NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ

    Cyber Threat Intelligence 07 August 2026

    Cyber Security News
    1
    1
    5
    โหลดโพสเพิ่มเติม
    • เก่าสุดไปยังใหม่สุด
    • ใหม่สุดไปยังเก่าสุด
    • Most Votes
    ตอบ
    • ตอบโดยตั้งกระทู้ใหม่
    เข้าสู่ระบบเพื่อตอบกลับ
    Topic นี้ถูกลบไปแล้ว เฉพาะผู้ใช้งานที่มีสิทธิ์ในการจัดการ Topic เท่านั้นที่จะมีสิทธิ์ในการเข้าชม
    • NCSA_THAICERTN
      NCSA_THAICERT
      แก้ไขล่าสุดโดย

      ndustrial Sector

      • OT Security Analysis: Exposed Devices Attacked In US Water Systems
        "On July 28, Minesota IT Services (MNIT) reported a coordinated cyberattack against more than 30 water systems in the state. No city reported degraded water quality but Plymouth, South St. Paul, Maple Plain, and Braham confirmed operational impacts. Braham reported that threat actors used malware via a wireless connection to shut down water plant controls. Plymouth reported its affected equipment – two water towers and 14 sewer lift stations – were cellular-connected."
        https://www.forescout.com/blog/ot-security-analysis-exposed-devices-attacked-in-us-water-systems/
        https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html
        https://cyberscoop.com/exposed-rockwell-controllers-water-system-attacks/
      • The Water Sector Just Got It’s Wake-Up Call. Again.
        "Last week, the FBI and EPA issued a joint alert that should concern anyone who drinks water in America–which is to say, everyone. Since July 27, water and wastewater utilities in at least seven states have reported cyberattacks against internet-facing programmable logic controllers (PLCs), the small industrial computers that run pumps, valves, and treatment equipment. Some of these attacks degraded operations. Utilities reported pressure loss and flooding, several systems reverted to manual control, and one Minnesota community declaring a local state of emergency."
        https://cyberscoop.com/water-utility-cyberattacks-prevention-nozomi-networks-ceo-op-ed/

