<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cyber Security News]]></title><description><![CDATA[พูดคุยข่าวสารเกี่ยวกับภัยคุกคามทางไซเบอร์ทั่วประเทศ และข่าวประกาศเกี่ยวกับความปลอดภัยทางไซเบอร์ทั่วไป]]></description><link>https://webboard-nsoc.ncsa.or.th/category/12</link><generator>RSS for Node</generator><lastBuildDate>Mon, 13 Jul 2026 15:17:13 GMT</lastBuildDate><atom:link href="https://webboard-nsoc.ncsa.or.th/category/12.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 13 Jul 2026 10:03:21 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[ETDA Cyber Threat Intelligence 13 July 2026]]></title><description><![CDATA[<p dir="auto"><strong>Financial Sector</strong></p>
<ul>
<li><strong>Only 28% Of Financial Workforce MFA Is Phishing-Resistant</strong><br />
"Passwords remain part of many workforce authentication flows in financial organizations, making phishing and credential theft major identity security risks, according to a new Secret Double Octopus report. Banks and financial organizations use a mix of authentication methods, combining phishing-resistant technologies with methods that remain vulnerable to phishing attacks."<br />
<a href="https://www.helpnetsecurity.com/2026/07/10/financial-identity-security-trends-report/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/10/financial-identity-security-trends-report/</a></li>
<li><strong>Fresh ATM Crypto Software Bugs: Jackpot Or Bust?</strong><br />
"A researcher has discovered nine vulnerabilities in an ATM and corporate security program. The researcher and major ATM manufacturer Diebold Nixdorf disagree, though, about whether it could allow attackers to steal cash or not. At Black Hat USA 2026, Matt Burch, principal security researcher for Atredis Partners, will present nine new vulnerabilities he discovered in CryptWare CryptoPro Secure Disk. CryptoPro, for short, is a full‑disk encryption (FDE) and pre‑boot authentication solution for Windows that, strangely, is marketed to both corporations generally and ATM manufacturers specifically."<br />
<a href="https://www.darkreading.com/vulnerabilities-threats/atm-crypto-software-bugs-jackpot-bust" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/vulnerabilities-threats/atm-crypto-software-bugs-jackpot-bust</a></li>
</ul>
<p dir="auto"><strong>Healthcare Sector</strong></p>
<ul>
<li><strong>Healthcare Ransomware Roundup: H1 2026 Stats On Attacks, Ransoms, And Data Breaches</strong><br />
"During the first six months of 2026, the healthcare sector suffered an average of 2.3 ransomware attacks per day. Attacks increased by nearly 14 percent when compared to H2 2025, rising from 360 to 410. Of the 410 attacks we recorded in H1 2026, 247 were on hospitals, clinics, and other direct care providers. 163 hit businesses operating within the healthcare sector, such as pharmaceutical/medical manufacturers, medical billing providers, and healthcare tech companies. Attacks on healthcare providers rose just over three percent from H2 2025, but attacks on healthcare businesses rose nearly 35 percent."<br />
<a href="https://www.comparitech.com/news/healthcare-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.comparitech.com/news/healthcare-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/</a><br />
<a href="https://www.darkreading.com/threat-intelligence/cybercriminals-healthcare-businesses-attacks-surge" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/threat-intelligence/cybercriminals-healthcare-businesses-attacks-surge</a></li>
</ul>
<p dir="auto"><strong>Industrial Sector</strong></p>
<ul>
<li><strong>OpenPLC v3</strong><br />
"Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to the filesystem and escalate this into arbitrary native code execution through the normal OpenPLC program compilation process, potentially resulting in code execution as the OpenPLC runtime user."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-01" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-01</a></li>
<li><strong>Schneider Electric PowerChute Serial Shutdown</strong><br />
"Successful exploitation of these vulnerabilities could allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger denial‑of‑service conditions, truncate or alter logging information, reset user credentials, or expose sensitive information."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-02" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-02</a></li>
<li><strong>Schneider Electric Easergy MiCOM Px40 Series</strong><br />
"Schneider Electric is aware of a vulnerability in its Easergy MiCOM Px40 Series products. The <a href="https://www.se.com/ww/en/product-subcategory/4725-easergy-micom-px40-series/?filter=business-6-medium-voltage-distribution-and-grid-automation" target="_blank" rel="noopener noreferrer nofollow ugc">Easergy MiCOM Px40</a> is a protection relay series for Medium Voltage, High Voltage and Extra High Voltage protection. Failure to apply the mitigations provided below may risk unauthorized exposure of basic device identification through the SNMP protocol."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-03" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-190-03</a></li>
</ul>
<p dir="auto"><strong>Vulnerabilities</strong></p>
<ul>
<li><strong>URGENT - Progress Tells ShareFile Customers To Shut Down Storage Zone Controllers Over Security Threat</strong><br />
"Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a "credible external security threat." The company has temporarily disabled access to the affected accounts, a step it says it took "out of an abundance of caution" while it works with internal and external security experts. It says it has no indication of unauthorized access to any ShareFile accounts or data, and that it notified customers after learning of the threat. What Progress has not said is what the threat is or who is behind it."<br />
<a href="https://thehackernews.com/2026/07/urgent-progress-tells-sharefile.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/urgent-progress-tells-sharefile.html</a><br />
<a href="https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/</a><br />
<a href="https://securityaffairs.com/195194/hacking/progress-told-sharefile-customers-to-pull-the-plug-on-their-servers-heres-what-we-know.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/195194/hacking/progress-told-sharefile-customers-to-pull-the-plug-on-their-servers-heres-what-we-know.html</a></li>
<li><strong>Zimbra Urges Customers To Patch Critical Web Client XSS Flaw</strong><br />
"The Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration suite. Zimbra is a very popular email and collaboration software suite used by hundreds of millions of people, including thousands of businesses and hundreds of government agencies worldwide. Also known as the Classic UI, this Ajax-based webmail interface is faster than Zimbra's modern web client, which requires more resources when loading large email folders. The company released Zimbra 10.1.19 this Tuesday to patch this stored cross-site scripting (XSS) security flaw, which has yet to receive a CVE ID for easy tracking. Attackers can exploit this Classic Web Client security issue through specially crafted emails that execute malicious code when the email is opened."<br />
<a href="https://www.bleepingcomputer.com/news/security/zimbra-urges-customers-to-patch-critical-web-client-xss-flaw/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/zimbra-urges-customers-to-patch-critical-web-client-xss-flaw/</a><br />
<a href="https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-19/" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-19/</a><br />
<a href="https://thehackernews.com/2026/07/critical-zimbra-flaw-could-let-crafted_0483473395.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/critical-zimbra-flaw-could-let-crafted_0483473395.html</a><br />
<a href="https://securityaffairs.com/195130/hacking/update-now-critical-zimbra-classic-web-client-flaw-could-expose-mailboxes.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/195130/hacking/update-now-critical-zimbra-classic-web-client-flaw-could-expose-mailboxes.html</a></li>
<li><strong>CISA Adds Two Known Exploited Vulnerabilities To Catalog</strong><br />
"CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.<br />
CVE-2026-48939 iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability<br />
CVE-2026-56291 Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability"<br />
<a href="https://www.cisa.gov/news-events/alerts/2026/07/10/cisa-adds-two-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/alerts/2026/07/10/cisa-adds-two-known-exploited-vulnerabilities-catalog</a><br />
<a href="https://securityaffairs.com/195164/security/u-s-cisa-adds-icagenda-and-balbooa-forms-flaws-to-its-known-exploited-vulnerabilities-catalog.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/195164/security/u-s-cisa-adds-icagenda-and-balbooa-forms-flaws-to-its-known-exploited-vulnerabilities-catalog.html</a></li>
<li><strong>Unfit To Boot: Breaking U-Boot's FIT Signature Verification</strong><br />
"U-Boot is one of the most widely used bootloaders in the world. It runs on a huge variety of hardware, from home routers and smart cameras to the Baseboard Management Controllers (BMCs), which are commonly used to remotely manage servers in large data centres. As a bootloader, its job usually includes initialising the CPU and memory, bringing up the essential peripherals, and finally handing over execution to the next stage of the boot chain."<br />
<a href="https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification</a><br />
<a href="https://www.bleepingcomputer.com/news/security/new-u-boot-flaws-could-enable-stealthy-firmware-attacks/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/new-u-boot-flaws-could-enable-stealthy-firmware-attacks/</a><br />
<a href="https://thehackernews.com/2026/07/six-new-u-boot-flaws-could-let.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/six-new-u-boot-flaws-could-let.html</a><br />
<a href="https://securityaffairs.com/195150/security/critical-u-boot-bugs-undermine-secure-boot-on-millions-of-devices.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/195150/security/critical-u-boot-bugs-undermine-secure-boot-on-millions-of-devices.html</a></li>
<li><strong>Bypassing Tangem Card Security With a Laser Attack</strong><br />
"After uncovering a genuine check bypass on the Tangem Android application and a brute-force attack on the card's authentication protocol, the Ledger Donjon turned its attention to the card itself with more advanced tools and sophisticated techniques. What we found is a critical vulnerability that lets an attacker with physical access to a single Tangem card reset its password and steal all associated funds."<br />
<a href="https://donjon.ledger.com/blog/bypassing-tangem-card-security-with-laser-attack/" target="_blank" rel="noopener noreferrer nofollow ugc">https://donjon.ledger.com/blog/bypassing-tangem-card-security-with-laser-attack/</a><br />
<a href="https://thehackernews.com/2026/07/laser-attack-resets-tangem-wallet.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/laser-attack-resets-tangem-wallet.html</a></li>
<li><strong>I Sent a WhatsApp Message To An AI Agent. It Ran My Code On The Host.</strong><br />
"There's a particular feeling you get when you watch an AI agent cheerfully execute a payload you just sent it over WhatsApp. It's somewhere between fascination and dread. Like watching someone hold the front door open for a burglar because they said they were from maintenance. Last week, I sent a perfectly normal-looking debugging request to an OpenClaw AI assistant over WhatsApp. Thirty seconds later, I had arbitrary code execution on the host machine. The AI — Claude Sonnet 4, arguably the most safety-aligned model commercially available — didn't just allow it. It helped. It formatted the output nicely and asked if I needed anything else."<br />
<a href="https://medium.com/@chinmohannayak/i-sent-a-whatsapp-message-to-an-ai-agent-it-ran-my-code-on-the-host-adbbcbb0e0ad" target="_blank" rel="noopener noreferrer nofollow ugc">https://medium.com/@chinmohannayak/i-sent-a-whatsapp-message-to-an-ai-agent-it-ran-my-code-on-the-host-adbbcbb0e0ad</a><br />
<a href="https://thehackernews.com/2026/07/researcher-details-whatsapp-to-host.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/researcher-details-whatsapp-to-host.html</a></li>
<li><strong>XRING: Crashing XQUIC With Spec-Compliant QPACK Instructions</strong><br />
"During recent research into the different QUIC stacks for our active TLS scanner, JA4Scan, I found a deterministic remote crash in XQUIC, Alibaba's QUIC and HTTP/3 library, dubbed XRING. XQUIC enables HTTP/3 support for Tengine, the Nginx-based web server Alibaba runs across its cloud and CDN infrastructure, including sites like Taobao or AliPay. A remote, unauthenticated client sends spec-compliant HTTP/3 operation traffic and the server process terminates. The crash requires only 260 bytes of client traffic. Every XQUIC version is impacted. There is no patch available."<br />
<a href="https://foxio.io/blog/xring-crashing-xquic-with-spec-compliant-qpack-instructions" target="_blank" rel="noopener noreferrer nofollow ugc">https://foxio.io/blog/xring-crashing-xquic-with-spec-compliant-qpack-instructions</a><br />
<a href="https://thehackernews.com/2026/07/unpatched-xring-flaw-in-xquic-lets.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/unpatched-xring-flaw-in-xquic-lets.html</a></li>
<li><strong>Study Of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, And Tracking</strong><br />
"Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics people install a VPN for, i.e., keeping their traffic private and secure. The apps flagged with at least one problem have been installed more than 2.4 billion times. The problems are basic, not sophisticated. 29 apps let user traffic leak outside the encrypted tunnel, including the DNS lookups that reveal which websites you visit. 61 apps send some data in plain text that anyone watching the traffic on that network can read."<br />
<a href="https://thehackernews.com/2026/07/study-of-281-free-android-vpn-apps.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/study-of-281-free-android-vpn-apps.html</a></li>
<li><strong>The ‘Ghost’ In The Database: Recovering Active ADFS Signing Keys Via Machine DPAPI</strong><br />
"The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to any SAML-federated application, bypassing multifactor authentication (MFA), conditional access, and all identity-based controls."<br />
<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer nofollow ugc">https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi</a></li>
<li><strong>We Put The Exploit In a Picture. The AI Code Reviewer Never Opened It.</strong><br />
"Almost nobody reviews the pull request. We surveyed 6,480 pull requests across the 300 most active public repositories of the last ninety days, and 73% of the ones that got merged reached the default branch with no substantive human review and no bot review at all. The thing filling that gap is a new kind of reviewer: an LLM that reads every diff and comments like a human would. Cursor Bugbot and CodeRabbit are the two with real deployment. Hence, we built a pull request that steals a repository's secrets and walks straight past both of them. The trick is that the malicious instruction is not text. It is a picture."<br />
<a href="https://asset-group.github.io/disclosures/ghostcommit/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asset-group.github.io/disclosures/ghostcommit/</a><br />
<a href="https://www.bleepingcomputer.com/news/security/ghostcommit-hides-prompt-injection-in-images-to-fool-ai-agents-steal-secrets/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/ghostcommit-hides-prompt-injection-in-images-to-fool-ai-agents-steal-secrets/</a></li>
</ul>
<p dir="auto"><strong>Malware</strong></p>
<ul>
<li><strong>Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories</strong><br />
"Our investigation began with a malicious Go module, github[.]com/kaleidora/dnsub-scanning-tool, that posed as a DNS/subdomain scanner. The module did more than impersonate a developer utility: it exposed a Windows malware-staging chain that used hidden PowerShell execution, public dead-drop resolution, protected archive delivery, and RAT/infostealer deployment. Pivoting from that module revealed the larger finding: a GitHub-based lure network of 222 confirmed repositories across 190 accounts, built to make malicious or deceptive software projects look active, plausible, and recently maintained."<br />
<a href="https://socket.dev/blog/malicious-go-module-exposes-github-malware-lure-network" target="_blank" rel="noopener noreferrer nofollow ugc">https://socket.dev/blog/malicious-go-module-exposes-github-malware-lure-network</a><br />
<a href="https://www.securityweek.com/network-of-200-github-repositories-used-for-malware-infection/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/network-of-200-github-repositories-used-for-malware-infection/</a><br />
<a href="https://securityaffairs.com/195101/security/222-github-repositories-linked-to-fake-go-package-malware-operation.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/195101/security/222-github-repositories-linked-to-fake-go-package-malware-operation.html</a></li>
<li><strong>One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement</strong><br />
"Suspected China- and India-nexus threat actors carried out intrusions into several Pakistani law enforcement organizations between 2024 and 2026. Our analysis of C2 netflow data revealed that suspected China- and India-nexus threat actors operating PlugX, ShadowPad, Cobalt Strike, and Remcos infrastructure have converged on this victim class. All of these threat actors were active against Balochistan Police, the principal police force serving the Pakistani province of the same name, at various points between 2024 and 2026."<br />
<a href="https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/</a><br />
<a href="https://therecord.media/china-india-ran-separate-spy-campaigns-against-same-police-force" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/china-india-ran-separate-spy-campaigns-against-same-police-force</a><br />
<a href="https://thehackernews.com/2026/07/hackers-weaponize-balochistan-police.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/hackers-weaponize-balochistan-police.html</a><br />
<a href="https://www.securityweek.com/china-india-linked-hackers-both-targeted-same-pakistani-police-force/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/china-india-linked-hackers-both-targeted-same-pakistani-police-force/</a></li>
<li><strong>Operation Phnom Penh: Silver Fox Ghost Distributor Targets Specific Victims With MODBEACON Custom Trojan</strong><br />
""Silver Fox / UTG-Q-1000" has long been regarded as a byword for low-sophistication, high-activity cybercriminal operations that distribute counterfeit software via SEO channels. However, behind the scenes lies an organizational structure resembling foreign Malware-as-a-Service (MaaS), composed of multiple distributors. These distributors conduct activities across Asia using counterfeit software installers distributed through SEO campaigns, leveraging variants of Ghost and WinOS (ValleyRat) trojan families. In 2025, we countered one such distributor[1], whose remote-control objective was limited to delivering fraud links in IM group chats, with no involvement in information theft or political motives."<br />
<a href="https://ti.qianxin.com/blog/articles/operation-phnom-penh-silverfox-ghost-distributor-targets-specific-victims-with-modbeacon-en/" target="_blank" rel="noopener noreferrer nofollow ugc">https://ti.qianxin.com/blog/articles/operation-phnom-penh-silverfox-ghost-distributor-targets-specific-victims-with-modbeacon-en/</a><br />
<a href="https://thehackernews.com/2026/07/new-modbeacon-rat-uses-grpc-streaming.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/new-modbeacon-rat-uses-grpc-streaming.html</a></li>
<li><strong>How WP-SHELLSTORM Exposed 1.4M WordPress Sites</strong><br />
"Every so often, a threat actor’s mistake hands over the keys to their entire operation. That’s what happened here: a Python SimpleHTTPServer instance, left open for 22 days, exposed the full toolkit, logs, and target lists of a professional, financially motivated cybercrime group. The SOCRadar Threat Intelligence Team found it. What turned up, now tracked as WP-SHELLSTORM, is a modern webshell access-brokerage operation: over 1.4 million targeted domains, 27 CVEs weaponized, more than 5,700 active webshells, and a second, quieter campaign hitting enterprise Java infrastructure that hasn’t surfaced in other public reporting on this actor."<br />
