<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cyber Threat Intelligence 27 July 2026]]></title><description><![CDATA[<p dir="auto"><strong>Healthcare Sector</strong></p>
<ul>
<li><strong>Ransomware Gangs Go After EMEA Healthcare’s Supply Chain</strong><br />
"A ransomware attack against a hospital makes headlines, while attacks on the rest of the ecosystem around it tend to stay quiet despite doing damage that can be just as bad. Flare researcher Assaf Morag analyzed ransomware leak-site activity tied to healthcare organizations in the EMEA region between 2024 and 2026, and found that ransomware groups are going after the entire healthcare supply chain."<br />
<a href="https://www.helpnetsecurity.com/2026/07/24/emea-healthcare-ransomware-activity/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/24/emea-healthcare-ransomware-activity/</a></li>
</ul>
<p dir="auto"><strong>Vulnerabilities</strong></p>
<ul>
<li><strong>Fastjson RCE (≤1.2.83): Active Exploitation Detected — Detection &amp; Mitigation</strong><br />
"A remote code execution vulnerability in Fastjson affects every version up to and including 1.2.83. A remote attacker can run arbitrary code on a vulnerable server by sending it specially crafted JSON — no user privileges, no victim interaction, and no third-party libraries required. ThreatBook TDP<img src="https://webboard-nsoc.ncsa.or.th/assets/plugins/nodebb-plugin-emoji/emoji/android/00ae.png?v=2sqmsl7eedm" class="not-responsive emoji emoji-android emoji--registered" style="height:23px;width:auto;vertical-align:middle" title=":registered:" alt="®" /> (Threat Detection Platform) has already captured this vulnerability being exploited in the wild, so if you run an affected version without SafeMode enabled, treat remediation as urgent."<br />
<a href="https://threatbook.io/blog/fastjson-rce-1.2.83-active-exploitation-detected-detection-mitigation" target="_blank" rel="noopener noreferrer nofollow ugc">https://threatbook.io/blog/fastjson-rce-1.2.83-active-exploitation-detected-detection-mitigation</a><br />
<a href="https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-16723-critical-fastjson-1-x-zero-day-rce/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-16723-critical-fastjson-1-x-zero-day-rce/</a><br />
<a href="https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html</a></li>
<li><strong>Default Azure Automation Setting Enables Cross-Tenant Identity Takeover</strong><br />
"A critical vulnerability in Microsoft's Azure Automation service could have exposed accounts to cross-tenant identity takeovers due to a default setting that had the potential to make account identities become public. Azure Automation is widely used by Microsoft internally and by enterprises running Azure for DevOps, resource deployment, patching, and secrets rotation using scripted runbooks tied to embedded managed identities. Shay Shavit, a senior security researcher on Microsoft's Azure Networking Security Research team, discovered the vulnerability last year and reported it to the Microsoft Security Response Center (MSRC), which issued an advisory."<br />
<a href="https://www.darkreading.com/cloud-security/default-azure-automation-setting-cross-tenant-identity-takeover" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cloud-security/default-azure-automation-setting-cross-tenant-identity-takeover</a></li>
<li><strong>Tego AI Discloses Second Claude Flaw In a Week: Hidden Link Silently Sends Files To Attackers</strong><br />
"One week after disclosing that Anthropic’s Claude Tag Slack integration could be driven by plain “@Claude” text, Tego AI today published a second piece of research on the Claude ecosystem. This one focuses on Claude Code, Anthropic’s agentic command-line coding tool. Cloning an ordinary repository and starting Claude Code can cause the tool to read a file from outside the project and include it in the model’s first request, without a warning or approval prompt the user would recognize."<br />
<a href="https://hackread.com/tego-ai-discloses-second-claude-flaw-in-a-week-hidden-link-silently-sends-files-to-attackers/" target="_blank" rel="noopener noreferrer nofollow ugc">https://hackread.com/tego-ai-discloses-second-claude-flaw-in-a-week-hidden-link-silently-sends-files-to-attackers/</a></li>
<li><strong>Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller</strong><br />
"Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync. Microsoft patched the Active Directory Certificate Services (AD CS) issue ten days earlier as CVE-2026-54121. Microsoft classed the flaw as improper authorization and assigned it a CVSS score of 8.8."<br />
