ข้อมูลกลุ่ม ส่วนตัว

administrators

  • Cisco เตือนช่องโหว่ Static Credential ใน Secure Firewall Management Center ถูกใช้โจมตีจริง

    Cisco เตือนช่องโหว่ Static Credential ใน Secure Firewall Management Center ถูกใ.png

    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 12ad936f-83a0-47f6-9b7a-df14c70af6a9-image.png

    โพสต์ใน Cyber Security News
  • Minnesota พบการโจมตีระบบ OT ของ Water Utilities กว่า 30 แห่ง กระทบโรงผลิตน้ำบางแห่งชั่วคราว

    Minnesota พบการโจมตีระบบ OT ของ Water Utilities กว่า 30 แห่ง กร.png

    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 0e91bd7e-389d-4165-9139-8901e0c4c552-image.png

    โพสต์ใน Cyber Security News
  • OpenAI เผยข้อมูลจากเหตุการณ์โมเดล AI หลุดระบบทดสอบ พบใช้ช่องโหว่เข้าถึงบริการภายนอกเพิ่มเติม

    OpenAI เผยข้อมูลจากเหตุการณ์โมเดล AI หลุดระบบทด.png

    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e194445e-b9ad-4fcc-adba-1666947bfd41-image.png

    โพสต์ใน Cyber Security News
  • Cyber Threat Intelligence 31 July 2026

    Industrial Sector

    Vulnerabilities

    Malware

    • [Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor And The Gunra Ransomware Group)
      "AhnLab SEcurity intelligence Center (ASEC) identified evidence that a state-sponsored threat group continuously distributed malware from 2025 through the first half of 2026 by exploiting vulnerabilities in Korean financial security software installed when using financial and institutional services. The attackers induced targets to access malicious URLs through various methods, including watering hole and spear-phishing attacks, and then exploited the vulnerabilities to ultimately install backdoor malware. In particular, legitimate Korean websites across various industries, including media organizations, educational institutions, healthcare institutions, and manufacturing companies, were confirmed to have been abused in watering hole attacks during this period."
      https://asec.ahnlab.com/en/94696/
      https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html
      https://therecord.media/north-korea-hackers-ransomware
    • XMRig Covert Ops: The Cryptomining Campaign That Abuses Trusted Access And Deploys Forensic Smokescreens
      "In May 2026, a highly covert Monero (XMR) cryptomining campaign was identified, leveraging advanced stealth techniques to infiltrate and persist within targeted Linux environments. The initial compromise occurred through a trusted third-party relationship, allowing threat actors to traverse from a trusted environment into the primary network undetected. This blog post details the campaign’s tactics, from weaponizing Linux Pluggable Authentication Modules (PAM) to create a forensic smokescreen, to the deployment of a highly customized, self-unlinking XMRig botnet implant and employment of MITRE technique T1564.013."
      https://www.group-ib.com/blog/xmrig-covert-linux-pam-abuse/
    • Toy Ghouls’ New Toy: The GenieLocker Ransomware
      "The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector, and attributed to the Toy Ghouls group by open-source intelligence (link in Russian). The Toy Ghouls, also known as Bearlyfy, Labubu and Laboo.boo, is a financially motivated extortion group, which previously relied on third-party encryption Trojans like RedAlert, LockBit, and Babuk. GenieLocker, apparently a custom design, upgrades their toolkit and reduces their reliance on third-party software. We discovered multiple samples of this Trojan in two variants: PE builds for Windows and ELF builds for Linux and ESXi."
      https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/
    • Not Every Fox Is Silver: Inside An AtlasRAT Loader Chain
      "AtlasRAT is a Windows-based remote access malware. This report analyzes a four-stage in-memory loader chain—which begins with a Delphi executable that is disguised as AGE Flash Player—and its final RAT functionality. The final payload performs TLS-based ChaCha20-encrypted C2 communication, executes modular plugins, performs offline keylogging, and injects DLLs into WeChat processes."
      https://asec.ahnlab.com/en/94704/
    • Chaos In Teams Vishing
      "Sophos analysts investigated a Microsoft Teams voice phishing (vishing) campaign tracked as STAC4749 that used a consistent set of IT-themed cloud domains and personas to gain remote access to victims’ systems. Between February and June 2026, Sophos analysts observed the threat actors targeting dozens of North American organizations. Following initial access, STAC4749 operators deployed a modular post‑exploitation toolset, including a custom loader and backdoor to maintain persistent, controlled access and support follow‑on activity. In several incidents, attackers later leveraged this access to deploy Chaos ransomware."
      https://www.sophos.com/en-us/blog/chaos-in-teams-vishing
      https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/
    • After The Break-In: What Attackers Do Once They're Already Inside
      "Most of us in IT spend our energy trying to keep attackers out. But a recent incident investigated by Huntress tells us a lot about what happens after an attacker gets in (and why it matters just as much). Once an attacker has gained initial access, they don't rush straight to the smash-and-grab, doing things like stealing data, encrypting files, or dropping ransomware. Instead, they take time to dwell and settle in—creating backdoors, covering their tracks, and disabling the tools meant to catch them."
      https://www.bleepingcomputer.com/news/security/after-the-break-in-what-attackers-do-once-theyre-already-inside/
    • OctLurk And SilkLurk: Newly Identified Tailored Backdoors In Cyber-Espionage Campaign In Central Asia
      "We have been tracking two new backdoors, OctLurk and SilkLurk, observed in attacks against government organizations primarily in Central Asia since January 2025. Identified victims are located in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. These organizations operate across several sectors, including healthcare, research, government offices, ministries of foreign affairs, logistics, law‑enforcement agencies, urban planning and facilities management, and public educational establishments. The backdoor loaders are customized for each victim and use information from the victim’s machine to decrypt the payload. Both the loaders and the backdoors are heavily obfuscated, making analysis more complicated."
      https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/
    • When AI Becomes The Attacker: Understanding Autonomous Offensive Security Agents
      "Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, and Nebula lower the barriers to vulnerability identification and exploitation. The analysis also explores why AI is being repurposed for real attacks and what defenders should do in response. From a broader perspective, cybercriminals and foreign adversaries are expected to leverage AI to maximize the impact of cyberattacks, while also optimizing and scaling malicious activity —creating a race between AI-driven attackers and defenders."
      https://www.resecurity.com/blog/article/when-ai-becomes-the-attacker-understanding-autonomous-offensive-security-agents
      https://securityaffairs.com/196331/ai/cybercriminals-are-leveraging-autonomous-ai-offensive-security-agents.html
    • ClickFix, EtherHiding & a DPRK Wallet Trail
      "A routine web search for security research led to the discovery of a sophisticated macOS malvertising campaign combining ClickFix-style social engineering, blockchain-hosted command-and-control, browser-extension hijacking, and crypto-theft infrastructure."
      https://www.allsecure.io/blog/clickfix-etherhiding-dprk-wallet/
      https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html
    • Cato CTRL™ Threat Research: SilverFox Evolves: Abuse Of New Drivers And Trusted Software Hijacking Enable Remote Access With ValleyRAT In Japan
      "SilverFox is expanding its toolkit. In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate applications for DLL sideloading, defense evasion, and layered recovery mechanisms to keep ValleyRAT running. We investigated an active campaign targeting a Japanese organization in the industrial manufacturing sector. The attack begins with an invoice-themed phishing lure and uses attacker-controlled content hosted through legitimate QQ and Tencent Cloud services. The attackers then abuse ConvertToPDF.exe and PDFDirect.exe to sideload a malicious PDFCORE8.dll. Based on the public research we reviewed, neither application had previously been documented as a DLL-sideloading host."
      https://www.catonetworks.com/blog/cato-ctrl-silverfox-evolves/
      https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html
    • Chinese-Speaking Threat Actor Harnesses AI Models For Autonomous Cyberattacks
      "Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact. The actor, operating under the aliases knaithe and KnYuan, leveraged DeepSeek, via the Hermes Agent framework, as their autonomous offensive operator. They orchestrated this operator via Telegram for the following activities:"
      https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/
    • Batten Down Your Packages: Mitigation Guidance For Supply Chain Compromise
      "For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. However, Google Threat Intelligence Group (GTIG) has been tracking growth in threat activity targeting open source software repositories to conduct supply chain compromises over the past several years. A series of large scale open source software supply chain compromise campaigns in 2025 and the first half of 2026 underscore how important it is that organizations implement defensive strategies that directly address this threat vector."
      https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise
    • Beyond The Screenshot: Why You Should Verify What You See
      "Someone sends you a screenshot showing that a payment has gone through. It carries the right logo, amount, timestamp and transaction status. Yet the money never arrives. What passes for proof today can generally be very different from just a few years ago. Screenshots, often commonly treated as a convenient record of a payment, message or online conversation, are hard to take at face value. To be sure, they have always been open to manipulation, but generative AI and other readily available tools have made convincing fabrications even quicker and easier to produce. Everything from bank transfers and bookings to social media posts and corporate chats can be easily created to order."
      https://www.welivesecurity.com/en/cybersecurity/beyond-screenshot-why-verify-you-see/