<a href="https://socradar.io/blog/wp-shellstorm-expose-1-4m-wordpress-sites/" target="_blank" rel="noopener noreferrer nofollow ugc">https://socradar.io/blog/wp-shellstorm-expose-1-4m-wordpress-sites/</a><br />
<a href="https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html</a></li>
<li><strong>Attackers Exploit 'Ill Bloom' Vulnerability To Drain Over $5 Million From Cryptocurrency Wallets</strong><br />
"Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated its recovery phrase, the words that control the money. When that phrase is made with weak randomness, an attacker can work it out and take everything it controls. The firm has confirmed one coordinated sweep on May 27 that drained about $3.1 million from 431 wallets, and it told The Hacker News that a further $2.1 million in USDT was stolen from an exposed wallet afterward, pushing confirmed losses past $5 million."<br />
<a href="https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html</a></li>
<li><strong>No Manners Here: The Ruthless Rise Of The Gentlemen Ransomware</strong><br />
"The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS, which Unit 42 tracks as Spikey Scorpius. Their ransomware variants are written in both C and Go programming languages, enabling the threat actors to spread their encryptors across different operating systems and virtual infrastructure. Figure 1 below illustrates the desktop wallpaper used by the ransomware after deployment."<br />
<a href="https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/" target="_blank" rel="noopener noreferrer nofollow ugc">https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/</a></li>
<li><strong>Deadlock Ransomware Group</strong><br />
"DeadLock is a financially motivated ransomware group that emerged in mid-July 2025. The group employs double extortion tactics, demanding ransom payments in cryptocurrencies while threatening to sell stolen data on underground markets. They utilize innovative techniques, such as blockchain smart contracts, to manage their command-and-control infrastructure, enhancing their evasion capabilities."<br />
<a href="https://socradar.io/free-tools/ransomware-intelligence/groups/deadlock" target="_blank" rel="noopener noreferrer nofollow ugc">https://socradar.io/free-tools/ransomware-intelligence/groups/deadlock</a></li>
<li><strong>Jscrambler Npm Package Publishes Malicious Preinstall Binary</strong><br />
"On July 11, 2026, version 8.14.0 of jscrambler was published to npm carrying a malicious preinstall hook that drops and executes a platform-specific native binary on Linux, Windows, and macOS. jscrambler is the official CLI client for the Jscrambler Code Integrity API, a commercial JavaScript obfuscation and web-app protection service, with a clean version history dating back to 0.1.0. The compromised release was flagged by StepSecurity's AI Release Analyzer with a suspicion score of 0 (the maximum suspicion rating) on publish."<br />
<a href="https://www.stepsecurity.io/blog/jscrambler-npm-package-publishes-malicious-preinstall-binary" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.stepsecurity.io/blog/jscrambler-npm-package-publishes-malicious-preinstall-binary</a><br />
<a href="https://safedep.io/jscrambler-npm-supply-chain-compromise/" target="_blank" rel="noopener noreferrer nofollow ugc">https://safedep.io/jscrambler-npm-supply-chain-compromise/</a><br />
<a href="https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html</a></li>
</ul>
<p dir="auto"><strong>Breaches/Hacks/Leaks</strong></p>
<ul>
<li><strong>Police Suspects Dutch Hackers Were Involved In Odido Breach</strong><br />
"The Dutch National Police (Politie) says it has found "strong indications" that Dutch hackers have been involved in a February breach at the telecommunications provider Odido. "This includes a telephone conversation that was made with Odido customer service shortly before the hack. In this conversation, a Dutch-speaking man posed as Odido's IT employee. The company was then misled through phishing, after which the data theft took place," the police said in a Thursday press release."<br />
<a href="https://www.bleepingcomputer.com/news/security/police-suspects-dutch-hackers-were-involved-in-odido-breach/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/police-suspects-dutch-hackers-were-involved-in-odido-breach/</a><br />
<a href="https://therecord.media/dutch-police-suspect-dutch-accomplice-in-odido-cyberattack" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/dutch-police-suspect-dutch-accomplice-in-odido-cyberattack</a></li>
<li><strong>Fashion Mart Miinto Unzips Breach Details, Warns Shoppers To Watch For Phisherfolk</strong><br />
"Danish ecommerce company Miinto admitted an intruder has been looking at its order data, according to emails it sent to customers this week. The emails, seen by The Register, do not comment on the scale of the data accessed by the perp or how exactly the breach occurred, although UK-based customers of the Copenhagen-HQ'd biz have received them. “We are writing to let you know about a security incident that may have affected some of the personal data associated with a purchase you made on Miinto,” the email states."<br />
<a href="https://www.theregister.com/security/2026/07/10/miinto-fesses-up-to-breach-says-customers-open-to-phishing/5269891" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/07/10/miinto-fesses-up-to-breach-says-customers-open-to-phishing/5269891</a></li>
</ul>
<p dir="auto"><strong>General News</strong></p>
<ul>
<li><strong>The Open Source Library Holding Up Your Stack Might Have One Maintainer</strong><br />
"Every serious software product runs on code that someone else wrote and released for free. A web service leans on a cryptography library, a data pipeline pulls in a parser, and a mobile app ships a handful of small utilities that one person maintains in spare time. All of it carries the same label. A new paper argues that the single label hides differences large enough to change how each piece behaves once it lands in production. Researchers sorted open source software into fourteen sub-genres, each defined by who starts and sustains a project and to what end. Their review screened close to four thousand unique papers drawn from two scholarly indexes. The result is a typology, along with an argument that the kind of project a study samples sets how far its conclusions travel."<br />
<a href="https://www.helpnetsecurity.com/2026/07/10/open-source-software-library-types/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/10/open-source-software-library-types/</a><br />
<a href="https://arxiv.org/pdf/2607.01750" target="_blank" rel="noopener noreferrer nofollow ugc">https://arxiv.org/pdf/2607.01750</a></li>
<li><strong>Most Data Brokers Won’t Tell You What Happened To Your Deletion Request</strong><br />
"Data brokers collect personal details on most adults in the United States and sell them to buyers that include employers, landlords, insurance companies, and government agencies. California gives residents a way to push back. You can ask a broker to delete your records, or to stop selling and sharing them. A team at UC Irvine decided to find out what happens when someone sends those requests to the whole California registry. The answer gives consumers little comfort. The researchers sent deletion and opt-out requests to every reachable broker on California’s public list in the fall of 2025. That worked out to 322 deletion requests and close to 360 opt-out requests. To keep real people out of the mix, they built two made-up identities, one for each request type, each with a working email address and a plausible California address."<br />
<a href="https://www.helpnetsecurity.com/2026/07/10/trouble-with-data-broker-deletion-requests/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/10/trouble-with-data-broker-deletion-requests/</a><br />
<a href="https://arxiv.org/pdf/2607.04552" target="_blank" rel="noopener noreferrer nofollow ugc">https://arxiv.org/pdf/2607.04552</a></li>
<li><strong>Evolving Windows Vulnerability Management To Meet The Speed Of AI-Powered Discovery</strong><br />
"Windows has adapted to emerging threats for decades, all while operating at unparalleled scale. It’s our responsibility to bring clarity, transparency and sustained investment so customers understand what is happening, what Microsoft is doing and how they can reduce their exposure. The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code, with new mechanisms that can accelerate both discovery and analysis. The fastest way to reduce customer exposure is to find issues before attackers can use them. Windows is expanding its ability across the platform to find issues earlier, accelerate the engineering work to fix them, strengthen validation and deliver timely, high-quality updates that keep customers protected."<br />
<a href="https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/" target="_blank" rel="noopener noreferrer nofollow ugc">https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/</a><br />
<a href="https://www.theregister.com/security/2026/07/10/microsoft-warns-customers-ai-will-mean-busier-patch-tuesdays/5269618" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/07/10/microsoft-warns-customers-ai-will-mean-busier-patch-tuesdays/5269618</a><br />
<a href="https://www.infosecurity-magazine.com/news/microsoft-increase-number-security/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/microsoft-increase-number-security/</a></li>
<li><strong>Armenian National Extradited To The United States Pleads Guilty To Ransomware Extortion Conspiracy</strong><br />
"An Armenian national extradited from Ukraine to the United States pleaded guilty yesterday for his role in Ryuk ransomware attacks and an extortion conspiracy targeting companies throughout the United States, including a technology company operating in Oregon. Karen Serobovich Vardanyan, 34, pleaded guilty to conspiracy and computer fraud."<br />
<a href="https://www.justice.gov/usao-or/pr/armenian-national-extradited-united-states-pleads-guilty-ransomware-extortion-conspiracy" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.justice.gov/usao-or/pr/armenian-national-extradited-united-states-pleads-guilty-ransomware-extortion-conspiracy</a><br />
<a href="https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-pleads-guilty-in-the-us-faces-15-years-in-prison/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-pleads-guilty-in-the-us-faces-15-years-in-prison/</a><br />
<a href="https://therecord.media/ryuk-operator-pleads-guilty-alphv-conspirator-sentenced" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/ryuk-operator-pleads-guilty-alphv-conspirator-sentenced</a><br />
<a href="https://cyberscoop.com/karen-vardanyan-armenian-ryuk-ransomware-guilty/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/karen-vardanyan-armenian-ryuk-ransomware-guilty/</a><br />
<a href="https://securityaffairs.com/195216/uncategorized/ryuk-ransomware-member-pleads-guilty-over-attacks-on-u-s-organizations.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/195216/uncategorized/ryuk-ransomware-member-pleads-guilty-over-attacks-on-u-s-organizations.html</a></li>
<li><strong>Man Serving Federal Prison Sentence Charged With Theft Of Forfeited Cryptocurrency</strong><br />
"Rossen G. Iossifov, 53, a Bulgarian national, made an initial appearance in federal court in the Eastern District of Kentucky yesterday on charges of the destruction or removal of property to prevent seizure, aiding and abetting, and conspiracy to commit money laundering. The charges stem from Iossifov’s alleged role in the unauthorized withdrawal and transfer of approximately $290,000 in cryptocurrency that had been seized and forfeited by the United States."<br />
<a href="https://www.justice.gov/opa/pr/man-serving-federal-prison-sentence-charged-theft-forfeited-cryptocurrency" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.justice.gov/opa/pr/man-serving-federal-prison-sentence-charged-theft-forfeited-cryptocurrency</a><br />
<a href="https://www.bleepingcomputer.com/news/security/money-launderer-accused-of-stealing-seized-crypto-while-in-prison/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/money-launderer-accused-of-stealing-seized-crypto-while-in-prison/</a></li>
<li><strong>Lessons From CISA’s Cyber Incident</strong><br />
"Sharing experiences from incident response activities help other organizations learn from such experiences and enables them to take necessary precautions to prevent similar incidents from happening in their environments. For years, CISA has said this type of information exchange is critical to identifying trends and contributing to broader national awareness. Now, it is our turn. On Friday, May 15, CISA began an internal incident response when an investigative reporter inquired about internal CISA Amazon AWS GovCloud Keys and other information being made available in a public repository. The reporter received this information from a security researcher whose company continuously scans public code repositories."<br />
<a href="https://www.cisa.gov/news-events/news/lessons-cisas-cyber-incident" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/news/lessons-cisas-cyber-incident</a><br />
<a href="https://www.infosecurity-magazine.com/news/cisa-incident-response-exposed-aws/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/cisa-incident-response-exposed-aws/</a></li>
<li><strong>When Cyberattacks Turn Physical: Threats Of Violence In Digital Extortion</strong><br />
"Cyberattacks have always had real‑world consequences. A ransomware incident can halt production, delay patient care or shut down public services. But until recently, most attacks relied strictly on digital leverage: encrypt data, threaten to leak it and demand payment. Threat intelligence and industry reporting now point to a clear shift toward hybrid attacks that combine cyber intrusion, psychological pressure and real-world intimidation. In practical terms, attackers are no longer satisfied with controlling systems. They are increasingly trying to control outcomes and influence decisions and behavior by introducing fear that extends beyond the network."<br />
<a href="https://blog.barracuda.com/2026/07/09/cyberattacks-physical-threats-ransomware-trend" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.barracuda.com/2026/07/09/cyberattacks-physical-threats-ransomware-trend</a></li>
<li><strong>Ransomware Never Stopped: Over 9,000 Confirmed Attacks Since 2018</strong><br />
"Ransomnews has independently confirmed 9,291 ransomware attacks worldwide between January 2018 and July 2026, tracking incidents only when verified through victim disclosures, regulatory filings, official statements, or credible press reporting. Leak-site listings alone don’t qualify, operators inflate, duplicate, and occasionally fabricate claims. The result is a dataset that’s smaller than what most ransomware statistics cite, and more defensible. “Confirmed ransomware attacks have run at roughly 1,400 to 1,550 per year since 2023, after a visible dip in 2022. The 2020 to 2021 surge, the 2022 trough (which coincided with the Conti shutdown and the Russia-Ukraine war reshuffling the ecosystem), and the post-2023 plateau are all visible in the yearly series. The current year always shows a partial count.” reads the Ransomnews ‘s report."<br />
<a href="https://securityaffairs.com/195117/cyber-crime/ransomware-never-stopped-over-9000-confirmed-attacks-since-2018.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/195117/cyber-crime/ransomware-never-stopped-over-9000-confirmed-attacks-since-2018.html</a></li>
</ul>
<p dir="auto"><strong>อ้างอิง</strong></p>
<p dir="auto">Electronic Transactions Development Agency (ETDA) <img src="/assets/uploads/files/1783936997999-19eb53a0-3599-46c5-a7a9-0537ec9ea7f8-image.png" alt="19eb53a0-3599-46c5-a7a9-0537ec9ea7f8-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3086/etda-cyber-threat-intelligence-13-july-2026</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3086/etda-cyber-threat-intelligence-13-july-2026</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Mon, 13 Jul 2026 10:03:21 GMT</pubDate></item><item><title><![CDATA[ETDA Cyber Threat Intelligence 10 July 2026]]></title><description><![CDATA[<p dir="auto"><strong>Vulnerabilities</strong></p>
<ul>
<li><strong>Chrome 150 Update Patches 27 Vulnerabilities</strong><br />
"Google on Wednesday announced a Chrome 150 security update that resolves 27 vulnerabilities, including two critical-severity flaws. The two critical bugs are use-after-free issues in Chrome’s Ozone and Views components. Both were found by Google last month. The Chrome refresh resolves a total of 13 use-after-free defects, including 10 high-severity and one medium-severity weakness."<br />
<a href="https://www.securityweek.com/chrome-150-update-patches-27-vulnerabilities/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/chrome-150-update-patches-27-vulnerabilities/</a></li>
<li><strong>Microsoft Patches RoguePlanet Defender Zero-Day Vulnerability</strong><br />
"Microsoft has released a security patch to address a Defender zero-day vulnerability known as "RoguePlanet," disclosed after the June 2026 Patch Tuesday. The flaw (tracked as CVE-2026-50656) was disclosed by a security researcher using the "Nightmare Eclipse" handle as part of an ongoing dispute with Microsoft over the company's bug bounty and vulnerability disclosure practices. They also shared a proof-of-concept exploit in a self-hosted Git repository, claiming that Microsoft had previously removed their repos hosting exploits on GitHub and GitLab."<br />
<a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-rogueplanet-defender-zero-day-vulnerability/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-rogueplanet-defender-zero-day-vulnerability/</a><br />
<a href="https://thehackernews.com/2026/07/microsoft-patches-rogueplanet-defender.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/microsoft-patches-rogueplanet-defender.html</a><br />
<a href="https://www.darkreading.com/vulnerabilities-threats/microsoft-rogueplanet-zero-day-threat" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/vulnerabilities-threats/microsoft-rogueplanet-zero-day-threat</a><br />
<a href="https://www.malwarebytes.com/blog/news/2026/07/microsoft-fixes-rogueplanet-zero-day-in-defender" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/news/2026/07/microsoft-fixes-rogueplanet-zero-day-in-defender</a><br />
<a href="https://www.securityweek.com/microsoft-patches-defender-rogueplanet-vulnerability/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/microsoft-patches-defender-rogueplanet-vulnerability/</a><br />
<a href="https://securityaffairs.com/195016/security/microsoft-fixed-defender-flaw-rogueplanet-cve-2026-50656.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/195016/security/microsoft-fixed-defender-flaw-rogueplanet-cve-2026-50656.html</a><br />
<a href="https://www.theregister.com/security/2026/07/09/microsoft-closes-book-on-nightmare-eclipses-rogueplanet-zero-day/5269280" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/07/09/microsoft-closes-book-on-nightmare-eclipses-rogueplanet-zero-day/5269280</a><br />
<a href="https://www.helpnetsecurity.com/2026/07/09/microsoft-releases-fix-for-rogueplanet-defender-flaw-cve-2026-50656/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/09/microsoft-releases-fix-for-rogueplanet-defender-flaw-cve-2026-50656/</a></li>
<li><strong>WolfSSL, GeoVision, VTK Vulnerabilities</strong><br />
"Cisco Talos’ Vulnerability Discovery &amp; Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy."<br />
<a href="https://blog.talosintelligence.com/wolfssl-vulnerabilities/" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.talosintelligence.com/wolfssl-vulnerabilities/</a></li>
<li><strong>Palo Alto Networks Patches 13 Vulnerabilities</strong><br />
"Palo Alto Networks on Wednesday published advisories describing more than a dozen vulnerabilities affecting its products. The new advisories cover 13 vulnerabilities specific to Palo Alto Networks products, as well as more than 500 flaws patched recently by Google in Chromium, which the cybersecurity giant uses for its Prisma browser. The most severe of the newly patched vulnerabilities is CVE-2026-0288. Assigned high severity and highest urgency ratings, the CVE covers multiple buffer overflows in the PAN-OS software, which powers Palo Alto’s firewalls."<br />
<a href="https://www.securityweek.com/palo-alto-networks-patches-13-vulnerabilities/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/palo-alto-networks-patches-13-vulnerabilities/</a></li>
</ul>
<p dir="auto"><strong>Malware</strong></p>
<ul>
<li><strong>RedHook Returns With a Dangerous Upgrade</strong><br />