<a href="https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html</a></li>
<li><strong>Bing Images Flaws Let Crafted SVGs Run Commands As SYSTEM On Microsoft's Servers</strong><br />
"A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing's image tier, not on one bad machine. Microsoft issued two critical CVEs, CVE-2026-32194 and CVE-2026-32191, and rated both 9.8 on the CVSS scale."<br />
<a href="https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html</a></li>
<li><strong>Finding Eight High-Severity Vulnerabilities In NodeBB In Six Hours</strong><br />
"While improving our AI Pentest, we ran a whitebox assessment on NodeBB, a forum software powered by NodeJS. The result? Eight high-severity vulnerabilities that would all be exploitable on default instances of NodeBB. This includes Cross-Site Scripting (XSS), two of which require interaction with a custom Federation server that the AI agent had to set up itself. Another affects practically every input on NodeBB due to a template injection. Apart from these issues, there were clever authorization bypasses to hijack and read various data that shouldn't be public. We've explained all of the interesting technical details below."<br />
<a href="https://www.aikido.dev/blog/eight-high-severity-vulnerabilities-nodebb" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.aikido.dev/blog/eight-high-severity-vulnerabilities-nodebb</a><br />
<a href="https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html</a></li>
<li><strong>Kimi K3 Agents Found Redis Zero-Days And Built RCE Exploit, Researchers Say</strong><br />
"Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution."<br />
<a href="https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html</a></li>
<li><strong>Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands As Git</strong><br />
"Security researchers depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update. Any authenticated user who can push to a project can run it. The attacker commits a crafted Jupyter notebook and opens its commit diff, which leaks a heap pointer. Enough of those and an automated probe can locate the libraries in memory. Two more notebooks then fire the payload. No administrator rights, no CI or runner access, no victim interaction, no access to anyone else's project."<br />
<a href="https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html</a></li>
</ul>
<p dir="auto"><strong>Malware</strong></p>
<ul>
<li><strong>Clop Ransomware Targets Windchill, FlexPLM In Data Theft Attacks</strong><br />
"The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances. As cybersecurity company ReliaQuest reported on Thursday, Clop operators have been deploying JSP webshells that allow them to exfiltrate sensitive data from targeted companies' compromised PLM platforms."<br />
<a href="https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/</a><br />
<a href="https://ransom-isac.org/blog/clop-windchill-flexplm-exploitation/" target="_blank" rel="noopener noreferrer nofollow ugc">https://ransom-isac.org/blog/clop-windchill-flexplm-exploitation/</a><br />
<a href="https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html</a></li>
<li><strong>DNS Poisoning Tactics Expand To Hospitality Wi-Fi</strong><br />
"Adversaries have been compromising public Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack the accounts of traveling corporate employees. Once they control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, in activity ongoing since at least June 2026. ReliaQuest assesses this tradecraft is similar to that of “APT28” (also known as “Fancy Bear” and “Forest Blizzard”), a Russian military intelligence group that was previously linked to similar router-based campaigns compromising Microsoft 365 accounts."<br />
<a href="https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/" target="_blank" rel="noopener noreferrer nofollow ugc">https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/</a><br />
<a href="https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/</a><br />
<a href="https://www.infosecurity-magazine.com/news/hotel-wifi-dns-poisoning/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/hotel-wifi-dns-poisoning/</a><br />
<a href="https://securityaffairs.com/196017/security/hackers-hijack-hotel-wi-fi-to-steal-microsoft-365-credentials.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/196017/security/hackers-hijack-hotel-wi-fi-to-steal-microsoft-365-credentials.html</a></li>
<li><strong>Operation RoundPress Rolls On With More Half-Click Webmail Zero-Days From TA458</strong><br />
