NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ

    Cyber Threat Intelligence 10 September 2026

    Cyber Security News
    1
    1
    13
    โหลดโพสเพิ่มเติม
    • เก่าสุดไปยังใหม่สุด
    • ใหม่สุดไปยังเก่าสุด
    • Most Votes
    ตอบ
    • ตอบโดยตั้งกระทู้ใหม่
    เข้าสู่ระบบเพื่อตอบกลับ
    Topic นี้ถูกลบไปแล้ว เฉพาะผู้ใช้งานที่มีสิทธิ์ในการจัดการ Topic เท่านั้นที่จะมีสิทธิ์ในการเข้าชม
    • NCSA_THAICERTN
      NCSA_THAICERT
      แก้ไขล่าสุดโดย

      Industrial Sector

      • ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
        "Industrial giants Schneider Electric, Siemens, and Aveva have published September 2026 Patch Tuesday advisories, informing customers about vulnerabilities found in their ICS products. Schneider Electric published four new security advisories and updated four others, including one originally released in 2019. The most severe of the newly addressed issues is a critical authentication vulnerability in Modicon M580 and Modicon M580 Safety controllers. Tracked as CVE-2026-3869, the flaw has a CVSS score of 9.2."
        https://www.securityweek.com/ics-patch-tuesday-schneider-electric-siemens-fix-critical-flaws/

      New Tooling

      • AI-Infra-Guard: Open-Source Security Scanner For AI Systems
        "Tencent’s Zhuque Lab built AI-Infra-Guard, an open-source security scanner for AI systems. It fingerprints running services such as Ollama, vLLM and ComfyUI and checks them against more than 1,600 known CVEs, inspects MCP servers and agent skills across 14 categories of risk, and runs jailbreak evaluations against a target model. To check a skill, the platform asks a language model whether it looks malicious. Zhuque Lab scores that call against SkillTrustBench, a public set of 5,520 human-labeled samples across nine risk categories. False positive rates there run from 1.20 percent to 18.67 percent, depending on which model does the judging."
        https://www.helpnetsecurity.com/2026/09/09/ai-infra-guard-open-source-security-scanner-ai-systems/
        https://github.com/Tencent/AI-Infra-Guard

