Cyber Tensions Rise as Hacktivist Activity Surges Following Iran Strikes, While State Operations Remain Limited

124/69 Wednesday, March 4, 2026 Following the military operations Epic Fury by the United States and Roaring Lion by Israel on February 28, 2026, which targeted critical Iranian infrastructure and communications systems, cybersecurity experts from organizations such as CrowdStrike and Palo Alto Networks have reported a notable increase in activity from pro-Iranian hacktivist groups. However, […]

sittisak mintaboon

March 4, 2026

Microsoft Warns of Fake Gaming Utilities Spreading RAT Malware for Remote System Control

123/69 Monday, March 2, 2026 The Microsoft Defender research team has identified a campaign in which attackers distribute trojanized “gaming utility” programs through web browsers and chat platforms. The malicious files, disguised as legitimate tools such as Xeno.exe or RobloxPlayerBeta.exe, trick users into executing them, ultimately leading to the installation of a Remote Access Trojan […]

sittisak mintaboon

March 2, 2026

Internet in Iran Nearly Goes Dark Amid U.S. and Israeli Military Operations

122/69 Monday, March 2, 2026 On Saturday, internet access across Iran dropped to nearly zero amid ongoing military operations by the United States and Israel. Global internet monitoring organization NetBlocks reported network data confirming a “near-total blackout,” with national connectivity falling to approximately 4% of normal levels. NetBlocks noted that the disruption resembles measures previously […]

sittisak mintaboon

March 2, 2026

Thousands of Publicly Exposed Google Cloud API Keys Risk Unauthorized Access to Gemini AI

121/69 Monday, March 2, 2026 Security firm Truffle Security has released new research revealing that nearly 2,863 Google Cloud API keys were embedded in client-side website code and exposed to the public internet. Some of the affected websites were reportedly associated with Google itself. Although these API keys were originally intended only to identify projects […]

sittisak mintaboon

March 2, 2026

Critical Vulnerabilities in Claude Code Could Enable Remote Code Execution and API Key Theft

120/69 Friday, February 27, 2026 Check Point Research has identified multiple security vulnerabilities in Claude Code, an AI-powered coding assistant developed by Anthropic. The flaws could allow attackers to execute malicious code remotely (Remote Code Execution – RCE) and steal users’ API keys. The issues stem from configuration mechanisms within the tool, including Hooks, Model […]

sittisak mintaboon

February 27, 2026

ShinyHunters Attack Impacts Over 12.4 Million CarGurus User Accounts

119/69 Friday, February 27, 2026 The cybercrime group ShinyHunters has published personal data from more than 12.4 million user accounts belonging to CarGurus after a failed extortion attempt. CarGurus is a U.S.-based online automotive marketplace and research platform operating in the United States, Canada, and the United Kingdom. The platform attracts approximately 40 million monthly […]

sittisak mintaboon

February 27, 2026

Critical Vulnerability in Zyxel Routers Could Allow Remote Device Takeover

118/69 Friday, February 27, 2026 Zyxel, a leading network equipment manufacturer, has issued a security advisory regarding a critical vulnerability identified as CVE-2025-13942, which carries a CVSS score of 9.8 out of 10. The flaw allows unauthenticated attackers to execute arbitrary commands remotely, potentially gaining full control of affected devices. The vulnerability impacts more than […]

sittisak mintaboon

February 27, 2026

High-Severity Vulnerabilities in VMware Aria Operations Could Allow Remote Code Execution (RCE)

117/69 Thursday, February 26, 2026 Broadcom has issued a security advisory and released patches to address multiple vulnerabilities in VMware Aria Operations, including a high-severity flaw that could lead to remote code execution. The most critical issue, CVE-2026-22719 (CVSS 8.1), is a Command Injection vulnerability. An unauthenticated attacker could exploit this flaw to execute arbitrary […]

sittisak mintaboon

February 26, 2026

SolarWinds Releases Patches for Four Critical Serv-U Vulnerabilities That Could Lead to Root Compromise

116/69 Thursday, February 26, 2026 SolarWinds has released security updates addressing four critical vulnerabilities in its Serv-U file transfer software, which supports FTP, FTPS, SFTP, and HTTP/S protocols. Serv-U is widely used by organizations to exchange large files both internally and externally. If left unpatched, the vulnerabilities could allow attackers to execute remote code (RCE) […]

sittisak mintaboon

February 26, 2026

Lazarus Group Turns to Medusa Ransomware to Extort Vulnerable Organizations

115/69 Thursday, February 26, 2026 A recent report from Symantec’s Threat Hunter Team and Carbon Black highlights a concerning shift in tactics by the state-sponsored Lazarus Group. The group, historically known for cyber espionage operations, is increasingly focusing on financial gain by deploying the Medusa ransomware against healthcare and social service organizations worldwide. By collaborating […]

sittisak mintaboon

February 26, 2026
1 … 20 21 22 … 26