NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ

    Cyber Threat Intelligence 02 September 2026

    Cyber Security News
    1
    1
    11
    โหลดโพสเพิ่มเติม
    • เก่าสุดไปยังใหม่สุด
    • ใหม่สุดไปยังเก่าสุด
    • Most Votes
    ตอบ
    • ตอบโดยตั้งกระทู้ใหม่
    เข้าสู่ระบบเพื่อตอบกลับ
    Topic นี้ถูกลบไปแล้ว เฉพาะผู้ใช้งานที่มีสิทธิ์ในการจัดการ Topic เท่านั้นที่จะมีสิทธิ์ในการเข้าชม
    • NCSA_THAICERTN
      NCSA_THAICERT
      แก้ไขล่าสุดโดย

      Industrial Sector

      • Rockwell Automation RSLinx Classic
        "Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-01
      • Rockwell Automation Redundancy Module Configuration Tool
        "Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-02
      • Rockwell Automation Logix Platform
        "The following versions of Rockwell Automation Logix Platform are affected:"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-03
      • Rockwell Automation FactoryTalk Activation Manager
        "The following versions of Rockwell Automation FactoryTalk Activation Manager are affected:"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-04
      • Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix
        "The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected:"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-05
      • Rockwell Automation Historian ME
        "Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-06
      • Can AI Create PLC Attacks? Yes, But It’s Not That Easy Yet
        "We used AI assistance to successfully port a remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) model to another. The exercise required significant researcher involvement, including guiding the AI through dead ends, supplying disassembly context, and correcting false leads. The final RCE development stage consumed $535.74 in API tokens during an 8-hour, 32-minute session for a single exploit on a single target. An attempt to extend the exploit into a command-and-control implant bricked the PLC, highlighting how unforgiving binary exploitation on embedded targets can be."
        https://www.forescout.com/blog/can-ai-create-plc-attacks-yes-but-it’s-not-that-easy-yet/
        https://www.securityweek.com/experiment-porting-a-plc-exploit-with-ai-takes-hours-and-hundreds-of-dollars/

      Vulnerabilities

      • Nearly 22,000 Microsoft Exchange Servers Vulnerable To Hijack Attacks
        "Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. Tracked as CVE-2026-62911 and reported by DEVCORE Research Team's Orange Tsai, this security flaw affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software. Threat actors with basic privileges on the targeted server can exploit it in low-complexity attacks that require user interaction."
        https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/
      • Recently Patched PaperCut Zero-Days Used In Data Theft Attacks
        "Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. According to PaperCut Software, the software is used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions. Tracked as CVE-2026-81578 and CVE-2026-82078, the two security flaws can be chained to bypass authentication and gain remote code execution on vulnerable PaperCut NG and MF print management servers."
        https://www.bleepingcomputer.com/news/security/recently-patched-papercut-zero-days-used-in-data-theft-attacks/
      • Attackers Pounce On Critical Artifactory Flaw Following Disclosure
        "Threat actors are actively exploiting a critical JFrog Artifactory vulnerability just days after its public disclosure, putting a fresh spotlight on the software repository platform after OpenAI's AI agents exploited zero-day flaws in the repository manager during their attack on Hugging Face earlier this year. CVE-2026-82329 is a critical (CVSS: 9.8) authentication bypass vulnerability in default configurations of Artifactory that an unauthenticated attacker can exploit to gain administrative access to the platform, with no user interaction required."
        https://www.darkreading.com/application-security/attackers-pounce-critical-artifactory-flaw-disclosure
        https://thehackernews.com/2026/09/attackers-exploit-critical-jfrog.html
        https://www.securityweek.com/critical-jfrog-artifactory-vulnerability-reportedly-exploited-in-the-wild/
      • WatchGuard Patches Critical Vulnerabilities
        "WatchGuard has released patches for over two dozen vulnerabilities, including five critical-severity flaws leading to remote code execution (RCE) and account takeover. Three of the critical bugs impact the iked process of Fireware OS, the core Internet Key Exchange (IKE) daemon that handles cryptographic key establishment and manages IPsec VPN negotiations over the IKEv1 and IKEv2 protocols. Exploitable without authentication, the three security defects are a heap buffer overflow (CVE-2026-19313), a stack-based buffer overflow (CVE-2026-19318), and a type confusion (CVE-2026-19315)."
        https://www.securityweek.com/watchguard-patches-critical-vulnerabilities/
      • Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague
        "Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting GenDigital Avast Antivirus. The researcher named the exploit PrettyPrague, it triggers a privilege escalation flaw. The researcher claims to have found another zero-day in an antimalware product, this time targeting Avast Antivirus. The PoC exploits a flaw in Avast Sandbox to dump the Windows SAM database and gain a SYSTEM-level shell. It reportedly works even on fully patched Avast Antivirus and Windows 11 25H2. The researcher also suspects the flaw may affect other Gen Digital products, including AVG and Norton."
        https://securityaffairs.com/198243/hacking/chaotic-eclipse-releases-gendigital-avast-antivirus-zeroday-prettyprague.html