"RedHook is an Android Remote Access Trojan (RAT) that has re-emerged with significant improvements. While retaining core RAT functionalities, such as screen streaming and keylogging, the latest iterations demonstrate a sophisticated shift toward privilege abuse. This analysis details how RedHook abuses Android’s ADB Wireless Debugging features to autonomously obtain shell-level access (uid 2000). Also, by examining the malware’s persistence stack and its expanded command-and-control capabilities, this report provides technical insights into this evolving mobile threat. RedHook was first documented by Cyble researchers in July 2025."<br />
<a href="https://www.group-ib.com/blog/redhook-android-rat-upgraded/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.group-ib.com/blog/redhook-android-rat-upgraded/</a></li>
<li><strong>How The Reddit And Discord False Report Scam Steals Accounts</strong><br />
"A stranger messages you on Reddit. They say someone reported them, and the reporting account looks a lot like yours. Was it you? It wasn’t. That’s not really the point of the message. This version relies entirely on social engineering. There is no malware and no malicious links. It starts with a conversation, but the goal is to trick you into handing over a login or verification code so the scammer can access your Reddit account."<br />
<a href="https://www.malwarebytes.com/blog/threat-intel/2026/07/how-the-reddit-and-discord-false-report-scam-steals-accounts" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/threat-intel/2026/07/how-the-reddit-and-discord-false-report-scam-steals-accounts</a><br />
<a href="https://www.helpnetsecurity.com/2026/07/09/reddit-false-report-scam-direct-message/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/09/reddit-false-report-scam-direct-message/</a></li>
<li><strong>Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real Victims</strong><br />
"Residential proxies are one of the hottest topics in cybersecurity today. Turns out, they are often not in residences, and they facilitate a wide range of criminal activity. In the simplest terms, a little piece of software in a TV, digital picture frame, or your phone might enable a company to sell access to your device’s bandwidth to their own customers. Those companies—proxy providers—often have affiliate programs where they pay for installation of the software. Sound familiar? It’s the same model as the advertising networks we often write about. Residential proxies are yet another tangled ecosystem full of buyers and sellers, with players in every shade of grey. This blog tells the story of a bad actor who operates an end-to-end malicious proxy business grounded in a collection of clever lookalike domains."<br />
<a href="https://www.infoblox.com/blog/threat-intelligence/fake-installers-fake-reviews-fake-services-real-proxies-real-victims/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infoblox.com/blog/threat-intelligence/fake-installers-fake-reviews-fake-services-real-proxies-real-victims/</a><br />
<a href="https://thehackernews.com/2026/07/fake-7-zip-installers-turn-devices-into.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/fake-7-zip-installers-turn-devices-into.html</a><br />
<a href="https://securityaffairs.com/194990/malware/fake-vpn-and-7-zip-apps-turn-victims-into-residential-proxy-nodes.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/194990/malware/fake-vpn-and-7-zip-apps-turn-victims-into-residential-proxy-nodes.html</a></li>
<li><strong>Compromised Injective SDK Npm Package Exfiltrates Wallet Keys And Mnemonics</strong><br />
"Socket detected a malicious @injectivelabs/sdk-ts@1.20.21 release published to npm with fake telemetry functionality that exfiltrates wallet private keys and mnemonic phrases. The affected package is part of the Injective Labs TypeScript SDK and receives roughly 50,000 weekly downloads, making the incident significant for developers and applications that handle Injective wallet workflows."<br />
<a href="https://socket.dev/blog/compromised-injective-sdk-npm-package" target="_blank" rel="noopener noreferrer nofollow ugc">https://socket.dev/blog/compromised-injective-sdk-npm-package</a><br />
<a href="https://www.ox.security/blog/injectivelabs-npm-package-hijacked-impacting-87-dependent-packages/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.ox.security/blog/injectivelabs-npm-package-hijacked-impacting-87-dependent-packages/</a><br />
<a href="http://www.stepsecurity.io/blog/injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-keys" target="_blank" rel="noopener noreferrer nofollow ugc">http://www.stepsecurity.io/blog/injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-keys</a><br />
<a href="https://www.bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer/</a></li>
<li><strong>Helix, a New Name In The Data Extortion Ecosystem?</strong><br />
"ReliaQuest has identified a data extortion group operating under the name "Helix." However, the playbook it runs and the identity gaps it exploits extend well beyond the group itself. Helix uses vishing to initiate contact—we've even seen the group spoof a target's direct manager by name on caller ID. Device code phishing then sidesteps Conditional Access policies, and automated tools enumerate and mass-download SharePoint libraries before bulk exfiltration triggers an alert. ReliaQuest has confirmed shared infrastructure across attacks on multiple targets, including a phishing domain with target-specific subdomains, suggesting a widespread campaign."<br />
<a href="https://reliaquest.com/blog/threat-spotlight-helix-new-name-in-data-extortion-ecosystem" target="_blank" rel="noopener noreferrer nofollow ugc">https://reliaquest.com/blog/threat-spotlight-helix-new-name-in-data-extortion-ecosystem</a><br />
<a href="https://www.bleepingcomputer.com/news/security/new-helix-vishing-group-emerges-in-sharepoint-data-theft-attacks/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/new-helix-vishing-group-emerges-in-sharepoint-data-theft-attacks/</a></li>
<li><strong>Inside Forg365: A Telegram-Distributed Sneaky 2FA-Style PhaaS Targeting Microsoft 365</strong><br />
"Forg365 is a mature Microsoft 365-focused phishing-as-a-service platform that combines device-auth phishing, AiTM delivery, AntiBot evasion, campaign delivery, session persistence, AI-assisted lure creation, and post-compromise mailbox operations inside a commercial operator ecosystem."<br />
<a href="https://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas" target="_blank" rel="noopener noreferrer nofollow ugc">https://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas</a><br />
<a href="https://www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/</a></li>
<li><strong>When AI Infrastructure Becomes Part Of The Attack Surface</strong><br />
"Darktrace investigated a compromised AI gateway connected to Amazon Bedrock services that was later observed communicating with cryptomining infrastructure. The incident highlights how AI gateways are becoming part of the enterprise attack surface and demonstrates the importance of behavioral analysis, cloud visibility, and securing AI infrastructure alongside identities and workloads."<br />
<a href="https://www.darktrace.com/blog/when-ai-infrastructure-becomes-part-of-the-attack-surface" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darktrace.com/blog/when-ai-infrastructure-becomes-part-of-the-attack-surface</a><br />
<a href="https://www.darkreading.com/cyber-risk/ai-gateways-keys-kingdom" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cyber-risk/ai-gateways-keys-kingdom</a><br />
<a href="https://hackread.com/ai-gateway-amazon-bedrock-hijacked-cryptomining/" target="_blank" rel="noopener noreferrer nofollow ugc">https://hackread.com/ai-gateway-amazon-bedrock-hijacked-cryptomining/</a></li>
<li><strong>GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver To Disable Defenses</strong><br />
"Analysis of a recent GodDamn ransomware attack indicates that this seemingly new ransomware is in fact the latest rebrand of the Beast ransomware, which in itself was a rebrand of the Monster ransomware, which was first seen in 2022. The Symantec Threat Hunter Team tracks the developer behind these ransomware families as Hyadina."<br />
<a href="https://www.security.com/blog-post/goddamn-ransomware-beast-rebrand" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.security.com/blog-post/goddamn-ransomware-beast-rebrand</a><br />
<a href="https://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.html</a><br />
<a href="https://www.darkreading.com/cyberattacks-data-breaches/goddamn-ransomware-byovd-smite-companies" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cyberattacks-data-breaches/goddamn-ransomware-byovd-smite-companies</a><br />
<a href="https://securityaffairs.com/195042/malware/goddamn-ransomware-uses-poisonx-to-blind-security-software.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/195042/malware/goddamn-ransomware-uses-poisonx-to-blind-security-software.html</a></li>
<li><strong>GigaWiper: Anatomy Of a Destructive Backdoor Assembled From Multiple Malware</strong><br />
"In October 2025, Microsoft Threat Intelligence identified destructive wiping activity and uncovered a sophisticated Go programming language (Golang)-based backdoor we now track as GigaWiper, a versatile implant that combines robust command-and-control (C2) capabilities with multiple destructive payloads, including disk wiping, fake ransomware, and system-level sabotage. GigaWiper is particularly notable for its makeup. It’s not a single, purpose-built tool, but an amalgamation of separate malware families that were folded into GigaWiper as on-demand backdoor commands, giving threat actors the flexibility to choose their mode of destruction:"<br />
<a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/</a><br />
<a href="https://thehackernews.com/2026/07/new-gigawiper-windows-backdoor-bundles.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/new-gigawiper-windows-backdoor-bundles.html</a><br />
<a href="https://hackread.com/microsoft-gigawiper-backdoor-destroy-windows-pcs/" target="_blank" rel="noopener noreferrer nofollow ugc">https://hackread.com/microsoft-gigawiper-backdoor-destroy-windows-pcs/</a></li>
<li><strong>Analyzing AI-Augmented Network Enumeration</strong><br />
"We recently came across an incident in early June where a threat actor used a vibe-coded PowerShell script for Active Directory (AD) enumeration. The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory and exporting out a number of files, and finally creating AD_Report.html to measure the success of the enumeration attempt. AI-assisted tradecraft continues to change the threat landscape. Defenders should focus on the fundamental behaviors of the attack lifecycle, because while AI can change the code syntax, it can't easily change the underlying parts of an attack, like enumeration."<br />
<a href="https://www.huntress.com/blog/ai-coded-malware-vibe-coding-active-directory" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.huntress.com/blog/ai-coded-malware-vibe-coding-active-directory</a><br />
<a href="https://www.infosecurity-magazine.com/news/vibe-coded-malware-ai-powershell/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/vibe-coded-malware-ai-powershell/</a></li>
<li><strong>Coordinated GitHub API Enumeration And Access Token Abuse</strong><br />
"Datadog Security Research is tracking several overlapping campaigns that systematically enumerate corporate GitHub organizations, repositories, and user accounts through the GitHub API. Operators rely on automated scraping tooling with custom or legitimate-sounding user agents, leveraging GitHub "ghost" accounts that are often years old, or compromised OAuth tokens and personal access tokens (PATs) from legitimate users. Most requests target public data, making it look like ordinary API traffic. In some cases, the activity escalated past public information enumeration, appearing to successfully clone private repositories."<br />
<a href="https://securitylabs.datadoghq.com/articles/coordinated-github-api-enumeration/" target="_blank" rel="noopener noreferrer nofollow ugc">https://securitylabs.datadoghq.com/articles/coordinated-github-api-enumeration/</a><br />
<a href="https://thehackernews.com/2026/07/dormant-github-accounts-help-attackers.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/dormant-github-accounts-help-attackers.html</a></li>
<li><strong>From Invoice To AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations</strong><br />
"The Seqrite Threat Research Team identified a targeted spear-phishing campaign disguised as a legitimate business invoice. The phishing email impersonates a legitimate Russian research institute associated with aerospace and aviation systems and is delivered using a spoofed domain designed to mimic the organization. The malicious email contains a password-protected attachment that ultimately deploys additional payloads on the victim’s system. Analysis indicates that the threat actor’s primary objective is to establish persistent remote access by silently configuring AnyDesk for unattended access, exfiltrating AnyDesk configuration data to an attacker-controlled email account and implementing persistence mechanisms to retain long-term control of the compromised host."<br />
<a href="https://www.seqrite.com/blog/from-invoice-to-anydesk-uncovering-a-phishing-campaign-targeting-russian-aerospace-organizations/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.seqrite.com/blog/from-invoice-to-anydesk-uncovering-a-phishing-campaign-targeting-russian-aerospace-organizations/</a></li>
<li><strong>CrowdStrike Uncovers New Prompt Injection Techniques</strong><br />
"Prompt injection is among the defining security challenges of the AI era. As organizations move from chatbots to AI agents, adversaries are finding more ways to manipulate the language, context, and data these systems trust. With the rise of powerful AI agents that can crawl webpages, access file stores, and even write shell commands, indirect prompt injection has emerged as a critical threat vector. Adversaries can hide these attacks in the data consumed by these agents and then hijack their capabilities to cause further damage."<br />
<a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-uncovers-new-prompt-injection-techniques/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.crowdstrike.com/en-us/blog/crowdstrike-uncovers-new-prompt-injection-techniques/</a></li>
<li><strong>Large-Scale Exploitation Campaign Targeting Website Content Management Systems (CMS)</strong><br />
"A large-scale exploitation campaign is targeting various vulnerabilities in content management systems (CMS) globally, including in Australia, with many small to medium sized Australian businesses impacted. As part of this campaign, malicious cyber actors are actively scanning websites for opportunities to deploy webshells, leveraging various vulnerabilities affecting CMS software and plugins. These vulnerabilities primarily allow unauthenticated file upload, remote code execution, server side request forgery or deserialisation."<br />
<a href="https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/large-scale-exploitation-campaign-targeting-website-content-management-systems-cms" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/large-scale-exploitation-campaign-targeting-website-content-management-systems-cms</a></li>
</ul>
<p dir="auto"><strong>Breaches/Hacks/Leaks</strong></p>
<ul>
<li><strong>AssuranceAmerica Data Breach Exposes Records Of 6.9 Million Drivers</strong><br />
"American insurance company AssuranceAmerica has disclosed a data breach impacting nearly 7 million drivers after attackers gained access to its systems earlier this year. AssuranceAmerica operates through a network of over 9,500 independent agents and provides auto, renters, and commercial auto insurance coverage across 14 U.S. states. While the company has yet to publish a press release regarding the incident, it revealed in a filing with Maine's Office of the Attorney General that the data breach has exposed the information of 6,998,886 people."<br />
<a href="https://www.bleepingcomputer.com/news/security/assuranceamerica-data-breach-exposes-records-of-69-million-drivers/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/assuranceamerica-data-breach-exposes-records-of-69-million-drivers/</a><br />
<a href="https://www.malwarebytes.com/blog/data-breaches/2026/07/6-9-million-drivers-license-numbers-stolen-from-assuranceamerica" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/data-breaches/2026/07/6-9-million-drivers-license-numbers-stolen-from-assuranceamerica</a><br />
<a href="https://securityaffairs.com/195027/data-breach/assuranceamerica-breach-exposes-7-million-drivers-licenses-after-employee-account-hack.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/195027/data-breach/assuranceamerica-breach-exposes-7-million-drivers-licenses-after-employee-account-hack.html</a></li>
</ul>
<p dir="auto"><strong>General News</strong></p>
<ul>
<li><strong>Q2 2026 Statistical Report On Malware Targeting Windows Web Servers</strong><br />
"In the second quarter of 2026, the AhnLab SEcurity intelligence Center (ASEC) compiled an analysis of the current attack status for poorly managed Windows web servers and classified the malware used in these attacks. The targets were Internet Information Services (IIS) web servers and Apache Tomcat web servers running in Windows environments."<br />
<a href="https://asec.ahnlab.com/en/94398/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/94398/</a></li>
<li><strong>Statistical Report On Malware Targeting Linux SSH Servers In The Second Quarter Of 2026</strong><br />
"In the second quarter of 2026, the AhnLab SEcurity intelligence Center (ASEC) collected and analyzed attack logs targeting poorly managed Linux SSH servers through honeypots. The scope of the analysis covers attack sources that progressed to executing actual malware installation commands, as well as statistics on the malware used in those attacks."<br />
<a href="https://asec.ahnlab.com/en/94396/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/94396/</a></li>
<li><strong>Statistical Report On Malware Targeting Windows Database Servers In The Second Quarter Of 2026</strong><br />
"The AhnLab SEcurity intelligence Center (ASEC) analyzed attack logs from the second quarter of 2026 targeting MS-SQL server and MySQL server installations on Windows. This report summarizes the damage status, attack status, and the classification of the malware and tools used in the attacks."<br />
<a href="https://asec.ahnlab.com/en/94397/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/94397/</a></li>
<li><strong>Inside The Underground Economy: 5 Dark Web Trends Shaping The 2026 Threat Landscape</strong><br />
"The dark web is no longer just a hidden marketplace for stolen credentials; it has grown far beyond that point and now affects nearly every phase of the cyberattack lifecycle. Markets that once traded only compromised accounts now also sell ransomware services, initial network access, exploit kits, phishing infrastructure, and even AI-powered attack tools. What used to be a place for selling stolen data has become the operational backbone of modern cybercrime."<br />
<a href="https://cyble.com/blog/dark-web-trends-2026-cyber-threat-landscape/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyble.com/blog/dark-web-trends-2026-cyber-threat-landscape/</a></li>
<li><strong>Messaging Fraud Trends Point To Smarter Attacks, Stronger Blocking</strong><br />
"Fraudsters spent 2025 investing in scale. New routes, new tools, and higher message volumes moved through the SMS, voice, and chat channels that businesses rely on to reach customers. Money follows that activity. The Communications Fraud Control Association puts global telecom fraud losses at around 42 billion dollars for the year, several billion higher than its estimate for the prior year. Blocked volumes rose alongside the threat. Infobip, a communications platform that handles billions of interactions each month, reports that blocked messages grew 77% between 2024 and 2025. This means attackers pushed more traffic, and detection systems caught a wider range of it. Some markets also show better outcomes as detection infrastructure matured, a sign that defenses are catching up in places where they had lagged."<br />
<a href="https://www.helpnetsecurity.com/2026/07/09/infobip-messaging-fraud-trends/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/09/infobip-messaging-fraud-trends/</a></li>
<li><strong>A Single Malware File Can Outweigh An Entire AI Dataset</strong><br />
