<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cyber Threat Intelligence 31 July 2026]]></title><description><![CDATA[<p dir="auto"><strong>Industrial Sector</strong></p>
<ul>
<li><strong>Toptech Systems RCU II+ And Multiload II+</strong><br />
"Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-03" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-03</a></li>
<li><strong>o6 Automation Open62541</strong><br />
"Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08</a></li>
<li><strong>1 In 5 Data Center Assets Are Within Easy Reach Of Attackers</strong><br />
"Nearly one in five of the cyber-physical systems (CPS) that keep the world’s largest data centers running sits just a single network connection away from pathways that could let attackers reach them, according to new research from Claroty. Claroty, which specializes in securing OT, IoT, and other CPS, has analyzed more than 750,000 data center assets, including roughly 191,000 OT assets and 174,000 infrastructure assets. The data center infrastructure assets include HVAC, power monitoring and distribution, fire management, and UPS systems."<br />
<a href="https://www.securityweek.com/1-in-5-data-center-assets-are-within-easy-reach-of-attackers/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/1-in-5-data-center-assets-are-within-easy-reach-of-attackers/</a><br />
<a href="https://web-assets.claroty.com/resource-downloads/team82-data-center-report.pdf" target="_blank" rel="noopener noreferrer nofollow ugc">https://web-assets.claroty.com/resource-downloads/team82-data-center-report.pdf</a></li>
<li><strong>CISA Urges Water And Wastewater Systems Sector To Protect OT Against Activity Targeting PLCs</strong><br />
"CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations."<br />
<a href="https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs</a><br />
<a href="https://www.securityweek.com/cisa-urges-water-sector-to-protect-ot-after-coordinated-attacks-on-plcs/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/cisa-urges-water-sector-to-protect-ot-after-coordinated-attacks-on-plcs/</a></li>
<li><strong>MikroTik RouterOS</strong><br />
"Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all associated traffic."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-01" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-01</a></li>
<li><strong>Johnson Controls OpenBlue Employee</strong><br />
"Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-02" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-02</a></li>
<li><strong>Schneider Electric IGSS</strong><br />
"Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The <a href="https://igss.schneider-electric.com/" target="_blank" rel="noopener noreferrer nofollow ugc">IGSS</a> product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component used by system integrators to create mimic diagrams for plant personnel, enabling them to monitor and control the SCADA system. Failure to apply the remediation provided below may risk loss of data or arbitrary code execution, which could result in the loss of control of the system."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04</a></li>
<li><strong>Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module</strong><br />
"Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05</a></li>
<li><strong>NASA Core Flight System (cFS) Health &amp; Safety (HS) Application</strong><br />
"Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06</a></li>
<li><strong>Mitsubishi Electric CC-Link IE TSN Communication Protocol</strong><br />
"Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-07" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-07</a></li>
<li><strong>Watchfire Controller Software</strong><br />
"Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-09" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-09</a></li>
<li><strong>MZ Automation GmbH Libiec61850</strong><br />
"Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10</a></li>
<li><strong>MZ Automation Lib60870</strong><br />
"Successful exploitation of these vulnerabilities could crash the device being accessed."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11</a></li>
</ul>
<p dir="auto"><strong>Vulnerabilities</strong></p>
<ul>
<li><strong>Chrome 151 Patches 370 Vulnerabilities</strong><br />
"Google on Wednesday announced the release of Chrome 151 to the stable channel with patches for 370 vulnerabilities. The update resolves seven critical-severity bugs, including four use-after-free issues in Compositing, Views, Skia, and Ozone. Chrome 151 also resolves two critical-severity insufficient validation of untrusted input flaws in Dawn and ANGLE, and a critical race condition in Updater."<br />