    Breaches/Hacks/Leaks

    General News

    • Exposed Credentials Are Giving Attackers a Head Start Many Organizations Don’t See
      "Compromised credentials can remain active long after passwords are created, leaving organizations trying to identify exposed accounts before attackers can use them. The 2026 Credential Risk Report from Enzoic shows growing awareness of the problem, but monitoring and response capabilities continue to lag. 73% of organizations identified employee or contractor credentials in breach data, dark web sources, or infostealer logs during the past year, while nearly one in five lack visibility into whether their credentials have been exposed. More than seven in 10 companies experienced an authentication-related incident during the past year, and two-thirds of the most recent incidents involved attackers signing in with valid credentials."
      https://www.helpnetsecurity.com/2026/07/30/enzoic-credential-exposure-risks-report/
    • 200 New CVEs a Day And No Realistic Way To Patch Them All
      "Ryan Dewhurst, CEO at KEVIntel, explains how his team confirms exploitation that CISA’s catalog has not listed yet. He describes a global honeypot sensor network, AI triage, and human verification in a lab before a vulnerability reaches the public feed. He covers CISA’s three-day patching deadline under BOD 26-04, why virtual patching buys time, and how AI-generated proof-of-concept code muddies the evidence. He also ranks incident reports, honeypot hits, scanning and PoC chatter by how much each should move a defender’s confidence."
      https://www.helpnetsecurity.com/2026/07/30/ryan-dewhurst-kevintel-known-exploited-vulnerabilities/
    • Making Forensic Observability The Norm For Network Devices
      "Organisations' firewalls, VPN gateways and other network devices are increasingly targeted by attackers. This creates a shared challenge for both the vendors that build these products and the organisations that buy and operate them. When incidents occur, organisations need reliable ways to understand what happened and assess whether a device can still be trusted. This is why forensic observability matters. It enables defenders to investigate compromise using supported capabilities built into the product, rather than relying on reverse engineering, or specialist vulnerability research – as is still often the case."
      https://www.ncsc.gov.uk/blogs/making-forensic-observability-the-norm-for-network-devices
      https://www.infosecurity-magazine.com/news/ncsc-calls-device-manufacturers/
    • US And Allies Update SBOM Guidance
      "Government agencies in the US and 13 allied countries this week released updated guidance on the minimum elements of a software bill of materials (SBOM). Meant to reflect the changes in supply chain security and software transparency, the document builds on the SBOM Minimum Elements guidance that NTIA released in 2021 and takes into consideration comments received during the public feedback period last year. An SBOM, the authoring agencies say, should serve as a “key building block of software security and supply chain risk management,” helping organizations build accurate inventories of the software and software components within their environments."
      https://www.securityweek.com/us-and-allies-update-sbom-guidance/
      https://www.helpnetsecurity.com/2026/07/30/cisa-sbom-guidance-updated/
    • Adverse Cyber Extortion Outcomes Happen More Often Than Victims Are Told
      "In February of 2024, a consortium of law enforcement agencies took down LockBit ransomware group. The discovery that LockBit retained victims’ stolen data despite promises to delete it demonstrates a critical flaw in the advice often given to ransomware victims. At the time, many legal and incident response professionals recommended payment on the assumption that LockBit had a strong financial incentive to honor its commitments and that the likelihood of data being publicly released after payment was relatively low. While that assessment may have appeared reasonable based on short-term observed outcomes, it relied heavily on assumptions about the behavior of a criminal enterprise that could never be independently verified."
      https://www.veeam.com/blog/cyber-extortion-payment-trends-q2-2026.html
      https://www.bankinfosecurity.com/flailing-ransomware-hackers-resorting-to-extreme-tactics-a-32375
    • Open Source Software: Security Principles And Practices
      "Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework for trust assessment, and provides specific recommendations for vulnerability management, software bill of materials use, secure development, and handling open source artificial intelligence systems."
      https://www.cisa.gov/resources-tools/resources/open-source-software-security-principles-and-practices
      https://cyberscoop.com/cisa-open-source-software-security-guidance/
    • AI Harnesses Burst With Potential Exploit Opps
      "Major frontier AI vendors — including Anthropic, Google, and OpenAI — need to rein in the harnesses they wrap around their large language modules, to limit security weaknesses created by software components that are too trusting of each other. That's the word from researchers at AI penetration testing firm Novee Security, who were able to use Google's AI agent to execute a supply chain attack and write to its own repository on GitHub, says Elad Meged, a founding team and security researcher at the company. The team also found issues in Anthropic's and OpenAI's AI agents by exploiting misalignments in the trust between elements to enable attacks."
      https://www.darkreading.com/application-security/ai-harnesses-potential-exploit-opps
    • Claude Mythos — Hype Vs. Reality: What Security Teams Need To Know
      "In the latest installment of our monthly Reporters' Notebook video series, Dark Reading's Alexander Culafi, TechTarget Cybersecurity's Alissa Irei, and Cybersecurity Dive's David Jones discuss the ongoing fervor around Anthropic's Claude Mythos model and the long-term security implications of powerful, bug-hunting large language models (LLMs). Mythos was announced in April as Anthropic's new frontier model, notable particularly because of its supposed cyber capabilities. Anthropic said Mythos was capable of discovering and exploiting critical zero-day vulnerabilities with little prompting, even in decades-old software. The possible danger of such technology getting into attacker hands led to Anthropic's launch of Project Glasswing; the AI firm said it would share the model in preview with choice partners."
      https://www.darkreading.com/cybersecurity-operations/claude-mythos-hype-vs-reality
    • Action1 2026 Survey Report: AI Impact On Sysadmins
      "AI was supposed to be running patch management, vulnerability prioritization, and incident response by now. It isn’t. So where does that leave sysadmins in 2026? The Action1 2026 Survey Report: AI Impact on Sysadmins tracks how AI adoption compares to what sysadmins predicted two years ago, where AI has earned real trust, and where it still hits a hard wall of human oversight. Based on insights from more than 1,000 system administrators worldwide, this fourth annual report captures how expectations, adoption, and trust have shifted since 2023."
      https://www.action1.com/2026-ai-impact-on-sysadmins-survey-report/
      https://www.infosecurity-magazine.com/news/ai-automation-fall-short-sysadmin/
    • Why Brand Impersonation Is Becoming An Initial Access Vector
      "Attackers recently poisoned more than 700 websites, including sites run by Harvard, Oxford, and DuckDuckGo. They used a fake Cloudflare page to trick visitors into running a ClickFix attack that installed malware. Researchers tracing the incident found the same injected code running across hundreds of unrelated sites, all feeding shared attacker infrastructure. That Harvard and Oxford can get turned into malware delivery platforms is concerning. That two rival criminal groups were fighting each other for control of the same hijacked sites is cause for immediate action."
      https://securityaffairs.com/196359/hacking/why-brand-impersonation-is-becoming-an-initial-access-vector.html
    • Timeless Compliance: Why Better Questions Beat Bigger Frameworks
      "In 2009, a surgeon named Atul Gawande and a team backed by the World Health Organization showed that a 19-item surgical checklist could cut complications and deaths by dramatic margins across eight hospitals worldwide. Not a thousand-page protocol. Not a comprehensive framework. Nineteen items, printed on a single card. Aviation learned the same lesson decades earlier: the pre-flight checklist fits in a pilot’s hand, not in a binder. Nearly two decades later, I watch security teams send AI vendors questionnaires with 300 questions, half of which begin with “describe your approach to…” and almost none of which would catch a real failure. We have the frameworks. What we don’t have is the checklist."
      https://www.securityweek.com/timeless-compliance-why-better-questions-beat-bigger-frameworks/
    • Welcome To Danglegeddon
      "There are billions of forgotten, abandoned, and misconfigured subdomains on the internet that point to nowhere. Seemingly harmless on the surface, they aren’t necessarily an imminent cyber threat warranting an immediate call to arms from analysts, agents, or defenders. Looking at this “dangling DNS” infrastructure, the Silent Push research team asked a simple question: What if we looked at it the same way a trained nation-state attacker would? And what if we simulated a scaled exploit of this “highly exploitable” infrastructure that the world has not yet seen? What would the impact be? How widespread could it become, and how quickly could a massive-scale takeover be possible?"
      https://www.silentpush.com/blog/danglegeddon/
      https://www.securityweek.com/danglegeddon-ai-could-weaponize-forgotten-dns-records-at-global-scale/
    • Investigating Three Real-World Incidents In Our Cybersecurity Evaluations
      "In a review of our cybersecurity evaluation transcripts, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations. Below we describe what happened, how it happened, and what we’re changing. We encourage other AI labs to perform similar reviews. This post reflects our current understanding; we'll update it if any details change."
      https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
      https://www.bleepingcomputer.com/news/security/anthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests/
      https://cyberscoop.com/anthropic-claude-ai-hacks-real-companies/

