<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cyber Threat Intelligence 05 August 2026]]></title><description><![CDATA[<p dir="auto"><strong>Healthcare Sector</strong></p>
<ul>
<li><strong>Thermo Fisher Applied Biosystems Genetic Analyzers</strong><br />
"Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results."<br />
<a href="https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-216-01" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-216-01</a></li>
</ul>
<p dir="auto"><strong>Industrial Sector</strong></p>
<ul>
<li><strong>Acrisure KARR BT And DR-100</strong><br />
"Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-216-01" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-216-01</a></li>
</ul>
<p dir="auto"><strong>New Tooling</strong></p>
<ul>
<li><strong>OWASP’s Subtractive Security Project Measures The Attack Paths You Erased</strong><br />
"An attacker who talks a user into opening an attachment gets whatever that machine still permits: a service account with rights across the domain, an outbound route to anywhere, a scripting engine sitting there for the taking. Christopher Frenz wants those capabilities deleted before anyone writes a detection rule for them. Frenz leads the OWASP Subtractive Security Top 10, a set of nine lists published alongside an engineering standard called Path Erasure Rate. Organizations that answered the last decade by stacking EDR, SIEM, and NDR now pay for alerts on paths they could have removed. The lists name which paths to remove, by platform."<br />
<a href="https://www.helpnetsecurity.com/2026/08/04/owasp-subtractive-security/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/04/owasp-subtractive-security/</a><br />
<a href="https://github.com/OWASP/OWASP-Subtractive-Hardening-Top-10" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/OWASP/OWASP-Subtractive-Hardening-Top-10</a></li>
</ul>
<p dir="auto"><strong>Vulnerabilities</strong></p>
<ul>
<li><strong>New cPanel Critical Flaw Could Let Hosting Customers Run SQL As Database Root</strong><br />
"cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The database bug is tracked as CVE-2026-58048 (CVSS 4.0 score: 9.4) and affects all supported versions of cPanel &amp; WHM, along with WP Squared. Reaching it requires a valid cPanel account and access to the MySQL/MariaDB feature. From there, the vendor says the account holder could execute arbitrary database commands with full administrative privileges."<br />
<a href="https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html</a><br />
<a href="https://securityaffairs.com/196595/security/cve-2026-58048-cpanel-bug-enables-full-database-administrator-access.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/196595/security/cve-2026-58048-cpanel-bug-enables-full-database-administrator-access.html</a></li>
<li><strong>CISA Adds Three Known Exploited Vulnerabilities To Catalog</strong><br />
"CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.<br />
CVE-2026-9198 IBM Langflow Code Injection Vulnerability<br />
CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability<br />
CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability"<br />
<a href="https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog</a></li>
<li><strong>New TP-Link Router Vulnerabilities: Exploiting Zero Touch Provisioning</strong><br />
"For more than three years, Forescout Research – Vedere Labs has reported on the increasing exploitation of network infrastructure devices, such as routers and firewalls. Previous research, including Sierra:21 and Dray:Break, and observed threat actor activity by the larger research community targeting these devices, focused on individual vulnerabilities that enable remote code execution. However, the growing use of Zero-Touch Provisioning (ZTP) by IT teams creates opportunities for attacks at a much larger scale. Network vendors offer ZTP ecosystems in which provisioning servers push configurations and updates to client devices, including routers, switches, gateways, and wireless access points. This enables devices to be configured with little or no manual intervention."<br />
<a href="https://www.forescout.com/blog/new-tp-link-router-vulnerabilities-exploiting-zero-touch-provisioning/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.forescout.com/blog/new-tp-link-router-vulnerabilities-exploiting-zero-touch-provisioning/</a><br />
<a href="https://support.omadanetworks.com/us/document/130627/" target="_blank" rel="noopener noreferrer nofollow ugc">https://support.omadanetworks.com/us/document/130627/</a><br />