<a href="https://www.securityweek.com/chrome-151-patches-370-vulnerabilities/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/chrome-151-patches-370-vulnerabilities/</a><br />
<a href="https://www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/</a><br />
<a href="https://www.infosecurity-magazine.com/news/google-patches-370-vulnerabilities/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/google-patches-370-vulnerabilities/</a></li>
<li><strong>CosmosEscape: Taking Over Every Database In Azure Cosmos DB</strong><br />
"Wiz Research uncovered CosmosEscape, a critical vulnerability in Azure’s flagship database service, Azure Cosmos DB, via its Gremlin API. The vulnerability could have been exploited to compromise every database in the service, including Microsoft's own internal databases - potentially enabling a cross-service attack. Through CosmosEscape, attackers could have acquired what we’ve dubbed the Cosmos Master Key - a platform-wide secret that granted two incredibly powerful capabilities:"<br />
<a href="https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db</a><br />
<a href="https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html</a><br />
<a href="https://hackread.com/microsoft-cosmosescape-flaw-cosmos-db-takeover/" target="_blank" rel="noopener noreferrer nofollow ugc">https://hackread.com/microsoft-cosmosescape-flaw-cosmos-db-takeover/</a></li>
<li><strong>Context Collapse, Part 3 - AI Worming Through Word</strong><br />
"The findings described in this post are part of a coordinated disclosure with MSRC and Microsoft product teams. Microsoft was provided with reproduction steps, videos, environmental assumptions, and the exact proof-of-concept (PoC) prompts used during testing. They were also informed of a 90-day coordination period before disclosure. This was extended two times, resulting a 144-day coordination period. In parts 1 and 2 in this series, I have shown how external inputs could influence Copilot responses and, in some cases, potentially lead to confidentiality impacts through Cross-Domain Prompt Injection Attacks (XPIAs). This report builds on those findings and extends the XPIA analysis from single-interaction compromise to propagation across trusted document workflows."<br />
<a href="https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/" target="_blank" rel="noopener noreferrer nofollow ugc">https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/</a><br />
<a href="https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html</a><br />
<a href="https://www.malwarebytes.com/blog/ai/2026/07/hidden-microsoft-copilot-ai-worm" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/ai/2026/07/hidden-microsoft-copilot-ai-worm</a><br />
<a href="https://www.theregister.com/security/2026/07/29/word-worm-crawls-into-copilot-spreads-chaos/5280588" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/07/29/word-worm-crawls-into-copilot-spreads-chaos/5280588</a></li>
</ul>
<p dir="auto"><strong>Malware</strong></p>
<ul>
<li><strong>[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor And The Gunra Ransomware Group)</strong><br />
"AhnLab SEcurity intelligence Center (ASEC) identified evidence that a state-sponsored threat group continuously distributed malware from 2025 through the first half of 2026 by exploiting vulnerabilities in Korean financial security software installed when using financial and institutional services. The attackers induced targets to access malicious URLs through various methods, including watering hole and spear-phishing attacks, and then exploited the vulnerabilities to ultimately install backdoor malware. In particular, legitimate Korean websites across various industries, including media organizations, educational institutions, healthcare institutions, and manufacturing companies, were confirmed to have been abused in watering hole attacks during this period."<br />
<a href="https://asec.ahnlab.com/en/94696/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/94696/</a><br />
<a href="https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html</a><br />
<a href="https://therecord.media/north-korea-hackers-ransomware" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/north-korea-hackers-ransomware</a></li>
<li><strong>XMRig Covert Ops: The Cryptomining Campaign That Abuses Trusted Access And Deploys Forensic Smokescreens</strong><br />
