NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ

    Cyber Threat Intelligence 05 October 2026

    Cyber Security News
    1
    1
    14
    โหลดโพสเพิ่มเติม
    • เก่าสุดไปยังใหม่สุด
    • ใหม่สุดไปยังเก่าสุด
    • Most Votes
    ตอบ
    • ตอบโดยตั้งกระทู้ใหม่
    เข้าสู่ระบบเพื่อตอบกลับ
    Topic นี้ถูกลบไปแล้ว เฉพาะผู้ใช้งานที่มีสิทธิ์ในการจัดการ Topic เท่านั้นที่จะมีสิทธิ์ในการเข้าชม
    • NCSA_THAICERTN
      NCSA_THAICERT
      แก้ไขล่าสุดโดย

      Financial Sector

      • 8 Out Of 10 Banks HATE This One Weird 3SKey RCE
        "1M+ users, an extension middleware+native host for authentication with eIDs, 3SKeys and other hardware signing tokens had a drive-by RCE which enabled any site or iframe a user saw to silently download and execute a dll due to a poor hand-rolled implementation of RSA-2048 token validation, enabling a use of uninitialized memory validation bypass which enabled "plugins" (DLLs) to be loaded. v2.16.0.0 of the extension and native host is vulnerable. CVE-2026-18397. CVSS 9.4."
        https://amibeingpwned.com/blog/8-in-10-banks
        https://www.darkreading.com/cybersecurity-operations/swift-banking-govt-middleware-rce

      Vulnerabilities

      • GitLab Warns Of Critical RCE Vulnerability In AI Gateway Service
        "GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. AI Gateway is a service that gives access to AI-native GitLab Duo features. While GitLab operates its own cloud-based AI Gateway instance used by GitLab.com, GitLab Self-Managed, and GitLab Dedicated, users can also deploy their own self-hosted instances on GitLab Self-Managed through GitLab Duo Self-Hosted. Tracked as CVE-2026-90970, this security flaw stems from an improper neutralization weakness and can let attackers with basic privileges and Duo Agent Platform access execute arbitrary commands on unpatched instances."
        https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/
        http://docs.gitlab.com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-19-4-1-released/
        https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html
        https://securityaffairs.com/200283/hacking/cve-2026-90970-critical-gitlab-ai-gateway-flaw-fixed.html
      • Dell Asks Admins To Patch Max Severity CSM Flaws As Soon As Possible
        "Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. CSM supports Dell's primary storage platforms (PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT), and it extends the capabilities of the standard Container Storage Interface (CSI) drivers for Kubernetes. In a security advisory published on Thursday, Dell said that both critical security flaws were found in the Dell CSM Authorization security module and stem from "missing authentication for critical functions" weaknesses."
        https://www.bleepingcomputer.com/news/security/new-max-severity-dell-csm-flaws-give-hackers-admin-privileges/
        https://www.dell.com/support/kbdoc/en-us/000515771/dsa-2026-448-security-update-for-dell-container-storage-modules-multiple-vulnerabilities
        https://thehackernews.com/2026/10/dell-csm-flaws-enable-unauthenticated.html
      • Fortra Patches Critical Vulnerabilities In BoKS
        "Fortra has released patches for eight vulnerabilities in Core Privileged Access Manager (BoKS), including three critical-severity bugs. BoKS provides organizations with central management of Unix and Linux fleets, enabling policy enforcement and access control across accounts. On Thursday, the company warned that BoKS Manager deployments relying on BoKS keytab for Active Directory service account management are affected by a critical flaw leading to authentication bypass."
        https://www.securityweek.com/fortra-patches-critical-vulnerabilities-in-boks/
      • Citrix Patches NetScaler SAML Zero-Day Exploited In Attacks
        "Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. The vulnerability is a memory buffer flaw affecting NetScaler ADC and NetScaler Gateway appliances using SAML authentication with Gateway or AAA functionality. The Citrix security advisory says the vulnerability has a CVSS score of 8.7 and has been used in targeted attacks against unmitigated NetScaler deployments, causing denial-of-service conditions."
        https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/
        https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-102489 Zammad GmbH Zammad Session Fixation Vulnerability
        CVE-2026-102490 Zammad GmbH Zammad Improper Privilege Management Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/10/02/cisa-adds-two-known-exploited-vulnerabilities-catalog
        https://securityaffairs.com/200248/security/u-s-cisa-adds-zammad-gmbh-zammad-flaws-to-its-known-exploited-vulnerabilities-catalog.html
      • How We Hijacked An AI Agent With a Single Email
        "Salt Labs found that the agentic AI platform Manus could be hijacked with a single email. By hiding malicious instructions inside an ordinary message, researchers got Manus to execute malicious code and, from there, reach the email, cloud storage, and code repository accounts a user had connected to it. The full attack required nothing from the victim beyond asking Manus to check their inbox. No stolen password, no clicked link. The most important finding is not the specific flaw, which has since been resolved and is no longer exploitable, but what it reveals about autonomous systems. Manus's own security guardrail detected the attack, but only after the code had already run. On a system that acts on its own, no human sits between the alert and the action, so a control that fires a moment too late provides no protection."
        https://salt.security/blog/how-we-hijacked-an-ai-agent-with-a-single-email
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-88779 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/10/04/cisa-adds-one-known-exploited-vulnerability-catalog