"Antivirus vendors and security startups keep shipping AI features that promise to read malware the way a seasoned analyst would. The results inside security teams tell a quieter story. A new paper argues that static analysis of software, the job of deciding whether a program is malicious by examining its contents on disk, remains one of the hardest places to make generative AI work. The scale of the problem explains much of the difficulty. Standard datasets in other fields look small next to a single security sample. ImageNet, the benchmark that helped launch deep learning in computer vision, fits in about 17 GB once its images are resized down, and it holds more than a million of them. Routine static analysis means processing single files that outweigh entire datasets from other research areas."<br />
<a href="https://www.helpnetsecurity.com/2026/07/09/research-ai-in-cybersecurity/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/09/research-ai-in-cybersecurity/</a><br />
<a href="https://arxiv.org/pdf/2606.28929" target="_blank" rel="noopener noreferrer nofollow ugc">https://arxiv.org/pdf/2606.28929</a></li>
<li><strong>Over 5,800 Arrests, USD 293 Million Intercepted In Global Fraud Bust</strong><br />
"A global anti-fraud operation involving 97 countries and territories has led to the arrest of 5,811 individuals and the interception of USD 293 million in illicit assets. Operation First Light 2026 (15 Jan 2026 – 30 April 2026), coordinated by INTERPOL, focused on combatting social engineering scams and associated money laundering activities. Social engineering is a broad term that refers to techniques that exploit a person’s trust to obtain money or confidential information. This type of fraud can include business email compromise, sextortion, as well as romance, impersonation or investment scams."<br />
<a href="https://www.interpol.int/News-and-Events/News/2026/Over-5-800-arrests-USD-293-million-intercepted-in-global-fraud-bust" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.interpol.int/News-and-Events/News/2026/Over-5-800-arrests-USD-293-million-intercepted-in-global-fraud-bust</a><br />
<a href="https://www.bleepingcomputer.com/news/security/police-arrests-5-800-suspects-in-global-anti-fraud-crackdown/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/police-arrests-5-800-suspects-in-global-anti-fraud-crackdown/</a><br />
<a href="https://cyberscoop.com/interpol-cybercrime-crackdown-operation-first-light/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/interpol-cybercrime-crackdown-operation-first-light/</a><br />
<a href="https://www.infosecurity-magazine.com/news/china-interpol-cybercrime-crackdown/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/china-interpol-cybercrime-crackdown/</a><br />
<a href="https://securityaffairs.com/195056/security/interpol-operation-first-light-nets-5811-arrests-and-seizes-293-million.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/195056/security/interpol-operation-first-light-nets-5811-arrests-and-seizes-293-million.html</a><br />
<a href="https://www.helpnetsecurity.com/2026/07/09/interpol-fraud-bust-social-engineering-scams/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/09/interpol-fraud-bust-social-engineering-scams/</a></li>
<li><strong>Friendly Fire: Hijacking Defensive Cyber AI Agents For Remote Code Execution</strong><br />
"We are revealing a proof-of-concept exploit that enables remote code execution in Anthropic’s Claude Code CLI (with Claude Sonnet 4.6 &amp; 5, Opus 4.8) and OpenAI’s Codex CLI (with GPT-5.5) when employed to defensively assess the security of an open-source or third-party library. Our attack only requires an out-of-the-box configuration of Claude Code in “auto-mode” or Codex in “auto-review” and leverages prompt injections disseminated across a library’s source code that target AI-enabled cyber defense without the need for hooks, skills, plugins, MCP servers, or configuration files as an injection vector. As such, we warn against the recent initiatives that mandate the acceleration of AI-enabled defensive tools without consideration of the substantial and unmitigated risks associated with the deployment of defensive AI, especially in the context of safety-critical infrastructure—where AI is most urgently being considered for deployment."<br />
<a href="https://ainowinstitute.org/publications/friendly-fire-exploit-brief" target="_blank" rel="noopener noreferrer nofollow ugc">https://ainowinstitute.org/publications/friendly-fire-exploit-brief</a><br />
<a href="https://thehackernews.com/2026/07/friendly-fire-ai-agents-built-to-catch.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/friendly-fire-ai-agents-built-to-catch.html</a></li>
<li><strong>A New Ransomware Leader Emerges As June 2026 Attack Volumes Climb Worldwide</strong><br />
"June reversed the brief calm of May. Organizations faced an average of 2,270 weekly cyber attacks, a 10% rise from the previous month and a 17% increase compared with June last year. What makes this month notable is not just the size of the jump but its reach. Rather than one region or sector absorbing the bulk of the growth, the increase showed up almost everywhere at once, suggesting attackers spread their effort wider rather than concentrating it."<br />
<a href="https://blog.checkpoint.com/research/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.checkpoint.com/research/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/</a></li>
<li><strong>AI Agents Are a New Kind Of Identity &amp; Most Organizations Aren't Ready</strong><br />
"I recently read an opinion piece on TechTarget by Todd Thiemann, a principal analyst at Omdia, on identity security for AI agents. It is one of the clearest things I have read on this topic, but it also made me think about something that I want to dig into further because it's the most important factor in enterprise security right now, and it's not getting the attention it deserves: the development environment. Thiemann makes a point that I have been making for a while now, and it's worth repeating loudly: AI agents are not just another type of non-human identity. They are fundamentally different. If you're still treating them like a service account or an API token, you are already behind."<br />
<a href="https://www.darkreading.com/identity-access-management-security/ai-agents-new-kind-identity-most-organizations-not-ready" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/identity-access-management-security/ai-agents-new-kind-identity-most-organizations-not-ready</a></li>
<li><strong>Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure</strong><br />
"For many CISOs, the headlines detailing Iranian-linked strikes on water utilities and power grids trigger a dangerous sense of immunity: "I'm not a utility; I'm not a target." There is a comforting, yet flawed, assumption that these operations are merely geopolitical theater confined to the high-stakes arena of critical infrastructure. But in the modern threat landscape, obscurity is not a defense, and "non-critical" status is not a shield. If your organization has a digital heartbeat and an Internet-facing vulnerability, you're already at risk from multiple potential threats, whether you realize it or not."<br />
<a href="https://www.darkreading.com/cyber-risk/iran-cyber-crosshairs-beyond-critical-infrastructure" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cyber-risk/iran-cyber-crosshairs-beyond-critical-infrastructure</a></li>
<li><strong>As Global Conflicts Go Digital, Businesses Need Wartime Gameplans</strong><br />
"Intellect Services could hardly be less interesting. A midsized, family-owned business in Ukraine that sold tax software. Its owners really can't be faulted for not anticipating that they might one day be a huge pawn in a regional cyberwar. To Russian foreign military intelligence, Intellect Services was totally interesting. The company's platform, M.E.Doc, was ubiquitous across Ukrainian businesses. Compromising M.E.Doc they could, in effect, impact most of the country's economy. And like other midsize businesses, the company wasn't likely to have any kind of exceptional cybersecurity defenses getting in Russia's way."<br />
<a href="https://www.darkreading.com/cybersecurity-operations/businesses-wartime-cybersecurity-gameplans" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cybersecurity-operations/businesses-wartime-cybersecurity-gameplans</a></li>
<li><strong>78% Of CISOs Say C-Level Do Not Fully Understand Employee-Driven Cyber Risk</strong><br />
"More than three quarters of CISOs across Europe say C-level senior decision-makers do not fully understand the cyber risk posed by employees, according to new research, at a time when AI is making human-targeted attacks more sophisticated, scalable, convincing and increasingly frequent. The survey of 200 CISOs across the UK, France, Germany and Sweden, carried out by MetaCompliance, the human cyber risk management company, reveals a growing disconnect between the risks organisations face at the human layer and the level of senior understanding, alignment and support needed to manage them effectively."<br />
<a href="https://www.metacompliance.com/company-news/78-of-cisos-say-c-level-do-not-fully-understand-employee-driven-cyber-risk" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.metacompliance.com/company-news/78-of-cisos-say-c-level-do-not-fully-understand-employee-driven-cyber-risk</a><br />
<a href="https://www.infosecurity-magazine.com/news/cisos-fear-execs-dont-understand/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/cisos-fear-execs-dont-understand/</a></li>
<li><strong>ENISA’s View On Cybersecurity In The Frontier AI Era</strong><br />
"This publication provides national competent authorities in Member States and EU policymakers, defenders, and service providers with an initial set of recommendations to support them in their respective roles towards developing the necessary operational capabilities to face machine-speed threats. The recommendations are not an all-inclusive checklist. ENISA aims to further refine and expand these recommendations in close cooperation with Member States and EUIBAs and will align these to upcoming European Commission Action Plan."<br />
<a href="https://www.enisa.europa.eu/publications/enisas-view-on-cybersecurity-in-the-frontier-ai-era" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.enisa.europa.eu/publications/enisas-view-on-cybersecurity-in-the-frontier-ai-era</a><br />
<a href="https://www.enisa.europa.eu/sites/default/files/2026-07/ENISA%20view%20on%20cybersecurity%20in%20the%20frontier%20AI%20era_en_0.pdf" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.enisa.europa.eu/sites/default/files/2026-07/ENISA view on cybersecurity in the frontier AI era_en_0.pdf</a></li>
<li><strong>Florida Ransomware Negotiator Who Extorted And Attacked Multiple U.S. Victims Sentenced To Prison</strong><br />
"Angelo Martino, 41, of Land O’Lakes, Florida, formerly employed as a ransomware negotiator, was sentenced today to 70 months for his role in conspiring with Blackcat/ALPHV (BlackCat) actors to extort multiple victims, as well as conspiring with other former cybersecurity professionals to attack additional victims in 2023. “Angelo Martino’s victims shared heartbreaking accounts of how their businesses were nearly destroyed, while the people they hired to help them instead betrayed them to ransomware gangs,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division."<br />
<a href="https://www.justice.gov/opa/pr/florida-ransomware-negotiator-who-extorted-and-attacked-multiple-us-victims-sentenced-prison" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.justice.gov/opa/pr/florida-ransomware-negotiator-who-extorted-and-attacked-multiple-us-victims-sentenced-prison</a><br />
<a href="https://cyberscoop.com/digitalmint-ransomware-negotiator-angelo-martino-sentenced/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/digitalmint-ransomware-negotiator-angelo-martino-sentenced/</a></li>
<li><strong>June 2026 Dark Web Breach Incident Trend Report</strong><br />
"The June 2026 Dark Web Breach Incident Trend Report is based on major data breach cases posted on the deep web and dark web forums. Due to the nature of some sources, it was difficult to fully verify the accuracy of certain information, so the report includes content that requires further verification."<br />
<a href="https://asec.ahnlab.com/en/94411/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/94411/</a></li>
<li><strong>June 2026 Dark Web Issue Trend Report</strong><br />
"The June 2026 Dark Web Issue Trend Report summarizes major issues that occurred on the deep web and dark web. Due to the nature of the sources, it is sometimes difficult to fully verify the accuracy of certain information, and this is noted accordingly."<br />
<a href="https://asec.ahnlab.com/en/94416/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/94416/</a></li>
<li><strong>June 2026 Dark Web Threat Actor Trend Report</strong><br />
"The June 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—operating on the deep web and dark web. It is noted that the accuracy of some information could not be verified."<br />
<a href="https://asec.ahnlab.com/en/94417/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/94417/</a></li>
</ul>
<p dir="auto"><strong>อ้างอิง</strong></p>
<p dir="auto">Electronic Transactions Development Agency (ETDA) <img src="/assets/uploads/files/1783936655249-6b3b3c38-8813-4563-9263-cb10c24b1944-image.png" alt="6b3b3c38-8813-4563-9263-cb10c24b1944-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3085/etda-cyber-threat-intelligence-10-july-2026</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3085/etda-cyber-threat-intelligence-10-july-2026</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Mon, 13 Jul 2026 09:57:39 GMT</pubDate></item><item><title><![CDATA[CISA เพิ่มช่องโหว่ iCagenda และ Balbooa Forms ที่ถูกใช้โจมตีจริงเข้า KEV]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1783936247529-cisa-%E0%B9%80%E0%B8%9E-%E0%B8%A1%E0%B8%8A-%E0%B8%AD%E0%B8%87%E0%B9%82%E0%B8%AB%E0%B8%A7-icagenda-%E0%B9%81%E0%B8%A5%E0%B8%B0-balbooa-forms-%E0%B8%97-%E0%B8%96-%E0%B8%81%E0%B9%83%E0%B8%8A-%E0%B9%82%E0%B8%88%E0%B8%A1%E0%B8%95.png" alt="CISA เพิ่มช่องโหว่ iCagenda และ Balbooa Forms ที่ถูกใช้โจมต.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783936255974-0394270a-b472-49ea-ab9e-ea4ddee1645a-image.png" alt="0394270a-b472-49ea-ab9e-ea4ddee1645a-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3084/cisa-เพ-มช-องโหว-icagenda-และ-balbooa-forms-ท-ถ-กใช-โจมต-จร-งเข-า-kev</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3084/cisa-เพ-มช-องโหว-icagenda-และ-balbooa-forms-ท-ถ-กใช-โจมต-จร-งเข-า-kev</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Mon, 13 Jul 2026 09:51:06 GMT</pubDate></item><item><title><![CDATA[Zimbra เตือนช่องโหว่ XSS ใน Classic Web Client เสี่ยงรันโค้ดอันตรายผ่าน Email]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1783936213004-zimbra-%E0%B9%80%E0%B8%95-%E0%B8%AD%E0%B8%99%E0%B8%8A-%E0%B8%AD%E0%B8%87%E0%B9%82%E0%B8%AB%E0%B8%A7-xss-%E0%B9%83%E0%B8%99-classic-web-client-%E0%B9%80%E0%B8%AA-%E0%B8%A2%E0%B8%87%E0%B8%A3-%E0%B8%99%E0%B9%82%E0%B8%84-%E0%B8%94%E0%B8%AD.png" alt="Zimbra เตือนช่องโหว่ XSS ใน Classic Web Client เสี่ยงรันโค้ดอ.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783936221852-15893241-5ec4-4f3a-ae67-cc0638f00ac1-image.png" alt="15893241-5ec4-4f3a-ae67-cc0638f00ac1-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3083/zimbra-เต-อนช-องโหว-xss-ใน-classic-web-client-เส-ยงร-นโค-ดอ-นตรายผ-าน-email</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3083/zimbra-เต-อนช-องโหว-xss-ใน-classic-web-client-เส-ยงร-นโค-ดอ-นตรายผ-าน-email</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Mon, 13 Jul 2026 09:50:32 GMT</pubDate></item><item><title><![CDATA[ตรวจพบ GigaWiper แบ็กดอร์สายพันธุ์ใหม่บน Windows ผสานความสามารถโจมตีลบข้อมูลและเรียกค่าไถ่]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1783936143254-%E0%B8%95%E0%B8%A3%E0%B8%A7%E0%B8%88%E0%B8%9E%E0%B8%9A-gigawiper-%E0%B9%81%E0%B8%9A-%E0%B8%81%E0%B8%94%E0%B8%AD%E0%B8%A3-%E0%B8%AA%E0%B8%B2%E0%B8%A2%E0%B8%9E-%E0%B8%99%E0%B8%98-%E0%B9%83%E0%B8%AB%E0%B8%A1-%E0%B8%9A%E0%B8%99-windows-%E0%B8%9C%E0%B8%AA%E0%B8%B2%E0%B8%99.png" alt="ตรวจพบ GigaWiper แบ็กดอร์สายพันธุ์ใหม่บน Windows ผสาน.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783936153198-2fe6aa38-09dd-4cf0-bdc6-282f0b654e3e-image.png" alt="2fe6aa38-09dd-4cf0-bdc6-282f0b654e3e-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3082/ตรวจพบ-gigawiper-แบ-กดอร-สายพ-นธ-ใหม-บน-windows-ผสานความสามารถโจมต-ลบข-อม-ลและเร-ยกค-าไถ</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3082/ตรวจพบ-gigawiper-แบ-กดอร-สายพ-นธ-ใหม-บน-windows-ผสานความสามารถโจมต-ลบข-อม-ลและเร-ยกค-าไถ</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Mon, 13 Jul 2026 09:49:55 GMT</pubDate></item><item><title><![CDATA[Google ออกอัปเดต Chrome 150 แก้ช่องโหว่ 27 รายการ รวมถึงช่องโหว่ระดับ Critical]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1783679262905-google-%E0%B8%AD%E0%B8%AD%E0%B8%81%E0%B8%AD-%E0%B8%9B%E0%B9%80%E0%B8%94%E0%B8%95-chrome-150-%E0%B9%81%E0%B8%81-%E0%B8%8A-%E0%B8%AD%E0%B8%87%E0%B9%82%E0%B8%AB%E0%B8%A7-27-%E0%B8%A3%E0%B8%B2%E0%B8%A2%E0%B8%81%E0%B8%B2%E0%B8%A3-%E0%B8%A3%E0%B8%A7%E0%B8%A1%E0%B8%96.png" alt="Google ออกอัปเดต Chrome 150 แก้ช่องโหว่ 27 รายการ รวมถึ.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783679270833-f2b7cbdc-a71f-4e2c-8ceb-89e1b849203c-image.png" alt="f2b7cbdc-a71f-4e2c-8ceb-89e1b849203c-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3081/google-ออกอ-ปเดต-chrome-150-แก-ช-องโหว-27-รายการ-รวมถ-งช-องโหว-ระด-บ-critical</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3081/google-ออกอ-ปเดต-chrome-150-แก-ช-องโหว-27-รายการ-รวมถ-งช-องโหว-ระด-บ-critical</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Fri, 10 Jul 2026 10:27:55 GMT</pubDate></item><item><title><![CDATA[Mount Royal University ยืนยันเหตุข้อมูลรั่วไหล หลังแฮกเกอร์อ้างโจมตีและเรียกค่าไถ่]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1783679235666-mount-royal-university-%E0%B8%A2-%E0%B8%99%E0%B8%A2-%E0%B8%99%E0%B9%80%E0%B8%AB%E0%B8%95-%E0%B8%82-%E0%B8%AD%E0%B8%A1-%E0%B8%A5%E0%B8%A3-%E0%B8%A7%E0%B9%84%E0%B8%AB%E0%B8%A5-%E0%B8%AB%E0%B8%A5-%E0%B8%87%E0%B9%81%E0%B8%AE%E0%B8%81%E0%B9%80.png" alt="Mount Royal University ยืนยันเหตุข้อมูลรั่วไหล หลังแฮกเ.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783679242473-897726ea-ecee-4c3c-a814-7a9b2ecdb19a-image.png" alt="897726ea-ecee-4c3c-a814-7a9b2ecdb19a-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3080/mount-royal-university-ย-นย-นเหต-ข-อม-ลร-วไหล-หล-งแฮกเกอร-อ-างโจมต-และเร-ยกค-าไถ</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3080/mount-royal-university-ย-นย-นเหต-ข-อม-ลร-วไหล-หล-งแฮกเกอร-อ-างโจมต-และเร-ยกค-าไถ</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Fri, 10 Jul 2026 10:27:26 GMT</pubDate></item><item><title><![CDATA[แฮกเกอร์เพียงตัวคนเดียว สามารถใช้ AI เจาะระบบคลาวด์ AWS สำเร็จได้ภายใน 72 ชั่วโมง]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1783679196536-%E0%B9%81%E0%B8%AE%E0%B8%81%E0%B9%80%E0%B8%81%E0%B8%AD%E0%B8%A3-%E0%B9%80%E0%B8%9E-%E0%B8%A2%E0%B8%87%E0%B8%95-%E0%B8%A7%E0%B8%84%E0%B8%99%E0%B9%80%E0%B8%94-%E0%B8%A2%E0%B8%A7-%E0%B8%AA%E0%B8%B2%E0%B8%A1%E0%B8%B2%E0%B8%A3%E0%B8%96%E0%B9%83%E0%B8%8A-ai-%E0%B9%80%E0%B8%88%E0%B8%B2%E0%B8%B0%E0%B8%A3%E0%B8%B0.png" alt="แฮกเกอร์เพียงตัวคนเดียว สามารถใช้ AI เจาะระ.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783679208628-2cb3968b-ceec-4a54-84e1-f3b8c01ca5cf-image.png" alt="2cb3968b-ceec-4a54-84e1-f3b8c01ca5cf-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3079/แฮกเกอร-เพ-ยงต-วคนเด-ยว-สามารถใช-ai-เจาะระบบคลาวด-aws-สำเร-จได-ภายใน-72-ช-วโมง</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3079/แฮกเกอร-เพ-ยงต-วคนเด-ยว-สามารถใช-ai-เจาะระบบคลาวด-aws-สำเร-จได-ภายใน-72-ช-วโมง</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Fri, 10 Jul 2026 10:27:00 GMT</pubDate></item><item><title><![CDATA[CISA เพิ่ม 4 ช่องโหว่ที่ถูกใช้โจมตีจริงใน Adobe ColdFusion, Joomla และ Langflow เข้า KEV]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1783588532781-cisa-%E0%B9%80%E0%B8%9E-%E0%B8%A1-4-%E0%B8%8A-%E0%B8%AD%E0%B8%87%E0%B9%82%E0%B8%AB%E0%B8%A7-%E0%B8%97-%E0%B8%96-%E0%B8%81%E0%B9%83%E0%B8%8A-%E0%B9%82%E0%B8%88%E0%B8%A1%E0%B8%95-%E0%B8%88%E0%B8%A3-%E0%B8%87%E0%B9%83%E0%B8%99-adobe-coldf.png" alt="CISA เพิ่ม 4 ช่องโหว่ที่ถูกใช้โจมตีจริงใน Adobe ColdF.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783588543806-4a343551-82a6-4e37-adc1-5c89cd43d9c5-image.png" alt="4a343551-82a6-4e37-adc1-5c89cd43d9c5-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3078/cisa-เพ-ม-4-ช-องโหว-ท-ถ-กใช-โจมต-จร-งใน-adobe-coldfusion-joomla-และ-langflow-เข-า-kev</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3078/cisa-เพ-ม-4-ช-องโหว-ท-ถ-กใช-โจมต-จร-งใน-adobe-coldfusion-joomla-และ-langflow-เข-า-kev</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Thu, 09 Jul 2026 09:15:56 GMT</pubDate></item><item><title><![CDATA[KDDI เผยเหตุข้อมูลรั่วไหล กระทบประชาชนกว่า 12 ล้านราย หลังแพลตฟอร์มอีเมลของ ISP ถูกโจมตี]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1783588502217-kddi-%E0%B9%80%E0%B8%9C%E0%B8%A2%E0%B9%80%E0%B8%AB%E0%B8%95-%E0%B8%82-%E0%B8%AD%E0%B8%A1-%E0%B8%A5%E0%B8%A3-%E0%B8%A7%E0%B9%84%E0%B8%AB%E0%B8%A5-%E0%B8%81%E0%B8%A3%E0%B8%B0%E0%B8%97%E0%B8%9A%E0%B8%9B%E0%B8%A3%E0%B8%B0%E0%B8%8A%E0%B8%B2%E0%B8%8A%E0%B8%99%E0%B8%81%E0%B8%A7-%E0%B8%B2-12.png" alt="KDDI เผยเหตุข้อมูลรั่วไหล กระทบประชาชนกว่า 12 .png" class=" img-fluid img-markdown" /></p>