      Malware

      • Daisy-Chaining Trust: Investigating Faronics Deploy Abuse
        "Huntress has identified a surge in phishing campaigns that abuse Faronics Deploy, with more than 457 endpoints encountering Faronics-related lures between July 21 and August 20. Huntress reported this activity to the Faronics support team on August 5. Starting on August 21, we observed the activity drop dramatically as they implemented new measures to disrupt threat actors. Faronics Deploy is a legitimate endpoint management platform for remotely deploying software and executing scripts across managed devices. By chaining legitimate software, attackers are leveraging Faronics to execute malicious PowerShell scripts and subsequently deploy ScreenConnect, effectively blending in with trusted business workflows. This post details the attack chain, provides key forensic artifacts such as the ScriptRunner.log, and explains how the ck identifier can be used to cluster malicious deployments and track infrastructure."
        https://www.huntress.com/blog/faronics-deploy-abuse
        https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/
        Critical Langflow Flaw Exploited To Steal OpenAI And AWS Keys*
        ***** "Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. The security issue received a critical severity rating and resides in the code validator of Langflow’s custom component editor. Threat intelligence company VulnCheck detected the activity on its honeypots in the U.K. that were targeted in at least 50 exploitation attempts over the weekend, with attack traffic originating primarily from Russia."
        https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/
        https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html
        https://www.darkreading.com/vulnerabilities-threats/critical-langflow-flaw-exploited-attacks-rise
        https://www.bankinfosecurity.com/attacks-targeting-langflow-ai-agent-building-tool-surge-a-32712
        https://www.securityweek.com/hackers-start-exploiting-critical-langflow-vulnerability/
      • Hackers Push Malicious Virtualizor Update In BGP Hijacking Attack
        "Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. Virtualizor is a legacy web control panel from Softaculous that hosting providers use to create, sell, and manage virtual private servers (VPS). An urgent notice from the vendor warns that between 20:57 UTC on August 28 and 06:10 UTC on August 30, an attacker rerouted a block of Hetzner-hosted IP addresses in a BGP (Border Gateway Protocol) hijacking attack."
        https://www.bleepingcomputer.com/news/security/hackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack/
        https://www.virtualizor.com/blog/security-incident-bgp-hijacking/
        https://www.theregister.com/security/2026/09/01/33-hour-bgp-hijack-of-softaculous-traffic-prompts-security-scramble/5293608
      • EtherHiding Exposed: What Security Leaders Need To Know
        "Attackers have compromised the websites of at least 31 legitimate businesses, including e-commerce, professional services and retail logistics organizations. Visitors arriving to the compromised sites via search engine encounter a fake “Verify you’re human”. This CAPTCHA prompt instructs them to paste a command into their own computer, a tactic known as “ClickFix”. That single action installs a persistent backdoor with no visible indication of compromise. The backdoor survives reboots, beacons to C2 every minute and retrieves updated instructions from the Polygon blockchain."
        https://www.guidepointsecurity.com/blog/etherhiding_exposed_what_security_leaders_need_to_know/
        https://www.darkreading.com/endpoint-security/clickfix-campaign-comprises-31-orgs-abuses-polygon-blockchain
      • Mirage Kitten Targeting Aviation And FinTech Sectors Across The Middle East And Africa With a New Malware Set
        "While monitoring Mirage Kitten activity, we uncovered a previously undocumented malware family that we dubbed NodeRabbit. We identified the first sample on a system in Afghanistan. Further threat hunting revealed two additional, more advanced, variants: one on a system in Egypt and another on a system in Ethiopia. NodeRabbit is a cross-platform remote access trojan (RAT) built with Node.js. It targets Windows, Linux, and macOS. Its operators deliver it through spear-phishing messages on LinkedIn and other job search platforms that contain trojanized coding challenge archives."
