Ivanti Releases Patches for Three Critical Vulnerabilities in Connect Secure and Policy Secure

62/68 Friday, February 14, 2025 Ivanti has released security updates for Ivanti Connect Secure (ICS), Ivanti Policy Secure (IPS), and Ivanti Secure Access Client (ISAC) to address three critical vulnerabilities: These vulnerabilities require authentication before exploitation. However, if attackers manage to steal login credentials, they could exploit these flaws to gain control over the system. […]

ThaiCERT

February 14, 2025

1.17TB Data Leak Exposes Wi-Fi Passwords and IPs from Mars Hydro’s IoT Grow Light Devices

61/68 Friday, February 14, 2025 A major data breach has been discovered in the database of Mars Hydro, a manufacturer of smart IoT grow lights, exposing over 1.17 terabytes of data and 2.7 billion records without any security protection. The leaked information includes Wi-Fi network names (SSIDs), passwords, IP addresses, device IDs, email addresses, and […]

ThaiCERT

February 14, 2025

OpenSSL Releases Patch for CVE-2024-12797 Vulnerability

60/68 Thursday, February 13, 2025 OpenSSL has released a patch addressing the high-severity vulnerability CVE-2024-12797, which was discovered by Apple. This flaw could allow Man-in-the-Middle (MitM) attacks. OpenSSL is a widely used cryptographic library that secures network communications by encrypting data and verifying identities. It supports Secure Sockets Layer (SSL) and Transport Layer Security (TLS) […]

ThaiCERT

February 13, 2025

Critical vulnerability in KerioControl firewall exploited by hackers.

59/68 Thursday, February 13, 2025 Security experts have issued a warning that more than 12,000 KerioControl firewalls from GFI Software have been compromised through the critical CVE-2024-52875 vulnerability. This flaw allows hackers to execute remote code (RCE). The vulnerability was discovered by researcher Egidio Romano (EgiX) in mid-December 2024 and was first patched in version […]

ThaiCERT

February 13, 2025

Zimbra Releases Security Update to Patch SQL Injection, Stored XSS, and SSRF Vulnerabilities

58/68 Tuesday, February 11, 2025 Zimbra has released a software update to address critical security vulnerabilities that could lead to data exposure if exploited. The vulnerability tracked as CVE-2025-25064 has been assigned a CVSS score of 9.8 and is an SQL Injection flaw in the ZimbraSync Service SOAP endpoint, affecting versions prior to 10.0.12 and […]

ThaiCERT

February 11, 2025

Sophos Warns: Hackers Using SVG Files to Spread Malware and Phishing Links

57/68 Tuesday, February 11, 2025 Security researchers from Sophos have reported that cybercriminals are increasingly using Scalable Vector Graphics (SVG) files to distribute malicious links via phishing emails. SVG files can open automatically in web browsers on Windows and support XML commands, allowing attackers to embed links to dangerous websites or inject malicious code. Sophos […]

ThaiCERT

February 11, 2025

CISA Adds Trimble Cityworks Vulnerability to Known Exploited Vulnerabilities (KEV) Catalog

56/68 Monday, February 10, 2025 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the Trimble Cityworks vulnerability CVE-2025-0994 to its Known Exploited Vulnerabilities (KEV) Catalog. Trimble Cityworks is an asset management and permitting software that utilizes GIS technology for local governments, public utilities, and infrastructure organizations. The software integrates with Esri’s ArcGIS to […]

ThaiCERT

February 10, 2025

Joint Operation Arrests Notorious Hacker “Natohub” After Attacking Over 40 Government and Private Sector Entities

55/68 Monday, February 10, 2025 Spanish police and the Civil Guard have successfully arrested a key suspect in a major cybercrime case, known as “Natohub” on the Breach Forums platform. The suspect is accused of orchestrating over 40 cyberattacks targeting both government and private sector organizations in Spain and internationally. These attacks involved breaches of […]

ThaiCERT

February 10, 2025

New Veeam Vulnerability Allows Arbitrary Code Execution via Man-in-the-Middle Attack

54/68 Friday, February 7, 2025 Veeam has released a patch to address a vulnerability in its backup software that could allow attackers to execute malicious code on affected systems. The vulnerability, identified as CVE-2025-23114, has been assigned a CVSS severity score of 9.0. According to Veeam, the issue lies within the Veeam Updater Component, which […]

ThaiCERT

February 7, 2025

International Civil Aviation Organization (ICAO) Faces Major Data Breach

53/68 Friday, February 7, 2025 The International Civil Aviation Organization (ICAO) is urgently investigating a data breach that has impacted its systems and employee security. In its latest statement, ICAO confirmed reports of a potential security incident linked to a threat group known for targeting international organizations. The breach came to light after a post […]

ThaiCERT

February 7, 2025
1 2 3 16