    อ้างอิง
    Electronic Transactions Development Agency (ETDA) 4eca9677-2dc6-4f31-8716-ae54537914a2-image.png

    โพสต์ใน Cyber Security News
  • Cyber Threat Intelligence 30 July 2026

    Energy Sector

    • The Energy Sector’s OT Cybersecurity Talent Is Retiring Faster Than It Can Be Replaced
      "A ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to bring them online meets encrypted processes and altered configurations. The outage runs into weeks, and the losses travel down the supply chain in both directions. Refineries, chemical plants and pipeline operators carry this exposure across control systems that run 20 to 40 years."
      https://www.helpnetsecurity.com/2026/07/29/ot-cybersecurity-in-energy/

    Healthcare Sector

    Industrial Sector

    • Siemens Desigo CC
      "OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available."
      https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01
    • Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
      "Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available."
      https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-04
    • Siemens Mendix Runtime
      "Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknowingly apply overly permissive access rules to System.User, resulting in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications. A common misconfiguration identified is with the anonymous user role with a System.User entity to gain access to all stored records, even though no access rights are explicitly configured on that role. Siemens recommends Mendix developers to review their access rules based on updated documentation."
      https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-02
    • MikroTik RouterOS And Cloud Hosted Router
      "Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access."
      https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05
    • Siemens SIMATIC S7-PLCSIM Advanced
      "SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available."
      https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-03
    • Igloohome Smart Lock Mobile Application
      "Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services."
      https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-06
    • ABB KNX Update Tool
      "ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully exploited this vulnerability could cause the product to become unusable. ABB confirms the vulnerability but at the same time acknowledges that the issue affects exclusively classic KNX devices that are not supporting the latest KNX Secure standard. Due to a lack of security in legacy KNX devices, the issue cannot be resolved via a software change. In order to actively exploit this vulnerability, an attacker requires physical access to the bus, the affected device is connected to. ABB has no plans of corrective measures."
      https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-07

    New Tooling

    Vulnerabilities

    • RufRoot: The MCP Bridge Vulnerability That Turns Agents Into Rogue Admins (CVE-2026-59726)
      "Noma Labs found a critical (10 CVSS) vulnerability in Ruflo, an open source AI agent orchestration platform with more than 67,000 GitHub stars at the time of this writing and ranked #2 on MCPMarket. Ruflo ships with a chat UI, agent swarms, persistent memory, and MCP-based tool calling. The platform’s MCP Bridge, the Express.js server that handles all tool invocations, exposes 233 tools over HTTP with zero authentication. Noma Labs researchers got one of those tools to run arbitrary shell commands. A single unauthenticated HTTP POST request to port 3001 gave full command execution inside the container. No token, no API key, no header check, no IP allowlist. Nothing."
      https://noma.security/blog/rufroot-the-mcp-bridge-vulnerability-that-turns-agents-into-rogue-admins-cve-2026-59726/
      https://www.darkreading.com/cyber-risk/patch-resistant-rufroot-flaw-malicious-ai-agent-swarms
      https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html
      https://hackread.com/rufroot-vulnerability-attackers-hijack-ruflo-login/
    • Three Critical VMware Flaws Allow Auth Bypass, Code Execution, And VM Escape
      "Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. "A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system," Broadcom said."
      https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html
      https://www.securityweek.com/critical-vm-escape-vulnerability-patched-in-vmware-esxi/
      https://securityaffairs.com/196231/security/broadcom-patches-critical-vmware-esxi-vulnerability-enabling-host-code-execution.html
    • Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files Via Image Uploads
      "Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens. Those secrets may enable remote code execution (RCE) or lateral movement into connected systems. Affected applications use libvips for Active Storage image processing and accept image uploads from untrusted users. Rails selects Vips under load_defaults 7.0, and later defaults retain it."
      https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
    • New Gitea RCE Lets Repository Writers Plant a Git Hook To Run Shell Commands
      "Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The vulnerable API call requires authentication and repository write permission. But Gitea enables registration by default, so an outside visitor can create a normal account and repository on an unchanged installation, then exploit the bug without pre-existing credentials."
      https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html
    • CISA Adds One Known Exploited Vulnerability To Catalog
      "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
      CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability"
      https://www.cisa.gov/news-events/alerts/2026/07/29/cisa-adds-one-known-exploited-vulnerability-catalog
    • Cisco Warns Of FMC Static Credential Flaw Exploited In Zero-Day Attacks
      "Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. The vulnerability is caused by static credentials for a low-privilege account built into Cisco Secure FMC Software. Cisco says an unauthenticated, remote attacker can use these credentials to log in to an affected system and access sensitive data available to the account."
      https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/
    • An AI Agent Can Pass Every Safety Check And Still Leak Secrets
      "A pull request lands with a tidy bug report in the description. A bot reads it before any person does, pulls a few shell commands out of it, gets them approved, and posts the output back on the thread. The maintainer reads the whole exchange the next morning. Elad Meged, a founding engineer at Novee Security, ran that sequence against three vendors’ own repositories, in the configurations those vendors ship by default. Anthropic’s pipeline handed over secrets. Any organization running one of these agents out of the box carries the same exposure."
      https://www.helpnetsecurity.com/2026/07/29/ai-agent-security-safety-check/
    • Android Malware Detection Collapses When The Context Stage Comes Out
      "A phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine learning malware scanner and it comes back flagged. Six Android detectors in wide research use, including Drebin, MalScan, and MaskDroid, produced that result on more than half the apps in a benign test set assembled from 49 Google Play categories. The worst performer, an LLM-based detector called LAMD, flagged 80% of them. Anyone gating an app store, an enterprise deployment, or a build pipeline on those verdicts is working a queue made mostly of legitimate software."
      https://www.helpnetsecurity.com/2026/07/29/android-malware-detection-research/
      https://arxiv.org/pdf/2607.23272
    • Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
      "Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. "No settings or additional user interaction are required," Eten Zou, CEO of Nebula Security, told The Hacker News. "Visiting a malicious webpage is enough to trigger it," Zou said every Tor Browser release that incorporated a vulnerable Firefox version was affected, though researchers have not identified the exact Tor releases."
      https://thehackernews.com/2026/07/researchers-show-single-malicious.html
    • Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
      "On July 22, 2026, Check Point published a security advisory for CVE-2026-16232, an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration. Exploitation requires network access to the Management Server and for a Trusted Clients configuration that does not restrict GUI clients, which in our testing was a default setting. This vulnerability was reported as being exploited in the wild as a zero-day vulnerability at the time of disclosure."
      https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232/
      https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html

