NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ

    Cyber Threat Intelligence 29 July 2026

    Cyber Security News
    1
    1
    12
    โหลดโพสเพิ่มเติม
    • เก่าสุดไปยังใหม่สุด
    • ใหม่สุดไปยังเก่าสุด
    • Most Votes
    ตอบ
    • ตอบโดยตั้งกระทู้ใหม่
    เข้าสู่ระบบเพื่อตอบกลับ
    Topic นี้ถูกลบไปแล้ว เฉพาะผู้ใช้งานที่มีสิทธิ์ในการจัดการ Topic เท่านั้นที่จะมีสิทธิ์ในการเข้าชม
    • NCSA_THAICERTN
      NCSA_THAICERT
      แก้ไขล่าสุดโดย

      Industrial Sector

      • CI Fortify – Advice For Isolating Vital Systems
        "This CI Fortify guide helps critical infrastructure organisations improve their cyber resilience. Developed with international partners, the guide explains how organisations can isolate critical operational technology (OT) and supporting systems from other networks during cyber incidents or periods of increased cyber threat. It provides practical guidance and strategic advice for OT owners, operators, and cyber security teams. By reviewing and applying this guidance, organisations can strengthen their ability to prepare for, respond to, and recover from cyber incidents."
        https://www.cyber.gov.au/business-government/secure-design/operational-technology-environments/ci-fortify/ci-fortify-advice-for-isolating-vital-systems
        https://www.bleepingcomputer.com/news/security/cisa-shares-advice-on-isolating-vital-systems-during-cyberattacks/

      Vulnerabilities

      • Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code As Root
        "OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6 REQUEST. odhcpd runs as root, and the advisory notes that embedded hardware commonly lacks stack canaries and address space layout randomization (ASLR), making code execution a realistic outcome on typical devices."
        https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html
      • Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
        "JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already been updated. JetBrains has credited Antoni Tremblay with discovering and reporting the flaw on July 10, 2026. "If exploited, this flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process," JetBrains said."
        https://thehackernews.com/2026/07/critical-teamcity-flaw-could-let.html
        https://securityaffairs.com/196169/security/jetbrains-patches-cvss-9-8-teamcity-flaw-allowing-server-takeover.html
        https://www.helpnetsecurity.com/2026/07/28/teamcity-rce-cve-2026-63077-fixed/
      • How We Hacked Thousands Of Data Centers In Minutes Using a 20-Year-Old Vulnerability
        "A Baseboard Management Controller (BMC) is a highly privileged management processor that provides remote control over a server independently of its operating system. It allows administrators to manage and troubleshoot servers remotely, eliminating the need for physical access to the hardware. We identified 36,872 internet-exposed server-management interfaces running IPMI, a protocol introduced more than two decades ago for remote control over physical servers. Of the systems we tested, 24,650 disclosed password-derived authentication hashes before login because of CVE-2013-4786, a vulnerability in the IPMI 2.0 authentication protocol that enables offline password-cracking attempts."
        https://lavahq.io/research/bmc-exposure-alert
        https://thehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html
        https://www.bleepingcomputer.com/news/security/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/
        https://www.darkreading.com/cyber-risk/flaw-exposes-data-centers-server-takeover
        https://www.helpnetsecurity.com/2026/07/28/exposed-bmc-ipmi-vulnerability-research/
      • FaceHugger: Vulnerabilities In Hugging Face Diffusers Open Door To Supply Chain Attacks On Enterprise AI
        "Zafran Labs discovered a set of high-severity vulnerabilities in Hugging Face's diffusers library that let a malicious model repository silently execute arbitrary code on any client machine that loads it. These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the custom pipelines loading process. Hugging Face has become a critical part of the AI software supply chain, rapidly evolving to be the "GitHub of the AI era". Its libraries and repositories are widely integrated into development, research, and production environments."
        https://www.zafran.io/resources/facehugger-vulnerabilities-in-hugging-face-diffusers-open-door-to-supply-chain-attacks-on-enterprise-ai
        https://www.infosecurity-magazine.com/news/hugging-face-diffusers-trust/
      • Apple Patches 87 Vulnerabilities In iOS, 155 In MacOS Tahoe
        "Apple announced on Monday that it has released patches for dozens of vulnerabilities discovered recently in its operating systems. The company patched 87 vulnerabilities with the release of iOS 26.6 and iPadOS 26.6. The flaws can be exploited to access sensitive user data, fingerprint users, cause a DoS condition, execute arbitrary code, delete files, modify the file system, bypass security, add contacts without authorization, spoof the UI, and escalate privileges. In macOS Tahoe 26.6, Apple fixed 155 vulnerabilities, including ones allowing access to sensitive user data, arbitrary code execution, security bypasses, and DoS attacks."
        https://www.securityweek.com/apple-patches-87-vulnerabilities-in-ios-155-in-macos-tahoe/
        https://www.malwarebytes.com/blog/news/2026/07/july-apple-updates-are-especially-important-if-you-receive-images
      • Libssh2 Flaws Let Malicious SSH Servers Corrupt Client Memory
        "Four new libssh2 vulnerabilities put SSH and SFTP clients at risk. Each one lets a malicious SSH server corrupt memory on the machine that connects to it. VulnCheck disclosed the flaws on July 24, 2026, and upstream fixes are ready."
        https://securityonline.info/libssh2-vulnerabilities/
      • When AI Makes 0-Days Feel Like N-Days
        "After my n-day analysis on net/tls bugs and exploit writing for a patched net/rxrpc bug, I moved on to 0-day bug hunting. With the help of AI, I found a UAF bug in net/sched, and went about creating an LPE exploit based on it. This blog goes into the technical details of that exploit, and how I optimized it to target CentOS 9 desktop in TyphoonPwn 2026. Additionally, I will show a glimpse of two other exploitable bugs I found in kernel/events/core.c (with an LPE exploit for one)."
        https://starlabs.sg/blog/2026/07-when-ai-makes-0-days-feel-like-n-days/
        https://thehackernews.com/2026/07/researcher-says-ai-helped-develop-linux.html
        https://www.infosecurity-magazine.com/news/ai-linux-kernel-zero-day-net-sched/

