NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ

    Cyber Threat Intelligence 25 September 2026

    Cyber Security News
    1
    1
    20
    โหลดโพสเพิ่มเติม
    • เก่าสุดไปยังใหม่สุด
    • ใหม่สุดไปยังเก่าสุด
    • Most Votes
    ตอบ
    • ตอบโดยตั้งกระทู้ใหม่
    เข้าสู่ระบบเพื่อตอบกลับ
    Topic นี้ถูกลบไปแล้ว เฉพาะผู้ใช้งานที่มีสิทธิ์ในการจัดการ Topic เท่านั้นที่จะมีสิทธิ์ในการเข้าชม
    • NCSA_THAICERTN
      NCSA_THAICERT
      แก้ไขล่าสุดโดย

      Industrial Sector

      • Botslab G980H Dashcams
        "Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, gain unauthorized access to sensitive data and privileged device functionality, modify device configuration, disrupt device operation."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01
      • Eufy Omni C20, Omni X10 Pro
        "Successful exploitation of these vulnerabilities could allow an attacker to run system level commands or execute arbitrary code."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-02
      • OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise On ICS Integrators
        "NIST this week released a draft of Special Publication 800-82 Revision 4, titled Guide to Operational Technology (OT) Security. Public comments are due by November 30, 2026. The document covers how to secure OT while accounting for the performance, reliability and safety demands specific to these systems. The revision expands the guide’s sector coverage to include building automation, water and wastewater systems, food and agriculture, freight rail, maritime vessels, and the convergence of industrial IoT and cloud. The guide is now organized around NIST Cybersecurity Framework 2.0, and the former risk management section has been reorganized to focus on the framework’s Govern function."
        https://www.securityweek.com/ot-security-guidance-nist-drafts-updated-guide-cisa-fbi-advise-on-ics-integrators/
        https://csrc.nist.gov/pubs/sp/800/82/r4/ipd

      Vulnerabilities

      • SolarWinds Patches Critical RCE Flaws In Observability Self-Hosted
        "SolarWinds has released patches for two severe vulnerabilities in Observability Self-Hosted that could be exploited for remote code execution (RCE). Observability Self-Hosted is an on-premises and hybrid IT monitoring solution that provides organizations with unified monitoring across environments, configuration management, and control over operational data and security compliance. The first flaw, tracked as CVE-2026-28324 (CVSS score of 9.8), is an insufficient integrity check issue leading to RCE on deployments that run non-default and non-secure configurations."
        https://www.securityweek.com/solarwinds-patches-critical-rce-flaws-in-observability-self-hosted/
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability
        CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalog
      • Hackers Now Exploit Critical Roundcube Flaw In Code Injection Attacks
        "A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. Roundcube Webmail is a browser-based IMAP email client used as the default mail interface by thousands of services with millions of users, and it is pre-installed with the widely used cPanel web hosting control panel. In May, the Roundcube security team patched the flaw (tracked as CVE-2026-48842), describing it as a pre-authenticated SQL injection in the virtuser_query built-in plugin, which handles database-driven user lookups and maps users to email addresses."
        https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/
      • CISA: Ransomware Gangs Now Exploiting Critical TeamCity Flaw
        "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. JetBrains patched the security flaw (tracked as CVE-2026-63077) on July 25 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3, saying it is a critical authentication bypass vulnerability that lets attackers with HTTP(S) access execute arbitrary operating system commands."
        https://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw/
      • A Decision Model Breaks Like Any Other Language Model: A First Look At Jev
        "Nobody reads a decision. That is the whole reason we ran this test. A model that writes text gets checked by the person reading the text. A model that returns a verdict gets wired straight into the system that acts on it: an application proceeds to the next hiring stage, a recommendation goes to a committee, or an insurance claim gets rejected. There is no paragraph to disagree with, because there is not one."
        https://blog.checkpoint.com/ai-security/jev-is-not-a-language-model-but-it-breaks-like-one-prompt-injection-against-a-typed-decision-model/
      • Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
        "A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not said which. OnePlus confirmed both flaws in May. In the same reply, the company told Moorats that it alone decides when to make a flaw public and warned that publishing without its permission could result in legal liability. He published on September 24 anyway, when OnePlus had released no fix."
        https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html