"TA458 is an espionage threat actor with prolific access to “half-click” cross-site scripting (XSS) exploits in webmail software. TA458 is likely aligned with Russia’s General Staff Main Intelligence Directorate (GRU). In March 2026, Proofpoint discovered TA458 exploiting a zero-day vulnerability in the SOGo webmail platform, which we reported to the vendor, Alinto; it was patched as CVE-2026-8496 in version 5.12.8. TA458 primarily targets Ukrainian government and Eastern European military and government entities across Albania, Greece, Moldova, and Türkiye, with occasional targeting of chemical, telecommunications, and technology firms. TA458 continues to use SpyPress - an obfuscated JavaScript-based malware seen in Operation RoundPress - which the adversary modifies based on the targeted mailserver."<br />
<a href="https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits</a></li>
<li><strong>Inside a DPRK BlueNoroff ClickFix Kit</strong><br />
"JUMPSEC has obtained and analysed the source code behind an active BlueNoroff phishing kit used to impersonate Zoom and Microsoft Teams meetings. Unlike previous reporting, this research provides source-level visibility into how the operation works after operators mistakenly exposed JavaScript source maps on live infrastructure. This is not simply a fake Zoom lure. We demonstrate how BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet reconnaissance and malware delivery into a repeatable victim acquisition pipeline."<br />
<a href="https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/</a><br />
<a href="https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html</a></li>
<li><strong>TAG-195 Upgrades MaaS Ecosystem With Modular Tools</strong><br />
"Insikt Group identified four new TAG-195 ("Golden Chickens", “Venom Spider”) malware families through ongoing tracking of the TAG-195 MaaS ecosystem. We named two of the families "TinyEgg" and “ChonkyChicken"; the third is a modularized variant of ChonkyChicken. The fourth family, which includes a modified browser credential theft helper, we named “ChromEggscalator". TAG-195 is a financially motivated malware-as-a-service (MaaS) developer whose tooling Insikt Group has previously linked to TAG-127 as an operator and customer. (Insikt Group has directly observed TAG-127 deploying TinyEgg via “ClickFix”-style campaigns that use fake security verification pages to trick victims into manually executing malicious commands that download and install malware payloads via a legitimate Windows system utility.)"<br />
<a href="https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem</a><br />
<a href="https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0723.pdf" target="_blank" rel="noopener noreferrer nofollow ugc">https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0723.pdf</a><br />
<a href="https://thehackernews.com/2026/07/golden-chickens-resurfaces-with-four.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/golden-chickens-resurfaces-with-four.html</a></li>
<li><strong>Silent Replacement Of Trusted MacOS App Executables</strong><br />
"A vulnerability in macOS allows an attacker to silently replace the main executable of any application downloaded from the web without requiring elevated privileges. As a result, trusted applications can be made to execute attacker-controlled code without triggering security warnings when relaunched. Apple assessed the reported behaviour as not requiring a security fix."<br />
<a href="https://mysk.blog/2026/07/23/macos-overwrite-app-executables/" target="_blank" rel="noopener noreferrer nofollow ugc">https://mysk.blog/2026/07/23/macos-overwrite-app-executables/</a><br />
<a href="https://www.theregister.com/security/2026/07/24/researchers-replace-downloaded-macos-apps-with-evil-twins-apple-shrugs/5277858" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/07/24/researchers-replace-downloaded-macos-apps-with-evil-twins-apple-shrugs/5277858</a></li>
<li><strong>The Signs Were There: What The First Autonomous Ransomware Case Confirms</strong><br />
"Ransomware has always had a person behind it. Someone picks the target, buys or builds the access, runs the tools, and extorts the victim for a payout. However, in an intrusion documented this month by the security firm Sysdig and dubbed JADEPUFFER, no one did. By their account, a large language model (LLM) agent broke into a live production system, harvested credentials, moved deeper, encrypted a database, destroyed the originals, and left a ransom note. It was choosing and sequencing every step itself in near real time, with no human at the keyboard between the break-in and the damage."<br />