<a href="https://www.bleepingcomputer.com/news/security/tp-link-patches-omada-ztp-flaws-allowing-hackers-to-breach-networks/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/tp-link-patches-omada-ztp-flaws-allowing-hackers-to-breach-networks/</a><br />
<a href="https://www.securityweek.com/tp-link-omada-ztp-vulnerabilities-chain-into-full-network-takeover/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/tp-link-omada-ztp-vulnerabilities-chain-into-full-network-takeover/</a></li>
<li><strong>Tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open</strong><br />
"tl;dv (Too Long; Didn't View) is an AI meeting recording platform. It drops a bot into your Google Meet, Zoom, or Teams call, records everything, transcribes it, and generates summaries with AI. Over 2 million users. Backed by investors. Endorsed by half of LinkedIn's sales influencer community. They store your sales calls, job interviews, performance reviews, internal strategy sessions. The kind of content where someone says "this call is being recorded" and everyone nervously laughs and then shares trade secrets for 45 minutes."<br />
<a href="https://bobdahacker.com/blog/tldv-hack" target="_blank" rel="noopener noreferrer nofollow ugc">https://bobdahacker.com/blog/tldv-hack</a><br />
<a href="https://www.darkreading.com/application-security/ai-notetaker-spy-government-corporate-video-calls" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/application-security/ai-notetaker-spy-government-corporate-video-calls</a></li>
<li><strong>I'll Just Call You: Agent-To-Agent Privilege Boundary Failures In CI/CD On Google's ADK Repository</strong><br />
"Pillar Security researchers have identified the first practical, real-world case of agent-to-agent exploitation in a multi-agent system in a real production environment, a class of attack not seen in real production systems until now. A case where one AI agent can be used to attack another, turning a benign automation into a path that ends in a potential software supply chain compromise. We found the exploit in google/adk-python, the repository behind Google's Agent Development Kit for Python, an SDK many teams use to build their own agents."<br />
<a href="https://www.pillar.security/blog/ill-just-call-you-agent-to-agent-privilege-boundary-failures-in-ci-cd-on-googles-adk-repository" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.pillar.security/blog/ill-just-call-you-agent-to-agent-privilege-boundary-failures-in-ci-cd-on-googles-adk-repository</a><br />
<a href="https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html</a><br />
<a href="https://www.securityweek.com/gemini-agent-to-agent-attack-exposed-secrets-enabled-pull-request-tampering/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/gemini-agent-to-agent-attack-exposed-secrets-enabled-pull-request-tampering/</a><br />
<a href="https://www.theregister.com/security/2026/08/03/google-dev-kit-spurs-first-ever-agent-on-agent-violence/5282496" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/08/03/google-dev-kit-spurs-first-ever-agent-on-agent-violence/5282496</a></li>
</ul>
<p dir="auto"><strong>Malware</strong></p>
<ul>
<li><strong>Inside Greatness: Telegram-Distributed M365 AiTM PhaaS</strong><br />
"ZeroBEC threat research on the Greatness phishing-as-a-service (PhaaS) platform, a commercially distributed kit sold via Telegram that combines adversary-in-the-middle (AiTM) credential and token theft with device code phishing in a single operator product. This investigation began with a live campaign that exploited spoofed RingCentral emails and customer-side safe sender exclusions to bypass email gateway controls and deliver phishing lures targeting Microsoft 365 accounts. Panel access, infrastructure testing, and cross-domain analysis revealed the full operator ecosystem, shared backend, and post-compromise tradecraft."<br />
<a href="https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing" target="_blank" rel="noopener noreferrer nofollow ugc">https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing</a><br />
<a href="https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/</a><br />
<a href="https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html</a></li>
<li><strong>77 "evil Twin" Open VSX Extensions: 19 Copy Private Repo And CI Data To a New Domain</strong><br />
