Docker Releases Patch for CVE-2025-9074 Vulnerability in Docker Desktop

310/68 Wednesday, August 27, 2025 Docker has released a security update to address a critical vulnerability, CVE-2025-9074, with a CVSS score of 9.3, affecting Docker Desktop on both Windows and macOS. The flaw allows attackers to perform a Container Escape-gaining unauthorized access from within a container to the host system. The vulnerability has been fixed […]

ThaiCERT

August 27, 2025

Warning: Fake Voicemail Emails Spreading UpCrypter Malware on Windows Systems

309/68 Wednesday, August 27, 2025 FortiGuard Labs, the threat intelligence division of Fortinet, has issued a global cybersecurity alert regarding a rapidly spreading phishing campaign. The attack leverages deceptive emails titled “Missed Phone Call” or “Voicemail Message”, as well as fake purchase orders, to trick Windows users into downloading malicious files that silently install the […]

ThaiCERT

August 27, 2025

DaVita Confirms Ransomware Attack Exposed Data of Nearly 2.7 Million Patients

308/68 Tuesday, August 26, 2025 DaVita Inc., a U.S.-based dialysis service provider, has confirmed that a ransomware attack led to the leak of personal and health information affecting nearly 2.7 million individuals. The breach was publicly disclosed on April 18, 2025, after DaVita detected encryption activity on its network systems on April 12. To maintain […]

ThaiCERT

August 27, 2025

APT36 Hackers Exploit .desktop Files on Linux in New Malware Campaign

307/68 Tuesday, August 26, 2025 The Pakistan-based hacker group APT36 has adopted a new tactic targeting Indian government and security agencies by abusing .desktop files on Linux systems. Normally used as simple shortcut launchers for applications, these files are now being leveraged to hide malware, enabling data theft and persistent access. According to cybersecurity firms […]

ThaiCERT

August 27, 2025

Malvertising Campaign Targets macOS Users at Over 300 Organizations with SHAMOS Stealer

306/68 Monday, August 25, 2025 CrowdStrike has warned that from June to August 2025, more than 300 organizations worldwide were targeted by SHAMOS malware, a variant of Atomic macOS Stealer (AMOS). The malware was distributed through a Malvertising Campaign, embedded in Google ads that redirected victims to fake macOS support websites, tricking users into running […]

ThaiCERT

August 27, 2025

The Return of “Gayfemboy” Botnet Exploiting IoT Vulnerabilities Worldwide

305/68 Monday, August 25, 2025 Cyber researchers at FortiGuard Labs have reported the resurgence of the “Gayfemboy” botnet, a new evolution of the original Mirai malware, exhibiting more sophisticated and dangerous capabilities. This botnet exploits both known vulnerabilities (N-day) and unpatched zero-day vulnerabilities in devices from DrayTek, TP-Link, Raisecom, and Cisco to spread malware. The […]

ThaiCERT

August 27, 2025

Apple Patches Zero-Day Vulnerability CVE-2025-43300 in iOS, iPadOS, and macOS

304/68 Friday, August 22, 2025 Apple has released security updates to address a zero-day vulnerability, tracked as CVE-2025-43300, affecting iOS, iPadOS, and macOS. The flaw was reportedly exploited in targeted attacks. The vulnerability resides in the ImageIO framework and could lead to memory corruption when the system processes a specially crafted image. According to Apple, […]

ThaiCERT

August 22, 2025

Experts Discover “DOM-Based Extension Clickjacking” Vulnerability in Popular Password Managers

303/68 Friday, August 22, 2025 Security researcher Marek Tóth presented findings at DEF CON 33, revealing a newly identified vulnerability dubbed DOM-Based Extension Clickjacking that affects popular password manager browser extensions such as 1Password, iCloud Passwords, Bitwarden, LastPass, and several others. This flaw can potentially allow attackers to steal sensitive information simply by tricking users […]

ThaiCERT

August 22, 2025

CISA Adds Trend Micro Apex One Vulnerability to Known Exploited Vulnerabilities Catalog

302/68 Thursday, August 21, 2025 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Trend Micro Apex One, identified as CVE-2025-54948, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming that it has been actively exploited. This vulnerability is a command injection Remote Code Execution (RCE) flaw that allows unauthenticated […]

ThaiCERT

August 21, 2025

AI-Powered Plush Toys: A New Companion for Kids or a Hidden Risk

301/68 Thursday, August 21, 2025 The world of children’s toys is entering a new era as AI startups like Curio introduce intelligent plushies capable of holding conversations, answering questions, and telling stories. These toys, named Grem, Gabbo, and Grok, are marketed as screen-time alternatives that can become playful companions. However, academics and U.S. consumer protection […]

ThaiCERT

August 21, 2025
1 2 39