Oracle Notifies Customers Following Data Breach Allegedly Involving Cloud Credentials

134/68 Tuesday, April 8, 2025 Oracle has confirmed a data breach incident and has begun privately notifying affected customers. While the company appears to be downplaying the severity of the breach, a hacker going by the alias rose87168 claims to have accessed millions of records from Oracle Cloud, including encrypted credentials for over 140,000 users. […]

ThaiCERT

April 8, 2025

Beware: SMS Phishing Campaign Impersonates E-ZPass Toll Collection Services

133/68 Tuesday, April 8, 2025 A growing SMS phishing campaign is targeting users by impersonating E-ZPass and other toll collection agencies such as FasTrak and the Florida Turnpike. Victims are receiving fraudulent iMessages and SMS messages designed to steal personal and credit card information. The messages typically claim that the recipient has unpaid toll fees […]

ThaiCERT

April 8, 2025

Cisco Patches Critical Vulnerabilities in Meraki Devices and Enterprise Chat System

131/68 Friday, April 4, 2025 Cisco has released patches for two critical security vulnerabilities that could lead to Denial-of-Service (DoS) attacks targeting Meraki MX and Meraki Z devices, as well as the Enterprise Chat and Email (ECE) platform. The first flaw, CVE-2025-20212, affects the VPN AnyConnect server and allows an authenticated attacker to force the […]

ThaiCERT

April 4, 2025

Microsoft Warns of Critical Vulnerability in Canon Printer Drivers Allowing Code Execution

130/68 Thursday, April 3, 2025 Microsoft’s MORSE (Microsoft Offensive Research and Security Engineering) team has discovered a critical vulnerability, tracked as CVE-2025-1268 (CVSS 9.4), affecting Canon printer drivers. The vulnerability is classified as an out-of-bounds issue that impacts various printer driver models, including those for production printers, office/small office multifunction printers, and laser printers—particularly during […]

ThaiCERT

April 3, 2025

Over 1,500 PostgreSQL Servers Compromised in Fileless Cryptocurrency Mining Campaign

129/68 Thursday, April 3, 2025 Cybersecurity researchers at Wiz have uncovered an ongoing campaign targeting externally accessible PostgreSQL servers, exploiting weak or easily guessable credentials to deploy fileless cryptocurrency mining malware. One of the key payloads used in this campaign is a malware strain called PG_MEM, which was first detected by Aqua Security in August […]

ThaiCERT

April 3, 2025

CISA Adds Cisco Smart Licensing Utility Flaws to Known Exploited Vulnerabilities Catalog

128/68 Wednesday, April 2, 2025 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two high-severity vulnerabilities in Cisco Smart Licensing Utility to its Known Exploited Vulnerabilities (KEV) Catalog: Although there was no evidence of active exploitation initially, once vulnerability details were published by researcher Nicholas Starke, associated attack activity began to surface. The […]

ThaiCERT

April 2, 2025

‘Lucid’ Phishing Platform Behind Global SMS Attacks on iOS and Android

127/68 Wednesday, April 2, 2025 Researchers at Prodaft have uncovered that Lucid, a Phishing-as-a-Service (PhaaS) platform operated by the Chinese cybercriminal group XinXin, is behind a wave of targeted SMS phishing attacks affecting 169 victims across 88 countries. Lucid provides Telegram-registered members with access to automated phishing site generators, over 1,000 domains, and fake messaging […]

ThaiCERT

April 2, 2025

CISA Warns of RESURGE Malware Exploiting Ivanti Connect Secure Vulnerability

126/68 Tuesday, April 1, 2025 The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a new malware strain named RESURGE, which is actively exploiting CVE-2025-0282, a vulnerability in Ivanti Connect Secure (ICS) appliances. In a recently published Malware Analysis Report (MAR), CISA highlights that RESURGE exhibits behaviors similar to SPAWNCHIMERA malware, but […]

ThaiCERT

April 1, 2025

Crocodilus Banking Trojan Targets Android Users to Steal Financial and Crypto Wallet Data

125/68 Tuesday, April 1, 2025 Cybersecurity researchers at ThreatFabric have discovered a new Android banking trojan named Crocodilus, which is actively targeting users in Spain and Turkey. Designed to take full control of infected devices, the malware leverages advanced techniques such as remote access, screen recording, and overlay attacks to steal user credentials. Crocodilus disguises […]

ThaiCERT

April 1, 2025
1 2 3 4 24