ข้อมูลกลุ่ม ส่วนตัว

administrators

  • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

    เมื่อวันที่ 17 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

    • CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability

    ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

    อ้างอิง
    https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog
    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand a865c16d-98b2-4831-a134-de1fbb77e3b3-image.png

    โพสต์ใน Cyber Security News
  • Cyber Threat Intelligence 18 August 2026

    Government/Law/Policy

    • ETSI Launches Approval Process For 17 European Standards Supporting The Cyber Resilience Act
      "ETSI is pleased to announce the availability of the 17 vertical final draft standards developed in the framework of the EU Cyber Resilience Act (CRA) and currently under Public Enquiry. These standards aim to become Harmonised Standards, giving manufacturers a recognised way to demonstrate compliance with the legislation, the so-called “presumption of conformity”. The ETSI EN 304 xxx series standards on cybersecurity requirements have been submitted this summer to 41 member organisations across Europe, including the national standardisation bodies of the European Economic Area. They will be able to provide comments as part of the first phase of the approval procedure. ETSI’s societal partners ANEC (the European consumer voice in standardisation), ECOS (the European Environmental Citizens’ Organisation for Standardisation), ETUC (the European Trade Union Confederation), and SBS (Small Business Standards), collectively known as the Annex III Organisations, will also be able to comment on these standards."
      https://www.etsi.org/newsroom/press-releases/etsi-launches-approval-process-for-17-european-standards-supporting-the-cyber-resilience-act/
      https://www.infosecurity-magazine.com/news/etsi-proposes-17-cybersecurity/

    New Tooling

    • Hazmat: Open-Source Containment For AI Agents
      "Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud credentials, and the pile of configuration in your home directory that has accumulated over years. Hazmat gives the agent a home of its own and shares only the project directory you point it at. Your keys and credential folders sit outside what the session can reach."
      https://www.helpnetsecurity.com/2026/08/17/hazmat-open-source-ai-coding-agent-containment/
      https://github.com/dredozubov/hazmat

    Vulnerabilities

    Malware

    • C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
      "In July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbitrary commands, performing reconnaissance, and deploying second-stage payloads. In this blog post, ThreatLabz provides a technical analysis of the identified C2Looper variants, including their network communication protocols and capabilities."
      https://www.zscaler.com/blogs/security-research/c2looper-new-backdoor-likely-tied-ransomware-github-c2
    • Global Exploitation Of CVE-2026–59310 By Suspected Chinese-Nexus APT & Related CVE-2026–59309 Activity
      "QUIRSO’s Incident Response team recently investigated a VMware vCenter compromise that uncovered a coordinated, global exploitation campaign targeting CVE-2026–59310 as well as exploitation of CVE-2026–59309 by a possible different actor. Our investigation enabled us to map affected systems across numerous countries and identify evidence pointing to a Chinese-nexus advanced persistent threat. We continue to track the campaign as it develops. This article presents our current findings on its scale, victimology, infrastructure, tooling and attribution, while acknowledging that the assessment may evolve as new evidence emerges."
      https://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d
      https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html
    • The Gentlemen Ransomware: Inside One Of The Fastest-Growing Extortion Operations
      "The Gentlemen is a financially motivated ransomware-as-a-service (RaaS) double-extortion operation. Originally appearing as affiliate activity under other ransomware programs, the core operators established The Gentlemen as an independent brand in mid-2025 and began recruiting experienced affiliates with a 90% share of ransom proceeds. This generous affiliate share is one of several reasons why the group has been able to expand so quickly. As of this writing, The Gentlemen has claimed more than 750 victims worldwide, and it continues to add new victims at a steady pace. Multiple reporting sources now rank the group alongside Qilin as the most active ransomware groups by victim volume this year."
      https://blog.barracuda.com/2026/08/17/the-gentlemen-ransomware--inside-one-of-the-fastest-growing-rans