    Malware

    • Case Study: Targeted Attack Case On An MS-SQL Server Involving The Installation Of GotoHTTP And SoftEther VPN
      "While monitoring attack cases targeting MS-SQL servers, the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner. While the installation of CoinMiner is common in attack cases targeting MS-SQL servers, in this particular attack case, the attacker installed VShell and GotoHTTP to gain control over the infected system and also installed SoftEther to use it as a VPN server."
      https://asec.ahnlab.com/en/94685/
    • Cleaning Out Inboxes: TA488 Comes For Outlook With Another Half-Click Exploit
      "On 22 July 2026 (the day prior to Proofpoint’s joint release with the NSA), TA488 initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA). Proofpoint did not have sufficient time to analyze, action, and incorporate the new activity into existing reporting, so we are issuing a rapid follow-up to highlight this activity. TA488 used a series of compromised accounts to send emails exploiting a vulnerability in Outlook Webmail. The campaign targeted entities in the government, telecommunications, finance, hospitality, and aerospace sectors. The volume of messages and breadth of targeting is unusual for TA488 and may have been intentionally broad to blend in with mass-mailing spam and avoid scrutiny."
      https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit
      https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/
      https://therecord.media/russia-hackers-outlook-webmail-malware
      https://www.infosecurity-magazine.com/news/ta488-outlook-half-click-owareaper/
    • Amazon Identifies North Korean Hacker Group Behind Open-Source Supply Chain Attacks
      "Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications. Amazon Threat Intelligence has linked several recent compromises of popular Node Package Manager (NPM) libraries to the same DPRK-linked threat actor, a connection that hasn’t been publicly reported until now. The analysis also describes how generative AI is already changing what malicious software packages look like and how threat actors are beginning to probe AI-based code systems. We’re sharing this research to help the open source community and security teams better identify and address these types of events."
      https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/
      https://www.bankinfosecurity.com/north-korea-behind-slew-javascript-supply-chain-hacks-a-32366
      https://cyberscoop.com/amazon-north-korea-open-source-software-attacks/
    • Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon
      "Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure, allowing phishing campaigns to bypass many of the warning signs employees have been trained to recognize. Starting on June 25th through the second week of July, we identified more than 200 phishing emails targeting users across approximately 120 organizations, spanning a wide range of industries and countries worldwide. The messages impersonated Microsoft Teams task notifications from HR and directed recipients to a legitimate Microsoft sign-in page."
      https://blog.checkpoint.com/email-security/attackers-are-turning-microsofts-trusted-login-system-into-their-latest-phishing-weapon/
    • Huntress Threat Advisory: Widespread SonicWall Credential Stuffing Campaign
      "Starting on July 25, 2026, at approximately 18:02:21 UTC, the Huntress SOC detected an out-of-the-ordinary spike in successful SonicWall VPN and firewall logins. These logins originated from a suspicious Autonomous System Number (ASN). We did not observe any post-compromise hands-on-keyboard activity from these attacks. Rather than a highly targeted strike on a single entity, our analysis indicates that this campaign is a broad, opportunistic attack. The threat actors are casting a wide net, systematically validating credentials against remote access portals to compromise as many vulnerable accounts as possible across unrelated organizations."
      https://www.huntress.com/blog/sonicwall-credential-stuffing-campaign
      https://cyberscoop.com/sonicwall-credential-attacks-vpn-firewall/
    • Ad Account Theft: The Digital Advertising Commodity Fueling Global Fraud
      "Over four years, Mimecast has tracked 6.4 million detections of the systematic theft of Meta Business Manager and Google Ads accounts. This is a widespread commodity crime in the advertising ecosystem where threat actors drain business budgets, when possible, but what they really trade on is account reputation. Aged Business Managers and Google Ads accounts with clean spend history are graded, sold, and reused in a mature underground market with tiered pricing, escrow, and money-back warranties. Unlike card fraud, where chargeback and zero-liability protections exist, platforms offer no equivalent — and have a structural financial incentive not to act quickly."
      https://www.mimecast.com/threat-intelligence-hub/ad-account-theft/
      https://www.helpnetsecurity.com/2026/07/29/ad-account-theft-meta-google/
    • Threat Spotlight: LogoKit Phishing Service Becomes a Cloud-Based, Real-Time Deception Platform
      "The evolution of LogoKit highlights how phishing platforms continue to evolve and what this means for defenders and their security strategies. Barracuda researchers have analyzed recent LogoKit campaigns. The attacks feature common phishing themes, such as warnings about passwords or certificates expiring or other access restrictions, delivery failures, timesheet updates, and ICANN email verification notices — but the techniques used are very different."
      https://blog.barracuda.com/2026/07/29/logokit-phishing-service-real-time-deception-platform
      https://www.infosecurity-magazine.com/news/logokit-phishing-real-time/
    • FunFoneFarm And The Off-The-Shelf Scam Economy
      "New research from HUMAN’s Satori Threat Intelligence and Research Team exposes a deep ecosystem enabling threat actors to design, launch, and automate common scams, including romance and adult-content scams, pig-butchering scams, and astroturfed social media accounts. These scams are operated on phone farms sold as kits on open and dark web marketplaces, the farms are automated with AI interfaces, and the scams often use AI in their design and operation, significantly lowering the barrier to entry for would-be threat actors and commoditizing cybercrime."
      https://www.humansecurity.com/learn/blog/funfonefarm-off-the-shelf-scam-economy/
      https://www.infosecurity-magazine.com/news/researchers-aienhanced-phone-fraud/
    • Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, And a New Platform Called Night Dragon
      "While conducting routine open-source research, NetAskari identified a malicious Android APK impersonating a Chinese Provincial Public Security Bureau service app. Analysis of the malware led to a Telegram channel distributing the source code for an undocumented Android application builder and device control framework called Flying Eagle (飞鹰). Hunt.io researchers pivoted on TLS certificates and panel fingerprints to identify 170 servers running the framework, and uncovered a fractured criminal ecosystem built around its leaked codebase."
      https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon
      https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html
      https://www.darkreading.com/endpoint-security/flying-eagle-mobile-rat-builder-china
    • Nine-Year Fraud Campaign Clones Russian Company Sites To Steal Advance Payments
      "Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks. The operation has been ongoing since 2017."
      https://thehackernews.com/2026/07/nine-year-fraud-campaign.html
    • Two Joyfill Npm Beta Releases Compromised To Deliver DEV#POPPER Remote Access Trojan
      "Two npm beta releases in the @joyfill namespace contain an import-time JavaScript implant that resolves encrypted code through Tron, Aptos, and BNB Smart Chain transactions. Static analysis shows that its primary branch reaches a 77 KB Node.js remote-access trojan. A parallel branch launches a detached Node.js process, requests a separate boot payload from 23[.]27[.]13[.]43/$/boot, sends the marker header Sec-V: A9-0135-3, decrypts the response, and evaluates it."
      https://socket.dev/blog/joyfill-npm-beta-releases-compromised
      https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html
    • Distributed Npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers
      "Analysis of a malicious npm package lib-mtop containing a simple downloader malware led to an investigation into a targeted campaign that remained undetected for 3 months. The lib-mtop package, originally published three years ago, had three new versions published at the end of March, 2026. This indicates a potential maintainer account takeover, but the possibility of a maintainer going rogue can’t be excluded. Whichever the case, it is not that relevant for the story, since there was only one version of the lib-mtop package initially published, with no functionality and an insignificant number of downloads."
      https://socket.dev/blog/npm-rat-targets-alibaba
    • Tracking Over 35,000 Fake Sites In The 2026 World Cup Scam Wave
      "From June 11 to July 19, 2026, the 2026 FIFA World Cup took place, co-hosted by the United States, Canada, and Mexico, drawing attention from fans around the world. Large-scale events like this are prime targets for cybercriminals, and online scams exploiting the tournament have been observed worldwide. This article explains the scam techniques TrendAI™ has identified and what internet users should watch out for. It bears emphasizing that these scams merely impersonate FIFA, its affiliated organizations, official tournament partners, and legitimate broadcasters and video streaming services, none of which are in any way involved in the scams themselves."
      https://www.trendmicro.com/en_us/research/26/g/tracking-fake-sites-in-the-2026-world-cup-scam-wave.html

