NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ

    Cyber Threat Intelligence 28 July 2026

    Cyber Security News
    1
    1
    12
    โหลดโพสเพิ่มเติม
    • เก่าสุดไปยังใหม่สุด
    • ใหม่สุดไปยังเก่าสุด
    • Most Votes
    ตอบ
    • ตอบโดยตั้งกระทู้ใหม่
    เข้าสู่ระบบเพื่อตอบกลับ
    Topic นี้ถูกลบไปแล้ว เฉพาะผู้ใช้งานที่มีสิทธิ์ในการจัดการ Topic เท่านั้นที่จะมีสิทธิ์ในการเข้าชม
    • NCSA_THAICERTN
      NCSA_THAICERT
      แก้ไขล่าสุดโดย

      Industrial Sector

      • Johnson Controls C-CURE 9000 And Victor Application Server
        "Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01
      • Panduit IntraVUE
        "Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-04
      • Weintek cMT3092X
        "Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-03
      • Johnson Controls XAAP Android
        "Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-02
      • Rockwell Automation ThinManager
        "Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-05
      • MZ Automation LibIEC61850
        "Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06
      • MZ Automation Lib60870
        "Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-07
      • Marathon Petroleum’s CISO On OT Security Automation, Supply Chain Risk
        "In this interview with Help Net Security, Mary Rose Martinez, CISO at Marathon Petroleum, talks about what happens to security when automation reaches deep into refineries, pipelines, and terminals. She explains why the old idea of air-gapped operational technology has faded, how the Purdue model helps her team apply controls without stopping production, and where supply chain risk sits when vendors and their vendors hold the keys. She also covers cross-skilling the workforce and working with government agencies as state aligned actors probe energy systems."
        https://www.helpnetsecurity.com/2026/07/27/mary-rose-martinez-marathon-petroleum-ot-security-automation/

      New Tooling

      • Nono: Open-Source Sandbox For AI Agents
        "An AI coding agent opens a terminal, reads a config file, and finds a live cloud key sitting in plaintext. It runs with the permissions of the person who launched it. Every file that person can read, the agent reads. Every credential in the environment, the agent can use. That reach is where the damage starts. A prompt injection, a mistyped command, or a hallucinated path points that access at the company’s own credentials and production systems."
        https://www.helpnetsecurity.com/2026/07/27/nono-open-source-ai-agent-sandboxing/
        https://github.com/nolabs-ai/nono

      Vulnerabilities

      • Arista Patches VeloCloud Orchestrator Zero-Day Exploited In Attacks
        "Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. The vulnerability, tracked as CVE-2026-16812, is an unauthenticated OS command injection flaw with severity scores of 10.0, the maximum score that can be given to flaws. VeloCloud Orchestrator, also known as VCO, is a centralized management platform used to configure, monitor, and manage VeloCloud SD-WAN deployments and associated edge devices."
        https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/
      • vBulletin Runtime Template RunMaths Preauth RCE
        "A vulnerability in vBulletin has been identified, the vulnerability allows an unauthenticated user to cause the vBulletin to execute arbitrary code (PHP) on the remote server."
        https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
        https://thehackernews.com/2026/07/public-exploit-released-for-patched.html
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
        CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
      • Breaking The Sandbox Again: Bypassing n8n's CVE-2026-27577 Patch
        "n8n is one of the most popular open-source workflow automation platforms in the world, with over 200,000 GitHub stars and deployments ranging from solo developers to enterprise AI pipelines. It lets users connect APIs, databases, LLMs and cloud services using a visual workflow editor. At the heart of each workflow is an expression evaluator - a JavaScript sandbox that lets users write dynamic logic like ={{ $input.first().json.name }} directly inside node parameters. That sandbox is the attack surface."
        https://www.securityjoes.com/blog/breaking-the-sandbox-again-bypassing-n8n-s-cve-2026-27577-patch
        https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html

