Threat Actors Found Buying Expired Domains to Use as Infrastructure for Cyberattacks and Malware Distribution

442/69 monday, August 17, 2026 Reports indicate a growing trend in cyberattacks in which threat actors purchase expired website domains that have been abandoned and repurpose them as infrastructure to deceive users and distribute malware. Statistics show that in the first half of the year, previously used domains accounted for 20% of all new domain […]

ThaiCERT

August 17, 2026

WordPress Releases Patch for RCE Vulnerability via Image File Processing

441/69 Friday, August 14, 2026 WordPress has released a security update to fix CVE-2026-65640, a High-severity vulnerability with a CVSS score of 8.8. The vulnerability could allow an authenticated attacker with Author-level privileges or higher to execute code on the system by uploading a specially crafted file. Exploitation requires file upload privileges and affects only […]

ThaiCERT

August 14, 2026

CEVA Logistics Hit by Cyberattack, Affecting Warehouses and Shipments in Europe

440/69 Friday, August 14, 2026 CEVA Logistics, a logistics company under CMA CGM Group, disclosed a cyberattack that occurred on July 29, 2026, affecting some of its operations in Europe. Eight warehouses were impacted, and the company is currently working to restore affected services. CEVA Logistics operates in more than 170 countries and is part […]

ThaiCERT

August 14, 2026

New Android Malware Can Steal Credit Card Data and Secretly Conduct Financial Transactions

439/69 Friday, August 14, 2026 Researchers from Group-IB have reported the discovery of a new threat targeting the Android operating system. This threat involves the combined use of WindRelay, a malware strain that relays data through Near Field Communication (NFC), and SpyNote, a Remote Administration Tool (RAT) used to control infected devices. The threat affects […]

ThaiCERT

August 14, 2026

Zoom Patches Zero-Click Vulnerability in Annotation Feature That Could Allow Code Execution on Users’ Devices

438/69 Thursday, August 13, 2026 Zoom has released a security update to fix CVE-2026-53413, a High-severity vulnerability with a CVSS score of 8.3 in the Annotation feature of Zoom clients. The vulnerability could allow an attacker who joins a meeting to execute code on other participants’ devices without requiring users to download files or click […]

ThaiCERT

August 13, 2026

ExfilSquad Adds New Victims and Uses Torrents to Publish Data Stolen from Cloud Portals

437/69 Thursday, August 13, 2026 Resecurity has published a report tracking the activities of ExfilSquad, a cybercrime group that emerged in mid-2026. The group uses a data theft and extortion model, threatening to publish stolen information on a dark web leak site if victims refuse to pay ransom, rather than deploying ransomware to encrypt systems. […]

ThaiCERT

August 13, 2026

Google Says Chrome on Android Blocks More Than 7 Billion Harmful Notifications Per Day

436/69 Thursday, August 13, 2026 Google disclosed in a report for the first quarter of 2026 that Chrome’s abuse protection system blocks more than 7 billion unwanted notifications per day on Android. This development is important for cybersecurity because threat actors increasingly abuse browser notifications as a channel to distribute malware, conduct phishing scams, and […]

ThaiCERT

August 13, 2026

CISA Warns Progress Kemp LoadMaster Vulnerability Is Being Actively Exploited

435/69 Tuesday, August 11, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8037, a vulnerability affecting Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation. The flaw is a command injection vulnerability that could allow an unauthenticated attacker to execute commands on affected systems. According […]

sittisak mintaboon

August 11, 2026

IEH Discloses Phishing Incident Affecting Microsoft 365 Mailbox, Potentially Exposing Export-Controlled Military Data

434/69 Tuesday, August 11, 2026 IEH Corporation, a U.S. defense and aerospace manufacturer based in Brooklyn, New York, disclosed a cybersecurity incident in an 8-K filing submitted to the U.S. Securities and Exchange Commission (SEC) after discovering that a threat actor had gained unauthorized access to an employee’s Microsoft 365 mailbox. IEH manufactures high-reliability electrical […]

sittisak mintaboon

August 11, 2026

Over 800 Malicious npm Packages Found Distributing Cross-Platform Malware and Stealing Data on Windows, macOS, and Linux

433/69 Tuesday, August 11, 2026 Cybersecurity researchers have discovered nearly 800 malicious packages published on the npm package registry as part of a new campaign designed to distribute cross-platform malware targeting Windows, macOS, and Linux systems. The campaign poses a direct risk to software developers and organizations that may unknowingly incorporate these packages into their […]

sittisak mintaboon

August 11, 2026
1 … 11 12 13 … 119