      Malware

      • Call Of Duty Mobile Scam Uses Fake Free Points To Steal Player Accounts
        "Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway. Victims are asked to log in with their email address and password to claim free Call of Duty Points (CP), the game’s premium currency. They’re then redirected to a second page asking for their two-factor authentication (2FA) code. The site has no connection to Activision. Its only purpose is to steal the login details needed to take over accounts."
        https://www.malwarebytes.com/blog/threat-intel/2026/07/call-of-duty-mobile-scam-uses-fake-free-points-to-steal-player-accounts
        https://www.helpnetsecurity.com/2026/07/28/call-of-duty-mobile-players-scam/
      • Mirage Kitten Targets Middle East And Africa Region With New Malware
        "Mirage Kitten – also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore – is an advanced persistent threat (APT) group focused on cyber-espionage operations against aerospace, aviation, defense, and telecommunications sectors across the Middle East and Europe, using highly targeted spear-phishing campaigns, fake recruitment portals, and custom multi-stage malware to gain persistent access and exfiltrate sensitive data. During recent threat research, we identified a previously undocumented malware set developed and used by Mirage Kitten. The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture; and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, for covert network access and operator-controlled tunneling."
        https://securelist.com/mirage-kitten-new-tools/120811/
        https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html
      • CubePilot Drone Software Dev Hit By DNS Hijacking To Intercept Traffic
        "CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. Hijacking domain name system (DNS) records allows threat actors to redirect users to their infrastructure, diverting traffic intended for a legitimate service. This exposes users to dangerous scenarios such as sensitive data interception, malware delivery, and phishing. According to a status update published on CubePilot’s website, an attacker gained control of the cubepilot[.]org domain DNS settings on July 24, allowing them to intercept traffic intended for internal systems."
        https://www.bleepingcomputer.com/news/security/cubepilot-drone-software-dev-hit-by-dns-hijacking-to-intercept-traffic/
      • Notes From Underground: Adversarial Prompt Injection
        "AI’s impact on the threat landscape continues to be top of mind for most organizations, both in terms of how malicious actors will leverage the technology in attacks and how defenders will secure their own operationalized AI and agentic applications. Proofpoint Threat Research continues to observe widespread incorporation of large language model (LLM) assisted tooling and generated material into attack chains. This is leading to enhanced scale, velocity, and variability of activity within malicious campaigns. The noted increase of device code phishing frameworks is one good example."
        https://www.proofpoint.com/us/blog/threat-insight/notes-underground-adversarial-prompt-injection
      • Tengu: A Modernized Mirai That Doesn’t Want To Leave
        "Tengu is a modern Mirai-derived IoT malware family that shows how today’s botnets are evolving beyond simple distributed denial-of-service tooling. We selected tengu for deeper analysis because it stood out from the many Mirai-derived samples we track, and because it was surfaced by our machine-learning system for identifying previously unknown malware families. It combines a custom encrypted command-and-control protocol, proxy functionality, payload updates, system and network discovery, and a broad set of denial-of-service capabilities targeting multiple protocols and services. It also includes multiple persistence and self-defense mechanisms designed to keep the malware running on compromised Linux-based devices and make recovery more difficult."
        https://www.nozominetworks.com/blog/tengu-a-modernized-mirai-that-doesnt-want-to-leave
        https://thehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html

