NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ

    Cyber Threat Intelligence 23 July 2026

    Cyber Security News
    1
    1
    5
    โหลดโพสเพิ่มเติม
    • เก่าสุดไปยังใหม่สุด
    • ใหม่สุดไปยังเก่าสุด
    • Most Votes
    ตอบ
    • ตอบโดยตั้งกระทู้ใหม่
    เข้าสู่ระบบเพื่อตอบกลับ
    Topic นี้ถูกลบไปแล้ว เฉพาะผู้ใช้งานที่มีสิทธิ์ในการจัดการ Topic เท่านั้นที่จะมีสิทธิ์ในการเข้าชม
    • NCSA_THAICERTN
      NCSA_THAICERT
      แก้ไขล่าสุดโดย

      Financial Sector

      • Beyond The Vault: What Banking Sites Quietly Share Before You Ever Log In
        "Banks present themselves as the most careful custodians of personal and financial data. Customers expect that trust to extend to every digital interaction including public websites and online application flows. Yet Jscrambler’s Security Research Team found that many banking experiences transmit sensitive information to third-party advertising, analytics, and personalization platforms. In many cases, the data leaves the browser before the user has made a consent choice. In others, it continues to flow even after users have rejected tracking technologies."
        https://jscrambler.com/blog/beyond-the-vault-what-banking-sites-share
        https://www.darkreading.com/data-privacy/eu-financial-institutions-cookie-trackers
        https://www.bankinfosecurity.com/pixels-tracking-every-loan-you-take-on-eu-bank-websites-a-32296

      Industrial Sector

      • Federal Agencies Broaden Alert On Iran-Linked OT Attacks
        "The federal government has expanded a warning that it issued in April about attacks on internet-facing operational technology (OT) by hackers affiliated with the Iranian regime. The initial advisory focused on programmable logic controllers (PLCs) from manufacturers Rockwell Automation and Allen-Bradley. Wednesday’s revision “expands the manufacturer scope to include observed targeting of Schneider Electric, Siemens and possible other PLC manufacturers,” according to a news release from CISA."
        https://therecord.media/federal-agencies-broaden-alert-on-iran-linked-ot-attacks

      New Tooling

      • Snowpick: Open-Source ServiceNow Exposure Scanner
        "An employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and get records back. Bishop Fox ran that test across 166 ServiceNow instances during authorized penetration tests. The firm published the results along with the Go tool it used, Snowpick."
        https://www.helpnetsecurity.com/2026/07/22/servicenow-data-exposure-snowpick-open-source-scanner/
        https://github.com/BishopFox/snowpick
      • Now In Preview: Find And Fix Software Vulnerabilities With CodeMender
        "As adversarial AI threats accelerate attacks on code, security teams must counter them with machine-speed defenses that can automate code remediation and fight AI with AI. CodeMender is our managed code security agent, and starting today, we're bringing its code scanning and remediation capabilities directly to you in preview. CodeMender offers access to our generally available models via Gemini Enterprise Agent Platform, or it can be deployed as a core component of AI Threat Defense."
        https://cloud.google.com/blog/products/identity-security/find-and-fix-software-vulnerabilities-with-codemender
        https://www.infosecurity-magazine.com/news/google-codemender-available-ai/

