ข้อมูลกลุ่ม ส่วนตัว

administrators

  • เตือนผู้ใช้ iPhone อัปเดต iOS และ WhatsApp หลังพบกรณีบัญชีถูกใช้ส่งข้อความผิดปกติ

    เตือนผู้ใช้ iPhone อัปเดต iOS และ WhatsApp หลังพบกรณีบัญชีถูกใช้ส่งข้อความผิดปกติ.png

    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand eb3997c6-7292-42ab-9ec3-0646675c69d6-image.png

    โพสต์ใน Cyber Security News
  • พบการโจมตีช่องโหว่ SQL Injection ใน Ghost CMS ถูกใช้ฝังสคริปต์อันตรายผ่านแคมเปญ ClickFix

    พบการโจมตีช่องโหว่ SQL Injection ใน Ghost CMS ถูกใช้ฝังสคริปต์อันตรายผ่านแคมเปญ ClickFix.png

    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 3b3ac074-c471-4c3b-a857-9ec952207052-image.png

    โพสต์ใน Cyber Security News
  • แนวโน้มแรนซัมแวร์ปี 2026 เปลี่ยนรูปแบบสู่การขโมยข้อมูลเพื่อรีดไถ โดยไม่เข้ารหัสระบบแล้ว

    แนวโน้มแรนซัมแวร์ปี 2026 เปลี่ยนรูปแบบสู่การขโมยข้อมูลเพื่อรีดไถ โดยไม่เข้ารหัสระบบแล้ว.png

    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e60ca4a0-a52d-42a4-88a2-6acc870e3fb3-image.png

    โพสต์ใน Cyber Security News
  • Cyber Threat Intelligence 26 May 2026

    New Tooling

    • OpenHack: Open-Source AI-Powered Vulnerability Research
      "Source-guided vulnerability research increasingly leans on coding harnesses such as Claude Code, Codex, and Cursor to drive agent-based reviews of application code. A new MIT-licensed project from the Dutch security firm Hadrian, called OpenHack, packages that approach into a file-based workspace that any of those harnesses can run. OpenHack is a set of agents and tools that mimics how Hadrian’s research team performs automated vulnerability research. The workflow runs inside a coding harness or a custom runner, with durable state kept in plain files such as cloned source, recon items, scenario prompts, scenario results, finding candidates, triage decisions, findings, and logs. The harness supplies model execution, terminal access, repository access, and human-in-the-loop approval."
      https://www.helpnetsecurity.com/2026/05/25/openhack-open-source-ai-powered-vulnerability-research/
      https://github.com/hadriansecurity/openhack

    Malware

    • RemotePE: The Lazarus RAT That Lives In Memory
      "Last year, we published research1 about a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations, encountered during multiple incident response engagements. This Lazarus subgroup overlaps with activity linked to AppleJeus2, Citrine Sleet3, UNC47364, and Gleaming Pisces5. In one investigation, we observed that the actor had replaced ThemeForestRAT and PondRAT with a more sophisticated memory-only toolset. This follow-up post covers all three malware families from that toolset: DPAPILoader, RemotePELoader and RemotePE."
      https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/
      https://thehackernews.com/2026/05/lazarus-deploys-remotepe-memory-only.html
      TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages And Hundreds Of Versions Across Npm, PyPI, And Crates.io
      "Socket researchers have identified an active crypto stealer supply chain attack spanning npm, PyPI, and Crates.io. The campaign, which Socket is tracking as TrapDoor, spans more than 34 malicious packages and 384+ related versions and artifacts across npm, PyPI, and Crates.io, with some already removed and others still live at the time of writing. The earliest package Socket observed was the PyPI package [email protected], uploaded on May 22, 2026 at 20:20:18 UTC, with the wheel published at 20:22:04 UTC. The packages were then published in waves by a handful of accounts and actively updated throughout the weekend."
      https://socket.dev/blog/trapdoor-crypto-stealer-npm-pypi-crates
      https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html
    • Zero-Click WhatsApp Account Takeover Hits iPhone Users Running iOS 16. No Linked Devices, No Warning
      "There is a particular kind of security incident that is harder to explain than most: your WhatsApp account is sending messages you did not write, asking your contacts for money transfers, and when you check the “Linked Devices” section in the app, it shows nothing. No unauthorized sessions, no suspicious logins, no QR codes scanned by mistake. Just your phone, your account, and someone else apparently using it at the same time. That is exactly what happened to multiple iPhone users in Italy over the past few weeks, and the forensic investigation that followed has uncovered what appears to be an active zero-click exploitation campaign targeting a specific combination of iOS version and WhatsApp client."
      https://securityaffairs.com/192627/security/zero-click-whatsapp-account-takeover-hits-iphone-users-running-ios-16-no-linked-devices-no-warning.html