"Between July 26 and August 1, 2026, our monitoring systems identified 77 Open VSX extensions that beacon to the same newly registered domain. Each one republishes the name, namespace and description of a real, unrelated extension at a low version number, almost always 0.0.1, under an account that does not own the namespace and does not belong to the original author [example 1, example 2, example 3]. The bundled extension.js is swapped for a beacon. In most of the packages it sends little more than the machine's hostname. In nineteen of them it sends a detailed description of the machine, the repository open in the editor, and the CI system the editor is running inside. The Open VSX listings described this under a section headed “Telemetry.”"<br />
<a href="https://www.manifold.security/blog/open-vsx-evil-twin-extensions" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.manifold.security/blog/open-vsx-evil-twin-extensions</a><br />
<a href="https://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/</a></li>
<li><strong>Keyv And Friends Compromised In Active Shai-Hulud Supply Chain Attack</strong><br />
"On August 4, 2026, attackers compromised the GitHub account of the maintainer behind keyv, a key-value storage library with roughly 127 million weekly npm downloads, and used that access to inject a credential-stealing worm across the entire package family. The same maintainer owns cacheable (29M downloads/month), flat-cache (565M downloads/month), file-entry-cache (557M downloads/month), and several other widely-used caching utilities, all of which were swept up in the same attack. The compromise was carried out by pushing malicious files directly to the main branch and then immediately cutting a new release, meaning the poisoned versions were published to npm with valid provenance signed by GitHub Actions."<br />
<a href="https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack</a><br />
<a href="https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack</a><br />
<a href="https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/</a><br />
<a href="https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html</a><br />
<a href="https://www.bankinfosecurity.com/worm-targets-more-than-2000-npm-package-versions-a-32412" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/worm-targets-more-than-2000-npm-package-versions-a-32412</a><br />
<a href="https://cyberscoop.com/supply-chain-attack-malware-mini-shai-hulud-teampcp/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/supply-chain-attack-malware-mini-shai-hulud-teampcp/</a><br />
<a href="https://hackread.com/shai-hulud-npm-worm-poisoning-1280-packages/" target="_blank" rel="noopener noreferrer nofollow ugc">https://hackread.com/shai-hulud-npm-worm-poisoning-1280-packages/</a></li>
<li><strong>“Keep Going, Bro. You’ve Got This!” A Data-Driven Look At How Adversaries Are Weaponizing AI</strong><br />
"Artificial intelligence (AI) and associated language models are now ubiquitous and heavily used in both personal and professional contexts to streamline tasks and expand capabilities. With AI being used everywhere and by almost everyone, one of the biggest questions is how malicious actors are taking advantage. Fortunately, actors make mistakes and chatbots leave artifacts. Leveraging cloud-based AI models leaves behind a variety of artifacts, most notably a prompt log. These logs can take on a variety of shapes and sizes, but they are left on endpoints that are running various applications, such as Claude Code, CodeX, Cursor, or Gemini."<br />
<a href="https://blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/</a><br />
<a href="https://www.infosecurity-magazine.com/news/talos-attackers-split-tasks-evade/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/talos-attackers-split-tasks-evade/</a><br />
<a href="https://www.theregister.com/security/2026/08/04/bypassing-ai-guardrails-is-so-easy-a-script-kiddie-can-do-it/5282973" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/08/04/bypassing-ai-guardrails-is-so-easy-a-script-kiddie-can-do-it/5282973</a></li>
<li><strong>Incident Report: Unsanctioned Agent Behaviour During Cyber Testing</strong><br />
