Warning for Users of Legacy D-Link Routers: Critical Vulnerability “CVE-2026-0625” Actively Exploited – Immediate Device Replacement Recommended Due to No Available Patch

10/69 Thursday, January 8, 2026 A critical security vulnerability, CVE-2026-0625, has been identified in several legacy D-Link router models that have already reached End-of-Life (EoL). The vulnerability is a Command Injection flaw in a CGI library, specifically at the dnscfg.cgi endpoint, caused by insufficient input validation. This flaw allows unauthenticated attackers to execute arbitrary commands […]

ThaiCERT

January 8, 2026

Chrome Extension “Claude” Poses Security Risks as Hackers Could Abuse AI to Steal Tokens and Execute Cross-Site Scripts

09/69 Wednesday, January 7, 2026 Security researchers from Zenity Labs have warned about potential security risks associated with Anthropic’s “Claude in Chrome” extension, which enables the AI to directly browse websites, fill out forms, and interact with web applications on behalf of users. Because the extension remains logged in at all times, Claude effectively gains […]

ThaiCERT

January 7, 2026

Ledger Customers Impacted by Data Breach at Third-Party Provider Global-e

08/69 Wednesday, January 7, 2026 Ledger, the manufacturer of self-custodial hardware wallets for digital assets, has notified some customers that their personal information may have been affected by a data breach involving its third-party payment service provider, Global-e. The company emphasized that the incident did not impact Ledger’s own network, hardware, or software systems, and […]

ThaiCERT

January 7, 2026

New ClickFix Attack Campaign Uses Fake Windows Blue Screen (BSOD) to Trick Victims Into Installing Malware

07/69 Wednesday, January 7, 2026 Security researchers from Securonix have identified a new cyberattack campaign dubbed PHALT#BLYX, targeting businesses in the travel and hospitality sector. Attackers send phishing emails impersonating customers from Booking[.]com, claiming to cancel hotel reservations and requesting unusually large refunds to create a sense of urgency. When employees click the link in […]

ThaiCERT

January 7, 2026

“VVS Stealer” Infostealer Malware Evades Detection, Targets Discord Accounts and Browser Data

06/69 Tuesday, January 6, 2026 Cybersecurity researchers have identified a new information-stealing malware strain called VVS Stealer, developed in Python and heavily obfuscated using the PyArmor tool to evade security detection. The malware has been sold on Telegram since April 2025 at prices starting as low as €10 (approximately USD 11), and is primarily designed […]

ThaiCERT

January 6, 2026

Sedgwick Discloses Data Breach Following TridentLocker Ransomware Attack

05/69 Tuesday, January 6, 2026 Sedgwick, a global provider of claims management and risk administration services, has disclosed a cybersecurity incident affecting one of its U.S. government contracting units, Sedgwick Government Solutions, after the TridentLocker ransomware group claimed it had accessed and exfiltrated approximately 3.4 GB of data. The incident was publicly disclosed around New […]

ThaiCERT

January 6, 2026

New Phishing Campaign Abuses Google Cloud Features to Send Highly Convincing Emails That Evade Detection

04/69 Tuesday, January 6, 2026 Cybersecurity researchers from Check Point have revealed a newly discovered phishing campaign that employs a sophisticated technique by abusing Google Cloud Application Integration, an automation feature provided by Google, to send fraudulent emails to victims. What makes this campaign particularly concerning is that the phishing emails are sent from a […]

ThaiCERT

January 6, 2026

Finland Seizes Cargo Vessel Over Suspected “Sabotage” After Anchor Dragged and Severed Undersea Internet Cables

03/69 Monday, January 5, 2026 Finnish authorities have seized a cargo vessel and detained its crew following an incident in which an undersea internet cable operated by Elisa, connecting Finland and Estonia, was severed in the early hours of New Year’s Day. Finland’s maritime authorities reported that the vessel was observed dragging its anchor across […]

ThaiCERT

January 5, 2026

Covenant Health Data Breach Following Ransomware Attack Impacts More Than 478,000 Individuals

02/69 Monday, January 5, 2026 Covenant Health, a U.S.-based healthcare organization, disclosed that it suffered a ransomware cyberattack in May 2025, resulting in the unauthorized access to personal and health information of more than 478,000 individuals. Covenant Health provides medical services through hospitals and healthcare facilities across several states, including Massachusetts, Maine, New Hampshire, Pennsylvania, […]

ThaiCERT

January 5, 2026

Over 10,000 Fortinet Firewalls Worldwide Still Vulnerable to 2FA Bypass Attacks

01/69 Monday, January 5, 2026 Recent data from Shadowserver reveals that more than 10,000 Fortinet firewall devices remain exposed to the internet without having applied critical security patches and are actively at risk of exploitation via CVE-2020-12812, a severe vulnerability first disclosed in 2020. Statistics indicate that Asia is the most affected region, with over […]

ThaiCERT

January 5, 2026
1 11 12 13 76