XSS Vulnerabilities in Ninja Forms and WPC Product Bundles Exploited to Attack WordPress Websites

555/69 Thursday, October 8, 2026 Researchers from Patchstack have disclosed active exploitation of Stored Cross-Site Scripting (XSS) vulnerabilities in two WordPress plugins: Ninja Forms, tracked as CVE-2026-94504 and affecting version 3.15.3 and earlier, and WPC Product Bundles for WooCommerce, tracked as CVE-2026-93836 and affecting version 8.6.6 and earlier. In both cases, attackers used JavaScript payloads […]

ThaiCERT

October 8, 2026

Fake Websites Impersonating ChatGPT, Gemini, and Claude Advertisements Used to Steal Credentials and MFA Codes

554/69 Thursday, October 8, 2026 Cybersecurity researchers have disclosed a phishing platform impersonating advertising services associated with multiple AI chatbots, including Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. The fake websites claim to provide services such as advertising campaign optimization, spending monitoring, and business account integration. In reality, they are designed […]

ThaiCERT

October 8, 2026

Atlassian Product Vulnerability Could Allow Unauthorized Access to System Files

553/69 Thursday, October 8, 2026 Atlassian has issued a security advisory regarding CVE-2026-21589, which affects several self-hosted Data Center products, particularly widely used platforms such as Confluence, Jira, and Bitbucket. The vulnerability could allow an unauthenticated attacker to access files within affected systems, potentially exposing sensitive information stored on organizational servers. Atlassian Cloud customers are […]

ThaiCERT

October 8, 2026

Vulnerabilities Found in LibreOffice Calc and Apache OpenOffice Calc Could Allow Code Execution on Users’ Devices

552/69 Wednesday, October 7, 2026 Security researchers have disclosed vulnerabilities affecting LibreOffice Calc and Apache OpenOffice Calc that could allow attackers to execute Java code on a user’s device through a specially crafted spreadsheet file. The vulnerabilities are tracked as CVE-2026-63277 for LibreOffice and CVE-2026-59265 for Apache OpenOffice. Successful exploitation requires the user to open […]

sittisak mintaboon

October 7, 2026

IQVIA Fined $7.8 Million Over Improper Handling of Personal Health Data

551/69 Wednesday, October 7, 2026 Italy’s data protection authority, the Garante per la Protezione dei Dati Personali (GPDP), has imposed a €7 million fine, approximately US$7.8 million, on IQVIA over improper data processing practices that may have exposed the health information of around one million patients to the risk of disclosure or re-identification. IQVIA provides […]

sittisak mintaboon

October 7, 2026

Microsoft Releases Emergency Security Update for Exchange Server Vulnerability, Preventing Unauthorized Access to Internal Emails

550/69 Wednesday, October 7, 2026 Microsoft has released an emergency security update to address a high-severity vulnerability affecting Microsoft Exchange Server. The vulnerability could allow a malicious actor to elevate access privileges and gain unauthorized access to sensitive information. This issue directly affects organizations that continue to operate on-premises email servers and is considered particularly […]

sittisak mintaboon

October 7, 2026

ClingSTUN Exploits More Than 24 Vulnerabilities to Compromise Linux Devices and Turn Them into Proxies

549/69 Tuesday, October 6, 2026 Researchers from FortiGuard Labs have disclosed the discovery of ClingSTUN malware on Linux systems, targeting internet-exposed devices by exploiting previously disclosed but unpatched vulnerabilities to gain access. Researchers found that the attackers exploited 24 vulnerabilities affecting products from multiple vendors, including D-Link, TP-Link, Ivanti, Realtek, Tenda, and AVTECH, before installing […]

ThaiCERT

October 6, 2026

Suspected ShinyHunters Member Detained in Jordan, Reportedly Cooperating with FBI to Track Group Members

548/69 Tuesday, October 6, 2026 A man suspected of being a member of the ShinyHunters group has reportedly been detained by Jordanian authorities and is cooperating with the FBI to help identify other members of the group. The individual has been identified as Saif al-Din Khader, who sources said was arrested last Tuesday. However, details […]

ThaiCERT

October 6, 2026

Warlock Ransomware Continues Exploiting Older SharePoint Vulnerabilities to Target Critical Infrastructure Worldwide

547/69 Tuesday, October 6, 2026 The threat group behind Warlock ransomware, also known as Longlegs or Storm-2603, has reportedly continued exploiting the Microsoft SharePoint ToolShell vulnerability chain, first disclosed in mid-2025, as an initial access vector. Over the past two months, the group has attacked at least four organizations, including a water utility, a telecommunications […]

ThaiCERT

October 6, 2026

CloudSyncD Malware Disguised as Zoom Installer on macOS Tricks Users into Providing Passwords and Deploys a Backdoor

546/69 Monday, October 5, 2026 Researchers from Jamf Threat Labs have disclosed the discovery of CloudSyncD malware on macOS, which disguises itself as a Zoom installer and uses instructions on the installation page to trick users into bypassing Gatekeeper protections before displaying a fake prompt requesting the password for the local account. Researchers first identified […]

ThaiCERT

October 5, 2026
1 2 … 119