      Malware

      • New Dysphoria DDoS Botnet Spreads To 200k Devices Worldwide
        "A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. According to QiAnXin XLab cybersecurity researchers, Dysphoria evolved from the ‘jackskid’ and ‘fbot' malware by adding a covert blockchain-based command-and-control (C2) resolution mechanism. Specifically, the botnet uses Ethereum ENS and Solana SNS domains to retrieve infrastructure information, while C2 addresses are concealed inside fake IPv6 strings and recovered using a custom byte-transformation algorithm."
        https://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/
        https://thehackernews.com/2026/07/dysphoria-iot-botnet-adds-blockchain-c2.html
      • MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions
        "We recently came across a sample of MedusaHVNC, a new remote access trojan (RAT) being sold as malware-as-a-service (MaaS). When we took it apart, we found a hidden virtual network computing (HVNC) module that opens a browser on a separate Windows desktop, out of sight of the victim. The browser still runs on the victim’s device, so it can load an existing profile, including cookies and session state. This gives the operator access to live, logged-in sessions while the activity continues to come from the victim’s usual machine."
        https://www.blackfog.com/medusahvnc-a-hidden-desktop/
        https://securityaffairs.com/196111/malware/medusahvnc-trojan-creates-hidden-desktops-to-hijack-browsers-and-steal-data.html
        https://www.securityweek.com/medusahvnc-malware-uses-hidden-windows-desktops-to-evade-detection/
      • Helpdesk Hijackers: Teams Vishing, Quick Assist, And GoGRPC Backdoor
        "Zscaler ThreatLabz has been tracking attacks from a threat actor that is likely an initial access broker for ransomware attacks since January 2026. The threat actor targets organizations by leveraging vishing techniques through Microsoft Teams and deploying a variety of tools including a Go-based backdoor that we named GoGRPC. ThreatLabz has identified at least four variants of GoGPRC that we named Lep, Giver, Pet, and Kind. In some instances, the threat actor has deployed additional malware tools that include a backdoor that we named BlindDoor, a Go-based reverse SOCKS proxy we named RevSocket, a Python-based reverse SOCKS proxy we named PyGRPC, and two other tools we named S3Siphon and RSOX."
        https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor
      • Operation BlueDash: Multi-RMM Workplace Phishing
        "ZeroBEC investigated a live Microsoft Teams-themed phishing operation that began with a "secure document" email and ended with the silent enrollment of the victim endpoint into attacker-controlled remote monitoring and management environments. The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened. The active download delivered supportdev.exe, an Inno Setup-based loader that launched PowerShell in a hidden window, retrieved the official Level RMM installer, and registered the endpoint using an attacker-controlled enrollment secret. The same command attempted to deploy ScreenConnect in parallel, providing a redundant remote-access channel."
        https://zerobec.com/blog/operation-bluedash-multi-rmm-workplace-phishing
        https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html
      • Check And Protect: Analysis Of Telegram Phishing Operation Targeting Exiled Activist
        "In July 2026, RESIDENT.NGO investigated an instance of a cloaked Telegram phishing campaign used against an exiled Belarusian activist living in Lithuania. Delivered in a private Telegram Secret Chat as a fake Telegram security alert, the phishing link led to a convincing Telegram-themed page designed to capture one-time login codes in real time. The operation’s defining feature was not the phishing page itself but its browser- and device-aware cloaking: visitors using browser and platform configurations accepted by the server, together with a syntactically valid token, could receive the phishing interface, while other configurations—including many automated scanners and some common desktop browsers—were shown decoy content or redirected to Telegram’s legitimate website."
        https://resident.ngo/lab/writeups/check-and-protect-analysis-of-telegram-phishing-operation-targeting-exiled-activist/
        https://therecord.media/telegram-belarus-activist-russia-cyberattack
      • DinDoor, DenoRAT, And NightshadeC2: Analyzing TAG-150's Evolving Tradecraft
        "In June 2026, eSentire's Threat Response Unit (TRU) disrupted a malicious ClickFix-style command in a Finance customer's environment. Further investigation found that the command installs DinDoor, a Deno-based loader, DenoRAT, a Deno-based Remote Access Trojan (RAT), and NightshadeC2, a sophisticated RAT and information stealer associated with TAG-150, a threat group active since March 2025."
        https://www.esentire.com/blog/dindoor-denorat-and-nightshadec2-analyzing-tag-150s-evolving-tradecraft
      • APT42: AI-Assisted Rapport Phishing And a More Resilient TAMECAT
        "APT42 continues to refine a familiar operating model, making it harder to detect and easier to scale. Three developments define the current picture. SpearSpecter combined prolonged WhatsApp engagement, Windows search-ms and WebDAV abuse, and a substantially expanded TAMECAT backdoor. APT42 also incorporated generative AI into target research, persona and pretext development, translation, malware engineering, debugging, code generation, and exploitation research. In March 2026, TA453 activity overlapping APT42 targeted a US think tank with a live credential-phishing operation during an active regional conflict."
        https://darkatlas.io/blog/apt42-ai-assisted-phishing-tamecat-analysis