      Malware

      • MacSync Under The Microscope: New Delivery Methods And a New Payload
        "MacSync is a relatively young, rapidly evolving family of crypto/info stealers. First advertised on the dark web in 2025 as Mac.c, the stealer was later renamed to MacSync by its creators. The initial versions were implemented as AppleScripts and closely resembled the AMOS stealer family, but over time, MacSync developed distinctive features of its own, including a backdoor module. In this report, we discuss a new infection chain that differs significantly from previous variants. We first spotted it in the wild in September 2026."
        https://securelist.com/macsync-new-version/121383/
        https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/
      • CARBONATO:​ ​a​ ​botnet​ ​built​ ​around An AI Agent​
        "In August 2026, we found an unauthenticated Docker registry that had been publicly exposed since May. Over one day of passive, read-only collection, we recovered 59 repositories, 234 image tags, 605 verified blobs, and 4.3 GB of image data. The archive spans October 2024 through August 2026. It documents two linked product lines: a factory distributing trojanized cryptocurrency wallet apps, and a botnet that compromises Docker daemons exposed on port 2375."
        https://www.threatdown.com/blog/carbonato/
        https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/
      • SalesBleed: Hijacking Agentforce In Slack For Anonymous Phishing Attacks
        "We discovered that Agentforce agents could be hijacked to send phishing messages in Slack. This issue originated from the default Slack Knowledge subagent template and its built-in Reply to a Slack Thread action, which allowed messages to be sent without user confirmation and without any way for other users to know who really initiated the message. Combined with the URL-redaction bypass described in our first post, this vulnerability could allow either an internal user or an external attacker to deliver phishing links using the agent’s own identity."
        https://labs.zenity.io/post/salesbleed-hijacking-agentforce-in-slack-for-anonymous-phishing
        https://www.darkreading.com/application-security/salesbleed-exploits-salesforce-agents-slack-phishing
        https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958
      • Uncovering a SectopRAT Variant Embedded In Legitimate Software
        "The FortiGuard Incident Response (FGIR) team recently investigated an intrusion involving SectopRAT, which was used to control the victim’s device. SectopRAT (also known as ArechClient2) is a .NET-based remote access trojan (RAT) that provides a range of functions through multiple control commands. These include collecting sensitive data from the victim’s device, capturing screens, remotely managing processes and files, controlling bots, and other forms of remote device management."
        https://www.fortinet.com/blog/threat-research/uncovering-a-sectoprat-variant-embedded-in-legitimate-software
        https://www.darkreading.com/cyberattacks-data-breaches/sectoprat-returns-hiding-inside-legitimate-application
      • Ghost Service Accounts Enable M365 Data Theft In Chile
        "Hackers are leveraging overlooked machine accounts in Microsoft 365 (M365) to steal enterprise data from organizations in Chile. Within any organization's M365 environment, there are accounts that belong to humans, sure, but also shared functional identities and accounts for applications and automated processes. Individuals are responsible for their own identities, but who keeps track of, maintains, and secures those nonhuman ones? Without due diligence, those types can fall out of focus and become forgotten relics with default credentials and excessive permissions."
        https://www.darkreading.com/cyberattacks-data-breaches/ghost-service-accounts-m365-data-theft-chile
      • "n0n Ransomware" Emerges As a New Threat Group With Destructive Extortion Claims
        "n0n is a financially motivated cyber extortion group that emerged in September 2026, first seen on September 18, 2026, with activity tracked through September 22, 2026. The group operates a double-extortion model, combining data theft with threats to destroy or encrypt victims' backup and shadow-copy infrastructure, publishing victims to a dedicated Tor-hosted leak site ("no js | no mercy") when payment deadlines are not met.n0n has published 13 victims to date across 10 identified countries, spanning sectors including financial services, education, retail & e-commerce, technology, and healthcare/pharmaceuticals. Of these 13 listings, 2 remain active with pending payment deadlines and 11 have already had data leaked after deadlines expired."