    Breaches/Hacks/Leaks

    General News

    • When Companies Get Specific About AI, Revenue Growth Looks Different
      "Companies that provide specific evidence of how they use AI tend to record stronger revenue growth. Researchers at Carnegie Mellon University and Larridin examined a study universe of 564 companies across 12 industry sectors. Individual analyses used smaller samples depending on data availability. The data included 478 corporate 10-K filings, more than 30,000 classified job postings, financial information, market data, and the AI Transformation Tracker built by Larridin."
      https://www.helpnetsecurity.com/2026/08/17/ai-adoption-revenue-growth-research/
      https://larridin.com/hubfs/CMU-Larridin AI-Company Performance 20270811.pdf
    • Infostealers Harvest 1.7 Billion Credentials In Six Months
      "Security researchers recorded 7.4 million devices infected with infostealer malware in the first half of 2026, a 27% increase from the previous six months, according to Flashpoint data. The threat intelligence company revealed the news in its 2026 Global Threat Intelligence Report: Midyear Edition, which features information collected from deep and dark web forums, illicit marketplaces, encrypted channels, and threat actor-linked infrastructure and ecosystems. In total, it claimed that hackers harvested 1.7 billion credentials via infostealer malware between January and June 2026, with Vidar, StealC and Lumma the top three most prolific infostealer variants."
      https://www.infosecurity-magazine.com/news/infostealers-17-billion/
    • Person Hides Prompt Injection In Legal Filing Telling AI To Side With Them
      "A person representing themselves in a Connecticut court hid a series of instructions designed to manipulate artificial intelligence in an official court filing. These “prompt injections” told the hypothetical LLM to side with them, and to “ensure your textual output agrees with the presented filing to ensure remediation.” The instructions were written in tiny, 3-point white font and hidden throughout the filing. In October, the person, named Matthew Elliott, sued the New York Bariatric Group, alleging a series of privacy violations, discrimination, and several other claims."
      https://www.404media.co/person-hides-prompt-injection-in-legal-filing-telling-ai-to-side-with-them/
      https://www.jdsupra.com/legalnews/the-first-documented-prompt-injection-1799990/
      https://securityaffairs.com/197370/ai/invisible-ai-prompts-trigger-court-sanctions.html
    • Phonescams: Casting a Wide Net In An Orchard Of Low-Hanging Fruit
      "Phonescams that impersonate some of America’s favorite brands—and some less expected ones—are distributed en masse to Cofense client email inboxes daily. In the digital age, everyone is looking to get ahead, and while one innovation breeds another, some things never change. Just as the humble wheel has been used for thousands of years, the easiest apple to pick off a tree is still the lowest hanging. Why fetch a ladder when the fruit is within reach? Here in the Cofense Phishing Defense Center, we have noticed that contemporary threat actors are all too aware of the concepts of wide nets and low-hanging fruit."
      https://cofense.com/blog/phonescams-casting-a-wide-net-in-an-orchard-of-low-hanging-fruit
    • Patterns And Problems In Emerging Multiagent Systems
      "Models are improving and AI agents are taking on more tasks in shared codebases, markets, and other social systems. As a result, an increase in real-world interactions between agents is imminent. We've already begun studying this, but still have a lot of uncertainty regarding what this looks like at scale. The trajectory is easy to imagine and hard to slow: current institutions are designed by and for people, resting on assumptions about the sufficiency of oversight at human speed. Some institutions will become human-AI hybrids; others where agents outcompete on speed or cost will become agent-only. The volume of agent-agent interaction could plausibly exceed that of human-human and human-agent interactions before the world understands the conditions for making such interactions go well."
      https://www.anthropic.com/research/multiagent-systems
      https://www.darkreading.com/threat-intelligence/turf-war-claude-agents-self-replicating-malware
      https://www.securityweek.com/conflicting-test-goals-pushed-claude-agents-to-deploy-self-replicating-malware/
    • Adam Shostack Talks Hugging Face & PHANTOM-B
      "OpenAI's rogue agents are raising a whole new set of questions for cyber defenders, and Dark Reading's senior news director Rob Wright sat down at the News Desk with threat modelling expert Adam Shostack to find out more. Shostack attended OpenAI's recent presentation on its findings in the wake of their AI agents going rogue, and he posed fundamental questions the industry will have to reckon with: namely, who is held liable when AI agents do real damage?"
      https://www.darkreading.com/vulnerabilities-threats/adam-shostack-talks-hugging-face-phantom-b

    อ้างอิง
    Electronic Transactions Development Agency (ETDA) 7e726480-ef24-4b7b-b7b6-b76eab99d0ab-image.png

