CVE-2026-6770 Vulnerability Found in Firefox and Tor Browser, Risk of Cross-Site Fingerprinting Tracking

234/69 Wednesday, April 29, 2026 Researchers have discovered a vulnerability, CVE-2026-6770, affecting Mozilla Firefox, Mozilla Thunderbird, and Tor Browser, classified as a medium-severity issue. This flaw may allow websites to generate unique identifiers for fingerprinting, enabling the tracking of user activity across different websites—even when users are in Private Browsing mode or using Tor Browser, […]

sittisak mintaboon

April 29, 2026

Medtronic Confirms Cybersecurity Incident After ShinyHunters Claims Theft of Over 9 Million Records

233/69 Wednesday, April 29, 2026 Medtronic, a global medical device manufacturer, has confirmed a cybersecurity incident affecting its internal IT systems after the cybercrime group ShinyHunters claimed it had accessed and stolen more than 9 million records. The company stated that it detected unauthorized access to certain parts of its IT environment but has not […]

sittisak mintaboon

April 29, 2026

Warning: 82 Chrome Extensions Found Collecting and Selling Personal Data, Affecting Over 6.5 Million Users

232/69 Wednesday, April 29, 2026 A 2026 report by LayerX Security reveals that at least 82 extensions on Google Chrome have been found secretly collecting users’ personal data and selling it to third parties, impacting more than 6.5 million users worldwide. Notably, these tools are not traditional malware. Instead, they explicitly disclose data-sharing practices in […]

sittisak mintaboon

April 29, 2026

Vulnerability in Microsoft Entra Agent ID Could Lead to Privilege Escalation and Tenant Takeover

231/69 Tuesday, April 29, 2026 Researchers from Silverfort have disclosed a vulnerability in Microsoft Entra Agent ID, a mechanism designed to manage digital identities for AI agents. The issue lies in the Agent ID Administrator role, which was intended to manage only agent-related objects but was found to have excessive permissions. This allowed it to […]

sittisak mintaboon

April 28, 2026

Trigona Ransomware Uses Custom Tools for Data Theft and Evasion

230/69 Tuesday, April 29, 2026 Researchers from Symantec report that the Trigona ransomware has evolved its tactics by using a self-developed command-line tool for data exfiltration instead of commonly detected tools like Rclone or MegaSync. This trend, observed in attacks during March 2026, highlights the group’s effort to increase sophistication and evade detection. Trigona operates […]

sittisak mintaboon

April 28, 2026

Critical Vulnerability in CrowdStrike LogScale Allows Unauthenticated File Access on Servers

229/69 Tuesday, April 28, 2026 CrowdStrike has disclosed a critical vulnerability, CVE-2026-40050, affecting its LogScale product in self-hosted deployments. The flaw is an unauthenticated path traversal vulnerability located in a specific Cluster API endpoint. If left unpatched, it could allow remote attackers to access and read sensitive files on the server’s file system without requiring […]

sittisak mintaboon

April 28, 2026

UNC6692 Uses Microsoft Teams to Deploy “Snow” Malware, Targeting Enterprise Domain Takeover

228/69 Monday, April 27, 2026 Researchers from Mandiant have identified a campaign by the threat group UNC6692 leveraging social engineering techniques to compromise organizations. The attack begins with email bombing to overwhelm victims and create urgency. Attackers then impersonate IT helpdesk staff and contact targets via Microsoft Teams, convincing them to install what is claimed […]

sittisak mintaboon

April 27, 2026

Critical Vulnerability in Breeze Cache Plugin Puts Over 400,000 Websites at Risk

227/69 Monday, April 27, 2026 Researchers from Wordfence have disclosed a critical vulnerability, CVE-2026-3844 (CVSS 9.8), in the Breeze Cache plugin for WordPress, developed by Cloudways. The flaw allows unauthenticated file uploads to the server, potentially leading to remote code execution (RCE). The plugin is currently used by more than 400,000 websites, and at least […]

sittisak mintaboon

April 27, 2026

Warning: Fake CAPTCHA Scam Tricks Users into Sending International SMS, Causing Hidden Charges

226/69 Monday, April 27, 2026 Researchers from the Threat Intelligence team at Infoblox have uncovered a sophisticated global fraud campaign known as Click2SMS. In this scheme, attackers abuse familiar CAPTCHA verification systems as a tool for International Revenue Share Fraud (IRSF). The scam aims to drain money from victims’ accounts or mobile bills by tricking […]

sittisak mintaboon

April 27, 2026

Urgent Update: Apple Fixes iOS Flaw That Could Allow Recovery of Deleted Messages

225/69 Friday, April 24, 2026 Apple has released security updates to address vulnerability CVE-2026-28950 in iOS and iPadOS, after discovering an issue in the notification handling system that allowed deleted notification data to remain stored on devices. The flaw has been fixed in iOS 26.4.2, iPadOS 26.4.2, iOS 18.7.8, and iPadOS 18.7.8. Apple stated that […]

sittisak mintaboon

April 24, 2026
1 3 4 5 90