      Breaches/Hacks/Leaks

      • Origin Energy Data Breach Affects 900,000 Australians
        "Australian power company Origin Energy Limited said the recent data breach affects 900,000 current and former customers. Origin Energy, which has roughly 4.8 million customers, is one of Australia’s largest electricity and gas retailers. The company recently started investigating a cybersecurity incident and determined that threat actors gained access to customer data, including names, dates of birth, phone numbers, addresses, account information, and partial payment card or bank account numbers."
        https://www.securityweek.com/origin-energy-data-breach-affects-900000-australians/
      • Coordinated Cyberattack Disrupts Water Utilities In 30+ Minnesota Communities
        "More than 30 Minnesota communities saw their water and wastewater utilities disrupted by a coordinated cyberattack on Sunday and Monday, the state’s technology bureau announced Tuesday. Among those was the City of Braham, a community of 1,700 people that brands itself the “Homemade Pie Capital of Minnesota.” Braham officials on Monday morning announced on the city website that its water plant was “offline for an unknown reason” and asked its residents to minimize water use because the city water tower held only a “limited quantity.” A second notice later that day noted that the plant was back online, explaining that the outage had been the result of “a malicious cyber-attack of computerized operating systems by unknown actors.”"
        https://statescoop.com/coordinated-cyberattack-disrupts-water-utilities-in-30-minnesota-communities/