        https://cyberxtron.com/resources/blogs/-n0n-ransomware-emerges-as-a-new-threat-group-with-destructive-extortion-claims--8167
        https://www.infosecurity-magazine.com/news/ransomware-gang-uses-backup/
      • The Psychedelic Stealer: When a CAPTCHA Becomes An Installer
        "Arctic Wolf Labs is tracking an ongoing campaign that compromises legitimate Ukrainian business websites and uses injected iframes to display a Ukrainian-language fake Cloudflare verification page. When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the Windows Run dialog. The command retrieves an MSI package that ultimately delivers a previously unidentified infostealer containing the embedded tag “Psychedelic.”"
        https://arcticwolf.com/resources/blog/psychedelic-stealer-fake-clickfix-captcha-targets-ukraine/
        https://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.html
      • Inside Corp MDM, The Android Spyware Targeting Logistics Companies
        "A malware campaign targeting the logistics sector used fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file disguised as a system service. The delivered app, package com.corp.mdm, is a compact surveillance implant designed to exfiltrate newly received SMS content, divert calls, and maintain a hidden foreground service. The implant is narrow by design. It does not contain the broad surveillance functions often associated with commercial Android spyware. We assess that the threat actor likely used AI during development, and the spyware contains bugs that hinder its capabilities."
        https://haveibeensquatted.com/blog/inside-corp-mdm-android-spyware-targeting-logisitics
        https://thehackernews.com/2026/09/corp-mdm-spyware-targets-logistics.html
      • 17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report By CTM360
        "ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why blocking malicious domains is no longer a useful defense. A particular kind of security problem no patch will close. ClickFix is one of them. The attack begins with a page that presents a problem the user believes is theirs to solve. A human verification check that will not complete. A browser that cannot render the page. A document that will not open. A Mac that is running low on storage. The page offers a remedy in the form of instructions, quietly writes the "fix" to the clipboard, and asks the user to open a system interface they already trust, paste, and press Enter."
        https://thehackernews.com/2026/09/17000-urls-reveal-how-clickfix-turns.html
        https://www.ctm360.com/reports/clickfix-beyond
      • The Rogue RMM Stack: One Phish, Multiple Persistence Paths
        "Attackers are increasingly turning to trusted software your business already depends on instead of custom malware or exploits. In one recent Huntress Security Operations Center (SOC) investigation, a secure-document lure hid the installation of a remote monitoring and management (RMM) tool. The employee didn't know the file they opened would lead to an attacker's successful intrusion, ultimately installing a rogue ITarian client, followed by a ScreenConnect session for persistent access."
        https://www.huntress.com/blog/rogue-rmm-abuse-phishing-persistent-access
      • Russia Escalating Hybrid Attacks Across Europe
        "Since Russia’s full-scale invasion of Ukraine in February 2022, Russia has escalated its use of hybrid, asymmetric warfare across Europe, far beyond the former Soviet Union, where Russia historically focused its aggression. These tactics fall under a Russian military strategy known as New Generation Warfare (NGW). Insikt Group assesses that Russia is likely to escalate NGW tactics over the next two years, potentially culminating in a full-scale NGW campaign. Europe-based private and public sector entities are very likely at risk of physical and cyber sabotage as Russia deploys NGW tactics. Critical infrastructure entities in Europe are at high risk of being targeted, potentially resulting in data loss, physical damage to facilities, or injury or death of personnel."
        https://www.recordedfuture.com/blog/russia-new-generation-warfare
      • When Business Email Compromise Starts Rewriting Reality
        "Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets. This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details and broader findings based within the Zimbra Collaboration Suite. Our investigation disrupted the traditional BEC model in unexpected ways. We uncovered over 50 vulnerabilities, and found that several allow attackers not just to observe environments, but to actively rewrite them by impersonating senders without credentials, controlling inbox visibility, and altering shared documents and calendars."
        https://www.rapid7.com/blog/post/ve-business-email-compromise-rewriting-reality-zimbra-cve/

