Half of Mobile Devices Still Run Outdated Operating Systems, Study Finds

159/68 Wednesday, April 30, 2025 A new study reveals that over half of mobile devices worldwide continue to run outdated operating systems, posing a significant cybersecurity risk. The 2025 Global Mobile Threat Report by cybersecurity firm Zimperium highlights a growing trend in cyberattacks targeting mobile devices and vulnerabilities in mobile applications. The report warns that […]

ThaiCERT

April 30, 2025

Zero-Day Exploits Used in Craft CMS Attacks, Orange Cyberdefense Warns

158/68 Tuesday, April 29, 2025 The CSIRT team at Orange Cyberdefense has reported that attackers exploited two vulnerabilities—one of them a zero-day—in Craft CMS to compromise servers and steal data. The vulnerabilities, which were actively exploited in the wild, were discovered during an incident response investigation involving a compromised client server. The two flaws include: […]

ThaiCERT

April 29, 2025

WooCommerce Plugin Users Targeted by Phishing Campaign Impersonating Fake Security Vulnerability

157/68 Tuesday, April 29, 2025 Cybersecurity researchers have issued a warning about a large-scale phishing campaign targeting WooCommerce plugin users by exploiting fake security alerts. The attackers are tricking website administrators into downloading a “critical patch” that instead installs a backdoor granting the attacker covert control over the site. Patchstack, a cybersecurity firm specializing in […]

ThaiCERT

April 29, 2025

MTN Group Confirms Data Breach Affecting Customers’ Personal Information

156/68 Monday, April 28, 2025 MTN Group, the South African multinational telecommunications giant, has confirmed a data breach that resulted in unauthorized access to the personal information of some customers in certain countries. However, the company stated that its core network, billing systems, and financial services infrastructure were not affected and remain secure and fully […]

ThaiCERT

April 28, 2025

Asian Cybercrime Networks Expand Global Influence

155/68 Monday, April 28, 2025 A recent report by the United Nations Office on Drugs and Crime (UNODC) highlights the growing reach of transnational crime syndicates operating out of Southeast Asia, running large-scale online scam centers that have evolved into a massive “cybercrime industry.” These operations generate tens of billions of dollars annually through various […]

ThaiCERT

April 28, 2025

Blue Shield of California Exposes Health Data of 4.7 Million Members to Google

154/68 Friday, April 25, 2025 Blue Shield of California has disclosed a data breach in which Protected Health Information (PHI) of more than 4.7 million members was inadvertently exposed to Google’s analytics and advertising platforms. The breach was due to a misconfiguration of Google Analytics on certain sections of the organization’s website. The incident occurred […]

ThaiCERT

April 25, 2025

Google Ends Cookie Notifications in Chrome and Introduces IP Protection for Incognito Mode

153/68 Friday, April 25, 2025 Google has announced that it will no longer display separate notifications regarding the use of third-party cookies in its Chrome browser, as part of its ongoing Privacy Sandbox initiative. Anthony Chavez, Vice President of Google’s Privacy Sandbox, stated that users can still manage their cookie preferences via Chrome’s privacy and […]

ThaiCERT

April 25, 2025

Hackers Exploit Zoom Remote Control Feature to Steal Cryptocurrency from Victims

151/68 Thursday, April 24, 2025 A hacker group known as Elusive Comet has been exposed for using social engineering tactics, specifically exploiting the Remote Control feature in Zoom to trick victims into granting control of their computers. The group targets high-value cryptocurrency users, according to cybersecurity firm Trail of Bits, which noted that the group’s […]

ThaiCERT

April 24, 2025

Kimsuky Exploits BlueKeep Vulnerability to Target Systems in South Korea and Japan, Focusing on Software, Energy, and Financial Industries

150/68 Wednesday, April 23, 2025 Cybersecurity researchers from AhnLab Security Intelligence Center (ASEC) in South Korea have detected a new cyberattack campaign linked to Kimsuky, a North Korean threat actor. The group is exploiting the BlueKeep vulnerability (CVE-2019-0708) in Microsoft Remote Desktop Services (RDP) to breach systems in South Korea and Japan. This campaign, dubbed […]

ThaiCERT

April 23, 2025
1 19 20 21 45