NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ

    Cyber Threat Intelligence 24 July 2026

    Cyber Security News
    1
    1
    17
    โหลดโพสเพิ่มเติม
    • เก่าสุดไปยังใหม่สุด
    • ใหม่สุดไปยังเก่าสุด
    • Most Votes
    ตอบ
    • ตอบโดยตั้งกระทู้ใหม่
    เข้าสู่ระบบเพื่อตอบกลับ
    Topic นี้ถูกลบไปแล้ว เฉพาะผู้ใช้งานที่มีสิทธิ์ในการจัดการ Topic เท่านั้นที่จะมีสิทธิ์ในการเข้าชม
    • NCSA_THAICERTN
      NCSA_THAICERT
      แก้ไขล่าสุดโดย

      Vulnerabilities

      • New RefluXFS Linux Flaw Lets Attackers Gain Root Privileges
        "A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. Dubbed RefluXFS by the Qualys Threat Research Unit (TRU), which found and reported it, the security flaw affects systems with an XFS filesystem with reflink enabled (a default configuration on major enterprise Linux distributions), running Linux kernel v4.11 or later, with a directory writable by an unprivileged local user, and a high-value target (a root-owned configuration file or SUID-root binary)."
        https://www.bleepingcomputer.com/news/linux/new-refluxfs-linux-flaw-lets-attackers-gain-root-privileges/
        https://cdn2.qualys.com/advisory/2026/07/22/RefluXFS.txt
        https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-gives.html
      • SharedRoot; Escaping The Claude Cowork Sandbox
        "Untrusted content in a Claude Cowork session can escape the VM it's sandboxed in and read and write files anywhere on your Mac. The kernel bug that makes it possible isn't the interesting part. Four design decisions are, and they'd have stopped the next kernel bug too."
        https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/
        https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html
      • Millions Of Cars Could Be Tracked And Unlocked By a Hidden Security Flaw
        "A car alarm vendor’s coding mistake has left millions of vehicles vulnerable to theft and location tracking. Thanks to the way dealers sell car alarms, many affected drivers don’t even know they have one installed. The device is the KARR Security System, a Bluetooth-enabled aftermarket alarm built by Acrisure Protection Group. It’s installed by dealers, primarily at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California."
        https://www.malwarebytes.com/blog/bugs/2026/07/millions-of-cars-could-be-tracked-and-unlocked-by-a-hidden-security-flaw

