Two hospitals in the United Kingdom targeted by cyberattacks.

431/67 Tuesday, December 3, 2024 Alder Hey Children’s Hospital in the United Kingdom has disclosed that its systems were targeted in a cyberattack, resulting in the theft and online publication of patient data and other critical information. The ransomware group Inc Ransom claimed responsibility, stating they obtained data spanning from 2018 to 2024. The hospital […]

ThaiCERT

December 3, 2024

Gambling apps use AI-generated voices to deceive users into accessing sensitive information.

430/67 Tuesday, December 3, 2024 Cybersecurity firm Group-IB has issued a warning to internet users after uncovering a scam involving fake gambling apps and deceptive advertisements on social media platforms across various regions, including the Middle East, Europe, and Asia. Criminals use AI-generated multilingual voices to enhance credibility, tricking victims into divulging personal information and […]

ThaiCERT

December 3, 2024

Hackers steal millions of dollars from the Bank of Uganda.

429/67 Monday, December 2, 2024 The Ugandan government confirmed on Thursday that the country’s central bank was the target of a cyberattack by a criminal group seeking financial gain, resulting in significant monetary losses. The incident is under investigation by the Criminal Investigations Directorate and the Auditor General’s office. Henry Musasizi, Uganda’s Minister of State […]

ThaiCERT

December 2, 2024

15 SpyLoan apps discovered on Google Play with over 8 million installations.

428/67 Monday, December 2, 2024 McAfee security researchers have uncovered 15 SpyLoan applications on the Android platform available in the Google Play Store, with a total of over 8 million installations. These apps primarily target users in South America, Southeast Asia, and Africa. Far from being simple loan tools, they act as a means to […]

ThaiCERT

December 2, 2024

VMware Fixes Five Vulnerabilities in Aria Operations

427/67 Friday, November 29, 2024 VMware has released a security update to address five vulnerabilities in its Aria Operations product (formerly known as VMware vRealize Operations), a comprehensive cloud management platform. These vulnerabilities could potentially be exploited for privilege escalation and cross-site scripting (XSS) attacks. The details of the vulnerabilities are as follows: Users of […]

ThaiCERT

November 29, 2024

Hackers Exploit Godot Engine to Distribute GodLoader Malware

426/67 Friday, November 29, 2024 A group of hackers has leveraged the popular open-source Godot Engine to develop and distribute malware called GodLoader. This malware is designed to evade antivirus detection and has already infected over 17,000 systems within just three months. According to Check Point, a cybersecurity research company, GodLoader targets multiple platforms, including […]

ThaiCERT

November 29, 2024

Critical Vulnerability in WordPress Anti-Spam Plugin Allows Remote Exploitation

425/67 Thursday, November 28, 2024 Two critical vulnerabilities, identified as CVE-2024-10542 and CVE-2024-10781, have been discovered in the Spam Protection, Anti-Spam, and Firewall components of WordPress. These vulnerabilities could allow unauthenticated attackers to install and activate malicious plugins on vulnerable websites, potentially leading to remote code execution. Both vulnerabilities have a CVSS severity score of […]

ThaiCERT

November 28, 2024

A U.S. Insurance Company Fined $11.3 Million for Failing to Comply with Data Security Measures

424/67 Thursday, November 28, 2024 The State of New York has fined two auto insurance companies, GEICO and Travelers Indemnity, a total of $11.3 million for failing to secure customer data adequately. This failure allowed cybercriminals to steal the personal information of over 12,000 individuals and use it to file fraudulent unemployment claims during the […]

ThaiCERT

November 28, 2024

CISA adds vulnerabilities in Array Networks AG and vxAG ArrayOS to the Known Exploited Vulnerabilities (KEV) catalog.

423/67 Wednesday, November 27, 2024 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2023-28461, with a CVSS score of 9.8, to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability affects Array Networks AG Series and vxAG ArrayOS (version 9.4.0.481 and earlier). The vulnerability allows attackers to exploit the SSL VPN Gateway through unauthenticated […]

ThaiCERT

November 27, 2024

The RomCom threat group exploits vulnerabilities in Firefox and Windows to deliver advanced malware attacks targeting victims.

422/67 Wednesday, November 27, 2024 The Russian state-sponsored cyber threat group RomCom has been discovered exploiting critical vulnerabilities in Mozilla Firefox and Microsoft Windows to attack victim systems with a backdoor malware of the same name. These attacks leverage vulnerabilities that enable the execution of malicious code without user interaction. The operation involves two major […]

ThaiCERT

November 27, 2024
1 5 6 7 10