Broadcom Patches Critical VM Escape Vulnerability in VMware Workstation and Fusion

488/69 Monday, September 7, 2026 Broadcom has published security advisory VMSA-2026-0007 to address two vulnerabilities in VMware Workstation and VMware Fusion that could allow an attacker inside a virtual machine (VM) to execute code on the underlying host. One of the vulnerabilities is rated Critical, and no workaround is available to reduce the risk. The […]

ThaiCERT

September 7, 2026

Attacks Detected Exploiting MikroTik Router Vulnerabilities to Gain Unauthenticated System Control

487/69 Monday, September 7, 2026 CERT Polska has issued a cybersecurity warning after detecting threat actors exploiting vulnerabilities in MikroTik routers exposed to the public internet through Secure Shell (SSH). The exploitation could allow attackers to gain full administrator-level control of affected systems without authentication. Initial reports indicate that the activity has been observed since […]

ThaiCERT

September 7, 2026

All-in-One WP Migration and Backup Vulnerability Could Allow Code Execution on WordPress Websites

486/69 Friday, September 4, 2026 Reports have disclosed a vulnerability in the All-in-One WP Migration and Backup plugin for WordPress, tracked as CVE-2026-19949, with a CVSS score of 8.8. The flaw is a Second-Order SQL Injection vulnerability affecting version 7.109 and earlier. The plugin is used on more than 5 million websites, and reports indicate […]

ThaiCERT

September 4, 2026

SonicWall Patches Two Zero-Day Vulnerabilities in SMA 1000 VPN After Active Exploitation Confirmed

485/69 Friday, September 4, 2026 SonicWall has released security updates to address two zero-day vulnerabilities in SMA 1000 VPN appliances after confirming that the flaws have been exploited in attacks. The first vulnerability, CVE-2026-83548, has a CVSS score of 10.0 and is a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the Appliance WorkPlace interface. It […]

ThaiCERT

September 4, 2026

Preparing for Impact: OpenAI Confirms Astra AI Model Can Automatically Find Zero-Day Vulnerabilities and Generate Exploit Code

484/69 Friday, September 4, 2026 OpenAI has classified its new artificial intelligence (AI) model, Astra, at the highest cybersecurity risk level, Critical, under its Preparedness Framework. This marks the first model from the organization to reach this level. The assessment indicates that the system is capable of finding zero-day vulnerabilities and systematically developing exploit code […]

ThaiCERT

September 4, 2026

WatchGuard Patches Five Critical Vulnerabilities in Fireware OS and Dimension That Could Lead to Code Execution and Administrator Account Takeover

483/69 Thursday, September 3, 2026 WatchGuard has released patches to address more than 20 vulnerabilities in Fireware OS and WatchGuard Dimension, including five Critical vulnerabilities that could lead to remote code execution (RCE) or administrator account takeover. The five Critical vulnerabilities have CVSS scores of 9.3 and have been fixed in Fireware OS versions 2026.2.2, […]

ThaiCERT

September 3, 2026

Aesto Health Reports Data Breach Affecting Health Information of More Than 9.5 Million People After AWS Infrastructure Accessed

482/69 Thursday, September 3, 2026 Aesto Health, a U.S.-based healthcare technology company, disclosed a data breach affecting the personal and health information of more than 9.5 million people after attackers gained access to parts of the company’s infrastructure on Amazon Web Services (AWS). Aesto Health provides services for managing and protecting Electronic Health Records (EHRs) […]

ThaiCERT

September 3, 2026

Phishing Campaign Impersonates Adobe to Trick Users into Installing Faronics Deploy for System Takeover

481/69 Thursday, September 3, 2026 Cybersecurity researchers from Huntress detected a phishing campaign impersonating business documents, invoices, or tax documents to target users in organizations. More than 457 computers were targeted between July 21 and August 20. The threat actors abused Faronics Deploy, a legitimate cloud-based endpoint management platform, as the main channel to take […]

ThaiCERT

September 3, 2026

Fire Ant Uses Cisco IOS XR Routers to Capture Traffic and Hide Attack Activity

480/69 Wednesday, September 2, 2026 Security researchers have disclosed attacks by the Fire Ant group targeting infrastructure used by organizations to connect and manage networks, including Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. The attackers used these systems to maintain access, capture network traffic and credentials, and pivot to other connected […]

ThaiCERT

September 2, 2026

Hackers Steal Identity and Vehicle Registration Data from Latvia’s Road Traffic Safety Authority

479/69 Wednesday, September 2, 2026 Latvia’s Road Traffic Safety Directorate (CSDD) disclosed a data breach after attackers gained access to the agency’s systems and stole data belonging to approximately 1.2 million individuals and around 200,000 legal entities. The number of affected individuals represents roughly two-thirds of Latvia’s population. CERT.LV stated that the attackers obtained the […]

ThaiCERT

September 2, 2026
1 … 7 8 9 … 119