Google Releases Patch for Fourth Chrome Zero-Day of 2026 Exploited in the Wild

191/69 Friday, April 3, 2026 Google has released a security update for its Chrome browser to address 21 vulnerabilities, including a zero-day flaw that has already been actively exploited in the wild. The vulnerability, tracked as CVE-2026-5281, is a Use-After-Free (UAF) issue in the WebGPU Dawn component, which is responsible for graphics processing. Google confirmed […]

sittisak mintaboon

April 3, 2026

New “CrystalRAT” Malware Sold as a Subscription Service Bundling Spyware, Stealer, and Prank Features in One Package

190/69 Friday, April 3, 2026 Security researchers from Kaspersky have discovered a new malware strain named CrystalRAT (also known as CrystalX), which is being promoted as a Malware-as-a-Service (MaaS) offering via platforms like Telegram and YouTube. Written in Go and showing similarities to earlier threats such as WebRAT, this malware adopts a tiered subscription model […]

sittisak mintaboon

April 3, 2026

Multiple Vulnerabilities in CrewAI Allow Sandbox Escape and Remote Code Execution via Prompt Injection

189/69 Thursday, April 2, 2026 Four security vulnerabilities have been discovered in CrewAI, an open-source Python framework for managing AI multi-agent systems. These flaws could enable a range of attacks, including remote code execution (RCE). The primary issue originates from the Code Interpreter component, which is designed to safely execute Python code inside a Docker […]

sittisak mintaboon

April 2, 2026

Lloyds Banking Group Incident Exposes Transaction Data of Over 450,000 Customers

188/69 Thursday, April 2, 2026 Lloyds Banking Group has disclosed a data security incident caused by a faulty software update on March 12, which led to the exposure of transaction data belonging to nearly 450,000 mobile banking users. The issue allowed some customers to view other users’ transaction details within the mobile application. The incident […]

sittisak mintaboon

April 2, 2026

Google Allows Users to Change @gmail.com Email Addresses, Rollout Begins in the U.S.

187/69 Thursday, April 2, 2026 Google has started rolling out a long-awaited feature that allows users to change their primary email address—specifically the part before “@gmail.com.” Previously, this portion of a Gmail address was permanently fixed, and users could only create aliases or secondary email addresses. The feature has initially been spotted among users in […]

sittisak mintaboon

April 2, 2026

CareCloud Reports Cyberattack Impacting Electronic Health Records (EHR) Systems

186/69 Wednesday, April 1, 2026 CareCloud, Inc., a healthcare company based in New Jersey, disclosed in a filing with the U.S. Securities and Exchange Commission (SEC) that it detected a system intrusion on March 16, 2026. The incident caused a temporary disruption to CareCloud Health services for approximately eight hours. It impacted one of the […]

sittisak mintaboon

April 1, 2026

Critical Vulnerability in OpenAI Codex Could Allow GitHub Token Theft via Unicode Injection

185/69 Wednesday, April 1, 2026 Researchers from BeyondTrust Phantom Labs have disclosed a critical vulnerability in OpenAI Codex that could be exploited to steal GitHub OAuth tokens. The flaw is a command injection vulnerability caused by insufficient input sanitization, allowing attackers to embed malicious commands within GitHub branch names. Notably, the attack leverages special Unicode […]

sittisak mintaboon

April 1, 2026

RoadK1ll Malware Uses WebSocket Tunneling to Enable Stealthy Internal Network Intrusions

184/69 Wednesday, April 1, 2026 Cybersecurity researchers from Blackpoint Cyber have identified a new malware strain called RoadK1ll, a Node.js-based implant designed to act as a relay point for lateral movement within compromised networks. The malware operates stealthily by blending in with normal network traffic, transforming infected machines into controlled pivot points that attackers can […]

sittisak mintaboon

April 1, 2026

Apple Issues Urgent Lock Screen Alerts, Urges iPhone and iPad Users to Update Software to Prevent Data Theft

183/69 Tuesday, March 31, 2026 Apple has begun sending “Critical Software” alerts directly to the lock screens of iPhone and iPad users running outdated versions of iOS and iPadOS. The notifications warn of web-based attacks targeting older, unpatched software versions. The alerts have appeared on a wide range of devices, including those running iOS 17.0, […]

sittisak mintaboon

March 31, 2026

Critical Vulnerability in Smart Slider 3 Plugin Affects Over 500,000 WordPress Sites, Risking Data Exposure

182/69 Tuesday, March 31, 2026 A security vulnerability has been discovered in the widely used Smart Slider 3 plugin for WordPress, which is installed on more than 800,000 websites. The flaw, tracked as CVE-2026-3098, allows low-privileged users such as Subscribers to access sensitive files on the server, including wp-config.php, which contains critical information such as […]

sittisak mintaboon

March 31, 2026
1 2 3 84