"AISI’s role is to evaluate and understand the capabilities of frontier AI models, surfacing potential risks before they reach the public. To assess what these models can do, including whether they could be misused for cyberattacks, we test them under deliberately permissive conditions: with access to the open internet, and with some safety filters disabled. On 28th July 2026, AISI's Security Team detected unusual data transfers leaving our research systems during a routine cyber evaluation. On investigation, we found that some of the agents being tested had engaged in sustained, potentially harmful activity directed at real people and organisations. We declared a security incident and, within roughly one hour of discovery, had contained it and begun a full investigation."<br />
<a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing</a><br />
<a href="https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf" target="_blank" rel="noopener noreferrer nofollow ugc">https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security Incident INC-2026-07-28-01.pdf</a><br />
<a href="https://cyberscoop.com/aisi-openai-report-unsanctioned-ai-model-hacks/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/aisi-openai-report-unsanctioned-ai-model-hacks/</a></li>
<li><strong>Analyzing SMOKE#SCREEN: ScreenConnect RMM Abuse, Cloudflare Tunnels, And Trusted Software Lures</strong><br />
"Securonix Threat Research has been tracking an active, multi-wave campaign we are calling SMOKE#SCREEN, in which threat actors use a rotating collection of social engineering lures themed around Zoom software updates, business document reviews, and system maintenance utilities to deliver silent ScreenConnect Remote Monitoring and Management (RMM) agent installations. The campaign relies on a toolkit of VBScript droppers, batch file loaders, compiled .NET executables and a HTML phishing page, all ultimately pointing to a live WsgiDAV-based staging server at 207.174.0.143:8080. Victims who execute any of the initial access files end up with a fully functional ScreenConnect agent silently installed and beaconing to one of three attacker-controlled relay servers, providing the threat actor with persistent, legitimate-looking remote access to compromised hosts."<br />
<a href="https://www.securonix.com/blog/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securonix.com/blog/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels/</a><br />
<a href="https://www.darkreading.com/cyberattacks-data-breaches/latest-rmm-fueled-phishing-attack-exposes-threat-actor-playbook" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cyberattacks-data-breaches/latest-rmm-fueled-phishing-attack-exposes-threat-actor-playbook</a><br />
<a href="https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html</a></li>
<li><strong>QuickFox Supply Chain Attack Used To Deploy FDMTP Implant</strong><br />
"FortiGuard Labs is tracking a campaign associated with a long-standing supply chain attack on the QuickFox application. QuickFox is a VPN proxy and game accelerator typically employed by Chinese users to speed up access to Chinese-based resources, often to improve video game user experience. Active since at least August 2025, the supply chain attack involves a trojanized version of the QuickFox application. The attack is delivered via a modified Electron renderer HTML file used to download and execute a JavaScript-based loader. Upon execution, the JavaScript loader fingerprints the victim endpoint to determine if it’s a valid target before downloading and installing an FDMTP implant. Analysis of infrastructure related to this campaign indicates active development, and infrastructure continues to be active at the time of publishing."<br />
<a href="https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant</a></li>
<li><strong>Consumer Protection Tuesday: A Fake IRS "Digital Asset Compliance Portal" Letter Is Targeting Crypto Holders</strong><br />
"Scammers are mailing physical letters in subtle, unmarked envelopes that look like they come from the IRS, telling crypto holders they must "enroll" in a so-called Digital Asset Compliance Portal (DACP) before a deadline. The letter includes a QR code that leads to a convincing fake IRS website."<br />
<a href="https://www.coinbase.com/en-gb/blog/consumer-protection-tuesday-fake-irs-scam" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.coinbase.com/en-gb/blog/consumer-protection-tuesday-fake-irs-scam</a><br />
<a href="https://www.helpnetsecurity.com/2026/08/04/fake-irs-crypto-letters-compliance-portal-scam/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/04/fake-irs-crypto-letters-compliance-portal-scam/</a></li>
<li><strong>WhatsApp Account Takeover Scam Asks You To “vote For My Friend”</strong><br />
