Phishing Campaign via Microsoft Teams Installs A0Backdoor Malware Targeting Finance and Healthcare Sectors

139/69 Wedesday, March 11, 2026 Cybersecurity experts have identified a new malware campaign involving A0Backdoor, which specifically targets employees within global financial institutions and healthcare organizations. Attackers begin by sending large volumes of spam emails to disrupt victims. They then impersonate corporate IT staff and contact employees through Microsoft Teams, offering assistance in resolving the […]

sittisak mintaboon

March 11, 2026

Malicious npm Package “OpenClaw” Distributes GhostLoader Malware to Steal Sensitive Data on macOS

138/69 Tuesday, March 10, 2026 Security researchers from JFrog have discovered a malicious npm package named @openclaw-ai/openclawai, uploaded on March 3, 2026. The package impersonates an installer for the OpenClaw application and is designed to spread malware on macOS systems. The package has already been downloaded more than 180 times and remains available for download. […]

sittisak mintaboon

March 10, 2026

Critical Vulnerability in Nginx UI (CVE-2026-27944) Could Expose Server Backup Data

137/69 Tuesday, March 10, 2026 A critical security vulnerability has been discovered in Nginx UI, tracked as CVE-2026-27944 with a CVSS score of 9.8. The flaw could allow attackers to download and decrypt server backup files without authentication, potentially exposing sensitive information such as system configurations, credentials, and encryption keys-particularly if the management interface is […]

sittisak mintaboon

March 10, 2026

Warning: Hackers Use .arpa Domains and IPv6 to Evade Phishing Detection Systems

136/69 Tuesday, March 10, 2026 Security experts from Infoblox have discovered a sophisticated phishing campaign in which attackers abuse the “.arpa” top-level domain (TLD)-a domain normally reserved for internet infrastructure-to host malicious links. The .arpa domain is typically used for infrastructure functions such as Reverse DNS lookups, where IP addresses are mapped back to hostnames. […]

sittisak mintaboon

March 10, 2026

Anthropic Reports Claude Opus 4.6 Discovered 22 New Vulnerabilities in Mozilla Firefox

135/69 Monday, March 9, 2026 Anthropic has announced the discovery of 22 previously unknown vulnerabilities in the Mozilla Firefox browser through a collaboration with Mozilla. The findings were made using the large language model Claude Opus 4.6, which analyzed Firefox source code for only two weeks in January 2026. Among the vulnerabilities discovered, 14 were […]

sittisak mintaboon

March 9, 2026

Data Breach at Cognizant TriZetto Impacts Over 3.4 Million Patients

134/69 Monday, March 9, 2026 TriZetto Provider Solutions, a healthcare information technology provider that delivers software and systems to health insurers and medical service providers-and has operated under Cognizant since 2014—has disclosed a data breach affecting the personal information of more than 3.4 million patients. The company reported detecting suspicious activity within its systems on […]

sittisak mintaboon

March 9, 2026

OpenAI Launches Codex Security, Scanning 1.2 Million Code Commits and Detecting 792 Critical Vulnerabilities

133/69 Monday, March 9, 2026 OpenAI officially launched Codex Security on Friday, introducing an AI-powered security agent designed to automatically identify, verify, and suggest fixes for vulnerabilities in source code. The feature is currently available as a Research Preview for users of ChatGPT Pro, Enterprise, Business, and Edu plans, with the first month offered free […]

sittisak mintaboon

March 9, 2026

Phishing Campaign Using Fake Zoom/Teams Meeting Invites and Stolen Certificates Targets Corporate Networks

132/69 Friday, March 6, 2026 Security researchers from Microsoft’s Defender team have identified a new phishing campaign observed since February 2026 that targets office workers through fake meeting invitations impersonating Zoom and Microsoft Teams. Victims are often lured into opening a blurred PDF attachment designed to prompt curiosity. When users click the embedded link, they […]

sittisak mintaboon

March 6, 2026

LastPass Warns of Spoofed Security Alert Emails Designed to Steal Master Passwords

131/69 Friday, March 6, 2026 LastPass has issued a warning to users about a new phishing campaign that impersonates security alert emails claiming unauthorized account access or changes to a user’s Master Password. The attackers use display name spoofing to make the messages appear as if they originate from LastPass, increasing the likelihood that recipients […]

sittisak mintaboon

March 6, 2026

Iranian Hackers Target CCTV Cameras in Israel and the Middle East to Support Military Reconnaissance

130/69 Friday, March 6, 2026 A recent report from Check Point Research has identified cyberattack attempts linked to Iranian-affiliated hacker groups targeting hundreds of IP cameras (CCTV systems) across Israel and several Middle Eastern countries, including Qatar, Bahrain, and the United Arab Emirates-regions with significant military activity. The campaign primarily focuses on compromising cameras from […]

sittisak mintaboon

March 6, 2026
1 2 3 4 80