Exploits Detected Targeting Vulnerabilities in Cisco Smart Licensing Utility

114/68 Monday, March 24, 2025 Cybersecurity experts have issued warnings following the discovery of active attacks exploiting two newly disclosed vulnerabilities in Cisco Smart Licensing Utility—CVE-2024-20439 and CVE-2024-20440. Both flaws, recently patched by Cisco, are rated Critical with a CVSS score of 9.8. Details of the Vulnerabilities: Although Cisco has released software updates to address […]

ThaiCERT

March 24, 2025

Warning! Hackers Use Fake Chatbots to Steal Instagram Business Accounts

113/68 Monday, March 24, 2025 A new phishing scheme is targeting Instagram business accounts by using fake chatbots and spoofed support emails to trick users into handing over their login credentials. According to the Cofense Phishing Defense Center, the attack begins with a fake notification email claiming that a user’s ad has been suspended due […]

ThaiCERT

March 24, 2025

California Cryobank Discloses Data Breach Impacting Customer Information

112/68 Friday, March 21, 2025 California Cryobank (CCB), one of the largest sperm banks in the United States, has disclosed a data breach that may have exposed customers’ personal information to unauthorized access. Suspicious activity was first detected on April 21, 2024, and an investigation revealed that attackers accessed or stole certain files between April […]

ThaiCERT

March 21, 2025

‘DollyWay’ Malware Campaign Has Been Targeting WordPress Sites Globally for Over 8 Years

111/68 Friday, March 21, 2025 Since 2016, a long-running malware campaign known as “DollyWay” has infected more than 20,000 WordPress websites worldwide, redirecting users to malicious sites including dating scams, online gambling platforms, and various other fraudulent destinations. The campaign has evolved over the years, employing advanced evasion techniques and reinfection mechanisms to maintain persistence. […]

ThaiCERT

March 21, 2025

Microsoft Discovers StilachiRAT Malware Designed for Data Theft and Evasion

110/68 Thursday, March 20, 2025 Microsoft has identified a new malware strain called StilachiRAT, a Remote Access Trojan (RAT) with advanced techniques for hiding itself and stealing sensitive data such as browser passwords, cryptocurrency wallet information, and system details. The malware leverages the WWStartupCtrl64.dll module and utilizes WMI Query Language (WQL) through Web-based Enterprise Management […]

ThaiCERT

March 20, 2025

Unpatched Edimax Camera Vulnerability Exploited in Mirai Botnet Attacks Since 2024

108/68 Wednesday, March 19, 2025 Hackers have been exploiting CVE-2025-1316, a high-severity OS command injection vulnerability (CVSS 9.3) in Edimax IC-7100 cameras, to spread the Mirai Botnet since May 2024. This vulnerability enables remote code execution (RCE) through specially crafted requests. According to Akamai, a Proof-of-Concept (PoC) exploit was publicly available as early as June […]

ThaiCERT

March 19, 2025

SSRF Vulnerability in Open-Source ChatGPT Developed by Chinese Developer Exploited in Attacks

107/68 Wednesday, March 19, 2025 Cybersecurity firm Veriti has reported CVE-2024-27564, a Server-Side Request Forgery (SSRF) vulnerability affecting an open-source ChatGPT version developed by a Chinese developer—a separate platform from OpenAI’s widely used ChatGPT. While categorized as a medium-severity issue, it has been actively exploited in real-world attacks, with 10,479 attempts recorded within a single […]

ThaiCERT

March 19, 2025

Warning! Fake Security Alert Campaign on GitHub Tricks Developers into Approving Malicious Apps

105/68 Tuesday, March 18, 2025 GitHub developers are being targeted in a large-scale phishing campaign that uses fake security alerts to trick users into approving a malicious OAuth app. Attackers send deceptive notifications warning of an “unusual access attempt” from Reykjavik, Iceland, citing a suspicious IP address 53.253.117.8 to create urgency. The notification includes a […]

ThaiCERT

March 18, 2025
1 2 3 21