      Vulnerabilities

      • Active Exploitation Of Cisco Secure Firewall Management Center Vulnerabilities
        "Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account."
        https://blog.talosintelligence.com/fmc-ongoing-exploitation/
        https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/
      • Fortinet Patches Critical Vulnerabilities In FortiMonitorOnSight, Chrome Extension
        "Fortinet on Tuesday released patches for 10 vulnerabilities across its products, including critical security defects. The first critical bug, tracked as CVE-2026-84390 (CVSS score of 9.6), is described as an inclusion of sensitive information in source code issue affecting the FortiMonitorOnSight web portal. A remote, unauthenticated attacker could exploit the flaw to bypass authentication via a forged or reused JSON Web Token (JWT). The second critical vulnerability is an improper authentication issue in the Fortinet Privileged Access Agent Chrome extension, tracked as CVE-2026-84388 (CVSS score of 9.1)."
        https://www.securityweek.com/fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension/
      • Ivanti Patches Critical Flaws Across Enterprise Security Products
        "Ivanti on Tuesday announced security updates that address vulnerabilities rated critical and high severity in its Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM) products. Neurons for ITSM received fixes for the largest number of security defects. Of the eight bugs, six are critical-severity issues that could lead to remote code execution, Ivanti warns. These include CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646 (CVSS score of 9.9/10), described as missing authorization issues; and CVE-2026-12650 (CVSS score of 9.9/10), CVE-2026-12744, and CVE-2026-12745 (CVSS score of 9.8/10), described as deserialization of untrusted data weaknesses."
        https://www.securityweek.com/ivanti-patches-critical-flaws-across-enterprise-security-products/
      • Google Fixes Yet Another Actively Exploited Chrome Zero-Day (CVE-2026-87491)
        "Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. “Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in a Tuesday security advisory. The fix has been shipped in Chrome 153.0.8010.36 and .37 for Windows and macOS and Chrome 153.0.8010.36 for Linux."
        https://www.helpnetsecurity.com/2026/09/09/google-chrome-cve-2026-87491-zero-day-flaw/
        https://www.bleepingcomputer.com/news/security/google-patches-seventh-chrome-zero-day-exploited-in-attacks-this-year/
        https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html
        https://www.securityweek.com/chrome-153-patches-seventh-zero-day-of-2026/
        https://securityaffairs.com/198757/security/google-fixes-the-seventh-actively-exploited-chrome-zero-day-of-2026.html
      • DeepSeek Harness < 0.1.2-Alpha.1 Authentication Bypass Via Host Header Spoofing
        "DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP control-plane API that allows attackers to gain full agent control by supplying a spoofed Host header, as the server validates only the client-supplied Host header value rather than the actual TCP connection origin. Attackers can exploit this flaw to invoke privileged commands such as commands/execute with danger-full-access permissions, escalate session approval policies to unconfined execution, and retrieve all stored conversations without any credential or API key."
        https://www.vulncheck.com/advisories/deepseek-harness-alpha-1-authentication-bypass-via-host-header-spoofing
        https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html
      • Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
        "Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through v1.18.5, all released before August 2025, and Alby said one user has been affected so far."
        https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html
      • CISA Adds Four Known Exploited Vulnerabilities To Catalog
        "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
        CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
        CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability
        CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog
      • Skullcandy Dime 3 Wireless Earbuds Contain An Unauthenticated Bluetooth Pairing Vulnerability
        "Skullcandy Dime 3 wireless earbuds, running firmware version 1.0.0.28, accept a new Bluetooth Classic (BR/EDR) pairing request from an unpaired device without requiring the earbuds to be placed into pairing mode or requiring any physical confirmation or interaction from the owner."
