Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 15 รายการ เมื่อวันที่ 13 สิงหาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้
- ICSA-26-225-01 AVEVA Enterprise SCADA
- ICSA-26-225-02 Haiwell IoT Cloud HMI Gateway
- ICSA-26-225-03 Johnson Controls Inc. Airwall
- ICSA-26-225-04 Hitachi Energy APM Edge Product
- ICSA-26-225-05 ANDRITZ HIPASE-250 and 250 SCALA
- ICSA-26-225-06 Siemens RUGGEDCOM APE1808
- ICSA-26-225-07 Siemens License Server (SLS)
- ICSA-26-225-08 Siemens Desigo DXR and PXC Controllers
- ICSA-26-225-09 Siemens Siveillance Video
- ICSA-26-225-10 Siemens Parasolid
- ICSA-26-225-11 Siemens Simcenter Femap
- ICSA-26-225-12 Siemens Solid Edge
- ICSA-26-225-13 Siemens LOGO! Soft Comfort
- ICSA-26-225-14 Johnson Controls Metasys
- ICSMA-26-225-01 Flow Neuroscience FL-100
CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)
อ้างอิง
https://www.cisa.gov/news-events/ics-advisories
สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 













(CTU) researchers investigated a June 2026 campaign in which threat actors used the Deno JavaScript runtime as a core execution mechanism within a ClickFix-driven intrusion chain. On June 3 and June 4, compromised WordPress sites served Cloudflare-themed ClickFix lures that prompted users to execute a clipboard-delivered PowerShell command. This command initiated an MSI-based staging process that installed Deno and enabled retrieval and execution of remote JavaScript. CTU
