NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ

    Cyber Threat Intelligence 28 September 2026

    Cyber Security News
    1
    1
    14
    โหลดโพสเพิ่มเติม
    • เก่าสุดไปยังใหม่สุด
    • ใหม่สุดไปยังเก่าสุด
    • Most Votes
    ตอบ
    • ตอบโดยตั้งกระทู้ใหม่
    เข้าสู่ระบบเพื่อตอบกลับ
    Topic นี้ถูกลบไปแล้ว เฉพาะผู้ใช้งานที่มีสิทธิ์ในการจัดการ Topic เท่านั้นที่จะมีสิทธิ์ในการเข้าชม
    • NCSA_THAICERTN
      NCSA_THAICERT
      แก้ไขล่าสุดโดย

      Industrial Sector

      • Considerations For Critical Infrastructure Operators Working With Third-Party ICS Integrators
        "The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—hereafter referred to as the “authoring agencies”—have published this fact sheet to highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control system (ICS) integrators. ICS is an umbrella term referring to integrated networks of hardware and software designed to monitor and automate physical processes, encompassing specialized control systems and devices, such as supervisory control and data acquisition (SCADA) systems and programmable logic controllers. Third-party integrators provide varying types of services for ICS, such as control system design, installation, operational data analysis, device support and service, and daily operational control."
        https://www.cisa.gov/resources-tools/resources/considerations-critical-infrastructure-operators-working-third-party-ics-integrators
        https://www.bankinfosecurity.com/cisa-fbi-warn-ot-operators-about-third-party-hacking-a-32942

      Telecom Sector

      • Inside The Telecom Attack Surface: SS7, BGP Hijacking, And The Technical Reality Of Nation-State Intrusions
        "Nation-state operators rarely need a zero-day to get inside a carrier. Much of the telecom stack still runs protocols designed when every participant was a known, trusted operator. SS7 assumes that the node sending a request has a legitimate reason to send it. BGP assumes a network announcing a route actually owns it. Attackers who understand those assumptions can operate inside a carrier for years without triggering a single alert. For telecom CISOs and SOC teams, defending this environment starts with understanding how these attacks actually work."
        https://cyble.com/blog/ss7-bgp-nation-state-intrusions/