    Breaches/Hacks/Leaks

    • Hacker Selling 340 Million OnlyFans User Records Built From Old Breaches
      "A threat actor is advertising what they describe as a massive database containing information linked to hundreds of millions of OnlyFans users, including creators and subscribers. However, conversations with the seller and a review of sample data suggest that the collection did not result from a direct breach or scraping of OnlyFans systems. The listing appeared earlier this week on a well-known cybercrime forum, where a user operating under the alias “Euphoric_Reply_5727” offered what they described as “340 Million User Records” linked to OnlyFans users. The seller priced the database at 0.313 BTC, roughly $76,000 at the time of writing."
      https://hackread.com/hacker-selling-onlyfans-user-records-old-breaches/
      https://securityaffairs.com/192643/cyber-crime/340-million-onlyfans-profiles-allegedly-rebuilt-from-leaks.html
    • Oncology Institute Discloses Data Breach
      "The Oncology Institute says a previously disclosed cybersecurity incident has been confirmed to impact patient information. The Oncology Institute (TOI) is an oncology provider founded in 2007 that delivers specialized cancer care through a network of over 100 clinics across five states. The healthcare organization told the SEC in November 2025 that it had learned of a cybersecurity incident affecting a third-party software services provider. At the time, the vendor’s investigation was ongoing and it could not say whether patient information had been compromised."
      https://www.securityweek.com/oncology-institute-discloses-third-party-data-breach/
    • 266,000 Affected By Data Breach At Radiology Associates Of Richmond
      "Radiology Associates of Richmond (RAR) has disclosed a data breach impacting the protected health information of 266,000 individuals. According to the healthcare organization’s incident notice, the data breach occurred on or about July 25, 2025, when hackers accessed its internal systems. RAR did not say when the intrusion was discovered, but said that it worked with external cybersecurity experts to contain the attack and investigate its scope."
      https://www.securityweek.com/266000-affected-by-data-breach-at-radiology-associates-of-richmond/
    • DocketWise Data Breach Impacts 143,000
      "Immigration and legal case management platform DocketWise is notifying over 143,000 people that their personal, financial, and medical information was compromised in a data breach. The incident, the company says, involved third-party partner repositories that a threat actor cloned using valid credentials. DocketWise launched an investigation into the matter in October 2025, and this year determined that some of the cloned repositories were used as a data migration pipeline for the DocketWise application, which contains law firm records, including personally identifiable information (PII)."
      https://www.securityweek.com/docketwise-data-breach-impacts-143000/

    General News

    • Turns Out The C-Suite Loves Shadow AI
      "Senior decision-makers are the heaviest users of unapproved AI tools, and they continue using them despite being aware of the security and privacy risks linked to shadow AI, according to TrustedTech’s Shadow AI in the Workplace report. The study found that 65% of decision-makers use shadow AI, compared with 31% of employees below decision-maker level. The data suggests that shadow AI is not mainly driven by junior employees experimenting with consumer tools. The people creating policies and overseeing teams appear to be some of the most active users of unapproved AI systems."
      https://www.helpnetsecurity.com/2026/05/25/trustedtech-workplace-shadow-ai-use-report/

    อ้างอิง
    Electronic Transactions Development Agency (ETDA) 98404978-f658-4324-86c0-6150496ea5a3-image.png

    โพสต์ใน Cyber Security News
  • 🚨เร่งตรวจสอบ! Trend Micro ออกแพตช์แก้ไขช่องโหว่ Apex One หลังพบการโจมตีจริง

    ศูนย์ประสานการรักษาความมั่นคงปลอดภัยระบบคอมพิวเตอร์แห่งชาติ (ThaiCERT) ได้ติดตามรายงานการออกอัปเดตความปลอดภัยของ Trend Micro สำหรับผลิตภัณฑ์ Apex One และ Vision One Standard Endpoint Protection (SEP) หลังพบหลายช่องโหว่ในระบบ Endpoint Security โดยมีช่องโหว่ CVE-2026-34926 ที่ได้รับการยืนยันว่าพบความพยายามนำไปใช้โจมตีจริงแล้ว ผู้ใช้งานและผู้ดูแลระบบควรเร่งตรวจสอบเวอร์ชันและดำเนินการอัปเดตโดยเร็ว[1][2]

