
สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 

สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 

สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 

สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 
Industrial Sector
Vulnerabilities
Malware
Proxying To Compromise: SonicWall Secure Mobile Access 0-Day Exploitation
"In early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised SonicWall Secure Mobile Access (SMA) VPN appliances through a chain of multiple zero-day exploits in the devices. The initial compromise was discovered after suspect authentication and lateral movement attempts were observed from the SonicWall SMA appliances. Following public disclosure by SonicWall on July 14, 2026, Volexity is now able to share details on the exploits used, when they were used, and what the threat actor did with their access."
https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/
https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html
None And Done? Kittykatkrew’s Short-Lived Ransomware Play
"kittykatkrew is a financially motivated ransomware and data-extortion threat actor that announced its operation on February 22, 2026. In the roughly two months that followed, the group claimed two victims on its leak site, appeared to release a stolen law-enforcement dataset, and then went quiet. No confirmed ransom payment, no verified breach and no further activity as of mid-2026. The data leak site was offline as of April 9, 2026."
https://blog.barracuda.com/2026/07/16/none-and-done-kitty-kat-krew-ransomware-group
Sequel To ChainVeil Npm Malware Targets Vite Ecosystem
"When we published our ChainVeil report in June 2026, we noted something that didn’t fit: the SuccessKey campaign’s Command and Control (Command and Control (C2)) infrastructure contained a secondary server at 198.105.127[.]210 and a tertiary server at 23.27.202[.]27 that no known ChainVeil package ever called home to. We predicted additional campaigns were already running on the same backend. We were right."
https://checkmarx.com/zero-post/sequel-to-chainveil-npm-malware-targets-vite-ecosystem/
https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html
NadMesh Botnet Analysis: A Product-Grade Threat For The AI Service Era
"In early July 2026 we observed a Go-based botnet pushing bot samples onto the internet at scale. It folds scanning, exploitation, and credential/AI-service intelligence harvesting into a single autonomous platform. Because its controller calls itself n4d mesh controller in the source, we named it NadMesh. NadMesh is not a one-off worm outbreak. It is a continuously iterated, autonomous botnet aimed squarely at AI infrastructure and the MCP ecosystem. What sets it apart from traditional worms:"
https://blog.xlab.qianxin.com/nadmesh-botnet-analysis-a-product-grade-threat-for-the-ai-service-era-en/
https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
Introducing CylindricalCanine: The GoldenEyeDog Subgroup Responsible For The April DigiCert Incident
"In this blog, we review the behavior and capabilities of a malware we call Golden Gh0st Loader and Golden Gh0st RAT. We believe these malware are used exclusively by a sub-group dubbed “GoldenEyeDog”, a Chinese cybercrime group. In April 2026, the actors behind the malware were able to gain access to DigiCert to intercept code-signing certificates intended for DigiCert customers, and then used the certificates to sign their own malware. This piqued our interest in the malware, leading us to use DeceptionPro to monitor the malware over days in a controlled enterprise environment—and create a tool to decrypt the malware’s network communications."
https://expel.com/blog/introducing-cylindricalcanine/
https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html
New North Korean Campaign Uses Fake Coding Interviews To Steal Developer Credentials
"Elastic Security Labs found a new Contagious Interview campaign, tracked as REF9403, hiding malware inside SVG image files using steganography. To our knowledge, this specific infection chain has not been previously documented. We found it after the DPRK-aligned group targeted our own community Slack workspace with a fake job posting and a "coding challenge" project. Any user who ran the project ended up with a four-stage payload aligned with OTTERCOOKIE: a browser credential and crypto wallet stealer, a file stealer, a Socket.IO-based remote access trojan (RAT), and a clipboard stealer."
https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography
https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html
ACR Stealer: Two Observed Intrusion Chains Amid Increased Threat Activity
"From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments. Successful compromise can expose browser credentials, session tokens, authentication artifacts, and sensitive enterprise data, potentially enabling account compromise, unauthorized access to cloud resources, and follow-on intrusion activity. Security teams should prioritize monitoring for ClickFix lures, suspicious WebDAV activity, obfuscated PowerShell execution, and attempts to access browser credential stores."
https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/
https://thehackernews.com/2026/07/acr-stealer-uses-clickfix-lures-to.html
https://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/
Inside Qilin Ransomware: Custom Rust Loader And Kernel-Level EDR Killer
"In this post we analyze Qilin ransomware’s new custom Rust loader, break down the inner workings of its sophisticated kernel-level EDR killer, and explore how organizations can defend against these aggressive defense evasion tactics. Flashpoint customers can access the full intelligence report—complete with deeper technical analysis and all associated IOCs—directly within Flashpoint Ignite."
https://flashpoint.io/blog/inside-qilin-ransomware/
**Breaches/Hacks/Leaks
Abbott Probes Two Cyber Incidents Amid Extortion Claims**
"Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data. The company confirmed the Cancer Diagnostics incident after the ShinyHunters extortion gang added Abbott to its data leak site, initially threatening to publish allegedly stolen data after July 18 unless the company negotiated with the group, before later extending the deadline to July 21."
https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/
Ernst & Young Discloses Data Breach After Support System Hack
"Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. According to the company, support tickets submitted through the platform may have included documents containing client tax information. Ernst & Young (EY) is among the world’s four largest auditing and professional services providers, offering auditing, tax, consulting, and transaction advisory services to major organizations in more than 150 countries."
https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/
https://securityaffairs.com/195550/data-breach/ernst-young-ey-investigates-data-breach-involving-third-party-support-tickets.html
Hugging Face Discloses AI-Agent-Driven Breach Of Internal Clusters
"The interesting part of Hugging Face's security incident write-up, published July 16, is not that a dataset hub got popped, but how. The company says the intrusion was "driven, end to end, by an autonomous AI agent system." A malicious dataset abused two code-execution paths in Hugging Face's dataset processing, a remote-code loader and template injection in dataset configuration, to run on a processing worker. From there the agent escalated to node access, harvested cloud and cluster credentials, and moved laterally into several internal clusters over a weekend, generating what the disclosure calls "many thousands of individual actions across a swarm of short-lived sandboxes.""
https://aiweekly.co/alerts/hugging-face-discloses-ai-agent-driven-breach-of-internal-clusters
https://huggingface.co/blog/security-incident-july-2026
General News
อ้างอิง
Electronic Transactions Development Agency (ETDA)

สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 

สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 

สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 
Industrial Sector
Vulnerabilities
Malware
Breaches/Hacks/Leaks
General News
อ้างอิง
Electronic Transactions Development Agency (ETDA) 
Industrial Sector
New Tooling
Vulnerabilities
Malware
Research obtained and analyzed 200 Gemini CLI session logs from the Russian-speaking threat actor known as “bandcampro” that provided a month-long window (March 19-April 21, 2026) into the actor's daily AI-assisted operations. The logs documented how the threat actor used an AI agent to migrate a command-and-control (C&C) server, and to control a small-scale botnet, among other hacking activities. The actor used Google Gemini CLI to deploy and operate a C&C infrastructure to control eight computers in a dental clinic and access their OpenDental database."Breaches/Hacks/Leaks
General News
อ้างอิง
Electronic Transactions Development Agency (ETDA) 

สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 