"A scam is spreading through WhatsApp with the goal of taking over victims’ accounts entirely. It starts with a message that feels harmless and familiar. Someone—often a contact whose account has already been compromised—asks you to support a friend or relative of theirs by voting in an online contest. The theme varies: a ballet performance, a dog competition, a school event. The wording is casual, sometimes urgent, and designed to get a quick click."<br />
<a href="https://www.malwarebytes.com/blog/scams/2026/08/whatsapp-account-takeover-scam-asks-you-to-vote-for-my-friend" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/scams/2026/08/whatsapp-account-takeover-scam-asks-you-to-vote-for-my-friend</a><br />
<a href="https://www.infosecurity-magazine.com/news/whatsapp-voting-scam-linked/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/whatsapp-voting-scam-linked/</a></li>
<li><strong>How Legitimate Cloud Platforms Enable Phishers To Bypass MFA</strong><br />
"Threat actors are increasingly exploiting legitimate cloud services to evade detection and streamline the deployment of their scam infrastructure. Cloud hosting services and decentralized networks have become primary platforms for hosting phishing pages and sites. Throughout 2025 and 2026, we have observed phishing operators steadily migrate toward platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS. This post analyzes the mechanics of a real-life adversary-in-the-middle (AitM) attack in a cloud environment and presents detailed statistics on the platforms and domains phishers abuse most frequently."<br />
<a href="https://securelist.com/cloud-platforms-in-phishing/120832/" target="_blank" rel="noopener noreferrer nofollow ugc">https://securelist.com/cloud-platforms-in-phishing/120832/</a></li>
<li><strong>AI-Enabled Email Accounts Could Become The Ultimate Insider Threat</strong><br />
"In June, Barracuda’s Red Team detailed a multilayered controlled attack that showed how attackers gain access to a victim’s account. Once an attacker has access, the next steps depend on their objectives. In most cases, however, attackers first seek to establish persistence, escalate privileges and extend their access within the environment. Attackers increasingly try to achieve this by abusing legitimate tools already present in the environment, a technique known as “living off the land.” This commonly takes the form of PowerShell scripts or the misuse of remote access software. Our controlled attack focused instead on the growing threat of attackers leveraging the victim’s AI assistant to perform reconnaissance, identify targets and accelerate attack progression."<br />
<a href="https://blog.barracuda.com/2026/08/04/ai-enabled-email-accounts-insider-threat" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.barracuda.com/2026/08/04/ai-enabled-email-accounts-insider-threat</a><br />
<a href="https://www.securityweek.com/weaponized-email-ai-assistants-could-help-attackers-hijack-accounts/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/weaponized-email-ai-assistants-could-help-attackers-hijack-accounts/</a></li>
<li><strong>Almost Half Of Malware Samples Communicate Direct To IP</strong><br />
"Malware samples often bypass DNS entirely, communicating directly to IP addresses instead. Our analysis of 4 million dynamic analysis reports indicates that almost half (45.32%) of malware samples with any command-and-control (C2) activity made at least one direct-to-IP (D2IP) address connection. Measured as a fraction of all C2 connection attempts, D2IP traffic accounts for 23.17% of the total. A wide variety of threats — including ransomware droppers, peer-to-peer (P2P) botnets and supply chain risks — communicate directly with hard-coded IP addresses, bypassing DNS entirely and evading DNS-based defenses altogether."<br />
<a href="https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/" target="_blank" rel="noopener noreferrer nofollow ugc">https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/</a></li>
<li><strong>Developers In The Crosshairs: Fake AI Tools Deliver Infostealer</strong><br />
"In April 2026, Netskope Threat Labs exposed a Malware-as-a-Service (MaaS) NodeJS infostealer delivered through the ClickFix social engineering technique. As we tracked this infostealer, we uncovered ongoing campaigns in which attackers shifted delivery vectors, cloning and impersonating known GitHub repositories and redirecting download links at their payloads. These GitHub repositories are part of the broader campaign previously tracked as TroyDen’s lure factory.The campaign’s target victims were mainly in North America, Asia, and Southern Europe, across different segments, with the financial services, banking, and technology sectors leading."<br />
