miniOrange Vulnerabilities Actively Exploited on WordPress, Risking Authentication Bypass

465/69 Wednesday, August 26, 2026 Security researchers have disclosed attacks targeting WordPress websites by exploiting two Critical vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin. The vulnerabilities can be chained to forge SAML responses and bypass authentication, allowing attackers to log in with website administrator privileges. Patchstack has already detected […]

ThaiCERT

August 26, 2026

Warning: WeedHack Malware Hidden in Minecraft Add-ons Imitates Legitimate Websites to Steal Data

463/69 Wednesday, August 26, 2026 Cybersecurity researchers have detected the spread of WeedHack malware targeting gamers. Threat actors created fake websites impersonating providers of Minecraft add-ons or clients. Reports indicate that access to these malicious websites has already been detected and blocked more than 6,000 times. The attackers used search engine optimization poisoning, or SEO […]

ThaiCERT

August 26, 2026

Keycloak Releases Patch for Critical Vulnerability That Could Allow Account Takeover via Password Reset

462/69 Tuesday, August 25, 2026 Security researchers have disclosed a Critical vulnerability, CVE-2026-18963, in Keycloak, an Identity and Access Management (IAM) system. The vulnerability has a CVSS severity score of 9.1 and occurs in the password reset process. It could allow unauthenticated attackers to change passwords and take over user accounts, including administrator accounts, without […]

ThaiCERT

August 25, 2026

Slovakia Warns of Cybersecurity Risks in Speed Cameras That Could Affect Vehicle Data and Government Networks

461/69 Tuesday, August 25, 2026 Slovakia’s National Security Authority (NBÚ) has issued a warning about risks associated with the use of several types of road speed cameras. The agency stated that these devices could pose a significant threat because they are network-connected systems that collect vehicle data, process license plate information, and communicate with other […]

ThaiCERT

August 25, 2026

Anthropic Expands Access to Mythos 5 AI Model to Strengthen Cyber Defense

460/69 Tuesday, August 25, 2026 Anthropic has officially announced expanded access to the cybersecurity capabilities of its advanced AI model, Mythos 5, for defenders through integrations with cybersecurity partners, updates to Claude Security, and the expansion of its Cyber Verification Program. The company also introduced the Defender Advantage Fund (0xDAF), a USD 35 million fund […]

ThaiCERT

August 25, 2026

ToxicPanda 2.0 Malware Uses VPN Permissions to Block Google Play on Android Devices

459/69 Monday, August 24, 2026 Security researchers have disclosed ToxicPanda 2.0, an Android malware strain that has added the ability to request VPN Service permissions to create a local interface for controlling network traffic on infected devices. This feature allows the malware to block communications from Google Play and Google Play Services, potentially interfering with […]

ThaiCERT

August 24, 2026

Malware Hijacks Android Car Head Units, Risking System Control and User Data Theft

458/69 Monday, August 24, 2026 Researchers from Kaspersky have published a report on Android malware targeting car head units, or infotainment systems and certain control components in vehicles. They described it as the first documented case of malware infection on a car head unit through an update mechanism specific to this type of device. The […]

ThaiCERT

August 24, 2026

Hardware Manufacturers Accelerate Processor Chip Upgrades to Support Post-Quantum Cryptography

457/69 Monday, August 24, 2026 Leading hardware and processor chip manufacturers are accelerating the development of security capabilities by integrating post-quantum cryptography (PQC) into hardware to prepare for future cyber threats. Although quantum computers capable of breaking today’s cryptographic algorithms are still expected to take several years before reaching broad commercial availability, cybersecurity experts remain […]

ThaiCERT

August 24, 2026

Zimbra Vulnerability Actively Exploited, Risking Command Execution on Servers

456/69 Friday, August 21, 2026 CERT Polska has warned that CVE-2026-73570 in Zimbra Collaboration Suite (ZCS) is being exploited in attacks. The vulnerability was fixed in Zimbra version 10.1.20, released on July 20, 2026. The flaw is a command injection vulnerability in the SNMP Monitoring component and could allow unauthenticated attackers to execute commands on […]

ThaiCERT

August 21, 2026
1 2 110