U.S. Issues Cybersecurity Warning Following Airstrikes on Iranian Nuclear Facilities

232/68 Thursday, June 26, 2025 On June 13, 2025, the U.S. Department of Homeland Security (DHS) issued a cybersecurity warning, citing an increased risk of domestic cyber threats in the wake of U.S. airstrikes targeting Iranian nuclear infrastructure. The warning comes amid escalating tensions between Iran and Israel. DHS stated that pro-Iranian hacktivist groups and […]

ThaiCERT

June 26, 2025

New Spyware “SparkKitty” Found on App Store and Play Store, Targets Crypto via Photo Theft

231/68 Thursday, June 26, 2025 Cybersecurity firm Kaspersky has identified a new strain of spyware called SparkKitty, discovered hiding in applications on both the Apple App Store and Google Play Store. The spyware’s primary objective is to steal all images from a victim’s phone—specifically looking for pictures containing cryptocurrency-related information, such as wallet recovery phrases, […]

ThaiCERT

June 26, 2025

Citrix Patches Critical Vulnerabilities in NetScaler ADC and Gateway Amid “CitrixBleed” Fears

229/68 Wednesday, June 25, 2025 Citrix has released critical security patches for vulnerabilities affecting its NetScaler ADC and NetScaler Gateway products, addressing serious flaws including CVE-2025-5777, which carries a CVSS score of 9.3. This vulnerability is classified as an out-of-bounds read, resulting from insufficient input validation. It allows attackers to craft specially designed requests to […]

ThaiCERT

June 25, 2025

CoinMarketCap Suffers Supply Chain Attack Using Fake Web3 Popup to Steal Crypto

228/68 Tuesday, June 24, 2025 On June 20, 2025, cryptocurrency price tracking platform CoinMarketCap experienced a supply chain attack that led to the injection of a malicious wallet drainer script into its homepage. During the incident, users who visited the site encountered a fake Web3 popup that mimicked a “Connect Wallet” prompt. Upon connecting, the […]

ThaiCERT

June 24, 2025

Qilin Ransomware Introduces “Call Lawyer” Feature to Pressure Victims into Paying Ransom

227/68 Tuesday, June 24, 2025 The Qilin ransomware group has escalated its operations by launching a new feature called “Call Lawyer”, offering legal advisory services to its affiliates to help pressure victims into paying ransom. According to cybersecurity firm Cybereason, Qilin is aiming to position itself as a major player in the Ransomware-as-a-Service (RaaS) ecosystem, […]

ThaiCERT

June 24, 2025

Iran Shuts Down Nationwide Internet Access to Counter Cyberattacks from Israel and Protect Critical Infrastructure

226/68 Monday, June 23, 2025 The Iranian government has officially confirmed that it has restricted nationwide internet access in response to escalating cyber tensions with Israel. Officials stated that the move was aimed at protecting critical infrastructure from cyberattacks and preventing adversaries from remotely controlling drones via internet networks. According to reports by Iranian news […]

ThaiCERT

June 23, 2025

Cloudflare Mitigates Record-Breaking 7.3 Tbps DDoS Attack

225/68 Monday, June 23, 2025 In May 2025, Cloudflare—one of the world’s leading web infrastructure and cybersecurity companies—announced that it successfully mitigated the largest Distributed Denial of Service (DDoS) attack ever recorded, which peaked at a staggering 7.3 terabits per second (Tbps). The attack targeted a hosting provider and exceeded the previous record by 12%, […]

ThaiCERT

June 23, 2025

Veeam Patches Critical RCE Vulnerability in Backup & Replication

224/68 Friday, June 20, 2025 Veeam has released a security update to address a critical vulnerability in its Backup & Replication product. The flaw, tracked as CVE-2025-23121 and rated CVSS 9.9, allows authenticated domain users to execute arbitrary code remotely on the Backup Server, potentially leading to full system compromise. This vulnerability affects versions 12.3.1.1139 […]

ThaiCERT

June 20, 2025

Russian Hackers Bypass Gmail 2FA Using App-Specific Passwords in Sophisticated Phishing Campaign

223/68 Friday, June 20, 2025 A Russian state-linked hacking group has been detected using a highly targeted phishing technique that bypasses Gmail’s two-factor authentication (2FA) by exploiting a lesser-known Google feature called App-Specific Passwords (ASPs). According to Google’s Threat Intelligence Group, the campaign ran from April to early June, with attackers impersonating officials from the […]

ThaiCERT

June 20, 2025
1 22 23 24 53