      Vulnerabilities

      • Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
        "Oracle has patched more than 1,400 vulnerabilities with its July 2026 Critical Patch Update (CPU), with a vast majority of the flaws likely identified by artificial intelligence. According to Oracle, the latest quarterly CPU includes 1,449 security patches, addressing 1,434 unique CVEs across 334 products. Vulnerabilities have been patched in products such as Database Server, APEX, Autonomous Health Framework, Essbase, Global Lifecycle Management, GoldenGate, NoSQL Database, Spatial Studio, SQL Developer, TimesTen In-Memory Database, Application Testing Suite, Commerce, Communications, Construction and Engineering, and E-Business Suite."
        https://www.securityweek.com/oracle-patches-over-1400-vulnerabilities-with-quarterly-security-updates/
        https://www.oracle.com/security-alerts/cpujul2026.html
      • CVE-2026-8933: Local Privilege Escalation In Set-Capabilities Snap-Confine
        "The Qualys Threat Research Unit (TRU) has identified a Local Privilege Escalation (LPE) vulnerability in snap-confine (CVE-2026-8933). This flaw allows an unprivileged local user to gain full root access on default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The issue stems from a security hardening change that inadvertently introduced a race condition during sandbox initialization."
        https://blog.qualys.com/vulnerabilities-threat-research/2026/07/21/cve-2026-8933-snap-confine-local-privilege-escalation
        https://thehackernews.com/2026/07/ubuntu-snap-confine-flaw-could-give.html
        https://www.infosecurity-magazine.com/news/ubuntu-snap-confine-local-root-cve/
        https://hackread.com/ubuntu-desktop-vulnerability-local-access-root-control/
        https://securityaffairs.com/195833/security/cve-2026-8933-ubuntu-security-flaw-breaks-snap-sandbox-protections.html
      • Security Advisory – Action Required – July 2026 Security Update
        "As part of Check Point’s Frontier AI Readiness Program, we are releasing a jumbo hotfix with security and hardening fixes for our firewall and management products. This update includes a number of security hardening improvements and fixes, the most significant of which are outlined below. During a routine BLAST review, we discovered a few vulnerabilities. Following a thorough analysis, we identified one of those in the wild, affecting a handful of customers. This only affects a very specific configuration — when Management is exposed directly to the internet without IP restrictions. We’ve already notified the affected customers."
        https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/
      • When Your AI Reviewer Works For The Attacker: A Confused-Deputy Bug In Microsoft's Azure DevOps MCP Server
        "An invisible comment in an Azure DevOps pull request can turn a developer's own AI agent against them. Microsoft ships an official Azure DevOps MCP server that lets AI agents read and act on Azure DevOps (pull requests, pipelines, wikis, work items) on the user's behalf. An attacker with access to a single project can hide instructions inside an HTML comment, invisible in the Azure DevOps UI, delivered verbatim into the agent's context. When a victim asks their agent to review the PR, the hidden instructions hijack the agent's goal. Because the agent is holding the victim's credentials, it performs actions across projects the attacker can't reach on their own."
        https://www.manifold.security/blog/azure-devops-mcp-server-vulnerability
        https://thehackernews.com/2026/07/microsoft-azure-devops-mcp-flaw-lets.html
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability
        CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/07/22/cisa-adds-two-known-exploited-vulnerabilities-catalog
      • New InfraTrust Report Reveals Infrastructure Flaws Admins Should Patch First
        "Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. The monthly report aggregates security advisories from major infrastructure vendors and highlights the vulnerabilities administrators should prioritize based on a flaw's exploitability, exposure, and real-world risk rather than severity scores alone."
        https://www.bleepingcomputer.com/news/security/new-infratrust-report-reveals-infrastructure-flaws-admins-should-patch-first/
        https://pulse.infra-trust.org/july-2026/
      • HermeticReader: The Vulnerability That Turned Adobe's 300M-Install Extension Into a Full WhatsApp Takeover
        "A single click on a malicious web page could turn the Adobe Acrobat Chrome extension, installed on roughly 329 million browsers, into a one-click WhatsApp exfiltration tool, quietly handing a visitor's entire WhatsApp clear-text chats, contacts, and private info to the attacker's hands. Here at Guardio Labs we uncovered a chain of vulnerabilities in the extension that compounds into a single powerful cross-origin exfiltration chain. A working, runtime-confirmed exploit followed within hours, thanks to our AI harness specially built to secure the browser extensions domain. Adobe's response to our full disclosure was phenomenal: acknowledged, patched, and shipped over a single weekend, with CVE-2026-48294 issued days later."
        https://guard.io/labs/hermeticreader---the-vulnerability-that-turned-adobe-300m-install-extension-into-a-full-whatsapp-takeover
        https://www.bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-let-sites-access-private-whatsapp-chats/
        https://thehackernews.com/2026/07/adobe-acrobat-extension-flaw-let.html
        https://www.securityweek.com/flaw-in-adobe-extension-with-300m-installs-enabled-whatsapp-data-theft/
        https://securityaffairs.com/195805/hacking/adobe-acrobat-chrome-extension-bug-enabled-silent-whatsapp-data-theft.html
      • Hackers Exploit Windmill Flaw To Read Arbitrary Server Files Without Authentication
        "A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log_file" endpoint ("/api/w/{workspace}/jobs_u/get_log_file/{filename}")."
        https://thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html
      • Open Directory Stages NGINX Rift And Ghost CMS Exploits Against Government And Finance Across Eleven Countries
        "NGINX sits in front of a large share of the internet's web traffic and Ghost CMS powers well over 100,000 publishing sites. Within months of each other earlier this year, critical vulnerabilities were found in both: NGINX Rift (CVE-2026-42945), a long-standing heap overflow in the rewrite module, and a blind SQL injection in the Ghost Content API (CVE-2026-26980). Exploit code for both became public quickly. What we found was a single host staging them alongside five other exploits, wired to confirm its own hits over out-of-band callbacks."
        https://hunt.io/blog/open-directory-nginx-rift-ghost-cms-multi-cve
      • Langflow Exploited To Build Custom DDoS Gafgyt Botnets
        "The cybersecurity world spent the last few years worrying about advanced AI threats — such as automated phishing, deepfakes, and autonomous malware. However, threat actors are proving that their immediate goals are much more pragmatic. They don't just want to manipulate AI; they want to hijack its underlying infrastructure to fuel traditional, high-volume cybercrime. Recent threat intelligence reveals a fascinating intersection of modern AI deployment and classic botnet architecture: Attackers are actively exploiting CVE-2025-3248 (an RCE vulnerability in Langflow) to drop a highly customized variant of the veteran Gafgyt/BASHLITE DDoS bot. In this blog post, I’ll describe how attackers are actively exploiting CVE-2025-3248 to turn cutting-edge AI frameworks into brute-force network weapons."
        https://www.akamai.com/blog/security-research/2026/jul/langflow-exploited-build-custom-ddos-gafgyt-botnets

