NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ

    Cyber Threat Intelligence 23 September 2026

    Cyber Security News
    1
    1
    5
    โหลดโพสเพิ่มเติม
    • เก่าสุดไปยังใหม่สุด
    • ใหม่สุดไปยังเก่าสุด
    • Most Votes
    ตอบ
    • ตอบโดยตั้งกระทู้ใหม่
    เข้าสู่ระบบเพื่อตอบกลับ
    Topic นี้ถูกลบไปแล้ว เฉพาะผู้ใช้งานที่มีสิทธิ์ในการจัดการ Topic เท่านั้นที่จะมีสิทธิ์ในการเข้าชม
    • NCSA_THAICERTN
      NCSA_THAICERT
      แก้ไขล่าสุดโดย

      Industrial Sector

      • LwIP TCP/IP Stack MQTT Client Application
        "Successful exploitation of this vulnerability could allow an attacker to gain full code execution on the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-01
      • LwIP (Lightweight IP)
        "Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-02
      • Siemens Siveillance Control
        "A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server. Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-03
      • Siemens Industrial Edge Management
        "Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-06
      • Siemens SIMOVE Fleetmanager And SIPLANT
        "SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-07
      • Siemens SIPLUS And SIMATIC Products
        "Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-04
      • Siemens Desigo CC Family
        "A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-05
      • Siemens WTV676 And WTV776
        "The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the latest versions."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-08
      • OpenPLC Runtime v3
        "Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-09
      • Operational Technology Scope Expands As Security Matures
        "Serious cybersecurity incidents involving operational technology systems carry a cost, averaging over 16 hours of downtime and losses of up to $500,000 per hour. As a result, more industrial organizations report putting plans and capabilities in place designed specifically to prevent such downtime, or to minimize operational disruption when it does occur. Those findings come from Honeywell Technologies' inaugural 2026 Operational Technology Cybersecurity Benchmark Report, based on studies conducted by ISMG advisory firm CyberTheory."
        https://www.bankinfosecurity.com/operational-technology-scope-expands-as-security-matures-a-32890
        https://www.honeywell.com/us/en/insights/research/2026-ot-security-benchmark
      • Beyond The Pipes: The Identity Exposure Hiding In U.S. Water Utility Vendors
        "Recent attacks against U.S. water and wastewater systems have put a spotlight on exposed operational technology – PLCs (programmable logic controllers) and HMIs (human-machine interfaces) reachable from the public internet, still running default passwords. That’s a real problem, and CISA has said so directly. But it’s not the only one. SpyCloud researchers collated a target database of 66,845 EPA-registered drinking-water and wastewater systems and completed a record-level identity analysis on 10,000 of those organizations, spanning utilities, and the ICS/OT and water-technology vendors that supply them. What we found: identity exposure runs through this sector on its own track – separate from, but just as urgent as, the OT risk making headlines."
        https://spycloud.com/blog/water-utility-identity-exposure/
        https://cyberscoop.com/spycloud-study-water-utilities-infostealer-exposure/
      • More Than a Third Of Industrial Orgs See Cybersecurity Risk As a Top Obstacle To Growth, Study Finds
        "Rockwell Automation, Inc. (NYSE: ROK), the world’s largest company dedicated to industrial automation and digital transformation, today released “Operational Resilience in the Age of Connectivity,” an industry insights report based on input from 1,500 manufacturing and industrial operations decision makers across 17 countries. The research reveals a disconnect between confidence in comprehensive cybersecurity protection and operational risk. Although industrial organizations are investing in cybersecurity, those investments do not automatically translate into operational resilience."
        https://www.darkreading.com/cyber-risk/third-industrial-orgs-see-cybersecurity-risk-top-obstacle
        https://www.rockwellautomation.com/en-us/capabilities/industrial-cybersecurity/operational-resilience-in-the-age-of-connectivity2.html

      New Tooling

      • Introducing CAIRN: Frontier Tracking For AI-Integrated Malware
        "A cairn is a marker left behind on a trail, a deliberately placed stack of stones that helps hikers find their way when the path is unclear. Attackers building AI-integrated malware unintentionally (and inevitably) leave behind markers of their own: prompt templates, provider endpoints, API keys, jailbreak terms, and other artifacts embedded throughout their tooling. When we consider these strings as cognitive artifacts, or vestiges left behind from AI integration, we can enable a new, metadata-first hunting methodology for AI-integrated malware that is fast and scalable. These artifacts can be extracted, related, and classified without ever touching the underlying binary."
        https://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/
        https://www.helpnetsecurity.com/2026/09/22/cairn-open-source-framework-ai-malware-closedquorum/