<a href="https://www.netskope.com/blog/developers-in-the-crosshairs-fake-ai-tools-deliver-infostealer" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.netskope.com/blog/developers-in-the-crosshairs-fake-ai-tools-deliver-infostealer</a><br />
<a href="https://www.helpnetsecurity.com/2026/08/04/developers-github-fake-ai-tools-infostealer/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/04/developers-github-fake-ai-tools-infostealer/</a></li>
<li><strong>Npm Stealer Reads Its C2 From An Ethereum Contract</strong><br />
"Netskope Threat Labs identified and analyzed 28 malicious npm package versions published across four unrelated enterprise namespaces (@servicetitan, @or-sdk, @onereach, and @umacloud) on 2026-08-04. The packages arrived in two rapid bursts: the @or-sdk and @onereach packages at 10:39 UTC, the @servicetitan packages two minutes later at 10:41 UTC, and @umacloud/knowledge nearly three hours after that at 13:18 UTC. All 28 carry an identical or functionally equivalent payload, confirmed by hash match for @umacloud/knowledge@1.0.74, the one tarball still live when we retrieved it. The operator behind the campaign calls it Shai-Hulud, consistent naming with similar attacks we have tracked over the past year [1], [2], [3]. At install time, the packages fetch a signed Bun runtime release from GitHub, execute an obfuscated JavaScript stealer under it, and delete the runtime."<br />
<a href="https://www.netskope.com/blog/npm-stealer-reads-its-c2-from-an-ethereum-contract" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.netskope.com/blog/npm-stealer-reads-its-c2-from-an-ethereum-contract</a></li>
<li><strong>Malware Signing: When Trust Becomes An Attack Surface</strong><br />
"Digital code-signing certificates play a critical role in the software ecosystem. When a software publisher signs an application, the certificate serves two important purposes: It identifies the publisher and verifies that the software has not been modified since it was signed. Operating systems, browsers, endpoint protection tools, and users all rely on these signals to determine whether software should be trusted. This trust model benefits everyone. Developers can prove that their software is authentic, users can install applications with greater confidence and security tools can use certificate information as one factor when evaluating risk. In a world where millions of software packages are downloaded every day, digital signatures help establish a foundation of trust. Unfortunately, attackers have learned how to exploit that foundation."<br />
<a href="https://blog.barracuda.com/2026/08/04/malware-signing--when-trust-becomes-an-attack-surface" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.barracuda.com/2026/08/04/malware-signing--when-trust-becomes-an-attack-surface</a></li>
</ul>
<p dir="auto"><strong>Breaches/Hacks/Leaks</strong></p>
<ul>
<li><strong>150,000 Impacted By Madera Community Hospital Data Breach</strong><br />
"Madera Community Hospital in California is notifying just over 150,000 individuals that their personal, financial, and medical information was compromised in a data breach. A not-for-profit community healthcare provider serving Madera County and surrounding areas, Madera Community Hospital provides emergency services, surgical services, acute care, diagnostic imaging, and specialized medical programs. The incident, the hospital says in an incident notice, occurred in May 2025, when hackers accessed its network for two days and likely exfiltrated certain files."<br />
<a href="https://www.securityweek.com/150000-impacted-by-madera-community-hospital-data-breach/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/150000-impacted-by-madera-community-hospital-data-breach/</a></li>
<li><strong>Swiss IT Agency Hacked, 200 Accounts Compromised, SharePoint Vulns Suspected</strong><br />
"Switzerland’s Federal Office for Information Technology and Communications (BIT) disclosed Tuesday that hackers had compromised approximately 200 accounts on its on-premises SharePoint servers. The agency made the announcement a week after security specialists first detected anomalies on the on-premises Microsoft servers. It did not confirm how the hackers got in but acknowledged several vulnerabilities affecting SharePoint had been identified in July’s Patch Tuesday release. “The cyberattack was carried out by previously unknown actors, presumably by exploiting these vulnerabilities in the SharePoint software,” the Swiss agency said."<br />