      Breaches/Hacks/Leaks

      • Coca-Cola Confirms Data Theft In Fairlife Ransomware Attack
        "The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. In a short statement earlier today, the global beverages giant says that it is still working to restore some of the impacted systems and operations, but most of the production in the U.S. has been resumed. Coca-Cola disclosed the cyberattack in a filing with the U.S. Securities and Exchange Commission (SEC) on July 16, revealing that a ransomware attack had disrupted production operations at Fairlife."
        https://www.bleepingcomputer.com/news/security/coca-cola-confirms-data-theft-in-fairlife-ransomware-attack/
        https://www.securityweek.com/coca-cola-confirms-data-breach-after-fairlife-ransomware-attack/
      • Ernst & Young Data Breach Claimed By ShinyHunters Extortion Gang
        "The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack. Ernst & Young disclosed the breach earlier this month, saying a third-party support ticket system used by its IT personnel was compromised and support tickets that may contain client tax information were stolen. EY says it detected unusual activity on April 23 and determined that the attacker accessed the platform between March 28 and April 12, downloading multiple documents."
        https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
      • Health System In South Carolina, Georgia Closes Offices After Malware Affects Networks
        "A non-profit health system serving South Carolina and Georgia is dealing with a cyber incident that forced it to close dozens of departments. On Sunday, AnMed published a statement online saying they were “experiencing a cybersecurity disruption involving malware” and were working to restore systems and determine the scope of the incident. Earlier in the day, the company had warned of a phone and internet outage across all of its facilities. The company on Monday published a breakdown of the dozens of facilities and departments that were closed due to the incident. Urgent care services remain open but all imaging, OBGYN and primary care clinics are closed, as well as all medical group offices."
        https://therecord.media/health-system-south-carolina-georgia-disruptions-malware
        https://www.bankinfosecurity.com/malware-attack-forces-anmed-to-close-care-facilities-a-32336
      • Bank Of Baroda Breach Tests Disclosure Readiness
        "India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer and internal data surfaced online. The incident stemmed from the "compromise of an employee's email account, resulting in unauthorized access to certain data," the state-owned lender said in a post on X. The statement followed claims that the Triple X ransomware group published the data on the dark web on July 24. The relatively new group, first observed in May, primarily uses a double-extortion model: stealing data first, then threatening to leak it."
        https://www.bankinfosecurity.com/bank-baroda-breach-tests-disclosure-readiness-a-32335
      • DentaQuest Data Breach Potentially Impacts Over 23 Million People
        "Dental and vision benefits administrator DentaQuest is notifying millions of people that their personal and dental health information might have been stolen in a data breach. The incident was discovered on May 20, and DentaQuest’s investigation determined that the hackers had access to the organization’s network between May 17 and May 20. During the timeframe, the attackers accessed information such as names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, benefits provider names, diagnosis, treatment details, and billing information."
        https://www.securityweek.com/dentaquest-data-breach-potentially-impacts-over-23-million-people/
        https://securityaffairs.com/196100/data-breach/dentaquest-disclosed-a-data-breach-that-impacted-23-million-individuals.html
      • MCBS Data Breach Affects 1.2 Million Individuals
        "A data breach suffered last year by Atlanta-based medical business management company MCBS (Medical Computer Business Services) affects more than 1.2 million individuals. According to a data breach notification posted on its website, MCBS was targeted by hackers in September 2025. An investigation showed that attackers had access to its systems between September 22 and September 26, potentially stealing files that contained personal information such as name, address, SSN, date of birth, health insurance information, and medical information."
        https://www.securityweek.com/mcbs-data-breach-affects-1-2-million-individuals/

