Supply Chain Attack Through Tensorlake npm Package Steals Credentials and Spreads Malware

558/69 Friday, October 9, 2026 Cybersecurity researchers have disclosed that version 0.5.144 of the tensorlake package on npm was compromised with malware as part of a supply chain campaign linked to ChainDrop/Shai-Hulud. The malware executes during package installation through a preinstall script and is designed to steal credentials and sensitive information from developer systems, including […]

ThaiCERT

October 9, 2026

ASOS Investigates Unauthorized Push Notifications After Attackers Claim Access to Customer Data in Snowflake

557/69 Friday, October 9, 2026 ASOS disclosed that it is investigating an unauthorized access incident after attackers used the company’s official mobile application to send push notifications directly to customers on October 6, 2026. The notification, titled “ASOS HACKED,” claimed that the attackers had compromised a Snowflake instance and threatened to publish the data unless […]

ThaiCERT

October 9, 2026

Ransomware Recovery Company Executive Charged with Fraud for Secretly Paying Hackers and Overcharging Customers

556/69 Friday, October 9, 2026 The U.S. Department of Justice has charged an executive of MonsterCloud, a company providing ransomware recovery services, with allegedly defrauding organizations that had fallen victim to cyberattacks. According to reports, the company advertised that it possessed advanced proprietary technology capable of decrypting customers’ data without negotiating with ransomware groups. In […]

ThaiCERT

October 9, 2026

XSS Vulnerabilities in Ninja Forms and WPC Product Bundles Exploited to Attack WordPress Websites

555/69 Thursday, October 8, 2026 Researchers from Patchstack have disclosed active exploitation of Stored Cross-Site Scripting (XSS) vulnerabilities in two WordPress plugins: Ninja Forms, tracked as CVE-2026-94504 and affecting version 3.15.3 and earlier, and WPC Product Bundles for WooCommerce, tracked as CVE-2026-93836 and affecting version 8.6.6 and earlier. In both cases, attackers used JavaScript payloads […]

ThaiCERT

October 8, 2026

Fake Websites Impersonating ChatGPT, Gemini, and Claude Advertisements Used to Steal Credentials and MFA Codes

554/69 Thursday, October 8, 2026 Cybersecurity researchers have disclosed a phishing platform impersonating advertising services associated with multiple AI chatbots, including Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. The fake websites claim to provide services such as advertising campaign optimization, spending monitoring, and business account integration. In reality, they are designed […]

ThaiCERT

October 8, 2026

Atlassian Product Vulnerability Could Allow Unauthorized Access to System Files

553/69 Thursday, October 8, 2026 Atlassian has issued a security advisory regarding CVE-2026-21589, which affects several self-hosted Data Center products, particularly widely used platforms such as Confluence, Jira, and Bitbucket. The vulnerability could allow an unauthenticated attacker to access files within affected systems, potentially exposing sensitive information stored on organizational servers. Atlassian Cloud customers are […]

ThaiCERT

October 8, 2026

Vulnerabilities Found in LibreOffice Calc and Apache OpenOffice Calc Could Allow Code Execution on Users’ Devices

552/69 Wednesday, October 7, 2026 Security researchers have disclosed vulnerabilities affecting LibreOffice Calc and Apache OpenOffice Calc that could allow attackers to execute Java code on a user’s device through a specially crafted spreadsheet file. The vulnerabilities are tracked as CVE-2026-63277 for LibreOffice and CVE-2026-59265 for Apache OpenOffice. Successful exploitation requires the user to open […]

sittisak mintaboon

October 7, 2026

IQVIA Fined $7.8 Million Over Improper Handling of Personal Health Data

551/69 Wednesday, October 7, 2026 Italy’s data protection authority, the Garante per la Protezione dei Dati Personali (GPDP), has imposed a €7 million fine, approximately US$7.8 million, on IQVIA over improper data processing practices that may have exposed the health information of around one million patients to the risk of disclosure or re-identification. IQVIA provides […]

sittisak mintaboon

October 7, 2026

Microsoft Releases Emergency Security Update for Exchange Server Vulnerability, Preventing Unauthorized Access to Internal Emails

550/69 Wednesday, October 7, 2026 Microsoft has released an emergency security update to address a high-severity vulnerability affecting Microsoft Exchange Server. The vulnerability could allow a malicious actor to elevate access privileges and gain unauthorized access to sensitive information. This issue directly affects organizations that continue to operate on-premises email servers and is considered particularly […]

sittisak mintaboon

October 7, 2026

ClingSTUN Exploits More Than 24 Vulnerabilities to Compromise Linux Devices and Turn Them into Proxies

549/69 Tuesday, October 6, 2026 Researchers from FortiGuard Labs have disclosed the discovery of ClingSTUN malware on Linux systems, targeting internet-exposed devices by exploiting previously disclosed but unpatched vulnerabilities to gain access. Researchers found that the attackers exploited 24 vulnerabilities affecting products from multiple vendors, including D-Link, TP-Link, Ivanti, Realtek, Tenda, and AVTECH, before installing […]

ThaiCERT

October 6, 2026
1 2 … 119