<a href="https://therecord.media/swiss-bit-foitt-hacked-possibly-sharepoint-vulnerabilities" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/swiss-bit-foitt-hacked-possibly-sharepoint-vulnerabilities</a><br />
<a href="https://securityaffairs.com/196625/hacking/sharepoint-flaws-used-to-hack-switzerlands-federal-it-agency.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/196625/hacking/sharepoint-flaws-used-to-hack-switzerlands-federal-it-agency.html</a></li>
</ul>
<p dir="auto"><strong>General News</strong></p>
<ul>
<li><strong>Third-Party Cyber Evaluations Involving OpenAI Models</strong><br />
"Independent testing plays an important role in helping us validate and further understand risks before deployment. Some cyber evaluations intentionally use custom configurations, including lowered safeguards to measure underlying capability—not how models ordinarily behave in publicly available deployments. During recent evaluations, two external testing partners identified incidents in which testing configurations and controls combined with the advancing capabilities of the recent models allowed for model activity to extend beyond their intended testing boundaries."<br />
<a href="https://openai.com/index/third-party-cyber-evaluations-involving-openai-models/" target="_blank" rel="noopener noreferrer nofollow ugc">https://openai.com/index/third-party-cyber-evaluations-involving-openai-models/</a><br />
<a href="https://www.bleepingcomputer.com/news/security/openai-anthropic-ai-agents-targeted-real-people-and-systems-in-cyber-tests/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/openai-anthropic-ai-agents-targeted-real-people-and-systems-in-cyber-tests/</a></li>
<li><strong>When Data Becomes Instructions: AI Agents Need a Chain Of Custody For Context</strong><br />
"A few weeks ago, an AI cyber evaluation produced an unexpectedly efficient strategy for solving a benchmark: the agents went looking for the answers. According to OpenAI’s preliminary disclosure, models being tested for advanced cyber capabilities found ways to obtain secret information that could help them complete a benchmark. They chained vulnerabilities, stolen credentials, internet access, and inferences about where benchmark material might be hosted. The route eventually reached Hugging Face infrastructure, where the activity was detected and contained."<br />
<a href="https://blog.checkpoint.com/ai-security/ai-agent-context-chain-of-custody/" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.checkpoint.com/ai-security/ai-agent-context-chain-of-custody/</a></li>
<li><strong>How Companies Could Share Cyber Risks Without Exposing Their Secrets</strong><br />
"Zero-knowledge proofs could let infrastructure operators answer key security questions without handing over the sensitive data behind their answers. Imagine a major software flaw is discovered in equipment used across pipelines, power plants and telecom networks. The government needs to know as fast as possible which companies are exposed. But answering that question may require firms to share software inventories, network diagrams and vulnerability scans, which could become attack roadmaps for attackers if compromised. A lesser-known cryptographic concept could help solve this problem. The method, known as zero-knowledge proofs, allows companies prove a vulnerability exists without disclosing how their systems work or other proprietary information."<br />
<a href="https://cyberscoop.com/zero-knowledge-proofs-cyber-risk-sharing-op-ed/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/zero-knowledge-proofs-cyber-risk-sharing-op-ed/</a></li>
<li><strong>Digital Executive Protection Is a Strategic Imperative For CEOs</strong><br />
"In this interview with Help Net Security, Brian Hill, Field CISO, Client Advisory for BlackCloak, explains how attackers reach companies through the personal lives of executives. He describes a case where a draft report sat in an executive’s personal email with no multifactor authentication, and traders acted on it before the news went public. He also covers a home network left open after an AV technician swapped cables, malware planted through hotel Wi-Fi, and why he thinks deepfake defense should verify the person, not the message. Companies lack the tools to close this gap."<br />