      Malware

      • The Perfect Heist: NuGet Typosquat Targets Betting Platform To Rig Results
        "The JFrog Security Research team has discovered and disclosed a typosquatted NuGet package named Newtonsoftt.Json.Net. Note the double t and the .Net suffix. This package has been masquerading as the popular Newtonsoft.Json library while quietly shipping a trojanized fork. The trojan rigs Digitain, an online betting platform, and in later generations, exfiltrates rigged round results to an attacker-controlled server, utilizing the header X-Seq-ApiKey: theperfectheist2025. The author published seven versions under the same package, all sharing the same target-specific payload."
        https://jfrog.com/blog/nuget-typosquat-targets-betting-platform/
        https://thehackernews.com/2026/07/trojanized-newtonsoftjson-fork-hides.html
      • Denying The Worm: Detecting SANDWORM_MODE And The Emerging Class Of AI Toolchain Supply Chain Attacks
        "In February 2026, Socket.dev published research on a multi-stage npm supply chain worm operating under the internal flag SANDWORM_MODE. The campaign spanned 19 malicious packages in total across two unique publisher aliases and demonstrated a new class of supply chain attacks that targeted AI-augmented development workflows. Many recently observed supply chain attacks target build outputs, inject static backdoors, or conduct mass credential harvesting, but SANDWORM_MODE was unique in its exploitation of the runtime behaviors of AI coding assistants, CI automation, and LLM toolchains."
        https://www.crowdstrike.com/en-us/blog/denying-the-worm-sandworm-mode-and-ai-toolchain-supply-chain-attacks/
        https://www.darkreading.com/cyber-risk/attackers-live-off-ai-toolchain
        https://cyberscoop.com/sandworm-mode-malware-ai-supply-chain-crowdstrike/
      • How a Fake Bahrain Civil-Defense App Turns a Phone Into a Listening Post
        "Throughout July and including the day that this article is being published, Gulf states, including Bahrain and Kuwait have been activating civil-defense sirens and public-safety guidance for residents in the wake of Iranian missiles. During active air-defense events, official emergency-alert applications see sharp spikes in install demand. Some actors treat that demand as a distribution opportunity. On July 17, Dream researchers analyzed an Android application that impersonates a Bahraini Civil Defense “BH Alert” siren app."
        https://dreamgroup.com/blog/how-a-fake-bahrain-civil-defense-app-turns-a-phone-into-a-listening-post
        https://www.darkreading.com/mobile-security/fake-bahrain-alert-apps-android-surveillance-malware
      • Inside a TrickBot Variant Using DNS Tunneling For C2
        "FortiGuard Labs recently captured several malicious samples that were sending malformed DNS queries. After conducting an in-depth analysis, I determined that these samples are TrickBot variants that use DNS tunneling to communicate with their command-and-control (C2) servers. TrickBot is a modular malware family that FortiGuard Labs has repeatedly captured over the past decade. Its modular architecture enables it to extend its capabilities by downloading and executing additional modules on compromised devices. Previously observed TrickBot variants primarily relied on HTTP to communicate with its C2 servers."
        https://www.fortinet.com/blog/threat-research/inside-a-trickbot-variant-using-dns-tunneling-for-c2
        https://www.infosecurity-magazine.com/news/trickbot-dns-tunneling-c2/
      • Analysis Of Kimsuky's Attack On a South Korean Groupware Vendor Using a New Gomir Family Variant
        "The ENKI WhiteHat Threat Research Team tracked a campaign by Kimsuky, a North Korea-linked threat group, that infiltrated the internal networks of South Korean groupware vendors between 2025 and early 2026. Our analysis revealed that Kimsuky gained control of internet-facing servers through vulnerability exploitation and spear-phishing, and deployed Gomir and its variants. Kimsuky developed Gomir variants with significantly altered C2 communication methods to evade detection, including leveraging Google Drive as a C2 channel and implementing a new custom protocol. We also observed indicators of aggressive lateral movement, including compromising customer servers that used the affected vendors' groupware and tampering with groupware login pages to harvest employee credentials."
        https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant
        https://therecord.media/kimsuky-north-korea-espionage-groupware-companies
      • Device Code Phishing: Turning a Convenience Feature Into An MFA Bypass
        "For years, the advice to users was simple: turn on multi-factor authentication (MFA), and most account takeovers can be prevented. That advice still holds, and MFA still blocks most password-based attacks. The problem is that attackers adapt, and the more an organization relies on a single control, the more attention that control attracts. The first big shift was adversary-in-the-middle phishing, where a proxy site sits between the user and Microsoft and relays the login in real time to capture the session cookie. Device code phishing is the next step, and in some ways, it is cleaner for the attacker. There is no fake login site to build or to get blocked, and there is nothing visually wrong for the user to notice, because the page they enter their password on really is Microsoft. The only unusual thing is a short code and a plausible reason to enter it."
        https://www.trendmicro.com/en_us/research/26/g/device-code-phishing.html