      Vulnerabilities

      • Security Advisory – Action Required – Active Exploitation Of CVE-2026-85102 And a Management Pre-Authentication Vulnerability CVE-2026-93616
        "As part of Check Point’s Frontier AI Readiness Program, we continue to release Jumbo hotfixes with security fixes and hardening improvements for our Firewall and Management products. This advisory addresses the active exploitation described below, and the immediate steps customers should take to protect affected systems. Check Point Research has identified active exploitation of two vulnerabilities affecting Security Gateway and Security Management: A fix for CVE-2026-85102 has been available since September 9, and customers who have applied it are already protected. CVE-2026-93616 is a newly discovered zero-day vulnerability in Security Management, and a fix is available now as part of this advisory."
        https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
        https://www.bleepingcomputer.com/news/security/check-point-patches-management-server-zero-day-exploited-in-attacks/
        https://thehackernews.com/2026/09/check-point-warns-of-management-server.html
        https://securityaffairs.com/199549/security/check-point-fixes-a-new-actively-exploited-critical-security-flaw.html
      • D-Link Warns Of Max Severity Zero-Day Bug In DIR-822A Routers
        "D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. This security flaw stems from a stack-based buffer overflow and improper data handling in the DHCP server component and can be exploited without authentication or user interaction. Attackers without valid credentials on the same local network can send crafted DHCP packets to the device, trigger the overflow, and potentially crash the DHCP daemon or achieve remote code execution on targeted devices."
        https://www.bleepingcomputer.com/news/security/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers/
        https://www.bankinfosecurity.com/d-link-flags-max-severity-zero-day-in-legacy-router-a-32896
      • JFSA-2026-001686326 - Bifrost Is Vulnerable To Unauthenticated Remote Code Execution Via MCP Stdio Client Registration
        "Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image). The HTTP request may time out. The process is already running. transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it. The 1.6.x line through 1.6.11 does not contain the fix."
        https://research.jfrog.com/vulnerabilities/bifrost-is-vulnerable-to-unauthenticated-remote-code-execution-via-mcp-stdio-client-registration-cve-2026-90898/
        https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html
      • New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited In Certificate-Based Setups
        "Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are exposed. As of September 22, fixed releases are out for the 5.2 and 6.4 release trains, but not yet for the 6.1 and 7.0 trains. Arista has already patched the Hosted and Dedicated versions of VCO. The affected releases include those that fixed a different VCO flaw, which Arista reported as exploited in July."
        https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html
      • WordPress 7.1.2 Security Release: Unauthenticated LFI To RCE
        "WordPress 7.1.2 landed on 22 September 2026. It’s a security-only release with a single fix, and that fix is the most serious thing WordPress has patched in a while: an unauthenticated local file inclusion in page template resolution that can reach remote code execution. Patchstack customers are protected by a RapidMitigate rule. We still recommend updating to the most recent version of WordPress available."
        https://patchstack.com/articles/wordpress-7-1-2-security-release-unauthenticated-lfi-to-rce/
        https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html
      • SharePoint Flaw Initially Listed As Spoofing By Microsoft Enables Authenticated RCE
        "A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been available since the August 11 security updates, and the National Vulnerability Database scores it 8.8."
        https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html
      • Comment2Shell: Zero-Click Pre-Auth XSS To RCE In WordPress Core
        "This blog post is about an unauthenticated stored XSS vulnerability in WordPress core, tracked as CVE-2026-93485. If you use WordPress, please update to at least version 7.1.1, or to the latest release in your branch. The fix was backported to every supported branch down to 4.7.36."
        https://idnsec.com/research/comment2shell-zero-click-pre-auth-xss-to-rce-in-wordpress-core/
        https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html
      • CISA Adds Four Known Exploited Vulnerabilities To Catalog
        "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability
        CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability
        CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
        CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalog
      • New Windows Defender Zero-Day Blocks Microsoft Antivirus Updates
        "Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates. Naceri named it BigDiskBuster and said it is similar to another Defender zero-day known as UnDefend, which he released in April and that allowed standard users to block definition updates. The security researcher added that BigDiskBuster works on all supported Windows versions and that it needs to run in the background to block Defender updates."
        https://www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/
        https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html
        https://www.theregister.com/security/2026/09/22/nightmareeclipses-latest-zero-day-leaves-microsoft-defender-stuck-in-the-past/5298320
        https://www.securityweek.com/nightmare-eclipse-drops-new-microsoft-defender-exploit-after-revealing-identity/
        https://securityaffairs.com/199538/hacking/chaotic-eclipse-released-bigdiskbuster-a-poc-for-windows-defender-update-dos-zero-day.html
      • Meta’s Muse AI Assistant Has a Zero-Day That Can Turn It Into a Mac Backdoor
        "Mac security researcher Patrick Wardle says it’s trivial to turn Muse into “the ultimate backdoor.” Increasingly, AI assistants are changing from tools that simply answer questions into agents that can plan tasks, use connected services, and take actions for us. These actions might include booking appointments, filling out forms, creating documents, making purchases, or interacting with email and calendars."
        https://www.malwarebytes.com/blog/bugs/2026/09/metas-muse-ai-assistant-has-a-zero-day-that-can-turn-it-into-a-mac-backdoor
        https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html
      • New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access To Host Memory
        "A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine. The affected code is part of the mainline Linux kernel for ARM64, and it is fixed in Linux 6.18.51, 7.2.5, and 7.3-rc1."
        https://thehackernews.com/2026/09/new-linux-kernel-flaw-gives-arm64-kvm.html