<p dir="auto">สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783588510503-a4713865-2f2c-43e6-a792-919852612002-image.png" alt="a4713865-2f2c-43e6-a792-919852612002-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3077/kddi-เผยเหต-ข-อม-ลร-วไหล-กระทบประชาชนกว-า-12-ล-านราย-หล-งแพลตฟอร-มอ-เมลของ-isp-ถ-กโจมต</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3077/kddi-เผยเหต-ข-อม-ลร-วไหล-กระทบประชาชนกว-า-12-ล-านราย-หล-งแพลตฟอร-มอ-เมลของ-isp-ถ-กโจมต</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Thu, 09 Jul 2026 09:15:17 GMT</pubDate></item><item><title><![CDATA[เตือนภัยกลุ่มแฮกเกอร์ UAT-7810 ใช้ยมัลแวร์ LONGLEASH พุ่งเป้าโจมตีเราเตอร์เพื่อสร้างเครือข่ายพรางตัว]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1783588467513-%E0%B9%80%E0%B8%95-%E0%B8%AD%E0%B8%99%E0%B8%A0-%E0%B8%A2%E0%B8%81%E0%B8%A5-%E0%B8%A1%E0%B9%81%E0%B8%AE%E0%B8%81%E0%B9%80%E0%B8%81%E0%B8%AD%E0%B8%A3-uat-7810-%E0%B9%83%E0%B8%8A-%E0%B8%A2%E0%B8%A1-%E0%B8%A5%E0%B9%81%E0%B8%A7%E0%B8%A3-longleash.png" alt="เตือนภัยกลุ่มแฮกเกอร์ UAT-7810 ใช้ยมัลแวร์ LONGLEASH .png" class=" img-fluid img-markdown" /></p>
<p dir="auto">สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783588473785-02052452-58fc-47b1-abaf-f7731bb5acb1-image.png" alt="02052452-58fc-47b1-abaf-f7731bb5acb1-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3076/เต-อนภ-ยกล-มแฮกเกอร-uat-7810-ใช-ยม-ลแวร-longleash-พ-งเป-าโจมต-เราเตอร-เพ-อสร-างเคร-อข-ายพรางต-ว</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3076/เต-อนภ-ยกล-มแฮกเกอร-uat-7810-ใช-ยม-ลแวร-longleash-พ-งเป-าโจมต-เราเตอร-เพ-อสร-างเคร-อข-ายพรางต-ว</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Thu, 09 Jul 2026 09:14:47 GMT</pubDate></item><item><title><![CDATA[Cyber Threat Intelligence 09 July 2026]]></title><description><![CDATA[<p dir="auto"><strong>Vulnerabilities</strong></p>
<ul>
<li><strong>Foxit PDF Reader Flaws Enable Arbitrary Code Execution</strong><br />
"Foxit shipped Foxit PDF Reader 2026.1.2 and PDF Editor 2026.1.2 for Windows. The release fixes 28 security flaws. Twenty of them can lead to arbitrary code execution when someone opens a crafted PDF. So far, no vendor or researcher has confirmed active exploitation or a public proof-of-concept."<br />
<a href="https://securityonline.info/foxit-pdf-reader-code-execution/" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityonline.info/foxit-pdf-reader-code-execution/</a></li>
<li><strong>IonStack Part II: GhostLock, a Stack-UAF That Has Existed In ALL Linux Distributions For 15 Years</strong><br />
"GhostLock (CVE-2026-43499) is a Linux kernel vulnerability found by VEGA that exists in every major distribution since 2011. Triggering the bug does not require any special kernel config or privilege. By turning it into a 97% stable privilege escalation and container escape, Google has rewarded us $92,337 in kernelCTF. This writeup covers the technical details of the exploit."<br />
<a href="https://nebusec.ai/research/ionstack-part-2/" target="_blank" rel="noopener noreferrer nofollow ugc">https://nebusec.ai/research/ionstack-part-2/</a><br />
<a href="https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html</a></li>
<li><strong>GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures</strong><br />
"New research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps "Verified." Everything a reviewer would check matches. The commit's hash does not. That matters because so many systems treat a verified commit hash as a permanent, unique name for its contents."<br />
<a href="https://thehackernews.com/2026/07/github-verified-commits-can-be.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/github-verified-commits-can-be.html</a><br />
<a href="https://arxiv.org/abs/2607.02820" target="_blank" rel="noopener noreferrer nofollow ugc">https://arxiv.org/abs/2607.02820</a></li>
</ul>
<p dir="auto"><strong>Malware</strong></p>
<ul>
<li><strong>CAI Cloud Worm Gives Competitors' Malware The Boot, Then Steals Secrets And Mines For Coin</strong><br />
"There's no honor among thieves as a new worm steals from other infectious software. It pilfers “multiple” victims’ credentials and mines for cryptocurrency while killing competitors’ processes, including similar secret-harvesting malware. It’s called Cloud AI Infrastructure Attack Framework (CAI), and it’s a centralized botnet that targets cloud-native developer tools like Docker, Kubernetes, Redis, etcd, Kubelet, and Ray for credential theft and cryptomining. The scripts “are heavily inspired” by the likes of other similar credential-stealing worms that have wreaked havoc across cloud environments and supply chains this year, “using code comments like ‘PCPJack-aligned,’” according to security researcher Michael R."<br />
<a href="https://www.theregister.com/cyber-crime/2026/07/07/cai-cloud-worm-gives-competitors-malware-the-boot-then-steals-secrets-and-mines-for-coin/5267856" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/cyber-crime/2026/07/07/cai-cloud-worm-gives-competitors-malware-the-boot-then-steals-secrets-and-mines-for-coin/5267856</a></li>
<li><strong>What If You Received An Email About Transferring Your Kakao Account? Check This First.</strong><br />
"Recently, a phishing email disguised as an official Kakao account transfer notification has been identified. The email attempts to instill anxiety by claiming that the user’s Kakao account is scheduled to be transferred, and prompts the user to click on the “Verify Account” link included in the body of the message. If a user enters their email address and password on the linked phishing page, the entered credentials may be transmitted to an external server controlled by the threat actor. In this article, we’ll examine the phishing tactics used in these Kakao account migration emails and the precautions users should take."<br />
<a href="https://asec.ahnlab.com/en/94388/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/94388/</a></li>
<li><strong>Files Locked Behind a White Padlock: A Warning From WhiteLock Ransomware</strong><br />
"If files start getting locked one by one and even remote access tools stop working, your system may already be infected with ransomware. The recently identified WhiteLock ransomware encrypts key files on Windows systems and then generates a ransom note demanding payment. A key characteristic of this ransomware is that it communicates with external servers during the encryption process and terminates Services related to remote access tools—such as AnyDesk and TeamViewer—to prevent victims from responding remotely. In this article, we’ll examine the main operating mechanisms of WhiteLock ransomware and the security considerations to keep in mind when responding to a ransomware attack."<br />
<a href="https://asec.ahnlab.com/en/94390/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/94390/</a></li>
<li><strong>Coordinated Npm And PyPI Campaign Typosquats Popular Secure Payment Apps</strong><br />
"Socket’s AI scanner detected a cluster of npm and PyPI malware published on July 7, 2026. The 17 packages, published nearly simultaneously, target SDK developers and users of the popular PaySafe, Skrill and Neteller payment applications. Ultimately, the packages perform credential and token theft, exfiltrating stolen data to AWS infrastructure."<br />
<a href="https://socket.dev/blog/npm-pypi-campaign-typosquats-popular-secure-payment-apps" target="_blank" rel="noopener noreferrer nofollow ugc">https://socket.dev/blog/npm-pypi-campaign-typosquats-popular-secure-payment-apps</a><br />
<a href="https://www.bleepingcomputer.com/news/security/fake-paysafe-skrill-sdks-on-npm-and-pypi-steal-credentials/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/fake-paysafe-skrill-sdks-on-npm-and-pypi-steal-credentials/</a></li>
<li><strong>Vishing Actors Target Entra Passkey Enrollment</strong><br />
"Since April 2026, a threat actor tracked as O-UNC-066 (also known as "Pink" by Palo Alto Networks Unit 42) has deployed a panel-controlled phishing kit targeting the passkey enrollment process for Microsoft 365 customers. Okta has observed the targeting of enterprise organizations across the food and beverage, technology, healthcare, automotive, construction, and aviation industries by this cluster of activity. The primary motivation of the threat actors is data extortion. The threat actor registers domains that incorporate the word passkey as part of a voice-enabled phishing (“vishing”) scheme. The threat actor then calls targeted users on the phone in an attempt to persuade them that they need to register a new passkey."<br />
<a href="https://www.okta.com/en-au/blog/threat-intelligence/vishing-actors-target-microsoft-entra-passkey-enrollment-/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.okta.com/en-au/blog/threat-intelligence/vishing-actors-target-microsoft-entra-passkey-enrollment-/</a><br />
<a href="https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/</a></li>
<li><strong>Inside An AI-Assisted Cloud Attack: Familiar Techniques At Unfamiliar Speed</strong><br />
"This case study shows that AI-enabled attackers do not necessarily need novel malware or zero-days. The real shift is speed, scale, and orchestration: familiar cloud attack techniques were executed faster and across more surfaces than defenders could comfortably contain."<br />
<a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/</a><br />
<a href="https://www.darkreading.com/cloud-security/lone-attacker-ai-breach-aws-cloud-environment" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cloud-security/lone-attacker-ai-breach-aws-cloud-environment</a><br />
<a href="https://www.infosecurity-magazine.com/news/threat-actor-agentic-ai-cloud/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/threat-actor-agentic-ai-cloud/</a></li>
<li><strong>Meta Phishers Abuse Business Account Manager Service</strong><br />
"Huntress is tracking a threat actor who has figured out how to manipulate a legitimate service offering from Meta to send a spam lure email that passes validation. The phishing group conducting this operation began as late as November 2025 but have recently added new infrastructure and a new spin to the attack: starting in June, they modified their phishing lure to incorporate a chatbot, run through a fraudulent account on Facebook Messenger, and began sending credentials to a private Telegram channel."<br />
<a href="https://www.huntress.com/blog/meta-business-manager-phishing" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.huntress.com/blog/meta-business-manager-phishing</a><br />
<a href="https://www.infosecurity-magazine.com/news/phishing-facebook-fake-verification/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/phishing-facebook-fake-verification/</a></li>
<li><strong>Beware Of Agentic Botnets: Scalable Untargeted Promptware Attacks Via Universal And Transferable Adversarial HalluSquatting</strong><br />
"We show that attackers can exploit predictable LLM hallucinations of resource identifiers to launch scalable, untargeted prompt injection attacks without requiring any direct channel to LLM applications. By preemptively registering hallucinated resources—a technique we call adversarial hallucination squatting (HalluSquatting)—we demonstrate remote tool execution and remote code execution at scale across a range of popular agentic LLM applications, which could be exploited to the establishment of a botnet."<br />
<a href="https://sites.google.com/view/agentic-botnets/home" target="_blank" rel="noopener noreferrer nofollow ugc">https://sites.google.com/view/agentic-botnets/home</a><br />
<a href="https://thehackernews.com/2026/07/new-hallusquatting-attack-could-trick.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/new-hallusquatting-attack-could-trick.html</a></li>
<li><strong>New Ghost Phishing Wave Is Breaking Traditional Email Security</strong><br />
"A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser. For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365 access, sensitive data, and response time are already at stake."<br />
<a href="https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html</a></li>
<li><strong>ClickFix To Cash-Out: Anatomy Of a Mexican Banking-Fraud Toolkit</strong><br />
"A Mexican banking fraud operation we're tracking as REF6045 doesn't run on autopilot. A human operator is behind the wheel, monitoring infected machines and deciding what happens next. Victims are infected through fake CAPTCHA pages that trick them into running a single command, which installs SCMBANKER, a PowerShell toolkit with components dating back to at least October 2025. Once installed, the operator can see when a victim opens a banking session, lock the screen behind a fake bank warning, push the victims towards live phone interaction, redirect the browser, or replace account numbers copied to the clipboard. For a full takeover, they can also deploy a commercial remote-access tool."<br />
<a href="https://www.elastic.co/security-labs/mexican-banking-fraud-scmbanker-ref6045" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.elastic.co/security-labs/mexican-banking-fraud-scmbanker-ref6045</a><br />
<a href="https://thehackernews.com/2026/07/scmbanker-malware-uses-clickfix-lures.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/scmbanker-malware-uses-clickfix-lures.html</a></li>
<li><strong>Targeted Phishing Attacks On Manufacturing Companies</strong><br />
"We have identified a new targeted phishing campaign in which cybercriminals attempted to attack manufacturing companies. The attack employed a multi-stage approach — before sending the phishing link directly, the attackers engaged in correspondence with the victim to lower their guard. The email texts were apparently generated using large language models. As of this post’s publication, the attack is still ongoing, so we recommend staying vigilant!"<br />
<a href="https://www.kaspersky.com/blog/manufacturing-phishing-2026/56097/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.kaspersky.com/blog/manufacturing-phishing-2026/56097/</a></li>
</ul>
<p dir="auto"><strong>Breaches/Hacks/Leaks</strong></p>
<ul>
<li><strong>Moody Bible Institute Breach Leaves 2.3M Accounts Needing Salvation, Says Cyber Expert</strong><br />
"Data on more than 2.3 million people associated with Moody Bible Institute (MBI) has been exposed online after the Christian college was targeted by ShinyHunters. The attack was first disclosed by MBI in June, and the extortion crew later leaked the stolen data. Have I Been Pwned has since added the cache to its breach notification database, putting a figure on the number of exposed accounts. MBI is one of many victims of ShinyHunters' pay-or-leak attacks in 2026, and while the organization has not explicitly commented on whether it negotiated with the criminals, the leak suggests that the group's extortion demands were not met."<br />
<a href="https://www.theregister.com/security/2026/07/06/moody-bible-institute-breach-leaves-23m-accounts-needing-salvation-says-cyber-expert/5266827" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/07/06/moody-bible-institute-breach-leaves-23m-accounts-needing-salvation-says-cyber-expert/5266827</a></li>
<li><strong>Mount Royal University Confirms Breach As Hackers Claim Attack</strong><br />
"Mount Royal University in Calgary says hackers stole and then deleted data from its file storage systems after breaching the university's network. In an update published on its website, MRU states that it has engaged technical teams and external cybersecurity experts to investigate the incident and to support recovery efforts following a cyberattack on June 17. The incident disrupted a broad range of university systems, including online services, internet access, and certain internal systems."<br />
<a href="https://www.bleepingcomputer.com/news/security/mount-royal-university-confirms-breach-as-hackers-claim-attack/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/mount-royal-university-confirms-breach-as-hackers-claim-attack/</a></li>
<li><strong>Telco Giant KDDI Says Data Breach Affects Over 12 Million People</strong><br />
"Japanese telecommunications giant KDDI revealed that millions of people had their email addresses and passwords exposed after attackers breached an email platform used by five internet service providers (ISPs) in the country. KDDI is the second-largest mobile telecommunications provider in Japan, with 45,000 employees and annual revenue of $32.4 billion. The company disclosed last month that it blocked the attackers' access and implemented defensive measures after discovering the incident on June 17, and revealed that the breach impacted the STNet, JCOM, Chubu Telecommunications C, NIFTY Corporation, and BIGLOBE ISP operators.</li>
</ul>
<p dir="auto"><a href="https://www.bleepingcomputer.com/news/security/japanese-telecom-giant-kddi-says-data-breach-affects-12-million-people/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/japanese-telecom-giant-kddi-says-data-breach-affects-12-million-people/</a></p>
<p dir="auto"><strong>General News</strong></p>
<ul>
<li><strong>Orbia CISO Miranda Ritchie On Building Security Into Sustainable Infrastructure</strong><br />
"In this interview with Help Net Security, Miranda Ritchie, CISO at Orbia, talks about protecting industrial systems where software runs water, chemical and manufacturing processes. She explains why a cyber incident in these settings can harm people, equipment and the environment, and how spread-out sites and aging control hardware widen the risk. Ritchie describes tying security to safety culture, embedding cyber teams early in new projects, and treating nothing as trusted just because it sits on the network. Her view: speed and security can support each other."<br />
<a href="https://www.helpnetsecurity.com/2026/07/08/miranda-ritchie-orbia-industrial-cybersecurity/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/08/miranda-ritchie-orbia-industrial-cybersecurity/</a></li>
<li><strong>When AI Agents Look Like Attackers: What Behavioral Telemetry Tells Us</strong><br />
"AI coding agents (Claude Code, Cursor, Codex, and others built on skill packs such as GStack) are showing up in customer environments. They write code, install dependencies, automate browser tasks, and troubleshoot failures by trying alternative approaches. From the perspective of an endpoint behavioral engine, some of that activity is indistinguishable from typical activity seen on customer networks – or, in some cases, from actions that might be undertaken by an active adversary."<br />
<a href="https://www.sophos.com/en-us/blog/2607_agents_vs_telemetry" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.sophos.com/en-us/blog/2607_agents_vs_telemetry</a><br />
<a href="https://thehackernews.com/2026/07/ai-coding-agents-found-triggering.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/ai-coding-agents-found-triggering.html</a></li>
<li><strong>GitHub Copilot Refuses Harmful Requests In Chat, Then Writes Them In Code</strong><br />
"An AI coding assistant that refuses to answer a dangerous request in its chat box can answer it anyway if the same request is broken into small, ordinary-looking steps inside a code editor. That is the finding of a new study of GitHub Copilot by researchers Abhishek Kumar and Carsten Maple. The models they tested through Copilot, Claude from Anthropic, and Gemini from Google, refused almost every harmful request when asked directly. Reframed as steps in a normal coding task, they produced the harmful answers in all 816 of the study's workflow runs."<br />
<a href="https://thehackernews.com/2026/07/github-copilot-refuses-harmful-requests.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/github-copilot-refuses-harmful-requests.html</a><br />
<a href="https://arxiv.org/abs/2607.03968" target="_blank" rel="noopener noreferrer nofollow ugc">https://arxiv.org/abs/2607.03968</a><br />
<a href="https://www.theregister.com/security/2026/07/08/github-copilot-sorry-dave-i-cant-do-that-harmful-thing-unless-you-ask-me-in-code/5268654" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/07/08/github-copilot-sorry-dave-i-cant-do-that-harmful-thing-unless-you-ask-me-in-code/5268654</a></li>
<li><strong>GhostApproval: A Trust Boundary Gap In AI Coding Assistants</strong><br />
