StealC V2 Malware Hides Inside Blender 3D Model Files, Steals Over 100 Types of Data

491/68 Wednesday, November 26, 2025 Cybercriminals are spreading the StealC V2 information-stealing malware through malicious Blender model files uploaded to 3D asset marketplaces such as CGTrader. The attackers exploit Blender’s ability to automatically run Python scripts (Auto Run), allowing malicious code to execute immediately when a user opens a .blend file. Many users enable this […]

ThaiCERT

November 26, 2025

Harvard University Discloses Data Breach Affecting Students, Alumni, Donors, and Staff

490/68 Wednesday, November 26, 2025 Harvard University has disclosed a data breach affecting its Alumni Affairs and Development (AAD) system, which was compromised through a voice phishing (vishing) attack. The incident allowed unauthorized access to personal information of alumni, donors, students, staff, and related individuals. The breach was detected on November 18, 2025, and Harvard […]

ThaiCERT

November 26, 2025

Warning Issued as ClickFix Attacks Re-emerge Using Fake Windows Update Screens and Steganography-Based Malware Delivery

489/68 Wednesday, November 26, 2025 A new and more sophisticated wave of ClickFix cyberattacks has been detected, leveraging highly convincing full-screen browser windows that mimic authentic Windows Update animations or authentication prompts. These fake screens are used to socially engineer victims into following instructions that ultimately execute malicious commands silently copied into the clipboard and […]

ThaiCERT

November 26, 2025

SonicWall Issues Warning for High-Severity Vulnerability CVE-2025-40601, Urges Immediate Updates

488/68 Tuesday, November 25, 2025 SonicWall has issued a security advisory regarding a high-severity buffer overflow vulnerability in the SonicOS SSLVPN service, identified as CVE-2025-40601 (CVSS 7.5). The flaw allows unauthenticated remote attackers to trigger a Denial-of-Service (DoS) condition, causing Gen7 and Gen8 firewalls to reboot or stop functioning. The vulnerability affects only devices with […]

ThaiCERT

November 25, 2025

Iberia Discloses Data Breach Following Compromise of Third-Party Service Provider

487/68 Tuesday, November 25, 2025 Spanish airline Iberia has issued a customer alert regarding a data breach after a third-party service provider linked to the airline’s systems was hacked, resulting in unauthorized access to certain customer information. The attackers claim to possess up to 77 GB of data related to the airline. As Spain’s flag […]

ThaiCERT

November 25, 2025

New Android Malware “Sturnus” Breaches Encrypted WhatsApp/Signal Chats and Steals Financial Data

486/68 Tuesday, November 25, 2025 Cybersecurity researchers from ThreatFabric have announced the discovery of a new and highly sophisticated Android malware variant named “Sturnus” on November 20, 2025. It is classified as a high-risk threat due to its advanced capabilities, which surpass those of typical malware. The most alarming feature is its ability to completely […]

ThaiCERT

November 25, 2025

BadAudio Uses Advanced Evasion Techniques to Infiltrate Enterprise Networks Persistently

485/68 Monday, November 24, 2025 Security researchers are warning about a long-running cyber-espionage campaign-active for nearly three years-that leverages supply-chain attacks and multiple infection techniques to distribute the “BadAudio” malware to a wide range of targets. The attackers spread the malware through website compromises, embedding malicious code into files from partner companies, and highly targeted […]

ThaiCERT

November 24, 2025

SolarWinds Patches Three Critical Vulnerabilities in Serv-U Products

484/68 Monday, November 24, 2025 SolarWinds has released a security update addressing three critical vulnerabilities in its Serv-U File Transfer Solution that could allow attackers to execute arbitrary code remotely (Remote Code Execution – RCE). All vulnerabilities affect Serv-U version 15.5.2.2.102 and have been fixed in version 15.5.3. Details of the patched vulnerabilities include: SolarWinds […]

ThaiCERT

November 24, 2025

CISA Warns of Critical Zero-Day Vulnerability in Oracle Identity Manager Now Actively Exploited

483/68 Monday, November 24, 2025 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Oracle Identity Manager vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming that attackers are actively exploiting it in the wild. The flaw, CVE-2025-61757, carries a CVSS score of 9.8/10 and stems from an authentication validation failure. It […]

ThaiCERT

November 24, 2025

Operation WrtHug Targets Over 50,000 ASUS Routers to Build a Global Botnet

482/68 Friday, November 21, 2025 Researchers have uncovered a cyberattack campaign known as Operation WrtHug, which targets older and near end-of-life (EOL) ASUS routers-over 50,000 devices worldwide-with the goal of creating a massive botnet. The largest concentrations of compromised devices were found in Taiwan, the United States, and Russia. Most affected routers were using ASUS […]

ThaiCERT

November 21, 2025
1 2 57