      Malware

      • SMTP Is The Key: BPFDoor And AVERAT Hitting The Network Edge
        "Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant we track as AVERAT, deployed against Taiwanese appliances. Additionally, we provide source code details of the Rapid7 BPFDoor controller introduced in our April 2026 blog, Stealthy BPFDoor Variants are a Needle That Looks Like Hay."
        https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge/
        https://www.darkreading.com/threat-intelligence/malicious-linux-implants-mimic-asian-mail-security
      • Convincing Free Mobile Phishing Emails Appear After Data Breach
        "Free Mobile, one of France’s main cellular providers, was fined €27 million by France’s data protection regulator, the CNIL, in January over failures to protect customer data. The October 2024 breach allowed an unauthorized party to access sensitive customer records, including bank account details and login information. Since the breach, we’ve seen many poorly written scam campaigns targeting Free Mobile customers. However, over the past few weeks, a well-written scam has appeared, closely copying the design of the official Free Mobile website and email templates."
        https://www.malwarebytes.com/blog/threat-intel/2026/10/free-mobile-phishing-texts-appear-days-after-data-breach

      Breaches/Hacks/Leaks

      • Frontline Education Breach Exposes School District Employee Data
        "Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. Frontline Education is an edtech company that provides administration and workforce management software and services used by school districts. Last night, a reader shared a data breach notification with BleepingComputer that Frontline sent to an impacted school district, stating that attackers breached its environment through a vulnerability in a third-party application."
        https://www.bleepingcomputer.com/news/security/frontline-education-data-breach-impacts-school-district-employees/
      • Microsoft’s X Account Hacked In Crypto Pump-And-Dump Scheme
        "On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. The attack began when the Microsoft account (@Microsoft) followed and reposted a tweet from another now-suspended X account (@clippymsftcto) impersonating Microsoft's Clippy virtual assistant, The Verge first reported. While @clippymsftcto has been suspended, another X account (@ClippyMSFT) that reposted Microsoft's tweet is still promoting a $Clippy crypto token, claiming that it has "has a liquidity pool paired directly with $MSFT.""
        https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/
        https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/
      • Mississippi Mayor Says Ransomware Incident Led City To Shut Down Systems
        "A ransomware attack has shut down the computer systems of Vicksburg, Mississippi, the city’s mayor told residents on Thursday evening. Mayor Willis Thompson published a statement in the local newspaper saying the city is investigating a ransomware attack that has not impacted emergency services but has affected payments for utilities. He said the system shutdown was “temporary.” Thompson said no one's services will be shut off while the investigation is ongoing and no penalties will be issued for late payments. He later told the Vicksburg Post that the city has been working on the recovery effort with the FBI, Department of Homeland Security and other state officials alongside private cybersecurity experts."
        https://therecord.media/vicksburg-mississippi-government-ransomware-attack
      • Danish University DTU Breach Exposes Data Of Up To 200,000 People
        "The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. ​The university says the attacker used compromised credentials to log into DTUBasen, its identity and access management (IAM) system, allowing access to more than two decades of user data. In a disclosure on Friday, DTU confirmed that it cannot “determine precisely what information was downloaded or how many people have been affected.”"
        https://www.bleepingcomputer.com/news/security/danish-university-dtu-breach-exposes-data-of-up-to-200-000-people/