      Vulnerabilities

      • Citrix Confirms Two NetScaler RCE Zero-Days Exploited In Attacks
        "Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws. The vulnerabilities are the same zero-days that cybersecurity researchers, IT providers, and national cybersecurity agencies began privately warning organizations about over the weekend. NetScaler appliances are particularly valuable targets because organizations commonly deploy them as Internet-facing edge devices that provide remote access and application delivery services for internal corporate networks."
        https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
        https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
        https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html
        https://securityaffairs.com/199873/security/citrix-confirmed-two-new-netscaler-flaws-exploited-as-zero-day.html
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability
        CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalog
        https://thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html
        https://securityaffairs.com/199777/hacking/u-s-cisa-adds-microsoft-sharepoint-and-mikrotik-routeros-flaws-to-its-known-exploited-vulnerabilities-catalog.html
        https://www.securityweek.com/microsoft-sharepoint-flaw-cve-2026-65660-now-exploited-in-attacks/
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-one-known-exploited-vulnerability-catalog
        https://securityaffairs.com/199790/security/u-s-cisa-adds-wordpress-flaw-to-its-known-exploited-vulnerabilities-catalog.html
      • Kiteworks Urges 6-Hour Server Shutdown Over Potential Zero-Day Attacks
        "Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack. According to German technology publication Heise, Kiteworks CISO Frank Balonis emailed customers warning that the company had received "credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend.""
        https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/
        https://therecord.media/kiteworks-urges-customers-to-stop-using-systems-incident
        https://thehackernews.com/2026/09/kiteworks-urges-customers-to-shut-down.html
      • Cross-Site Request Forgery In Elementor Plugin Affecting 2 Million+ Sites
        "This blog post is about a Cross-Site Request Forgery vulnerability in the Elementor Website Builder plugin. One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perform. On a stock installation, an administrator clicking the link creates a second administrator account for the attacker. The link needs no JavaScript, no form, and no page under the attacker’s control. It works as a plain anchor in an email, a chat message, or a comment. Patchstack has issued mitigation rules to protect against exploitation of this vulnerability."
        https://patchstack.com/articles/cross-site-request-forgery-in-elementor-plugin-affecting-2-million-sites/
        https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/
        https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html
      • SalesBleed: Indirect Prompt Injection And 0-Click Data Exfiltration On Agentforce
        "We found a way to pull sensitive account data out of Salesforce Agentforce without ever logging in, or requiring the victim to click anything. The entry point was a public Web-to-Lead form, the exit was a DNS query. We call it SalesBleed. In between, sat a few guardrails and Salesforce's Trusted URLs mechanism, which is a redaction layer built to strip untrusted URLs out of agent responses before a user ever sees them. We were eventually able to fully bypass all these mechanisms and exfiltrate data."
        https://labs.zenity.io/post/salesbleed-0-click-data-exfiltration-on-agentforce
        https://www.infosecurity-magazine.com/news/vulnerabilities-salesforce-ai/
        https://www.securityweek.com/salesbleed-flaws-in-salesforce-agentforce-enabled-zero-click-data-exfiltration/
      • How Cloudflare Addressed a Cross-Tenant Data Exposure Vulnerability In Containers
        "On September 4, 2026, Oren Yomtov, a security researcher from Accomplish, responsibly reported a vulnerability affecting Cloudflare Containers and Cloudflare Sandboxes (which is built on Containers), through Cloudflare’s bug bounty program. Cloudflare has fully remediated the vulnerability, and we have no evidence that customer data has been compromised. This post was prepared in collaboration with Oren Yomtov and the Accomplish security research team, whose detailed report and controlled testing helped us validate the issue and respond quickly."
        https://blog.cloudflare.com/containers-cross-tenant-vulnerability/
        https://thehackernews.com/2026/09/cloudflare-fixes-flaw-that-let-one.html
        https://www.bleepingcomputer.com/news/security/cloudflare-fixes-containers-cross-tenant-flaw-exposing-customer-data/
      • File Notification Attacks
        "File-notification systems tell applications when files change, e.g., opened, closed, written, deleted. With only read permission on a file or directory, an attacker can watch these notifications and reconstruct user behavior. We find generic issues similar on each of Linux, Android, Windows, and macOS. However, there are three issues that are severe and unique to their platform: 1. On Linux, watching a readable directory reports every event on a file inside it, even one the attacker cannot read directly. The most severe case of this is with /dev/input, discussed in Inter-Keystroke Timing below. 2. On Android, FileObserver bypasses the FUSE layer's per-app storage view, letting an unprivileged app watch another app's private folder. We show this against WhatsApp, revealing exactly when photos, videos, and files arrive or get deleted, detailed in Revealing Private Communication below."
        https://inoti.fyi/
        https://www.securityweek.com/windows-linux-android-file-notification-systems-leak-user-activity/
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-88771 Citrix NetScaler Improper Input Validation Vulnerability
        CVE-2026-88772 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog

      Malware

      • The Brand Was Real. The Desktop App Wasn’t.
        "Someone is impersonating major HR and payroll platforms with “native desktop apps” that do not exist. The download is real and what it installs is real, but it is not what the victim is expecting. The file is a copy of ConnectWise ScreenConnect, a legitimate remote monitoring and management (RMM) tool of the kind IT teams use to administer machines remotely, configured here for silent unattended access and pinned to the attacker’s server. The lure pages were generated with an AI app builder and hosted on Vercel, the payload was served from GitHub Releases, and a single operator ran at least three brand lookalikes at once."
        https://alluresecurity.com/blog/signal-noise-brand-was-real-app-wasnt
        https://www.helpnetsecurity.com/2026/09/25/fake-payroll-desktop-apps-screenconnect/
        https://www.theregister.com/security/2026/09/25/crooks-use-fake-desktop-apps-to-fool-hr-staff-into-giving-them-remote-access/5299226
      • AliExpress Phishing Campaign: What EfficientIP Research Labs Uncovered
        "EfficientIP Research Labs uncovered an AliExpress phishing campaign designed to lure people to a convincing fake shopping site. On June 9, researchers identified ten potential web addresses before they were registered and added them to DNS Threat Pulse. On July 2, the addresses became active, and their shared naming patterns and infrastructure linked them to the same campaign. The campaign directed visitors through a series of links to a fake AliExpress-themed site. It used familiar branding, a lookalike name and an “Add to Browser” prompt encouraging visitors to install a shopping-assistant extension. Several independent security services classified the destination as malicious or unsafe."
        https://efficientip.com/blog/aliexpress-phishing-campaign-dns/
        https://www.infosecurity-magazine.com/news/aliexpress-phishing-flagged-early/
      • Kothamine Malware Uses Tailscale’s Tailcat To Evade Network Detection
        "We discovered an undocumented remote-access Trojan (RAT) called Kothamine Agent. It supports more than 30 commands and it gives attackers control of an infected Windows computer: they can run commands, read and change files, and add new capabilities. Some versions can also steal browser data and record through the camera and microphone. We found Kothamine linked to malicious npm packages, which could put users and developers who install those packages at risk. In recent versions, the malware uses tailcat, an open-source tool from Tailscale, to receive commands over an encrypted connection. That makes its communications harder to inspect and gives defenders no conventional command-and-control (C2) domain to block."
        https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection
      • Threat Actors Use Google Ads To Target Ledger Users
        "In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake device-verification process prompted users to enter their secret recovery phrases, which attackers could use to access their wallets without the physical devices. In this blog post, ThreatLabz examines the campaign’s infrastructure and the steps used to trick users into submitting their recovery phrases."
        https://www.zscaler.com/blogs/security-research/threat-actors-use-google-ads-target-ledger-users
      • Re-Enabled GitHub Actions Expose Thousands Of Repositories To Mini Shai-Hulud
        "The GitHub Actions actions-cool/issues-helper and actions-cool/maintain-one-comment were compromised in the May 2026 Mini Shai-Hulud campaign. GitHub security team disabled both repositories on May 19, 2026, one day after the malicious content was introduced. Disabling the repositories stopped the attack: downstream workflows could no longer download either action, so they failed before any action code ran. On September 16, 2026, both repositories became accessible again. Their release tags were not cleaned up first. They still point to the malicious content introduced on May 18, so any workflow that references either action by a version tag resumed downloading and executing the payload on its next run."
        https://socket.dev/blog/mini-shai-hulud-actions
        https://thehackernews.com/2026/09/compromised-github-actions-came-back.html
        https://www.bleepingcomputer.com/news/security/github-actions-re-enabled-with-mini-shai-hulud-payload-still-active/
      • PamStealer Adapts Again: a Move To Swift With a Server-Side Decryption Chain
        "Following our July 2026 publication of PamStealer, Jamf Threat Labs has continued to monitor and identify additional variants. While our earliest publication documented a compiled JXA dropper distributed as a fake Maccy clipboard manager, the sample analyzed here uses the same compiled JXA outer format but shifts the lure and rebuilds the delivery chain entirely. What distinguishes this variant from its earlier ones is not what it collects but how it is delivered. Where earlier variants embedded their payload key material directly in the JXA source, it now fetches a purpose-built decryption utility and completes a key exchange with the server before the payload can be unwrapped. Without the server's cooperation, the payload cannot be recovered statically. The second stage has also been rewritten, moving from Rust to Swift, while carrying forward the PAM-based credential validation that gave this family its name."
        https://www.jamf.com/blog/pamstealer-wavel-macos-infostealer/
        https://thehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html
      • Been Told To Pay At a Bitcoin ATM? Read This First
        "Many of us still view cryptocurrency as a niche asset. Yet some estimates claim that nearly one in 10 people globally own some. That’s why you may have noticed Bitcoin or crypto ATMs springing up in retail stores, transport hubs, and gas stations over recent years. Today there are tens of thousands in the US alone. Their job is simple: allow you to buy or sell crypto using cash or card. But scammers also have them in their sights. If you ever receive an unsolicited call urging you to deposit money into a crypto ATM, hang up immediately, no matter how serious the allegations. No real government agency, bank, or company will ever tell you to pay them via a Bitcoin ATM."