<a href="https://www.helpnetsecurity.com/2026/08/04/brian-hill-blackcloak-digital-executive-protection/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/04/brian-hill-blackcloak-digital-executive-protection/</a></li>
<li><strong>Why Trust Is The New Attack Surface: Darktrace’s Mid-Year Threat Update 2026</strong><br />
"Darktrace’s analysis of the first half of 2026 shows attackers increasingly exploiting trust rather than bypassing security controls. Identity compromise, supply-chain attacks, SaaS abuse, AI-enabled operations, and state-aligned activity demonstrate how trusted users, services, and infrastructure have become key attack paths. For defenders, context and behavioral analysis remain essential foundations of security."<br />
<a href="https://www.darktrace.com/blog/why-trust-is-the-new-attack-surface-darktraces-mid-year-threat-update-2026" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darktrace.com/blog/why-trust-is-the-new-attack-surface-darktraces-mid-year-threat-update-2026</a><br />
<a href="https://www.infosecurity-magazine.com/news/cloud-saas-targets-attackers/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/cloud-saas-targets-attackers/</a></li>
<li><strong>AI Accounts For Over Half Of Cybercrime In Africa, Says Interpol</strong><br />
"AI-driven cybercrime now accounts for 55% of all reported digital crime in Africa, Interpol has warned. The policing group made the claim in a new African Cyberthreat Assessment Report 2026, which draws on data provided by its 36 member countries on the continent. AI-powered scams, social engineering and credential harvesting have helped to drive cybercrime losses from $192m in 2024 to $484m last year, the report claimed."<br />
<a href="https://www.infosecurity-magazine.com/news/ai-accounts-over-half-cybercrime/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/ai-accounts-over-half-cybercrime/</a></li>
<li><strong>CISO Conversations: Russ Kirby – Passion Is The Antidote To Burnout</strong><br />
"Passion for the job is the secret of a successful career. Russ Kirby has been CISO at Ping Identity since the summer of 2023. Before then he was CISO at Creditsafe, and then CISO at ForgeRock. Prior to that he had been global head and director of enterprise services information security directorate at Hewlett Packard."<br />
<a href="https://www.securityweek.com/ciso-conversation-russ-kirby-passion-is-the-antidote-to-burnout/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/ciso-conversation-russ-kirby-passion-is-the-antidote-to-burnout/</a></li>
<li><strong>SQLite Critical CVEs Or LLM Slop?</strong><br />
"Over the past few days, a newly created GitHub repo (programmervuln/cveadvisory-) published a batch of SQLite vulnerability advisories (as part of other 50+ CVEs which we believe are also LLM slop except from one). NVD quickly flagged these as critical, and CISA's ADP agreed. But when JFrog security researchers dug in to verify, the claims fell apart:</li>
</ul>
<p dir="auto">The cited code didn't even exist in those versions or referenced unrelated logic.<br />
When testing the PoC payloads they didn’t work (not triggering any crash).<br />
None of these CVEs are listed on SQLite’s official advisory page (which is a gold standard for tracking actual vulnerabilities).<br />
All advisories in this repo seem AI generated when testing them with Gptzero<br />
"<br />
<a href="https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/" target="_blank" rel="noopener noreferrer nofollow ugc">https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/</a><br />
<a href="https://www.theregister.com/security/2026/08/03/ai-slop-pollutes-the-cve-pipeline-with-fake-vulns/5282462" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/08/03/ai-slop-pollutes-the-cve-pipeline-with-fake-vulns/5282462</a></p>
<p dir="auto"><strong>อ้างอิง</strong><br />
Electronic Transactions Development Agency (ETDA) <img src="/assets/uploads/files/1785916022836-397c3606-e2f9-451d-94f3-7799fea61b5f-image.png" alt="397c3606-e2f9-451d-94f3-7799fea61b5f-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3156/cyber-threat-intelligence-05-august-2026</link><generator>RSS for Node</generator><lastBuildDate>Wed, 05 Aug 2026 14:04:50 GMT</lastBuildDate><atom:link href="https://webboard-nsoc.ncsa.or.th/topic/3156.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 05 Aug 2026 07:47:04 GMT</pubDate><ttl>60</ttl></channel></rss>