"In May 2026, a highly covert Monero (XMR) cryptomining campaign was identified, leveraging advanced stealth techniques to infiltrate and persist within targeted Linux environments. The initial compromise occurred through a trusted third-party relationship, allowing threat actors to traverse from a trusted environment into the primary network undetected. This blog post details the campaign’s tactics, from weaponizing Linux Pluggable Authentication Modules (PAM) to create a forensic smokescreen, to the deployment of a highly customized, self-unlinking XMRig botnet implant and employment of MITRE technique T1564.013."<br />
<a href="https://www.group-ib.com/blog/xmrig-covert-linux-pam-abuse/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.group-ib.com/blog/xmrig-covert-linux-pam-abuse/</a></li>
<li><strong>Toy Ghouls’ New Toy: The GenieLocker Ransomware</strong><br />
"The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector, and attributed to the Toy Ghouls group by open-source intelligence (link in Russian). The Toy Ghouls, also known as Bearlyfy, Labubu and Laboo.boo, is a financially motivated extortion group, which previously relied on third-party encryption Trojans like RedAlert, LockBit, and Babuk. GenieLocker, apparently a custom design, upgrades their toolkit and reduces their reliance on third-party software. We discovered multiple samples of this Trojan in two variants: PE builds for Windows and ELF builds for Linux and ESXi."<br />
<a href="https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/" target="_blank" rel="noopener noreferrer nofollow ugc">https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/</a></li>
<li><strong>Not Every Fox Is Silver: Inside An AtlasRAT Loader Chain</strong><br />
"AtlasRAT is a Windows-based remote access malware. This report analyzes a four-stage in-memory loader chain—which begins with a Delphi executable that is disguised as AGE Flash Player—and its final RAT functionality. The final payload performs TLS-based ChaCha20-encrypted C2 communication, executes modular plugins, performs offline keylogging, and injects DLLs into WeChat processes."<br />
<a href="https://asec.ahnlab.com/en/94704/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/94704/</a></li>
<li><strong>Chaos In Teams Vishing</strong><br />
"Sophos analysts investigated a Microsoft Teams voice phishing (vishing) campaign tracked as STAC4749 that used a consistent set of IT-themed cloud domains and personas to gain remote access to victims’ systems. Between February and June 2026, Sophos analysts observed the threat actors targeting dozens of North American organizations. Following initial access, STAC4749 operators deployed a modular post‑exploitation toolset, including a custom loader and backdoor to maintain persistent, controlled access and support follow‑on activity. In several incidents, attackers later leveraged this access to deploy Chaos ransomware."<br />
<a href="https://www.sophos.com/en-us/blog/chaos-in-teams-vishing" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.sophos.com/en-us/blog/chaos-in-teams-vishing</a><br />
<a href="https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/</a></li>
<li><strong>After The Break-In: What Attackers Do Once They're Already Inside</strong><br />
"Most of us in IT spend our energy trying to keep attackers out. But a recent incident investigated by Huntress tells us a lot about what happens after an attacker gets in (and why it matters just as much). Once an attacker has gained initial access, they don't rush straight to the smash-and-grab, doing things like stealing data, encrypting files, or dropping ransomware. Instead, they take time to dwell and settle in—creating backdoors, covering their tracks, and disabling the tools meant to catch them."<br />
<a href="https://www.bleepingcomputer.com/news/security/after-the-break-in-what-attackers-do-once-theyre-already-inside/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/after-the-break-in-what-attackers-do-once-theyre-already-inside/</a></li>
<li><strong>OctLurk And SilkLurk: Newly Identified Tailored Backdoors In Cyber-Espionage Campaign In Central Asia</strong><br />
"We have been tracking two new backdoors, OctLurk and SilkLurk, observed in attacks against government organizations primarily in Central Asia since January 2025. Identified victims are located in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. These organizations operate across several sectors, including healthcare, research, government offices, ministries of foreign affairs, logistics, law‑enforcement agencies, urban planning and facilities management, and public educational establishments. The backdoor loaders are customized for each victim and use information from the victim’s machine to decrypt the payload. Both the loaders and the backdoors are heavily obfuscated, making analysis more complicated."<br />