      General News

      • Treasury Sanctions Financial Network Of Foreign Terrorist Organization, Tren De Aragua, After Theft Of Millions From U.S. Banks
        "Today, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) designated 10 targets involved in a Tren de Aragua (TdA) fraud scheme that has become a key source of revenue for the organization. TdA is a Foreign Terrorist Organization (FTO) responsible for violent and exploitative criminal activity across the Western Hemisphere—including drug trafficking, human trafficking, extortion, and murder-for-hire—making the disruption of its financial networks essential to protecting Americans. This operation is orchestrated by one of the FBI’s ten most-wanted fugitives, Anibal Alexander Canelon Aguirre (aka “Prometheus”). In addition to this network, today OFAC also designated Juan Gabriel Rivas Nunez (aka “Juancho”), a high ranking TdA leader directing operations in multiple South American countries."
        https://home.treasury.gov/news/press-releases/sb0640
        https://www.bleepingcomputer.com/news/security/us-sanctions-tren-de-aragua-members-in-atm-jackpotting-crackdown/
      • The Legal Questions Raised By Agentic AI Hacks
        "As AI agents escaping testing sandboxes and hacking organizations have gone from unprecedented to seemingly routine in a matter of weeks, policymakers, regulators and cybersecurity attorneys largely agree on one thing: Something must be done to hold AI companies accountable for the incidents. Exactly what can be done under our current laws and regulations is much less clear. The conversation has moved from policy and industry chatter to the floor where the future of liability will be determined. Speaking about the Hugging Face hack at a Senate hearing this week, Georgetown University law professor Paul Ohm summarized the argument."
        https://cyberscoop.com/ai-agent-hacks-legal-liability-cfaa/
      • Kiteworks & Citrix Incidents Show Challenges Of Zero-Day Response
        "On Sept. 24, threat detection firm GreyNoise Intelligence observed a single US-based IP address scanning for Citrix NetScaler installations and conducting remote code execution (RCE) attacks. The company issued alerts to customers about the malicious activity. Over the next two days, reports of potential zero-day attacks on NetScaler installations emerged on social media, and cybersecurity professionals debated whether the rumored attacks were true — some argued the activity targeted vulnerabilities already patched in August. On Sept. 26, however, Benjamin Harris, founder and CEO of exposure-management firm watchTowr, urged NetScaler users to take their systems offline."
        https://www.darkreading.com/cybersecurity-operations/kiteworks-citrix-incidents-challenges-zero-day-response
      • Is Your Organization Ready For 2027's AI Accountability Era?
        "Artificial intelligence (AI) risks have evolved significantly over the past year. Reports of OpenAI and Anthropic agents acting autonomously continue to unfold, igniting a development slowdown debate amid heightened security concerns. Organizations will need to address the state of their own AI security for 2027, but preparations begin now. Organizations spent 2026 deploying AI at record speeds across operations. Top executives pushed for new innovations and urged employees to use them. Now organizations must prove they can govern, secure, and benefit from AI – a task that may be more difficult than simply implementing it."
        https://www.darkreading.com/cybersecurity-operations/is-your-organization-ready-for-2027-s-ai-accountability-era-
      • Is It Fair To Blame 'Rogue' AI For Security Failures?
        "Experts are pushing back on classifying AI escape incidents as "going rogue" because it risks obscuring the real security problems behind these events, they say. The tech ecosystem has been inundated with stories of large language model (LLM) agents "going rogue," specifically referring to models breaking out of their sandboxes, harnesses, and other containments in some way, and causing trouble by interacting with and breaching third-party organizations. The incident that kicked off much of this discourse came in July, when OpenAI disclosed that two of its frontier models autonomously hacked AI model store Hugging Face during a security exercise. Other major firms, including Meta, Anthropic, and Google, soon disclosed their own AI escape incidents."
