Unpatched Edimax Camera Vulnerability Exploited in Mirai Botnet Attacks Since 2024

108/68 Wednesday, March 19, 2025 Hackers have been exploiting CVE-2025-1316, a high-severity OS command injection vulnerability (CVSS 9.3) in Edimax IC-7100 cameras, to spread the Mirai Botnet since May 2024. This vulnerability enables remote code execution (RCE) through specially crafted requests. According to Akamai, a Proof-of-Concept (PoC) exploit was publicly available as early as June […]

ThaiCERT

March 19, 2025

SSRF Vulnerability in Open-Source ChatGPT Developed by Chinese Developer Exploited in Attacks

107/68 Wednesday, March 19, 2025 Cybersecurity firm Veriti has reported CVE-2024-27564, a Server-Side Request Forgery (SSRF) vulnerability affecting an open-source ChatGPT version developed by a Chinese developer—a separate platform from OpenAI’s widely used ChatGPT. While categorized as a medium-severity issue, it has been actively exploited in real-world attacks, with 10,479 attempts recorded within a single […]

ThaiCERT

March 19, 2025

Warning! Fake Security Alert Campaign on GitHub Tricks Developers into Approving Malicious Apps

105/68 Tuesday, March 18, 2025 GitHub developers are being targeted in a large-scale phishing campaign that uses fake security alerts to trick users into approving a malicious OAuth app. Attackers send deceptive notifications warning of an “unusual access attempt” from Reykjavik, Iceland, citing a suspicious IP address 53.253.117.8 to create urgency. The notification includes a […]

ThaiCERT

March 18, 2025

Warning! Malicious PyPI Packages Stealing Cloud Tokens Downloaded Over 14,100 Times Before Removal

104/68 Monday, March 17, 2025 Cybersecurity researchers have uncovered a malicious campaign using fake packages in the Python Package Index (PyPI) to steal sensitive data, including cloud access tokens. According to ReversingLabs, 20 malicious packages were identified in two separate sets, collectively downloaded over 14,100 times before being removed from PyPI. The most downloaded malicious […]

ThaiCERT

March 17, 2025

ClickFix Technique Gains Popularity Among Cybercriminals and APT Groups for Attacking Victims

103/68 Monday, March 17, 2025 Cybersecurity firm Group-IB has revealed that since August 2024, state-sponsored hacker groups (APT groups) and cybercriminals have increasingly used the ClickFix technique in data-stealing malware attacks. ClickFix is a social engineering deception that leverages JavaScript on web pages to display fake system update alerts or reCAPTCHA verification prompts. When victims […]

ThaiCERT

March 17, 2025

Microsoft Releases March 2025 Patch Tuesday Security Update, Fixing Six Zero-Day Vulnerabilities

102/68 Friday, March 14, 2025 Microsoft has released its March 2025 Patch Tuesday security update, addressing a total of 56 vulnerabilities across various products, including Windows and Windows Components, Office and Office Components, Azure, .NET and Visual Studio, Remote Desktop Services, DNS Server, and Hyper-V Server. Among these, six zero-day vulnerabilities have been actively exploited […]

ThaiCERT

March 14, 2025

CISA Warning! Medusa Ransomware Attacks Over 300 Critical Infrastructure Organizations in the U.S.

101/68 Friday, March 14, 2025 The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the FBI and the Multi-State Information Sharing and Analysis Center (MS-ISAC), has issued a warning regarding the Medusa ransomware, which has impacted more than 300 organizations across critical sectors such as healthcare, education, law, insurance, technology, and manufacturing since […]

ThaiCERT

March 14, 2025

CISA Adds Advantive VeraCore and Ivanti EPM Vulnerabilities to Known Exploited Vulnerabilities (KEV) Catalog

100/68 Thursday, March 13, 2025 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities affecting Advantive VeraCore and Ivanti Endpoint Manager (EPM) to its Known Exploited Vulnerabilities (KEV) Catalog: CISA has identified that the Vietnam-based cybercrime group XE Group is actively exploiting VeraCore vulnerabilities to infiltrate target systems, deploying reverse shells and […]

ThaiCERT

March 13, 2025

Lazarus Hackers Use npm to Spread Malware Targeting Software Developers

99/68 Thursday, March 13, 2025 The North Korean state-sponsored hacking group Lazarus has resurfaced, employing typosquatting tactics to distribute malicious npm packages. These fake packages mimic popular ones, tricking developers into downloading and installing malware. Researchers from the Socket Research Team discovered six such malicious packages, which have already been downloaded over 330 times. The […]

ThaiCERT

March 13, 2025
1 2 3 4 21