      General News

      • Shadow AI Incident Response Begins With Logs That May Already Be Gone
        "In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound traffic to AI platforms are often gone before responders arrive, and what regulators look for when they assess whether a company did enough. Wityak also discusses the gap between an AI policy in a wiki and a control a company can defend, and when documentation helps or hurts."
        https://www.helpnetsecurity.com/2026/07/28/brandy-wityak-levelblue-shadow-ai-incident-response/
      • For Some, So-Called ‘Skynet Day’ Came Too Close To Sci-Fi After a Rogue Agent Hacked Into a Startup
        "To be fair, James Cameron did warn us. Long before OpenAI broke out of its test corral and hacked into Hugging Face, before the internet and Sam Altman were even born, Cameron wrote a screenplay about an autonomous artificial intelligence system that triggers a nuclear apocalypse. That system, “Skynet,” was solidly science fiction — and, for its day, pure speculation. But four decades after it appeared in “The Terminator,” it looks more like a forecast of the “unprecedented cyber incident” in which a rogue artificial intelligence system hacked into another AI company on its own."
        https://www.securityweek.com/for-some-so-called-skynet-day-came-too-close-to-sci-fi-after-a-rogue-agent-hacked-into-a-startup/
      • Fast Remediation Is The New Trust Model: JFrog And OpenAI Collaboration On Zero-Day Security Findings
        "Just last week, OpenAI and Hugging Face jointly disclosed what may be the first incident of its kind: during an internal evaluation of frontier cyber capabilities, OpenAI’s models, running deliberately without production safeguards in an isolated research environment, autonomously discovered and employed chained vulnerabilities to escape its sandbox, reach the open internet, and extract evaluation answers from Hugging Face’s infrastructure. The industry is right to pay attention. This is a preview of a world where software, not humans, probes, chains, and exploits vulnerabilities at machine speed. We want to share how the JFrog and OpenAI teams collaborate on security incidents to drive them to resolution, and why we believe the outcome demonstrates the trust model the industry now needs."
        https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/
        https://www.bleepingcomputer.com/news/security/openai-models-used-artifactory-zero-days-to-escape-to-the-internet/
        https://thehackernews.com/2026/07/jfrog-confirms-openai-models-exploited.html
      • VulnCheck State Of Exploitation 1H-2026
        "Over the past six months, we’ve seen a significant change in vulnerability discovery and disclosure resulting in a substantial increase in the number of CVEs disclosed. This increase has come with warnings about the increase in vulnerability discovery by Autonomous AI systems, creating a “dangerous” scenario for the software ecosystem. So, I was curious to explore: are more vulnerabilities being discovered and disclosed, resulting in more vulnerabilities being exploited? Is the rate at which vulnerabilities are being exploited faster? Are vulnerabilities being discovered with AI tools more dangerous? Or are we all feeding into the AI-Assisted vulnerability discovery hype cycle?"
        https://www.vulncheck.com/blog/state-of-exploitation-1h-2026
        https://www.bankinfosecurity.com/many-more-bugs-but-exploits-stay-steady-a-32346
        https://cyberscoop.com/ai-assisted-security-tools-are-finding-more-bugs-but-the-threat-level-has-not-changed/
      • IR Trends Q2 2026: Phishing And Weaponized Remote Management Tools Drive Attack Chains
        "Phishing was the primary means of gaining initial access this quarter, appearing in over half of all Cisco Talos Incident Response (Talos IR) engagements – an increase from approximately a third of engagements last quarter. Attackers continued to innovate their delivery methods to evade defenses, deploying QR code-embedded PDFs to bypass traditional email gateways and hosting links on trusted cloud platforms. We also saw a spike in authentication abuse this quarter — observed in 65 percent of engagements compared to 35 percent last quarter — with attackers frequently bypassing or defeating multi-factor authentication (MFA) using adversary-in-the-middle (AitM) proxies, session-token theft, MFA fatigue attacks, and self-enrolled devices, amongst other methods."
        https://blog.talosintelligence.com/ir-trends-q2-2026/
        https://www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/
      • Discovering Cryptographic Weaknesses With Claude
        "Using Claude Mythos Preview, researchers at Anthropic have discovered improved ways to attack cryptographic algorithms (the mathematical methods used to keep online data private). The first attack significantly weakens HAWK, a digital signature scheme that was built for a post-quantum world. The second identifies a new way to attack round-reduced AES, the most widely used symmetric cipher. These are substantial research advances, but they do not currently affect any production systems. This post describes both findings in more detail and discusses the implications for cryptography in an age of powerful AI models."
        https://www.anthropic.com/research/discovering-cryptographic-weaknesses
        https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html
        https://cyberscoop.com/anthropic-claude-mythos-encryption-flaws-hawk-aes-pqc/
      • Ghost Credentials Expose Cloud Systems To Hidden Identity Risks
        "A seemingly minor insider incident last year involving a small, isolated cloud account turned out to be a harbinger of a potentially larger identity problem. When an AI‑enabled workflow agent that had been idle for 30 days suddenly woke up and began firing off API calls at unusual times, it triggered an anomaly investigation. During the course of the investigation, Aleksandr Krasnov, a distinguished security architect at Ducker Tech Consulting, discovered a mesh of "ghost credentials" and non‑human identities — tokens, agents, and service accounts that lived outside traditional trust boundaries but were still able to move laterally through the environment and escalate privileges to access systems."
        https://www.darkreading.com/cloud-security/non-human-identity-sprawl-creates-a-new-cloud-attack-path
      • When AI Agents Escape Sandboxes, Old Security Rules Apply