<a href="https://www.trendmicro.com/en_us/research/26/g/autonomous-ransomware.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.trendmicro.com/en_us/research/26/g/autonomous-ransomware.html</a></li>
<li><strong>Steam Forum ClickFix Attacks Infect Gamers With XMRig Cryptominers</strong><br />
"Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. BleepingComputer learned of the campaign from a reader, who told us threat actors are creating random Steam accounts to post what appears to be helpful fixes for people's posts about games crashing, lost inventory items, and other technical issues."<br />
<a href="https://www.bleepingcomputer.com/news/security/steam-forum-clickfix-attacks-infect-gamers-with-xmrig-cryptominers/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/steam-forum-clickfix-attacks-infect-gamers-with-xmrig-cryptominers/</a></li>
<li><strong>SourTrade: Browser-Assembled Malware Delivered Through Malvertising</strong><br />
"SourTrade is a malvertising operation that has been running ads since late 2024, impersonating TradingView, Solana, and Luno to reach retail traders and crypto investors across 12 countries in 25 languages. It is built to separate real targets from analysts and bots. Security researchers see a blank page, legitimate victims see a convincing replica of a platform they trust. What makes SourTrade technically distinct is what happens on its landing page. It does not distribute finished malware. Instead, it delivers assembly instructions to the victim’s browser, retrieves a clean legitimate file from separate infrastructure, and directs the browser to build the final malware in memory on the victim’s machine. No finished malware ever exists on the network."<br />
<a href="https://blog.confiant.com/p/sourtrade-browser-assembled-malware" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.confiant.com/p/sourtrade-browser-assembled-malware</a><br />
<a href="https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/</a><br />
<a href="https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html</a></li>
<li><strong>ShinyHunters Data Leaks Fuel $2,000 Sextortion Email Scam</strong><br />
"Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. The emails claim to come from ShinyHunters and tell recipients that hackers compromised their devices after obtaining their email addresses from breached company databases. However, the messages appear to be sent by someone who downloaded data previously leaked by ShinyHunters rather than by the extortion group itself, using the exposed email addresses to make the threats appear more legitimate."<br />
<a href="https://www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam/</a></li>
<li><strong>Funky Mantis: Platform, Coordination And Locker Analysis</strong><br />
"Funky Mantis , publicly tracked as DevMan, is a centrally administered ransomware-as-a-service operation that combined affiliate management, access distribution, payload generation, victim negotiation, and revenue tracking by late 2025. The evidence set contains two generations of its web panel, private and group communications and a Windows encryptor. These independent sources support the assessment that the service progressed beyond advertising or development and was used in at least one real intrusion."<br />
<a href="https://catalyst.prodaft.com/public/report/funky-mantis-platform-coordination-and-locker-analysis/overview" target="_blank" rel="noopener noreferrer nofollow ugc">https://catalyst.prodaft.com/public/report/funky-mantis-platform-coordination-and-locker-analysis/overview</a><br />
<a href="https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html</a></li>
</ul>
<p dir="auto"><strong>Breaches/Hacks/Leaks</strong></p>
<ul>
<li><strong>Thailand's Ministry Of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged</strong><br />
"Attackers have started handing routine offensive work to AI agents, and the agents are doing it without anyone watching. We have seen this in ransomware and cloud intrusions, and now in espionage. An open directory left exposed on a staging server gave us a look at one of these operations mid-run: an agent enumerating a government ministry's network on its own. From July 9 - 13, 2026, <a href="http://Hunt.io" target="_blank" rel="noopener noreferrer nofollow ugc">Hunt.io</a> Attack Capture<img src="https://webboard-nsoc.ncsa.or.th/assets/plugins/nodebb-plugin-emoji/emoji/android/2122.png?v=2sqmsl7eedm" class="not-responsive emoji emoji-android emoji--tm" style="height:23px;width:auto;vertical-align:middle" title=":tm:" alt="™" /> identified three simultaneous open directories on 43.246.208[.]207, hosted on AS132883 (TOPIDC) in Hong Kong. The directories contained exploit code for multiple CVEs, webshells, suo5 HTTP tunnels, custom scripts with hardcoded stolen credentials targeting mail infrastructure and Apache Hadoop."<br />