      Breaches/Hacks/Leaks

      • Early Rogue AI Agent Activity And Attempts To Hack Found On Urlquery[.]net
        "We present evidence that AI agents used the web security service urlquery.net to bypass restrictions and expand their access to the public internet. The agents also tried on three occasions to hack public data providers, including an Australian government website. We link at least some of this activity to agent swarms previously attributed to OpenAI. We also find evidence of earlier agent activity going back to at least March 6th, 2026, and potentially earlier, predating the previously reported Hugging Face, collusion.wiki, and RubyGems incidents by at least two months."
        https://transluce.org/agent-activity
        https://www.bleepingcomputer.com/news/security/openai-hacked-australian-medicare-govt-site-probed-data-providers/
        https://thehackernews.com/2026/09/openai-agent-bypassed-australian.html
        https://therecord.media/openai-australia-health-breach
        https://www.bankinfosecurity.com/rogue-openai-agent-hacks-australian-medicare-site-a-32921
        https://www.infosecurity-magazine.com/news/openai-hacks-australian-medicare/
        https://www.malwarebytes.com/blog/ai/2026/09/openai-agent-breached-medicare-statistics-portal-then-took-months-to-report-it
        https://www.securityweek.com/openai-agents-probed-websites-for-vulnerabilities-while-fetching-public-data/
        https://securityaffairs.com/199662/ai/openai-agent-bypassed-an-australian-government-health-portal-during-internal-research.html
        https://www.helpnetsecurity.com/2026/09/24/openai-agent-hacking-australia/
      • Astrana Latest Healthcare Tech Firm To Report Data Breach To SEC
        "The healthcare company Astrana warned regulators this week that a recent cyberattack exposed confidential information. The company filed a report with the Securities and Exchange Commission (SEC) on Tuesday evening about a recent incident in which hackers impersonated Astrana personnel and spoofed the company’s main corporate telephone number. The hackers contacted employees using the spoofed number and eventually were able to gain access to company servers."
        https://therecord.media/astrana-cyberattack-sec-ransomware
        https://www.securityweek.com/astrana-health-data-breach-impacts-private-confidential-information/
      • Someone Went Shopping In ASUS's eShop – For Customer Data
        "Asus has warned eShop customers that an intruder got into part of its online store and may have helped themselves to contact details and order records. The PC maker disclosed the incident in an email sent to customers, first reported by KitGuru, in which it said had identified "unauthorized access to part of the Asus eShop environment," although exactly when that access occurred remains unclear. "Our investigation indicates that certain customer order information, including contact details and order records, may have been accessed," the company said."
        https://www.theregister.com/security/2026/09/24/someone-went-shopping-in-asuss-eshop-for-customer-data/5298860