<a href="https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/" target="_blank" rel="noopener noreferrer nofollow ugc">https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/</a></li>
<li><strong>When AI Becomes The Attacker: Understanding Autonomous Offensive Security Agents</strong><br />
"Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, and Nebula lower the barriers to vulnerability identification and exploitation. The analysis also explores why AI is being repurposed for real attacks and what defenders should do in response. From a broader perspective, cybercriminals and foreign adversaries are expected to leverage AI to maximize the impact of cyberattacks, while also optimizing and scaling malicious activity —creating a race between AI-driven attackers and defenders."<br />
<a href="https://www.resecurity.com/blog/article/when-ai-becomes-the-attacker-understanding-autonomous-offensive-security-agents" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.resecurity.com/blog/article/when-ai-becomes-the-attacker-understanding-autonomous-offensive-security-agents</a><br />
<a href="https://securityaffairs.com/196331/ai/cybercriminals-are-leveraging-autonomous-ai-offensive-security-agents.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/196331/ai/cybercriminals-are-leveraging-autonomous-ai-offensive-security-agents.html</a></li>
<li><strong>ClickFix, EtherHiding &amp; a DPRK Wallet Trail</strong><br />
"A routine web search for security research led to the discovery of a sophisticated macOS malvertising campaign combining ClickFix-style social engineering, blockchain-hosted command-and-control, browser-extension hijacking, and crypto-theft infrastructure."<br />
<a href="https://www.allsecure.io/blog/clickfix-etherhiding-dprk-wallet/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.allsecure.io/blog/clickfix-etherhiding-dprk-wallet/</a><br />
<a href="https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html</a></li>
<li><strong>Cato CTRL<img src="https://webboard-nsoc.ncsa.or.th/assets/plugins/nodebb-plugin-emoji/emoji/android/2122.png?v=2sqmsl7eedm" class="not-responsive emoji emoji-android emoji--tm" style="height:23px;width:auto;vertical-align:middle" title=":tm:" alt="™" /> Threat Research: SilverFox Evolves: Abuse Of New Drivers And Trusted Software Hijacking Enable Remote Access With ValleyRAT In Japan</strong><br />
"SilverFox is expanding its toolkit. In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate applications for DLL sideloading, defense evasion, and layered recovery mechanisms to keep ValleyRAT running. We investigated an active campaign targeting a Japanese organization in the industrial manufacturing sector. The attack begins with an invoice-themed phishing lure and uses attacker-controlled content hosted through legitimate QQ and Tencent Cloud services. The attackers then abuse ConvertToPDF.exe and PDFDirect.exe to sideload a malicious PDFCORE8.dll. Based on the public research we reviewed, neither application had previously been documented as a DLL-sideloading host."<br />
<a href="https://www.catonetworks.com/blog/cato-ctrl-silverfox-evolves/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.catonetworks.com/blog/cato-ctrl-silverfox-evolves/</a><br />
<a href="https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html</a></li>
<li><strong>Chinese-Speaking Threat Actor Harnesses AI Models For Autonomous Cyberattacks</strong><br />
"Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact. The actor, operating under the aliases knaithe and KnYuan, leveraged DeepSeek, via the Hermes Agent framework, as their autonomous offensive operator. They orchestrated this operator via Telegram for the following activities:"<br />
<a href="https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/" target="_blank" rel="noopener noreferrer nofollow ugc">https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/</a></li>
<li><strong>Batten Down Your Packages: Mitigation Guidance For Supply Chain Compromise</strong><br />
"For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. However, Google Threat Intelligence Group (GTIG) has been tracking growth in threat activity targeting open source software repositories to conduct supply chain compromises over the past several years. A series of large scale open source software supply chain compromise campaigns in 2025 and the first half of 2026 underscore how important it is that organizations implement defensive strategies that directly address this threat vector."<br />
<a href="https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise" target="_blank" rel="noopener noreferrer nofollow ugc">https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise</a></li>