"The value of AI coding assistants is simple and straightforward: the agent proposes an action, then you approve. Before any file is modified, a confirmation dialog appears: the Human-in-the-Loop safety net that keeps you in control. But what if the controls you see aren’t the controls you’re actually operating? Symbolic links have been a security headache since the early days of Unix. From /tmp race conditions to privilege escalation exploits, symlinks have a long history of bypassing security boundaries by making one path silently resolve to another. It's a well-documented attack primitive - CWE-61 dates back decades. So what happens when you apply this classic trick to AI coding assistants?"<br />
<a href="https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants</a><br />
<a href="https://www.theregister.com/security/2026/07/08/bug-in-top-ai-coding-agents-shows-that-unix-era-security-headaches-never-really-die/5268025" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/07/08/bug-in-top-ai-coding-agents-shows-that-unix-era-security-headaches-never-really-die/5268025</a></li>
<li><strong>ESET Threat Report H1 2026</strong><br />
"The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations. Rather than relying on entirely new methods and tools, they are quickly adapting established techniques to new platforms, technologies, and user behaviors. Artificial intelligence is playing a growing role in this development. In H1 2026, ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of outright malicious instances. The number of AI skills within this new ecosystem is growing rapidly “as we speak”, further expanding the attack surface."<br />
<a href="https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/</a><br />
<a href="https://www.helpnetsecurity.com/2026/07/08/eset-ai-threat-trends-report/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/08/eset-ai-threat-trends-report/</a></li>
</ul>
<p dir="auto"><strong>อ้างอิง</strong><br />
Electronic Transactions Development Agency (ETDA) <img src="/assets/uploads/files/1783585112410-8a083dec-a552-43d8-ab84-a505b569a61c-image.png" alt="8a083dec-a552-43d8-ab84-a505b569a61c-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3075/cyber-threat-intelligence-09-july-2026</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3075/cyber-threat-intelligence-09-july-2026</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Thu, 09 Jul 2026 08:18:33 GMT</pubDate></item><item><title><![CDATA[BeyondTrust เตือนช่องโหว่ Critical ใน RS และ PRA เสี่ยงถูกข้ามการยืนยันตัวตน]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1783504600329-beyondtrust-%E0%B9%80%E0%B8%95-%E0%B8%AD%E0%B8%99%E0%B8%8A-%E0%B8%AD%E0%B8%87%E0%B9%82%E0%B8%AB%E0%B8%A7-critical-%E0%B9%83%E0%B8%99-rs-%E0%B9%81%E0%B8%A5%E0%B8%B0-pra-%E0%B9%80%E0%B8%AA-%E0%B8%A2%E0%B8%87%E0%B8%96-%E0%B8%81%E0%B8%82.png" alt="BeyondTrust เตือนช่องโหว่ Critical ใน RS และ PRA เสี่ยงถูกข้.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783504609132-be8fa15a-be16-4485-9e7b-385cd91ed8de-image.png" alt="be8fa15a-be16-4485-9e7b-385cd91ed8de-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3074/beyondtrust-เต-อนช-องโหว-critical-ใน-rs-และ-pra-เส-ยงถ-กข-ามการย-นย-นต-วตน</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3074/beyondtrust-เต-อนช-องโหว-critical-ใน-rs-และ-pra-เส-ยงถ-กข-ามการย-นย-นต-วตน</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Wed, 08 Jul 2026 09:56:55 GMT</pubDate></item><item><title><![CDATA[ช่องโหว่ Backdoor ในเราเตอร์ Tenda เปิดทางผู้โจมตี Bypass Login และได้สิทธิ์ผู้ดูแลระบบ ยังไม่มีแพตช์แก้ไข]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1783504549923-%E0%B8%8A-%E0%B8%AD%E0%B8%87%E0%B9%82%E0%B8%AB%E0%B8%A7-backdoor-%E0%B9%83%E0%B8%99%E0%B9%80%E0%B8%A3%E0%B8%B2%E0%B9%80%E0%B8%95%E0%B8%AD%E0%B8%A3-tenda-%E0%B9%80%E0%B8%9B-%E0%B8%94%E0%B8%97%E0%B8%B2%E0%B8%87%E0%B8%9C-%E0%B9%82%E0%B8%88%E0%B8%A1%E0%B8%95-by.png" alt="ช่องโหว่ Backdoor ในเราเตอร์ Tenda เปิดทางผู้โจมตี By.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783504560567-19eada3b-a673-4e12-baee-424507a89c83-image.png" alt="19eada3b-a673-4e12-baee-424507a89c83-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3073/ช-องโหว-backdoor-ในเราเตอร-tenda-เป-ดทางผ-โจมต-bypass-login-และได-ส-ทธ-ผ-ด-แลระบบ-ย-งไม-ม-แพตช-แก-ไข</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3073/ช-องโหว-backdoor-ในเราเตอร-tenda-เป-ดทางผ-โจมต-bypass-login-และได-ส-ทธ-ผ-ด-แลระบบ-ย-งไม-ม-แพตช-แก-ไข</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Wed, 08 Jul 2026 09:56:10 GMT</pubDate></item><item><title><![CDATA[ผู้ไม่หวังดีพุ่งเป้าสแกนช่องโหว่ความรุนแรงระดับวิกฤตบน Gitea Docker หลังการเปิดเผยข้อมูลเพียง 13 วัน]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1783504497005-%E0%B8%9C-%E0%B9%84%E0%B8%A1-%E0%B8%AB%E0%B8%A7-%E0%B8%87%E0%B8%94-%E0%B8%9E-%E0%B8%87%E0%B9%80%E0%B8%9B-%E0%B8%B2%E0%B8%AA%E0%B9%81%E0%B8%81%E0%B8%99%E0%B8%8A-%E0%B8%AD%E0%B8%87%E0%B9%82%E0%B8%AB%E0%B8%A7-%E0%B8%84%E0%B8%A7%E0%B8%B2%E0%B8%A1%E0%B8%A3-%E0%B8%99.png" alt="ผู้ไม่หวังดีพุ่งเป้าสแกนช่องโหว่ความรุน.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783504509164-80258978-dbe1-4272-9dbe-848ef3288907-image.png" alt="80258978-dbe1-4272-9dbe-848ef3288907-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3072/ผ-ไม-หว-งด-พ-งเป-าสแกนช-องโหว-ความร-นแรงระด-บว-กฤตบน-gitea-docker-หล-งการเป-ดเผยข-อม-ลเพ-ยง-13-ว-น</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3072/ผ-ไม-หว-งด-พ-งเป-าสแกนช-องโหว-ความร-นแรงระด-บว-กฤตบน-gitea-docker-หล-งการเป-ดเผยข-อม-ลเพ-ยง-13-ว-น</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Wed, 08 Jul 2026 09:55:25 GMT</pubDate></item><item><title><![CDATA[CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก]]></title><description><![CDATA[<p dir="auto">เมื่อวันที่ 7 กรกฏาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้</p>
<ul>
<li>CVE-2026-48282 Adobe ColdFusion Path Traversal Vulnerability</li>
</ul>
<p dir="auto">ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต</p>
<p dir="auto"><strong>อ้างอิง</strong></p>
<p dir="auto"><a href="https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-one-known-exploited-vulnerability-catalog" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-one-known-exploited-vulnerability-catalog</a></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3071/cisa-เพ-มช-องโหว-ท-ถ-กใช-โจมต-1-รายการลงในแคตตาล-อก</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3071/cisa-เพ-มช-องโหว-ท-ถ-กใช-โจมต-1-รายการลงในแคตตาล-อก</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Wed, 08 Jul 2026 08:59:53 GMT</pubDate></item><item><title><![CDATA[CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 3 รายการลงในแคตตาล็อก]]></title><description><![CDATA[<p dir="auto">เมื่อวันที่ 7 กรกฏาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 3 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้</p>
<ul>
<li>CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability</li>
<li>CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled Key Vulnerability</li>
<li>CVE-2026-56290 Joomlack Page Builder Improper Access Control Vulnerability</li>
</ul>
<p dir="auto"><strong>อ้างอิง</strong><br />
<a href="https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog</a><br />
สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783501033203-788160c0-7841-4cfc-9a7e-b950c61fc1c4-image.png" alt="788160c0-7841-4cfc-9a7e-b950c61fc1c4-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3070/cisa-เพ-มช-องโหว-ท-ถ-กใช-โจมต-3-รายการลงในแคตตาล-อก</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3070/cisa-เพ-มช-องโหว-ท-ถ-กใช-โจมต-3-รายการลงในแคตตาล-อก</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Wed, 08 Jul 2026 08:58:09 GMT</pubDate></item><item><title><![CDATA[Cyber Threat Intelligence 08 July 2026]]></title><description><![CDATA[<p dir="auto"><strong>Industrial Sector</strong></p>
<ul>
<li><strong>Hydro-Québec Le Circuit Electrique Charging Station Backend</strong><br />
"Successful exploitation of these vulnerabilities could lead to privilege escalation, or result in a denial-of-service attack."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01</a></li>
<li><strong>Siemens SINEC OS</strong><br />
"SINEC OS before V4.0 contains multiple vulnerabilities. Siemens has released a new version for RUGGEDCOM RST2428P and recommends to update to the latest version."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-05" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-05</a></li>
<li><strong>Hitachi Energy PROMOD V</strong><br />
"Hitachi Energy is aware of insecure HTTP transmission vulnerability in PROMOD V product versions listed in this document. This vulnerability could allow attackers to intercept or manipulate sensitive data in transit, potentially leading to credential theft, session hijacking, or unauthorized access."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-02" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-02</a></li>
<li><strong>Hitachi Energy e-Mesh EMS</strong><br />
"Hitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) and possible arbitrary code execution. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-03" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-03</a></li>
<li><strong>Siemens Mendix Studio Pro</strong><br />
"Mendix Studio Pro versions before V11.12 are affected by a file parsing vulnerability that could be triggered when the application reads specially crafted malicious project during the build pipeline. This could allow an attacker to execute arbitrary code in the context of that user. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-04" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-04</a></li>
<li><strong>Labcenter Proteus 9</strong><br />
"Successful exploitation of these vulnerabilities could disclose information and allow a malicious user to execute arbitrary code on affected installations."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-06" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-06</a></li>
<li><strong>Digi International PortServer TS, Digi One SP IA</strong><br />
"Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and gain access to restricted resources, obtain credentials, and inject malicious scripts."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-07" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-07</a></li>
<li><strong>Threat Landscape For Industrial Automation Systems. Q1 2026</strong><br />
"The percentage of ICS computers on which malicious objects were blocked continued to decrease, reaching 19.6% in Q1 2026. This is the lowest value in three years, and it is 1.4 times lower than in Q2 2023."<br />
<a href="https://securelist.com/industrial-threat-report-q1-2026/120643/" target="_blank" rel="noopener noreferrer nofollow ugc">https://securelist.com/industrial-threat-report-q1-2026/120643/</a></li>
</ul>
<p dir="auto"><strong>New Tooling</strong></p>
<ul>
<li><strong>Apple Container: Open-Source Tool For Linux Containers On The Mac</strong><br />
"Developers on Apple silicon Macs have run Linux containers through software built around a single shared virtual machine for years. Apple’s open-source Container project gives each Linux workload its own lightweight virtual machine. Container is written in Swift and tuned for Apple silicon. It creates and runs Linux containers as lightweight virtual machines, and it works with OCI-compatible images, so a developer can pull from and push to any standard registry. Images built with it run in any other OCI-compatible application. Under the hood, it draws on the Containerization Swift package for low-level container, image, and process management."<br />
<a href="https://www.helpnetsecurity.com/2026/07/07/apple-container-open-source-linux-mac/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/07/apple-container-open-source-linux-mac/</a><br />
<a href="https://github.com/apple/container" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/apple/container</a></li>
</ul>
<p dir="auto"><strong>Vulnerabilities</strong></p>
<ul>
<li><strong>Security Advisory Bulletin 066</strong><br />
"A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device."<br />
<a href="https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc" target="_blank" rel="noopener noreferrer nofollow ugc">https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc</a></li>
<li><strong>BeyondTrust Warns Of Critical Flaws In Remote Access Software</strong><br />
"BeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication. The first vulnerability, tracked as CVE-2026-40138, affects the company's RS remote desktop and assistance platform (versions 25.3.2 or earlier) and the PRA enterprise cybersecurity solution (versions 25.3.2 or earlier). This vulnerability stems from an improper authentication weakness in the authentication subsystem, and successful exploitation enables attackers without privileges to bypass access controls and access targeted appliances, including accounts with elevated privileges."<br />
<a href="https://www.bleepingcomputer.com/news/security/beyondtrust-warns-of-critical-flaws-in-remote-access-software/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/beyondtrust-warns-of-critical-flaws-in-remote-access-software/</a><br />
<a href="https://www.beyondtrust.com/trust-center/security-advisories/bt26-03" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.beyondtrust.com/trust-center/security-advisories/bt26-03</a><br />
<a href="https://thehackernews.com/2026/07/beyondtrust-patches-critical-auth.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/beyondtrust-patches-critical-auth.html</a></li>
<li><strong>Tenda Firmware (multiple Versions) Contains Hidden Authentication Backdoor</strong><br />
"Several versions of Tenda firmware contain an undocumented authentication backdoor that grants administrative access to the devices' web management interfaces. An attacker can expoit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process and obtain full administrative control without valid credentials."<br />
<a href="https://kb.cert.org/vuls/id/213560" target="_blank" rel="noopener noreferrer nofollow ugc">https://kb.cert.org/vuls/id/213560</a><br />
<a href="https://thehackernews.com/2026/07/certcc-warns-of-hidden-admin-backdoor.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/certcc-warns-of-hidden-admin-backdoor.html</a><br />
<a href="https://www.bleepingcomputer.com/news/security/hidden-backdoor-in-tenda-router-firmware-grants-admin-access/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/hidden-backdoor-in-tenda-router-firmware-grants-admin-access/</a><br />
<a href="https://securityaffairs.com/194878/security/hidden-tenda-router-backdoor-grants-admin-access-no-patch-available.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/194878/security/hidden-tenda-router-backdoor-grants-admin-access-no-patch-available.html</a></li>
<li><strong>CISA Adds Three Known Exploited Vulnerabilities To Catalog</strong><br />
"CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.<br />
CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability<br />
CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled Key Vulnerability<br />
CVE-2026-56290 Joomlack Page Builder Improper Access Control Vulnerability"<br />
<a href="https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog</a></li>
<li><strong>CISA Adds One Known Exploited Vulnerability To Catalog</strong><br />
"CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.<br />
CVE-2026-48282 Adobe ColdFusion Path Traversal Vulnerability"<br />
<a href="https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-one-known-exploited-vulnerability-catalog" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-one-known-exploited-vulnerability-catalog</a></li>
<li><strong>Rogue Agent: How a Single Code Block Could Hijack Your AI Conversations In Google’s DialogFlow</strong><br />
"Varonis Threat Labs discovered a critical vulnerability in Google Cloud Platform’s (GCP) Dialogflow CX service, Google’s flagship conversational AI platform for building interactive experiences across voice and text chatbots. We’ve named this latest discovery Rogue Agent. The vulnerability allowed attackers to exploit the Code Blocks feature to inject persistent malicious code into the Dialogflow agents’ pipeline, silently exfiltrating conversations and conducting large-scale phishing campaigns. To initiate, the exploit requires a single edit permission known as dialogflow.playbooks.update on one agent."<br />
<a href="https://www.varonis.com/blog/rogue-agent-dialogflow-attack" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.varonis.com/blog/rogue-agent-dialogflow-attack</a><br />
<a href="https://www.darkreading.com/application-security/dialogflow-cx-rogue-agent-flaw-enabled-ai-chatbot-data-theft" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/application-security/dialogflow-cx-rogue-agent-flaw-enabled-ai-chatbot-data-theft</a><br />
<a href="https://thehackernews.com/2026/07/rogue-agent-flaw-could-have-let.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/rogue-agent-flaw-could-have-let.html</a></li>
<li><strong>GitLost: How We Tricked GitHub’s AI Agent Into Leaking Private Repos</strong><br />
"Noma Labs discovered a critical prompt injection vulnerability within GitHub’s new Agentic Workflows, allowing an unauthenticated attacker to silently pull data from private repositories by posting a crafted GitHub Issue in a public repository belonging to the same organization as the private repositories. Noma Labs named the vulnerability GitLost."<br />
<a href="https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/" target="_blank" rel="noopener noreferrer nofollow ugc">https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/</a><br />
<a href="https://thehackernews.com/2026/07/public-github-issue-could-trick-github.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/public-github-issue-could-trick-github.html</a><br />
<a href="https://www.darkreading.com/cyber-risk/gitlost-leaks-private-data-github-agentic-workflows" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cyber-risk/gitlost-leaks-private-data-github-agentic-workflows</a><br />
<a href="https://hackread.com/gitlost-github-ai-agent-leaking-repository-data/" target="_blank" rel="noopener noreferrer nofollow ugc">https://hackread.com/gitlost-github-ai-agent-leaking-repository-data/</a></li>
<li><strong>WriteOut: Abusing The Sandbox For a Critical Cross-Tenant Vulnerability In Writer AI</strong><br />
"Every AI platform tells you the same comforting bedtime story. Don't worry, the code runs in a sandbox. Whatever the model generates, whatever the user uploads, whatever the agent decides to do at 2 a.m. with no human watching, it's all safely boxed in. The box is the boundary. Enter Writer AI, an enterprise platform where teams build their own AI agents. We found a way to turn Writer's own sandbox against its users: an agent could hand an attacker the keys to any account on the platform. We dubbed it WriteOut, and Writer has since fixed it. Until they did, an outsider could go from having no access to taking over any Writer AI organization inside industry-leading enterprises, with nothing more than a link."<br />
<a href="https://www.sandsecurity.ai/blog/writeout-writer-ai-cross-tenant" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.sandsecurity.ai/blog/writeout-writer-ai-cross-tenant</a><br />
<a href="https://thehackernews.com/2026/07/writer-ai-flaw-could-let-agent-previews.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/writer-ai-flaw-could-let-agent-previews.html</a></li>
</ul>
<p dir="auto"><strong>Malware</strong></p>
<ul>
<li><strong>Vidar Infostealer Being Spread Through Phishing Emails</strong><br />
"First identified in 2018, Vidar operates under a Malware-as-a-Service (MaaS) model and continues to be distributed through various attack cases to this day. AhnLab SEcurity intelligence Center (ASEC) has been monitoring cases of Vidar distribution targeting Korea, and this report summarizes the Vidar distribution cases identified in the first half of 2026."<br />
<a href="https://asec.ahnlab.com/en/94363/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/94363/</a></li>
<li><strong>Connecting Scattered Spider: Defining A Cybercrime Collective Through Shared TTPs</strong><br />
"Scattered Spider has attracted a lot of attention in recent years, including the mass media, especially after being attributed as the responsible party for a number of high profile attacks. Its initial days can be traced back to 2022, when notorious attacks started being attributed to Scattered Spider, such as the attack which compromised around 125 Twilio customers in August 2022 or the Caesars Palace and MGM Resort incidents in September 2023. These high profile attacks have led to law enforcement agencies taking action against the so-called Scattered Spider members. However, attacks attributed to Scattered Spider never stopped, with CISA and other organizations releasing advisories warning about its attacks even in 2025."<br />
<a href="https://www.group-ib.com/blog/connecting-scattered-spider/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.group-ib.com/blog/connecting-scattered-spider/</a><br />