<a href="https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent" target="_blank" rel="noopener noreferrer nofollow ugc">https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent</a><br />
<a href="https://www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry/</a><br />
<a href="https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html</a><br />
<a href="https://securityaffairs.com/195941/hacking/thailands-ministry-of-finance-targeted-with-hermes-ai-agent-running-unattended-hades-implant-staged.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/195941/hacking/thailands-ministry-of-finance-targeted-with-hermes-ai-agent-running-unattended-hades-implant-staged.html</a></li>
<li><strong>OnTrac Notifies Customers Of Data Breach After Network Hack</strong><br />
"OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. The incident was detected on March 23, and an internal investigation revealed that the attacker accessed certain files between March 20 and 22. Apart from names, it is unclear what type of information was exposed, as the company redacted the data elements in the notification sample shared with authorities."<br />
<a href="https://www.bleepingcomputer.com/news/security/ontrac-notifies-customers-of-data-breach-after-network-hack/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/ontrac-notifies-customers-of-data-breach-after-network-hack/</a></li>
<li><strong>Vatican's Official Prayer App Leaks 700K+ Global Users' PII</strong><br />
"A popular Vatican website and mobile app has been leaking hundreds of thousands of users' names and email addresses. "Click to Pray" is the Vatican's official prayer app. Users can sign up for access to daily prayers, and a steady stream of papal content on their phones or computers. It's available on iOS and Android, and via a Web browser. According to its website, Click to Pray is used in more or less every country on the planet."<br />
<a href="https://www.darkreading.com/vulnerabilities-threats/vatican-official-prayer-app-leaks-700k-pii" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/vulnerabilities-threats/vatican-official-prayer-app-leaks-700k-pii</a><br />
<a href="https://www.theregister.com/security/2026/07/24/popes-official-prayer-app-commits-cardinal-sin-leaks-700k-users-info/5278603" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/07/24/popes-official-prayer-app-commits-cardinal-sin-leaks-700k-users-info/5278603</a></li>
</ul>
<p dir="auto"><strong>General News</strong><br />
June 2026 Threat Trend Report On Ransomware<br />
"This report summarizes the quantity of ransomware samples collected, the number of affected systems, statistics on targeted businesses, and major Korean &amp; global issues during the month of June 2026. Statistics on targeted businesses were compiled based on information posted on DLS (Dedicated Leak Sites) operated by ransomware groups, which publish details of attacks."<br />
<a href="https://asec.ahnlab.com/en/94619/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/94619/</a></p>
<ul>
<li><strong>June 2026 Threat Trend Report On APT Attacks (South Korea)</strong><br />
"AhnLab monitored domestic APT (Advanced Persistent Threat) attacks—which are conducted covertly and persistently—using its own infrastructure. This report summarizes the classification and statistics on domestic APT attacks identified in June 2026 and describes the capabilities of each type of APT attack."<br />
<a href="https://asec.ahnlab.com/en/94594/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/94594/</a></li>
<li><strong>Europol-Led Action Against Nihilistic Violent Extremist Network "The Com"</strong><br />
"Over several weeks in June and July 2026, Europol supported an action targeting nihilistic violent extremist content online. Investigators from nine countries participated in these ‘Referral Action Days’, with the common goal to disrupt The Com online ecosystem and limit propaganda dissemination, as well as to find new investigative leads. The action also aimed at enhancing platforms’ response to and awareness of terrorist content online produced and disseminated by The Com groups."<br />
<a href="https://www.europol.europa.eu/media-press/newsroom/news/europol-led-action-against-nihilistic-violent-extremist-network-com" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.europol.europa.eu/media-press/newsroom/news/europol-led-action-against-nihilistic-violent-extremist-network-com</a><br />
