“HybridPetya”: New Ransomware Capable of Bypassing UEFI Secure Boot

340/68 Monday, September 15, 2025 Researchers have uncovered a new ransomware strain called “HybridPetya”, which merges features of the infamous Petya and NotPetya malware that caused devastating outbreaks in 2016–2017. The alarming aspect of HybridPetya lies in its ability to bypass the UEFI Secure Boot security mechanism, enabling it to implant malicious code into the […]

ThaiCERT

September 15, 2025

“RatOn” Android Malware Uses NFC Relay and ATS Techniques to Target Banks and Crypto

339/68 Friday, September 12, 2025 Security researchers from the Netherlands have uncovered a new Android malware strain called RatOn, which evolved from NFC relay tools into a sophisticated Remote Access Trojan (RAT). RatOn is equipped with Automated Transfer System (ATS) capabilities to manipulate financial transactions, combining features such as overlay attacks, automated transfers, and NFC […]

ThaiCERT

September 12, 2025

KillSec Ransomware Attacks MedicSolution, Compromises Healthcare Data in Brazil

338/68 Friday, September 12, 2025 The KillSec ransomware group has claimed responsibility for a cyberattack against MedicSolution, a Brazilian healthcare software provider, threatening to leak stolen data if negotiations are not initiated. According to a report by Resecurity, the incident stemmed from data exfiltration via an unsecured AWS S3 bucket, which had been left exposed […]

ThaiCERT

September 12, 2025

Warning: Akira Ransomware Gang Exploits SonicWall Vulnerabilities to Target Organizations Worldwide

337/68 Friday, September 12, 2025 Cybersecurity experts at Rapid7 have issued an urgent warning about escalating cyberattacks, as the Akira ransomware group has resumed exploiting vulnerabilities in SonicWall appliances. These include critical flaws that were already abused last year. Contrary to earlier suspicions of a new zero-day exploit, the attacks are leveraging known vulnerabilities such […]

ThaiCERT

September 12, 2025

Experts Say Red Sea Undersea Internet Cable Cut Likely an “Accident” Rather Than an Attack

336/68 Thursday, September 11, 2025 The recent incident involving the severing of undersea internet cables in the Red Sea over the weekend significantly reduced internet speeds in several countries, particularly in the Middle East, India, and Pakistan. The International Cable Protection Committee (ICPC) stated that the cause was most likely an accident related to maritime […]

ThaiCERT

September 11, 2025

SAP Releases Patches for Vulnerabilities in NetWeaver and S/4HANA

335/68 Thursday, September 11, 2025 SAP has issued security updates addressing multiple vulnerabilities, including three critical flaws affecting SAP NetWeaver and one high-severity flaw in SAP S/4HANA. The details are as follows: In addition, CVE-2025-42957 (CVSS 9.9) in S/4HANA, which was patched in August 2025, has already been confirmed as under active exploitation. While there […]

ThaiCERT

September 11, 2025

Australia’s Qantas Cuts Executive Pay Following Cyberattack

334/68 Thursday, September 11, 2025 Qantas Group, Australia’s largest airline, announced a 15% reduction in short-term performance-based compensation for senior executives, including current CEO Vanessa Hudson, amounting to $250,000. The decision was made to demonstrate accountability for the cyberattack earlier this year, which had a significant impact on customers. The pay cut was disclosed in […]

ThaiCERT

September 11, 2025

Lazarus Group Uses Fake Job Interviews to Spread ClickFix Malware in Cyberattacks

333/68 Wednesday, September 10, 2025 North Korea’s Lazarus hacking group has been leveraging the ClickFix technique to trick job seekers in the crypto and blockchain sector through fake job interviews. Victims are instructed to copy and paste malware-laden commands onto their systems, enabling attackers to steal data, siphon funds, and generate revenue to support the […]

ThaiCERT

September 10, 2025

GPUGate Malware Campaign Uses Google Ads and Fake GitHub Commits to Target IT Companies

332/68 Wednesday, September 10, 2025 Cybersecurity researchers have uncovered a new malware campaign called GPUGate, which targets IT and software development companies. The attackers rely on malvertising via Google Ads to trick users searching for popular tools such as GitHub Desktop into downloading malicious files. A key feature of this campaign is the use of […]

ThaiCERT

September 10, 2025

“MostereRAT” Malware Stealthily Evades Detection and Disables Security Software

331/68 Wednesday, September 10, 2025 A new report from Fortinet has revealed a cyberattack campaign involving MostereRAT (Mostere Remote Access Trojan), a malware specifically designed to stealthily infiltrate and maintain long-term control over Windows systems. What makes MostereRAT stand out is its use of an uncommon programming language, its ability to disable security software, and […]

ThaiCERT

September 10, 2025
1 2 3 43