Critical Vulnerability in Roundcube Webmail Discovered After Over a Decade, Puts Millions at Risk

204/68 Friday, June 6, 2025 Cybersecurity researchers have disclosed a critical vulnerability tracked as CVE-2025-49113 (CVSS score: 9.9) in Roundcube Webmail, a widely used open-source webmail platform that has been in operation for over 10 years. The flaw allows authenticated attackers to execute arbitrary code remotely (Remote Code Execution) and potentially take full control of […]

ThaiCERT

June 6, 2025

Ukrainian Authorities Arrest Hacker for Hijacking Over 5,000 Hosting Accounts to Illegally Mine Cryptocurrency

203/68 Friday, June 6, 2025 Ukrainian police have arrested a 35-year-old man accused of hacking into more than 5,000 user accounts from international hosting companies to illegally mine cryptocurrency using unauthorized server resources. The operation, which caused an estimated $4.5 million in damages, involved hijacking customer accounts used for website and platform hosting, installing and […]

ThaiCERT

June 6, 2025

HPE Warns of Critical Vulnerabilities in StoreOnce Backup System, Including Authentication Bypass Risk

202/68 Thursday, June 5, 2025 Hewlett Packard Enterprise (HPE) has issued a security advisory warning of eight vulnerabilities affecting its StoreOnce data backup and deduplication solution, widely used in enterprise environments. The most critical flaw, CVE-2025-37093 (CVSS 9.8), is an authentication bypass vulnerability caused by a flaw in the machineAccountCheck function. This issue allows attackers […]

ThaiCERT

June 5, 2025

New “Crocodilus” Malware Targets Android Users Worldwide

201/68 Thursday, June 5, 2025 Cybersecurity experts are warning of a new malware strain called Crocodilus, which is rapidly spreading across Android devices globally. Initially detected in Turkey, Crocodilus disguises itself as fake banking apps, fake browser updates, and malicious ads to infect users. While early tests in March showed it targeting primarily Turkish Android […]

ThaiCERT

June 5, 2025

Qualcomm Releases Patches for Three Actively Exploited Zero-Day Vulnerabilities

200/68 Wednesday, June 4, 2025 Qualcomm has issued patches to address three zero-day vulnerabilities that have been actively exploited in the wild. These flaws were reported by Google’s Android Security team and are tracked as CVE-2025-21479, CVE-2025-21480, and CVE-2025-27038. The company distributed the patches to OEMs in May 2025 and strongly recommends immediate updates. Details […]

ThaiCERT

June 4, 2025

Australia Introduces New Law Requiring Organizations to Report Ransomware Payments

199/68 Wednesday, June 4, 2025 Australia has introduced new regulations mandating organizations with annual revenues of over AUD 3 million (approximately USD 2 million) to report ransomware payments and any related communications within 72 hours of the incident. The move is part of Australia’s broader national cybersecurity strategy, which aims to position the country as […]

ThaiCERT

June 4, 2025

“PumaBot” – New Botnet Targets Linux-Based IoT Devices to Steal SSH Credentials and Mine Cryptocurrency

197/68 Friday, May 30, 2025 Cybersecurity firm Darktrace has discovered a new botnet dubbed “PumaBot”, which is actively targeting Internet of Things (IoT) devices running on Linux. Unlike traditional widespread scans, PumaBot uses SSH brute-force attacks to compromise devices and expand its botnet network. It pulls a curated list of IP addresses from an external […]

ThaiCERT

May 30, 2025

DragonForce Exploits SimpleHelp Vulnerabilities to Launch Supply Chain Attacks on MSPs

196/68 Thursday, May 29, 2025 The ransomware group DragonForce has been identified as the actor behind a series of supply chain attacks targeting Managed Service Providers (MSPs). The attackers exploited vulnerabilities in SimpleHelp, a widely used Remote Monitoring and Management (RMM) platform, to breach MSP networks, conduct reconnaissance on client environments, exfiltrate sensitive data, and […]

ThaiCERT

May 29, 2025

Fake AI Ads on Facebook Spread Malware to Steal Personal Data, Researchers Warn

195/68 Thursday, May 29, 2025 Cybersecurity researchers have issued a warning about a large-scale malware campaign spreading across social media platforms, particularly Facebook and LinkedIn. A threat actor known as UNC6032 is exploiting growing public interest in artificial intelligence by distributing fake advertisements promoting AI-powered video generation tools. These ads claim to offer text-to-video AI […]

ThaiCERT

May 29, 2025
1 4 5 6 33