        https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/
        https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html
        https://therecord.media/iranian-cyber-spies-target-aviation-fintech-new-malware
      • Financially Motivated Threat Actor BREEZE COMET Targets Brazil
        "Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In this blog, we detail BREEZE COMET’s tactics and toolkit, and provide mitigation recommendations and detections to support organizations in defending against this active and developing threat."
        https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil/
        https://thehackernews.com/2026/09/breeze-comet-executes-hundreds-of.html
      • 13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds
        "Socket’s Threat Research Team found 13 malicious Composer theme packages on Packagist, published across five vendor namespaces, that inject JavaScript into every page of the Vietnamese movie and comic streaming sites that install them. The injected code runs two operations against a site’s visitors: a mobile ad-fraud and gambling-redirect chain, and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware. We reported the iOS chain to Apple and coordinated disclosure. Apple confirmed the kernel escape was already fixed in iOS and macOS 26.1 before our report, and the two WebKit entry points are public and listed in CISA's Known Exploited Vulnerabilities catalog. Our earlier research covered six themes under a single vendor (ophimcms); this expands the confirmed set to 13 packages across five vendors and follows the chain through to the iOS payload and its most recent redeployment."
        https://socket.dev/blog/packagist-themes-ios-spyware
        https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html
      • RevStealer Is Built To Be Silent
        "RevStealer is a Windows information stealer delivered inside a trojanized Electron desktop application that impersonates legitimate software. Morphisec Threat Labs observed it distributed through GitHub repositories and game-cheat-themed sites, with the most notable lure a fake “Claude Opus 5 Free Desktop” project that impersonates Anthropic and advertises free access to a paid AI model. The theft itself is ordinary. Browser databases, session cookies, cryptocurrency wallets, password-manager artifacts and VPN configurations have been the standard infostealer haul for years. What makes RevStealer worth studying is that every stage of it is engineered around the assumption that something is watching."
        https://www.morphisec.com/blog/revstealer-silence-is-its-greatest-weapon/
        https://www.helpnetsecurity.com/2026/09/01/revstealer-malware-claude-opus-5-github/
      • FBI Raises Alarm Over Deceptive Phishing Campaign Targeting Prominent People
        "Attackers are targeting prominent, high-profile people, their family members and acquaintances on a commercial messaging application to gain long-term access to their accounts containing sensitive data, the FBI warned in an alert Tuesday. Officials did not describe the objectives or origins of the attackers, which have more recently impersonated government officials, journalists and publicly known personalities. Attackers are tricking victims into granting them access to a legitimate cloud service, such as Microsoft or Google, under the guise of reviewing a draft article or document."
        https://cyberscoop.com/fbi-alert-oauth-consent-phishing-campaign/
        https://www.ic3.gov/PSA/2026/PSA260901
      • Ungentlemanly Behavior: Insights Into a Ransomware Operation
        "Counter Threat Unit™ (CTU) researchers identified a consistent post-exploitation playbook used in The Gentlemen ransomware-as-a-service (RaaS) scheme, operated by a threat group that CTU™ researchers track as GOLD SHERWOOD. Rapid privilege escalation, adaptive tool usage, and aggressive defense evasion enable ransomware deployment soon after initial access, sometimes within 24 hours of the first identified post-compromise activity. The affiliates leverage legitimate tools and compromised credentials to evade detection and accelerate impact. Organizations should prioritize hardening remote access services, enforcing multi-factor authentication (MFA), monitoring administrative activity, and detecting anomalous use of data exfiltration tools and staging directories."
        https://www.sophos.com/en-us/blog/ungentlemanly-behavior-insights-into-a-ransomware-operation

