SonicWall Warns of Zero-Day Vulnerabilities in SMA1000 Appliances, Urging Administrators to Apply Security Patches

388/69 Thursday, July 16, 2026 SonicWall has issued an advisory after threat actors were observed exploiting two zero-day vulnerabilities in SonicWall SMA1000 appliances. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog and ordered federal agencies under its scope to address affected systems by July […]

ThaiCERT

July 16, 2026

Supply Chain Attack Found Hiding Infostealer Malware in Jscrambler npm Package

387/69 Wednesday, July 15, 2026 Security researchers have disclosed a supply chain attack affecting the official jscrambler package on npm. Attackers published modified versions of the package containing a Rust-based infostealer, putting developer machines and CI/CD systems that installed the affected package at risk of sensitive data theft. Jscrambler stated that the issue affects package […]

ThaiCERT

July 15, 2026

Lidl Discloses Online Shop Customer Data Breach After Service Provider Attack

386/69 Wednesday, July 15, 2026 Lidl, a German discount supermarket chain under the Schwarz Group, has notified online shop customers in Germany, Belgium, and the Netherlands after attackers stole personal data in a data breach affecting an external IT service provider. Lidl is part of the Schwarz Group, Europe’s largest food retailer, with more than […]

ThaiCERT

July 15, 2026

Google and Microsoft Remove ModHeader Extension After Hidden Code Found Collecting Browsing History Data

385/69 Wednesday, July 15, 2026 Google and Microsoft have removed the ModHeader extension, which had more than 1.6 million combined installations on Chrome and Edge, from their official stores. The action came after cybersecurity firm Stripe OLT discovered hidden code designed to collect website browsing history data embedded in the official version of the extension. […]

ThaiCERT

July 15, 2026

RedHook Android Malware Uses Wireless ADB to Control Infected Devices

384/69 Tuesday, July 14, 2026 Security researchers have disclosed that a new version of the RedHook Android malware uses Wireless Android Debug Bridge (ADB) to access the Android shell on infected devices without requiring a connection to a computer or root privileges. After tricking users into granting Accessibility permissions, this technique allows the malware to […]

chanapon

July 14, 2026

Dutch Police Find Leads Linked to Odido Hack Affecting More Than 6 Million Customers

383/69 Tuesday, July 14, 2026 Dutch police have disclosed progress in the investigation into the cyberattack against Odido, one of the country’s major telecommunications providers, which occurred in February 2026. Investigators found indications that the perpetrators may be Dutch nationals or may have connections inside the Netherlands. The incident resulted in the theft of data […]

chanapon

July 14, 2026

Warning: Global Campaign Targets Vulnerable Content Management Systems (CMS) to Deploy Web Shells and Compromise Systems

382/69 Tuesday, July 14, 2026 The Australian Cyber Security Centre (ACSC) has issued an advisory warning of a global cyberattack campaign targeting vulnerabilities in content management systems (CMS) and various plugins. Several organizations and businesses have already been affected by this campaign. This threat is significant and should be closely monitored, as attackers are focusing […]

chanapon

July 14, 2026

CISA Adds Actively Exploited iCagenda and Balbooa Forms Vulnerabilities to KEV Catalog

381/69 Monday, July 13, 2026 CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after finding evidence that they have been actively exploited in attacks. The vulnerabilities are CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa Forms, both of which are Joomla extensions and could allow attackers to upload malicious files to affected […]

chanapon

July 13, 2026

Zimbra Warns of XSS Vulnerability in Classic Web Client That Could Allow Malicious Code Execution via Email

380/69 Monday, July 13, 2026 Zimbra has issued an advisory urging users to update its software to fix a serious vulnerability affecting the Classic Web Client. The vulnerability is a Stored Cross-Site Scripting (Stored XSS) flaw that could allow attackers to send specially crafted emails to execute malicious scripts in a user’s session when the […]

chanapon

July 13, 2026

GigaWiper, a New Windows Backdoor, Combines Data-Wiping and Ransomware Capabilities

379/69 Monday, July 13, 2026 Microsoft security researchers have reported the discovery of a new Windows backdoor malware family called GigaWiper, developed in Golang. The developers combined code from at least three malware families into a modular tool with multiple capabilities. The malware not only functions as a backdoor that allows attackers to covertly control […]

chanapon

July 13, 2026
1 7 8 9 110