CISA Warns Progress Kemp LoadMaster Vulnerability Is Being Actively Exploited

435/69 Tuesday, August 11, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8037, a vulnerability affecting Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation. The flaw is a command injection vulnerability that could allow an unauthenticated attacker to execute commands on affected systems. According […]

sittisak mintaboon

August 11, 2026

IEH Discloses Phishing Incident Affecting Microsoft 365 Mailbox, Potentially Exposing Export-Controlled Military Data

434/69 Tuesday, August 11, 2026 IEH Corporation, a U.S. defense and aerospace manufacturer based in Brooklyn, New York, disclosed a cybersecurity incident in an 8-K filing submitted to the U.S. Securities and Exchange Commission (SEC) after discovering that a threat actor had gained unauthorized access to an employee’s Microsoft 365 mailbox. IEH manufactures high-reliability electrical […]

sittisak mintaboon

August 11, 2026

Over 800 Malicious npm Packages Found Distributing Cross-Platform Malware and Stealing Data on Windows, macOS, and Linux

433/69 Tuesday, August 11, 2026 Cybersecurity researchers have discovered nearly 800 malicious packages published on the npm package registry as part of a new campaign designed to distribute cross-platform malware targeting Windows, macOS, and Linux systems. The campaign poses a direct risk to software developers and organizations that may unknowingly incorporate these packages into their […]

sittisak mintaboon

August 11, 2026

Metabase Warns of Zero-Day Exploited in the Wild, Allowing Privilege Escalation to Administrator

432/69 Monday, August 10, 2026 Metabase has issued a security advisory for a critical vulnerability affecting its Business Intelligence and Data Visualization platform after discovering that the flaw had been actively exploited as a zero-day. The vulnerability carries a CVSS score of 10.0 and had not yet been assigned a CVE identifier at the time […]

sittisak mintaboon

August 10, 2026

Unlimited Technology Systems Data Breach Impacts More Than 3.8 Million Healthcare Patients

431/69 Monday, August 10, 2026 Unlimited Technology Systems, a U.S.-based healthcare technology company, has disclosed a data breach affecting more than 3.8 million individuals after attackers gained access to the company’s commercial data center between October 5 and October 10, 2025. The company, headquartered in Montgomery, Ohio, provides financial technology, billing, and revenue cycle management […]

sittisak mintaboon

August 10, 2026

OpenAI Tightens Security Measures for Astra Model as Anthropic Eases Restrictions on Fable

430/69 Monday, August 10, 2026 OpenAI has announced stricter security measures for its new AI model, Astra, following preliminary assessments indicating that the model may possess advanced cyber capabilities capable of introducing new forms of risk. Meanwhile, Anthropic, another major AI developer, appears to be moving in the opposite direction by easing certain restrictions on […]

sittisak mintaboon

August 10, 2026

Mistic RAT Used as an Initial Access Tool, Increasing the Risk of Ransomware Attacks

345/69 Thursday, June 25, 2026 Security researchers have revealed that the Initial Access Broker (IAB) group tracked as Woodgnat, also known as KongTuke, is using a new Remote Access Trojan (RAT) called Mistic RAT to compromise organizations across multiple industries. The group has been linked to providing network access to several ransomware operations, including Qilin, […]

sittisak mintaboon

June 25, 2026

Tata Electronics Confirms Cyberattack After World Leaks Claims Theft and Publication of Company Data

344/69 Thursday, June 25, 2026 Tata Electronics has confirmed that it was the target of a cyberattack that affected portions of its internal IT infrastructure. The company stated that it detected the incident several weeks ago and immediately initiated its incident response procedures. Tata Electronics emphasized that the attack has not affected its business operations, […]

sittisak mintaboon

June 25, 2026

LastPass Confirms Customer CRM Data Exposure Following Supply Chain Attack Through Klue Platform

343/69 Thursday, June 25, 2026 LastPass has confirmed a customer data exposure involving its Customer Relationship Management (CRM) system hosted within its Salesforce environment. The incident resulted from a supply chain attack targeting Klue, a third-party competitive intelligence platform. According to the company, the threat actor known as Icarus compromised Klue’s infrastructure and stole OAuth […]

sittisak mintaboon

June 25, 2026

Supply Chain Attack Through ShapedPlugin Update System Impacts WordPress Websites

333/69 Friday, June 19, 2026 Security researchers have disclosed a supply chain attack affecting ShapedPlugin’s premium WordPress plugins. Attackers were able to inject malicious code into plugin packages distributed through the vendor’s official update infrastructure, meaning website administrators who installed or updated affected plugins through legitimate channels may have unknowingly received compromised files. According to […]

sittisak mintaboon

June 19, 2026
1 2 26