Researchers Warn: DPRK Hackers Deploy BeaverTail via ClickFix in Fake Job Campaigns

359/68 Tuesday, September 23, 2025 Security researchers have discovered that North Korean hackers (DPRK) are leveraging the ClickFix technique to trick job seekers in marketing and cryptocurrency trading roles into installing the BeaverTail and InvisibleFerret malware. The campaign, part of the Contagious Interview operation (also tracked as Gwisin Gang) under the Lazarus Group, began in […]

ThaiCERT

September 23, 2025

Fortra Releases Patch for Critical GoAnywhere MFT Vulnerability

358/68 Tuesday, September 23, 2025 Fortra, the developer of Managed File Transfer (MFT) solutions, has released a patch to address a critical vulnerability (CVSS Score 10.0) in its GoAnywhere MFT software, tracked as CVE-2025-10035. The flaw is a deserialization vulnerability within the License Servlet, which allows attackers to craft a malicious License Response Signature and […]

ThaiCERT

September 23, 2025

Phishing-as-a-Service Platforms “Lighthouse” and “Lucid” Rampage Worldwide, Targeting 316 Brands Across 74 Countries

357/68 Tuesday, September 23, 2025 Cybersecurity experts have issued a warning about the widespread use of Phishing-as-a-Service (PhaaS) platforms named Lighthouse and Lucid, which are being leveraged as tools to conduct online phishing attacks. These services have been used to target more than 316 well-known global brands across 74 countries. The platforms allow threat actors […]

ThaiCERT

September 23, 2025

“ShadowLeak” Vulnerability Exposes Gmail Data via ChatGPT Deep Research

356/68 Monday, September 22, 2025 Researchers from Radware have disclosed a zero-click vulnerability in ChatGPT’s Deep Research function, named ShadowLeak, which allowed attackers to extract data from Gmail inboxes simply by sending an email containing hidden malicious instructions – without requiring any clicks or interaction from the victim. The attack leveraged text that was almost […]

ThaiCERT

September 22, 2025

Cyberattack on Collins Aerospace Disrupts Major European Airports – Check-in Systems Down, Flights Delayed

355/68 Monday, September 22, 2025 Collins Aerospace, a U.S.-based aviation technology company under RTX (formerly Raytheon Technologies), has suffered a cyberattack that disrupted the check-in and boarding systems at several major European airports, including London Heathrow, Brussels, and Berlin. The incident caused widespread delays and cancellations, leaving thousands of passengers facing long queues and hours […]

ThaiCERT

September 22, 2025

LastPass Issues Warning: Beware of Fake GitHub Repositories Spreading Data-Stealing Malware

354/68 Monday, September 22, 2025 LastPass has issued a warning to its users about a malicious campaign in which cybercriminals are creating fake repositories on GitHub to distribute malware disguised as popular software. The attacks specifically target macOS users, tricking them into installing a malware strain called Atomic Infostealer, which is designed to steal sensitive […]

ThaiCERT

September 22, 2025

SonicWall Urges Customers to Reset Passwords and Tokens After Firewall Backup Files Accessed

353/68 Friday, September 19, 2025 SonicWall has issued an advisory urging customers to reset their passwords and authentication tokens after discovering that firewall configuration backup files for some MySonicWall accounts were accessed without authorization. The incident raises concerns that attackers could exploit sensitive information, such as passwords, API keys, and tokens, to compromise firewall systems. […]

ThaiCERT

September 19, 2025

Microsoft and Cloudflare Dismantle RaccoonO365 Phishing Service

352/68 Friday, September 19, 2025 Microsoft and Cloudflare announced the successful takedown of the RaccoonO365 Phishing-as-a-Service (PhaaS) platform, which had been used to steal thousands of Microsoft 365 accounts. Microsoft tracked this threat under the name Storm-2246. According to Microsoft, its Digital Crimes Unit (DCU) filed a legal complaint with the Southern District of New […]

ThaiCERT

September 19, 2025
1 9 10 11 53