Over 800 Malicious npm Packages Found Distributing Cross-Platform Malware and Stealing Data on Windows, macOS, and Linux

433/69 Tuesday, August 11, 2026 Cybersecurity researchers have discovered nearly 800 malicious packages published on the npm package registry as part of a new campaign designed to distribute cross-platform malware targeting Windows, macOS, and Linux systems. The campaign poses a direct risk to software developers and organizations that may unknowingly incorporate these packages into their […]

sittisak mintaboon

August 11, 2026

Metabase Warns of Zero-Day Exploited in the Wild, Allowing Privilege Escalation to Administrator

432/69 Monday, August 10, 2026 Metabase has issued a security advisory for a critical vulnerability affecting its Business Intelligence and Data Visualization platform after discovering that the flaw had been actively exploited as a zero-day. The vulnerability carries a CVSS score of 10.0 and had not yet been assigned a CVE identifier at the time […]

sittisak mintaboon

August 10, 2026

Unlimited Technology Systems Data Breach Impacts More Than 3.8 Million Healthcare Patients

431/69 Monday, August 10, 2026 Unlimited Technology Systems, a U.S.-based healthcare technology company, has disclosed a data breach affecting more than 3.8 million individuals after attackers gained access to the company’s commercial data center between October 5 and October 10, 2025. The company, headquartered in Montgomery, Ohio, provides financial technology, billing, and revenue cycle management […]

sittisak mintaboon

August 10, 2026

OpenAI Tightens Security Measures for Astra Model as Anthropic Eases Restrictions on Fable

430/69 Monday, August 10, 2026 OpenAI has announced stricter security measures for its new AI model, Astra, following preliminary assessments indicating that the model may possess advanced cyber capabilities capable of introducing new forms of risk. Meanwhile, Anthropic, another major AI developer, appears to be moving in the opposite direction by easing certain restrictions on […]

sittisak mintaboon

August 10, 2026

Cisco Releases Patches for Critical Vulnerabilities in SD-WAN, IOS XE, and Secure Firewall Management Center

429/69 Friday, August 7, 2026 Cisco has released security updates to address vulnerabilities in enterprise networking and security management products, including Cisco Catalyst SD-WAN, Cisco IOS XE, and Cisco Secure Firewall Management Center (FMC). The updates include Critical vulnerabilities that could be exploited to escalate privileges, execute commands, or access affected systems if attackers meet […]

ThaiCERT

August 7, 2026

Creator of Ransom Cartel Ransomware Sentenced to 16 Years in Prison for Attacks on Organizations Worldwide

428/69 Friday, August 7, 2026 The U.S. Department of Justice (DOJ) disclosed that Maksim Silnikau, a 40-year-old Belarusian national who created and operated the Ransom Cartel ransomware operation, has been sentenced to 16 years in prison for ransomware attacks against at least 18 companies worldwide. Silnikau was convicted of conspiracy to commit an offense against […]

ThaiCERT

August 7, 2026

Hackers Use SQL Injection Vulnerability to Deploy khunt Attack Tool Directly Inside Oracle Database

427/69 Friday, August 7, 2026 Cybersecurity researchers from Huntress reported detecting a cyberattack in late July 2026, in which hackers exploited a SQL Injection vulnerability to deploy a post-exploitation toolkit called khunt directly inside an organization’s Oracle database. The attack was carried out through a public-facing Java application running on Apache Tomcat. In this incident, […]

ThaiCERT

August 7, 2026

CISA Adds Actively Exploited Langflow, N-central, and Apache Tomcat Vulnerabilities to KEV Catalog

426/69 Thursday, August 6, 2026 CISA has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after finding evidence that they have been actively exploited in attacks. The vulnerabilities are CVE-2026-9198 in IBM Langflow, CVE-2026-18556 in N-able N-central, and CVE-2026-34486 in Apache Tomcat. These vulnerabilities could lead to remote code execution, authentication bypass, or […]

ThaiCERT

August 6, 2026

Greatness Phishing Service Impersonates RingCentral to Steal Microsoft 365 Accounts

425/69 Thursday, August 6, 2026 Reports indicate that Greatness, a Phishing-as-a-Service (PhaaS) platform, has evolved from credential theft to Adversary-in-the-Middle (AiTM) attacks and device-code phishing to target Microsoft 365 accounts. The platform has been active since 2022 and previously targeted Microsoft 365 users in the United States, Canada, the United Kingdom, Australia, and South Africa. […]

ThaiCERT

August 6, 2026

AI-Linked Email Accounts Could Become a New Insider Threat in Organizations

424/69 Thursday, August 6, 2026 Barracuda Red Team researchers have disclosed the results of an attack simulation highlighting a new risk posed by AI assistants in enterprise email systems. The researchers stated that the key danger is not that AI creates new access privileges for attackers, but that AI enables attackers to use access gained […]

ThaiCERT

August 6, 2026
1 … 11 12 13 … 118