      General News

      • How To Build A SASE Framework For Modern Cybersecurity
        "Secure Access Service Edge (SASE) has demonstrated it can address many of the security concerns that arise at the intersection of on-premises, cloud and edge systems that many organizations need to combine to keep up their digital operations. But adopting SASE comes with its own challenges, and it's not a one-and-done process. To build an effective SASE framework, organizations need to rethink security governance, shift the focus of their policies, retrain teams internally and build new relationships externally. This transition can last 6-18 months, maybe longer, and requires maintaining security on both legacy and SASE systems simultaneously."
        https://www.darkreading.com/cloud-security/how-to-build-sase-framework
      • Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'
        "A simple but powerful prompt-injection vulnerability in a popular AI platform, Manus, could have opened the door for data theft and compromise —- and showcases the ongoing risk that users face from prompt injection. Manus is an agentic AI app whose rise to prominence was dramatic. Within a week of its launch in March 2025, 2 million people reportedly had signed up for its user waitlist. The same year it launched, it agreed to a sale to Meta for $2 billion, until the deal was scuppered by the Chinese government. It is now attempting to obtain new funding, which assumes a company valuation of $4 billion."
        https://www.darkreading.com/application-security/prompt-injection-bug-agentic-ai-app-manus
      • SASE Converges Network & Security Into One Cloud Solution
        "Hybrid cloud systems and the adoption of edge computing among enterprises has solved a number of modern problems, from the latency demands of real-time applications to the regulatory demands of data privacy in a global economy. But the intersection of on-premises, cloud and edge computing has created challenges in securing diverse systems under the same roof. Secure Access Service Edge (SASE) addresses this fragmentation. It integrates software-defined networking, threat prevention, access control, and application security into a unified, cloud-delivered platform accessed through a single management interface."
        https://www.darkreading.com/cloud-security/sase-converges-network-security-one-cloud
      • What To Do First When You Get 90 Days To Secure AI Agent Data
        "In this interview with Help Net Security, Kelly Herrell, CEO at Nol8, explains where AI agents create exposure inside organizations. The first thing to examine is the data path: what an agent can reach, what enters its context, and where results go. Ticketing systems, CRM platforms and shared drives hold years of sensitive context that agents can pull together in seconds. The conversation covers a 90-day plan for data access limits, the tension between business and security teams, and the case for enforcing policy in the data path."
        https://www.helpnetsecurity.com/2026/09/24/kelly-herrell-nol8-ai-agent-data-security/
      • Over 75% Of Organizations Experience Microsoft 365 Governance Issues
        "An estimated 77% of global organizations experienced at least one Microsoft 365 governance incident over the past year, with overconfidence in AI controls creating new risks, according to ShareGate. The governance specialist ran two surveys of nearly 1800 IT professionals and leaders across nine countries to produce its second annual State of Microsoft 365 report. Of those that suffered an incident, 38% admitted to leaving former employees or guests with access they should have lost, 35% encountered an audit or compliance gap and 26% had sensitive content reach the wrong people."
        https://www.infosecurity-magazine.com/news/75-organizations-microsoft-365/
      • Data Overtakes Skills As Top Threat Hunting Challenge, SANS Study Finds
        "Data has overtaken skills as the number one barrier for threat hunters, for the first time in the five years the SANS Institute has surveyed the industry. The research organization polled 500 cybersecurity practitioners and leaders across North America, Europe, Latin America and Asia to compile the SANS 2026 Threat Hunting Survey: The Evolution of Threat Hunting. Half (50%) of those respondents named data quality or quantity as their biggest hurdle to threat hunting, up from 41% last year and 34% in 2023."
        https://www.infosecurity-magazine.com/news/data-top-bottleneck-barrier-threat/
      • Autonomous AI Hacks Raise Thorny Questions Of Legal Accountability
        "The Justice Department has a long history of investigating and prosecuting hackers who break into a private company’s network. But what happens when the hackers aren’t human? That’s the question at the center of a public policy debate roiling Silicon Valley and Washington following disclosures by leading tech companies that their artificial intelligence models went rogue and hacked into other organizations. The attacks have generated calls even from within the industry for greater oversight and regulation, spurred congressional inquiries and raised questions about whether a years-old legal framework designed to punish criminal hackers is sufficient in an era of autonomous actors capable of engineering their own havoc."
        https://www.securityweek.com/autonomous-ai-hacks-raise-thorny-questions-of-legal-accountability/
      • Europe’s Technology Backbone Is Becoming a Cyber Target
        "Disruptive attacks on public-facing services, financially motivated cybercrime and compromises of shared technology providers are increasing cybersecurity risks across Europe. ENISA’s Threat Landscape 2026 identifies cybercrime, state-linked activity, foreign information manipulation and interference, hacktivism and vulnerability exploitation as key threats. Geopolitical developments influence attackers’ targets, and interconnected digital systems allow disruption to spread across organizations."
        https://www.helpnetsecurity.com/2026/09/24/enisa-eu-cyber-threats-report/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 5ad2779f-1f02-455a-a537-887c008a4800-image.png

      1 การตอบกลับ คำตอบล่าสุด ตอบ คำอ้างอิง 0
      • First post
        Last post