JINX-0164 Targets Cryptocurrency Firms Through Fake Recruitment Campaigns and macOS Malware

294/69 Friday, May 29, 2026 Researchers from Wiz have reported attacks carried out by a threat group tracked as JINX-0164, which targets cryptocurrency organizations. The group uses social engineering techniques through LinkedIn or impersonates recruiters and business partners to persuade victims to join online meetings. Victims are then directed to fake domains that imitate remote […]

sittisak mintaboon

May 29, 2026

Dutch Police Arrest Suspect Linked to Ajax Football Club Cyberattack

293/69 Friday, May 29, 2026 The Dutch National Police arrested a 35-year-old man suspected of being involved in multiple unauthorized intrusions into the computer systems of Ajax Amsterdam, also known as AFC Ajax, earlier in 2026. According to the police, the suspect unlawfully accessed the club’s computer systems several times. After the incident was reported, […]

sittisak mintaboon

May 29, 2026

U.S. Court Sentences Romanian Hacker to Nearly Five Years in Prison for Illegally Breaching Government Agency Networks

292/69 Friday, May 29, 2026 The U.S. Department of Justice (DoJ) announced that a 45-year-old Romanian hacker has been sentenced to four years and eight months in prison, followed by three years of supervised release. The sentence stems from unauthorized intrusions into the network of an emergency management agency in the State of Oregon in […]

sittisak mintaboon

May 29, 2026

Anthropic Enhances Claude Code Security with a Plugin to Detect Risky Code During Development

291/69 Thursday, May 28, 2026 Anthropic has introduced new security features for Claude, including a Self-hosted Sandbox for Claude Managed Agents and a Security Guidance Plugin for Claude Code. The Self-hosted Sandbox is currently available in Public Beta and is designed to allow Agent tools or code execution to run within an environment controlled by […]

sittisak mintaboon

May 28, 2026

Cybersecurity Firms Collaborate to Disrupt Glassworm Botnet After Fake Packages and Tools Were Used to Target Developers

290/69 Thursday, May 28, 2026 On May 26, 2026, CrowdStrike Counter Adversary Operations, in collaboration with Google and the Shadowserver Foundation, reportedly disrupted all four Command-and-Control (C2) channels used by the Glassworm Botnet at the same time. The operation aimed to stop communication between the malware and the attackers’ infrastructure. Glassworm is a campaign that […]

sittisak mintaboon

May 28, 2026

Zero-Day Exploitation of KnowledgeDeliver to Deploy Web Shell and Malware

289/69 Thursday, May 28, 2026 There have been reports of threat actors exploiting a critical zero-day vulnerability, tracked as CVE-2026-5426, in KnowledgeDeliver, a Learning Management System (LMS) platform. The vulnerability allows unauthenticated attackers to remotely execute malicious commands on the operating system. This threat directly affects organizations using vulnerable installations of the platform prior to […]

sittisak mintaboon

May 28, 2026

Microsoft Releases Security Updates Addressing RCE Vulnerability in SharePoint Server

288/69 Wednesday, May 27, 2026 Microsoft has released security updates to address a Remote Code Execution (RCE) vulnerability in Microsoft SharePoint Server tracked as CVE-2026-45659. The vulnerability has a CVSS severity score of 8.8 and is caused by the deserialization of untrusted data within SharePoint Server. The vulnerability could allow an authenticated attacker with minimal […]

sittisak mintaboon

May 27, 2026

Lazarus APT Deploys Fileless RemotePE RAT Operating Entirely in Memory to Evade Detection

287/69 Wednesday, May 27, 2026 Reports indicate that the Lazarus Group APT group has developed and deployed a new Remote Access Trojan (RAT) known as “RemotePE,” designed to operate entirely in the memory of compromised systems. Because the malware leaves almost no traces on disk, forensic analysis and retrospective investigation become significantly more difficult. Researchers […]

sittisak mintaboon

May 27, 2026

Megalodon Supply Chain Attack Impacts More Than 5,500 GitHub Repositories, Targeting Sensitive System Credentials

286/69 Wednesday, May 27, 2026 Cybersecurity researchers have reported the discovery of a large-scale supply chain attack campaign known as “Megalodon,” which has impacted more than 5,500 repositories on GitHub. The campaign primarily targets the theft of sensitive credentials, passwords, API keys, and other secrets used in software development environments. The incident is considered highly […]

sittisak mintaboon

May 27, 2026

iPhone Users Urged to Update iOS and WhatsApp Following Reports of Unauthorized Messaging Activity

285/69 Tuesday, May 26, 2026 Reports have emerged of multiple iPhone users in Italy having their WhatsApp accounts hijacked and used to send unauthorized messages, despite victims not clicking malicious links, scanning QR codes, entering verification codes, or linking new devices. Attackers reportedly used compromised accounts to send money transfer requests to recently contacted individuals. […]

sittisak mintaboon

May 26, 2026
1 11 12 13 104