    โพสต์ใน Cyber Security News
  • Cyber Threat Intelligence 17 August 2026

    Vulnerabilities

    Malware

    Breaches/Hacks/Leaks

    General News

    • Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw
      "Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers’ bank accounts. The theft, investigated by the Brazilian and German federal police agencies, occurred over four days in November 2023 and caused losses of around €30 million ($34.6 million). While neither the Brazilian Federal Police nor Germany's BKA named the affected German financial institution, Brazilian media identified it as Commerzbank, a major European financial institution that generates more than €11.1 billion ($12.8 billion) in annual revenue."
      https://www.bleepingcomputer.com/news/security/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw/
      https://therecord.media/investigation-into-banking-hack-leads-to-arrests-germany-brazil
    • Data Analyst Sent To Prison For Stealing Data, Extorting Employer
      "A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. Brightly is a Software-as-a-Service (SaaS) company formerly known as SchoolDude, which was acquired by Siemens in August 2022. Brightly employs over 700 people and provides asset management and maintenance software to more than 12,000 clients worldwide. 27-year-old North Carolina man Cameron Curry (also known as "Loot") was found guilty in March of orchestrating an "extensive cyber extortion scheme" targeting his employer."
      https://www.bleepingcomputer.com/news/security/data-analyst-sent-to-prison-for-stealing-data-extorting-employer/
    • Ransomware Threats In The Americas H1 2026: Dissecting The Regional Attack Patterns And Dominant Actors
      "The Americas carried the heaviest ransomware burden of any region on the planet in the first half of 2026. According to Cyble Research and Intelligence Labs (CRIL), North and South America combined experienced 2,188 documented ransomware attacks between January and June 2026. That single figure — 2,188 attacks — represents more than 57% of the 3,836 ransomware incidents CRIL tracked worldwide, making the Americas the undisputed center of gravity for global ransomware operations."
      https://cyble.com/blog/ransomware-threats-in-america-h1-2026/
    • What Boards Need To Know About Tech Risk
      "Most boardrooms are built to evaluate opportunity, growth initiatives, tech acquisitions, and operational improvements. The discussion centers on a familiar equation: investing in X to generate Y return. That mindset is essential for scaling a business. But it often creates dangerous blind spots in digital infrastructure. Unlike revenue-generating projects, many of the most important technology investments don't produce visible upsides."
      https://www.darkreading.com/cyber-risk/what-boards-must-know-tech-risk
    • The Hardest Part Of Agentic AI May Be Rebuilding The Business
      "Organizations expect AI agents to change how work gets done, driving productivity and growth while allowing employees to focus on higher-value tasks. Few, however, have the processes and workflows needed to realize those benefits, according to Deloitte’s latest research. About half of surveyed leaders say they understand how AI agents will affect their future operating model. Three main challenges limit wider adoption: the lack of a unified and accessible data foundation, limited trust in and governance of AI agents, and the cost and complexity of integration."
      https://www.helpnetsecurity.com/2026/08/14/deloitte-agentic-ai-readiness-gap-report/
    • Weak IAM Affects Up To 98% Of Cloud Environments
      "Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing encryption, exposed services, and logging gaps. CISA now mandates baseline cloud configuration practices for US federal agencies. More than two-thirds of midmarket organizations use multiple cloud providers, each with its own security model, terminology, and configuration settings. The same security issue can manifest differently across AWS, Azure, and Google Cloud, often requiring a different approach to identify and remediate, according to Intruder’s 2026 Cloud Security Index report."
      https://www.helpnetsecurity.com/2026/08/14/intruder-cloud-misconfiguration-trends-report/
    • Black Hat USA 2026: Will Vulnerability Discovery Eventually Decline In The AI Era?
      "The accelerated discovery of previously unknown software vulnerabilities has been making headlines for months. It’s an issue that has even led the US government to create a vulnerability clearing house named Gold Eagle to coordinate research efforts in vulnerability discovery, mitigation and fixes. An indication of the broader pressure facing cyber-defenders can be drawn from the sheer number of patches being delivered in Microsoft’s Patch Tuesday through the last four months: 169 CVEs in April, 118 CVEs in May, 571 CVEs overall in June (including 208 direct Microsoft CVEs) and another 622 vulnerabilities in July that included zero-days under active exploitation."
      https://www.welivesecurity.com/en/business-security/black-hat-usa-2026-vulnerability-discovery-decline-ai-era/
    • North Korean Remote Workers Are Infiltrating Government And Businesses: How To Expose Them Before Hiring
      "Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems companies spend millions trying to protect. That risk is no longer theoretical. The FBI is now investigating a North Korean remote IT worker who reportedly worked for a U.S. federal agency. For CISOs, the priority is clear: spot the warning signs before a fraudulent hire becomes trusted access."
      https://thehackernews.com/2026/08/north-korean-remote-workers-are.html
    • AI Can Find Bugs, But Human Knowledge Still Proves Them
      "Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, explain unfamiliar APIs, and run repetitive testing workflows at impressive speed. That is a real advantage for security teams. It also creates a new kind of pressure, because the industry can now produce more vulnerability-looking output than ever before."
      https://www.sans.org/blog/ai-can-find-bugs-but-human-knowledge-still-proves-them
    • Drop Something? Don’t Worry, Someone Caught It
      "Every day, tens of thousands of domain names expire and become available for registration. Some fade away and are never seen again. Others get a second chance. We refer to these as dropcatch domains: the domain was dropped, became available again, and someone caught it. This isn’t just our name; it’s widely used. There’s even an auction service called DropCatch[.]com. During the first half of 2026, we observed over 50k dropcatch domains a day in the gTLDs alone—when we add in various ccTLDs that number rises to around 65k. That’s an astounding number when you put it next to the total of new registrations every day. For the gTLDs, nearly 20% of all observed registrations are dropcatch. In other words, one of every five newly registered domains had a prior life, sometimes several."
      https://www.infoblox.com/blog/threat-intelligence/drop-something-dont-worry-someone-caught-it/
      https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html
      https://securityaffairs.com/197251/uncategorized/crooks-are-buying-your-expired-domains-and-using-them-to-deliver-malware.html
    • AI Won't Solve Cybersecurity Burnout. Better Leadership Might
      "Cybersecurity has spent years talking about workforce shortages. More recently, AI has entered the conversation as a possible solution. It can help teams analyze alerts, identify threats, automate investigations, and complete routine tasks faster than ever. That shift is already underway. According to SANS workforce research, 74% of cybersecurity teams are changing structures and role assignments because of AI, with entry-level SOC and security analyst roles among the most affected. Yet workloads, complexity and stress continue to rise. The latest ISSA workforce study found that 68% of professionals believe their jobs have become harder over the past two years, and nearly half have considered leaving their current role."
      https://blog.barracuda.com/2026/08/14/ai-won-t-solve-cybersecurity-burnout--better-leadership-might