      Vulnerabilities

      • Cisco Patches 12 SD-WAN And IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
        "Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode. "These vulnerabilities were found during internal security testing using existing testing processes as well as frontier AI models [...] and are not known to be actively exploited," Cisco said, urging customers to apply the necessary updates for optimal protection."
        https://thehackernews.com/2026/08/cisco-patches-12-sd-wan-and-ios-xe.html
        https://www.securityweek.com/cisco-patches-critical-sd-wan-ios-xe-fmc-vulnerabilities/
        https://www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/
      • New TONTOU CPU Attack Bypasses Spectre v2 Fixes, Leaks Linux Password Hashes
        "Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. ​The method works against Spectre v2 defenses on AMD and Intel processors that rely on sanitizing or isolating branch predictors, which researchers generically refer to as neutralization-based mitigations. Spectre v2 is also known as Branch Target Injection (BTI) and is a variant of the Spectre class of vulnerabilities."
        https://www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/
        https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf
        https://www.csail.mit.edu/news/new-attack-slips-past-latest-defenses-built-your-computers-processor
        https://thehackernews.com/2026/08/new-interrupt-injection-attack-can.html
      • Researcher Claims Control Of ChatGPT Secure Sandbox
        "A researcher presented a proof-of-concept attack this week claiming to establish full command and control inside an isolated ChatGPT sandbox. On Aug. 5, Simcha Kosman, senior security researcher at Palo Alto Networks, presented "A Billion-User Blast Radius: Owning ChatGPT's Secure Sandbox" at Black Hat USA 2026. Among other things, the presentation demonstrated a proof-of-concept attack chain against ChatGPT's secure sandbox, apparently bypassing the large language model (LLM) supervisor in order to achieve persistent root execution."
        https://www.darkreading.com/cloud-security/researcher-claims-control-chatgpt-secure-sandbox
      • IP And DNS Leaks In WebKit Affecting Proxy Browsers And Apple iCloud Private Relay
        "WebKit-based browsers on iOS and macOS can be configured to route all web traffic through proxy servers, which is how Tor browsers on iOS and our own Psylo work. We found three WebKit features — DNS prefetching, WebAuthn Related Origin Requests, and WebTransport — that bypass the configured proxy and send traffic directly from the device, which exposes the user’s real network. The same leaks also affect Apple’s iCloud Private Relay. All three are fixed in Psylo 1.3.1."
        https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/
        https://thehackernews.com/2026/08/webkit-proxy-bypasses-can-expose-real.html
        https://www.malwarebytes.com/blog/news/2026/08/apple-webkit-vulnerabilities-reveal-your-ip-address-despite-private-relay
      • Grand Theft Atlas
        "ChatGPT Atlas is the most hardened agentic browser we have tested. It ships with real boundaries by design: no localhost, no filesystem, URL classifiers, blocked pages, and confirmation gates on sensitive actions.Yet it too has fallen. Using intent collision, a planted comment under a popular X post was enough to steer Atlas into carrying out a mass phishing campaign from the victim's own WhatsApp account in one attack. In another attack a similar comment hijacked Atlas into making an unauthorized Amazon purchase that shipped straight to the attacker's own address."
        https://labs.zenity.io/post/grand-theft-atlas
        https://www.securityweek.com/zero-click-ai-browser-hacking-claude-and-chatgpt-atlas-hijacked-via-emails-x-posts/
      • New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape To Linux Hosts
        "Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86's shadow memory management unit (MMU), which manages shadow page tables used for nested guest memory translation. Security researcher Hyunwoo Kim, who disclosed the bug, said the demonstrated exploit path can run commands on the host with kernel, or root, privileges."
        https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html
        https://github.com/V4bel/Zapscape/blob/main/assets/write-up.md
      • Identifying The Wallets Behind Vulnerable Recovery Phrases
        "As part of the Ill Bloom investigation, we identified wallet addresses whose recovery phrases could be brute-forced due to weaknesses in their generation process. We then began investigating which wallet applications may have generated those phrases. A public blockchain address does not reveal which application originally generated the wallet behind it. The challenge is even greater when the wallet is closed source and has since been discontinued. In those cases, the exact software version that generated a wallet may no longer be available at all. Even for active wallets, identifying the relevant generation path may require locating and analyzing versions of the application other than the current release."
        https://illbloom.org/articles/identifying-wallets-vulnerable-recovery-phrases/
        https://thehackernews.com/2026/08/cryptojs-weak-rng-behind-57-million-in.html
      • AWS, Google, And Vercel Agent Flaws Let Attackers Trigger Tools Without Running The Model
        "Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of the attack paths, the model never ran at all, so system prompts, content filters, and model-level guardrails never got a chance to intervene. The affected products include Amazon Bedrock AgentCore's InvokeHarness API, Google's Agent Development Kit (ADK) for Python, and the Vercel AI SDK harness packages for the Codex and OpenCode coding agents. AWS has fixed the managed service, Google addressed the issues in ADK 2.5.0, and Vercel patched @ai-sdk/harness-codex in version 1.0.29 and @ai-sdk/harness-opencode in version 1.0.28."
        https://thehackernews.com/2026/08/aws-google-and-vercel-patch-agent-flaws.html
      • ENDLESSDOORS Is Phoning Home. Pick Up.
        "On my desk in suburban Philadelphia, an AX3000 Dual SIM 5G CPE WiFi 6 is plugged into an isolated research network. Its status lights blink and twinkle as it continuously attempts to reach a command and control server on the internet. The same plays out in homes, offices, and even vehicles across the globe: Zbtlink routers phone home, waiting for orders. Not because they were hacked. Because they were shipped that way."
        https://www.vulncheck.com/blog/zbt-endlessdoors
        https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html
        https://www.theregister.com/security/2026/08/06/chinese-router-vendor-denies-its-firmware-contains-backdoors-but-pauses-downloads-to-fix-security-issues-anyway/5283794
      • Black Hat 2026: Check Point Research Takes The Stage
        "Black Hat USA 2026 gave Check Point Research four chances to show the room something it hadn’t seen before. Across two days, our researchers pulled apart a decade-old Windows driver, a malware format most tools can’t touch, the plumbing underneath today’s AI agent frameworks, and the sandbox meant to contain them, and found the same pattern waiting in each: attackers moving into the layers we trust by default. Here’s a look at what they presented."
        https://blog.checkpoint.com/research/black-hat-2026-check-point-research-takes-the-stage/
        https://www.theregister.com/security/2026/08/05/prompt-injection-isnt-the-bug-ai-agent-frameworks-are/5283585

