‘DollyWay’ Malware Campaign Has Been Targeting WordPress Sites Globally for Over 8 Years

111/68 Friday, March 21, 2025 Since 2016, a long-running malware campaign known as “DollyWay” has infected more than 20,000 WordPress websites worldwide, redirecting users to malicious sites including dating scams, online gambling platforms, and various other fraudulent destinations. The campaign has evolved over the years, employing advanced evasion techniques and reinfection mechanisms to maintain persistence. […]

ThaiCERT

March 21, 2025

Microsoft Discovers StilachiRAT Malware Designed for Data Theft and Evasion

110/68 Thursday, March 20, 2025 Microsoft has identified a new malware strain called StilachiRAT, a Remote Access Trojan (RAT) with advanced techniques for hiding itself and stealing sensitive data such as browser passwords, cryptocurrency wallet information, and system details. The malware leverages the WWStartupCtrl64.dll module and utilizes WMI Query Language (WQL) through Web-based Enterprise Management […]

ThaiCERT

March 20, 2025

Unpatched Edimax Camera Vulnerability Exploited in Mirai Botnet Attacks Since 2024

108/68 Wednesday, March 19, 2025 Hackers have been exploiting CVE-2025-1316, a high-severity OS command injection vulnerability (CVSS 9.3) in Edimax IC-7100 cameras, to spread the Mirai Botnet since May 2024. This vulnerability enables remote code execution (RCE) through specially crafted requests. According to Akamai, a Proof-of-Concept (PoC) exploit was publicly available as early as June […]

ThaiCERT

March 19, 2025

SSRF Vulnerability in Open-Source ChatGPT Developed by Chinese Developer Exploited in Attacks

107/68 Wednesday, March 19, 2025 Cybersecurity firm Veriti has reported CVE-2024-27564, a Server-Side Request Forgery (SSRF) vulnerability affecting an open-source ChatGPT version developed by a Chinese developer—a separate platform from OpenAI’s widely used ChatGPT. While categorized as a medium-severity issue, it has been actively exploited in real-world attacks, with 10,479 attempts recorded within a single […]

ThaiCERT

March 19, 2025

Warning! Fake Security Alert Campaign on GitHub Tricks Developers into Approving Malicious Apps

105/68 Tuesday, March 18, 2025 GitHub developers are being targeted in a large-scale phishing campaign that uses fake security alerts to trick users into approving a malicious OAuth app. Attackers send deceptive notifications warning of an “unusual access attempt” from Reykjavik, Iceland, citing a suspicious IP address 53.253.117.8 to create urgency. The notification includes a […]

ThaiCERT

March 18, 2025

Warning! Malicious PyPI Packages Stealing Cloud Tokens Downloaded Over 14,100 Times Before Removal

104/68 Monday, March 17, 2025 Cybersecurity researchers have uncovered a malicious campaign using fake packages in the Python Package Index (PyPI) to steal sensitive data, including cloud access tokens. According to ReversingLabs, 20 malicious packages were identified in two separate sets, collectively downloaded over 14,100 times before being removed from PyPI. The most downloaded malicious […]

ThaiCERT

March 17, 2025

ClickFix Technique Gains Popularity Among Cybercriminals and APT Groups for Attacking Victims

103/68 Monday, March 17, 2025 Cybersecurity firm Group-IB has revealed that since August 2024, state-sponsored hacker groups (APT groups) and cybercriminals have increasingly used the ClickFix technique in data-stealing malware attacks. ClickFix is a social engineering deception that leverages JavaScript on web pages to display fake system update alerts or reCAPTCHA verification prompts. When victims […]

ThaiCERT

March 17, 2025

Microsoft Releases March 2025 Patch Tuesday Security Update, Fixing Six Zero-Day Vulnerabilities

102/68 Friday, March 14, 2025 Microsoft has released its March 2025 Patch Tuesday security update, addressing a total of 56 vulnerabilities across various products, including Windows and Windows Components, Office and Office Components, Azure, .NET and Visual Studio, Remote Desktop Services, DNS Server, and Hyper-V Server. Among these, six zero-day vulnerabilities have been actively exploited […]

ThaiCERT

March 14, 2025
1 34 35 36 53