Critical Vulnerability in Breeze Cache Plugin Puts Over 400,000 Websites at Risk

227/69 Monday, April 27, 2026 Researchers from Wordfence have disclosed a critical vulnerability, CVE-2026-3844 (CVSS 9.8), in the Breeze Cache plugin for WordPress, developed by Cloudways. The flaw allows unauthenticated file uploads to the server, potentially leading to remote code execution (RCE). The plugin is currently used by more than 400,000 websites, and at least […]

sittisak mintaboon

April 27, 2026

Warning: Fake CAPTCHA Scam Tricks Users into Sending International SMS, Causing Hidden Charges

226/69 Monday, April 27, 2026 Researchers from the Threat Intelligence team at Infoblox have uncovered a sophisticated global fraud campaign known as Click2SMS. In this scheme, attackers abuse familiar CAPTCHA verification systems as a tool for International Revenue Share Fraud (IRSF). The scam aims to drain money from victims’ accounts or mobile bills by tricking […]

sittisak mintaboon

April 27, 2026

Urgent Update: Apple Fixes iOS Flaw That Could Allow Recovery of Deleted Messages

225/69 Friday, April 24, 2026 Apple has released security updates to address vulnerability CVE-2026-28950 in iOS and iPadOS, after discovering an issue in the notification handling system that allowed deleted notification data to remain stored on devices. The flaw has been fixed in iOS 26.4.2, iPadOS 26.4.2, iOS 18.7.8, and iPadOS 18.7.8. Apple stated that […]

sittisak mintaboon

April 24, 2026

อัปเดตด่วน Apple แก้ไขช่องโหว่ iOS ที่อาจทำให้ข้อความที่ลบแล้วถูกกู้คืนได้

224/69 Friday, April 24, 2026 A report from Akamai reveals active exploitation of CVE-2025-29635, a command injection vulnerability affecting end-of-life D-Link DIR-823X routers. Attackers can send specially crafted POST requests to inject commands into the system and gain control of the device. The flaw stems from improper input validation, allowing user-controlled data to be passed […]

sittisak mintaboon

April 24, 2026

Kyber Ransomware Experiments with Post-Quantum Encryption, Targets Windows and VMware Simultaneously

223/69 Friday, April 24, 2026 A new ransomware group known as Kyber has been observed targeting critical enterprise infrastructure, particularly servers running on Windows and VMware ESXi. A major U.S.-based defense contractor and IT services provider has reportedly already fallen victim. The attackers use a Tor-based leak site called “Wall of Wonders” to pressure victims […]

sittisak mintaboon

April 24, 2026

CISA Adds 8 New Vulnerabilities to KEV After Evidence of Active Exploitation

222/69 Thursday, April 23, 2026 The Cybersecurity and Infrastructure Security Agency has added eight newly identified security vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming they are being actively exploited in the wild. These vulnerabilities affect products from multiple vendors, including PaperCut, JetBrains, Kentico, Quest Software, Synacor, and Cisco. These flaws pose risks […]

sittisak mintaboon

April 23, 2026

Crypto Platform Grinex Shuts Down After $13.7 Million Breach

221/69 Thursday, April 23, 2026 The cryptocurrency exchange Grinex announced a full suspension of its operations on April 16, 2026, after detecting a security incident that resulted in the loss of approximately 1 billion rubles (around $13.7 million). The company stated that the attack was highly sophisticated and suggested it may have involved Western intelligence […]

sittisak mintaboon

April 23, 2026

Betrayal in the Ranks: U.S. Ransomware Negotiator Leaked Sensitive Data to BlackCat to Inflate Ransom Demands

220/69 Thursday, April 23, 2026 The U.S. Department of Justice has revealed major developments in a significant cybercrime case involving 41-year-old Angelo Martino, a former ransomware negotiator who has pleaded guilty to conspiracy to commit extortion. Authorities found that Martino secretly collaborated with the BlackCat ransomware group in 2023. Acting as a negotiator for five […]

sittisak mintaboon

April 23, 2026

Fake TikTok Downloader Extensions on Chrome and Edge Spy on Over 130,000 Users

219/69 Wednesday, April 22, 2026 Researchers from LayerX have uncovered a malicious campaign named StealTok, which spreads through browser extensions on Google Chrome and Microsoft Edge. These extensions impersonate TikTok video download tools (no watermark), but their real purpose is to harvest user data and perform detailed device fingerprinting. The campaign has reportedly been active […]

sittisak mintaboon

April 22, 2026

France’s ANTS Identity Document System Hit by Cyberattack, Personal Data Potentially Exposed

218/69 Wednesday, April 22, 2026 France’s ANTS, which manages applications for essential identification documents such as national ID cards, passports, driver’s licenses, and residence permits, detected a cyberattack on April 15, 2026. The French Interior Ministry confirmed that the incident may have led to the exposure of certain personal data belonging to both individual users […]

sittisak mintaboon

April 22, 2026
1 2 3 88