    1. รายละเอียดช่องโหว่
      ช่องโหว่ CVE-2026-34926 (CVSS V3.1: 6.7)[3] เป็นช่องโหว่ Directory Traversal ใน Trend Micro Apex One แบบ On-Premise ซึ่งอาจเปิดโอกาสให้ผู้โจมตีที่สามารถเข้าถึงเซิร์ฟเวอร์และมีบัญชีระดับผู้ดูแลระบบอยู่ก่อนแล้ว แก้ไขข้อมูลสำคัญบนเซิร์ฟเวอร์เพื่อฝังโค้ดอันตรายและกระจายไปยัง Agent ภายในองค์กรได้ ช่องโหว่มีความเสี่ยงสูงในเชิงปฏิบัติ เนื่องจาก Apex One Server เป็นระบบบริหารจัดการ Endpoint Security ที่มีความน่าเชื่อถือสูงภายในองค์กร หากถูกยึดหรือถูกแก้ไข อาจถูกใช้เป็นช่องทางกระจาย payload ไปยังเครื่องลูกข่ายจำนวนมากได้

    2. ผลิตภัณฑ์และเวอร์ชันที่ได้รับผลกระทบ
      2.1 Trend Micro Apex One 2019 on-premise: Server Agent build ต่ำกว่า 17079
      2.2 Trend Micro Apex One as a Service: Agent build ต่ำกว่า 14.0.20731
      2.3 Trend Vision One Endpoint Security – SEP: Agent build ต่ำกว่า 14.0.20731

    3. แนวทางการป้องกันและแก้ไข
      3.1 อัปเดต Apex One on-premise เป็น SP1 CP Build 18012 หรือเวอร์ชันที่ผู้ผลิตแนะนำ
      3.2 ตรวจสอบให้ Security Agent เป็น build ที่ได้รับการแก้ไขแล้ว
      3.3 จำกัดการเข้าถึง Apex One Server เฉพาะเครือข่ายที่เชื่อถือได้
      3.4 ตรวจสอบบัญชีผู้ดูแลระบบ และเฝ้าระวัง Log ที่เกี่ยวข้อง

    4. กรณีไม่สามารถอัปเดตได้ทันที
      4.1 ปิดการเข้าถึงระบบบริหารจัดการจากอินเทอร์เน็ตโดยตรง
      4.2 บังคับใช้งาน VPN/MFA สำหรับการเข้าถึงจากระยะไกล
      4.3 จำกัดสิทธิ์ผู้ดูแลระบบเท่าที่จำเป็น
      4.4 เพิ่มการตรวจสอบ Log, Alert และการเปลี่ยนแปลงบน Apex One Server
      4.5 วางแผนอัปเดตในช่วงเวลาที่กระทบระบบงานน้อยที่สุดค่าที่ถูกแก้ไขโดยไม่ได้รับอนุญาต

    Trend Micro2.png

    1. แหล่งอ้างอิง
      [1] https://dg.th/brhdvu45e0
      [2] https://dg.th/bmuyg0k5vq
      [3] https://dg.th/fvh4oziwyk
    โพสต์ใน Cyber Security News
  • พบ RondoDox Botnet ใช้ช่องโหว่เก่าโจมตี ASUS Router ที่ยังไม่อัปเดต

    พบ RondoDox Botnet ใช้ช่องโหว่เก่าโจมตี ASUS Router ที่ยังไม่อัปเดต.png

    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand bb3a09f5-03b7-4b22-97ee-bf4adb4a650c-image.png

    โพสต์ใน Cyber Security News
  • Anthropic เผย Claude Mythos AI ช่วยค้นพบช่องโหว่กว่า 10,000 รายการในซอฟต์แวร์สำคัญทั่วโลก

    Anthropic เผย Claude Mythos AI ช่วยค้นพบช่องโหว่กว่า 10,000 รายการในซอฟต์แวร์สำคัญทั่วโลก.png

    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 904c8cdb-83b1-407d-b1e1-f44db4440fb9-image.png

    โพสต์ใน Cyber Security News
  • พบการโจมตีช่องโหว่ SQL Injection ระดับวิกฤต (CVE-2026-9082) ในระบบจัดการเนื้อหา Drupal

    พบการโจมตีช่องโหว่ SQL Injection ระดับวิกฤต (CVE-2026-9082) ในระบบจัดการเนื้อหา Drupal.png

