New Android Malware Can Steal Credit Card Data and Secretly Conduct Financial Transactions

439/69 Friday, August 14, 2026 Researchers from Group-IB have reported the discovery of a new threat targeting the Android operating system. This threat involves the combined use of WindRelay, a malware strain that relays data through Near Field Communication (NFC), and SpyNote, a Remote Administration Tool (RAT) used to control infected devices. The threat affects […]

ThaiCERT

August 14, 2026

Zoom Patches Zero-Click Vulnerability in Annotation Feature That Could Allow Code Execution on Users’ Devices

438/69 Thursday, August 13, 2026 Zoom has released a security update to fix CVE-2026-53413, a High-severity vulnerability with a CVSS score of 8.3 in the Annotation feature of Zoom clients. The vulnerability could allow an attacker who joins a meeting to execute code on other participants’ devices without requiring users to download files or click […]

ThaiCERT

August 13, 2026

ExfilSquad Adds New Victims and Uses Torrents to Publish Data Stolen from Cloud Portals

437/69 Thursday, August 13, 2026 Resecurity has published a report tracking the activities of ExfilSquad, a cybercrime group that emerged in mid-2026. The group uses a data theft and extortion model, threatening to publish stolen information on a dark web leak site if victims refuse to pay ransom, rather than deploying ransomware to encrypt systems. […]

ThaiCERT

August 13, 2026

Google Says Chrome on Android Blocks More Than 7 Billion Harmful Notifications Per Day

436/69 Thursday, August 13, 2026 Google disclosed in a report for the first quarter of 2026 that Chrome’s abuse protection system blocks more than 7 billion unwanted notifications per day on Android. This development is important for cybersecurity because threat actors increasingly abuse browser notifications as a channel to distribute malware, conduct phishing scams, and […]

ThaiCERT

August 13, 2026

CISA Warns Progress Kemp LoadMaster Vulnerability Is Being Actively Exploited

435/69 Tuesday, August 11, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8037, a vulnerability affecting Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation. The flaw is a command injection vulnerability that could allow an unauthenticated attacker to execute commands on affected systems. According […]

sittisak mintaboon

August 11, 2026

IEH Discloses Phishing Incident Affecting Microsoft 365 Mailbox, Potentially Exposing Export-Controlled Military Data

434/69 Tuesday, August 11, 2026 IEH Corporation, a U.S. defense and aerospace manufacturer based in Brooklyn, New York, disclosed a cybersecurity incident in an 8-K filing submitted to the U.S. Securities and Exchange Commission (SEC) after discovering that a threat actor had gained unauthorized access to an employee’s Microsoft 365 mailbox. IEH manufactures high-reliability electrical […]

sittisak mintaboon

August 11, 2026

Over 800 Malicious npm Packages Found Distributing Cross-Platform Malware and Stealing Data on Windows, macOS, and Linux

433/69 Tuesday, August 11, 2026 Cybersecurity researchers have discovered nearly 800 malicious packages published on the npm package registry as part of a new campaign designed to distribute cross-platform malware targeting Windows, macOS, and Linux systems. The campaign poses a direct risk to software developers and organizations that may unknowingly incorporate these packages into their […]

sittisak mintaboon

August 11, 2026

Metabase Warns of Zero-Day Exploited in the Wild, Allowing Privilege Escalation to Administrator

432/69 Monday, August 10, 2026 Metabase has issued a security advisory for a critical vulnerability affecting its Business Intelligence and Data Visualization platform after discovering that the flaw had been actively exploited as a zero-day. The vulnerability carries a CVSS score of 10.0 and had not yet been assigned a CVE identifier at the time […]

sittisak mintaboon

August 10, 2026

Unlimited Technology Systems Data Breach Impacts More Than 3.8 Million Healthcare Patients

431/69 Monday, August 10, 2026 Unlimited Technology Systems, a U.S.-based healthcare technology company, has disclosed a data breach affecting more than 3.8 million individuals after attackers gained access to the company’s commercial data center between October 5 and October 10, 2025. The company, headquartered in Montgomery, Ohio, provides financial technology, billing, and revenue cycle management […]

sittisak mintaboon

August 10, 2026

OpenAI Tightens Security Measures for Astra Model as Anthropic Eases Restrictions on Fable

430/69 Monday, August 10, 2026 OpenAI has announced stricter security measures for its new AI model, Astra, following preliminary assessments indicating that the model may possess advanced cyber capabilities capable of introducing new forms of risk. Meanwhile, Anthropic, another major AI developer, appears to be moving in the opposite direction by easing certain restrictions on […]

sittisak mintaboon

August 10, 2026
1 2 3 4 110