Microsoft Releases Security Updates Addressing RCE Vulnerability in SharePoint Server

288/69 Wednesday, May 27, 2026 Microsoft has released security updates to address a Remote Code Execution (RCE) vulnerability in Microsoft SharePoint Server tracked as CVE-2026-45659. The vulnerability has a CVSS severity score of 8.8 and is caused by the deserialization of untrusted data within SharePoint Server. The vulnerability could allow an authenticated attacker with minimal […]

sittisak mintaboon

May 27, 2026

Lazarus APT Deploys Fileless RemotePE RAT Operating Entirely in Memory to Evade Detection

287/69 Wednesday, May 27, 2026 Reports indicate that the Lazarus Group APT group has developed and deployed a new Remote Access Trojan (RAT) known as “RemotePE,” designed to operate entirely in the memory of compromised systems. Because the malware leaves almost no traces on disk, forensic analysis and retrospective investigation become significantly more difficult. Researchers […]

sittisak mintaboon

May 27, 2026

Megalodon Supply Chain Attack Impacts More Than 5,500 GitHub Repositories, Targeting Sensitive System Credentials

286/69 Wednesday, May 27, 2026 Cybersecurity researchers have reported the discovery of a large-scale supply chain attack campaign known as “Megalodon,” which has impacted more than 5,500 repositories on GitHub. The campaign primarily targets the theft of sensitive credentials, passwords, API keys, and other secrets used in software development environments. The incident is considered highly […]

sittisak mintaboon

May 27, 2026

iPhone Users Urged to Update iOS and WhatsApp Following Reports of Unauthorized Messaging Activity

285/69 Tuesday, May 26, 2026 Reports have emerged of multiple iPhone users in Italy having their WhatsApp accounts hijacked and used to send unauthorized messages, despite victims not clicking malicious links, scanning QR codes, entering verification codes, or linking new devices. Attackers reportedly used compromised accounts to send money transfer requests to recently contacted individuals. […]

sittisak mintaboon

May 26, 2026

Critical SQL Injection Vulnerability in Ghost CMS Exploited to Inject Malicious Scripts Through ClickFix Campaign

284/69 Tuesday, May 26, 2026 Researchers have identified a large-scale attack campaign exploiting the critical SQL Injection vulnerability CVE-2026-26980 in Ghost CMS to inject malicious JavaScript into websites, leading to ClickFix-style attacks. According to threat intelligence researchers from Qianxin XLab, more than 700 affected domains have been identified, including websites belonging to universities, AI/SaaS companies, […]

sittisak mintaboon

May 26, 2026

Ransomware Trends in 2026 Shift Toward Data Extortion Without File Encryption

283/69 Tuesday, May 26, 2026 Ransomware groups in 2026 are increasingly shifting their tactics away from encrypting victim systems and toward pure data extortion operations, focusing primarily on stealing sensitive information and threatening to publicly leak the data if victims refuse to pay. One of the key drivers behind this shift is the steady decline […]

sittisak mintaboon

May 26, 2026

RondoDox Botnet Exploits Unpatched ASUS Routers Through Legacy Vulnerability

282/69 Monday, May 25, 2026 Security researchers have reported that attackers linked to the RondoDox botnet are actively exploiting the legacy vulnerability CVE-2018-5999 in unpatched ASUS routers. The vulnerability carries a CVSS score of 9.8 (Critical) and affects ASUSWRT firmware, allowing attackers to modify router settings without authentication. According to reports, VulnCheck detected active exploitation […]

sittisak mintaboon

May 25, 2026

Anthropic Reveals Claude Mythos AI Helped Discover More Than 10,000 Vulnerabilities in Critical Software Worldwide

281/69 Monday, May 25, 2026 Anthropic revealed that Project Glasswing, the company’s proactive cybersecurity initiative, has identified more than 10,000 High and Critical vulnerabilities in widely used and mission-critical software projects worldwide since the program began last month. The initiative granted approximately 50 partners access to Claude Mythos Preview, an advanced AI model capable of […]

sittisak mintaboon

May 25, 2026

Critical SQL Injection Vulnerability (CVE-2026-9082) in Drupal Actively Exploited in the Wild

280/69 Monday, May 25, 2026 On May 20, 2026, Drupal released security patches to address a critical SQL Injection vulnerability tracked as CVE-2026-9082. However, less than 48 hours after the security update was published, researchers observed widespread exploitation attempts targeting vulnerable Drupal websites using PostgreSQL databases. The vulnerability allows unauthenticated attackers to gain access to […]

sittisak mintaboon

May 25, 2026

Cisco Patches Critical CVE-2026-20223 Vulnerability in Secure Workload Allowing Site Admin Privilege Compromise via REST API

279/69 Friday, May 22, 2026 Cisco has released security updates to address a maximum-severity vulnerability in Cisco Secure Workload, tracked as CVE-2026-20223 (CVSS 10.0). The vulnerability is caused by insufficient authentication and authorization validation in an internal REST API, allowing unauthenticated remote attackers to send specially crafted API requests to affected endpoints. If successfully exploited, […]

sittisak mintaboon

May 22, 2026
1 2 93