AI Accelerated Exploit Development for Discourse Vulnerability, Leading to OpenAI Staff Account Takeover Through SSO

518/69 Monday, September 21, 2026 Researchers from Hacktron disclosed the results of a security test in which they were able to take over ChatGPT and Codex accounts belonging to OpenAI staff through a vulnerability in a forum system running Discourse. The attack did not rely on phishing or leaked passwords, but stemmed from the image […]

ThaiCERT

September 21, 2026

New “BragJack” Attack Technique Discovered That Can Control Browser-Based AI Assistants Through Extensions

517/69 Monday, September 21, 2026 Security researchers from Forever Security have disclosed a new attack technique named “BragJack,” which allows threat actors to take control of artificial intelligence assistants installed in popular web browsers by using malicious extensions already present on a victim’s system. The attack primarily affects browsers or tools based on Chromium, including […]

ThaiCERT

September 21, 2026

ISC Patches BIND 9 Vulnerabilities That Could Affect DNS Service Availability and Data Integrity

516/69 Friday, September 18, 2026 Internet Systems Consortium (ISC) has released security updates for BIND 9 to address 14 vulnerabilities covering issues that may affect the availability and integrity of DNS services. Some of the vulnerabilities can be exploited without authentication and may cause the named process to crash or consume excessive system resources, resulting […]

ThaiCERT

September 18, 2026

FBI Seizes NightmareStresser DDoS-for-Hire Domains Under Operation PowerOFF

515/69 Friday, September 18, 2026 The U.S. Federal Bureau of Investigation (FBI), in cooperation with the Royal Canadian Mounted Police (RCMP), has seized internet domains associated with NightmareStresser, a DDoS-for-hire service accused of allowing customers to pay for access to infrastructure used to attack targets worldwide. The U.S. Department of Justice stated that NightmareStresser had […]

ThaiCERT

September 18, 2026

BambooToken Malware Uses MQTT Protocol to Control Windows and Linux Systems and Evade Detection

514/69 Friday, September 18, 2026 Security researchers from Lumen have discovered a new malware family named BambooToken, which has been used to target Windows and Linux systems from February 2023 through July 2026. The malware hides its activity by using the MQTT protocol, a messaging protocol commonly used in smart home devices and industrial systems, […]

ThaiCERT

September 18, 2026

The Events Calendar Plugin Vulnerabilities in WordPress Could Allow Command Execution and Website Takeover

513/69 Thursday, September 17, 2026 Wordfence disclosed two Critical vulnerabilities in The Events Calendar plugin for WordPress, tracked as CVE-2026-78159 and CVE-2026-78006. Both vulnerabilities have CVSS scores of 9.8 and could allow unauthenticated attackers to execute commands on the server and take control of affected websites. The plugin has more than 600,000 installations, while data […]

ThaiCERT

September 17, 2026

Google Releases Patch for Android Zero-Day on Pixel Devices After Reported Exploitation

512/69 Thursday, September 17, 2026 Google has released its September 2026 security update for Pixel devices, addressing a total of 110 vulnerabilities. Among them is one zero-day vulnerability that has reportedly been exploited in limited, targeted attacks. The vulnerability is tracked as CVE-2026-58704, and Google stated that exploitation of the flaw has been observed. The […]

ThaiCERT

September 17, 2026

KREMLIN Malware Targets Chrome and Edge Users to Steal Banking Account Data

511/69 Thursday, September 17, 2026 Cybersecurity researchers from Elastic Security Labs have discovered a new financial malware operation named KREMLIN, which targets users of Google Chrome and Microsoft Edge. Activity linked to the malware has been observed since May 2025. The malware uses social engineering by disguising itself as financial or banking documents to trick […]

ThaiCERT

September 17, 2026

WooCommerce Wholesale Lead Capture Vulnerability Exploited to Take Over WordPress Websites

510/69 Wednesday, September 16, 2026 Wordfence disclosed that attackers have been exploiting CVE-2026-27540, a Critical vulnerability with a CVSS score of 9.8 in the WooCommerce Wholesale Lead Capture plugin for WordPress. The vulnerability affects version 2.0.3.1 and earlier. It allows unauthenticated attackers to upload PHP files to websites, potentially leading to command execution on the […]

ThaiCERT

September 16, 2026

Japan Discloses VPN Attack Affecting Central Government Network Platform, Potentially Exposing 246,000 Records

509/69 Wednesday, September 16, 2026 Japan’s Digital Agency has disclosed an unauthorized access incident after attackers exploited a vulnerability in a VPN device to access the Government Solution Service (GSS), a shared IT infrastructure platform connecting 23 Japanese ministries and government agencies. The incident may have exposed approximately 246,000 records containing personal information of government […]

ThaiCERT

September 16, 2026
1 … 4 5 6 … 119