    อ้างอิง
    Electronic Transactions Development Agency (ETDA) 7b745a34-7080-45b9-8405-28899a9c7f37-image.png

    โพสต์ใน Cyber Security News
  • พบความพยายามใช้ประโยชน์จากช่องโหว่ SAP Commerce Cloud เสี่ยงรันโค้ดบนระบบ

    พบความพยายามใช้ประโยชน์จากช่องโหว่ SAP Commerce Clo.png

    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 35acf675-b145-44b4-ab65-8d41d42e0cc2-image.png

    โพสต์ใน Cyber Security News
  • CTM360 พบแคมเปญ Phishing สมัครงานกว่า 3,000 URL ใช้เทคนิค Browser-in-the-Browser ขโมย Credential

    CTM360 พบแคมเปญ Phishing สมัครงานกว่า 3,000 URL ใช้เทคนิค Bro.png

    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 9548d032-b9a5-41df-b758-4162bdc6eebc-image.png

    โพสต์ใน Cyber Security News
  • พบกลุ่มผู้ไม่หวังดีกว้านซื้อโดเมนที่หมดอายุแล้ว เพื่อใช้เป็นฐานในการโจมตีทางไซเบอร์และแพร่มัลแวร์

    พบกลุ่มผู้ไม่หวังดีกว้านซื้อโดเมนที่หมด.png

    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand df49e788-349b-46f2-ad92-23c2e992b1aa-image.png

    โพสต์ใน Cyber Security News
  • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 15 รายการ

    Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 15 รายการ เมื่อวันที่ 13 สิงหาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

