FortiBleed Exposes Large-Scale Credential Spraying Campaign Targeting Fortinet VPNs Worldwide

335/69 Monday, June 22, 2026 Reports indicate that FortiBleed has exposed a large-scale attack campaign that attempted to log in to Fortinet VPNs through billions of Credential Spraying attempts, resulting in compromises of multiple organizations worldwide. The incident was discovered by Volodymyr “Bob” Diachenko, a researcher from SecurityDiscovery.com, after the attackers’ infrastructure was exposed on […]

chanapon

June 22, 2026

The Gentlemen Ransomware Group Uses GentleKiller Tool to Exploit Driver Vulnerabilities and Disable Security Systems

334/69 Monday, June 22, 2026 ESET has published an investigation into the infrastructure of the Ransomware-as-a-Service group known as The Gentlemen, which has been active since late 2025 and has claimed more than 504 victims. Its primary targets are in Southeast Asia, South America, and Western Europe. What makes this group notable is not only […]

chanapon

June 22, 2026

Supply Chain Attack Through ShapedPlugin Update System Impacts WordPress Websites

333/69 Friday, June 19, 2026 Security researchers have disclosed a supply chain attack affecting ShapedPlugin’s premium WordPress plugins. Attackers were able to inject malicious code into plugin packages distributed through the vendor’s official update infrastructure, meaning website administrators who installed or updated affected plugins through legitimate channels may have unknowingly received compromised files. According to […]

sittisak mintaboon

June 19, 2026

Kodak Confirms Data Breach After ShinyHunters Claims Theft of More Than 2.2 Million Records

332/69 Friday, June 19, 2026 Kodak has confirmed that it is working with external cybersecurity experts to investigate a data breach after attackers gained unauthorized access to a portion of the company’s data. Kodak, formally known as Eastman Kodak Company, was founded in 1880 and is headquartered in Rochester, New York. The company operates in […]

sittisak mintaboon

June 19, 2026

Beware of Crypto-Stealing Malware Leveraging Fake Review Networks to Build Trust and Deceive Users

331/69 Friday, June 19, 2026 Cybersecurity researchers have uncovered a new cybercrime campaign targeting cryptocurrency holders and digital asset investors seeking quick profits. The attackers use sophisticated trust-building techniques to trick victims into downloading and installing malware on their devices. What makes this campaign particularly noteworthy is that the threat actors do not rely solely […]

sittisak mintaboon

June 19, 2026

Steam Workshop Used to Distribute Malware Through Wallpaper Engine, Risking Steam Account Compromise and Backdoor Installation

330/69 Thursday, June 18, 2026 Security researchers have uncovered a malware campaign leveraging Steam Workshop as a distribution channel for malicious files through wallpapers created for Wallpaper Engine. The attackers abuse the platform’s application wallpapers feature, a wallpaper type that allows Windows applications to run as wallpapers. As a result, seemingly harmless wallpaper files can […]

sittisak mintaboon

June 18, 2026

FulcrumSec Claims Theft of 1.3 TB of Data from Novo Nordisk Following Unauthorized System Access Incident

329/69 Thursday, June 18, 2026 Reports indicate that the hack-and-leak cybercriminal group FulcrumSec has claimed responsibility for breaching and stealing approximately 1.3 terabytes of data from Novo Nordisk, the Danish pharmaceutical giant behind major diabetes and weight-management medications such as Ozempic, Wegovy, Rybelsus, Victoza, and Saxenda, as well as several insulin products. The group’s claim […]

sittisak mintaboon

June 18, 2026

New Android Malware “Rokarolla” Targets Financial Applications and Cryptocurrency Wallets

328/69 Thursday, June 18, 2026 Researchers have identified a new Android malware strain named Rokarolla, which has been specifically developed to target more than 217 financial and cryptocurrency applications. The malware is distributed through fraudulent websites masquerading as legitimate download sources for popular applications such as Google Chrome and TikTok. Once installed, Rokarolla can obtain […]

sittisak mintaboon

June 18, 2026

Microsoft 365 Copilot Vulnerability Could Allow Data Theft Through a Link Click

327/69 Wednesday, June 17, 2026 Security researchers have disclosed a vulnerability in Microsoft 365 Copilot Enterprise Search, known as SearchLeak, which could allow attackers to steal data from emails, files in SharePoint and OneDrive, as well as MFA codes or one-time verification codes. The attack could be carried out by tricking a victim into clicking […]

chanapon

June 17, 2026

Mackay Sugar, Major Australian Sugar Producer, Reports Cyberattack Affecting Operations

326/69 Wednesday, June 17, 2026 Mackay Sugar, one of Australia’s major sugar producers, disclosed that the company experienced a cyberattack on June 10, 2026, which affected some of its operations. Mackay Sugar operates three main sugar mills: Farleigh, Marian, and Racecourse, with an annual raw sugar production capacity of approximately 700,000 tonnes for both domestic […]

chanapon

June 17, 2026
1 11 12 13 108