    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand f7d399dd-10ae-4fbb-8451-d4d9bbb7224d-image.png

    โพสต์ใน Cyber Security News
  • Cyber Threat Intelligence 25 May 2026

    Financial Sector

    • April 2026 Security Issues In Korean & Global Financial Sector
      "attack Stage 1 Phishing, Attack Stage 2 Backdoor-Downloader-Dropper, and Attack Stage 3 Infostealer-Ransomware were identified as the top malware in the financial sector. The actual distribution files were identified based on MD5 Hash, and it was explained that there may be many variants of the same family."
      https://asec.ahnlab.com/en/93805/

    Vulnerabilities

    Malware

    • RondoDox Botnet Exploits 2018 Flaw In Asus Routers
      "Operators behind a botnet picked up on a nearly decade-old flaw in Asus routers allowing an unauthenticated attacker to achieve remote code execution as a root user. Researchers at VulnCheck flagged in-the-wild exploitation of CVE-2018-5999, a critical flaw carrying a 9.8 CVSS score, to the RondoDox botnet. The botnet, which surfaced in mid-2025 and focuses on Linux systems, is often classed as a variant of the Mirai botnet. "Unlike Mirai, this malware’s sole purpose is to execute DoS attacks, while Mirai is not only capable of doing DoS attacks but also scan and exploit other systems," wrote Bitsight in March."
      https://www.bankinfosecurity.com/rondodox-botnet-exploits-2018-flaw-in-asus-routers-a-31768
      https://hackread.com/rondodox-botnet-2018-vulnerability-hijack-asus-routers/
    • Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns
      "Unit 42 researchers have observed evidence of cyberattacks by the Iran-nexus advanced persistent threat (APT) group Screening Serpens (aka UNC1549, Smoke Sandstorm and Iranian Dream Job). Based on our visibility, we believe that the group targeted entities in the U.S., Israel and the United Arab Emirates, and likely two additional Middle Eastern entities. This research follows an evolution through cyberattacks in mid-February through April 2026. The timing of these campaigns aligns closely with that of the regional conflict that started in the Middle East on Feb. 28, 2026. We discovered six new remote access Trojan (RAT) variants developed and deployed between February and April 2026."
      https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/
      https://www.bankinfosecurity.com/iranian-hackers-using-fake-job-sites-to-breach-defense-firms-a-31762
    • Megalodon: Mass GitHub Repo Backdooring Via CI Workflows
      "On May 18, 2026, an automated campaign codenamed megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories in a six-hour window. Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected GitHub Actions workflows containing base64-encoded bash payloads that exfiltrate CI secrets, cloud credentials, SSH keys, OIDC tokens, and source code secrets to a C2 server at 216[.]126[.]225[.]129:8443. The campaign deployed two payload variants. The mass variant (SysDiag) adds a new workflow triggered on every push and pull request, maximizing automated execution. A targeted variant (Optimize-Build) replaced existing workflows with workflow_dispatch triggers, creating dormant backdoors that the attacker can fire on demand via the GitHub API. The npm package @tiledesk/tiledesk-server versions 2.18.6 through 2.18.12 carry the targeted variant, propagated to npm through routine publishes by the legitimate maintainer from the compromised GitHub repository."
      https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/
      https://thehackernews.com/2026/05/megalodon-github-attack-targets-5561.html
      https://hackread.com/github-repositories-megalodon-supply-chain-attack/
      https://www.theregister.com/security/2026/05/22/megalodon-chums-the-waters-in-55k-github-repo-poisonings/5245342
    • SEO Poisoning Campaign Leverages Gemini And Claude Code Impersonation To Deliver Infostealer
      "Financially motivated eCrime actors will likely continue to expand opportunistic campaigns by impersonating AI platforms. These campaigns generate direct supply chain risk for enterprises, as threat actors target software developer tooling, including AI coding assistants and package managers, to compromise developer workstations. In early March 2026, EclecticIQ analysts identified an ongoing infostealer campaign targeting Gemini CLI and Claude Code users. Threat actors use SEO poisoning to surface fake domains above legitimate results, directing victims to attacker-controlled infrastructure that mimics genuine AI agent installation pages."
      https://blog.eclecticiq.com/seo-poisoning-campaign-leverages-gemini-and-claude-code-impersonation-to-deliver-infostealer
      https://www.infosecurity-magazine.com/news/gemini-claude-infostealers-seo/
    • Ghostwriter Targets Ukraine Government Entities With Prometheus Phishing Malware
      "The Belarus-aligned threat actor known as Ghostwriter (aka UAC-0057 and UNC1151Ukraine's National Security and Defense Council) has been observed using lures related to Prometheus, a Ukrainian online learning platform, to target government organizations in the country. The activity, per the Computer Emergency Response Team of Ukraine (CERT-UA), involves sending phishing emails to government entities using compromised accounts. It's been active since the spring of 2026."
      https://thehackernews.com/2026/05/ghostwriter-targets-ukraine-government.html
      https://therecord.media/oysterfresh-belarus-linked-campaign-targets-ukraine
      https://securityaffairs.com/192538/apt/ghostwriter-is-back-using-a-ukrainian-learning-platform-as-bait-to-hit-government-targets.html
    • FBI Warns Of Kali365 Phishing-As-a-Service After April Microsoft 365 Attacks
      "Cybercriminals are using a new, easy-to-use service to trick people into giving them access to their Microsoft 365 accounts, according to the FBI. The law enforcement agency published an advisory on Thursday about Kali365 — a Telegram-based service for cybercriminals that allows them to capture legitimate "OAuth" tokens enabling widespread access to Microsoft 365 environments. Multiple cybersecurity companies warned last month that they were seeing hundreds of attacks enabled by Kali365. The tool, which the FBI referred to as a Phishing-as-a-Service platform, “lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities.”"
      https://therecord.media/fbi-warns-of-kali365-phishing-attacks
      https://www.ic3.gov/PSA/2026/PSA260521
