LapDogs: China-Linked Cyberespionage Campaign Hacks Over 1,000 SOHO Devices Worldwide

236/68 Monday, June 30, 2025 Researchers from the STRIKE team at SecurityScorecard have uncovered a cyber-espionage campaign known as “LapDogs,” which is linked to China-nexus threat actors. The operation involves the compromise of over 1,000 SOHO (Small Office/Home Office) devices, creating a covert network called the Operational Relay Box (ORB). This network is used to […]

ThaiCERT

June 30, 2025

France Arrests Senior Members of BreachForums Involved in Leaked Data Trade

235/68 Monday, June 30, 2025 France’s cybercrime unit, the Brigade de Lutte contre la Cybercriminalité (BL2C), has arrested five individuals believed to be senior members of BreachForums—a notorious dark web marketplace known for trafficking in leaked data, hacking tools, and breached databases. Among the four most recently arrested suspects are individuals known by the aliases […]

ThaiCERT

June 30, 2025

Citrix Releases Critical Patch for CVE-2025-6543 in NetScaler ADC

234/68 Friday, June 27, 2025 Citrix has released a security update addressing a critical vulnerability (CVE-2025-6543) in its NetScaler ADC product, which carries a CVSS severity score of 9.2. The flaw is categorized as a memory overflow, which may lead to unintended code execution and potentially enable Denial-of-Service (DoS) attacks. The vulnerability affects systems configured […]

ThaiCERT

June 27, 2025

Critical Vulnerability Found in Millions of Brother Printers

233/68 Friday, June 27, 2025 Researchers from Rapid7 have discovered eight security vulnerabilities affecting up to 748 models of printers, scanners, and label printers from five major manufacturers. Among these, 689 models are from Japanese manufacturer Brother, with 695 models affected by a critical vulnerability tracked as CVE-2024-51978, which cannot be patched via firmware. This […]

ThaiCERT

June 27, 2025

U.S. Issues Cybersecurity Warning Following Airstrikes on Iranian Nuclear Facilities

232/68 Thursday, June 26, 2025 On June 13, 2025, the U.S. Department of Homeland Security (DHS) issued a cybersecurity warning, citing an increased risk of domestic cyber threats in the wake of U.S. airstrikes targeting Iranian nuclear infrastructure. The warning comes amid escalating tensions between Iran and Israel. DHS stated that pro-Iranian hacktivist groups and […]

ThaiCERT

June 26, 2025

New Spyware “SparkKitty” Found on App Store and Play Store, Targets Crypto via Photo Theft

231/68 Thursday, June 26, 2025 Cybersecurity firm Kaspersky has identified a new strain of spyware called SparkKitty, discovered hiding in applications on both the Apple App Store and Google Play Store. The spyware’s primary objective is to steal all images from a victim’s phone—specifically looking for pictures containing cryptocurrency-related information, such as wallet recovery phrases, […]

ThaiCERT

June 26, 2025

Citrix Patches Critical Vulnerabilities in NetScaler ADC and Gateway Amid “CitrixBleed” Fears

229/68 Wednesday, June 25, 2025 Citrix has released critical security patches for vulnerabilities affecting its NetScaler ADC and NetScaler Gateway products, addressing serious flaws including CVE-2025-5777, which carries a CVSS score of 9.3. This vulnerability is classified as an out-of-bounds read, resulting from insufficient input validation. It allows attackers to craft specially designed requests to […]

ThaiCERT

June 25, 2025

CoinMarketCap Suffers Supply Chain Attack Using Fake Web3 Popup to Steal Crypto

228/68 Tuesday, June 24, 2025 On June 20, 2025, cryptocurrency price tracking platform CoinMarketCap experienced a supply chain attack that led to the injection of a malicious wallet drainer script into its homepage. During the incident, users who visited the site encountered a fake Web3 popup that mimicked a “Connect Wallet” prompt. Upon connecting, the […]

ThaiCERT

June 24, 2025

Qilin Ransomware Introduces “Call Lawyer” Feature to Pressure Victims into Paying Ransom

227/68 Tuesday, June 24, 2025 The Qilin ransomware group has escalated its operations by launching a new feature called “Call Lawyer”, offering legal advisory services to its affiliates to help pressure victims into paying ransom. According to cybersecurity firm Cybereason, Qilin is aiming to position itself as a major player in the Ransomware-as-a-Service (RaaS) ecosystem, […]

ThaiCERT

June 24, 2025
1 9 10 11 41