CISA Urges Administrators to Patch Actively Exploited SharePoint Server Vulnerabilities

389/69 Thursday, July 16, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory last Tuesday after finding that attackers are exploiting three vulnerabilities in internet-exposed Microsoft SharePoint Server instances: CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164. These vulnerabilities affect all supported on-premises versions of SharePoint Server, including SharePoint Server Subscription Edition, the latest on-premises version […]

ThaiCERT

July 16, 2026

SonicWall Warns of Zero-Day Vulnerabilities in SMA1000 Appliances, Urging Administrators to Apply Security Patches

388/69 Thursday, July 16, 2026 SonicWall has issued an advisory after threat actors were observed exploiting two zero-day vulnerabilities in SonicWall SMA1000 appliances. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog and ordered federal agencies under its scope to address affected systems by July […]

ThaiCERT

July 16, 2026

Supply Chain Attack Found Hiding Infostealer Malware in Jscrambler npm Package

387/69 Wednesday, July 15, 2026 Security researchers have disclosed a supply chain attack affecting the official jscrambler package on npm. Attackers published modified versions of the package containing a Rust-based infostealer, putting developer machines and CI/CD systems that installed the affected package at risk of sensitive data theft. Jscrambler stated that the issue affects package […]

ThaiCERT

July 15, 2026

Lidl Discloses Online Shop Customer Data Breach After Service Provider Attack

386/69 Wednesday, July 15, 2026 Lidl, a German discount supermarket chain under the Schwarz Group, has notified online shop customers in Germany, Belgium, and the Netherlands after attackers stole personal data in a data breach affecting an external IT service provider. Lidl is part of the Schwarz Group, Europe’s largest food retailer, with more than […]

ThaiCERT

July 15, 2026

Google and Microsoft Remove ModHeader Extension After Hidden Code Found Collecting Browsing History Data

385/69 Wednesday, July 15, 2026 Google and Microsoft have removed the ModHeader extension, which had more than 1.6 million combined installations on Chrome and Edge, from their official stores. The action came after cybersecurity firm Stripe OLT discovered hidden code designed to collect website browsing history data embedded in the official version of the extension. […]

ThaiCERT

July 15, 2026

Docker Users Urged to Update Immediately: DockerDash Vulnerability in AI Assistant “Ask Gordon” Risks Code Execution via Image Metadata

72/69 Thursday, February 5, 2026 Cybersecurity researchers from Noma Labs have disclosed a critical vulnerability named DockerDash affecting Ask Gordon, the AI assistant integrated into Docker Desktop and Docker CLI. The flaw allows attackers to perform Remote Code Execution (RCE) and secretly exfiltrate sensitive data by exploiting how the assistant reads and processes metadata attached […]

ThaiCERT

February 5, 2026

React Native Vulnerability Actively Exploited in the Wild

71/69 Thursday, February 5, 2026 Researchers from vulnerability intelligence firm VulnCheck have revealed that a critical vulnerability in the React Native platform has been actively exploited since late December. The flaw, tracked as CVE-2025-11953, carries a CVSS score of 9.8 (Critical) and affects the widely used @react-native-community/cli package, a key tool for developing React Native […]

ThaiCERT

February 5, 2026

Critical Zero-Day Vulnerabilities in Ivanti EPMM Actively Exploited – Immediate Patching Urged

70/69 Thursday, February 5, 2026 Cybersecurity experts have issued a warning after discovering two newly identified critical vulnerabilities (CVE-2026-1281 and CVE-2026-1340) in Ivanti Endpoint Manager Mobile (EPMM), a platform widely used by large organizations to manage employee mobile devices. These flaws carry a severity score of 9.8 out of 10, as they allow attackers to […]

ThaiCERT

February 5, 2026

Researchers Discover Over 200 Malicious Skills on OpenClaw Distributing Password-Stealing Malware

69/69 Wednesday, February 4, 2026 Security researchers have identified a large number of malicious add-on packages, or “Skills,” targeting OpenClaw-an open-source personal AI assistant formerly known as Moltbot and ClawdBot. These threats were discovered on the official registry (ClawHub) and GitHub between January 27 and February 1. More than 230 harmful Skills were found impersonating […]

ThaiCERT

February 4, 2026

Panera Bread Data Breach Impacts 5.1 Million Accounts, Confirmed by HIBP

68/69 Wednesday, February 4, 2026 Have I Been Pwned (HIBP) has confirmed that the Panera Bread data breach affected approximately 5.1 million user accounts, a figure significantly lower than the 14 million accounts previously claimed by the cybercriminal group ShinyHunters. The group alleged that it had gained access to Panera Bread’s systems and stolen a […]

ThaiCERT

February 4, 2026
1 2 3 75