Lovense Vulnerabilities Could Let Hackers Hijack Accounts and Expose User Emails

282/68 Tuesday, August 5, 2025 Lovense has urgently released patches to address two critical vulnerabilities after a security researcher known as “BobDaHacker” revealed that the flaws could allow attackers to remotely take over user accounts and expose email addresses-all without needing a password. The first vulnerability stemmed from the app transmitting user email addresses without […]

ThaiCERT

August 5, 2025

Lazarus Group Uses Open-Source Tools to Spread Malware and Breach Global Software Development Ecosystems

281/68 Tuesday, August 5, 2025 The Lazarus Group, a hacking collective linked to the North Korean government, has once again been exposed for evolving its tactics-this time leveraging open-source software to distribute malware. Cybersecurity firm Sonatype recently reported the discovery of so-called “shadow downloads”—malicious files masquerading as popular software development tools embedded in over 200 […]

ThaiCERT

August 5, 2025

New Backdoor “Plague” Discovered on Linux-Hides in PAM to Bypass Authentication

280/68 Monday, August 4, 2025 Researchers at Nextron Systems have discovered a new malware strain called “Plague,” which embeds itself as a PAM (Pluggable Authentication Module) on Linux systems. The malware exploits the PAM framework to bypass standard authentication processes, allowing attackers to maintain persistent SSH access without needing to provide a password. Plague also […]

ThaiCERT

August 4, 2025

Akira Ransomware Group Exploits Zero-Day Vulnerability in SonicWall VPN Devices

279/68 Monday, August 4, 2025 Cybersecurity researchers from Arctic Wolf Labs have revealed that the Akira ransomware group has been actively targeting SonicWall SSL VPN systems since mid-July 2025. The attackers are using the VPN service as an entry point into victims’ networks. Notably, some of the affected devices had already been updated with the […]

ThaiCERT

August 4, 2025

Apple Patches Zero-Day Vulnerability Exploited Against Google Chrome Users – Urges Immediate Update

278/68 Friday, August 1, 2025 Apple has released a security patch to address a zero-day vulnerability, tracked as CVE-2025-6558 (CVSS score: 8.8), which has been actively exploited in attacks targeting Google Chrome users. The flaw stems from insufficient validation of untrusted data in the ANGLE (Almost Native Graphics Layer Engine) module and GPU components. If […]

ThaiCERT

August 1, 2025

VPN Usage Surges in the UK Following Age Verification Mandate Under Online Safety Act

277/68 Friday, August 1, 2025 Following the enforcement of the UK’s Online Safety Act, which came into effect last Friday, VPN (Virtual Private Network) usage across the country has skyrocketed. The new law requires websites to strictly verify users’ ages, prompting a massive surge in VPN traffic. According to Top10VPN, VPN usage in the UK […]

ThaiCERT

August 1, 2025

Ukrainian-Aligned Hackers Claim Cyberattack on Russia’s Aeroflot, Disrupting Over 100 Flights

276/68 Thursday, July 31, 2025 On July 28, 2025, pro-Ukrainian hacker groups Silent Crow and the Belarusian Cyber-Partisans claimed responsibility for a major cyberattack targeting Russia’s flagship airline Aeroflot, which crippled the company’s IT systems and forced the cancellation of over 100 flights. The Aeroflot website became inaccessible, and the Russian government later confirmed it […]

ThaiCERT

July 31, 2025

New Research Uncovers “Choicejacking” Attack That Steals Data from Phones via Public Chargers

275/68 Thursday, July 31, 2025 Cybersecurity researchers from Graz University of Technology in Austria have unveiled a novel attack technique called “Choicejacking,” which tricks smartphones into enabling USB data transfer without user consent, bypassing protections originally designed to prevent Juice Jacking attacks. By simply plugging a phone into a compromised public charger or USB cable […]

ThaiCERT

July 31, 2025

CISA Issues Urgent Alert on PaperCut Vulnerability Exploited in Ongoing Attacks

274/68 Wednesday, July 30, 2025 The Cybersecurity and Infrastructure Security Agency (CISA) has issued an official advisory regarding a critical vulnerability-CVE-2023-2533-in PaperCut NG/MF software, which is actively being exploited in cyberattacks. This vulnerability enables remote code execution through Cross-Site Request Forgery (CSRF), allowing an attacker to gain control of a system if an administrator-while still […]

ThaiCERT

July 30, 2025

Critical Vulnerability Found in Post SMTP Plugin for WordPress Puts Sites at Risk of Takeover

273/68 Wednesday, July 30, 2025 Security researchers from Patchstack have disclosed a critical vulnerability in the popular Post SMTP plugin for WordPress, which is used by over 400,000 websites globally to manage email delivery. The flaw, tracked as CVE-2025-24000, stems from a Broken Access Control issue that allows unauthorized access to sensitive data by low-privileged […]

ThaiCERT

July 30, 2025
1 3 4 5 39