<a href="https://www.bleepingcomputer.com/news/security/europol-flags-4-340-urls-for-removal-in-the-com-crackdown/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/europol-flags-4-340-urls-for-removal-in-the-com-crackdown/</a><br />
<a href="https://www.bankinfosecurity.com/europol-flags-4340-urls-tied-to-com-network-a-32325" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/europol-flags-4340-urls-tied-to-com-network-a-32325</a><br />
<a href="https://www.theregister.com/cyber-crime/2026/07/24/europol-flags-4340-horrific-urls-linked-to-the-com/5278556" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/cyber-crime/2026/07/24/europol-flags-4340-horrific-urls-linked-to-the-com/5278556</a></li>
<li><strong>Man Gets Six Years For Hacking 750 Women's Snapchat Accounts</strong><br />
"An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos, which he later traded or sold online. After being charged in December, 26-year-old defendant Kyle Svara admitted in February to having used various social engineering tactics to phish Snapchat access codes from over 750 women. Between May 2020 and February 2021, he targeted more than 4,500 victims while posing as a representative of Snap Inc and using anonymized phone numbers."<br />
<a href="https://www.bleepingcomputer.com/news/security/man-gets-six-years-for-hacking-750-womens-snapchat-accounts/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/man-gets-six-years-for-hacking-750-womens-snapchat-accounts/</a></li>
<li><strong>Symbiotic Parasites: The Modern Proxy Ecosystem</strong><br />
"Residential proxy networks may sound technical, but their impact is easy to understand: they help criminals hide in everyday internet traffic. In this post, we break down how these massive botnet-powered ecosystems enable fraud, evade detection and quickly recover after disruption—and why stopping them will take coordinated action across the security community."<br />
<a href="https://www.lumen.com/blog/en-us/symbiotic-parasites-the-modern-proxy-ecosystem" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.lumen.com/blog/en-us/symbiotic-parasites-the-modern-proxy-ecosystem</a><br />
<a href="https://cyberscoop.com/botnets-residential-proxy-networks-proliferate-lumen-black-lotus-labs/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/botnets-residential-proxy-networks-proliferate-lumen-black-lotus-labs/</a></li>
<li><strong>CISOs Vs. Boards: Myth Or Misunderstanding?</strong><br />
"The rumors are exaggerated. Executive boards aren't apathetic to security threats; they're often struggling with a cybersecurity language barrier. Increasingly disruptive cyberattacks require preventative and remediation efforts from positions across organizations, yet chief information security officers (CISOs) and IT teams feel unsupported by the powers that be. This adds pressure on the CISOs, as they fend off attacks and manage potentially devastating fallout."<br />
<a href="https://www.darkreading.com/cybersecurity-operations/cisos-vs-boards-myth-or-misunderstanding-" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cybersecurity-operations/cisos-vs-boards-myth-or-misunderstanding-</a></li>
<li><strong>Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation</strong><br />
"The hack of Hugging Face by a rogue AI agent created by Open AI engineers does not surprise researchers and AI-security professionals who best know machine-learning and AI systems. In a study of the behavior of seven different models, a research team at Carnegie Mellon University (CMU), for example, found that all of them escaped alignment in some scenarios. In a paper published to <a href="http://Arxiv.org" target="_blank" rel="noopener noreferrer nofollow ugc">Arxiv.org</a> in May, the team of six researchers found that every model violated "corrigibility" — an AI design principle that aims to make agents cooperative, correctable, and amenable to being shut down or modified by their human operators."<br />
<a href="https://www.darkreading.com/cybersecurity-operations/incorrigible-ai-models-resist-rehabilitation" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cybersecurity-operations/incorrigible-ai-models-resist-rehabilitation</a></li>
<li><strong>Europe's Multilingual Reality Exposes AI Security Gaps</strong><br />