        https://www.welivesecurity.com/en/scams/been-told-pay-bitcoin-atm-read-first/
      • Threat Actor Profile: Blue Locker Ransomware
        "Blue Locker Ransomware, first detected in late 2021, the group stayed low-profile for years before making global headlines in August 2025 with a targeted attack on Pakistan Petroleum Limited (PPL), the country’s second-largest oil and gas producer. The attack encrypted servers, wiped backups, and brought financial operations to a standstill for two days, prompting Pakistan’s National CERT to issue an emergency advisory to 39 government ministries and institutions. However, attribution remains vague due to competing analyses linking the malware to the Iranian-associated Proton ransomware family on one hand and to an open-source project called MemeCryptor on the other."
        https://socradar.io/blog/dark-web-profile-blue-locker-ransomware/
      • File Acquisition May Be Recorded As “FileAccessed” In Microsoft 365 (“M365”)
        "A recent trend has emerged where threat actor groups (e.g., ShinyHunters, PEAR, HELIX, etc.) have been leveraging phishing and vishing techniques to gain access to M365 email accounts. Through identity and token abuse, these actors have then automated large-scale file exfiltration and extortion campaigns targeting SharePoint, OneDrive, Microsoft Entra ID (formerly Azure AD), and email data through abuse of the Microsoft Graph API. Variations of this playbook have also included leveraging SSO-connected access to third-party platforms (e.g., Salesforce, Jira, etc.) to exfiltrate additional data. Threat actors may also leverage the My Apps page within Microsoft 365, which provides a centralized view of applications available to the user and is frequently used by threat actors to access connected services and applications."
        https://www.levelblue.com/blogs/spiderlabs-blog/file-acquisition-may-be-recorded-as-fileaccessed-in-microsoft-365
      • Beyond The Ransomware: Tracking Storm-2570’s Consistent Tradecraft Across Deployments
        "Activity associated with Storm-2570, a ransomware affiliate linked to multiple ransomware payloads, illustrates how tracking and responding to ransomware attacks by payload alone can obscure the affiliates carrying out intrusions and the recurring behaviors that defenders can use to detect and disrupt them. Microsoft Threat Intelligence has observed Storm-2570 using consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware. Across multiple investigations, Storm-2570 has maintained largely uniform tradecraft, infrastructure overlaps, and repeated use of the same remote access and cloud exfiltration tooling despite operating across multiple ransomware ecosystems."
        https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/
      • The Not So Silent Miner: Threat Actor Compiles Cryptominer On The Endpoint
        "Huntress researchers recently came across a unique incident where, after gaining initial access via exploiting a known Samsung MagicINFO vulnerability and installing a rogue AnyDesk instance on the endpoint, among other things, the threat actor aimed to deploy a cryptominer. Cryptominers in incidents aren't uncommon, but what raised our eyebrows was that the actor in this incident compiled the cryptominer directly on the endpoint. They ran commands via Silent XMR Miner Builder.exe (a Windows builder for deploying a Monero, or XMR, cryptominer, commonly associated with the open-source SilentXMRMiner project) that executed several .NET Framework utilities and an array of C compilers."
        https://www.huntress.com/blog/threat-actor-compiles-cryptominer
      • ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
        "As an update to the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), along with expanded global targeting across multiple sectors. In June, the threat actor exploited this vulnerability as a zero-day predominantly against academic institutions. This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint."
        https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft
        https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/
        https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html
      • Lunex Unmasked: A New Information Stealer Deployed Through BYOVD
        "The Ontinue Cyber Defence Centre has identified and reverse-engineered a four-stage attack chain associated with the Lunex Malware-as-a-Service platform, targeting Ukrainian-speaking users. The analysed stealer binary was compiled on 12 September 2026, with its supporting infrastructure provisioned shortly beforehand, indicating active development. The attack chain begins with a fake CAPTCHA page and culminates in the deployment of a fully featured C2 agent. The stealer extracts credentials and data from seven Chromium-based browsers, exfiltrates cryptocurrency wallets, and establishes persistent remote filesystem access through a PowerShell-based Native Messaging Host installed within the victim’s browser."
        https://www.ontinue.com/resource/lunex-unmasked-a-new-information-stealer-deployed-through-byovd/
        https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html
      • OpenAI Says Its Models Engaged With US Government Websites In New Model Misbehavior Disclosure
        "OpenAI disclosed Friday that its artificial intelligence agents had interacted with several U.S. government websites in unexpected ways, discovered as part of an ongoing review into the company’s models’ unanticipated behavior. The AI giant’s models accessed publicly available information on two websites operated by the Securities and Exchange Commission as well as U.S. Census Bureau data, the company revealed Friday. OpenAI did not find any use of SEC credentials, access to accounts or nonpublic information, changes to SEC data or systems, or evidence of a compromise or vulnerability, the company said."
        https://www.securityweek.com/openai-says-its-models-engaged-with-us-government-websites-in-new-model-misbehavior-disclosure/
        https://securityaffairs.com/199815/ai/openai-agents-accessed-us-government-websites-without-authorization.html

