Vulnerability Found in 7-Zip, Allowing Bypass of Mark of the Web (MotW) Feature

34/68 Friday, January 24, 2025 A vulnerability has been discovered in the file management software 7-Zip, identified as CVE-2025-0411, which allows attackers to bypass the Mark of the Web (MotW) security feature in Windows. MotW is a Windows security mechanism that tags files downloaded from untrusted sources, such as the internet, to mitigate potential security […]

ThaiCERT

January 24, 2025

Cloudflare Blocks Mirai Botnet DDoS Attack with Speeds of Up to 5.6 Tbps

33/68 Friday, January 24, 2025 Cloudflare revealed on Tuesday that it successfully detected and blocked a distributed denial-of-service (DDoS) attack reaching speeds of up to 5.6 terabits per second (Tbps), marking the largest attack ever recorded. This attack occurred on October 29, 2024, targeting an Internet Service Provider (ISP) in East Asia. The assault utilized […]

ThaiCERT

January 24, 2025

CERT-UA warns of scammers impersonating the agency with fake AnyDesk requests

32/68 Thursday, January 23, 2025 Ukraine’s Computer Emergency Response Team (CERT-UA) has issued a warning about malicious actors impersonating CERT-UA to send fake AnyDesk connection requests. These requests falsely claim to be for cybersecurity inspections. The attackers are using CERT-UA’s logo and fake AnyDesk IDs to deceive targets, employing social engineering techniques to build credibility. […]

ThaiCERT

January 23, 2025

Hewlett Packard Enterprise Investigates Claims by Hacker Group IntelBroker

30/68 Wednesday, January 22, 2025 Hewlett Packard Enterprise (HPE) is investigating claims made by IntelBroker, a hacker group that alleges it is selling stolen data and source code from the company. The data in question reportedly includes product source codes such as Zerto and ILO, SAP Hybris systems, digital certificates, Docker files, and legacy user […]

ThaiCERT

January 22, 2025

The APT group “DoNot Team” uses the Tanzeem malware to attack organizations in South Asia.

29/68 Wednesday, January 22, 2025 Cybersecurity researchers from CYFIRMA have uncovered new Android malware named Tanzeem and Tanzeem Update. The malware is linked to an Indian APT group known as the DoNot Team or APT-C-35, which primarily targets government organizations, military agencies, foreign ministries, and embassies in South Asian countries such as India, Pakistan, Sri […]

ThaiCERT

January 22, 2025

Details of a Vulnerability in Mercedes-Benz MBUX System Revealed

28/68 Tuesday, January 21, 2025 Kaspersky Reveals Over 10 Vulnerabilities in Mercedes-Benz User Experience (MBUX) System Kaspersky has disclosed details of more than 10 vulnerabilities in the Mercedes-Benz User Experience (MBUX) infotainment system. Some of these vulnerabilities could potentially be exploited for Denial of Service (DoS) attacks, data extraction, remote command execution, and privilege escalation. […]

ThaiCERT

January 21, 2025

Critical Vulnerability in W3 Total Cache Plugin Poses Risk of Sensitive Data Leak – Urgent Update Recommended

27/68 Tuesday, January 21, 2025 A severe vulnerability has been identified in the widely-used WordPress plugin, W3 Total Cache, potentially allowing attackers to access sensitive internal service data and metadata on cloud applications. The vulnerability, designated as CVE-2024-12365, carries a CVSS severity score of 8.5. W3 Total Cache is a popular plugin for optimizing WordPress […]

ThaiCERT

January 21, 2025

The U.S. sanctions Chinese cyber companies and hackers linked to the Salt Typhoon group for breaching government agency systems.

26/68 Monday, January 20, 2025 The U.S. Department of the Treasury, through the Office of Foreign Assets Control (OFAC), has imposed sanctions on China’s Sichuan Juxinhe Network Technology Co., LTD. due to its involvement with the Salt Typhoon hacking group, which recently targeted several U.S. telecommunications and internet service providers. Additionally, OFAC has sanctioned Yin […]

ThaiCERT

January 20, 2025

TikTok will be shut down in the United States due to a federal government ban citing security concerns.

25/68 Monday, January 20, 2025 TikTok, the globally popular social media platform, has officially announced its shutdown in the United States starting January 19, 2025, following a federal government ban citing national security concerns. In a notification to its users, TikTok stated, “We deeply regret this service disruption and sincerely thank you for your past […]

ThaiCERT

January 20, 2025
1 2 3 15