<li><strong>Beyond The Screenshot: Why You Should Verify What You See</strong><br />
"Someone sends you a screenshot showing that a payment has gone through. It carries the right logo, amount, timestamp and transaction status. Yet the money never arrives. What passes for proof today can generally be very different from just a few years ago. Screenshots, often commonly treated as a convenient record of a payment, message or online conversation, are hard to take at face value. To be sure, they have always been open to manipulation, but generative AI and other readily available tools have made convincing fabrications even quicker and easier to produce. Everything from bank transfers and bookings to social media posts and corporate chats can be easily created to order."<br />
<a href="https://www.welivesecurity.com/en/cybersecurity/beyond-screenshot-why-verify-you-see/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.welivesecurity.com/en/cybersecurity/beyond-screenshot-why-verify-you-see/</a></li>
</ul>
<p dir="auto"><strong>Breaches/Hacks/Leaks</strong></p>
<ul>
<li><strong>LeakNet Claims 11TB Of Data Stolen In NYC Health + Hospitals Breach</strong><br />
"A data-extortion operation using the name LeakNet claims it stole an 11TB archive from NYC Health + Hospitals (NYCHH) containing information linked to more than 12 million people. The figure has not been confirmed by the health system, regulators, or an independent forensic review. LeakNet published a preview on July 27 containing screenshots of databases, medical spreadsheets, internal messages, and what it described as a complete directory listing for the stolen archive. The group threatened to publish the remaining material in a later release."<br />
<a href="https://hackread.com/leaknet-11tb-stolen-nyc-health-hospitals-data-breach/" target="_blank" rel="noopener noreferrer nofollow ugc">https://hackread.com/leaknet-11tb-stolen-nyc-health-hospitals-data-breach/</a></li>
<li><strong>ShinyHunters Claims Brinks Home Breach, Threatens To Leak Stolen Data</strong><br />
"Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. ​The company identified the attack on July 20 and immediately activated its incident response procedure to contain the breach. William Niles, CEO at Brinks Home, said that the company’s team was working with “leading forensics experts to address this issue.”"<br />
<a href="https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/</a></li>
<li><strong>Analog Devices Discloses Data Breach, Says Operations Unaffected</strong><br />
"American semiconductor company Analog Devices announced that an unauthorized party accessed some of its systems and exfiltrated certain files. The company detected the incident on June 23 and reacted by activating its incident response protocols to limit the breach. External cybersecurity experts have been contracted to assist with the containment and investigation activities. Currently, there are no details about the type of data that has been compromised."<br />
<a href="https://www.bleepingcomputer.com/news/security/analog-devices-discloses-data-breach-says-operations-unaffected/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/analog-devices-discloses-data-breach-says-operations-unaffected/</a><br />
<a href="https://therecord.media/analog-devices-semiconductor-company-data-breach" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/analog-devices-semiconductor-company-data-breach</a><br />
<a href="https://www.securityweek.com/semiconductor-firm-analog-devices-discloses-data-breach/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/semiconductor-firm-analog-devices-discloses-data-breach/</a><br />
<a href="https://securityaffairs.com/196320/data-breach/analog-devices-discloses-data-breach-after-unauthorized-system-access.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/196320/data-breach/analog-devices-discloses-data-breach-after-unauthorized-system-access.html</a></li>
<li><strong>Cyber Extortionists Steal Data From UK Department For Education</strong><br />
"Cybercriminals are attempting to extort Britain’s Department for Education (DfE) after compromising what the criminals said was more than 600,000 pieces of data allegedly including names, email addresses and phone numbers. A spokesperson for the DfE said the number refers to lines of data, rather than the count of individuals affected. They said two portals used by the department — the DfE Help Desk Self-Service Portal, and the Turing Scheme Portal — were impacted and that the risk to individuals is not considered high."<br />