    Breaches/Hacks/Leaks

    • Cloud ShutterGap: Millions Of Cloud Resources Exposed - The Blind Spot CSPM/CNAPP Tools Don’t Cover
      "Aryon's research reveals millions of misconfigured ephemeral cloud resources, publicly exposed for only moments before being removed. Often, these exposures last only a few minutes, long enough for attackers to discover and exploit them, but too short for traditional CSPM and CNAPP tools to detect. Many of these resources contain highly sensitive information."
      https://www.aryon.security/resource/shuttergap-millions-cloud-resources-exposed
      https://www.helpnetsecurity.com/2026/07/29/cspm-blind-spot-report/
    • A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside The NotVPN / SplitVPN Breach
      "On the carding and data-leak forum Altenen (ATN), a long-tenured user operating under the handle vhacker51 posted a thread titled “SplitVPN (NotVPN) 23.4M users, 58M logs, 13.6M devices.” The listing describes the target as “a Russian VPN service for bypassing blocks, with users from Russia, Iran, India, Myanmar,” gives a dump date of 21 July 2026, and offers a compressed SQL file for download. The leak has since been picked up publicly by breach-tracking accounts such as Dark Web Informer. We don’t link to the download, name victims, or reproduce personal data in this write-up. What follows is a verification exercise: does the stolen database actually contain what the seller claims, and what does it reveal about how the service treated its users?"
      https://www.mysteriumvpn.com/blog/news/notvpn-splitvpn-breach-58-million-logs
      https://securityaffairs.com/196197/security/vpn-breach-exposes-58-million-connection-logs-despite-no-logs-claims.html
    • Cyberattack Hits Angola’s Largest Telco Hours Before Landmark Stock Debut
      "Angola’s largest telecommunications operator, Unitel, said Tuesday it was hit by a cyberattack in the early hours of the morning that has left millions of people nationwide without voice services, mobile data, and internet access. The attack struck less than 24 hours before the formerly state-owned company was due to make its landmark debut on the country’s stock exchange. Unitel said it detected the incident shortly after 2 a.m. local time. “Response and containment mechanisms were immediately activated, and technical and cybersecurity teams were mobilized” to mitigate the incident and restore services, the company said."
      https://therecord.media/angola-unitel-cyberattack-outage

    General News

    อ้างอิง
    Electronic Transactions Development Agency (ETDA) 253ec1fb-ee15-4e15-b170-b599f0a9ccb1-image.png

    โพสต์ใน Cyber Security News
  • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 7 รายการ

    Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 7 รายการ เมื่อวันที่ 28 กรกฏาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

    • ICSA-26-209-01 Siemens Desigo CC
    • ICSA-26-209-02 Siemens Mendix Runtime
    • ICSA-26-209-03 Siemens SIMATIC S7-PLCSIM Advanced
    • ICSA-26-209-04 Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
    • ICSA-26-209-05 MikroTik RouterOS and Cloud Hosted Router
    • ICSA-26-209-06 igloohome Smart Lock Mobile Application
    • ICSA-26-209-07 ABB KNX Update Tool

    CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

    อ้างอิง
    https://www.cisa.gov/news-events/ics-advisories 73d87d32-5fa2-4969-881e-1a69bc3a1b68-image.png

    โพสต์ใน OT Cyber Security News
  • Cyber Threat Intelligence 29 July 2026

    Industrial Sector

    Vulnerabilities

    Malware

    • Call Of Duty Mobile Scam Uses Fake Free Points To Steal Player Accounts
      "Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway. Victims are asked to log in with their email address and password to claim free Call of Duty Points (CP), the game’s premium currency. They’re then redirected to a second page asking for their two-factor authentication (2FA) code. The site has no connection to Activision. Its only purpose is to steal the login details needed to take over accounts."
      https://www.malwarebytes.com/blog/threat-intel/2026/07/call-of-duty-mobile-scam-uses-fake-free-points-to-steal-player-accounts
      https://www.helpnetsecurity.com/2026/07/28/call-of-duty-mobile-players-scam/
    • Mirage Kitten Targets Middle East And Africa Region With New Malware
      "Mirage Kitten – also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore – is an advanced persistent threat (APT) group focused on cyber-espionage operations against aerospace, aviation, defense, and telecommunications sectors across the Middle East and Europe, using highly targeted spear-phishing campaigns, fake recruitment portals, and custom multi-stage malware to gain persistent access and exfiltrate sensitive data. During recent threat research, we identified a previously undocumented malware set developed and used by Mirage Kitten. The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture; and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, for covert network access and operator-controlled tunneling."
      https://securelist.com/mirage-kitten-new-tools/120811/
      https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html
    • CubePilot Drone Software Dev Hit By DNS Hijacking To Intercept Traffic
      "CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. Hijacking domain name system (DNS) records allows threat actors to redirect users to their infrastructure, diverting traffic intended for a legitimate service. This exposes users to dangerous scenarios such as sensitive data interception, malware delivery, and phishing. According to a status update published on CubePilot’s website, an attacker gained control of the cubepilot[.]org domain DNS settings on July 24, allowing them to intercept traffic intended for internal systems."
      https://www.bleepingcomputer.com/news/security/cubepilot-drone-software-dev-hit-by-dns-hijacking-to-intercept-traffic/
    • Notes From Underground: Adversarial Prompt Injection
      "AI’s impact on the threat landscape continues to be top of mind for most organizations, both in terms of how malicious actors will leverage the technology in attacks and how defenders will secure their own operationalized AI and agentic applications. Proofpoint Threat Research continues to observe widespread incorporation of large language model (LLM) assisted tooling and generated material into attack chains. This is leading to enhanced scale, velocity, and variability of activity within malicious campaigns. The noted increase of device code phishing frameworks is one good example."
      https://www.proofpoint.com/us/blog/threat-insight/notes-underground-adversarial-prompt-injection
    • Tengu: A Modernized Mirai That Doesn’t Want To Leave
      "Tengu is a modern Mirai-derived IoT malware family that shows how today’s botnets are evolving beyond simple distributed denial-of-service tooling. We selected tengu for deeper analysis because it stood out from the many Mirai-derived samples we track, and because it was surfaced by our machine-learning system for identifying previously unknown malware families. It combines a custom encrypted command-and-control protocol, proxy functionality, payload updates, system and network discovery, and a broad set of denial-of-service capabilities targeting multiple protocols and services. It also includes multiple persistence and self-defense mechanisms designed to keep the malware running on compromised Linux-based devices and make recovery more difficult."
      https://www.nozominetworks.com/blog/tengu-a-modernized-mirai-that-doesnt-want-to-leave
      https://thehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html

    Breaches/Hacks/Leaks

    • Origin Energy Data Breach Affects 900,000 Australians
      "Australian power company Origin Energy Limited said the recent data breach affects 900,000 current and former customers. Origin Energy, which has roughly 4.8 million customers, is one of Australia’s largest electricity and gas retailers. The company recently started investigating a cybersecurity incident and determined that threat actors gained access to customer data, including names, dates of birth, phone numbers, addresses, account information, and partial payment card or bank account numbers."
      https://www.securityweek.com/origin-energy-data-breach-affects-900000-australians/
    • Coordinated Cyberattack Disrupts Water Utilities In 30+ Minnesota Communities
      "More than 30 Minnesota communities saw their water and wastewater utilities disrupted by a coordinated cyberattack on Sunday and Monday, the state’s technology bureau announced Tuesday. Among those was the City of Braham, a community of 1,700 people that brands itself the “Homemade Pie Capital of Minnesota.” Braham officials on Monday morning announced on the city website that its water plant was “offline for an unknown reason” and asked its residents to minimize water use because the city water tower held only a “limited quantity.” A second notice later that day noted that the plant was back online, explaining that the outage had been the result of “a malicious cyber-attack of computerized operating systems by unknown actors.”"
      https://statescoop.com/coordinated-cyberattack-disrupts-water-utilities-in-30-minnesota-communities/