    • ICSA-26-225-01 AVEVA Enterprise SCADA
    • ICSA-26-225-02 Haiwell IoT Cloud HMI Gateway
    • ICSA-26-225-03 Johnson Controls Inc. Airwall
    • ICSA-26-225-04 Hitachi Energy APM Edge Product
    • ICSA-26-225-05 ANDRITZ HIPASE-250 and 250 SCALA
    • ICSA-26-225-06 Siemens RUGGEDCOM APE1808
    • ICSA-26-225-07 Siemens License Server (SLS)
    • ICSA-26-225-08 Siemens Desigo DXR and PXC Controllers
    • ICSA-26-225-09 Siemens Siveillance Video
    • ICSA-26-225-10 Siemens Parasolid
    • ICSA-26-225-11 Siemens Simcenter Femap
    • ICSA-26-225-12 Siemens Solid Edge
    • ICSA-26-225-13 Siemens LOGO! Soft Comfort
    • ICSA-26-225-14 Johnson Controls Metasys
    • ICSMA-26-225-01 Flow Neuroscience FL-100

    CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

    อ้างอิง
    https://www.cisa.gov/news-events/ics-advisories
    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5659c9e0-8038-44d2-9544-47a194eab180-image.png

    โพสต์ใน OT Cyber Security News
  • Cyber Threat Intelligence 14 August 2026

    Healthcare Sector

    • Flow Neuroscience FL-100
      "Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to manipulate brain stimulation parameters and override safety limits."

    Industrial Sector

    • Haiwell IoT Cloud HMI Gateway
      "Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges."
    • Hitachi Energy APM Edge Product
      "Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation."
    • Siemens Siveillance Video
      "Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions."
    • AVEVA Enterprise SCADA
      "Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization."
    • Johnson Controls Inc. Airwall
      "Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources."
    • ANDRITZ HIPASE-250 And 250 SCALA
      "Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations."
    • Siemens License Server (SLS)
      "Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version."
    • Siemens Desigo DXR And PXC Controllers
      "A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions."
    • Siemens Parasolid
      "Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions."
    • Siemens Simcenter Femap
      "Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version."
    • Siemens Solid Edge
      "Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions."
    • Siemens LOGO! Soft Comfort
      "Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive project logic and configurations. Siemens has released a new version for LOGO! Soft Comfort and recommends to update to the latest version."
    • Johnson Controls Metasys
      "Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access."

    Vulnerabilities

    • WordPress 7.0.4 Patches Remote Code Execution Vulnerability
      "WordPress on Wednesday announced patches for a high-severity vulnerability that allows authenticated attackers to execute arbitrary code remotely. Tracked as CVE-2026-65640 (CVSS score of 8.8), the security defect can be exploited by attackers with Author-level user or higher permissions via malicious Postscript file uploads. According to WordPress’ advisory, the issue affects only installations that use Imagick and Ghostscript, as it was discovered in Ghostscript’s handling of certain embedded files. Successful exploitation requires that an attacker has file upload rights."
    • Fortinet Patches Authentication Flaws In FortiWeb And FortiManager
      "Fortinet on Wednesday announced patches for eight vulnerabilities across its products, including high-severity authentication bugs in FortiWeb and FortiManager. In FortiWeb, the company resolved an improper authentication issue impacting deployments configured with specific, non-default settings. A remote, unauthenticated attacker could exploit the flaw, tracked as CVE-2026-26035, “to log in to the FortiWeb GUI/CLI with a random username and password,” Fortinet explains."
    • Microsoft Patches LegacyHive Windows Zero-Day Vulnerability
      "Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. The security flaw was disclosed by a security researcher who uses the "Nightmare Eclipse" handle in protest of Microsoft's bug bounty and vulnerability disclosure practices. Nightmare Eclipse published a LegacyHive proof-of-concept (PoC) exploit hours after the July 2026 Patch Tuesday security updates were released, claiming it exploits a security vulnerability in the Windows User Profile Service."

