Cyberattacks Target Government Agencies in Central Asia Using New OctLurk and SilkLurk Malware

415/69 Monday, August 3, 2026 Since January 2025, reports have identified a new wave of cyberattacks carried out by an advanced threat group, primarily targeting government organizations in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria. The affected entities span several nationally important sectors, including public health, research, foreign affairs ministries, law enforcement […]

ThaiCERT

August 3, 2026

Cisco Warns of Static Credential Vulnerability in Secure Firewall Management Center Actively Exploited in Attacks

414/69 Friday, July 31, 2026 Cisco has issued an advisory for CVE-2026-20316 in Cisco Secure Firewall Management Center (FMC) after discovering that the vulnerability has been exploited in zero-day attacks. The vulnerability is caused by the presence of static credentials within the system, which could allow attackers to use those credentials to gain unauthorized access […]

ThaiCERT

July 31, 2026

OpenAI Discloses Additional Details on AI Model Test Escape, Finding Use of Vulnerabilities to Access External Services

412/69 Friday, July 31, 2026 OpenAI has disclosed additional information regarding an incident in which an artificial intelligence (AI) model escaped control during cybersecurity safety testing. The company found that more external organizations and services were affected than initially reported. The incident occurred after AI models such as GPT-5.6 Sol and an unreleased experimental model […]

ThaiCERT

July 31, 2026

Attack via Hotel Wi-Fi Targets Microsoft 365 Account Credentials

411/69 Monday, July 27, 2026 Security researchers have disclosed an attack campaign targeting Wi-Fi systems at hotels, conference centers, and other venues providing public network access. The attackers take control of or modify Wi-Fi gateway settings to redirect users to fake Microsoft 365 login pages and steal account credentials from corporate employees connected through those […]

ThaiCERT

July 27, 2026

Data Leaked by ShinyHunters Used in Sextortion Email Scam Demanding USD 2,000 in Bitcoin

410/69 Monday, July 27, 2026 Reports indicate that threat actors are using email addresses previously exposed in data breaches and published by the extortion group ShinyHunters to send sextortion scam emails demanding USD 2,000 in Bitcoin. The emails claim to be from ShinyHunters and state that the attackers have accessed the recipient’s device after obtaining […]

ThaiCERT

July 27, 2026

SourTrade Campaign Uses Malvertising to Trick Browsers into Assembling Malicious Files

409/69 Monday, July 27, 2026 Security researchers from Confiant have released a report on a malvertising campaign called SourTrade, which primarily targets retail investors and cryptocurrency users in multiple countries. The campaign was initially reported to have been active since late 2024 and uses fake websites that impersonate well-known investment platforms such as TradingView, Solana, […]

ThaiCERT

July 27, 2026

msaRAT Malware Uses Chrome and Edge as C2 Communication Channels to Evade Detection

408/69 Friday, July 24, 2026 The Chaos ransomware group has been observed using a new backdoor called msaRAT, developed in Rust, which abuses the Chrome DevTools Protocol (CDP) to control Google Chrome or Microsoft Edge for relaying communications with command-and-control (C2) servers instead of connecting directly from the malware itself. This causes the traffic to […]

ThaiCERT

July 24, 2026

New Dolphin X Malware Uses AI to Rank Victims and Help Hackers Identify High-Value Targets Faster

406/69 Friday, July 24, 2026 Researchers from Varonis Threat Labs have identified a new Remote Access Trojan (RAT) called Dolphin X, which is being advertised for sale on cybercrime forums. The malware is notable because it incorporates artificial intelligence (AI) technology to analyze and rank victims, allowing attackers to filter and prioritize high-value targets or […]

ThaiCERT

July 24, 2026

Zimbra Releases Patch for Critical Vulnerabilities in Zimbra Collaboration Suite

405/69 Thursday, July 23, 2026 Zimbra has released a security update for Zimbra Collaboration Suite (ZCS) version 10.1.20 to address multiple Critical vulnerabilities, including a command injection flaw in the SNMP monitoring component. The vulnerability could allow unauthenticated attackers to execute commands on the operating system of the email server if SNMP notifications are enabled […]

ThaiCERT

July 23, 2026
1 11 12 13 116