      Breaches/Hacks/Leaks

      • Chick-Fil-A Discloses Data Breach After Credential Stuffing Attacks
        "American fast food restaurant chain Chick-fil-A is notifying an undisclosed number of customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. Self-described as the third-largest quick-service restaurant company in the United States, Chick-fil-A operates a network of more than 3,000 restaurants and provides catering services across the U.S., Canada, Puerto Rico, the United Kingdom, and Singapore. The company revealed in data breach notification letters sent to affected individuals and filed with multiple Attorney General offices that it detected the attacks after identifying suspicious login activity to certain Chick-fil-A One accounts."
        https://www.bleepingcomputer.com/news/security/chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks/
        https://www.malwarebytes.com/blog/data-breaches/2026/07/chick-fil-a-loyalty-accounts-hijacked-using-stolen-passwords
      • OpenAI Says Its AI Models Hacked Hugging Face During Testing
        "OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. As the company explained, instead of focusing on finding a solution for the ExploitGym public AI cybersecurity benchmark on their own, the AI models tried to cheat by stealing the test solutions by hacking Hugging Face after inferring that they could get the test solutions directly from its production database. In one of their attempts, the OpenAI agents chained zero-day vulnerabilities and used stolen credentials to find a remote code execution attack vector while trying to gain access to Hugging Face servers."
        https://www.bleepingcomputer.com/news/security/openai-says-its-ai-models-hacked-hugging-face-during-testing/
        https://openai.com/index/hugging-face-model-evaluation-security-incident/
        https://thehackernews.com/2026/07/openai-says-its-own-ai-models-escaped.html
        https://therecord.media/openai-cyberattack-hugging-face
        https://www.darkreading.com/cyber-risk/openai-models-autonomously-hack-hugging-face
        https://www.infosecurity-magazine.com/news/open-ai-hacked-another-company/
        https://www.securityweek.com/openai-says-its-ai-models-broke-loose-and-hacked-hugging-face/
        https://securityaffairs.com/195774/ai/openai-ai-models-exploited-zero-days-to-reach-hugging-face-in-benchmark-test.html
        https://hackread.com/openai-models-breached-hugging-face/
        https://www.helpnetsecurity.com/2026/07/22/hugging-face-breach-openai-testing/
      • Upbound Says Hack Caused $13 Million In Fraudulent Acima Leases
        "The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. In a filing with the U.S. Securities and Exchange Commission (SEC), the company says that it "experienced cybersecurity incidents in which certain non-sensitive customer information and other documents were obtained without authorization." The threat actor used the information to commit fraud in lease-to-own agreements, resulting in financial losses of about $13 million in the Acima segment in the second quarter of this year."
        https://www.bleepingcomputer.com/news/security/upbound-says-hack-caused-13-million-in-fraudulent-acima-leases/
      • South Korea Discloses Data Breach Impacting Diplomats Worldwide
        "South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. The incident occurred in April 2025 after an unknown threat actor exploited a vulnerability in the Academy's server. It impacts at least 6,000 individuals, 350 of them being current government attachés dispatched abroad. The education platform was set up in 2022 to support remote training during the COVID-19 pandemic, and has since been used for government personnel training and video-conferencing."
        https://www.bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide/
      • Swiss Rail Giant Stadler Rejects $12.3M Ransom Demand After Cyberattack
        "Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. The threat actor has not publicly claimed the attack, but the Swiss company says that it received an extortion letter from Everest ransomware asking for a ransom of 10 million Swiss francs. The company responded by saying that it will not pay the threat actor and filed a criminal complaint with the Thurgau cantonal police."
        https://www.bleepingcomputer.com/news/security/swiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack/