      Breaches/Hacks/Leaks

      • ShinyHunters Hacked Clop Leak Site Using Grav CMS Path Traversal Flaw
        "The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. The Clop leak site was breached earlier this month by the ShinyHunters extortion gang, which first uploaded a small text file and later replaced the site with a full-page defacement displaying its Umbreon Pokémon logo and a link to its own data leak site."
        https://www.bleepingcomputer.com/news/security/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw/
      • Hackers Steal $351.6 Million In Bitget Crypto Exchange Hack
        "Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. The company discovered the breach Thursday evening after its security systems flagged multiple unauthorized transfers from a limited number of crypto wallets. Bitget has temporarily suspended all withdrawals while investigating the incident with help from law enforcement agencies, on-chain security institutions, and cybersecurity experts at Mandiant and SlowMist."
        https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/
        https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html
        https://therecord.media/crypto-ceo-accuses-north-korea-of-387-million-theft
        https://www.securityweek.com/north-korea-suspected-in-351-million-bitget-crypto-heist/
        https://securityaffairs.com/199754/cyber-crime/cryptocurrency-exchange-bitget-says-north-korea-linked-hackers-stole-351-6-million.html
        https://www.theregister.com/cyber-crime/2026/09/25/bitget-blames-north-korea-for-3875m-crypto-wallet-raid/5299218
      • Cyberattack Hits Welsh Police Force, May Have Affected Staff Data
        "Dyfed-Powys Police in Wales said Friday a cyberattack affecting the force disrupted some non-emergency systems and may have compromised staff information. The force said it identified the incident earlier this month. It has found no evidence that information belonging to members of the public was affected. The police are still investigating whether information involving employees was accessed or compromised, a spokesperson said."
        https://therecord.media/wales-cyberattack-police-breach