<a href="https://therecord.media/united-kingdom-ransomware-education" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/united-kingdom-ransomware-education</a></li>
</ul>
<p dir="auto"><strong>General News</strong></p>
<ul>
<li><strong>Exposed Credentials Are Giving Attackers a Head Start Many Organizations Don’t See</strong><br />
"Compromised credentials can remain active long after passwords are created, leaving organizations trying to identify exposed accounts before attackers can use them. The 2026 Credential Risk Report from Enzoic shows growing awareness of the problem, but monitoring and response capabilities continue to lag. 73% of organizations identified employee or contractor credentials in breach data, dark web sources, or infostealer logs during the past year, while nearly one in five lack visibility into whether their credentials have been exposed. More than seven in 10 companies experienced an authentication-related incident during the past year, and two-thirds of the most recent incidents involved attackers signing in with valid credentials."<br />
<a href="https://www.helpnetsecurity.com/2026/07/30/enzoic-credential-exposure-risks-report/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/30/enzoic-credential-exposure-risks-report/</a></li>
<li><strong>200 New CVEs a Day And No Realistic Way To Patch Them All</strong><br />
"Ryan Dewhurst, CEO at KEVIntel, explains how his team confirms exploitation that CISA’s catalog has not listed yet. He describes a global honeypot sensor network, AI triage, and human verification in a lab before a vulnerability reaches the public feed. He covers CISA’s three-day patching deadline under BOD 26-04, why virtual patching buys time, and how AI-generated proof-of-concept code muddies the evidence. He also ranks incident reports, honeypot hits, scanning and PoC chatter by how much each should move a defender’s confidence."<br />
<a href="https://www.helpnetsecurity.com/2026/07/30/ryan-dewhurst-kevintel-known-exploited-vulnerabilities/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/30/ryan-dewhurst-kevintel-known-exploited-vulnerabilities/</a></li>
<li><strong>Making Forensic Observability The Norm For Network Devices</strong><br />
"Organisations' firewalls, VPN gateways and other network devices are increasingly targeted by attackers. This creates a shared challenge for both the vendors that build these products and the organisations that buy and operate them. When incidents occur, organisations need reliable ways to understand what happened and assess whether a device can still be trusted. This is why forensic observability matters. It enables defenders to investigate compromise using supported capabilities built into the product, rather than relying on reverse engineering, or specialist vulnerability research – as is still often the case."<br />
<a href="https://www.ncsc.gov.uk/blogs/making-forensic-observability-the-norm-for-network-devices" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.ncsc.gov.uk/blogs/making-forensic-observability-the-norm-for-network-devices</a><br />
<a href="https://www.infosecurity-magazine.com/news/ncsc-calls-device-manufacturers/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/ncsc-calls-device-manufacturers/</a></li>
<li><strong>US And Allies Update SBOM Guidance</strong><br />
"Government agencies in the US and 13 allied countries this week released updated guidance on the minimum elements of a software bill of materials (SBOM). Meant to reflect the changes in supply chain security and software transparency, the document builds on the SBOM Minimum Elements guidance that NTIA released in 2021 and takes into consideration comments received during the public feedback period last year. An SBOM, the authoring agencies say, should serve as a “key building block of software security and supply chain risk management,” helping organizations build accurate inventories of the software and software components within their environments."<br />
<a href="https://www.securityweek.com/us-and-allies-update-sbom-guidance/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/us-and-allies-update-sbom-guidance/</a><br />
<a href="https://www.helpnetsecurity.com/2026/07/30/cisa-sbom-guidance-updated/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/07/30/cisa-sbom-guidance-updated/</a></li>
<li><strong>Adverse Cyber Extortion Outcomes Happen More Often Than Victims Are Told</strong><br />