    Malware

    • Armored Likho Expands Its Cyber-Espionage Toolkit
      "In May 2026, we discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals and organizations across various industries in Russia, including major corporations, the public sector, IT, and education. The attackers used a fake app as bait that mimics a service for donations. However, the most interesting part of this campaign isn’t the initial infection method – it’s the malicious implants the attackers use for cyber-espionage. We’ve written previously about recent Armored Likho attacks, but our analysis shows that the campaign discussed below has more in common with the group’s activity from February. That said, the attackers have significantly expanded their arsenal."
    • Akira Hits Safe Mode: Ransomware Rebooting Around EDR
      "Akira has become one of the most prolific ransomware operations and was the most active group we observed in 2025. Its affiliates have settled into a well-worn playbook: get in through an exposed VPN (usually SonicWall), pivot to the domain controller, enumerate Active Directory, stage and exfiltrate data, then detonate all within a few hours. Huntress has documented that playbook in depth: from the active exploitation of SonicWall SSL VPN appliances as an initial-access vector, to a recent case where an affiliate spun up a brand-new virtual machine on the victim's hypervisor specifically to run the encryptor somewhere Huntress wasn't installed."
    • Jewelbug: APT Group Runs Espionage And Crypto Fraud Operations Side By Side
      "A months-long investigation by the Symantec Threat Hunter Team has produced unprecedented visibility into the activities of Jewelbug (aka Earth Alux, REF7707, CL-STA-0049), a China-based APT group that has been breaking into government ministries across Asia and the Middle East while quietly running a cryptocurrency fraud business on the side. The two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel. Jewelbug’s commercial arm is tied to a known registered company in Hunan Province, China. The group has developed five generations of command-and-control (C&C) code and a family of implants spanning browsers, Windows endpoints, Linux servers and network devices, all of it feeding a single database of victims. That toolset serves two missions: espionage attacks against foreign governments and militaries, and for-profit crypto fraud aimed at Chinese-speaking victims."
    • Dissecting The JWR Phishing Framework
      "JWR is a phishing framework capable of harvesting complete payment card data, login credentials, and personally identifiable information (PII) documents and images in real time. The client-side engine of the framework impersonates login, and checkout flows of several payment gateways, including Shopify, PayPal, Apple, Klarna, and banks, while allowing the operator to stealthily control the victim session through an AES-CTR encrypted WebSocket channel. The client engine architecture is divided into a Host Bridge module that relays commands into a phishing inline frame (iframe) and a Vue.js victim application that renders across 44 phishing pages, streams the victim's keystrokes to the actor as they are typed, and carries out more than 40 distinct instructions issued from the command-and-control (C2) console. The data exfiltration schema is a cvvform object that includes fields such as credit card number, CVV, PIN, expiry date, Social Security Number (SSN), passport or ID images, two-factor authentication (2FA) codes, website logins, PayPal credentials, and device fingerprint."
    • Multi-Functional Linux Botnet “Evooo1Bot”
      "FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary. While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities. Telemetry from its command-and-control infrastructure indicates that Evooo1Bot has been actively targeting Internet-facing devices since July 2026, exploiting multiple vulnerabilities across diverse regions. In this article, we provide a detailed analysis of Evooo1Bot’s modular architecture and operational features."
    • How To Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign
      "Organizations increasingly rely on GitHub to develop and store proprietary source code, internal documentation, and other software assets. This makes GitHub Personal Access Tokens (PATs) an attractive target for attackers, as a compromised token can provide access to private repositories and expose secrets such as cloud credentials, API keys, and private keys that may enable further compromise. Recently, the Wiz Customer Incident Response Team (CIRT) investigated a coordinated campaign in which compromised GitHub PATs were used to conduct repository reconnaissance and mass repository exfiltration across multiple organizations. Active from mid-May through early June 2026, the campaign progressed through several distinct stages, from reconnaissance and access validation to large-scale repository cloning and follow-on attempts to leverage exfiltrated credentials."
    • Top 10 Phishing Kits Used By Cybercriminals
      "Phishing kits have turned credential theft into a scalable service by packaging fake login pages, hosting, traffic filtering, victim management, and technical support into ready-made platforms. Advanced services such as Tycoon2FA, EvilProxy, and Sneaky 2FA can also intercept session cookies and bypass MFA methods that are not phishing-resistant, while platforms such as Darcula and Telekopye focus more heavily on smishing and consumer fraud. This article examines ten prominent platforms selected for their documented use, technical influence, current relevance, and value to defenders. It is not a strict ranking, and disrupted services are identified accordingly."

