Researchers Find AI Email Summarization Systems Can Be Manipulated into Distorting Information Through Fabricated Content

538/69 Thursday, October 1, 2026 Researchers from Forcepoint X-Labs have disclosed a new technique for manipulating AI systems used to summarize email content. The research found that attackers can cause AI-generated summaries to contain inaccurate information by inserting fabricated content into an email thread, without relying on hidden text or directly injecting instructions intended to […]

ThaiCERT

October 1, 2026

CoreGraphics Vulnerability in Apple Devices Could Allow Code Execution

537/69 Wednesday, September 30, 2026 Apple has released security updates to address CVE-2026-86950, an out-of-bounds write vulnerability in the CoreGraphics component. Processing a specially crafted file could lead to code execution on an affected device. Apple stated that it received a report indicating the vulnerability may have been exploited in an extremely sophisticated attack against […]

ThaiCERT

September 30, 2026

Infostealers Target Enterprise AI Accounts, Exposing Sessions, API Keys, and Sensitive Data

536/69 Wednesday, September 30, 2026 SOCRadar has released an analysis of stealer log data collected over the past 90 days, identifying 482 organizations with exposed AI accounts or credentials. Of these, 295 organizations appeared in logs that remained active during the same period, indicating that many of the risks were linked to recent activity rather […]

ThaiCERT

September 30, 2026

Japan’s Keio Hit by Ransomware Attack, While Tokyo Metro Reports Email Data Breach

535/69 Wednesday, September 30, 2026 Keio Corporation, a major private railway and hotel operator in Japan, confirmed that it was hit by a ransomware attack on the morning of September 26, 2026, prompting the company to shut down parts of its network to prevent further damage. Over the same weekend, Tokyo Metro, another major Japanese […]

ThaiCERT

September 30, 2026

x47.c Windows Botnet Uses Grok to Maintain Persistence and Features AI API Drain Capability

534/69 Monday, September 28, 2026 Qrator Research Labs has disclosed the discovery of x47.c, a Windows botnet being advertised with multiple capabilities, including DDoS attacks, credential theft, SOCKS5 proxy creation, and an AI API Drain feature designed to consume credits or generate charges on AI service accounts. The botnet also includes an AI Stealth module […]

ThaiCERT

September 28, 2026

OpenAI Discloses Incident Where AI Agents Accidentally Uploaded User-Provided Images to External Websites

533/69 Monday, September 28, 2026 OpenAI confirmed that it is aware of a security incident in which AI agents unintentionally uploaded user-provided images to third-party image-hosting services. The company stated that the vast majority of users were not affected. An initial investigation identified 53 cases in which images were posted as links on image-hosting websites […]

ThaiCERT

September 28, 2026

Lunex Malware Exploits Vulnerable AMD Driver to Bypass Security Tools and Steal User Data

532/69 Monday, September 28, 2026 Cybersecurity researchers from Ontinue have disclosed a campaign involving Malware-as-a-Service known as Lunex, also referred to as Psychedelic Stealer, which is expanding its attacks against users across multiple countries. Initial findings show that threat actors are using fake websites that imitate Cloudflare verification pages to trick users into downloading the […]

ThaiCERT

September 28, 2026

AI Agents Used to Support E-Commerce Attacks and Steal Credit Card Data

531/69 Friday, September 25, 2026 Researchers from Gambit Security have disclosed a campaign in which attackers used open-source AI tools, including Strix, Cairn, and Hermes, to support attacks against organizations, particularly online retailers. The campaign has been active since July 2026, and between September 10 and 15, researchers observed 105 attack activities and confirmed that […]

ThaiCERT

September 25, 2026

Fake LastPass Campaign on GitHub Spreads Infostealer and Disables More Than 145 Security Tools

530/69 Friday, September 25, 2026 The LastPass Threat Intelligence, Mitigation, and Escalation team, together with Delphos Labs, disclosed a multi-stage malware campaign impersonating the LastPass brand on GitHub to trick users into downloading a fake LastPass Authenticator installer. The fraudulent GitHub page was discovered on August 13, 2026, after appearing in search results for “LastPass […]

ThaiCERT

September 25, 2026

IonQ Develops Quantum Error-Correction Decoder to Address Processing Bottlenecks

529/69 Friday, September 25, 2026 IonQ, a developer of quantum computing hardware and software, has successfully developed a quantum error-correction decoder capable of operating in real time on a single standard central processing unit (CPU). The innovation is designed to address a key bottleneck caused by latency when classical computers are used to process quantum […]

ThaiCERT

September 25, 2026
1 2 3 4 … 119