      https://cyberscoop.com/fbi-phishing-kali365-microsoft365-access-tokens/
      https://hackread.com/fbi-kali365-phishing-service-microsoft-365-account/
      https://www.helpnetsecurity.com/2026/05/22/kali365-microsoft-365-phishing-fbi-warning/
    • Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware
      "Void Dokkaebi, also tracked as Famous Chollima, is a North Korea-aligned intrusion set that systematically targets software developers who hold cryptocurrency wallet credentials, signing keys, and access to continuous integration/continuous delivery (CI/CD) pipelines and production infrastructure. As previously documented by TrendAI™ Research, the group poses as recruiters from cryptocurrency and AI firms, luring developers into cloning and executing code repositories as part of fabricated job interviews. TrendAI™ Research observed that InvisibleFerret, a Python-based malware family composed of multiple modules and delivered through the infection chain, has been obfuscated using Cython."
      https://www.trendmicro.com/en_us/research/26/e/analyzing-void-dokkaebi-invisibleferret-malware.html
    • Paved With Intent: ROADtools And Nation-State Tactics In The Cloud
      "ROADtools is an open-source framework written in Python and built for red-teaming and research. It primarily targets the identity and authentication layers of Azure, and focuses on how accounts, applications and tokens operate in tenants. To avoid detection, ROADtools operates through legitimate Microsoft APIs and can mimic typical traffic. Further defense evasion can be achieved by configuring request attributes such as user-agent strings. These capabilities have made ROADtools a valuable asset for attackers. Nation-state threat actors have used it in recent cloud intrusions for discovery, persistence and defense evasion. Attackers involved in a targeted phishing campaign in early 2025 used tooling that matches ROADtools' token management capabilities."
      https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/
    • A New SonicWall Scanning Spike Echoes The Pattern That Preceded CVE-2026-0400
      "Between May 9 and May 18, 2026, GreyNoise observed a significant new spike in scanning of SonicWall SonicOS management interfaces. The May 12 peak — approximately 597,000 sessions — was the largest single-day total recorded on the SonicWall SonicOS API Scanner tag in the past 90 days, roughly 46× the typical daily volume for this tag in the 30 days before the elevation. Similar elevations in activity against this GreyNoise tag have preceded new vulnerability disclosures affecting SonicWall (Ten Days Before Zero, GreyNoise 2026). Activity on this tag spiked three times in an earlier sequence — on January 18, January 30, and February 14 — at 37, 25, and 10 days before the February 24 disclosure of CVE-2026-0400. The current spike may be a similar early warning."
      https://www.greynoise.io/blog/sonicwall-scanning-spike-echoes-pattern-preceded-cve-2026-0400
    • Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten To Steal CI Secrets
      "On May 22, 2026, an attacker with push access to the Laravel-Lang GitHub organization rewrote every git tag across multiple popular Composer packages within a single 15 minute window. Anyone running composer update or installing fresh against laravel-lang/http-statuses, laravel-lang/actions, or laravel-lang/attributes now pulls a payload that exfiltrates CI secrets to a typosquatted attacker domain. StepSecurity confirmed end to end exploitation in an isolated runner and has filed security issues in all four repositories."
      https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack
      https://socket.dev/blog/laravel-lang-compromise
      https://www.aikido.dev/blog/supply-chain-attack-targets-laravel-lang-packages-with-credential-stealer
      https://www.bleepingcomputer.com/news/security/laravel-lang-packages-hijacked-to-deploy-credential-stealing-malware/
      https://thehackernews.com/2026/05/laravel-lang-php-packages-compromised.html
    • Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist And Node.js Projects
      "Socket researchers identified a coordinated supply chain campaign affecting eight packages on Packagist whose upstream repositories were modified to include the same malicious postinstall script. The script attempted to download a Linux binary from a GitHub Releases URL, save it to /tmp/.sshd, make it executable, and run it in the background. Although the affected packages were all Composer packages, the malicious code was not added to composer.json. Instead, it was inserted into package.json, targeting projects that ship JavaScript build tooling alongside PHP code. That cross-ecosystem placement is notable because developers and security teams reviewing PHP dependencies may focus on Composer metadata while overlooking package.json lifecycle hooks bundled inside the package."
      https://socket.dev/blog/malicious-postinstall-hook-found-across-700-github-repos
      https://thehackernews.com/2026/05/packagist-supply-chain-attack-infects-8.html
    • Foul Play: Fake FIFA Websites Target Soccer Fans Looking For World Cup Tickets, Merchandise
      "As the FIFA World Cup 2026™ in the United States, Canada, and Mexico draws closer, anticipation is building toward fever pitch. Many soccer fans may still be hunting for tickets, merchandise, travel and hospitality packages – and scammers know exactly how to exploit this demand. In other words, many people are already in the state of mind that scammers count on: interested, impatient and, indeed, maybe a little worried that the tickets or other goods will sell out. Which is ultimately what makes these scams so effective."
      https://www.welivesecurity.com/en/cybersecurity/foul-play-fake-fifa-world-cup-websites-tickets/
    • Ghost CMS SQL Injection Flaw Exploited In Large-Scale ClickFix Campaign
      "A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows. The campaign was discovered by XLab threat intelligence researchers at Chinese cybersecurity company Qianxin, who confirmed impact on more than 700 domains, including university portals, AI/SaaS companies, media outlets, fintech firms, security sites, and personal blogs. According to the researchers, threat actors planted malicious code on the websites of Harvard University, Oxford University, Auburn University, and DuckDuckGo."
      https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/

