DoppelCart Fake Online Store Network Uses More Than 119,000 Domains to Steal Payment Card Data

498/69 Thursday, September 10, 2026 Researchers from Nebty detected a fake online store network named DoppelCart, which is linked to more than 119,000 domains. The network impersonates legitimate stores and brands to steal personal information and payment card data. According to scans disclosed by the researchers, more than 105,000 fake stores in the network remain […]

ThaiCERT

September 10, 2026

More Than 36,000 Plex Media Servers Exposed to the Internet Remain Unpatched Against Recent Vulnerabilities

497/69 Thursday, September 10, 2026 Plex has issued an advisory urging administrators to update Plex Media Server and Plex Desktop after multiple security vulnerabilities were identified, though no official CVE identifiers have been assigned for tracking. The vulnerabilities affect Plex Media Server version 1.43.2 and earlier. Plex recommends that users upgrade Plex Media Server to […]

ThaiCERT

September 10, 2026

Phishing Campaign Abuses Google Services to Create Multi-Hop Redirect Links for Data Theft and Device Control

496/69 Thursday, September 10, 2026 In early September, cybersecurity researchers from KnowBe4 reported the discovery of a new phishing campaign in which threat actors abused features across multiple Google services to evade detection by security systems. The attackers created a redirection chain using trusted Google domains to deceive email filtering systems and other security tools, […]

ThaiCERT

September 10, 2026

BigBear 2.0 Phishing Service Bypasses Microsoft 365 MFA to Impersonate Account Access

495/69 Wednesday, September 9, 2026 Researchers from CloudSEK have disclosed a report on BigBear 2.0, a phishing-as-a-service tool designed to steal Microsoft 365 login information. The service can capture passwords and session data after users complete multi-factor authentication (MFA). The investigation found 5,137 stolen credential records, including plaintext passwords and a large number of session […]

ThaiCERT

September 9, 2026

Mathspace Reports Data Breach Affecting More Than 1 Million Students, Staff, and Parents

494/69 Wednesday, September 9, 2026 Mathspace, an online mathematics learning platform, disclosed a data breach after attackers gained access to its internal reporting system running a self-hosted Metabase deployment and stole data belonging to students, school staff, parents or guardians, and Mathspace employees, affecting more than 1 million people in total. Mathspace was founded in […]

ThaiCERT

September 9, 2026

Warning: Phone-Based Attacks Impersonate IT Staff to Steal Data from Microsoft 365

493/69 Wednesday, September 9, 2026 Cybersecurity researchers have disclosed a threat campaign targeting senior executives, such as directors and company vice presidents, to steal data and conduct extortion. The attackers focus on Microsoft 365 and other cloud-based software-as-a-service (SaaS) platforms. The threat actors use phone-based social engineering, or vishing, while impersonating IT staff or help […]

ThaiCERT

September 9, 2026

ConnectWise Warns of ScreenConnect Issue Affecting File Transfers Between Sessions, No Patch Available Yet

492/69 Tuesday, September 8, 2026 ConnectWise has issued a security advisory for ScreenConnect Remote Access related to file transfer behavior within Support and Access sessions. The issue affects both Cloud and On-Premise deployments. At this time, no CVE identifier has been assigned to the vulnerability, and an official patch is still under development. However, ConnectWise […]

ThaiCERT

September 8, 2026

N-able Releases Hotfix for Severe RCE Vulnerability in N-central

491/69 Tuesday, September 8, 2026 N-able has released a hotfix to address a severe Remote Code Execution (RCE) vulnerability in N-central, a Remote Monitoring and Management (RMM) platform used by IT teams and Managed Service Providers (MSPs) to monitor, manage, and support customer networks and devices through a centralized web-based console. The vulnerability is tracked […]

ThaiCERT

September 8, 2026

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

490/69 Tuesday, September 8, 2026 Cybersecurity researchers have disclosed the discovery of JSCeal, an infostealer malware strain developed to target general users, particularly retail investors and cryptocurrency traders in the Asia-Pacific and Latin America regions. The malware is distributed through malvertising campaigns on social media platforms such as Facebook and Google, luring users to fake […]

ThaiCERT

September 8, 2026

StyleSmuggler Vulnerability in Magento and Adobe Commerce Exploited, Risking Code Execution and Backdoor Deployment

489/69 Monday, September 7, 2026 Sansec has disclosed active exploitation of an unpatched vulnerability in Magento Open Source and Adobe Commerce, named StyleSmuggler. Attacks have been observed since September 4, 2026. The vulnerability could allow unauthenticated attackers to execute code on online store servers and install a backdoor to maintain system access. Sansec stated that […]

ThaiCERT

September 7, 2026
1 … 6 7 8 … 119