Linux Kernel Vulnerability on Ubuntu Could Allow Container Escape After Exploit Code Is Released

528/69 Thursday, September 24, 2026 Researchers from DepthFirst have disclosed technical details and exploit code for CVE-2026-80521, a Linux Kernel vulnerability with a CVSS score of 7.8. The flaw is a use-after-free vulnerability in the AF_UNIX subsystem. The published exploit was tested against Ubuntu 26.04 LTS and can be used from within a container to […]

ThaiCERT

September 24, 2026

Researchers Discover TrustSink Technique Using Rogue MFA Providers to Steal Passwords During Login

527/69 Thursday, September 24, 2026 Researchers from Varonis Threat Labs have disclosed an attack technique named TrustSink that allows attackers with elevated privileges in an Identity Provider environment to register a rogue external MFA provider and use it to steal users’ passwords during an apparently legitimate login process. The technique may apply to identity providers […]

ThaiCERT

September 24, 2026

FBI Investigates After ShinyHunters Claims Attack on Recruitment Website and Access to Staff Data

526/69 Thursday, September 24, 2026 The U.S. Federal Bureau of Investigation (FBI) is investigating a cybersecurity incident after the hacker group known as ShinyHunters claimed responsibility for attacking the agency’s recruitment website. Initial reports indicate that the website was defaced and that the recruitment portal remains unavailable. The attackers claim they gained access to the […]

ThaiCERT

September 24, 2026

Microsoft Warns SharePoint Vulnerability CVE-2026-65660 Could Lead to Command Execution on Servers

525/69 Wednesday, September 23, 2026 Microsoft has revised the classification of CVE-2026-65660 in SharePoint Server, changing it from a spoofing vulnerability with a CVSS score of 6.5 to a High-severity Remote Code Execution (RCE) vulnerability with a CVSS score of 8.8 after additional details about its impact were disclosed. The vulnerability affects SharePoint Server 2016, […]

ThaiCERT

September 23, 2026

BigCommerce Reports Data Breach After Compromised Ribon App Credentials Were Used to Inject Malicious Scripts into Online Stores

524/69 Wednesday, September 23, 2026 BigCommerce, a cloud-based SaaS e-commerce platform, has notified multiple merchants of a data breach after attackers compromised credentials belonging to the third-party applications Ribon and Ribon 1.5, developed by Be A Part Of, a subsidiary of Fastr. The attackers then used those credentials to inject malicious scripts into merchants’ online […]

ThaiCERT

September 23, 2026

Threat Actors Breach Water Control Systems at Utilities in Colorado, United States

523/69 Wednesday, September 23, 2026 Reports indicate that in late August, hackers attempted cyberattacks targeting the Operational Technology (OT) systems of two small private water utilities in Colorado, United States. Although the incidents involved attempts to interfere with operational systems, the utilities were able to respond and contain the risk quickly. As a result, there […]

ThaiCERT

September 23, 2026

Fake LastPass Campaign Spreads Rapuncel Infostealer and Disables Antivirus and EDR Tools

522/69 Tuesday, September 22, 2026 Security researchers have disclosed a campaign involving fake GitHub pages impersonating LastPass Authenticator and software from at least 40 organizations to trick users into downloading malicious installers. The attackers use SEO techniques to make the fake pages appear prominently in search results. Once the installer is executed, it deploys an […]

ThaiCERT

September 22, 2026

ShinyHunters Hacks and Defaces Clop Ransomware Leak Site on the Dark Web

521/69 Tuesday, September 22, 2026 The extortion group ShinyHunters was observed compromising and defacing the Tor-based leak site operated by the Clop ransomware group, replacing its original content with ShinyHunters branding and a message for visitors. The incident was discovered by Hackread.com on September 19, 2026. Clop’s website displayed ASCII artwork associated with ShinyHunters, a […]

ThaiCERT

September 22, 2026

ChainScript Malware Hides Command-and-Control Server Through Smart Contracts on Blockchain Network

520/69 Tuesday, September 22, 2026 Researchers from Blackpoint have discovered a new Remote Access Trojan (RAT) named ChainScript, developed in Node.js. The malware is being distributed through a ClickFix campaign that tricks users into copying and running malicious commands. A notable feature of this malware is its use of blockchain technology to hide its command-and-control […]

ThaiCERT

September 22, 2026

SolarWinds Access Rights Manager Vulnerability Could Allow Unauthenticated Command Execution

519/69 Monday, September 21, 2026 SolarWinds has released a security update to address CVE-2026-28326 in its Access Rights Manager (ARM) product. The vulnerability has a CVSS score of 8.8 and could allow an unauthenticated attacker to execute commands on affected systems. The flaw affects Access Rights Manager version 2026.2 and earlier, and SolarWinds has already […]

ThaiCERT

September 21, 2026
1 … 3 4 5 … 119