        "In a world where AI agents can discover vulnerabilities, escape sandboxes, and take autonomous action across networks, organizations should double down on some of cybersecurity's oldest principles. On July 21, OpenAI detailed a security incident in which it took responsibility for a breach against part of Hugging Face's production infrastructure. According to a blog post from the AI giant, a combination of OpenAI agents based on models including GPT‑5.6 Sol as well as "an even more capable pre-release model" broke containment during a sandboxed evaluation intended to quantify said models' cyber capabilities."
        https://www.darkreading.com/application-security/ai-agents-escape-sandboxes-old-security-rules-apply
      • Stronger AI Safety Requires Peeking Inside The 'Black Box'
        "Adding security to AI often treats the large language model (LLM) or AI system as a black box, focusing on analyzing the tokenized inputs and outputs but not what goes on inside the model. The resulting techniques are often complex and individualized to specific models. A group of offensive-security researchers hopes to change that, presenting at the Black Hat USA 2026 in August a model-agnostic approach to activation analysis with standardized rules for processing activation events. Rather than labeling certain activation distributions as "cybercrime" or "hate speech," the approach uses a more granular scheme of cognitive elements (CEs) that can be combined in rules."
        https://www.darkreading.com/cybersecurity-analytics/stronger-ai-safety-requires-peeking-inside-black-box
      • Agentic Browsers Rewind Web Security By 20 Years
        "As business users and developers alike tap into agentic browsers to take work off their plates, the very traits that make them useful are also introducing a whole new class of risks. Security researchers warn that to make it easier for agents to reach across different Web domains to get things done for the user, agentic browsers have "ripped out" some key security mechanisms from the browser. Unsurprisingly, this has opened up every commercial agentic browser out in the market to new attack possibilities that range from account takeover to full-blown browser escape and remote compromise of the underlying system running the browser."
        https://www.darkreading.com/endpoint-security/agentic-browsers-rewind-web-security-20-years
      • Why Resetting Passwords No Longer Stops Attackers
        "The surge in device-code phishing attacks highlights how threat actors are increasingly stealing passwords to target authentication sessions, tokens, and trust relationships that enable them to masquerade as legitimate users and maintain persistent access. Compromised tokens and sessions allow attackers to operate within trusted identity environments, making malicious activity indistinguishable from legitimate user behavior. Device code phishing, for instance, exploits a legitimate sign-in process designed for devices with limited input capabilities, such as smart TVs and Internet of Things (IoT) devices."
        https://www.darkreading.com/endpoint-security/why-resetting-passwords-no-longer-stop-attacks
      • Former Citigroup CISO Blauner On What Makes A Great Security Leader
        "The role of the chief information security officer (CISO) has transformed dramatically over the past three decades, evolving from an emerging technical position into one of the most strategically important leadership roles in business. Few people have witnessed that evolution as closely as Charles Blauner, who served as CISO at JPMorgan, Citigroup, and Deutsche Bank after entering the field at the dawn of information security. In this episode of Heard It From a CISO, Blauner reflects on the influence of Steve Katz, who is regarded as “The Godfather” of the CISO role, and explains how mentorship, collaboration, and a culture of paying it forward helped shape the profession."
        https://www.darkreading.com/cybersecurity-operations/former-citigroup-ciso-blauner-great-security-leader
      • While External Threats Are Driving Security Awareness, Internal Risks Are Growing
        "External threats remain among the primary reasons organizations invest in security awareness and training. Phishing, ransomware, credential theft, social engineering, and attacks on peer organizations all reinforce the same point: Employee behavior directly affects an organization’s cyber risk. According to the Fortinet Training Institute 2025 Security Awareness and Training Global Research Report, 41% of respondents cite external threats as the primary driver for implementing security awareness and training programs. Organizations face a threat landscape shaped by organized cybercrime, ongoing reconnaissance, shorter time-to-exploit, and the growing use of stolen credentials and access paths. These pressures help explain why external threats remain the top motivator for cybersecurity training in 2025."
        https://www.fortinet.com/blog/industry-trends/while-external-threats-are-driving-security-awareness-internal-risks-are-growing
      • Hugging Face Breach Reignites Open-Weights Debate, Raises Liability Questions
        "The first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident post-mortem compiled with the input from Hugging Face and several hundred members of Cloud Security Alliance’s CISO community, the nonprofit organization laid out the most salient points for security leaders and advised on what they should do next."
        https://www.helpnetsecurity.com/2026/07/28/hugging-face-breach-ciso-playbook-open-weight-llms/
      • Hacker Conversations: Tal Kollander’s Journey From Black Hat To Hack Blocker
        "Tal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks. Based in Tel Aviv, Israel, Tal Kollander has the mindset of a hacker (we’re talking specifically about computer hackers). She believes hackers use creative skills to access computers by ‘non-legit’, basically criminal but creative, methods. A hacker to Kollander is anyone who accesses a computer without proper authorization to do so. Hackers are then subdivided by their subsequent actions. A ‘good’ hacker will report findings to the computer owner. “This is what I found. Now go fix it,” explains Kollander. These are white hat hackers."
        https://www.securityweek.com/hacker-conversations-tal-kollanders-journey-from-black-hat-to-hack-blocker/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 42c8b188-ea9f-4458-9389-e85ac794737d-image.png

      1 การตอบกลับ คำตอบล่าสุด ตอบ คำอ้างอิง 0
      • First post
        Last post