      Breaches/Hacks/Leaks

      • Aesto Health Says Data Breach Affects Over 9.5 Million Patients
        "Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. The private technology company provides software-as-a-service solutions that help healthcare organizations migrate, archive, and access patient data when replacing electronic health record systems or acquiring medical practices. The company first informed the public of the attack on June 24 via a notification on its website, stating that “a limited portion” of its Amazon Web Services infrastructure had been compromised."
        https://www.bleepingcomputer.com/news/security/aesto-health-says-data-breach-affects-over-95-million-patients/
        https://www.securityweek.com/9-5-million-impacted-by-aesto-health-data-breach/
        https://securityaffairs.com/198250/data-breach/attackers-access-aesto-health-aws-infrastructure-exposing-9-5-million-records.html
      • Novocure Data Breach Affects More Than 1,400 Cancer Patients
        "Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. Novocure is a global oncology company with more than 1,300 employees and operations in North America, Europe, the Middle East, and Asia, known for inventing and commercializing Tumor Treating Fields (TTFields), a non-invasive electromagnetic field therapy for cancer tumors. The Company disclosed in a filing with the U.S. Securities and Exchange Commission (SEC) that it discovered the incident after unauthorized access to some of its information systems in mid-August."
        https://www.bleepingcomputer.com/news/security/novocure-data-breach-affects-more-than-1-400-cancer-patients/
      • AI Model Evaluator METR Hit By Credential Theft, Probing
        "A security nonprofit that helps evaluate risks in frontier AI models disclosed two cybersecurity incidents this week, including a breach that exposed an API key and a separate vulnerability that could have exposed nonpublic evaluation data. METR (Model Evaluation and Threat Research) disclosed two security incidents on Aug. 31 in which it was targeted by cyberattackers. In March of this year, attackers stole an API key used for inference on public models and consumed what METR described in a blog post as a "substantial" number of credits. In May, the company saw attackers probe publicly accessible infrastructure, including "an unsuccessful attempt to access internal data via an inadvertently exposed endpoint.""
        https://www.darkreading.com/identity-access-management-security/ai-model-evaluator-metr-credential-theft-probing
        https://metr.org/blog/2026-08-31-security-update/
        https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html
        https://www.infosecurity-magazine.com/news/attackers-steal-metr-api-key/

      General News

      • The Guardrails Debate: Security Researcher Changes His Mind
        "Four security experts took the stage, surrounded by massive skeletons, the theme for the capture-the-flag (CTF) competition that would commence later. A panel discussion about Anthropic's Claude model compromising real-world systems was first on the agenda, but quickly turned into a broader debate on artificial intelligence (AI) guardrails. While the speakers disagreed on some fronts they aligned on one stark reality: AI capabilities are advancing at a “terrifying” pace. The battle of the bots escalated recently when frontier artificial intelligence (AI) models from OpenAI and Anthropic broke out of sandboxes during security evaluations and targeted real companies, including OpenAI's high-profile breach of Hugging Face."
        https://www.darkreading.com/cyber-risk/the-guardrails-debate-security-researcher-changes-his-mind
      • Stronger Security Drives Ransomware Groups To Recruit From Within
        "Not all breaches begin after threat actors exploit a zero-day vulnerability or launch an increasingly sophisticated phishing campaign — some start with an employee who decides to help attackers walk right through the front door. A rise in malicious insider threats reflects a good news, bad news situation: organizations are bolstering their security protocols, but cybercriminals are exploiting the one thing that firewalls and VPNs can't defend against—people with legitimate access. Incidents stemming from insider threats can result in ransomware deployment, direct financial loss, compliance violations, and full data exfiltration, just to name a few damaging outcomes."
        https://www.darkreading.com/cyber-risk/stronger-security-drives-ransomware-groups-to-recruit-from-within
      • What Your Vendor Says About PQC Tells You If They Are Ready
        "In this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers which operator traffic stays sensitive for years, including subscriber identity mappings, billing records and call metadata, and which becomes worthless within hours. It walks through the order of work, starting with a crypto inventory and hybrid key exchange on TLS interfaces, then IPsec links. It also names the vendor answers that should raise suspicion and explains why a missed interface is the likely point of failure."
        https://www.helpnetsecurity.com/2026/09/01/yaakov-stein-allot-telecom-pqc-migration/
      • 65% Of Enterprises Have Seen AI Agents Act Out Of Scope
        "AI agents have acted outside their intended scope at 65% of surveyed enterprises, with 29% reporting measurable organizational impact. The finding comes from Agents Without Guardrails, a research report from Enterprise Management Associates (EMA) compiled for Cequence Security and based on responses from 202 enterprise technology and security leaders. Some 46% said their organizations were already scaling agentic AI across multiple departments and production workflows, while nearly 79% were running generative and agentic AI simultaneously."
        https://www.infosecurity-magazine.com/news/65-percent-enterprises-ai-agents/
        https://www.cequence.ai/wp-content/uploads/2026/08/EMA-Research-Report-Agents-Without-Guardrails.pdf
      • Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
        "The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year, accounting for 47% of the attacks in their notifications. Nothing arrives as an attachment, so there is nothing to scan. No vulnerability is used, so there is nothing to patch."
        https://thehackernews.com/2026/09/threat-actors-dont-want-better-attacks.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) f990cce2-9ead-4995-b612-185e4520aeec-image.png

      1 การตอบกลับ คำตอบล่าสุด ตอบ คำอ้างอิง 0
      • First post
        Last post