    General News

    • Shadow AI Incident Response Begins With Logs That May Already Be Gone
      "In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound traffic to AI platforms are often gone before responders arrive, and what regulators look for when they assess whether a company did enough. Wityak also discusses the gap between an AI policy in a wiki and a control a company can defend, and when documentation helps or hurts."
      https://www.helpnetsecurity.com/2026/07/28/brandy-wityak-levelblue-shadow-ai-incident-response/
    • For Some, So-Called ‘Skynet Day’ Came Too Close To Sci-Fi After a Rogue Agent Hacked Into a Startup
      "To be fair, James Cameron did warn us. Long before OpenAI broke out of its test corral and hacked into Hugging Face, before the internet and Sam Altman were even born, Cameron wrote a screenplay about an autonomous artificial intelligence system that triggers a nuclear apocalypse. That system, “Skynet,” was solidly science fiction — and, for its day, pure speculation. But four decades after it appeared in “The Terminator,” it looks more like a forecast of the “unprecedented cyber incident” in which a rogue artificial intelligence system hacked into another AI company on its own."
      https://www.securityweek.com/for-some-so-called-skynet-day-came-too-close-to-sci-fi-after-a-rogue-agent-hacked-into-a-startup/
    • Fast Remediation Is The New Trust Model: JFrog And OpenAI Collaboration On Zero-Day Security Findings
      "Just last week, OpenAI and Hugging Face jointly disclosed what may be the first incident of its kind: during an internal evaluation of frontier cyber capabilities, OpenAI’s models, running deliberately without production safeguards in an isolated research environment, autonomously discovered and employed chained vulnerabilities to escape its sandbox, reach the open internet, and extract evaluation answers from Hugging Face’s infrastructure. The industry is right to pay attention. This is a preview of a world where software, not humans, probes, chains, and exploits vulnerabilities at machine speed. We want to share how the JFrog and OpenAI teams collaborate on security incidents to drive them to resolution, and why we believe the outcome demonstrates the trust model the industry now needs."
      https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/
      https://www.bleepingcomputer.com/news/security/openai-models-used-artifactory-zero-days-to-escape-to-the-internet/
      https://thehackernews.com/2026/07/jfrog-confirms-openai-models-exploited.html
    • VulnCheck State Of Exploitation 1H-2026
      "Over the past six months, we’ve seen a significant change in vulnerability discovery and disclosure resulting in a substantial increase in the number of CVEs disclosed. This increase has come with warnings about the increase in vulnerability discovery by Autonomous AI systems, creating a “dangerous” scenario for the software ecosystem. So, I was curious to explore: are more vulnerabilities being discovered and disclosed, resulting in more vulnerabilities being exploited? Is the rate at which vulnerabilities are being exploited faster? Are vulnerabilities being discovered with AI tools more dangerous? Or are we all feeding into the AI-Assisted vulnerability discovery hype cycle?"
      https://www.vulncheck.com/blog/state-of-exploitation-1h-2026
      https://www.bankinfosecurity.com/many-more-bugs-but-exploits-stay-steady-a-32346
      https://cyberscoop.com/ai-assisted-security-tools-are-finding-more-bugs-but-the-threat-level-has-not-changed/
    • IR Trends Q2 2026: Phishing And Weaponized Remote Management Tools Drive Attack Chains
      "Phishing was the primary means of gaining initial access this quarter, appearing in over half of all Cisco Talos Incident Response (Talos IR) engagements – an increase from approximately a third of engagements last quarter. Attackers continued to innovate their delivery methods to evade defenses, deploying QR code-embedded PDFs to bypass traditional email gateways and hosting links on trusted cloud platforms. We also saw a spike in authentication abuse this quarter — observed in 65 percent of engagements compared to 35 percent last quarter — with attackers frequently bypassing or defeating multi-factor authentication (MFA) using adversary-in-the-middle (AitM) proxies, session-token theft, MFA fatigue attacks, and self-enrolled devices, amongst other methods."
      https://blog.talosintelligence.com/ir-trends-q2-2026/
      https://www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/
    • Discovering Cryptographic Weaknesses With Claude
      "Using Claude Mythos Preview, researchers at Anthropic have discovered improved ways to attack cryptographic algorithms (the mathematical methods used to keep online data private). The first attack significantly weakens HAWK, a digital signature scheme that was built for a post-quantum world. The second identifies a new way to attack round-reduced AES, the most widely used symmetric cipher. These are substantial research advances, but they do not currently affect any production systems. This post describes both findings in more detail and discusses the implications for cryptography in an age of powerful AI models."
      https://www.anthropic.com/research/discovering-cryptographic-weaknesses
      https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html
      https://cyberscoop.com/anthropic-claude-mythos-encryption-flaws-hawk-aes-pqc/
    • Ghost Credentials Expose Cloud Systems To Hidden Identity Risks
      "A seemingly minor insider incident last year involving a small, isolated cloud account turned out to be a harbinger of a potentially larger identity problem. When an AI‑enabled workflow agent that had been idle for 30 days suddenly woke up and began firing off API calls at unusual times, it triggered an anomaly investigation. During the course of the investigation, Aleksandr Krasnov, a distinguished security architect at Ducker Tech Consulting, discovered a mesh of "ghost credentials" and non‑human identities — tokens, agents, and service accounts that lived outside traditional trust boundaries but were still able to move laterally through the environment and escalate privileges to access systems."
      https://www.darkreading.com/cloud-security/non-human-identity-sprawl-creates-a-new-cloud-attack-path
    • When AI Agents Escape Sandboxes, Old Security Rules Apply
      "In a world where AI agents can discover vulnerabilities, escape sandboxes, and take autonomous action across networks, organizations should double down on some of cybersecurity's oldest principles. On July 21, OpenAI detailed a security incident in which it took responsibility for a breach against part of Hugging Face's production infrastructure. According to a blog post from the AI giant, a combination of OpenAI agents based on models including GPT‑5.6 Sol as well as "an even more capable pre-release model" broke containment during a sandboxed evaluation intended to quantify said models' cyber capabilities."
      https://www.darkreading.com/application-security/ai-agents-escape-sandboxes-old-security-rules-apply
    • Stronger AI Safety Requires Peeking Inside The 'Black Box'
      "Adding security to AI often treats the large language model (LLM) or AI system as a black box, focusing on analyzing the tokenized inputs and outputs but not what goes on inside the model. The resulting techniques are often complex and individualized to specific models. A group of offensive-security researchers hopes to change that, presenting at the Black Hat USA 2026 in August a model-agnostic approach to activation analysis with standardized rules for processing activation events. Rather than labeling certain activation distributions as "cybercrime" or "hate speech," the approach uses a more granular scheme of cognitive elements (CEs) that can be combined in rules."
      https://www.darkreading.com/cybersecurity-analytics/stronger-ai-safety-requires-peeking-inside-black-box
    • Agentic Browsers Rewind Web Security By 20 Years
      "As business users and developers alike tap into agentic browsers to take work off their plates, the very traits that make them useful are also introducing a whole new class of risks. Security researchers warn that to make it easier for agents to reach across different Web domains to get things done for the user, agentic browsers have "ripped out" some key security mechanisms from the browser. Unsurprisingly, this has opened up every commercial agentic browser out in the market to new attack possibilities that range from account takeover to full-blown browser escape and remote compromise of the underlying system running the browser."
      https://www.darkreading.com/endpoint-security/agentic-browsers-rewind-web-security-20-years
    • Why Resetting Passwords No Longer Stops Attackers
      "The surge in device-code phishing attacks highlights how threat actors are increasingly stealing passwords to target authentication sessions, tokens, and trust relationships that enable them to masquerade as legitimate users and maintain persistent access. Compromised tokens and sessions allow attackers to operate within trusted identity environments, making malicious activity indistinguishable from legitimate user behavior. Device code phishing, for instance, exploits a legitimate sign-in process designed for devices with limited input capabilities, such as smart TVs and Internet of Things (IoT) devices."
      https://www.darkreading.com/endpoint-security/why-resetting-passwords-no-longer-stop-attacks
    • Former Citigroup CISO Blauner On What Makes A Great Security Leader
      "The role of the chief information security officer (CISO) has transformed dramatically over the past three decades, evolving from an emerging technical position into one of the most strategically important leadership roles in business. Few people have witnessed that evolution as closely as Charles Blauner, who served as CISO at JPMorgan, Citigroup, and Deutsche Bank after entering the field at the dawn of information security. In this episode of Heard It From a CISO, Blauner reflects on the influence of Steve Katz, who is regarded as “The Godfather” of the CISO role, and explains how mentorship, collaboration, and a culture of paying it forward helped shape the profession."
      https://www.darkreading.com/cybersecurity-operations/former-citigroup-ciso-blauner-great-security-leader
    • While External Threats Are Driving Security Awareness, Internal Risks Are Growing
      "External threats remain among the primary reasons organizations invest in security awareness and training. Phishing, ransomware, credential theft, social engineering, and attacks on peer organizations all reinforce the same point: Employee behavior directly affects an organization’s cyber risk. According to the Fortinet Training Institute 2025 Security Awareness and Training Global Research Report, 41% of respondents cite external threats as the primary driver for implementing security awareness and training programs. Organizations face a threat landscape shaped by organized cybercrime, ongoing reconnaissance, shorter time-to-exploit, and the growing use of stolen credentials and access paths. These pressures help explain why external threats remain the top motivator for cybersecurity training in 2025."
      https://www.fortinet.com/blog/industry-trends/while-external-threats-are-driving-security-awareness-internal-risks-are-growing
    • Hugging Face Breach Reignites Open-Weights Debate, Raises Liability Questions
      "The first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident post-mortem compiled with the input from Hugging Face and several hundred members of Cloud Security Alliance’s CISO community, the nonprofit organization laid out the most salient points for security leaders and advised on what they should do next."
      https://www.helpnetsecurity.com/2026/07/28/hugging-face-breach-ciso-playbook-open-weight-llms/
    • Hacker Conversations: Tal Kollander’s Journey From Black Hat To Hack Blocker
      "Tal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks. Based in Tel Aviv, Israel, Tal Kollander has the mindset of a hacker (we’re talking specifically about computer hackers). She believes hackers use creative skills to access computers by ‘non-legit’, basically criminal but creative, methods. A hacker to Kollander is anyone who accesses a computer without proper authorization to do so. Hackers are then subdivided by their subsequent actions. A ‘good’ hacker will report findings to the computer owner. “This is what I found. Now go fix it,” explains Kollander. These are white hat hackers."
      https://www.securityweek.com/hacker-conversations-tal-kollanders-journey-from-black-hat-to-hack-blocker/

