Miasma Malware Campaign Found Hiding Malicious Code in More Than 20 npm Packages to Steal Developer Secrets

349/69 Monday, June 29, 2026 Microsoft has detected a malware campaign named Miasma, a supply chain worm capable of self-propagation. The latest activity involved malicious code embedded in more than 20 versions of npm packages used in the Leo Platform and RStreams ecosystems. According to Microsoft Threat Intelligence, the attack began on the evening of […]

chanapon

June 29, 2026

Google Releases Chrome 149 Update to Fix 18 Severe Vulnerabilities

348/69 Friday, June 26, 2026 Google has released a security update for Chrome 149 to address a total of 18 vulnerabilities, including 4 Critical and 14 High-severity flaws. This update is separate from the earlier emergency update that fixed the zero-day vulnerability CVE-2026-11645, which had reportedly been exploited in attacks. Google has not stated that […]

chanapon

June 26, 2026

GSM-R Railway Communication System Outage Across Germany Causes Widespread Train Service Suspension

347/69 Friday, June 26, 2026 Reports indicate that, at 10:30 p.m. on Tuesday, June 23, 2026, Deutsche Bahn, Germany’s national railway operator, informed passengers that trains across the country had to stop at stations due to a nationwide outage in the GSM-R system, or Global System for Mobile Communications – Railway. GSM-R is an internal […]

chanapon

June 26, 2026

Warning: Microsoft Edge Extension Used as an Attack Vector for Ransomware

346/69 Friday, June 26, 2026 Security researchers from Zscaler have disclosed the discovery of a new malware called Edgecution, which disguises itself as a Microsoft Edge extension to facilitate ransomware attacks. Edgecution is assessed to be operated by an Initial Access Broker (IAB) linked to a ransomware operation known as Payouts Kings. A key feature […]

chanapon

June 26, 2026

Mistic RAT Used as an Initial Access Tool, Increasing the Risk of Ransomware Attacks

345/69 Thursday, June 25, 2026 Security researchers have revealed that the Initial Access Broker (IAB) group tracked as Woodgnat, also known as KongTuke, is using a new Remote Access Trojan (RAT) called Mistic RAT to compromise organizations across multiple industries. The group has been linked to providing network access to several ransomware operations, including Qilin, […]

sittisak mintaboon

June 25, 2026

Tata Electronics Confirms Cyberattack After World Leaks Claims Theft and Publication of Company Data

344/69 Thursday, June 25, 2026 Tata Electronics has confirmed that it was the target of a cyberattack that affected portions of its internal IT infrastructure. The company stated that it detected the incident several weeks ago and immediately initiated its incident response procedures. Tata Electronics emphasized that the attack has not affected its business operations, […]

sittisak mintaboon

June 25, 2026

LastPass Confirms Customer CRM Data Exposure Following Supply Chain Attack Through Klue Platform

343/69 Thursday, June 25, 2026 LastPass has confirmed a customer data exposure involving its Customer Relationship Management (CRM) system hosted within its Salesforce environment. The incident resulted from a supply chain attack targeting Klue, a third-party competitive intelligence platform. According to the company, the threat actor known as Icarus compromised Klue’s infrastructure and stole OAuth […]

sittisak mintaboon

June 25, 2026

Apple Patches Beats Studio Buds Vulnerability After Risk of Microphone Eavesdropping Identified

342/69 Wednesday, June 24, 2026 Apple has released a security update for Beats Studio Buds to address CVE-2025-20701, a vulnerability that could allow an attacker within Bluetooth range to listen through the device’s microphone if the earbuds have not yet been paired and are in pairing request discovery mode. The vulnerability is related to open-source […]

chanapon

June 24, 2026

Xsolis Discloses Data Breach Affecting Nearly 1.4 Million People After Phishing Attack

341/69 Wednesday, June 24, 2026 Xsolis, Inc., a U.S.-based healthcare technology company that provides Utilization Management and Revenue Cycle solutions for healthcare providers, has disclosed a data breach affecting nearly 1.4 million people. The company stated that, on January 22, 2026, it detected unauthorized activity in certain parts of Xsolis systems as a result of […]

chanapon

June 24, 2026

WhatsApp Attack Uses VBScript Files Disguised as Business Documents to Take Control of Systems

340/69 Wednesday, June 24, 2026 Reports have emerged of a cyberattack campaign targeting WhatsApp users in multiple countries around the world, including countries in Asia. Threat actors are sending deceptive messages with malicious VBScript attachments through compromised WhatsApp accounts. The attack abuses the trust associated with people in the victim’s contact list to trick users […]

chanapon

June 24, 2026
1 9 10 11 108