      Malware

      • Larva-25012: A 2026 Proxyware Distribution Campaign By The Threat Actor (DigitalPulse, SOAX, Appsalt, IPRoyal)
        "The AhnLab SEcurity intelligence Center (ASEC) has been monitoring proxyjacking attacks and confirmed that, in the second half of 2026, the Larva-25012 threat actor has resumed actively distributing Proxyware. Rather than conducting malware distribution through new methods, the threat actor appears to have targeted already infected systems to distribute Proxyware."
        https://asec.ahnlab.com/en/95516/
      • Open Season On Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation
        "GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. GreyNoise has been tracking malicious use of an IP address since early June 2026 due to its frequent use in scans and attacks against a variety of technologies. We are withholding the exact IP address due to victim sensitivities and operational risk. Once these factors have been mitigated, GreyNoise will publish an update."
        https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation
        https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/
      • The Closed Quorum: Inside The First Reported Autonomous AI C2 Implant
        "AI’s impact on offensive cyber operations has thus far mainly focused on two dimensions: speed and scale. Attackers can generate phishing lures faster and produce more malicious code variants with less effort. These are real effects, visible in the proliferation of AI-generated coding samples and agent-assisted intrusions that have become common in the past few years. But in each case, the human operator remains present: directing the tooling, selecting targets, and guiding the execution. AI makes the operator faster and more productive but does not remove them from the operation."
        https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/
        https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/
        https://www.theregister.com/security/2026/09/22/windows-closedquorum-malware-uses-ai-models-to-autonomously-select-post-compromise-actions/5298435
      • From Payment Plan To Ransomware - Inside a Global Group Attack
        "Highly sophisticated ransomware now targets industries worldwide. Today’s ransomware allows threat actors to infiltrate networks, encrypt confidential data, and hold critical systems hostage until a cryptocurrency ransom is paid. Worse, threat actors often employ “double extortion” techniques by stealing sensitive company data and threatening to publish data publicly if the ransom is not paid. By weaponizing a company’s digital assets against itself, ransomware stands as the most severe cybersecurity threat to modern business operations."
        https://cofense.com/blog/from-payment-plan-to-ransomware-inside-a-global-group-attack
      • Mind The (Patch) Gap, Part 2: Fake Websites Used To Deploy Chrome & Windows 0-Day Exploits
        "On September 9, 2026, Volexity published a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) by two different Chinese advanced persistent threat (APT) actors. Shortly after that blog post was published, Volexity discovered additional campaigns—this time from a third Chinese threat actor, tracked by Volexity under the alias UTA0565—that used the same chained exploits on September 3-4, 2026, while the vulnerabilities were still unpatched. Notably, this threat actor’s campaigns differed from previously documented attacks by using multiple fake websites to deceive victims."
        https://www.volexity.com/blog/2026/09/21/mind-the-patch-gap-part-2-fake-websites-used-to-deploy-chrome-windows-0-day-exploits/
        https://cyberscoop.com/volexity-uta0565-china-exploit-chain-chrome-microsoft/
      • Relaying To The Frontier
        "Team Cymru has uncovered 10,000+ hidden gateway servers masking malicious activity originating in China that bypassed AI providers' region bans and potentially siphoned proprietary model outputs. This discovery now equips our customers and partners to detect and stop the abuse of frontier AI models, preventing exorbitant recovery costs, and compliance and IP exposure."
        https://www.team-cymru.com/post/llm-gateway-frontier-model-abuse
        https://www.darkreading.com/cyber-risk/relays-masking-chinese-access-frontier-ai-models
      • Spraying In The Andes: TeamFiltration Returns To Exploit Forgotten Service Accounts
