Hackers Use SQL Injection Vulnerability to Deploy khunt Attack Tool Directly Inside Oracle Database

427/69 Friday, August 7, 2026 Cybersecurity researchers from Huntress reported detecting a cyberattack in late July 2026, in which hackers exploited a SQL Injection vulnerability to deploy a post-exploitation toolkit called khunt directly inside an organization’s Oracle database. The attack was carried out through a public-facing Java application running on Apache Tomcat. In this incident, […]

ThaiCERT

August 7, 2026

CISA Adds Actively Exploited Langflow, N-central, and Apache Tomcat Vulnerabilities to KEV Catalog

426/69 Thursday, August 6, 2026 CISA has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after finding evidence that they have been actively exploited in attacks. The vulnerabilities are CVE-2026-9198 in IBM Langflow, CVE-2026-18556 in N-able N-central, and CVE-2026-34486 in Apache Tomcat. These vulnerabilities could lead to remote code execution, authentication bypass, or […]

ThaiCERT

August 6, 2026

Greatness Phishing Service Impersonates RingCentral to Steal Microsoft 365 Accounts

425/69 Thursday, August 6, 2026 Reports indicate that Greatness, a Phishing-as-a-Service (PhaaS) platform, has evolved from credential theft to Adversary-in-the-Middle (AiTM) attacks and device-code phishing to target Microsoft 365 accounts. The platform has been active since 2022 and previously targeted Microsoft 365 users in the United States, Canada, the United Kingdom, Australia, and South Africa. […]

ThaiCERT

August 6, 2026

AI-Linked Email Accounts Could Become a New Insider Threat in Organizations

424/69 Thursday, August 6, 2026 Barracuda Red Team researchers have disclosed the results of an attack simulation highlighting a new risk posed by AI assistants in enterprise email systems. The researchers stated that the key danger is not that AI creates new access privileges for attackers, but that AI enables attackers to use access gained […]

ThaiCERT

August 6, 2026

Thermo Fisher Releases Fix for DNA Analysis Software Vulnerability That Could Affect Data Integrity

423/69 Wednesday, August 5, 2026 Thermo Fisher Scientific has released a security update to fix a Critical vulnerability, tracked as CVE-2026-17583, in its Applied Biosystems Human Identification software, which is used for forensic genetics data analysis and human identification. The vulnerability could allow threat actors to modify DNA analysis data files before they are imported […]

ThaiCERT

August 5, 2026

PNLD Confirms Data Breach Affecting Police Officers and Justice Sector Personnel

422/69 Wednesday, August 5, 2026 The Police National Legal Database (PNLD), a legal reference database used by all 43 Home Office police forces in England and Wales, has confirmed a data breach after contact information belonging to police officers, staff, and justice sector personnel was published on the dark web. The incident also affected Ask […]

ThaiCERT

August 5, 2026

Pass-ta-key Attack Found Allowing Windows Malware to Steal Passkey Data from Google Password Manager

421/69 Wednesday, August 5, 2026 Cybersecurity researchers have discovered a new attack technique called Pass-ta-key, which targets Google Password Manager in the Chrome browser on Windows systems using TPM chips. The attack affects devices that are already infected with malware and could allow threat actors to take over accounts, bypass authentication processes, and extract passkey […]

ThaiCERT

August 5, 2026

Google to Block Chrome Extensions That Change the New Tab Page Without Authorization

420/69 Tuesday, August 4, 2026 Google is preparing to add a new security feature in Chrome to block extensions that attempt to change the New Tab page or default search engine through enterprise policies on unmanaged Windows and macOS devices. The feature aims to reduce attacks involving browser hijacker extensions, which may redirect users to […]

ThaiCERT

August 4, 2026

CareCloud Discloses Data Breach Affecting 345,000 People After AWS-Hosted System Attack

419/69 Tuesday, August 4, 2026 CareCloud, a healthcare technology company based in New Jersey, United States, has disclosed a data breach affecting approximately 345,000 people after attackers stole medical and financial data from systems hosted by the company on Amazon Web Services (AWS). CareCloud provides Electronic Health Records (EHR), practice management systems, revenue cycle management, […]

ThaiCERT

August 4, 2026

CrowdStrike Says AI Has Become Both a Weapon and a Target in Modern Cyberattacks

418/69 Tuesday, August 4, 2026 CrowdStrike has released its annual threat report, stating that artificial intelligence (AI) has shifted from being a tool for cyber defense to becoming both a weapon and a target for attackers. AI-driven activity now clearly exceeds human-generated activity. On average, for every one human-generated signal, there are 2.5 AI-generated signals. […]

ThaiCERT

August 4, 2026
1 … 11 12 13 … 117