    Breaches/Hacks/Leaks

    • FBI Director’s Former Apparel Brand Hit By Malware
      "Two months after Iran-linked hackers exfiltrated FBI Director Kash Patel's personal email inbox, the government official's name is tangled up in another cyber incident - this time through a MAGA swag shop he founded. A ClickFix attack on the Based Apparel site tried to trick shoppers into running a malicious command though a fake Cloudflare verification page on Thursday. The entire merchandise shop has been taken offline Friday."
      https://www.bankinfosecurity.com/fbi-directors-former-apparel-brand-hit-by-malware-a-31767
    • Hackers Steal Patient And Billing Data From German Hospitals Via Third-Party Provider
      "German university hospitals are grappling with a large-scale patient data breach after unknown hackers targeted an external billing service provider used by medical centers across the country, according to statements from several affected medical institutions. The attack reportedly hit Unimed, a company that handles billing services for privately insured and self-paying patients on behalf of numerous German hospitals. Hospitals said the breach did not compromise their own clinical infrastructure or disrupt patient treatment."
      https://therecord.media/hackers-steal-patient-billing-data-german-hospitals
    • Techie Claims Trump Mobile Website Was Leaking Thousands Of People's Data
      "The US President’s oft-maligned Trump Mobile venture may be facing another setback after a security buff claims he discovered a now-plugged website vulnerability that he says was leaking what could be tens of thousands of suckers' customers' details. The individual behind the discovery, who goes by "Louis," says he's a self-taught tech tinkerer and described himself as "just a nerd between jobs with too much time on my hands." He reckons the website’s data could be scooped up with a simple POST request."
      https://www.theregister.com/security/2026/05/22/trump-mobile-site-leaks-customer-data-as-phone-finally-ships/5244828