<a href="https://thehackernews.com/2026/07/court-filing-reveals-windows-device-id.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/court-filing-reveals-windows-device-id.html</a><br />
<a href="https://www.infosecurity-magazine.com/news/scattered-spider-as-cybercrime/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/scattered-spider-as-cybercrime/</a></li>
<li><strong>One Email Closer To The Edge: UNK_MassTraction &amp; The Physics Of Exploitation</strong><br />
"Beginning in May 2026, Proofpoint observed a new cluster of activity – tracked as UNK_MassTraction – exploiting CVE-2024-42009, a cross-site scripting vulnerability in Roundcube. The campaign targeted physics and engineering departments at major US and Canadian universities, with a focus on administrators and professors in departments with either national security ties, or entities studying astrophysics and particle physics. While the targeting appeared specific to these departments, the exploit only requires that the email is opened in the mail client to achieve access to the mailserver so the recipients may have been inconsequential."<br />
<a href="https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation</a><br />
<a href="https://thehackernews.com/2026/07/suspected-china-aligned-hackers-exploit.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/suspected-china-aligned-hackers-exploit.html</a><br />
<a href="https://www.bankinfosecurity.com/chinese-cyberespionage-exploits-university-roundcube-servers-a-32165" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/chinese-cyberespionage-exploits-university-roundcube-servers-a-32165</a><br />
<a href="https://cyberscoop.com/china-espionage-attacks-us-canada-universities-proofpoint/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/china-espionage-attacks-us-canada-universities-proofpoint/</a><br />
<a href="https://www.infosecurity-magazine.com/news/china-aligned-cluster-roundcube/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/china-aligned-cluster-roundcube/</a></li>
<li><strong>UAT-7810 Continues Building ORB Networks Using New Malware</strong><br />
"Talos assesses with high confidence that UAT-7810 is a China-nexus threat actor based on the infrastructure that it provides to secondary China-nexus APTs such as UAT-5918. Open-source reporting has also illustrated overlapping tooling between UAT-5918 and UAT-7810. However, at this time, Talos considers UAT-5918 and UAT-7810 separate APT actors tasked with their own set of objectives and targets. Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware dubbed “SHORTLEASH” with a newer version already being developed and hosted on attacker-controlled infrastructure. We track this new version of SHORTLEASH as “LONGLEASH.”"<br />
<a href="https://blog.talosintelligence.com/uat-7810/" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.talosintelligence.com/uat-7810/</a><br />
<a href="https://www.bleepingcomputer.com/news/security/chinese-hackers-develop-longleash-malware-to-expand-orb-network/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/chinese-hackers-develop-longleash-malware-to-expand-orb-network/</a></li>
<li><strong>RedWing: A Mobile Malware-As-a-Service Operation</strong><br />
"The zLabs team has uncovered RedWing, a new Android spyware variant offered as a Malware-as-a-Service (MaaS) through a Telegram channel and appears to have links to Russian threat actors. Malicious operators distribute this rental-based malware through mobile-targeted phishing sites. A substantial number of the associated payloads and droppers currently evade detection by conventional security tools. This discovery looks like a new variant of the oblivion malware, due to the similarity on the dropper stage and some of the overlays used."<br />
<a href="https://zimperium.com/blog/redwing-a-mobile-malware-as-a-service-operation" target="_blank" rel="noopener noreferrer nofollow ugc">https://zimperium.com/blog/redwing-a-mobile-malware-as-a-service-operation</a><br />
<a href="https://thehackernews.com/2026/07/redwing-maas-packages-android-bank.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/redwing-maas-packages-android-bank.html</a></li>
<li><strong>DEBULL: Storm-2372-Style Microsoft Device-Code Phishing With GraphSpy Post-Exploitation</strong><br />
"The tradecraft has strong characteristics previously described in Microsoft Storm-2372 reporting: messaging or Teams-style lures, device-code authentication, Microsoft Authentication Broker usage, geo-plausible infrastructure, and device-registration relevant follow-on activity. We do not attribute the campaign directly to Storm-2372. We assess that the operator is using Storm-2372-style tradecraft through a reusable tooling layer we track as DEBULL. Follow-up analysis exposed the backend behind the campaign. The same IP that created the attacker-side Microsoft Authentication Broker session also served a DEBULL login panel directly."<br />
<a href="https://zerobec.com/blog/debull-storm-2372-microsoft-device-code-phishing-graphspy" target="_blank" rel="noopener noreferrer nofollow ugc">https://zerobec.com/blog/debull-storm-2372-microsoft-device-code-phishing-graphspy</a><br />
<a href="https://thehackernews.com/2026/07/debull-tooling-abuses-microsoft-device.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/debull-tooling-abuses-microsoft-device.html</a></li>
<li><strong>Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders And File Inflation</strong><br />
"In April 2026, Unit 42 researchers identified a financially motivated campaign delivering Vidar stealer and the XMRig cryptocurrency miner to consumer and small- and medium-sized business victims worldwide. Attackers lure victims via malvertising to pages for downloading files that impersonate cracked versions of copyright-protected software. Upon execution, the loader drops and runs both Vidar stealer and XMRig. Vidar stealer targets information like browser credentials, cookies and crypto wallets. XMRig mines Monero cryptocurrency."<br />
<a href="https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysis/" target="_blank" rel="noopener noreferrer nofollow ugc">https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysis/</a></li>
</ul>
<p dir="auto"><strong>Breaches/Hacks/Leaks</strong></p>
<ul>
<li><strong>Accenture Confirms Breach After Hacker Offers Stolen Data For Sale</strong><br />
"IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. "We are aware of this isolated matter, and we have remediated its source. There is no impact to Accenture operations and service delivery," Accenture told BleepingComputer. Accenture is a global professional services company that provides consulting, technology, cloud, engineering, and managed services to businesses and governments worldwide."<br />
<a href="https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/</a></li>
<li><strong>County Government Reportedly Paid $1 Million To Cyber Extortion Group</strong><br />
"A government entity in the US reportedly paid a $1 million ransom to the Kairos cyber extortion group to prevent the public dissemination of information stolen in a May 2025 intrusion, Ransom-ISAC reports. A leaked negotiation transcript shows that the extortion group demanded $3 million in cryptocurrency from the victim organization, but eventually settled for $1 million. Kairos claimed to have stolen over 2 terabytes of data, or approximately 1.6 million files, after accessing the victim’s environment in a brute-force attack."<br />
<a href="https://www.securityweek.com/county-government-reportedly-paid-1-million-to-cyber-extortion-group/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/county-government-reportedly-paid-1-million-to-cyber-extortion-group/</a></li>
<li><strong>Major Japanese Telco Says Cyberattack Exposed 12 Million Emails</strong><br />
"One of Japan's largest telecommunications providers said Monday that a cyberattack targeting an email platform it operates for internet service providers exposed more than 12.2 million customer email addresses and 7.6 million passwords. The company said the breach affected an email system used to manage customer email accounts, webmail services and email storage for five Japanese internet service providers. KDDI first disclosed the unauthorized access in June but only confirmed the scale of the data exposure after completing its forensic investigation and submitting a report to Japan's communications ministry earlier this week."<br />
<a href="https://therecord.media/major-japanese-telco-cyberattack-12-million-emails" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/major-japanese-telco-cyberattack-12-million-emails</a></li>
</ul>
<p dir="auto"><strong>General News</strong></p>
<ul>
<li><strong>Q2 2026 Vulnerability Trends Report</strong><br />
"A total of 20,701 new CVEs were reported in the second quarter of 2026. Of these, 2,317 were “Critical” vulnerabilities with a CVSS score of 9.0 Or higher, accounting for 11.2% Of the total. Medium- and high-risk vulnerabilities, including those rated “High,” accounted for 51.7% Of the total. While the overall volume remained similar to Q1, the number of “Critical” vulnerabilities—which can cause immediate damage—increased by 62.5% From 1,426 in Q1."<br />
<a href="https://asec.ahnlab.com/en/94360/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/94360/</a></li>
<li><strong>Windows Platform Security For AI Agents</strong><br />
"AI agents are no longer just answering questions, they are taking actions across systems with increasing autonomy. As they become persistent participants in how software runs, they introduce new risk to control and trust, challenging the security assumptions that have defined computing for decades. Developers are building agents that read files, invoke services, modify environments and chain operations together at increasing speed. That capability is powerful, but it raises a critical question: how do you ensure these systems remain trustworthy when they operate autonomously, at scale, on real data?"<br />
<a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/windows-platform-security-for-ai-agents/" target="_blank" rel="noopener noreferrer nofollow ugc">https://blogs.windows.com/windowsdeveloper/2026/06/02/windows-platform-security-for-ai-agents/</a><br />
<a href="https://www.helpnetsecurity.com/2026/07/07/microsoft-execution-containers-ai-agents-constraints/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/07/microsoft-execution-containers-ai-agents-constraints/</a></li>
<li><strong>Power Shortages Could Slow AI Data Center Expansion</strong><br />
"AI adoption is increasing demand for data center capacity at the same time operators are running into limits around power, equipment, land, and permitting, according to NTT Data. Access to electricity is becoming a deciding factor in where new data centers are built, when new capacity comes online and how quickly AI projects can expand."<br />
<a href="https://www.helpnetsecurity.com/2026/07/07/ai-data-centers-demand-expansion/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/07/ai-data-centers-demand-expansion/</a></li>
<li><strong>CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader And Original Thinker</strong><br />
"Tarah Wheeler is CISO at TPO Group. TPO is an acronym for technology, policy and operations, and the firm provides cybersecurity consultancy for high-stakes organizations such as critical industries and federal agencies. But despite this elevated position, her journey was far from typical. “I absolutely did not choose this career on purpose,” she said. “No, I fell backwards into it. I feel like this career dragged me into an alley, coshed me over the head, and said, ‘You’re one of us now. kid’.” For Americans unfamiliar with British slang, the ‘cosh’ phrase would be better understood as ‘hit me over the head with a baseball bat’ – and it may be worth noting that although born in Washington, Wheeler is currently studying at Oxford in the UK."<br />
<a href="https://www.securityweek.com/ciso-conversations-tarah-wheeler-cybersecurity-leader-thought-leader-and-original-thinker/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/ciso-conversations-tarah-wheeler-cybersecurity-leader-thought-leader-and-original-thinker/</a></li>
</ul>
<p dir="auto"><strong>อ้างอิง</strong><br />
Electronic Transactions Development Agency (ETDA) <img src="/assets/uploads/files/1783499209759-db681405-4874-44b2-8b40-19c467a38620-image.png" alt="db681405-4874-44b2-8b40-19c467a38620-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3069/cyber-threat-intelligence-08-july-2026</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3069/cyber-threat-intelligence-08-july-2026</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Wed, 08 Jul 2026 08:26:51 GMT</pubDate></item><item><title><![CDATA[Adobe เตือนเร่งอัปเดต ColdFusion หลังยืนยันช่องโหว่ Critical ถูกใช้โจมตีจริง]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1783419179067-adobe-%E0%B9%80%E0%B8%95-%E0%B8%AD%E0%B8%99%E0%B9%80%E0%B8%A3-%E0%B8%87%E0%B8%AD-%E0%B8%9B%E0%B9%80%E0%B8%94%E0%B8%95-coldfusion-%E0%B8%AB%E0%B8%A5-%E0%B8%87%E0%B8%A2-%E0%B8%99%E0%B8%A2-%E0%B8%99%E0%B8%8A-%E0%B8%AD%E0%B8%87%E0%B9%82%E0%B8%AB%E0%B8%A7-c.png" alt="Adobe เตือนเร่งอัปเดต ColdFusion หลังยืนยันช่องโหว่ C.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783419185803-728df355-67fb-4a8d-89a5-ea8914205baf-image.png" alt="728df355-67fb-4a8d-89a5-ea8914205baf-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3068/adobe-เต-อนเร-งอ-ปเดต-coldfusion-หล-งย-นย-นช-องโหว-critical-ถ-กใช-โจมต-จร-ง</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3068/adobe-เต-อนเร-งอ-ปเดต-coldfusion-หล-งย-นย-นช-องโหว-critical-ถ-กใช-โจมต-จร-ง</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Tue, 07 Jul 2026 10:13:11 GMT</pubDate></item><item><title><![CDATA[Medtronic แจ้งเหตุข้อมูลรั่วไหล กระทบประชาชนกว่า 3.8 ล้านราย หลังถูกกลุ่ม ShinyHunters โจมตี]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1783419121527-medtronic-%E0%B9%81%E0%B8%88-%E0%B8%87%E0%B9%80%E0%B8%AB%E0%B8%95-%E0%B8%82-%E0%B8%AD%E0%B8%A1-%E0%B8%A5%E0%B8%A3-%E0%B8%A7%E0%B9%84%E0%B8%AB%E0%B8%A5-%E0%B8%81%E0%B8%A3%E0%B8%B0%E0%B8%97%E0%B8%9A%E0%B8%9B%E0%B8%A3%E0%B8%B0%E0%B8%8A%E0%B8%B2%E0%B8%8A%E0%B8%99%E0%B8%81%E0%B8%A7.png" alt="Medtronic แจ้งเหตุข้อมูลรั่วไหล กระทบประชาชนกว่.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783419129179-e8fab952-bed1-43cb-92fd-27c17fa0b14e-image.png" alt="e8fab952-bed1-43cb-92fd-27c17fa0b14e-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3067/medtronic-แจ-งเหต-ข-อม-ลร-วไหล-กระทบประชาชนกว-า-3-8-ล-านราย-หล-งถ-กกล-ม-shinyhunters-โจมต</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3067/medtronic-แจ-งเหต-ข-อม-ลร-วไหล-กระทบประชาชนกว-า-3-8-ล-านราย-หล-งถ-กกล-ม-shinyhunters-โจมต</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Tue, 07 Jul 2026 10:12:24 GMT</pubDate></item><item><title><![CDATA[Flipper Devices ปรับแนวทางการพัฒนาเฟิร์มแวร์ Flipper Zero โดยมุ่งเน้นการมีส่วนร่วมของชุมชนนักพัฒนา]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1783419067597-flipper-devices-%E0%B8%9B%E0%B8%A3-%E0%B8%9A%E0%B9%81%E0%B8%99%E0%B8%A7%E0%B8%97%E0%B8%B2%E0%B8%87%E0%B8%81%E0%B8%B2%E0%B8%A3%E0%B8%9E-%E0%B8%92%E0%B8%99%E0%B8%B2%E0%B9%80%E0%B8%9F-%E0%B8%A3-%E0%B8%A1%E0%B9%81%E0%B8%A7%E0%B8%A3-flipper-zero-%E0%B9%82.png" alt="Flipper Devices ปรับแนวทางการพัฒนาเฟิร์มแวร์ Flipper Zero โ.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783419081940-baef9c2b-cea9-4a34-a685-530616d30644-image.png" alt="baef9c2b-cea9-4a34-a685-530616d30644-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3066/flipper-devices-ปร-บแนวทางการพ-ฒนาเฟ-ร-มแวร-flipper-zero-โดยม-งเน-นการม-ส-วนร-วมของช-มชนน-กพ-ฒนา</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3066/flipper-devices-ปร-บแนวทางการพ-ฒนาเฟ-ร-มแวร-flipper-zero-โดยม-งเน-นการม-ส-วนร-วมของช-มชนน-กพ-ฒนา</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Tue, 07 Jul 2026 10:11:30 GMT</pubDate></item><item><title><![CDATA[CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก]]></title><description><![CDATA[<p dir="auto">เมื่อวันที่ 7 กรกฏาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้</p>
<ul>
<li>CISA Adds One Known Exploited Vulnerability to Catalog</li>
</ul>
<p dir="auto">ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต</p>
<p dir="auto"><strong>อ้างอิง</strong><br />
<a href="https://www.cisa.gov/news-events/alerts/2026/07/01/cisa-adds-one-known-exploited-vulnerability-catalog" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/alerts/2026/07/01/cisa-adds-one-known-exploited-vulnerability-catalog</a><br />
สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783413543785-7f3a27c4-343c-46c6-b80a-d9d4d696f308-image.png" alt="7f3a27c4-343c-46c6-b80a-d9d4d696f308-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3064/cisa-เพ-มช-องโหว-ท-ถ-กใช-โจมต-1-รายการลงในแคตตาล-อก</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3064/cisa-เพ-มช-องโหว-ท-ถ-กใช-โจมต-1-รายการลงในแคตตาล-อก</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Tue, 07 Jul 2026 08:39:04 GMT</pubDate></item><item><title><![CDATA[Cyber Threat Intelligence 07 July 2026]]></title><description><![CDATA[<p dir="auto"><strong>Financial Sector</strong></p>
<ul>
<li>The Future Of Payment Fraud Could Be Automated<br />
"Payment fraud is becoming more organized as criminal groups use fake websites, large-scale operations, and, in some cases, forced labor to steal money and personal information. Advances in agentic AI could automate many stages of payment fraud, from collecting and assembling stolen credentials to deploying password-cracking tools. CAPCO’s “US Payment Fraud Survey” found that consumers increasingly value fraud protection when choosing payment providers. Security was one of the most important factors for 63% of respondents, and 50% selected advanced fraud protection. Both ranked ahead of customer service, transaction speed, brand reputation, and rewards."<br />
<a href="https://www.helpnetsecurity.com/2026/07/06/key-payment-fraud-trends-report/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/06/key-payment-fraud-trends-report/</a></li>
</ul>
<p dir="auto"><strong>New Tooling</strong></p>
<ul>
<li><strong>Omnigent: Open-Source AI Agent Framework And Meta-Harness</strong><br />
"Plenty of developers now keep several coding agents close at hand, reaching for Claude Code on one task and Codex or Cursor on the next. Each tool arrives with its own command line, its own handling of credentials, and its own way of running shell commands against a working directory. That spread leaves teams with a governance gap around where agent actions land and how much they cost. Omnigent, an open-source project, sits one level above those tools as a meta-harness. The common layer drives Claude Code, Codex, Cursor, OpenCode, Hermes, Pi, and agents a team writes in YAML, and a user swaps or combines them with one-line changes."<br />
<a href="https://www.helpnetsecurity.com/2026/07/06/omnigent-open-source-ai-agent-framework/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/06/omnigent-open-source-ai-agent-framework/</a><br />
<a href="https://github.com/omnigent-ai/omnigent" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/omnigent-ai/omnigent</a></li>
</ul>
<p dir="auto"><strong>Vulnerabilities</strong></p>
<ul>
<li><strong>One Trigram At a Time: XSLeak Via Universal CSS Injection And DoS In Opera (GX)</strong><br />
"This paper focuses on a critical browser vulnerability discovered in Opera GX that allows cross-site data exfiltration simply by visiting an attacker-controlled website, without requiring any user interaction. By abusing the browser’s GX Mods feature, what initially appears to be a harmless customization mechanism can be turned into a universal CSS injection affecting every webpage visited by the user. As we will see, this makes it possible to build a practical XS-Leak capable of exfiltrating sensitive information from arbitrary websites. The same attack vector also enables a denial-of-service attack affecting both Opera GX and Opera."<br />
<a href="https://zhero-web-sec.github.io/research-and-things/one-trigram-at-a-time-xsleak-via-universal-css-injection-and-dos-in-opera-(gx)" target="_blank" rel="noopener noreferrer nofollow ugc">https://zhero-web-sec.github.io/research-and-things/one-trigram-at-a-time-xsleak-via-universal-css-injection-and-dos-in-opera-(gx)</a><br />
<a href="https://thehackernews.com/2026/07/opera-gx-flaw-let-malicious-sites-auto.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/opera-gx-flaw-let-malicious-sites-auto.html</a><br />
<a href="https://www.infosecurity-magazine.com/news/opera-gx-flaw-gx-mods-css/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/opera-gx-flaw-gx-mods-css/</a></li>
<li><strong>SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners With Self-Extracting Packing</strong><br />
"Scanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University of Science and Technology. Their strongest trick slipped past every scanner tested more than 90% of the time, and the same team built a runtime checker that catches most of the disguised skills the scanners miss."<br />
<a href="https://thehackernews.com/2026/07/new-skillcloak-technique-lets-malicious.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/new-skillcloak-technique-lets-malicious.html</a><br />
<a href="https://arxiv.org/abs/2607.02357" target="_blank" rel="noopener noreferrer nofollow ugc">https://arxiv.org/abs/2607.02357</a></li>
<li><strong>16-Year-Old Linux KVM Flaw Lets Guest VMs Escape To Host On Intel And AMD x86 Systems</strong><br />
"A use-after-free bug in Linux's KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it. Dubbed 'Januscape' and tracked as CVE-2026-53359, the flaw sits in the shadow MMU code that KVM shares across both Intel and AMD. The public proof-of-concept panics the host; the researcher claims that a separate, unreleased exploit turns the same bug into full host code execution. Security researcher Hyunwoo Kim (@v4bel) found and reported the bug. He described Januscape as the first guest-to-host exploit triggerable on both Intel and AMD, to the best of public knowledge. The flaw went unnoticed for roughly 16 years."<br />
<a href="https://thehackernews.com/2026/07/16-year-old-linux-kvm-flaw-lets-guest.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/16-year-old-linux-kvm-flaw-lets-guest.html</a><br />
<a href="https://github.com/V4bel/Januscape" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/V4bel/Januscape</a></li>
<li><strong>New TrojPix Attack Leaks Data From Air-Gapped Systems Via Video Cable Emissions</strong><br />
"Researchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, called TrojPix, tweaks on-screen pixels in ways the eye cannot see, so that the video cable carrying them radiates a faint radio signal a nearby receiver can decode. But TrojPix works only once malware is already on the target machine, so it is a way for stolen data to get out, not a way in. In the researchers' tests, TrojPix hit a peak throughput of 8.1 Mbps and reached as far as 208 meters, the two measured separately rather than together."<br />
<a href="https://thehackernews.com/2026/07/new-trojpix-attack-leaks-data-from-air.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/new-trojpix-attack-leaks-data-from-air.html</a></li>
</ul>
<p dir="auto"><strong>Malware</strong></p>
<ul>
<li><strong>Max Severity Adobe ColdFusion Flaw Now Exploited In Attacks</strong><br />
"Attackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, according to vulnerability intelligence company KEVIntel. ColdFusion is a commercial web app development platform designed to help build and deploy enterprise-grade websites. The CVE-2026-48282 security flaw affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by attackers without privileges to gain remote code execution on unpatched systems. Adobe released security updates on Tuesday to address the vulnerability, saying that it posed a high risk of exploitation and urging admins to deploy patches immediately."<br />
<a href="https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/</a><br />
<a href="https://securityaffairs.com/194837/hacking/adobe-coldfusion-flaw-cve-2026-48282-now-exploited-in-the-wild.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/194837/hacking/adobe-coldfusion-flaw-cve-2026-48282-now-exploited-in-the-wild.html</a></li>
<li><strong>Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure</strong><br />
"Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from the DevOps platform trusting the "X-WEBAUTH-USER" header from any source IP address, effectively allowing an unauthenticated internet client to get elevated access."<br />
<a href="https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html</a></li>
<li><strong>Phishing Poses As Big-Brand Job Interview To Steal Google Accounts</strong><br />
"A phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals. The operation is abusing the legitimate cloud-based PeopleForce human resources platform and a domain associated with the Salesforce Marketing Cloud service before redirecting the recipient to a malicious landing page. To further instill trust and increase the chances of success, the threat actor is using the names and pictures of real recruiters at impersonated companies."<br />
<a href="https://www.bleepingcomputer.com/news/security/phishing-poses-as-big-brand-job-interview-to-steal-google-accounts/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/phishing-poses-as-big-brand-job-interview-to-steal-google-accounts/</a><br />
<a href="https://gist.github.com/BushidoUK/57c38d5ee75481fb237e968a537de778" target="_blank" rel="noopener noreferrer nofollow ugc">https://gist.github.com/BushidoUK/57c38d5ee75481fb237e968a537de778</a></li>
<li><strong>Fake IT Support Calls On Microsoft Teams Push EtherRAT Malware</strong><br />
"Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks. The campaign, reported by Palo Alto Networks' Unit 42, combines phishing emails, Microsoft Teams voice calls, legitimate remote management tools, and a Node.js-based malware loader to compromise victims' computers. According to a report by Unit 42 posted on GitHub, the attack begins with a phishing email containing an "Employee Survey" lure and a malicious PDF attachment."<br />
<a href="https://www.bleepingcomputer.com/news/security/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware/</a><br />
<a href="https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-06-28-Fake-IT-support-abuses-Teams-to-deliver-EtherRAT.txt" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-06-28-Fake-IT-support-abuses-Teams-to-deliver-EtherRAT.txt</a></li>
<li><strong>Cavern Manticore: Exposing Iran-Linked Modular C2 Framework</strong><br />
"Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors. Cavern Manticore is an Iran MOIS (Ministry of Intelligence and Security)-linked actor, with links to the OilRig subgroup named Lyceum. The framework reflects a mature and adaptable toolset built around a shared .NET foundation, while using multiple compilation formats across different components, including .NET Framework, .NET Mixed-Mode C++/CLI, and .NET Native AOT. The compilation format itself becomes the anti-analysis layer that forces reverse engineers into multiple toolsets and metadata-reconstruction workflows."<br />
<a href="https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/" target="_blank" rel="noopener noreferrer nofollow ugc">https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/</a><br />
<a href="https://thehackernews.com/2026/07/iran-linked-hackers-use-new-cavern-c2.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/iran-linked-hackers-use-new-cavern-c2.html</a><br />
<a href="https://www.infosecurity-magazine.com/news/new-iran-hacking-group-targets/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/new-iran-hacking-group-targets/</a></li>
<li><strong>When Checking The URL Isn’t Enough: a Device Code Phishing Attack Via a Microsoft Website</strong><br />
"One of the most common pieces of anti-phishing advice is to double-check the website’s domain name before providing your credentials. Typically, a fraudulent domain stands out to the trained eye, differing from the official URL by at least a few characters. Recently, however, we encountered a campaign where attackers instruct victims to input data directly into a legitimate, trusted corporate site: the Microsoft Identity Platform, which supports an OAuth 2.0 specification known as the Device Authorization Grant."<br />
<a href="https://securelist.com/microsoft-device-code-phishing-attack/120350/" target="_blank" rel="noopener noreferrer nofollow ugc">https://securelist.com/microsoft-device-code-phishing-attack/120350/</a></li>
<li><strong>Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. Of India/MoF Tax Infrastructure Via Multi-Stage DcRAT Deployment</strong><br />
"Seqrite Lab actively tracks and analyse threat actors and their campaigns, focusing on attribution, infrastructure analysis, and adversary tradecraft. Throughout our research, we have attributed numerous operations to China-aligned threat clusters targeting both regional and international entities. As part of our latest investigation, we uncovered a campaign that demonstrates operational and technical similarities to a China-nexus threat cluster. Further analysis revealed overlapping TTPs with a prominent and highly active threat actor known for conducting cyber-espionage operations against Asian countries through the deployment of RAT-based malware."<br />
<a href="https://www.seqrite.com/blog/operation-dragonreturn-china-nexus-cyber-espionage-campaign-targeting-govt-of-india-mof-tax-infrastructure-via-multi-stage-dcrat-deployment/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.seqrite.com/blog/operation-dragonreturn-china-nexus-cyber-espionage-campaign-targeting-govt-of-india-mof-tax-infrastructure-via-multi-stage-dcrat-deployment/</a><br />
<a href="https://thehackernews.com/2026/07/suspected-china-nexus-hackers-use-fake.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/suspected-china-nexus-hackers-use-fake.html</a></li>
<li><strong>Novel Java-Based QuimaRAT Targets Windows, MacOS, And Linux</strong><br />
"Remote access trojans (RATs) are legacy threats that continue to evolve alongside an expanding and ever-changing threat landscape. Following our recently published articles about novel and notable RATs, including KarstoRAT, the latest version of ClickFix, and ClickFix’s macOS variant, we analyzed QuimaRAT, a novel Java-based RAT that targets Windows, Linux, and macOS environments and is currently being sold on the dark web as a subscription-based RAT platform."<br />
<a href="https://www.levelblue.com/blogs/spiderlabs-blog/novel-java-based-quimarat-targets-windows-macos-and-linux" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.levelblue.com/blogs/spiderlabs-blog/novel-java-based-quimarat-targets-windows-macos-and-linux</a><br />
<a href="https://thehackernews.com/2026/07/new-java-based-quimarat-maas-built-to.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/new-java-based-quimarat-maas-built-to.html</a></li>
<li><strong>Ukrainian Media Outlets Now Among 'priority Targets' For Russian Hackers</strong><br />
"Russia-linked hackers are increasingly targeting Ukrainian media organizations, local officials warned, as news outlets continue to face pressure not only from cyber operations but also Russia's ongoing military attacks. Ukraine's domestic security agency, the SBU, said media organizations have become "one of the priority targets" for Russian hackers. Previous attacks have primarily sought to disrupt broadcasts, spread propaganda and undermine public trust."<br />
<a href="https://therecord.media/ukraine-media-organizations-priority-hacking-targets-russia" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/ukraine-media-organizations-priority-hacking-targets-russia</a></li>
</ul>
<p dir="auto"><strong>Breaches/Hacks/Leaks</strong></p>
<ul>
<li><strong>US Army Websites Defaced With Pro-Kurdish Sentiments, Insults To Trump</strong><br />
"Multiple U.S. Army internet subdomains were defaced in a 404 hijacking campaign, CyberScoop has confirmed. As of Monday morning, error pages on two U.S. Army websites – oil.army.mil and ai2c.army.mil – displayed defacement messages visible to users. The messages denigrated President Donald Trump and United States Ambassador to Türkiye Tom Barrack, called to “FREE KURDISTAN,” And included another line reading “Kurdish sr was here.”"<br />
<a href="https://cyberscoop.com/us-army-websites-defaced-404-hijacking-kurdistan/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/us-army-websites-defaced-404-hijacking-kurdistan/</a></li>
</ul>
<p dir="auto"><strong>General News</strong></p>
<ul>
<li><strong>How To Prioritize AI Agent Security By Business Impact</strong><br />
"Your CEO calls about an AI agent security incident in finance. He wants to know whether money moved, whether financial data was exposed, who owned the agent and why it had this level of access. The agent was connected to a spend management application to reconcile invoices, summarize vendor contracts and flag unusual payment activity. The breakdown occurred when the employee who configured it left and the OAuth grant remained active, allowing the agent to continue accessing vendor banking details, contract terms and internal approval notes even though its ownership and business purpose had changed."<br />
<a href="https://www.helpnetsecurity.com/2026/07/06/prioritize-ai-agent-security-business-impact/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/06/prioritize-ai-agent-security-business-impact/</a></li>
<li><strong>OAuth, Guest Accounts, And Weak MFA Drive SaaS Risk</strong><br />
"Organizations often create guest accounts to give contractors, suppliers, and partners temporary access to files and SaaS applications. Many of these accounts remain active long after they are needed, creating overlooked access paths to corporate data. Guest accounts accounted for 69% of monitored SaaS accounts in 2025, an increase of more than 1.9 million compared with the previous year, according to Kaseya’s 2026 SaaS Security Report: Closing the Unmanaged Trust Gap."<br />
<a href="https://www.helpnetsecurity.com/2026/07/06/saas-environments-security-risks-report/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/06/saas-environments-security-risks-report/</a></li>
<li><strong>Finding Vulnerabilities Was Never The Hard Part</strong><br />
"I keep hearing the same frustration when I talk with security leaders. The real problem sitting on their desk isn’t finding vulnerabilities. It’s deciding which ones actually matter. The industry has spent billions on better visibility. We’ve convinced ourselves that if we could just discover more vulnerabilities, collect more data, and ingest more threat intelligence, we’d become more secure. But look around. Organizations still aren’t more secure. They’re just overwhelmed."<br />
<a href="https://cyberscoop.com/ai-cybersecurity-vulnerability-prioritization-op-ed/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/ai-cybersecurity-vulnerability-prioritization-op-ed/</a></li>
<li><strong>Mid-Year Threat Trends: What H1 2026 Signals For The Rest Of The Year</strong><br />
"The first half of 2026 has given security teams little room to breathe. Ransomware operators kept up a punishing pace. If that wasn’t enough, access brokers turned network intrusions into a marketplace, and nation-state activity blurred further into hacktivism and organized cybercrime. Taken together, the numbers point to a threat landscape that isn’t just growing louder; it’s becoming faster, more coordinated, and harder to attribute."<br />
<a href="https://cyble.com/blog/2026-threat-intelligence-trends/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyble.com/blog/2026-threat-intelligence-trends/</a></li>
<li><strong>It Might Feel Like We’ve Been Here Before, But We Haven’t</strong><br />
"As artificial intelligence (AI) adoption surges and organisations move from the ‘should we?’ phase to the ‘how do we?’ phase, it’s natural to evaluate the likelihood of positive returns on AI investments. That’s always been the case with the onset of each new technology paradigm: C-suite executives, guided by their boards and aided by technical and business teams, remain keenly focused on traditional metrics such as return on investment, shareholder equity, developing and extending competitive advantage, and ensuring superior customer relationships."<br />
<a href="https://www.paloaltonetworks.com/blog/2026/07/it-might-feel-like-weve-been-here-before-but-we-havent/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.paloaltonetworks.com/blog/2026/07/it-might-feel-like-weve-been-here-before-but-we-havent/</a><br />
<a href="https://www.paloaltonetworks.com/resources/ebooks/executive-edge-peer-insights-governing-ai-and-agentic-systems-at-enterprise-scale" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.paloaltonetworks.com/resources/ebooks/executive-edge-peer-insights-governing-ai-and-agentic-systems-at-enterprise-scale</a></li>
<li><strong>The Shift Toward Business-Aligned Risk Management</strong><br />
"In the movie Moneyball, the Oakland A’s didn’t need more data; they needed to know which data actually won games. Risk assessment data has the same problem. A CVSS score of 9.1 might mean little to a CFO; the fact that it represents a vulnerability in a payment system processing $2 million daily means a great deal. This data must therefore link to information about operational disruptions that can cause financial loss, product delays, or draw the ire of regulatory authorities, for it to become more actionable."<br />
<a href="https://www.securityweek.com/the-shift-toward-business-aligned-risk-management/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/the-shift-toward-business-aligned-risk-management/</a></li>
<li><strong>FBI And Spanish Police Arrest Alleged Cyber Army Of Russia Reborn Member</strong><br />
"Spanish police have arrested an alleged member of the pro-Russia hacktivist group Cyber Army of Russia Reborn, also known as Z-Pentest, in an operation carried out with support from the FBI. The arrest forms part of ongoing measures to identify and disrupt people involved in cyberattacks targeting critical infrastructure. The FBI confirmed that its Los Angeles field office worked with Spain’s National Police to coordinate the arrest. US authorities said the action falls under Operation Riptide, an international effort aimed at disrupting malicious cyber activity and holding those responsible accountable."<br />
<a href="https://hackread.com/fbi-spanish-police-arrest-cyber-army-russia-reborn-member/" target="_blank" rel="noopener noreferrer nofollow ugc">https://hackread.com/fbi-spanish-police-arrest-cyber-army-russia-reborn-member/</a></li>
</ul>
<p dir="auto"><strong>อ้างอิง</strong><br />
Electronic Transactions Development Agency (ETDA) <img src="/assets/uploads/files/1783413042150-8d2199e2-aa21-4aa7-af80-1150927cb657-image.png" alt="8d2199e2-aa21-4aa7-af80-1150927cb657-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3063/cyber-threat-intelligence-07-july-2026</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3063/cyber-threat-intelligence-07-july-2026</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Tue, 07 Jul 2026 08:30:43 GMT</pubDate></item><item><title><![CDATA[พบปฏิบัติการ JADEPUFFER ใช้ LLM Agent ดำเนินการโจมตีแรนซัมแวร์แบบอัตโนมัติ]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1783331321928-%E0%B8%9E%E0%B8%9A%E0%B8%9B%E0%B8%8F-%E0%B8%9A-%E0%B8%95-%E0%B8%81%E0%B8%B2%E0%B8%A3-jadepuffer-%E0%B9%83%E0%B8%8A-llm-agent-%E0%B8%94%E0%B8%B3%E0%B9%80%E0%B8%99-%E0%B8%99%E0%B8%81%E0%B8%B2%E0%B8%A3%E0%B9%82%E0%B8%88%E0%B8%A1%E0%B8%95-%E0%B9%81%E0%B8%A3%E0%B8%99.jpg" alt="พบปฏิบัติการ JADEPUFFER ใช้ LLM Agent ดำเนินการโจมตีแรน.jpg" class=" img-fluid img-markdown" /></p>
<p dir="auto">สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783331331005-38ec3089-ef68-4654-8114-1f798e16ea4c-image.png" alt="38ec3089-ef68-4654-8114-1f798e16ea4c-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3062/พบปฏ-บ-ต-การ-jadepuffer-ใช-llm-agent-ดำเน-นการโจมต-แรนซ-มแวร-แบบอ-ตโนม-ต</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3062/พบปฏ-บ-ต-การ-jadepuffer-ใช-llm-agent-ดำเน-นการโจมต-แรนซ-มแวร-แบบอ-ตโนม-ต</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Mon, 06 Jul 2026 09:48:57 GMT</pubDate></item><item><title><![CDATA[FBI เตือน TeamPCP เจาะเครื่องมือนักพัฒนา ขโมยข้อมูลรับรองคลาวด์และโจมตีแบบ Software Supply Chain]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1783331295568-fbi-%E0%B9%80%E0%B8%95-%E0%B8%AD%E0%B8%99-teampcp-%E0%B9%80%E0%B8%88%E0%B8%B2%E0%B8%B0%E0%B9%80%E0%B8%84%E0%B8%A3-%E0%B8%AD%E0%B8%87%E0%B8%A1-%E0%B8%AD%E0%B8%99-%E0%B8%81%E0%B8%9E-%E0%B8%92%E0%B8%99%E0%B8%B2-%E0%B8%82%E0%B9%82%E0%B8%A1%E0%B8%A2%E0%B8%82-%E0%B8%AD%E0%B8%A1.jpg" alt="FBI เตือน TeamPCP เจาะเครื่องมือนักพัฒนา ขโมยข้อม.jpg" class=" img-fluid img-markdown" /></p>
<p dir="auto">สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand <img src="/assets/uploads/files/1783331302631-eca84b7a-5312-4567-b866-b0ebdd91a139-image.png" alt="eca84b7a-5312-4567-b866-b0ebdd91a139-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3061/fbi-เต-อน-teampcp-เจาะเคร-องม-อน-กพ-ฒนา-ขโมยข-อม-ลร-บรองคลาวด-และโจมต-แบบ-software-supply-chain</link><guid isPermaLink="true">https://webboard-nsoc.ncsa.or.th/topic/3061/fbi-เต-อน-teampcp-เจาะเคร-องม-อน-กพ-ฒนา-ขโมยข-อม-ลร-บรองคลาวด-และโจมต-แบบ-software-supply-chain</guid><dc:creator><![CDATA[NCSA_THAICERT]]></dc:creator><pubDate>Mon, 06 Jul 2026 09:48:25 GMT</pubDate></item></channel></rss>