    อ้างอิง
    Electronic Transactions Development Agency (ETDA) 42c8b188-ea9f-4458-9389-e85ac794737d-image.png

    โพสต์ใน Cyber Security News
  • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 2 รายการลงในแคตตาล็อก

    เมื่อวันที่ 28 กรกฏาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 2 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

    • CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
    • CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

    ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

    อ้างอิง
    https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 67768399-fed7-490b-8f31-1e46a4d9320a-image.png

    โพสต์ใน Cyber Security News
  • Cyber Threat Intelligence 28 July 2026

    Industrial Sector

    New Tooling

    • Nono: Open-Source Sandbox For AI Agents
      "An AI coding agent opens a terminal, reads a config file, and finds a live cloud key sitting in plaintext. It runs with the permissions of the person who launched it. Every file that person can read, the agent reads. Every credential in the environment, the agent can use. That reach is where the damage starts. A prompt injection, a mistyped command, or a hallucinated path points that access at the company’s own credentials and production systems."
      https://www.helpnetsecurity.com/2026/07/27/nono-open-source-ai-agent-sandboxing/
      https://github.com/nolabs-ai/nono

    Vulnerabilities

    Malware

    • New Dysphoria DDoS Botnet Spreads To 200k Devices Worldwide
      "A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. According to QiAnXin XLab cybersecurity researchers, Dysphoria evolved from the ‘jackskid’ and ‘fbot' malware by adding a covert blockchain-based command-and-control (C2) resolution mechanism. Specifically, the botnet uses Ethereum ENS and Solana SNS domains to retrieve infrastructure information, while C2 addresses are concealed inside fake IPv6 strings and recovered using a custom byte-transformation algorithm."
      https://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/
      https://thehackernews.com/2026/07/dysphoria-iot-botnet-adds-blockchain-c2.html
    • MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions
      "We recently came across a sample of MedusaHVNC, a new remote access trojan (RAT) being sold as malware-as-a-service (MaaS). When we took it apart, we found a hidden virtual network computing (HVNC) module that opens a browser on a separate Windows desktop, out of sight of the victim. The browser still runs on the victim’s device, so it can load an existing profile, including cookies and session state. This gives the operator access to live, logged-in sessions while the activity continues to come from the victim’s usual machine."
      https://www.blackfog.com/medusahvnc-a-hidden-desktop/
      https://securityaffairs.com/196111/malware/medusahvnc-trojan-creates-hidden-desktops-to-hijack-browsers-and-steal-data.html
      https://www.securityweek.com/medusahvnc-malware-uses-hidden-windows-desktops-to-evade-detection/
    • Helpdesk Hijackers: Teams Vishing, Quick Assist, And GoGRPC Backdoor
      "Zscaler ThreatLabz has been tracking attacks from a threat actor that is likely an initial access broker for ransomware attacks since January 2026. The threat actor targets organizations by leveraging vishing techniques through Microsoft Teams and deploying a variety of tools including a Go-based backdoor that we named GoGRPC. ThreatLabz has identified at least four variants of GoGPRC that we named Lep, Giver, Pet, and Kind. In some instances, the threat actor has deployed additional malware tools that include a backdoor that we named BlindDoor, a Go-based reverse SOCKS proxy we named RevSocket, a Python-based reverse SOCKS proxy we named PyGRPC, and two other tools we named S3Siphon and RSOX."
      https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor
    • Operation BlueDash: Multi-RMM Workplace Phishing
      "ZeroBEC investigated a live Microsoft Teams-themed phishing operation that began with a "secure document" email and ended with the silent enrollment of the victim endpoint into attacker-controlled remote monitoring and management environments. The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened. The active download delivered supportdev.exe, an Inno Setup-based loader that launched PowerShell in a hidden window, retrieved the official Level RMM installer, and registered the endpoint using an attacker-controlled enrollment secret. The same command attempted to deploy ScreenConnect in parallel, providing a redundant remote-access channel."
      https://zerobec.com/blog/operation-bluedash-multi-rmm-workplace-phishing
      https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html
    • Check And Protect: Analysis Of Telegram Phishing Operation Targeting Exiled Activist
      "In July 2026, RESIDENT.NGO investigated an instance of a cloaked Telegram phishing campaign used against an exiled Belarusian activist living in Lithuania. Delivered in a private Telegram Secret Chat as a fake Telegram security alert, the phishing link led to a convincing Telegram-themed page designed to capture one-time login codes in real time. The operation’s defining feature was not the phishing page itself but its browser- and device-aware cloaking: visitors using browser and platform configurations accepted by the server, together with a syntactically valid token, could receive the phishing interface, while other configurations—including many automated scanners and some common desktop browsers—were shown decoy content or redirected to Telegram’s legitimate website."
      https://resident.ngo/lab/writeups/check-and-protect-analysis-of-telegram-phishing-operation-targeting-exiled-activist/
      https://therecord.media/telegram-belarus-activist-russia-cyberattack
    • DinDoor, DenoRAT, And NightshadeC2: Analyzing TAG-150's Evolving Tradecraft
      "In June 2026, eSentire's Threat Response Unit (TRU) disrupted a malicious ClickFix-style command in a Finance customer's environment. Further investigation found that the command installs DinDoor, a Deno-based loader, DenoRAT, a Deno-based Remote Access Trojan (RAT), and NightshadeC2, a sophisticated RAT and information stealer associated with TAG-150, a threat group active since March 2025."
      https://www.esentire.com/blog/dindoor-denorat-and-nightshadec2-analyzing-tag-150s-evolving-tradecraft
    • APT42: AI-Assisted Rapport Phishing And a More Resilient TAMECAT
      "APT42 continues to refine a familiar operating model, making it harder to detect and easier to scale. Three developments define the current picture. SpearSpecter combined prolonged WhatsApp engagement, Windows search-ms and WebDAV abuse, and a substantially expanded TAMECAT backdoor. APT42 also incorporated generative AI into target research, persona and pretext development, translation, malware engineering, debugging, code generation, and exploitation research. In March 2026, TA453 activity overlapping APT42 targeted a US think tank with a live credential-phishing operation during an active regional conflict."
      https://darkatlas.io/blog/apt42-ai-assisted-phishing-tamecat-analysis