        "Proofpoint researchers identified an active TeamFiltration campaign - tracked as UNK_CondorFiltration, that targeted over 5,700 accounts across 28 Microsoft 365 tenants in Latin America, focusing intensively on Chilean organizations. All 7 successfully compromised accounts were unmanaged functional/service accounts with no prior legitimate login baseline, strongly indicating default or predictable passwords that had never been rotated, with no MFA enforcement. Several compromised accounts showed post-access activity beyond the initial credential validation: the attacker signed in from a German VPN node, attempted to authenticate to the corporate VPN, and accessed several Azure apps, including OfficeHome, Azure Portal, and SharePoint Online."
        https://www.proofpoint.com/us/blog/threat-insight/Spraying-in-the-Andes-TeamFiltration-Returns
      • Malicious Npm Campaign Targets Developers Integrating Twilio
        "The volume of malware on public repositories hasn’t decreased. ReversingLabs (RL) has never seen more malicious packages published on public repositories, and the overall count of malicious software is steadily rising. Looking at the metrics, npm saw around 5308 unique malicious packages published in 2024 (excluding spam). By August of this year, the number of malicious npm packages reached 5723, exceeding the total for all of 2024 in just eight months. And the number of malicious packages continues to grow."
        https://www.reversinglabs.com/blog/malicious-npm-campaign-twilio
        https://thehackernews.com/2026/09/malicious-npm-package-poses-as-twilio.html
      • SideCopy Threat Intel: MSHTA-Driven Execution And RAT Deployment
        "The modern cyber warfare landscape has evolved significantly as threat actors pivot toward simple yet highly effective and evasive malware. While the primary objective of advanced persistent threat (APT) groups like SideCopy has historically been the surveillance and exfiltration of sensitive data from government officials and high-ranking personnel, their strategic scope has recently broadened to include academic institutions. SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols. This delivery mechanism facilitates the deployment of a remote access trojan (RAT), which serves as the central pillar of their offensive infrastructure."
        https://www.trellix.com/blogs/research/sidecopy-threat-intel-mshta-execution-rat-deployment/
        https://thehackernews.com/2026/09/sidecopy-broadens-india-targeting-to.html
      • Process Parameter Poisoning: Inside a Novel EDR Evasion Technique
        "Modern Endpoint Detection and Response (EDR) platforms have made traditional malware injection techniques significantly harder to execute. In most cases, if a threat actor attempts to write malicious code into a process, an alert will fire. However, that sense of security is being actively challenged as cybercriminals and red teams find new ways to blend malicious payloads into standard operating system routines. Flashpoint’s Intelligence team built and tested a proof-of-concept for a newly disclosed technique known as Process Parameter Poisoning. By compiling a custom payload and layering evasion mechanics, our analysts demonstrated how easily traditional API hooks can be rendered blind in a laboratory environment—achieving zero alerts across tested EDR/XDR controls."
        https://flashpoint.io/blog/process-parameter-poisoning-edr-evasion-technique/
      • Npm Supply-Chain Attack Abuses Trusted Publishing To Ship GHAPPIER Loader
        "A high-severity supply-chain attack was disclosed affecting the npm package @dforge-core/dforge-mcp, allowing attackers to distribute a remote-shell implant via a legitimate-looking update carrying valid npm provenance signatures. Due to the potential for full system compromise and the difficulty of forensic detection, immediate action is recommended for any organization that consumed version 0.2.21."
        https://orca.security/resources/research/ghappier-loader-npm-supply-chain-attack/
      • Graphalgo Campaign Spreads To Terraform Providers And Go Modules
        "We’ve identified Go malware distributed via at least two Terraform providers and at least two Go Modules. This is the first time we’ve observed malware distributed via Terraform providers. The malware overlaps with the Graphalgo NPM malware campaign, first reported by ReversingLabs in February 2026, and also reported on in the last week by Safedep, CheckMarx, and JFrog. The malware is a Go port of the Graphalgo malware that shares blockchain and Slack infrastructure and a public key with recent JavaScript samples distributed via NPM. The threat actor has also created at least two fake Go ecosystems to help promote its packages, suggesting an ongoing interest in the Go ecosystem."
        https://www.aikido.dev/blog/graphalgo-terraform-go-modules