        https://www.darkreading.com/insider-threats/blame-rogue-ai-security-failures
      • Vulnerability Backlogs Are An Ownership Problem
        "Most enterprises drowning in vulnerabilities don't have a detection problem. They have an accountability problem wearing a detection problem's clothing. You can see it in how they spend. When a backlog gets big enough to reach the board, the reflex is to buy better scanning — wider coverage, faster cycles, richer threat intel, a single pane of glass. A year later, the organization has excellent visibility into a backlog that has grown. That's a misdiagnosis, not a tooling failure. Scanning capacity and remediation capacity are independent variables, and only one of them scales with a purchase order."
        https://www.darkreading.com/cybersecurity-operations/vulnerability-backlogs-ownership-problem
      • Criminal Recruiters Want People On Your Payroll
        "Legitimate employee access can let criminals circumvent security controls that would be difficult to overcome from outside an organization. Routine actions such as information lookups, account resets, transaction approvals and shipment changes can become services sold to criminal customers, according to Intel 471’s Insiders for Hire: Underground Recruitment, Access Claims and Insider-Enabled Services report."
        https://www.helpnetsecurity.com/2026/10/02/intel-471-insider-threat-recruitment-report/
      • AI Agents Keep Access To Company Data After Their Work Is Done
        "IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf, according to a Delinea’s 2026 Identity Security Report: The AI Enforcement Gap. “Written policy is only as good as your ability to enforce it at the moment an AI agent acts,” said Art Gilliland, CEO of Delinea. “Our research echoes what I hear from leaders constantly: they have the AI policies in place, but they can’t see or report on what their agents actually do.”"
        https://www.helpnetsecurity.com/2026/10/02/delinea-ai-policy-adoption-enforcement-report/
      • In Rare Move, Alleged Iranian State Hacker Extradited To US
        "An Iranian national indicted in the US for hacking hundreds of organizations was extradited from Montenegro this week. Acting on an arrest warrant issued by the FBI, Montenegrin authorities arrested the individual, a dual citizen of Turkey and Iran, on June 25. The suspect is accused of involvement in numerous cyberattacks against US organizations starting in 2013. The attacks caused losses of more than $3.4 billion. The Montenegrin authorities did not name the individual, but mentioned his initials, A.B., and that he is 40 years old."
        https://www.securityweek.com/in-rare-move-iranian-hacker-accused-of-working-for-irgc-extradited-to-us/
      • Why AI Coding Agents Keep Writing Broken Access Control
        "AI coding agents produce authorization logic that compiles, passes review, and enforces the wrong policy. Broken access control ranks first in the OWASP Top 10:2025, where 100% of applications tested showed some form of it, across 1,839,701 recorded occurrences, the highest count of any category on the list. One part of that category is also the part that pattern-based scanning was never built to reach. When an agent omits an ownership check, the rule it broke belongs to the application rather than to a signature database. That leaves no known-bad pattern to match against."
        https://snyk.io/blog/ai-coding-agents-broken-access-control/
      • ShinyHunters Hacker In FBI Data Theft Detained In Jordan, Cooperating With Bureau, Sources Say
        "A suspected member of the ShinyHunters hacking group, which ​says it stole data on every FBI employee, was detained in Jordan this week and is cooperating with the FBI, three people familiar with the matter told Reuters. Saif ‌al-Din Khader was detained by Jordanian authorities, the three sources said. Two of them said he was brought into custody on Tuesday. Reuters could not immediately determine the circumstances of Khader’s detention or where he is being held. Two sources said that he is helping the FBI and global law enforcement locate the other hackers in the group."

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 9eb48edf-7dad-4354-bc27-7b3fed87c2a5-image.png

      1 การตอบกลับ คำตอบล่าสุด ตอบ คำอ้างอิง 0
      • First post
        Last post