    Breaches/Hacks/Leaks

    • Trezor Discloses Data Breach Affecting Nearly 14,000 Customers
      "Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked. During the incident, the attackers gained access to customers' order data, including their full names, shipping addresses, email addresses, and phone numbers. As the company explained in a Thursday blog post, the resulting data breach affects customers from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10th and August 8th, 2026."
    • Exposed AWS Access Key Linked To Data Breach Affecting 1500+ UK Charities
      "A compromised AWS access key was the likely root cause of the cyber-attack on CRM provider Beacon, which has exposed personal information held by around 1500 UK charities. The software provider said in an August 12 incident update that the access key was potentially exposed in public Javascript build artifacts. This suggests an error was made in the course of software development. Beacon has assessed that the attacker used these valid credentials to access and download all data contained within the CRM platform, including attachment files, thereby impacting its entire 1500-strong customer base of charitable organizations."
    • INC Ransom Targeted 24 Law Firms, But Only 10 Are Listed
      "INC was on an encryption streak against US law firms in March 2026. SOCRadar identified 24 individualized extortion sites, hosted across two IP addresses, that we assess with high confidence are tied to INC Ransom. Each one is built for a specific US law firm, complete with its own countdown timer and highly likely shared with the victim firm’s customers to increase the pressure. Cross-referencing those 24 firms against INC’s known leak site months later, roughly 58% (14 of 24) do not appear there, while 42% (10 of 24) are listed."

    General News

    • Ukraine Shuts Down 94 Fraudulent Call Centers, Seize Millions In Cash
      "Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. The operation occurred this week, and police officers conducted a total of 411 searches following an investigation that involved the National Police, Ukraine's Security Service, the Prosecutor General’s Office, and the German police. According to the Ukrainian police, the fraudsters ran various schemes to obtain money from victims or gain access to their bank accounts."
    • Ransomware Didn’t Slow Down In Q2 2026. It Just Spread Out.
      "Ransomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is more interesting: new research gave us a rare look inside a top tier operation as it was being built, and it revealed just how little it now takes for a small and skilled group to reach the top of the field. Here’s what the quarter actually showed, and what it means for how you defend against it."
    • PQC In Plaintext: Google Cloud’s Post-Quantum Cryptography Roadmap
      "Securing infrastructure and services against a future cryptographically-relevant quantum computer has been a goal for Google for a decade, and we’ve dedicated ourselves to help developers by advancing open standards that can benefit everyone. As post-quantum cryptography (PQC) has matured, we’ve been rolling it out in our infrastructure for internal and customer-facing services. Today, we're sharing our updated Google Cloud roadmap to migrate to PQC by 2029."
    • Germany Moves To Give Spy Agencies Hacking And Sabotage Powers
      "Germany’s cabinet approved legislation Wednesday that would let its intelligence agencies hack foreign systems, sabotage adversaries’ supply chains and feed false information to extremists inside Germany, in the biggest overhaul of the country’s spy laws of the postwar era. Chancellery chief Nina Warken said the new powers could allow the agencies to substitute faulty components into deliveries, use cyber operations to sabotage drone factories or chemical weapons laboratories and disable servers run by hostile state-sponsored hackers and disinformation operators."
    • Trump Taps Cyber Firms To Go On Offensive Against Criminals
      "The Trump administration will allow private companies to launch attacks on cybercrime organizations, according to a presidential memorandum released late on Wednesday. The firms will partner with the Justice and Homeland Security departments on offensive operations and surveillance targeting “transnational cybercrime, fraud, and other predatory schemes against American citizens.” “By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter [Transnational Criminal Organizations] threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” the memorandum said."
    • Apple Sends New ‘Threat Notification’ Alerts Over Mercenary Spyware Attacks
      "You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." Some users on Reddit are reporting that they received these alerts today after Apple sent out a new batch of threat notifications on August 13, but the feature itself is not new."

    อ้างอิง
    Electronic Transactions Development Agency (ETDA) af0a2506-b6c9-422b-817f-717d1773a477-image.png

    โพสต์ใน Cyber Security News
  • WordPress ออกแพตช์แก้ช่องโหว่ RCE ผ่านการประมวลผลไฟล์ภาพ

    WordPress ออกแพตช์แก้ช่องโหว่ RCE ผ่านการประมวลผล.jpg

    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 490dd133-1909-45a2-8893-39d6a3b74df6-image.png

    โพสต์ใน Cyber Security News
  • CEVA Logistics ถูกโจมตีทางไซเบอร์ กระทบคลังสินค้าและการจัดส่งในยุโรป

    CEVA Logistics ถูกโจมตีทางไซเบอร์ กระทบคลังสินค้าแ.jpg

    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand f073fcb3-5dd4-4b3c-b97d-f4c03805404b-image.png

    โพสต์ใน Cyber Security News