      General News

      • Rydox Marketplace Admin Pleads Guilty, Faces 22 Years In Prison
        "A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. Kosovo law enforcement and Albania's Special Anti-Corruption Body (SPAK) arrested 28-year-old Ardit Kutleshi and two other Rydox administrators (Jetmir Kutleshi and Shpend Sokoli) in December 2024. The arrests were part of a joint international law enforcement operation that also shut down the Rydox marketplace, seized the Rydox[.]cc domain, and seized its servers in Kuala Lumpur with the help of the Royal Malaysian Police."
        https://www.bleepingcomputer.com/news/security/rydox-marketplace-admin-pleads-guilty-faces-22-years-in-prison/
        https://www.securityweek.com/kosovar-owner-of-rydox-marketplace-pleads-guilty-in-us-court/
        https://securityaffairs.com/199825/uncategorized/rydox-admin-faces-20-years-after-selling-stolen-data-and-fraud-tools.html
      • Former U.S. Soldier Sentenced For Hacking And Extortion Scheme That Exposed Sensitive Data Of U.S. Government Official
        "Cameron John Wagenius, 22, a former Army soldier who was most recently stationed in Texas, was sentenced today to 70 months in prison and ordered to pay $294,978 in restitution for conspiring to hack into telecommunications companies’ databases, access sensitive records, and extort the companies by threatening to release the stolen data unless ransoms were paid. In November 2024, Wagenius made two online posts that disclosed stolen confidential non-content call detail records belonging to a government official and family members of another former official and threatened to release additional confidential records unless paid a ransom. The text of one of these online posts suggested that Wagenius was motivated by a desire to retaliate for the then-recent arrest of another cybercriminal."
        https://www.justice.gov/opa/pr/former-us-soldier-sentenced-hacking-and-extortion-scheme-exposed-sensitive-data-us
        https://cyberscoop.com/cameron-wagenius-att-snowflake-attacks-sentenced/
      • AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
        "In 1983, WarGames imagined a teenager accessing military systems and nearly triggering a nuclear conflict. The cultural impact was immediate. Congress held hearings, policymakers questioned whether such a scenario was possible, and concerns about computer security entered the mainstream. Forty years later, autonomous AI agents have sparked a similar reaction. Recent disclosures from OpenAI and Anthropic described cybersecurity agents reaching beyond the boundaries of the test environments designed to contain them. The headlines were predictable: AI had "escaped the sandbox.""
        https://www.darkreading.com/cyberattacks-data-breaches/ai-sandbox-escapes-forensic-readiness
      • Stopping IT Worker Scams Requires Revamped HR Process
        "When a suspected North Korean operative applied for a remote AI engineering position at human-risk management firm Nisos in June 2025, the company decided to run its own operation on the fraudster. Nisos notified law enforcement, conducted an HR interview, "hired" the worker, and sent a laptop to that person's US address in Florida — a laptop "farm" — with surveillance implants. "When they opened the laptop, we could see that [the computer was] in a closet with a bunch of other companies' computers," says Ryan LaSalle, the firm's CEO. "We could see it so well that we could see the names of the other companies on the screens across the closet.""
        https://www.darkreading.com/cyber-risk/stopping-it-worker-scams-revamped-hr-process
      • Threat Detection Dashboards Are Masking Security Coverage Gaps
        "A detection rule can show up as deployed on a coverage dashboard and still never fire when an attacker uses the technique it was built to catch. Conifers assessed 14,652 detections in its customer base, including rules written by customers and detections managed by vendors in SIEM, endpoint, cloud, identity, email and network tools. The research found that 47% of detections in the average organization need attention."
        https://www.helpnetsecurity.com/2026/09/25/threat-detections-coverage-gaps-report/
      • Stop Watching What AI Agents Say And Start Watching What They Do
        "In this interview with Help Net Security, Ariel Assaraf, CEO of Coralogix, explains why a system prompt can describe a boundary for an AI agent but cannot enforce one. Assaraf covers how his team builds AI agent guardrails at the execution layer, limits context without expanding authority, and tunes controls by risk so agents stay useful during incidents. He describes how he tracks the consequences of agent actions, since an agent can return 200s and still do harm."
        https://www.helpnetsecurity.com/2026/09/25/ariel-assaraf-coralogix-ai-agent-guardrails/
      • Your Incident Count Is Missing a Few Incidents
        "If you run security for a brand with hundreds or thousands of locations, the tools you’ve bought may have little to do with whether an attack stays at one store. A new VikingCloud survey asked 200 security and IT leaders at U.S. and European chains about the past year. None of the 13 security technologies it measured was tied to less spread between sites, and neither was real-time visibility. One policy decision was. The sections below cover that decision and why it matters most if franchisees run some of your sites. They also cover how many serious incidents never reach executive leadership, and the exposure that opens with every new store. Eighty percent of these chains open a location before central monitoring and enforcement reach it. The problem is widespread: 86% of respondents were attacked in the past year, and 77% of those saw the attack move past its starting point into other locations, corporate systems, or shared vendors."
        https://www.helpnetsecurity.com/2026/09/25/eu-usa-retail-chain-cyberattacks/
      • Exploit.in Database Reveals The Roots Of Today’s Ransomware Ecosystem
        "Ransomnews researcher Dancho Danchev dug up a database dump of Exploit.in covering its first three years, from February 2005 to May 2008, and the numbers inside it tell a story about Russian cybercrime that enforcement press releases don’t. The dump contains 9,647 registered members, 13,925 threads, and 80,891 posts. The researcher who analyzed it had been reading Russian-language forums since those years and expected to recognize the layout. What surprised them wasn’t the marketplace threads selling shells and credit cards next to botnet rental offers. It was how many of the people from 2005 are still on the boards twenty years later."
        https://securityaffairs.com/199800/cyber-crime/exploit-in-database-reveals-the-roots-of-todays-ransomware-ecosystem.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) e81ab778-66d4-4f05-b311-2dd8be30a873-image.png

      1 การตอบกลับ คำตอบล่าสุด ตอบ คำอ้างอิง 0
      • First post
        Last post