Zimbra Vulnerability Actively Exploited, Risking Command Execution on Servers

456/69 Friday, August 21, 2026 CERT Polska has warned that CVE-2026-73570 in Zimbra Collaboration Suite (ZCS) is being exploited in attacks. The vulnerability was fixed in Zimbra version 10.1.20, released on July 20, 2026. The flaw is a command injection vulnerability in the SNMP Monitoring component and could allow unauthenticated attackers to execute commands on […]

ThaiCERT

August 21, 2026

Hackers Compromise More Than 14,500 Dahua Cameras in 35-Day CameraSwarm Campaign

455/69 Friday, August 21, 2026 Researchers from threat intelligence company Hunt.io have disclosed a large-scale attack campaign named CameraSwarm, in which hackers compromised more than 14,500 Dahua IP cameras, most of them located in Ukraine and Russia. The campaign operated for at least 35 days, from June 17 to July 22, 2026, using multiple attack […]

ThaiCERT

August 21, 2026

CareCloud Healthcare IT Data Breach Affects More Than 3.7 Million Patients

454/69 Friday, August 21, 2026 CareCloud, a U.S.-based healthcare information technology provider that manages electronic health record systems and medical data management services, has disclosed a data breach affecting more than 3.7 million patients. The incident is particularly significant because the company’s systems store personal information and may include sensitive health data. The exposure could […]

ThaiCERT

August 21, 2026

CISA Warns Windows Task Host Vulnerability Exploited by Ransomware Groups

453/69 Thursday, August 20, 2026 CISA disclosed that CVE-2025-60710, a vulnerability in Host Process for Windows Tasks, has been exploited in attacks by ransomware groups. CISA previously added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog in April 2026 after confirming evidence of active exploitation. The flaw is a Windows privilege escalation vulnerability, and […]

ThaiCERT

August 20, 2026

GitLab Releases Emergency Patch for Critical GraphQL Vulnerability Affecting Self-Managed Servers

452/69 Thursday, August 20, 2026 GitLab has released patches to fix a Critical vulnerability, CVE-2026-19478, with a CVSS score of 9.4. The vulnerability could allow unauthenticated attackers to modify or delete public projects and user data through GraphQL directives under certain conditions. The flaw affects only self-managed installations. GitLab recommends that administrators update to versions […]

ThaiCERT

August 20, 2026

Ransomware Scam Group Claims It Can Help Delete Stolen Data, but Turns Out to Be a Double-Extortion Scheme

451/69 Thursday, August 20, 2026 Cybersecurity experts have identified a shift in ransomware-related threats, with the emergence of a group calling itself Ransom Busters. The group sends emails to organizations that have already fallen victim to ransomware attacks, claiming that it can breach the attackers’ servers and help delete the stolen data in exchange for […]

ThaiCERT

August 20, 2026

Forminator Vulnerability Could Allow PHP File Uploads and Code Execution on WordPress Websites

450/69 Wednesday, August 19, 2026 Security researchers have disclosed a Critical vulnerability, CVE-2026-15748, in the Forminator Forms plugin for WordPress, which is installed on more than 600,000 websites. The vulnerability has a CVSS severity score of 9.8 and could allow unauthenticated attackers to upload malicious files, including PHP files, to affected websites, potentially leading to […]

ThaiCERT

August 19, 2026

SafePal Reports Data Breach Affecting 39,798 Customers Through Vulnerability in Order-Tracking Plugin

449/69 Wednesday, August 19, 2026 SafePal, a cryptocurrency security company, disclosed a data breach affecting approximately 39,798 customers after attackers exploited an authorization vulnerability in the order-tracking function of a plugin related to customer order data. The vulnerability allowed unauthorized individuals to access other customers’ order information. The incident affected customers who placed orders between […]

ThaiCERT

August 19, 2026

Researchers Find AI Agents Creating Malware to Attack Each Other During Simulated Testing

448/69 Wednesday, August 19, 2026 Researchers from Anthropic identified unexpected behavior during AI testing when three groups of Claude model agents, each assigned different operational goals, came into conflict and began attacking one another to compete for workspace on the system. The incident serves as a clear case study showing that if AI agent systems […]

ThaiCERT

August 19, 2026

PATCHCORD Backdoor Found Using Google Sheets as C2 in Cyber Espionage Campaign

447/69 Tuesday, August 18, 2026 Security researchers have disclosed a cyber espionage campaign using a backdoor malware named PATCHCORD, targeting telecommunications providers in Afghanistan and critical infrastructure organizations in South Asia. The attackers used fake VPN installers and telecommunications management tools disguised to appear as software used by the target organizations, tricking users into installing […]

ThaiCERT

August 18, 2026
1 3 4 5 83