        https://kb.cert.org/vuls/id/859658
        https://www.bleepingcomputer.com/news/security/skullcandy-dime-3-earbuds-expose-users-to-bluetooth-hijacking/
      • Over 36,000 Exposed Plex Servers Vulnerable To Recent Flaws
        "Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. Plex urged users a week ago to secure their media servers immediately against security issues that still lack CVE IDs for easy tracking. While the company didn't provide additional details on Tuesday when it issued the warning, these security flaws are known to affect Plex Media Server v1.43.2 and earlier."
        https://www.bleepingcomputer.com/news/security/over-36-000-plex-servers-unpatched-against-recently-disclosed-flaws/
      • New Microsoft Defender 'ShieldCrash' Zero-Day Grants SYSTEM Access
        "An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. ShieldCrash is described as a bypass for the ShieldBreak Defender privilege escalation flaw patched on Thursday, which itself bypassed RoguePlanet, another Defender flaw disclosed in June and patched by Microsoft in July."
        https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldcrash-zero-day-grants-system-access/
        https://thehackernews.com/2026/09/researcher-drops-new-microsoft-defender.html
        https://securityaffairs.com/198726/security/chaotic-eclipse-released-shieldcrash-a-poc-for-microsoft-defender-zero-day.html
        https://www.theregister.com/security/2026/09/09/serial-microsoft-0-day-hunter-drops-yet-another-defender-exploit/5295335
      • Android’s September 2026 Updates Patch 180 Vulnerabilities
        "After two ‘no security vulnerabilities’ bulletins in July and August, Google on Tuesday announced the release of patches for 180 vulnerabilities as part of the September 2026 Android security updates. As usual, the updates are split into two parts. The first part arrives on devices as the 2026-09-01 security patch level and resolves 95 bugs across Android runtime, Framework, System, Setup Wizard, and multiple Project Mainline components (patched via Google Play system updates). “The most severe of these issues is a critical security vulnerability in the System component that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation,” Google notes in its advisory."
        https://www.securityweek.com/androids-september-2026-updates-patch-180-vulnerabilities/
      • Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories
        "Major chipmakers AMD, Arm, and Nvidia published new security advisories on Tuesday to notify customers of vulnerabilities recently discovered in their products. AMD announced fixes for CVE-2026-43603, a NULL pointer dereference flaw in its Linux GPU kernel driver that could lead to system crashes and a denial-of-service (DoS) condition. The company credited Maxime Rossi Bellom and Ramtine Tofighi Shirazi from SecMate for reporting the security defect."
        https://www.securityweek.com/chipmaker-patch-tuesday-nvidia-amd-arm-issue-security-advisories/
      • New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code As Root
        "cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected. The flaw is tracked as CVE-2026-67401. cPanel's advisory calls it an SQL injection issue in EmailTrack, but does not say which cPanel feature or privilege an account needs. cPanel's developer documentation lists an EmailTrack module that tracks email statistics, and the advisory does not say whether that is the affected code."
        https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html
      • One Blank Field Bypasses Direct Send Control
        "ReliaQuest observed that an empty Simple Mail Transfer Protocol (SMTP) envelope sender can bypass RejectDirectSend, a Microsoft 365 control in Exchange Online intended to block unauthenticated Direct Send emails from an organization’s domain. An external sender can omit the envelope domain while retaining an internal-looking address, making phishing messages more likely to be trusted. Direct Send allows devices and applications to send email to recipients in the same Microsoft 365 tenant without authentication. RejectDirectSend evaluates the domain in the SMTP envelope sender, but an empty value means there’s no domain to check. In testing, changing only this field caused Microsoft 365 to accept and queue a message it otherwise rejected."
        https://reliaquest.com/blog/threat-spotlight-one-blank-field-bypasses-direct-send-control