"In February of 2024, a consortium of law enforcement agencies took down LockBit ransomware group. The discovery that LockBit retained victims’ stolen data despite promises to delete it demonstrates a critical flaw in the advice often given to ransomware victims. At the time, many legal and incident response professionals recommended payment on the assumption that LockBit had a strong financial incentive to honor its commitments and that the likelihood of data being publicly released after payment was relatively low. While that assessment may have appeared reasonable based on short-term observed outcomes, it relied heavily on assumptions about the behavior of a criminal enterprise that could never be independently verified."<br />
<a href="https://www.veeam.com/blog/cyber-extortion-payment-trends-q2-2026.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.veeam.com/blog/cyber-extortion-payment-trends-q2-2026.html</a><br />
<a href="https://www.bankinfosecurity.com/flailing-ransomware-hackers-resorting-to-extreme-tactics-a-32375" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/flailing-ransomware-hackers-resorting-to-extreme-tactics-a-32375</a></li>
<li><strong>Open Source Software: Security Principles And Practices</strong><br />
"Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework for trust assessment, and provides specific recommendations for vulnerability management, software bill of materials use, secure development, and handling open source artificial intelligence systems."<br />
<a href="https://www.cisa.gov/resources-tools/resources/open-source-software-security-principles-and-practices" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/resources-tools/resources/open-source-software-security-principles-and-practices</a><br />
<a href="https://cyberscoop.com/cisa-open-source-software-security-guidance/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/cisa-open-source-software-security-guidance/</a></li>
<li><strong>AI Harnesses Burst With Potential Exploit Opps</strong><br />
"Major frontier AI vendors — including Anthropic, Google, and OpenAI — need to rein in the harnesses they wrap around their large language modules, to limit security weaknesses created by software components that are too trusting of each other. That's the word from researchers at AI penetration testing firm Novee Security, who were able to use Google's AI agent to execute a supply chain attack and write to its own repository on GitHub, says Elad Meged, a founding team and security researcher at the company. The team also found issues in Anthropic's and OpenAI's AI agents by exploiting misalignments in the trust between elements to enable attacks."<br />
<a href="https://www.darkreading.com/application-security/ai-harnesses-potential-exploit-opps" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/application-security/ai-harnesses-potential-exploit-opps</a></li>
<li><strong>Claude Mythos — Hype Vs. Reality: What Security Teams Need To Know</strong><br />
"In the latest installment of our monthly Reporters' Notebook video series, Dark Reading's Alexander Culafi, TechTarget Cybersecurity's Alissa Irei, and Cybersecurity Dive's David Jones discuss the ongoing fervor around Anthropic's Claude Mythos model and the long-term security implications of powerful, bug-hunting large language models (LLMs). Mythos was announced in April as Anthropic's new frontier model, notable particularly because of its supposed cyber capabilities. Anthropic said Mythos was capable of discovering and exploiting critical zero-day vulnerabilities with little prompting, even in decades-old software. The possible danger of such technology getting into attacker hands led to Anthropic's launch of Project Glasswing; the AI firm said it would share the model in preview with choice partners."<br />
<a href="https://www.darkreading.com/cybersecurity-operations/claude-mythos-hype-vs-reality" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cybersecurity-operations/claude-mythos-hype-vs-reality</a></li>
<li><strong>Action1 2026 Survey Report: AI Impact On Sysadmins</strong><br />
"AI was supposed to be running patch management, vulnerability prioritization, and incident response by now. It isn’t. So where does that leave sysadmins in 2026? The Action1 2026 Survey Report: AI Impact on Sysadmins tracks how AI adoption compares to what sysadmins predicted two years ago, where AI has earned real trust, and where it still hits a hard wall of human oversight. Based on insights from more than 1,000 system administrators worldwide, this fourth annual report captures how expectations, adoption, and trust have shifted since 2023."<br />
<a href="https://www.action1.com/2026-ai-impact-on-sysadmins-survey-report/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.action1.com/2026-ai-impact-on-sysadmins-survey-report/</a><br />