"Not all languages are treated equally when it comes to AI model function and safety, and European organizations face a particular risk when it comes to this reality. The modern large language model (LLM) ecosystem relies heavily on natural language, whether a user is speaking to a chatbot, issuing specific instructions for software development, generating emails, or performing large-scale data analysis. This reliance is further illustrated through the wide range of prompt injection attacks that rely on language-based trickery."<br />
<a href="https://www.darkreading.com/cybersecurity-operations/europes-multilingual-reality-exposes-ai-security-gaps" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cybersecurity-operations/europes-multilingual-reality-exposes-ai-security-gaps</a></li>
<li><strong>The Automotive Software Vulnerabilities Hiding In Your Dashboard</strong><br />
"Pop the hood on a new car and you won’t find much you can fix with a wrench. What you’ll find is software, and a lot of it. The screen in the dash probably runs Android or a flavor of Linux. The system watching the road for you might run QNX or VxWorks, the same kind of code that flies aircraft and runs factory floors. Carmakers spent the last decade making this switch, and it bought them app stores, wireless updates, and quicker release cycles. It also handed them something less welcome: every old, publicly documented bug those platforms have collected over the years."<br />
<a href="https://www.helpnetsecurity.com/2026/07/24/car-research-automotive-software-vulnerabilities/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/24/car-research-automotive-software-vulnerabilities/</a><br />
<a href="https://arxiv.org/pdf/2607.07226" target="_blank" rel="noopener noreferrer nofollow ugc">https://arxiv.org/pdf/2607.07226</a></li>
<li><strong>The Best-Funded Companies Open The Most Phishing Attachments</strong><br />
"An employee gets an email dressed as a password reset. She clicks the link, types her credentials into a page built to copy her company’s login screen, and moves on with her morning. She tells no one. That silence is the exposure. Across 13.9 million simulated phishing messages, one in ten recipients flagged the attempt to their security team. The rest let it through, and a live attacker needs only one of them."<br />
<a href="https://www.helpnetsecurity.com/2026/07/24/phishing-simulation-benchmark-report/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/24/phishing-simulation-benchmark-report/</a><br />
<a href="https://static.fortra.com/corporate/pdfs/other/fta-phishing-simulation-benchmark-report.pdf" target="_blank" rel="noopener noreferrer nofollow ugc">https://static.fortra.com/corporate/pdfs/other/fta-phishing-simulation-benchmark-report.pdf</a><br />
Education Ransomware Roundup: H1 2026 Stats On Attacks, Ransoms, And Data Breaches<br />
"Attacks on the education sector dropped by 13 percent in the first half of 2026, declining from 120 attacks in H2 2025 to 104 attacks in H1 2026. This decline wasn’t consistent across all levels of education, however. Attacks on K-12 (primary and secondary education) decreased 26 percent from H2 2025 but attacks on higher education increased more than eight percent."<br />
<a href="https://www.comparitech.com/news/education-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.comparitech.com/news/education-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/</a><br />
<a href="https://www.infosecurity-magazine.com/news/university-ransomware-attacks-rise/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/university-ransomware-attacks-rise/</a></li>
<li><strong>CertiK Intel3D H1 2026 Wrench Attacks</strong><br />
"H1 2026 confirms that wrench attacks are no longer a fringe phenomenon or an edge-case risk for cryptocurrency holders. Over the first six months, CertiK recorded 52 verified incidents worldwide, representing a 33.3% year-over-year (YoY) increase. The increase was driven by activity during the first quarter, which recorded 35 verified incidents compared to 22 in Q1 2025. Recorded losses and ransom demands reached approximately $124.1 million in H1 2026, compared with approximately $10.5 million in H1 2025. These figures remain indicative, not exhaustive: many ransoms, failed demands, recovered funds, frozen funds, and private settlements are not publicly disclosed or are partially disclosed."<br />
<a href="https://www.certik.com/certik-report/intel3d/intel3d-wrench-h1-2026" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.certik.com/certik-report/intel3d/intel3d-wrench-h1-2026</a><br />
<a href="https://therecord.media/wrench-attacks-against-cryptocurrency-holders" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/wrench-attacks-against-cryptocurrency-holders</a></li>