      Breaches/Hacks/Leaks

      • ShinyHunters Claims FBI Hack, Data Theft In PeopleSoft Zero-Day Breach
        "The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure. ShinyHunters claims it stole between 2TB and 3TB of data from the agency, including information on current and former FBI employees, job applicants, and other internal records."
        https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/
        https://cyberscoop.com/shinyhunters-claims-fbi-attack/
        https://www.theregister.com/security/2026/09/22/shinyhunters-claims-fbi-hack-this-is-not-financially-motivated/5298385
      • Elsevier.com, Evolve And Manuscript Submission Redirected To LAPSUS$ For At Least 78 Minutes
        "For at least 78 minutes on the evening of September 21, Elsevier's own homepage served an extortion page. Typing www.elsevier.com landed visitors on a site branded LAPSUS$ GROUP, Chapter II, carrying a signed statement that taunted the FBI and counted down to a future victim. It was not a lookalike domain and not a phishing email. The real address went to the attacker's page. Two other Elsevier properties did the same: submit.elsevier.com, where researchers upload manuscripts for peer review, and evolve.elsevier.com, the platform American nursing programs use for HESI exams and coursework. ScienceDirect was unaffected throughout. This was not ransomware. Nothing was encrypted and no Elsevier data has been claimed by anyone. What is confirmed is narrower and, in one specific way, worse: for the length of that window, someone else controlled where Elsevier's traffic went."
        https://www.cloudskope.com/breaches/elsevier-lapsus-domain-hijack-2026
        https://www.helpnetsecurity.com/2026/09/22/elsevier-domains-hijack-lapsus/

      General News

      • August 2026 Infostealer Trend Report
        "This report summarizes the distribution channels, number of Infostealers, number of detections, and companies disguised as targets by new Infostealers collected during the month of August 2026. It is based on data from AhnLab SEcurity intelligence Center (ASEC), AhnLab product diagnostic logs, automated data collection systems, email honeypot systems, and automated C2 analysis systems."
        https://asec.ahnlab.com/en/95519/
      • Disrupting EvilTokens: The AI Chatbot Built For Cybercrime
        "Microsoft has disrupted EvilTokens, a powerful cybercrime platform that used AI at every step of the attack chain—from compromising email accounts to designing intricate roadmaps for financial fraud and scams. While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim’s inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed. The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action. In short, AI was not simply helping attackers write more convincing messages. It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible."
        https://blogs.microsoft.com/on-the-issues/2026/09/22/disrupting-eviltokens-the-ai-chatbot-built-for-cybercrime/
        https://www.bleepingcomputer.com/news/security/eviltokens-phaas-disrupted-after-compromising-12-000-microsoft-accounts/
        https://www.darkreading.com/identity-access-management-security/microsoft-disrupts-eviltokens-device-code-phishing-service
        https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html
        https://therecord.media/two-arrested-in-uk-after-microsoft-takedown-eviltokens
        https://cyberscoop.com/microsoft-eviltokens-cybercrime-service-takedown/
        https://www.theregister.com/security/2026/09/22/uk-cops-arrest-2-eviltokens-suspects-microsoft-seizes-50-phishing-kit-websites/5298317
      • Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real
        "The debate around AI governance heated up this past week as AI experts warned that the growing number of rogue AI agents and instances of misaligned behavior are merely a preface to worse threats in the future. On Sept. 12, Anthropic CEO Dario Amodei warned in a widely read column that AI could soon slip the harness of human control if development is left unchecked. Within a few days, Microsoft delivered a Humanist AI Code of Conduct (read: manifesto) pledging human-centered development, and Google DeepMind's CEO agreed in principle in a post on X to the calls for more controls. Although Anthropic, OpenAI, and x.AI have all also suggested tighter government regulations for the technology, President Donald Trump dismissed the idea, suggesting that winning the AI competition with China is more important, reportedly saying, "Whoever wins AI, wins.""
        https://www.darkreading.com/cyber-risk/rogue-incidents-debate-ai-safety-gets-real

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 0bcdd868-7318-4640-a6ea-4e83352450b0-image.png

      1 การตอบกลับ คำตอบล่าสุด ตอบ คำอ้างอิง 0
      • First post
        Last post