    General News

    • The Proliferation And Evolution Of AI-Powered Hacking Tools – From Dark Web Distribution To Autonomous Attacks
      "since the emergence of WormGPT in June 2023, AI-based hacking tools have spread to the dark web, Telegram, GitHub, and Hugging Face. the market has evolved into a mix of paid subscription SaaS and free open-source distributions. key capabilities have been segmented into phishing automation, malware development, reconnaissance, brute force, vulnerability exploitation, and social engineering."
      https://asec.ahnlab.com/en/93816/
    • Netherlands Seizes 800 Servers Of Hosting Firm Enabling Cyberattacks
      "Financial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled cyberattacks, interference operations, and disinformation campaigns. FIOD arrested a 57-year-old suspect, who was the company director, and a 39-year-old who headed a separate firm that provided internet connectivity. According to the authorities, the suspects indirectly provided economic resources to Russian and Belarusian entities sanctioned by the European Union (EU)."
      https://www.bleepingcomputer.com/news/security/netherlands-seizes-800-servers-of-hosting-firm-enabling-cyberattacks/
    • Former US Execs Plead Guilty To Aiding Tech Support Scammers
      "Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide. Former CEO Adam Young (from Miami, Florida) and former CSO Harrison Gevirtz (from Las Vegas, Nevada) admitted to a misprision of a felony charge, which carries a maximum penalty of three years in federal prison, a fine of up to $250,000, or both, and are scheduled for sentencing on June 16."
      https://www.bleepingcomputer.com/news/security/former-us-execs-plead-guilty-to-aiding-tech-support-scammers/
    • When The Scanner Starts Thinking: Learnings From Mythos & GPT 5.5 Cyber In Security Testing
      "Frontier AI models like Anthropic Mythos and OpenAI GPT 5.5 Cyber present a critical inflection point for enterprise security. While they unlock transformative potential for security engineers seeking to embed AI into their workflows, they also expand the attack surface for organizations facing increasingly sophisticated attacks when used by threat actors. Mythos and GPT 5.5 Cyber do something fundamentally different from previous models. They reason across attack paths, weigh exploitability, and generate security-relevant workflows. The threat chain remains the same. Attackers will continue to find what’s exposed, break in through a weak point, move laterally, and steal data. What’s changed is the expertise required, speed, and scale."
      https://www.zscaler.com/blogs/security-research/when-scanner-starts-thinking-learnings-mythos-gpt-5-5-cyber-security
    • AI Attacks Are No Longer Experimental: Key Findings From The March-April 2026 AI Threat Landscape
      "Between late December 2025 and mid-February 2026, Gambit found that a single operator compromised nine Mexican government agencies, reaching tax records, civil registry data, patient files, and electoral infrastructure across a two-month campaign. What made it remarkable was not the scope but the method: the attacker ran the entire operation with commercial AI handling the exploitation work, and researchers only discovered what had happened after recovering materials from attacker-controlled servers. AI was not a productivity tool running in the background. It was the operational core of the attack."
      https://blog.checkpoint.com/research/ai-attacks-are-no-longer-experimental-key-findings-from-the-march-april-2026-ai-threat-landscape/
    • Downtime Has Become a $600 Billion Business Problem
      "The average cost of downtime has reached $600 billion for the Global 2000, a 50% increase in two years. According to Splunk’s The Hidden Costs of Downtime report, unplanned outages and service degradation cost each company an average of $300 million. Delayed product launches, brand damage, and stock declines continue to affect companies after systems return online. Customer expectations, cybersecurity threats, rising incident costs, and regulatory pressure have made downtime a priority for technology leaders."
      https://www.helpnetsecurity.com/2026/05/22/splunk-average-downtime-cost-report/
    • The New Economics Of Fraud: Cheaper, Faster, More Convincing
      "Scams have become one of the fastest-growing consumer risks, driven by AI-enabled impersonation, social engineering, and sophisticated attack methods, according to Visa’s Spring 2026 Biannual Threats Report. Fraud involves behavioral manipulation, fragmented ecosystems, and faster attack cycles that use AI to pressure people into authorizing payments themselves. The payments ecosystem continues to strengthen core defenses. Token fraud declined 9.6% and enumeration losses fell 16% from July through December 2025 compared with the same period in 2024. Improvements in tokenization, authentication, and network-level detection contributed to those results."