      Malware

      • Attack Cases By The Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)
        "AhnLab SEcurity intelligence Center (ASEC) previously disclosed an attack case in which the Kimsuky group used spear phishing attacks to install the PebbleDash malware in a post titled “Analysis of the Kimsuky Group’s Latest Attacks Exploiting PebbleDash and RDP Wrapper” [1]. The same threat actors have continued their activities in 2026 and have recently been conducting spear phishing attacks by impersonating diplomatic personnel. These spear phishing attacks utilize LNK malware to install various tools, including the PebbleDash backdoor, the PrxClient proxy malware, RDP Wrapper, UACMe, and KeyLogger. The decoy document files created during the attack process contain diplomatic-related content."
        https://asec.ahnlab.com/en/94552/
      • New Dolphin X Malware Uses AI To Rank High-Value Targets
        "A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. The malware was analyzed by Varonis Threat Labs researcher Daniel Kelley, who spotted it being advertised on a cybercrime forum by a vendor using the alias "Kontraktnik," promoting it as an all-in-one remote access trojan. According to Varonis, the operator panel lists 329 features across ten categories, including a credential-stealing feature that claims to target more than 300 applications."
        https://www.bleepingcomputer.com/news/security/new-dolphin-x-malware-uses-ai-to-rank-high-value-targets/
        https://www.infosecurity-magazine.com/news/new-dolphin-x-stealer-ai-targets/
      • Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations With SectopRAT
        "Between July 21 and July 22, 2026, Huntress' Security Operations Center (SOC) lit up with a swathe of unusual executable installs, Defender exclusions, and anomalous persistence across 29 organizations, all coming from ClaudeDesktop.exe. The attacks had one common denominator: victims had searched for the Claude desktop app and were taken to a malicious public Claude Artifact on the actual Claude AI domain, which appeared to be a legitimate download link for the desktop app."
        https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat
        https://www.bleepingcomputer.com/news/security/fake-claude-app-promoted-by-bing-ads-pushes-sectoprat-malware/
        https://www.helpnetsecurity.com/2026/07/23/anthropic-claude-artifacts-download-malware/
      • Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users Of Zimbra Collaboration Suite
        "A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecurity industry tracking), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD)."
        https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a
        https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF
        https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits
        https://unit42.paloaltonetworks.com/russian-webmail-espionage/
        https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/
        https://thehackernews.com/2026/07/russian-espionage-group-exploited.html
        https://www.darkreading.com/cyberattacks-data-breaches/russian-hackers-zimbra-zero-day-us-ukraine-targets
        https://therecord.media/zimbra-webmail-zero-click-phishing-russia-laundry-bear
        https://cyberscoop.com/russian-laundry-bear-zimbra-exploit/
        https://www.infosecurity-magazine.com/news/russian-hackers-zero-click/
      • Hackers Abuse Notepad++ Plugins To Stealthily Install Malware
        "Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. The campaign has been attributed to a threat cluster tracked as UAC-0099, which primarily targets organizations in Ukraine and has previously been linked to providing initial access for attacks carried out by APT44, also known as Sandworm. The attackers do not exploit any vulnerability or a supply-chain compromise impacting the popular software."
        https://www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-to-stealthily-install-malware/
      • Chaos Ransomware's MsaRAT: Living Off The Browser To Build a Covert C2 Channel
        "Chaos is a ransomware-as-a-service (RaaS) group whose activity was first confirmed in February 2025. Although the number of listings on their data leak site remains relatively low, the group consistently targets large organizations and employs double extortion tactics. For initial access, they rely on spam emails and voice-based social engineering, commonly known as vishing. Once inside a network, their traditional post-compromise methodology involves abusing remote monitoring and management (RMM) tools to establish persistent access, while leveraging legitimate file-sharing software to exfiltrate data. For a detailed breakdown of their tactics, techniques, and procedures (TTPs), please refer to our previous blog."
        https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/
        https://www.bleepingcomputer.com/news/security/new-msarat-malware-uses-chrome-edge-browsers-to-route-c2-traffic/
        https://thehackernews.com/2026/07/chaos-ransomware-uses-msarat-to-route.html
        https://securityaffairs.com/195876/malware/chaos-ransomware-deploys-browser-based-msarat-to-evade-network-detection.html
        https://www.helpnetsecurity.com/2026/07/23/cisco-talos-chaos-ransomware-msarat/
      • Lampion's Portugal-Focused Phishing Campaign Delivers Multistage Malware