      General News

      • Security Issues In The Korean & Global Financial Sector In June 2026
        "In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third Attack Stage, demonstrating that multi-stage attack chains—progressing from the initial distribution of bait to the installation of additional malware and ultimately to Information Theft—are widely used."
        https://asec.ahnlab.com/en/94543/
      • Small Teams Are The Heaviest Users Of AI Coding Agents
        "The pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to read it. On GitHub that somebody is usually one developer sitting alone with the diff, and the rest of the project never sees the code. Maliha Noushin Raida and Daqing Hou at Rochester Institute of Technology sorted 25,264 agentic pull requests by who reviewed them and who committed to them. The repositories all carry at least 100 stars, the agents are the ones most developers have already met, GitHub Copilot and OpenAI Codex and Claude Code, and the window runs from May through July 2025."
        https://www.helpnetsecurity.com/2026/07/22/users-of-ai-coding-agents/
      • Security Teams Keep Finding Critical Flaws After Scheduled Testing Ends
        "Enterprise environments change between scheduled security assessments, leaving organizations with periods where new vulnerabilities can go undetected. Synack’s State of Continuous Security Validation report found that 95% of surveyed organizations identified high- or critical-severity vulnerabilities outside planned testing windows during the past year, with 42% encountering them at least once a month."
        https://www.helpnetsecurity.com/2026/07/22/continuous-security-testing-gaps-report/
      • Cloud Operations Become The Next Big Role For Agentic AI
        "Companies are using agentic AI to manage growing application environments, automate routine tasks, and support decisions. Business and IT leaders increasingly see the technology as part of cloud application management, according to Unisys’ AI & Cloud Insights Report. Most organizations remain in testing or early deployment. Nearly one quarter have started scaling agentic AI across business functions. Early uses center on employee productivity and cloud management. Spending plans show continued interest, with half of respondents planning higher investment during the next year."
        https://www.helpnetsecurity.com/2026/07/22/agentic-ai-cloud-operations-report/
      • Vibe-Coded Apps Riddled With Exploitable Security Flaws
        "Vibe-coding is increasing. Vibe-coded apps tend to be buggy. Is this a worrying sign for the future? Vibe coding, the use of AI to assist or perform code generation, is increasing dramatically. In May 2026, Hostinger reported, “90% of developers regularly use at least one AI tool at work as of January 2026.” This is likely to increase through the basic business pressure that applies to everything: we need more, faster and cheaper. But while vibe coding is increasing in volume, so are concerns over the security of vibe-developed apps."
        https://www.securityweek.com/vibe-coded-apps-riddled-with-exploitable-security-flaws/
        https://go.xint.io/the-top-security-vulnerabilities-generated-by-ai-code
      • When Identity Verification Fails: Lessons From a Real-World SIM Swap And Near Account Takeover
        "For years, organizations have encouraged users to enable multi-factor authentication (MFA), use one-time passwords (OTPs), and protect their accounts with passcodes. Those controls remain important. However, a recent attack against my own wireless services account demonstrated that point-in-time authentication is no longer sufficient against determined identity-focused adversaries. What began as a seemingly routine customer service call quickly evolved into a coordinated attack that combined social engineering, identity impersonation, stolen personal information, SIM swapping, session hijacking, and unauthorized account changes."
        https://www.securityweek.com/when-identity-verification-fails-lessons-from-a-real-world-sim-swap-and-near-account-takeover/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 0ab0f750-7528-4021-968d-eeaac841a990-image.png

      1 การตอบกลับ คำตอบล่าสุด ตอบ คำอ้างอิง 0
      • First post
        Last post