      Malware

      • Analysis Of The Connection Between Xctdoor And Past CRAT Attack Cases (Larva-26005)
        "AhnLab SEcurity intelligence Center (ASEC) recently confirmed that the Larva-26005 threat actor is distributing Xctdoor to users in Korea. Xctdoor was disclosed through the ASEC blog in 2024, and [1] In March 2026, Hauri disclosed an attack case in which the malware was disguised as an integrated security program. [2]"
        https://asec.ahnlab.com/en/94847/
      • Wallet-Depleting MacOS Malware Wants Your Crypto
        "Huntress responded to an incident where the target was tricked into pasting a ClickFix command into a Mac Terminal. The target infected their macOS device with a Go-based Mach-O (the native application format for Mac computers) malware, which was delivered as the final payload of a chain of shell scripts the ClickFix command downloaded. The malware collects sensitive credentials from the macOS Keychain and other applications, and exfiltrates them to an external address."
        https://www.huntress.com/blog/mac-crypto-draining-malware
        https://www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/
      • Hedge Fund Cyberattacks Tied To BlackFile-Linked UNC6671 Extortion Group
        "A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. The attribution comes after Reuters and Bloomberg reported that Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel, and several private-equity firms were targeted in recent attacks that relied on voice phishing (vishing) to trick employees into granting the attackers access to corporate systems."
        https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/
      • Novel-Reading Apps Used Users’ Phones To Generate Fake Ad Traffic
        "A new mobile ad fraud scheme, dubbed Papyrus, is using a cluster of novel-reading apps to generate hidden browser traffic, according to IAS Threat Lab. While a person taps through chapters of a romance or fantasy story, the app is quietly loading websites in a browser window hidden from view, clicking on them, and scrolling through them on its own."
        https://www.helpnetsecurity.com/2026/08/06/papyrus-mobile-ad-fraud-scheme/
      • Ransomware Moves Up The Org Chart: Managers Are Prime Targets
        "When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization."
        https://www.zscaler.com/blogs/security-research/ransomware-moves-org-chart-managers-are-prime-targets
      • Understanding Calendar Invite Phishing: How Attackers Abuse .ics Files And How To Defend Against It
        "Attackers are increasingly using trusted calendar invites and .ics files to bypass traditional email-focused phishing defences. Malicious calendar events can contain phishing links, QR codes and fake business requests that lead victims to credential-harvesting sites. To strengthen email security, organizations should inspect .ics files, monitor identity activity and educate users that calendar invites can be phishing attacks."
        https://blog.barracuda.com/2026/08/06/calendar-invite-phishing-ics-files
      • Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
        "It’s three a.m., do you know what your AI agent is doing? Unit 42 has responded to a growing number of AI token jacking cases resulting in staggering financial losses. The financial loss comes from criminals gaining access to API keys used by legitimate developers for access to popular AI platforms. These keys are known as tokens, and their theft is called token hijacking, or token jacking for short. The unrelenting frenzy of AI adoption and soaring costs of model access are converging into an irresistible opportunity for cybercriminals. Premium pricing on scarce AI processing power means stolen access via tokens can generate a quick and easy profit for attackers. Complex, patchwork billing management and limitless scaling by default can lead to massive financial losses in short periods."
        https://unit42.paloaltonetworks.com/ai-token-jacking/

      Breaches/Hacks/Leaks

      • Meta AI Model Hacked a Company During Misconfigured Cyber Test
        "Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached Hugging Face. The Information was the first to report the incident on Wednesday, citing people familiar with the matter who said Meta's Muse Spark 1.1 model breached an unidentified company and made changes to its internal systems. According to the report, the model reached the public internet because of an error in the configuration of a sandbox testing environment operated with independent cybersecurity evaluation company Irregular."
        https://www.bleepingcomputer.com/news/security/meta-ai-model-hacked-a-company-during-misconfigured-cyber-test/
        https://www.theinformation.com/articles/meta-ai-model-hacked-another-company-cybersecurity-testing
        https://www.infosecurity-magazine.com/news/meta-ai-exploit-incident/
        https://www.securityweek.com/meta-ai-hacked-external-systems-during-cybersecurity-testing/
        https://securityaffairs.com/196731/security/meta-ai-model-hacked-a-company-during-testing-marking-third-ai-lab-incident.html
      • Cyberattack On North Carolina Ports ‘contained’ As Coast Guard, State Officials Investigate
        "North Carolina Ports is in the process of restoring its systems after a cybersecurity incident forced a shift to manual operations on Tuesday. A spokesperson for the ports, which handle more than 4 million tons of cargo each year, said the IT system was “hacked by an outside actor or group” requiring them to enact a contingency plan and contact multiple state agencies as well as the U.S. Coast Guard. “The breach has been contained, and we are now in the recovery process,” the spokesperson told Recorded Future News, adding that the incident affected all three North Carolina Ports locations of Wilmington, Morehead City and Charlotte."
        https://therecord.media/cyberattack-north-carolina-ports

