Zimbra Releases Patch for Critical Vulnerabilities in Zimbra Collaboration Suite

405/69 Thursday, July 23, 2026 Zimbra has released a security update for Zimbra Collaboration Suite (ZCS) version 10.1.20 to address multiple Critical vulnerabilities, including a command injection flaw in the SNMP monitoring component. The vulnerability could allow unauthenticated attackers to execute commands on the operating system of the email server if SNMP notifications are enabled […]

ThaiCERT

July 23, 2026

Google Launches Gemini 3.5 Flash Cyber, an AI Model for Cybersecurity Designed to Find, Verify, and Fix Software Vulnerabilities

404/69 Thursday, July 23, 2026 Google has launched Gemini 3.5 Flash Cyber, a cybersecurity-focused AI model built on Gemini 3.5 Flash and optimized to quickly and effectively find, verify, and help fix software vulnerabilities. Google stated that the model is designed to support defenders in responding to threats at scale, especially in situations where AI […]

ThaiCERT

July 23, 2026

Apple Fixes Hide My Email Vulnerability to Prevent Real Email Addresses from Leaking in Mail Logs

403/69 Thursday, July 23, 2026 Apple has fixed a security vulnerability in its Hide My Email service on iCloud+, a feature designed to generate random email addresses to conceal users’ real email addresses and help prevent spam. The vulnerability could allow users’ real email addresses to be exposed through email delivery logs, undermining the privacy […]

ThaiCERT

July 23, 2026

Microsoft Releases Out-of-Band Update to Fix Issue Causing Some Dell PCs to Shut Down Unexpectedly

402/69 Wednesday, July 22, 2026 Microsoft has released an out-of-band Windows 11 update, KB5121767, to fix an issue affecting some devices with Intel Innovation Platform Framework (Intel IPF) drivers installed. The issue could cause reduced performance, abnormal power usage, or changes in system behavior after installing a previous Windows update. On some Dell computers, users […]

ThaiCERT

July 22, 2026

Estée Lauder Discloses Data Breach After Oracle E-Business Suite Exploited in Attack

401/69 Wednesday, July 22, 2026 Estée Lauder, a major cosmetics company, has disclosed a data breach after attackers exploited a vulnerability in Oracle E-Business Suite, which the company uses for Human Resources (HR) processes. Estée Lauder stated that on June 19, 2026, it determined that unauthorized access to its Oracle E-Business Suite system had occurred […]

ThaiCERT

July 22, 2026

Warning: HollowGraph Malware Uses Microsoft 365 Calendar as a Covert Channel for Command Execution and Data Theft

400/69 Wednesday, July 22, 2026 Cybersecurity firm Group-IB has reported the discovery of a new malware strain called HollowGraph, which uses the Calendar feature in compromised Microsoft 365 accounts as a communication channel with command-and-control (C2) servers to receive commands and exfiltrate stolen data. Researchers assess that it is part of the Cavern framework, which […]

ThaiCERT

July 22, 2026

Chrome Releases Patch for Multiple Critical Memory Safety Vulnerabilities

399/69 Tuesday, July 21, 2026 Google has released a security update for Chrome to fix seven memory safety vulnerabilities. These include three Critical-severity Use-after-free vulnerabilities in the CameraCapture, GPU, and Network components, as well as three High-severity vulnerabilities in the Cast, Ozone, and Aura components. Google has not stated that any of the vulnerabilities in […]

ThaiCERT

July 21, 2026

ServiceNow Warns of Severe RCE Vulnerability in AI Platform Now Exploited in Attacks

398/69 Tuesday, July 21, 2026 Reports indicate that attackers have begun exploiting CVE-2026-6875 in the ServiceNow AI Platform, according to threat intelligence firm Defused. ServiceNow AI Platform, formerly known as the Now Platform, is an enterprise Platform-as-a-Service (PaaS) solution that helps organizations integrate AI into core business workflows. The vulnerability was discovered and reported by […]

ThaiCERT

July 21, 2026

Hugging Face, Major Open-Source AI Platform, Hacked by Automated AI Agent

397/69 Tuesday, July 21, 2026 Hugging Face, a major open-source AI platform, has disclosed that it was targeted in a cyberattack carried out by an automated AI agent, an incident that highlights a significant irony within the technology industry. The company stated that it detected and responded to a threat targeting its production infrastructure last […]

ThaiCERT

July 21, 2026

Microsoft Warns of Surge in ACR Stealer Attacks Targeting Passwords and Sensitive Data

396/69 Monday, July 20, 2026 Microsoft has observed a surge in attacks involving ACR Stealer, a malware strain designed to steal passwords, cookies, session data, authentication tokens, and important documents stored on users’ devices. Microsoft detected the campaign from late April to mid-June 2026 and believes that ACR Stealer is a Malware-as-a-Service (MaaS) offering linked […]

ThaiCERT

July 20, 2026
1 11 12 13 115