Google Revamps Bug Bounty Strategy, Raises Android Rewards to $1.5 Million to Counter AI-Era Cyber Threats

241/69 Tuesday, May 5, 2026 Google has announced a major overhaul of its Vulnerability Reward Programs (VRP) for both Android and Chrome, adapting to a new era where artificial intelligence plays a significant role in bug discovery. Reports indicate that advanced AI tools-such as GPT-5.4 Cyber-can rapidly analyze code and help generate attack models, leading […]

sittisak mintaboon

May 5, 2026

Backdoor Discovered in Quick Page/Post Redirect Plugin, Putting Websites at Risk of External Code Injection

240/69 Friday, May 1, 2026 Security researchers from Anchor Hosting have revealed that the Quick Page/Post Redirect WordPress plugin—used for creating redirects and installed on over 70,000 websites—has contained a hidden backdoor since 2020. The issue was identified after abnormal activity alerts were detected across 12 managed websites. Investigation found that versions 5.2.1 and 5.2.2 […]

sittisak mintaboon

May 1, 2026

cPanel Patches Authentication Vulnerability Affecting All Supported Versions

239/69 Friday, May 1, 2026 cPanel has released a security update to address an authentication vulnerability that could allow unauthorized access to server control panels. The flaw affects all currently supported versions and poses a significant risk to systems exposed to the internet. cPanel is a widely used web hosting control panel that enables users […]

sittisak mintaboon

May 1, 2026

Japan’s Financial Sector on Alert Over Mythos, Fears Advanced Vulnerability Discovery Capabilities

238/69 Friday, May 1, 2026 On April 24, senior executives in Japan’s financial sector formed a special task force to address potential cyber threats posed by Mythos, an AI model developed by Anthropic and described as a “super hacker.” Concerns were raised after testing reportedly showed that Mythos could identify previously unknown vulnerabilities across all […]

sittisak mintaboon

May 1, 2026

SQL Injection Vulnerability Found in LiteLLM Exposes Risk of Secret and Key Disclosure

237/69 Thursday, April 30, 2026 A critical vulnerability, CVE-2026-42208, has been actively exploited in LiteLLM, an open-source gateway for large language models (LLMs). The flaw is an unauthenticated SQL injection vulnerability that occurs during the proxy API key validation process. Attackers can exploit this issue by sending specially crafted Authorization headers to LiteLLM API endpoints, […]

sittisak mintaboon

April 30, 2026

Vimeo Confirms Data Breach Linked to Anodot Incident, Impacting Some User Data

236/69 Thursday, April 30, 2026 Vimeo, a global video hosting and streaming platform, has confirmed an incident involving unauthorized access to data, stemming from a security breach at Anodot. According to the company’s initial investigation, the affected data primarily includes technical information, video titles, and metadata. In some cases, user and customer email addresses were […]

sittisak mintaboon

April 30, 2026

Infighting in the Ransomware Scene: 0APT vs. KryBit Leads to Data Leaks

235/69 Thursday, April 30, 2026 A report from the Halcyon Ransomware Research Center has revealed a major conflict within the cybercriminal ecosystem, as two emerging ransomware groups-0APT and KryBit-engaged in a heated feud that escalated into mutual hacking and public data exposure. The conflict began when 0APT attempted to build its reputation by claiming it […]

sittisak mintaboon

April 30, 2026

CVE-2026-6770 Vulnerability Found in Firefox and Tor Browser, Risk of Cross-Site Fingerprinting Tracking

234/69 Wednesday, April 29, 2026 Researchers have discovered a vulnerability, CVE-2026-6770, affecting Mozilla Firefox, Mozilla Thunderbird, and Tor Browser, classified as a medium-severity issue. This flaw may allow websites to generate unique identifiers for fingerprinting, enabling the tracking of user activity across different websites—even when users are in Private Browsing mode or using Tor Browser, […]

sittisak mintaboon

April 29, 2026

Medtronic Confirms Cybersecurity Incident After ShinyHunters Claims Theft of Over 9 Million Records

233/69 Wednesday, April 29, 2026 Medtronic, a global medical device manufacturer, has confirmed a cybersecurity incident affecting its internal IT systems after the cybercrime group ShinyHunters claimed it had accessed and stolen more than 9 million records. The company stated that it detected unauthorized access to certain parts of its IT environment but has not […]

sittisak mintaboon

April 29, 2026

Warning: 82 Chrome Extensions Found Collecting and Selling Personal Data, Affecting Over 6.5 Million Users

232/69 Wednesday, April 29, 2026 A 2026 report by LayerX Security reveals that at least 82 extensions on Google Chrome have been found secretly collecting users’ personal data and selling it to third parties, impacting more than 6.5 million users worldwide. Notably, these tools are not traditional malware. Instead, they explicitly disclose data-sharing practices in […]

sittisak mintaboon

April 29, 2026
1 11 12 13 99