      https://www.helpnetsecurity.com/2026/05/22/visa-consumer-payment-fraud-report/
    • Cloud Atlas Activity In The Second Half Of 2025 And Early 2026: New Tools And a New Payload
      "In 2025, we observed pervasive SSH tunnel activity, which has remained active into 2026, affecting many government organizations and commercial companies in Russia and Belarus. Behind some of this activity is Cloud Atlas, a group we have known since 2014. During our investigation, we identified new tools used by this group, as well as indicators of compromise. The group is back to sending out archives containing malicious shortcuts that launch PowerShell scripts. This technique is employed in addition to the previously described use of malicious documents, which exploit an old vulnerability in the Microsoft Office Equation Editor process (CVE-2018-0802) to download and execute malicious code. We have observed the use of third-party public utilities (Tor/SSH/RevSocks) to gain a foothold in infected systems and create additional backup control channels."
      https://securelist.com/cloud-atlas-2026/119895/
    • Italy Disrupts CINEMAGOAL Piracy App That Stole Streaming Auth Codes
      "Italian authorities have dismantled a piracy ecosystem centered around the CINEMAGOAL app that provided access to various streaming platforms, including Netflix, Disney+, and Spotify. Unlike typical IPTV service providers that openly market themselves online and expose their operations, CINEMAGOAL's approach was stealthier, as it used an app that customers installed on their devices. During the large-scale anti-piracy operation called “Tutto Chiaro” (All Clear), Italian law enforcement conducted 100 searches across the country and seized materials that could help investigators identify involved individuals, as well as determine the amount of illegal profits."
      https://www.bleepingcomputer.com/news/legal/italy-disrupts-cinemagoal-piracy-app-that-stole-streaming-auth-codes/
      Why Pure Extortion Is Replacing Traditional Ransomware
      "Ransomware groups are quietly changing strategy in 2026. Instead of encrypting systems and causing immediate disruption, many attackers are now focusing on pure extortion: stealing sensitive data and threatening to leak it publicly if victims refuse to pay. This shift is happening for a simple reason. Encryption is noisy, risky, and easier for defenders to detect. Data theft is often faster, quieter, and in many cases more profitable. Several recent reports suggest attackers are increasingly prioritizing credential theft, long-term access, and exfiltration over traditional ransomware deployment. The pressure point is changing too. Companies are no longer paying just to restore operations, they are paying to avoid reputational damage, regulatory fallout, and exposure of sensitive internal documents."
      https://securityaffairs.com/192550/cyber-crime/why-pure-extortion-is-replacing-traditional-ransomware.html
    • Claude Mythos AI Finds 10,000 High-Severity Flaws In Widely Used Software
      "Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the world since the cybersecurity initiative went live last month. Project Glasswing is a defensive effort launched by the artificial intelligence (AI) company to secure critical global software infrastructure. It grants a small set of about 50 partners exclusive, early access to Claude Mythos Preview, a frontier model with capabilities to autonomously identify vulnerabilities in widely-used software before bad actors can exploit them."
      https://thehackernews.com/2026/05/claude-mythos-ai-finds-10000-high.html
      https://www.anthropic.com/research/glasswing-initial-update
      https://securityaffairs.com/192576/ai/anthropics-glasswing-10000-vulnerabilities-found-in-one-month-and-the-patching-problem-has-never-been-more-obvious.html
    • Dirty Frag, Copy Fail, Fragnesia: The Start Of a Worrisome Linux Security Trend
      "Dirty Frag, Copy Fail, and Fragnesia are less a random cluster of Linux bugs and more the public unveiling of how AI tools can pry open security holes with just a prompt or two. What they also have in common is their shared abuse of a core kernel abstraction: The page cache. What does this mean for you and me? Is this the rainstorm before a downpour of killer Linux security problems, or is this just a shower? It depends on who you ask."
      https://www.theregister.com/security/2026/05/23/dirty-frag-copy-fail-fragnesia-the-start-of-a-worrisome-linux-security-trend/5244742

    อ้างอิง
    Electronic Transactions Development Agency (ETDA) c15ceb14-6c52-4892-900c-0f3ded3d7a33-image.png

    โพสต์ใน Cyber Security News
  • Cisco อุดช่องโหว่วิกฤติ CVE-2026-20223 ใน Secure Workload เสี่ยงถูกยึดสิทธิ์ Site Admin ผ่าน REST API

    Cisco อุดช่องโหว่วิกฤติ CVE-2026-20223 ใน Secure Workload เสี่ยงถ.png

    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand a587a8bc-8adc-43ff-87ef-f8d4e1b45dd9-image.png

    โพสต์ใน Cyber Security News