        "Acronis Threat Research Unit (TRU) identified an active Lampion malware campaign targeting Portuguese users through phishing emails masquerading as financial and administrative communications. First publicly documented in December 2019, Lampion is a Brazilian banking malware family, derived from the ChePro lineage, that has consistently targeted Portugal and other Portuguese-speaking users rather than Brazilian victims. Initial payloads are delivered through ZIP archives containing heavily obfuscated HTML files designed to evade static detection and analysis. The HTML stage retrieves and executes additional script from attacker-controlled infrastructure, leading to the deployment of a multistage VBS infection chain."
        https://www.acronis.com/en/tru/posts/lampions-portugal-focused-phishing-campaign-delivers-multistage-malware/
        https://www.darkreading.com/cyberattacks-data-breaches/brazilian-banking-trojan-spreading-portugal
      • JadeProx: Tracing a China-Nexus Operation Through An OPSEC Mistake
        "In mid-April 2026, an exposed directory on an operator-owned Alibaba Cloud server gave us a complete view into an active China-nexus operation. The server with bash history, toolkits, webshell paths against victims, and staged phishing packages were all visible. The investigation uncovered simultaneous intrusions against a Vietnamese public hospital’s medical imaging system, the Malaysian Ministry of Foreign Affairs, and multiple Hong Kong educational institutions. Running in parallel, similar targeting of Honduras and phishing campaigns themed around fake Anthropic Claude software were observed."
        https://www.group-ib.com/blog/jadeprox-china-nexus-triback-loader/
        https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html
      • AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
        "OpenAI's Workspace Agents can connect to Outlook, Gmail, Slack, Google Drive, SharePoint, and Teams, execute actions across those services, and run on a schedule. They’re built through a conversational agent builder that lets users describe an agent in natural language, configure tools, preview its behavior, and publish it. During our research, we discovered that this workflow could be driven entirely by an attacker-controlled URL. We call it AgentForger: a Cross-Site Request Forgery (CSRF) that doesn't forge a single request; it forges an entire autonomous agent, attacker-controlled and living inside your organization's trust boundary."
        https://labs.zenity.io/p/agentforger-part-1-chatgpt-cross-site-agent-forgery
        https://labs.zenity.io/p/agentforger-part-2-the-autonomous-insider
        https://www.securityweek.com/openai-fixes-chatgpt-agent-flaw-that-could-let-attackers-forge-an-ai-insider/
      • Real Email Attacks. Stopped Cold.
        "Every month, Barracuda detects and blocks around 4.9 million brand and service impersonation emails, 46,065 QR code phishing (quishing), 242,300 CEO/executive impersonations attacks, 960,000 Bayesian-poisoning phishing emails, and 110,000 non-English phishing emails. To illustrate the many tactics and layers seen in today’s sophisticated email attacks, we selected seven examples. Each email is shown exactly as it arrived, alongside the signals that exposed it and where it would have taken anyone who clicked."
        https://blog.barracuda.com/2026/07/23/real-email-attacks-stopped-by-barracuda
      • Large-Scale GitHub Actions Abuse Powers a Distributed cPanel And WHM Exploitation Campaign
        "Our investigation into malicious Packagist development versions associated with a legitimate PHP and DevOps developer, dinushchathurya, uncovered a large-scale GitHub Actions abuse campaign. Although the investigation began in the PHP package ecosystem, the PHP library code itself was not the campaign’s execution mechanism. Instead, the malicious functionality was embedded in GitHub Actions workflow files committed to the developer’s source repositories."
        https://socket.dev/blog/github-actions-abuse-powers-cpanel-and-whm-exploitation
        https://thehackernews.com/2026/07/attackers-weaponize-github-actions.html
      • 13M+ Emails Sent In Tech Support Scam Targeting Users, Organizations In Japan
        "From mid-December 2025 through May 2026, we observed and analyzed a large-scale and sustained tech support scam campaign, luring victims to fake security alert websites via email. Over roughly five and a half months (165 days), we confirmed that more than 13 million emails were delivered from over 240,000 IP addresses, with more than 33,000 disposable fake alert sites serving as landing pages. Our analysis found that the campaign combined high-volume distribution, globally dispersed delivery infrastructure, rapidly rotating landing sites, and an expanding focus that appeared to include individuals within organizations:"
        https://www.trendmicro.com/en_us/research/26/g/tech-support-scams-targeting-japan.html
      • Behind The Refund: From GST Phishing To Remcos RAT Through a Multi-Stage .NET Infection Chain
        "Seqrite Labs recently identified a malware distribution campaign that abused the credibility of government institutions to increase infection success rates. The threat actors impersonated legitimate government departments and distributed malicious emails disguised as official notifications related to taxation, refunds, compliance requirements, and regulatory matters. By leveraging recognizable government branding, urgency, and financial incentives, the campaign was designed to persuade recipients to open malicious attachments or interact with embedded content. This activity highlights the continued effectiveness of government-themed social engineering techniques in facilitating malware delivery and compromising targeted users."
        https://www.seqrite.com/blog/behind-the-refund-from-gst-phishing-to-remcos-rat-through-a-multi-stage-net-infection-chain/

