Oracle Confirms Cl0p Ransomware Group Exploited Zero-Day (CVE-2025-61882) to Attack E-Business Suite Customers

389/68 Tuesday, October 7, 2025 Oracle has confirmed that the Cl0p ransomware group was behind attacks and data theft targeting Oracle E-Business Suite (EBS) customers, exploiting a Zero-Day vulnerability tracked as CVE-2025-61882. This critical flaw, rated CVSS 9.8, allows unauthenticated remote code execution and affects Oracle EBS versions 12.2.3 through 12.2.14, specifically within the BI […]

ThaiCERT

October 7, 2025

Zero-Day Exploit in Zimbra Used to Attack Brazilian Military via Malicious ICS Files

388/68 Tuesday, October 7, 2025 Cybersecurity researchers from StrikeReady Labs have uncovered an in-the-wild attack exploiting a Zero-Day vulnerability in Zimbra Collaboration, tracked as CVE-2025-27915 (CVSS 5.4), targeting the Brazilian military through malicious ICS calendar files. Attackers impersonated the Office of Protocol of the Libyan Navy and sent emails with weaponized ICS attachments. When opened, […]

ThaiCERT

October 7, 2025

Massive 500% Surge in Scanning Activity Targeting Palo Alto Networks Login Portals

387/68 Tuesday, October 7, 2025 Cybersecurity company GreyNoise has reported an unusual 500% spike in scanning activity targeting Palo Alto Networks login portals on October 3, 2025-the highest level seen in the past three months. The company detected scanning attempts from 1,285 unique IP addresses, up from a normal daily average of about 200. Of […]

ThaiCERT

October 7, 2025

Researchers Warn of “CometJacking” Vulnerability in Perplexity’s AI Browser – A Single Click Could Lead to Data Theft

386/68 Monday, October 6, 2025 Cybersecurity researchers have disclosed a new attack technique called CometJacking, targeting Perplexity’s Comet AI browser. The attack leverages prompt injection by embedding malicious instructions inside seemingly safe links. Once a victim clicks the link, the AI within the browser executes commands to retrieve data from connected services-such as Gmail or […]

ThaiCERT

October 6, 2025

Discord Discloses Data Breach After Hackers Stole Information from Customer Support System

385/68 Monday, October 6, 2025 Discord, the popular communication platform, revealed a data breach on September 20, 2025, after hackers gained access to the systems of an external customer support provider working with Discord and stole some users’ personal information. The stolen data included names, usernames, emails, contact details, IP addresses, messages and attachments sent […]

ThaiCERT

October 6, 2025

Apple Releases Patches for iOS and macOS Vulnerability Allowing Malicious Code Execution via Fonts

383/68 Friday, October 3, 2025 Apple has released updates for iOS and macOS to fix CVE-2025-43400, a vulnerability in the FontParser system that could cause an out-of-bounds write in memory. This flaw may lead to sudden application crashes, abnormal system behavior, or potentially allow attackers to execute arbitrary malicious code. An attacker could craft a […]

ThaiCERT

October 3, 2025

WestJet Confirms Data Breach Impacting 1.2 Million Customers

382/68 Friday, October 3, 2025 Canadian airline WestJet has disclosed that a cyberattack in June led to the theft of personal data belonging to over 1.2 million customers, including travel documents such as passports and government-issued IDs. The company confirmed the findings of its investigation and reported the incident to relevant authorities on September 15, […]

ThaiCERT

October 3, 2025

“Klopatra” Trojan Spreads Across Europe, Using VNC to Control Devices While Screens Are Off

381/68 Friday, October 3, 2025 Cybersecurity researchers from Cleafy have uncovered a new Android malware named “Klopatra”, which disguises itself as IPTV and VPN apps to infect over 3,000 devices in Europe. Classified as both a Banking Trojan and Remote Access Trojan (RAT), Klopatra comes with advanced capabilities such as real-time screen monitoring, keylogging, clipboard […]

ThaiCERT

October 3, 2025

Researchers Warn AI Can Clone Voices Within Minutes, Increasing Risk of Vishing Attacks

380/68 Thursday, October 2, 2025 Researchers from NCC Group have unveiled a new framework that leverages AI to clone a person’s voice in real time using only a few minutes of original audio samples. This advancement significantly boosts the credibility and realism of Vishing (voice phishing) attacks, putting organizations, employees, and individuals at higher risk […]

ThaiCERT

October 2, 2025
1 6 7 8 53