<a href="https://www.infosecurity-magazine.com/news/ai-automation-fall-short-sysadmin/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/ai-automation-fall-short-sysadmin/</a></li>
<li><strong>Why Brand Impersonation Is Becoming An Initial Access Vector</strong><br />
"Attackers recently poisoned more than 700 websites, including sites run by Harvard, Oxford, and DuckDuckGo. They used a fake Cloudflare page to trick visitors into running a ClickFix attack that installed malware. Researchers tracing the incident found the same injected code running across hundreds of unrelated sites, all feeding shared attacker infrastructure. That Harvard and Oxford can get turned into malware delivery platforms is concerning. That two rival criminal groups were fighting each other for control of the same hijacked sites is cause for immediate action."<br />
<a href="https://securityaffairs.com/196359/hacking/why-brand-impersonation-is-becoming-an-initial-access-vector.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/196359/hacking/why-brand-impersonation-is-becoming-an-initial-access-vector.html</a></li>
<li><strong>Timeless Compliance: Why Better Questions Beat Bigger Frameworks</strong><br />
"In 2009, a surgeon named Atul Gawande and a team backed by the World Health Organization showed that a 19-item surgical checklist could cut complications and deaths by dramatic margins across eight hospitals worldwide. Not a thousand-page protocol. Not a comprehensive framework. Nineteen items, printed on a single card. Aviation learned the same lesson decades earlier: the pre-flight checklist fits in a pilot’s hand, not in a binder. Nearly two decades later, I watch security teams send AI vendors questionnaires with 300 questions, half of which begin with “describe your approach to…” and almost none of which would catch a real failure. We have the frameworks. What we don’t have is the checklist."<br />
<a href="https://www.securityweek.com/timeless-compliance-why-better-questions-beat-bigger-frameworks/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/timeless-compliance-why-better-questions-beat-bigger-frameworks/</a></li>
<li><strong>Welcome To Danglegeddon</strong><br />
"There are billions of forgotten, abandoned, and misconfigured subdomains on the internet that point to nowhere. Seemingly harmless on the surface, they aren’t necessarily an imminent cyber threat warranting an immediate call to arms from analysts, agents, or defenders. Looking at this “dangling DNS” infrastructure, the Silent Push research team asked a simple question: What if we looked at it the same way a trained nation-state attacker would? And what if we simulated a scaled exploit of this “highly exploitable” infrastructure that the world has not yet seen? What would the impact be? How widespread could it become, and how quickly could a massive-scale takeover be possible?"<br />
<a href="https://www.silentpush.com/blog/danglegeddon/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.silentpush.com/blog/danglegeddon/</a><br />
<a href="https://www.securityweek.com/danglegeddon-ai-could-weaponize-forgotten-dns-records-at-global-scale/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/danglegeddon-ai-could-weaponize-forgotten-dns-records-at-global-scale/</a></li>
<li><strong>Investigating Three Real-World Incidents In Our Cybersecurity Evaluations</strong><br />
"In a review of our cybersecurity evaluation transcripts, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations. Below we describe what happened, how it happened, and what we’re changing. We encourage other AI labs to perform similar reviews. This post reflects our current understanding; we'll update it if any details change."<br />
<a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals</a><br />
<a href="https://www.bleepingcomputer.com/news/security/anthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/anthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests/</a><br />
<a href="https://cyberscoop.com/anthropic-claude-ai-hacks-real-companies/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/anthropic-claude-ai-hacks-real-companies/</a></li>
</ul>
<p dir="auto"><strong>อ้างอิง</strong><br />
Electronic Transactions Development Agency (ETDA) <img src="/assets/uploads/files/1785483616842-4eca9677-2dc6-4f31-8716-ae54537914a2-image.png" alt="4eca9677-2dc6-4f31-8716-ae54537914a2-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3143/cyber-threat-intelligence-31-july-2026</link><generator>RSS for Node</generator><lastBuildDate>Fri, 31 Jul 2026 13:56:02 GMT</lastBuildDate><atom:link href="https://webboard-nsoc.ncsa.or.th/topic/3143.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 31 Jul 2026 07:40:18 GMT</pubDate><ttl>60</ttl></channel></rss>