      Breaches/Hacks/Leaks

      • Australian Energy Provider Origin Says Data Breach Exposes Client Data
        "Australian energy provider Origin Energy has confirmed a data breach by an unknown threat actor that exposed customers' personally identifiable information (PII). The company has 4.8 million customers and is currently investigating how many of them have been impacted to inform them of the risk via individual notifications. Origin Energy is Australia’s largest energy retailer, providing electricity, natural gas, and broadband internet services to millions of clients across the country."
        https://www.bleepingcomputer.com/news/security/australian-energy-provider-origin-says-data-breach-exposes-client-data/
        https://therecord.media/australia-origin-energy-data-breach

      General News

      • Which Brands Are Impersonated Most? Inside The Q2 2026 Brand Phishing Report
        "Brand phishing is when a scammer impersonates a trusted, well known company, through email, a fake website, or both, in order to steal login credentials, payment details, or personal information. It works because trust is transferable. If a message looks like it came from a brand you already use and rely on, your guard drops. You’re not evaluating a stranger’s request. You’re responding to what feels like routine correspondence from a company you already have a relationship with. That single psychological shortcut is the entire business model behind brand phishing."
        https://blog.checkpoint.com/research/which-brands-are-impersonated-most-inside-the-q2-2026-brand-phishing-report/
      • Agentic AI Challenges Progress In Confidential Computing
        "After years of struggles, artificial intelligence (AI) is boosting enterprise adoption of confidential computing, but AI agents are creating new security challenges that current technology isn't designed to tackle. This is pushing proponents of the technology back to the drawing board. At last month's Linux Foundation's Confidential Computing Summit in San Francisco, these proponents advocated for a whole new paradigm."
        https://www.darkreading.com/endpoint-security/agentic-ai-challenges-progress-in-confidential-computing
      • Flaws In Passkey Implementation Show Old Attacks Still Work
        "Attackers can exploit flaws in Microsoft's passkey systems in ways surprisingly similar to old password attacks. But that doesn't mean it's time to give up on passkeys. Passkeys have received much attention in recent years. They're considered phishing-resistant, and their use of private keys means they are largely unaffected by data breaches when identity information and credentials are stolen. They also require zero memorization compared to traditional passwords because users embed authentication directly into the device by enabling biometrics or PINs. Even so, widespread adoption has been gradual."
        https://www.darkreading.com/identity-access-management-security/flaws-passkeys-implementation-old-attacks-work
      • Ransomware In 2026: Same Business, New Rules
        "The ransomware economy has entered a new phase. Affiliates are going independent, groups are absorbing their rivals, and encryption is becoming optional. Access to corporate networks has never been easier to buy. The market is splitting into a visible tier of opportunistic sales and an invisible tier of premium partnerships, and both are growing. AI-assisted malware development is already in production among multiple active groups, lowering the barrier to sophisticated operations and automating post-breach monetization."
        https://www.group-ib.com/blog/ransomware-2026-rules/
      • Multi-Patch Vulnerability Fixes Can Leave Open Source Exposed
        "Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A share work in a different way, arriving as a run of two or more commits where the first one leaves the flaw in place. Researchers at the University of Texas at Dallas went through 1,646 open source CVEs that carry more than one patch in the National Vulnerability Database, drawn from records filed between 1999 and 2025. Those cases are a small share of the whole, close to one in fifteen of the open source CVEs in the database that carry a linked patch. The operational weight sits in the interval between the first patch and the last one, a window in which the software stays open."
        https://www.helpnetsecurity.com/2026/07/23/research-multi-patch-vulnerability-fixes/
        https://arxiv.org/pdf/2607.13206
      • The AI Code Vulnerabilities That Grow With Your App
        "Theori built 28 apps with AI coding agents and scanned each one through its pentesting platform. Five models did the building, split between Anthropic and OpenAI, across apps written from a spec, thrown together from a casual prompt, and rewritten from an aging PHP codebase. The team went in expecting injection everywhere. SQL injection, cross-site scripting, the bugs that fill security tutorials. Those barely showed up. The models reached for prepared statements and ORMs on their own and sanitized their inputs."
        https://www.helpnetsecurity.com/2026/07/23/report-ai-code-vulnerabilities/
      • AI Agents Now The Enterprises Fastest Growing Exposed Attack Surface
        "The rapid adoption of enterprise AI tools is the fastest-growing source of new exposure for businesses, and it puts them at risk to additional cyber threats, a new report has warned. Published on July 22, the Sophos AI Security 2026 Report, warned that AI identities have become a new attack surface as AI agents and assistants are adopted in the workplace. Employees have deployed coding agents, agentic AI assistants, LLMs and other tools to help them with their work. It has become common for the agents to receive privileged access to core systems to aid with their efficiency."
        https://www.infosecurity-magazine.com/news/ai-agents-attack-surface/
        https://www.sophos.com/en-us/content/sophos-ai-security-2026-report
      • 2026 AI-Era Ransomware Report
        "Most organizations plan for ransomware as if it's a malware problem. The 2026 AI-Era Ransomware Report shows why that's the wrong playbook. Based on a global survey of security professionals, this report reveals how attackers are getting in through people—and why AI is making those attacks harder to catch."
        https://www.proofpoint.com/us/resources/threat-reports/ai-era-ransomware-report
        https://www.infosecurity-magazine.com/news/ai-boosts-ransomware-effectiveness/
      • Is Patching Dead? Vulnerability Management In The Post-Mythos Era
        "On July 14, 2026, the White House launched Gold Eagle: a federal clearinghouse that uses frontier AI to identify, rank, and coordinate the remediation of software vulnerabilities across government and critical infrastructure before attackers reach them. Bringing together the Treasury, DHS, DoD, open-source software partners, and operators of American critical infrastructure, Gold Eagle’s engine relies on frontier AI—including Anthropic’s Mythos, the same class of system that surfaced critical flaws inside classified U.S. government software during testing."
        https://www.securityweek.com/is-patching-dead-vulnerability-management-in-the-post-mythos-era/
      • The Upgrade Trap: When Upgrading Is The Wrong Answer To a CVE
        "The advice is always the same when a vulnerability tool flags a CVE: upgrade. Move to the patched version so you can close the ticket and move on. It’s become such a reflex that nobody stops to ask whether it’ll actually work. The proposed fix fails in three specific ways. There's no version to upgrade to and won't ever be, the patched version hasn't shipped yet, or the fix ships and breaks your application."
        https://www.aikido.dev/blog/cve-upgrade-breaking-changes-open-source

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 0d27e59e-f4ca-457c-a34d-a51405f73364-image.png

      1 การตอบกลับ คำตอบล่าสุด ตอบ คำอ้างอิง 0
      • First post
        Last post