      General News

      • The Branding And Attribution Behind Cybercrime
        "Threat actor names can sound simple. LockBit. Fancy Bear. BlackCat. Scattered Spider. Anonymous Sudan. Each name gives the impression of a clear group with a defined identity. In threat intelligence, however, the name is rarely the whole story. Some names are chosen by attackers. Others are assigned by researchers, security vendors, governments, or public databases. One name may represent a ransomware brand, a hacktivist identity, a research label, a campaign, a malware family, or an activity cluster observed across different incidents."
        https://blog.checkpoint.com/exposure-management/the-branding-and-attribution-behind-cybercrime/
      • APTs Top The List Of Most Active Threat Actors In H1 2026
        "You may have heard your peers say, “Cybercrime has become industrialized.” But did you have any proof? We do. Cyble Research and Intelligence Labs (CRIL) closed out its tracking for the first half of 2026 with a deep analysis of the Global Threat Landscape spanning ransomware, initial access brokers, data breaches and leaks, nation-state espionage, and hacktivism, among others."
        https://cyble.com/blog/most-active-threat-actors-h1-2026/
      • FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
        "Undermining affiliates' trust and strong international partnerships were the keys to dismantling LockBit, one the most successful ransomware-as-a-service (RaaS) groups of its time, which at its peak was responsible for a quarter of all ransomware attacks. LockBit operated primarily between 2020 and 2024, and Brett Leatherman, assistant director of the FBI's Cyber Division, tells Dark Reading that during its time it victimized more than 2,500 organizations across at least 120 countries, with more than 1,800 of these attacks occurring in the US. Overall, the group collected more than $500 million in ransom payments, and the group and its leader, a Russian national named Dmitry Yuryevich Khoroshev, seemed invincible."
        https://www.darkreading.com/cybersecurity-operations/fbi-breaking-affiliate-trust-lockbit-takedown
      • Adversaries Don't Need a Zero-Day — They Read Your Rulebook
        "Recently, Robert Lemos reported in Dark Reading that confidence in autonomous penetration testing is falling: The share of organizations willing to rely on it dropped to 9% in 2026, down from 29% a year earlier, according to a Cobalt report. Companies are still experimenting with AI systems that hunt for weaknesses, but far fewer are leaning on them the way they did a year ago. The obvious explanation is that the technology overpromised and is now settling into a trough. I think something more specific is going on, and it carries a lesson that applies to autonomous defense just as much as offense."
        https://www.darkreading.com/threat-intelligence/adversaries-do-not-need-zero-day-they-read-your-rulebook
      • Ransomware Evolution Report Q22026
        "Q2 2026 recorded 1,988 attack claims from 89 groups across 101 countries. The quarter was defined by a change at the top of the ecosystem, tooling built to blind security products, and the arrival of AI inside the attack chain. TheGentlemen overtook its former parent group for the lead by June. Qilin still finished the quarter ahead on volume but lost ground each month, while DragonForce and a resurgent LockBit rounded out a reshaped top tier. Among the key trends observed, the disabling of endpoint defenses shifted from edge case to standard practice across the ecosystem, and Iran-linked actors expanded their use of ransomware as cover for state objectives."
        https://www.halcyon.ai/ransomware-evolution-report/q2-2026
        https://www.infosecurity-magazine.com/news/ransomware-q2-2026-edr-kill/
      • Most Smart Watches, Rings, And Bands Lack Basic Transparency Reports And Key Privacy Features
        "Oura Rings, Garmin GPS fitness watches, Apple Watches, Whoop bands—every year, more and more tech devices are promising to monitor our health and fitness, guide us toward healthier living, and provide useful health metrics to take to our doctors. But few of these tools provide the sorts of privacy and security promises we demand from all technology, let alone tech that captures personal health data. It’s time they step up and start providing transparency reports and stronger encryption options."
        https://www.eff.org/deeplinks/2026/07/most-smart-watches-rings-and-bands-lack-basic-transparency-reports-and-key-privacy
        https://securityaffairs.com/196085/security/eff-most-smart-wearables-still-fall-short-on-privacy-and-transparency.html
      • LockBit5 And Qilin Lead Ransomware Attacks Against Italian Organizations
        "Six months, 148 confirmed ransomware claims against Italian targets, and one sector taking the brunt of it. That’s the headline number from a new semi-annual tracker compiled by ransomNews under its RedACT project, which pulls together OSINT and SOCMINT sources to build a manual, deduplicated picture of who’s getting hit and by whom. The pace works out to roughly 25 claims a month, just under six a week. Attackers claim to have exfiltrated over 13,400 GB of data across the period, though that figure only covers 64 of the 148 cases; where a volume is actually disclosed, it averages around 61 GB. Read that gap as a reminder that leak-site numbers are marketing copy from criminals, not audited disclosures."
        https://securityaffairs.com/196045/security/lockbit5-and-qilin-lead-ransomware-attacks-against-italian-organizations.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) e338a97e-9ec9-4c73-b016-d5072d145ed7-image.png

      1 การตอบกลับ คำตอบล่าสุด ตอบ คำอ้างอิง 0
      • First post
        Last post