Official HBO Max Reddit Account Compromised to Spread Infostealer Malware Through Malvertising

508/69 Wednesday, September 16, 2026 Reports indicate that the official verified Reddit account of the HBO Max streaming service was compromised by threat actors and used to distribute more than one hundred malware-laced advertisements. The campaign targeted users on both Windows and macOS. The attackers shifted their tactics to abuse the credibility of official social […]

ThaiCERT

September 16, 2026

Google Play Early Access Abused to Distribute Deceptive Android Apps

507/69 Tuesday, September 15, 2026 Bitdefender has released a report identifying numerous Android apps in Google Play Early Access that may deceive users, including fake casino games, reward apps, money-making apps, misleading utility apps, and apps that may infringe trademarks of well-known brands or games. Early Access is intended to allow developers to test apps […]

ThaiCERT

September 15, 2026

GitLab Warns of Critical CVE-2026-85706 Vulnerability That Could Allow Unauthenticated Access to Sensitive Files

506/69 Tuesday, September 15, 2026 GitLab disclosed CVE-2026-85706 on September 10, 2026. The vulnerability has a CVSS score of 10.0 and is a path traversal flaw in GitLab’s Repository Commits API. It could allow an unauthenticated attacker to send a single specially crafted HTTP request to read files that should not be accessible, such as […]

ThaiCERT

September 15, 2026

U.S. Court Sentences Hacker Behind Conti Ransomware Group to 4 Years in Prison

505/69 Tuesday, September 15, 2026 A U.S. federal court has sentenced 44-year-old Ukrainian national Oleksii Lytvynenko, a former lawyer who became a cybercriminal, to four years in prison for conspiracy to commit wire fraud over his involvement in the Conti ransomware operation. Conti was one of the cybercriminal groups responsible for significant global damage. Between […]

ThaiCERT

September 15, 2026

Attackers Use Claude to Analyze More Than 1.8 Million Android APK Files to Search for Credentials

504/69 Monday, September 14, 2026 Anthropic disclosed that it detected attackers using Claude to support credential-harvesting operations by building a process to download and analyze more than 1.8 million Android application files, or APKs, from multiple app distribution sources. The goal was to identify secrets embedded in applications and use the discovered data as an […]

ThaiCERT

September 14, 2026

Artifactory Vulnerabilities Exploited to Escalate Privileges and Deploy Backdoor on Servers

503/69 Monday, September 14, 2026 Reports indicate that attackers are exploiting Critical and High-severity vulnerabilities in JFrog Artifactory to bypass authentication, escalate privileges to administrator level, and install Rust-based backdoor malware on vulnerable self-hosted servers. A report from cloud security company Wiz confirmed observed attacks, including the chaining of CVE-2026-42018 and CVE-2026-42016 to access systems […]

ThaiCERT

September 14, 2026

Hackers Exploit Vulnerability in Tencent Application to Spread GrayRabbit Malware

502/69 Monday, September 14, 2026 Cybersecurity researchers from Gen Digital have warned of active exploitation of a high-severity vulnerability, CVE-2026-51990, in Sogou Input Method for Windows, a Chinese input application developed by Tencent. The vulnerability is a remote code execution (RCE) flaw that can be triggered when a user clicks a maliciously crafted link, known […]

ThaiCERT

September 14, 2026

Fortinet Vulnerability Exploited to Compromise Devices and Install PivotC2 Malware

501/69 Friday, September 11, 2026 Researchers from SOCRadar reported exploitation of CVE-2025-25249, a vulnerability with a CVSS score of 7.4 in FortiOS and FortiSwitchManager, to install PivotC2 malware on FortiGate devices. The vulnerability is a heap-based buffer overflow flaw that could allow unauthenticated attackers to execute commands through specially crafted data. Fortinet released patches for […]

ThaiCERT

September 11, 2026

Trezor Warns Customers of Phishing After External Email Provider Breach

500/69 Friday, September 11, 2026 Trezor, a cryptocurrency hardware wallet manufacturer, has warned customers after attackers compromised an external email provider used by the company and abused it to send phishing emails to customers. The fake emails used subject lines such as “Critical Security Alert” and claimed that a vulnerability had been found in the […]

ThaiCERT

September 11, 2026

Skullcandy Dime 3 Wireless Earbuds Vulnerability Could Allow Bluetooth Hijacking and Unauthorized Eavesdropping

499/69 Friday, September 11, 2026 The CERT Coordination Center at Carnegie Mellon University (CERT/CC) has issued an advisory warning users of Skullcandy Dime 3 wireless earbuds about a cybersecurity risk after discovering that the earbuds accept Bluetooth pairing requests from unknown nearby devices without requiring user authentication. The issue directly affects earbuds running firmware version […]

ThaiCERT

September 11, 2026
1 … 5 6 7 … 119