      Malware

      • Once In a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome And Windows Zero-Days
        "Beginning in late August and continuing into September 2026, Proofpoint identified multiple espionage-motivated threat actors rapidly adopting the BlueMoon exploit kit in targeted spearphishing campaigns. Several characteristics of this activity are consistent with a capability that was opportunistically adopted and deployed ahead of an anticipated patch. While the chain exploited vulnerabilities present in the latest stable versions of Chrome and Chromium-based browsers (such as Microsoft Edge), it was paired with a Windows LPE vulnerability present only in older Windows builds. This pairing substantially narrows the pool of viable targets and reduces the chain's overall probability of success."
        https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit
        https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html
        https://therecord.media/china-hackers-chrome-browser-zero-day-multiple-groups
        https://cyberscoop.com/china-espionage-groups-exploit-chain-zero-days/
        https://www.theregister.com/research/2026/09/09/novel-blue-moon-kit-targeting-chrome-and-windows-reflects-new-reality-of-ai-driven-exploits/5295399
      • Workflow Identity Hijacking: The Silent Backdoor In AI Workflows
        "An attacker sends a benign message to a company’s public support email. Minutes later, the attacker receives the quarterly sales numbers from the Finance Director's most recent email. The company's AI workflow read the message, understood the request, searched for the requested information, and replied. No prompt injection was required, no account was breached, and no workflow was hijacked. All the attacker had to do was ask."
        https://noma.security/noma-labs/workflow-identity-hijacking-the-silent-backdoor-in-ai-workflows
        https://www.darkreading.com/threat-intelligence/identity-based-ai-attack-security-enterprise-data
      • Vwork: Weaponized Open-Source Software As An Addon For Gigabud
        "During the “Hook for Gold” research, Group-IB discovered an application called Vwork that was installed within minutes after initial Gigabud infection along with tampered banking applications. Trials to find a sample of Vwork lead to Gigabud samples that are intentionally built to interact with Vwork. The significance of this finding meant that Vwork on infected devices cannot be considered a coincidence anymore. This article reveals what Vwork is, and how it is related to Gigabud."
        https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
        https://www.infosecurity-magazine.com/news/gigabud-android-app-cloning-fraud/
      • Threat Spotlight: Phishing Pages That Exist Only Inside The Victim’s Browser
        "Most phishing campaigns rely on a hosted webpage that security tools can retrieve, analyze, categorize, and eventually block. A recent campaign analyzed by Barracuda researchers breaks that model. Instead of delivering a phishing page from a web server, the malicious content is assembled inside the victim’s browser using a blob URL — a temporary browser-generated URL that points to content stored locally in memory rather than on a website. By the time the phishing page appears, the victim has already been routed through legitimate Microsoft services, including Microsoft OAuth and Microsoft Teams, with little visible indication that anything malicious is taking place."
        https://blog.barracuda.com/2026/09/09/browser-based-phishing-blob-urls-microsoft-redirects
        https://www.securityweek.com/new-phishing-attack-creates-malicious-pages-inside-the-victims-browser/
      • Signing In Without Actually Signing In
        "The price of AI tokens and subscriptions is increasing as AI model providers seek to recoup investment costs. As a result, these accounts are becoming more valuable targets for account takeover. Stopping this is paramount for enterprises. AI theft increases token bills. In three recent cases, it was to the tune of nearly $1 million for one organization, a shock $25,000 bill for a software architect and $600,000 in AI credits for an AI testing organization due to a stolen API key. Some AI providers are detecting this abuse and automatically logging affected users out and removing their payment cards on record to limit the damage. Malware developers and phishing operators have shown interest in applying AI to their operations, and attackers have been documented using stolen AI inference."
        https://www.okta.com/blog/threat-intelligence/signing_in_without_actually_signing_in/
        https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html
      • Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
        "A recent Unit 42 investigation into seemingly low-priority enterprise infections demonstrates how the most effective camouflage in cybercrime is not necessarily in the use of sophisticated techniques, but in how unremarkable the threat appears. The activities that we investigated would typically not require escalation or further inquiry. But upon closer inspection, we discovered a massive cybercrime campaign largely targeting young gamers. Tracked as CL-CRI-1171, in accordance with Unit 42’s attribution framework, the group behind this cluster has operated under the radar for at least two years, distributing an indeterminate number of payloads."
        https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
      • Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
        "GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. GreyNoise has been tracking malicious use of 45[.]142[.]193[.]132 since early July 2026 due to its use for attacks against internet facing technologies and devices from Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE."
        https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf

      Breaches/Hacks/Leaks

      • AdaptHealth Confirms 4.1 Million People Exposed In July Cyberattack
        "Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. The company provides home medical devices, supplies, and related services, including sleep-apnea and respiratory equipment, oxygen therapy, hospital beds, and mobility products. AdaptHealth first disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC) on July 2, 2026, informing that attackers accessed its systems and exfiltrated private data."
        https://www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-people-exposed-in-july-cyberattack/
      • Veradigm Warns Of Patient Data Breach After Ransomware Gang Claims Attack
        "Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. The company says the incident did not cause operational disruptions but affected a small number of customers. Formerly known as Allscripts Healthcare Solutions, Veradigm is a Chicago-based healthcare technology company that supplies medical practices with electronic health records, e-prescribing, patient-engagement, practice-management, and revenue-cycle software."
        https://www.bleepingcomputer.com/news/security/veradigm-discloses-patient-data-breach-after-gentlemen-gang-claims-attack/
        https://therecord.media/electronic-health-record-company-says-customer-data-stolen-in-breach

      General News

      • August 2026 Cyber Threat Landscape: GenAI Data Exposure Emerges As a New Enterprise Risk As Attacks, Phishing, And Ransomware Accelerate
        "August showed that cyber risk is intensifying on multiple fronts at once. Global attacks continued to rise, ransomware volumes accelerated, and phishing remained a consistent entry point for threat actors. GenAI added a more nuanced but equally important signal: while August recorded the lowest rate of high-risk for data exposure in GenAI prompts in several months, enterprise AI usage continued to expand sharply, with the average number of prompts per user rising from around 78 in June to 95 in July and 106 in August."
        https://blog.checkpoint.com/security/august-2026-cyber-threat-landscape-genai-data-exposure-emerges-as-a-new-enterprise-risk-as-attacks-phishing-and-ransomware-accelerate/
      • FBI Officials Say AI Is Bolstering Adversaries, Emphasizing Need To Focus On Cyber Basics, Patching
        "Artificial intelligence is souping up the speed and capabilities of malicious hackers, a top FBI official said Tuesday. And the speed of vulnerability discoveries is forcing organizations to patch more frequently, said another top FBI official. The officials made their remarks one day before the release of a new FBI cyber strategy Wednesday, which touches on AI, relief and justice for victims and other bureau priorities. Speaking to both CyberScoop and at the Billington CyberSecurity Summit, Jason Bilnoski, deputy assistant director of the FBI’s cyber division, said AI is “taking actors to the next level.”"
        https://cyberscoop.com/fbi-cyber-strategy-ai-threats-patching/
      • The Anthropic Glasswing Receipts Are Starting To Trickle In
        "Anthropic’s Project Glasswing is approaching 5 months old, and Anthropic published its Vulnerability Disclosure Ledger on May 22nd. It hadn't received an update until this past week, when it backfilled the ledger with additional findings and updates, so naturally I thought it would be worthwhile to take a look at the receipts. For a bit more context, I've been tracking Project Glasswing since they launched the project on April 7, and have published a series of blog posts covering the project:"
        https://www.vulncheck.com/blog/anthropic-glasswing-receipts
        https://www.darkreading.com/application-security/mythos-vulnerability-firehose-hits-human-bottleneck
      • Gartner: 70% Of SOCs Will Pilot AI Agents. Only 15% Will See Results
        "In the Gartner report Validate the Promises of AI SOC Agents With These Key Questions, analysts Craig Lawson and Andrew Davies posit that “By 2028, 70% of large SOCs will pilot AI agents to augment Tier 1 and Tier 2 operations, but only 15% will achieve measurable improvements without structured evaluation.” Just last year, Gartner placed AI SOC Agents at the Innovation Trigger stage with single-digit adoption. As of earlier this year, Gartner’s Hype Cycle for Security Operations, 2026 put them at the Peak of Inflated Expectations."
        https://www.helpnetsecurity.com/2026/09/09/prophet-security-evaluating-ai-soc-agents/
      • 2026 SpyCloud Identity Threat Report
        "Identity exposure is measurable and fixable – yet most organizations are still navigating with an outdated map, drawn for marked trails rather than the backcountry attackers now roam. The terrain has expanded past employee credentials to session tokens, non-human identities, and third-party ecosystems, and closing the gap means surveying what’s exposed beyond the camp’s edge before attackers get there first. This year’s Identity Threat Report [1] – a survey of security leaders and practitioners across North America, UK and select European Markets – benchmarks how enterprise organizations detect, remediate, and govern identity threats – and what separates the most mature programs from the rest."
        https://spycloud.com/resource/report/identity-threat-report-2026/
        https://www.infosecurity-magazine.com/news/nhis-number-one-corporate-entry/
      • This Key Will Self-Destruct: An Open Standard For Revocable API Keys
        "Every security leader has lived some version of this incident. A researcher, a scanner, or a well-meaning stranger finds one of your API keys sitting in a public repository. Now the clock is running, but instead of a kill switch, what follows is a scavenger hunt. Which company issued this key? Who do I contact? Is there a security.txt? Does anyone read that inbox? By the time the right person revokes the right credential, hours or days have passed, and attackers needed minutes. Bots scrape public repos constantly, and the majority of leaked secrets are still active years later."
        https://www.securityweek.com/this-key-will-self-destruct-an-open-standard-for-revocable-api-keys/
      • Scam Center Strike Force Conducts Seizures Of Chinese-Run Illicit Scammer Marketplace, And Restrains $52 Million In Laundered Crypto Scammer Funds In One Day
        "U.S. Attorney Jeanine Ferris Pirro, together with major federal law enforcement and interagency partners, announced actions taken by the Department of Justice’s Scam Center Strike Force to secure America against Southeast Asian cryptocurrency-related fraud and scams. The Strike Force and the Department of the Treasury took coordinated actions against Xinbi Guarantee (“Xinbi”), an illicit marketplace for scam services, and the Strike Force deployed to Madagascar to assist in the taking down of 13 Chinese-run scam compounds. Approximately $52 million of cryptocurrency involved in scam money laundering was restrained in one day, bringing the total restrained by the Scam Center Strike Force to approximately $938 million."
        https://www.justice.gov/usao-dc/pr/scam-center-strike-force-conducts-seizures-chinese-run-illicit-scammer-marketplace-and
        https://thehackernews.com/2026/09/us-disrupts-xinbi-guarantee-scam.html
        https://therecord.media/us-disrupts-xinbi-guarantee-marketplace-cybercrime

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) c1c561a3-1bce-4607-94f6-362419364e87-image.png

      1 การตอบกลับ คำตอบล่าสุด ตอบ คำอ้างอิง 0
      • First post
        Last post