      General News

      • The Coordination Gap: How Attackers Are Outpacing Law Enforcement
        "Artificial intelligence (AI) and cryptocurrency enablement have propelled attackers to new levels of sophistication, coordination, and scale, and it's put pressure on law enforcement to adapt. Ecosystems across the threat landscape have converged due to affiliate models that allow non-state actors to conduct ransomware-as-a-service, pig butchering, and romance scams. Although they may be less technically savvy compared to well-resourced nation-state actors, they learned how to inflict the same damage, draining dollars from individuals and organizations."
        https://www.darkreading.com/cyberattacks-data-breaches/coordination-gap-attackers-outpacing-law-enforcement
      • Three In Four AI-Generated Vulnerability Patches Leave Something Broken
        "Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write. When there is a test, it often passes. Roughly one time in four, it is a fix. Researchers at 1Password graded 6,080 patches for six freshly disclosed CVEs, and the failures are rarely the obvious kind: an exploit path gated behind a check with the vulnerable code still sitting there behind it, a bug fixed in one function and left untouched in its character-for-character twin, a memory error closed and a new one opened in the same helper."
        https://www.helpnetsecurity.com/2026/08/06/1password-ai-generated-vulnerability-patches/
        http://1password.com/files/resources/frontier-models-vulnerability-patches-flawed.pdf
        https://www.theregister.com/ai-and-ml/2026/08/06/ai-struggles-to-patch-vulns-without-adult-supervision/5284319
      • Browser Security Is Where Software, Data, And AI Meet
        "In this interview with Help Net Security, Rui Ribeiro, CEO of Jscrambler, explains why the browser has become a security problem organizations do not control. Companies do not own the device, the extensions, or the network path, yet that is where application logic, third-party code, customer data, and AI meet during every customer interaction. He discusses the limits of Content Security Policy and Subresource Integrity, the risks of third-party AI chat scripts running with the same privileges as the application, and what regulators expect when they ask what executed inside a user’s session. He also argues that AI lowers the cost, time, and expertise attackers need."
        https://www.helpnetsecurity.com/2026/08/06/rui-ribeiro-jscrambler-browser-security/
      • Non-Human Identities Are 91% Of Everything Active In Production
        "A backup job fires at two in the morning. A scanner walks the same AWS account an hour later, a deployment pipeline assumes a role at four, and a logging agent runs straight through the night. Each of those actions carries a credential issued to a machine. An attacker holding one of those credentials inherits the same cover. Only 20% of non-human activity in production falls inside standard business hours, which puts a rogue API call at 3 a.m. in the middle of normal traffic. Time of day tells a defender almost nothing."
        https://www.helpnetsecurity.com/2026/08/06/non-human-identities-active-in-production/
      • Space Systems As Targets And Tools For Cyberattacks
        "In November 2019 in Brussels, NATO leaders officially recognized space as a “new operational domain” (alongside land, sea, air, and cyberspace). This article explores issues related to information security and attacks in space. Its focus is not limited to targeted attacks on the digital infrastructure of space systems; it also encompasses a broader spectrum of incidents, including software glitches, system failures, and unintentional human errors. A retrospective analysis of these events provides valuable information for identifying hidden vulnerabilities and improving the resilience of space infrastructure. It is impossible to build an effective space cybersecurity strategy without factoring in errors and failures – this assertion lies at the core of the present research."
        https://ics-cert.kaspersky.com/publications/reports/2026/08/06/space-systems-as-targets-and-tools-for-cyberattacks/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 26c6d039-672a-4d0f-bd71-7b8873ec2855-image.png

      1 การตอบกลับ คำตอบล่าสุด ตอบ คำอ้างอิง 0
      • First post
        Last post