<li><strong>The AI Trust Paradox: Businesses Are Racing Ahead, But Consumers Are Hesitating</strong><br />
"Businesses are rapidly adopting AI, with 93% planning deployment, but consumer trust lags far behind: only 23% trust companies to use AI with their data, revealing a major “AI trust gap.” Research from Thales shows trust depends on transparency and use case, as users favor Artificial intelligence for cybersecurity but resist it in high-risk areas like financial decisions. To close this gap and reduce fears, organizations must clearly communicate how AI is used, where it adds security, and where humans remain in control."<br />
<a href="https://securityaffairs.com/195915/ai/the-ai-trust-paradox-businesses-are-racing-ahead-but-consumers-are-hesitating.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/195915/ai/the-ai-trust-paradox-businesses-are-racing-ahead-but-consumers-are-hesitating.html</a></li>
<li><strong>Don’t Swing At Everything</strong><br />
"Lately I've found myself thinking a lot about the Australian TV series Mr. Inbetween (IMDb 8.7/10) — not because I'm a hitman for hire, but because I literally feel in-between. Specifically, in-between what I'd call the "pre-Mythos" and “post-Mythos” eras. We've crossed a capability threshold, and it's not just one model family driving that — Codex 5.3 and GPT-5.5 deliver comparable or better performance, and Tulongfeng or GLM-5.2 (an incredibly powerful open-weight model, MIT-licensed) show the frontier isn't limited to closed models anymore."<br />
<a href="https://blog.talosintelligence.com/dont-swing-at-everything/" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.talosintelligence.com/dont-swing-at-everything/</a></li>
<li><strong>Email Threat Landscape: Q2 2026 Trends And Insights</strong><br />
"The second quarter of 2026 (April–June) was largely defined by the continuing downstream effects following Microsoft’s Digital Crimes Unit-led disruption efforts against the Tycoon2FA phishing-as-a-service (PhaaS) platform in March. Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs. Despite ongoing efforts to rebuild operations, Tycoon2FA did not recover its previous scale or influence during Q2, and no single service emerged to replace the platform at comparable scale."<br />
<a href="https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/</a></li>
<li><strong>The KEV Gap: How Fast Do Exploited Bugs Get Flagged?</strong><br />
"The Cybersecurity and Infrastructure Security Agency (CISA) keeps a public list called the Known Exploited Vulnerabilities catalog, or KEV: the security bugs it has confirmed attackers are actually using. U.S. federal agencies must patch everything on the list by a deadline, and many private security teams use it as their top fix-first queue. Each bug on the list has two dates: the day it was first published as a Common Vulnerabilities and Exposures (CVE), and the day CISA added it to KEV. The days between those two dates are the “KEV gap.” A common worry is that the gap is growing; that it takes longer and longer to flag a dangerous bug. It doesn’t. For new bugs, CISA is fast: the typical gap is about nine days, and nearly half are flagged within a week. The long delays you see in the raw numbers come from a separate group: old bugs, published years ago, that attackers have started using again."<br />
<a href="https://blog.barracuda.com/2026/07/24/KEV-gap-how-fast-do-exploited-bugs-get-flagged" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.barracuda.com/2026/07/24/KEV-gap-how-fast-do-exploited-bugs-get-flagged</a></li>
<li><strong>Updated Cyber Threat Actor Naming System</strong><br />
"Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. Historically, Mandiant and Google’s Threat Analysis Group (TAG) maintained distinct tracking systems, relying on parallel naming schemas that grew independently over time. The creation of GTIG has necessitated a new, fused tracking system, and a new naming system."<br />
<a href="https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/</a></li>
</ul>
<p dir="auto"><strong>อ้างอิง</strong><br />
Electronic Transactions Development Agency (ETDA) <img src="/assets/uploads/files/1785138241527-271fc13f-d4d8-4677-89f3-1d62e41f79b8-image.png" alt="271fc13f-d4d8-4677-89f3-1d62e41f79b8-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3133/cyber-threat-intelligence-27-july-2026</link><generator>RSS for Node</generator><lastBuildDate>Mon, 27 Jul 2026 09:29:39 GMT</lastBuildDate><atom:link href="https://webboard-nsoc.ncsa.or.th/topic/3133.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 27 Jul 2026 07:44:11 GMT</pubDate><ttl>60</ttl></channel></rss>