addresses within 41 minutes, totaling 1,082.65 BTC, or approximately USD 70.2 million at the time of the incident. Galaxy Research analyzed the transfer pattern and linked the incident to a vulnerability in the firmware of Coldcard, a Bitcoin-only hardware […]

ThaiCERT

August 3, 2026

Cyberattacks Target Government Agencies in Central Asia Using New OctLurk and SilkLurk Malware

415/69 Monday, August 3, 2026 Since January 2025, reports have identified a new wave of cyberattacks carried out by an advanced threat group, primarily targeting government organizations in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria. The affected entities span several nationally important sectors, including public health, research, foreign affairs ministries, law enforcement […]

ThaiCERT

August 3, 2026

Cisco Warns of Static Credential Vulnerability in Secure Firewall Management Center Actively Exploited in Attacks

414/69 Friday, July 31, 2026 Cisco has issued an advisory for CVE-2026-20316 in Cisco Secure Firewall Management Center (FMC) after discovering that the vulnerability has been exploited in zero-day attacks. The vulnerability is caused by the presence of static credentials within the system, which could allow attackers to use those credentials to gain unauthorized access […]

ThaiCERT

July 31, 2026

OpenAI Discloses Additional Details on AI Model Test Escape, Finding Use of Vulnerabilities to Access External Services

412/69 Friday, July 31, 2026 OpenAI has disclosed additional information regarding an incident in which an artificial intelligence (AI) model escaped control during cybersecurity safety testing. The company found that more external organizations and services were affected than initially reported. The incident occurred after AI models such as GPT-5.6 Sol and an unreleased experimental model […]

ThaiCERT

July 31, 2026

Attack via Hotel Wi-Fi Targets Microsoft 365 Account Credentials

411/69 Monday, July 27, 2026 Security researchers have disclosed an attack campaign targeting Wi-Fi systems at hotels, conference centers, and other venues providing public network access. The attackers take control of or modify Wi-Fi gateway settings to redirect users to fake Microsoft 365 login pages and steal account credentials from corporate employees connected through those […]

ThaiCERT

July 27, 2026

Data Leaked by ShinyHunters Used in Sextortion Email Scam Demanding USD 2,000 in Bitcoin

410/69 Monday, July 27, 2026 Reports indicate that threat actors are using email addresses previously exposed in data breaches and published by the extortion group ShinyHunters to send sextortion scam emails demanding USD 2,000 in Bitcoin. The emails claim to be from ShinyHunters and state that the attackers have accessed the recipient’s device after obtaining […]

ThaiCERT

July 27, 2026

SourTrade Campaign Uses Malvertising to Trick Browsers into Assembling Malicious Files

409/69 Monday, July 27, 2026 Security researchers from Confiant have released a report on a malvertising campaign called SourTrade, which primarily targets retail investors and cryptocurrency users in multiple countries. The campaign was initially reported to have been active since late 2024 and uses fake websites that impersonate well-known investment platforms such as TradingView, Solana, […]

ThaiCERT

July 27, 2026
1 2 3 77