    Breaches/Hacks/Leaks

    • Coca-Cola Confirms Data Theft In Fairlife Ransomware Attack
      "The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. In a short statement earlier today, the global beverages giant says that it is still working to restore some of the impacted systems and operations, but most of the production in the U.S. has been resumed. Coca-Cola disclosed the cyberattack in a filing with the U.S. Securities and Exchange Commission (SEC) on July 16, revealing that a ransomware attack had disrupted production operations at Fairlife."
      https://www.bleepingcomputer.com/news/security/coca-cola-confirms-data-theft-in-fairlife-ransomware-attack/
      https://www.securityweek.com/coca-cola-confirms-data-breach-after-fairlife-ransomware-attack/
    • Ernst & Young Data Breach Claimed By ShinyHunters Extortion Gang
      "The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack. Ernst & Young disclosed the breach earlier this month, saying a third-party support ticket system used by its IT personnel was compromised and support tickets that may contain client tax information were stolen. EY says it detected unusual activity on April 23 and determined that the attacker accessed the platform between March 28 and April 12, downloading multiple documents."
      https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
    • Health System In South Carolina, Georgia Closes Offices After Malware Affects Networks
      "A non-profit health system serving South Carolina and Georgia is dealing with a cyber incident that forced it to close dozens of departments. On Sunday, AnMed published a statement online saying they were “experiencing a cybersecurity disruption involving malware” and were working to restore systems and determine the scope of the incident. Earlier in the day, the company had warned of a phone and internet outage across all of its facilities. The company on Monday published a breakdown of the dozens of facilities and departments that were closed due to the incident. Urgent care services remain open but all imaging, OBGYN and primary care clinics are closed, as well as all medical group offices."
      https://therecord.media/health-system-south-carolina-georgia-disruptions-malware
      https://www.bankinfosecurity.com/malware-attack-forces-anmed-to-close-care-facilities-a-32336
    • Bank Of Baroda Breach Tests Disclosure Readiness
      "India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer and internal data surfaced online. The incident stemmed from the "compromise of an employee's email account, resulting in unauthorized access to certain data," the state-owned lender said in a post on X. The statement followed claims that the Triple X ransomware group published the data on the dark web on July 24. The relatively new group, first observed in May, primarily uses a double-extortion model: stealing data first, then threatening to leak it."
      https://www.bankinfosecurity.com/bank-baroda-breach-tests-disclosure-readiness-a-32335
    • DentaQuest Data Breach Potentially Impacts Over 23 Million People
      "Dental and vision benefits administrator DentaQuest is notifying millions of people that their personal and dental health information might have been stolen in a data breach. The incident was discovered on May 20, and DentaQuest’s investigation determined that the hackers had access to the organization’s network between May 17 and May 20. During the timeframe, the attackers accessed information such as names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, benefits provider names, diagnosis, treatment details, and billing information."
      https://www.securityweek.com/dentaquest-data-breach-potentially-impacts-over-23-million-people/
      https://securityaffairs.com/196100/data-breach/dentaquest-disclosed-a-data-breach-that-impacted-23-million-individuals.html
    • MCBS Data Breach Affects 1.2 Million Individuals
      "A data breach suffered last year by Atlanta-based medical business management company MCBS (Medical Computer Business Services) affects more than 1.2 million individuals. According to a data breach notification posted on its website, MCBS was targeted by hackers in September 2025. An investigation showed that attackers had access to its systems between September 22 and September 26, potentially stealing files that contained personal information such as name, address, SSN, date of birth, health insurance information, and medical information."
      https://www.securityweek.com/mcbs-data-breach-affects-1-2-million-individuals/

    General News

    • The Branding And Attribution Behind Cybercrime
      "Threat actor names can sound simple. LockBit. Fancy Bear. BlackCat. Scattered Spider. Anonymous Sudan. Each name gives the impression of a clear group with a defined identity. In threat intelligence, however, the name is rarely the whole story. Some names are chosen by attackers. Others are assigned by researchers, security vendors, governments, or public databases. One name may represent a ransomware brand, a hacktivist identity, a research label, a campaign, a malware family, or an activity cluster observed across different incidents."
      https://blog.checkpoint.com/exposure-management/the-branding-and-attribution-behind-cybercrime/
    • APTs Top The List Of Most Active Threat Actors In H1 2026
      "You may have heard your peers say, “Cybercrime has become industrialized.” But did you have any proof? We do. Cyble Research and Intelligence Labs (CRIL) closed out its tracking for the first half of 2026 with a deep analysis of the Global Threat Landscape spanning ransomware, initial access brokers, data breaches and leaks, nation-state espionage, and hacktivism, among others."
      https://cyble.com/blog/most-active-threat-actors-h1-2026/
    • FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
      "Undermining affiliates' trust and strong international partnerships were the keys to dismantling LockBit, one the most successful ransomware-as-a-service (RaaS) groups of its time, which at its peak was responsible for a quarter of all ransomware attacks. LockBit operated primarily between 2020 and 2024, and Brett Leatherman, assistant director of the FBI's Cyber Division, tells Dark Reading that during its time it victimized more than 2,500 organizations across at least 120 countries, with more than 1,800 of these attacks occurring in the US. Overall, the group collected more than $500 million in ransom payments, and the group and its leader, a Russian national named Dmitry Yuryevich Khoroshev, seemed invincible."
      https://www.darkreading.com/cybersecurity-operations/fbi-breaking-affiliate-trust-lockbit-takedown
    • Adversaries Don't Need a Zero-Day — They Read Your Rulebook
      "Recently, Robert Lemos reported in Dark Reading that confidence in autonomous penetration testing is falling: The share of organizations willing to rely on it dropped to 9% in 2026, down from 29% a year earlier, according to a Cobalt report. Companies are still experimenting with AI systems that hunt for weaknesses, but far fewer are leaning on them the way they did a year ago. The obvious explanation is that the technology overpromised and is now settling into a trough. I think something more specific is going on, and it carries a lesson that applies to autonomous defense just as much as offense."
      https://www.darkreading.com/threat-intelligence/adversaries-do-not-need-zero-day-they-read-your-rulebook
    • Ransomware Evolution Report Q22026
      "Q2 2026 recorded 1,988 attack claims from 89 groups across 101 countries. The quarter was defined by a change at the top of the ecosystem, tooling built to blind security products, and the arrival of AI inside the attack chain. TheGentlemen overtook its former parent group for the lead by June. Qilin still finished the quarter ahead on volume but lost ground each month, while DragonForce and a resurgent LockBit rounded out a reshaped top tier. Among the key trends observed, the disabling of endpoint defenses shifted from edge case to standard practice across the ecosystem, and Iran-linked actors expanded their use of ransomware as cover for state objectives."
      https://www.halcyon.ai/ransomware-evolution-report/q2-2026
      https://www.infosecurity-magazine.com/news/ransomware-q2-2026-edr-kill/
    • Most Smart Watches, Rings, And Bands Lack Basic Transparency Reports And Key Privacy Features
      "Oura Rings, Garmin GPS fitness watches, Apple Watches, Whoop bands—every year, more and more tech devices are promising to monitor our health and fitness, guide us toward healthier living, and provide useful health metrics to take to our doctors. But few of these tools provide the sorts of privacy and security promises we demand from all technology, let alone tech that captures personal health data. It’s time they step up and start providing transparency reports and stronger encryption options."
      https://www.eff.org/deeplinks/2026/07/most-smart-watches-rings-and-bands-lack-basic-transparency-reports-and-key-privacy
      https://securityaffairs.com/196085/security/eff-most-smart-wearables-still-fall-short-on-privacy-and-transparency.html
    • LockBit5 And Qilin Lead Ransomware Attacks Against Italian Organizations
      "Six months, 148 confirmed ransomware claims against Italian targets, and one sector taking the brunt of it. That’s the headline number from a new semi-annual tracker compiled by ransomNews under its RedACT project, which pulls together OSINT and SOCMINT sources to build a manual, deduplicated picture of who’s getting hit and by whom. The pace works out to roughly 25 claims a month, just under six a week. Attackers claim to have exfiltrated over 13,400 GB of data across the period, though that figure only covers 64 of the 148 cases; where a volume is actually disclosed, it averages around 61 GB. Read that gap as a reminder that leak-site numbers are marketing copy from criminals, not audited disclosures."
      https://securityaffairs.com/196045/security/lockbit5-and-qilin-lead-ransomware-attacks-against-italian-organizations.html

    อ้างอิง
    Electronic Transactions Development Agency (ETDA) e338a97e-9ec9-4c73-b016-d5072d145ed7-image.png

    โพสต์ใน Cyber Security News
  • พบการโจมตีผ่าน Wi-Fi โรงแรม มุ่งขโมยข้อมูลบัญชี Microsoft 365

    พบการโจมตีผ่าน Wi-Fi โรงแรม มุ่งขโมยข้อมูลบัญ.png

    สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 66e2ff25-e204-4b94-9248-38f6eba77333-image.png

    โพสต์ใน Cyber Security News