Spanish Police Arrest Suspect for Hacking Hotel Booking System, Paying Just 1 Cent per Night

110/69 Tuesday, February 24, 2026 Spanish police have arrested a 20-year-old man in Madrid on allegations that he manipulated the payment system of a hotel and travel booking website to secure luxury room reservations for just €0.01 per night. The actual room rates reportedly reached up to €1,000 per night, resulting in losses exceeding €20,000 […]

sittisak mintaboon

February 24, 2026

Researchers Reveal 27 Attack Techniques Against Leading Password Managers, Warning of Data Exposure If Servers Are Compromised

109/69 Tuesday, February 24, 2026 A research team from ETH Zurich and the Università della Svizzera italiana, led by Professor Kenneth Paterson, has published alarming findings about popular password management services such as Bitwarden, LastPass, and Dashlane. The study challenges the widely promoted concept of “zero-knowledge encryption”-which claims that service providers cannot access user data-suggesting […]

sittisak mintaboon

February 24, 2026

CISA Adds Two Roundcube Vulnerabilities to KEV After Confirmed Active Exploitation

108/69 Monday, February 23, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting Roundcube Webmail to its Known Exploited Vulnerabilities (KEV) catalog after confirming evidence of active exploitation. The vulnerabilities include: Security firm FearsOff, which discovered CVE-2025-49113, reported that attackers were able to analyze and weaponize the vulnerability within just […]

sittisak mintaboon

February 23, 2026

PayPal Discloses Six-Month Data Exposure Caused by Software Error in Lending App

107/69 Monday, February 23, 2026 PayPal has disclosed a data exposure incident stemming from a software error in its PayPal Working Capital (PPWC) platform, a business lending application. The flaw resulted in the unauthorized exposure of certain customers’ personal information between July 1 and December 13, 2025. Affected data included names, email addresses, phone numbers, […]

sittisak mintaboon

February 23, 2026

Predator Spyware Stealthily Disables Camera and Microphone Indicators on iOS

106/69 Monday, February 23, 2026 Researchers from Jamf, a company specializing in mobile device management, have disclosed new technical details about the “Predator” spyware developed by Intellexa. The spyware is capable of bypassing a key Apple privacy feature by suppressing the recording indicators-the green and orange dots displayed in the iPhone’s status bar when the […]

sittisak mintaboon

February 23, 2026

Researchers Discover 16 Vulnerabilities in Foxit and Apryse PDF Platforms, Risking Account Takeover and Data Theft

105/69 Friday, February 20, 2026 Researchers from security firm Novee have disclosed the discovery of 16 security vulnerabilities affecting PDF document management platforms, including Apryse WebViewer and Foxit PDF Cloud. The findings were assisted by AI agents used during the analysis process. The vulnerabilities range in severity from medium to critical and could potentially be […]

sittisak mintaboon

February 20, 2026

Spanish Court Orders NordVPN and ProtonVPN to Block LaLiga Piracy Websites

104/69 Friday, February 20, 2026 A Spanish court has issued precautionary measures against major VPN providers NordVPN and ProtonVPN, ordering both companies to block 16 websites involved in illegally streaming LaLiga football matches. The order applies to IP addresses within Spain and provides no opportunity for appeal. The ruling was issued inaudita parte, meaning it […]

sittisak mintaboon

February 20, 2026

Cybersecurity and Infrastructure Security Agency Warns of Critical Vulnerability in Honeywell CCTV Cameras Allowing Account Takeover and Live Feed Access

103/69 Friday, February 20, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory regarding a critical vulnerability affecting multiple Honeywell CCTV camera models. The flaw, tracked as CVE-2026-1670, carries a severity score of 9.8/10 and allows attackers to bypass authentication remotely. Successful exploitation could directly impact business environments and even […]

sittisak mintaboon

February 20, 2026

Notepad++ Enhances Update Security with “Double-Lock” Mechanism to Mitigate Supply Chain Threats

102/69 Thursday, February 19, 2026 Notepad++ has released version 8.9.2 to address vulnerabilities in its automatic update system that were previously exploited in a supply chain attack. The new release introduces a “Double-lock” security mechanism, implementing two layers of verification: This dual-verification process ensures that update files delivered to users have not been tampered with […]

sittisak mintaboon

February 19, 2026

CISA Adds Four Actively Exploited Vulnerabilities to KEV, Urges Immediate Remediation

101/69 Thursday, February 19, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after confirming evidence of active exploitation. The newly added vulnerabilities are: Regarding CVE-2026-2441, Google has confirmed active exploitation in the wild. However, detailed technical information about the attack techniques has […]

sittisak mintaboon

February 19, 2026
1 2 3 76