<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cyber Threat Intelligence 11 August 2026]]></title><description><![CDATA[<p dir="auto"><strong>New Tooling</strong></p>
<ul>
<li><strong>Chainloop: Open-Source Evidence Store And Policy Engine For The Software Supply Chain</strong><br />
"Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable storage, and references each one in a signed in-toto attestation. in-toto is a specification for recording who ran which step of a build, so the record can be checked afterward. Compliance and security teams get a control plane where all of it arrives, already signed, no matter which continuous integration provider produced it."<br />
<a href="https://www.helpnetsecurity.com/2026/08/10/chainloop-open-source-supply-chain-security/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/10/chainloop-open-source-supply-chain-security/</a><br />
<a href="https://github.com/chainloop-dev/chainloop" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/chainloop-dev/chainloop</a></li>
</ul>
<p dir="auto"><strong>Vulnerabilities</strong></p>
<ul>
<li><strong>Critical Flaws Discovered In Belgian eID Software Used By 2 Million People</strong><br />
"A security researcher has revealed severe, now-resolved security vulnerabilities in the Connective digital identity system, a browser extension used by over two million users in Belgium. Developed by Nitro Software Belgium, the software is used by eight of Belgium’s ten largest banks and over 60 government agencies to manage digital identity authentication and execute legally binding electronic signatures. James Arnott, security researcher and founder of cybersecurity firm Bay Area Labs, discovered that the software failed to verify which website was attempting to communicate with the user’s computer. Because these checks were missing, any website or embedded online ad could interact directly with the Connective application running on a victim’s machine without their knowledge or permission."<br />
<a href="https://www.securityweek.com/critical-flaws-discovered-in-belgian-eid-software-used-by-2-million-people/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/critical-flaws-discovered-in-belgian-eid-software-used-by-2-million-people/</a></li>
<li><strong>PSA: Supply Chain Compromise In BdThemes Ecosystem Via Poisoned API Response</strong><br />
"The Wordfence Threat Intelligence Team was notified on August 7th, 2026 of a supply chain compromise affecting BdThemes, a WordPress plugin vendor whose plugins are available in the official WordPress plugins directory. Currently, all the affected plugins are temporarily closed pending a full inspection and ongoing investigation by the WordPress Plugins team. Our investigation revealed an insidious supply chain compromise affecting several plugins. Unlike traditional software supply chain attacks, zero source code files were modified within the official <a href="http://WordPress.org" target="_blank" rel="noopener noreferrer nofollow ugc">WordPress.org</a> repository. Instead, threat actors poisoned a static remote JSON data stream fetched by an administrative promotional banner component."<br />
<a href="https://www.wordfence.com/blog/2026/08/psa-supply-chain-compromise-in-bdthemes-ecosystem-via-poisoned-api-response/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.wordfence.com/blog/2026/08/psa-supply-chain-compromise-in-bdthemes-ecosystem-via-poisoned-api-response/</a><br />
<a href="https://www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/</a><br />
<a href="https://www.infosecurity-magazine.com/news/bdthemes-wordpress-poisoned-api/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/bdthemes-wordpress-poisoned-api/</a></li>
<li><strong>Cisco Warns Of High-Severity ClamAV Vulnerabilities With Public PoC</strong><br />
"Cisco on Friday warned that its Secure Endpoint Connector products on Windows, macOS, and Linux are affected by seven ClamAV vulnerabilities that could lead to denial-of-service (DoS) conditions, including two with public proof-of-concept (PoC) code. ClamAV (Clam AntiVirus) is an open source, cross-platform malware detection engine that provides a multi-threaded virtual scanner, email filtering, and automatic database updates. The security defects, tracked as CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, were discovered in ClamAV’s parsers for ZIP, GPT, PESpin, PDF, Mach-O, and XAR file formats."<br />
<a href="https://www.securityweek.com/cisco-warns-of-high-severity-clamav-vulnerabilities-with-public-poc/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/cisco-warns-of-high-severity-clamav-vulnerabilities-with-public-poc/</a><br />
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26" target="_blank" rel="noopener noreferrer nofollow ugc">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26</a></li>
<li><strong>Cyber Vulnerability Sweep Picks Up Royal Navy Drones Sending Data To China</strong><br />
"Cameras aboard Royal Navy drone boats were found phoning home to an IP address in China during a routine cyber vulnerability assessment. The UK Ministry of Defence confirmed the discovery, describing it as "an issue affecting a Kraken Unmanned Surface Vessel sub-system used by the Royal Navy." The Register understands that the data consisted of a "heartbeat" signalling that the camera was online and functioning normally. Even so, an unexpected transmission from military equipment to an IP address in China will rattle nerves. We contacted unmanned surface vessel supplier Kraken for more information, but have yet to receive a reply."<br />
<a href="https://www.theregister.com/edge-and-iot/2026/08/10/cyber-vulnerability-sweep-picks-up-royal-navy-drones-sending-data-to-china/5285430" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/edge-and-iot/2026/08/10/cyber-vulnerability-sweep-picks-up-royal-navy-drones-sending-data-to-china/5285430</a><br />
<a href="https://www.telegraph.co.uk/news/2026/08/09/spy-cameras-on-navy-drones-secretly-sent-data-to-china/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.telegraph.co.uk/news/2026/08/09/spy-cameras-on-navy-drones-secretly-sent-data-to-china/</a></li>
</ul>
<p dir="auto"><strong>Malware</strong></p>
<ul>
<li><strong>Solidity Pro's WhiteCobra Chassis: Cloudflare C2 To Telegram Infostealer</strong><br />
"A Solidity extension called “Solidity Pro” sounds like the kind of tooling every crypto developer installs without thinking. That is exactly why it keeps appearing in malware campaigns. Yeeth Security recently tracked two publishers, helper-beeps and web3devtoolsx, shipping versions of a solidity-pro extension that evolved from a delayed Cloudflare-Worker dropper into a full browser-wallet and credential infostealer. The progression mirrors what public reporting has attributed to the WhiteCobra group, whose leaked “Operation Solidity Pro” playbook described a five-phase campaign targeting VS Code: and Open VSX users."<br />
<a href="https://yeethsecurity.com/blog/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-Telegram" target="_blank" rel="noopener noreferrer nofollow ugc">https://yeethsecurity.com/blog/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-Telegram</a><br />
<a href="https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html</a></li>
<li><strong>New StormEncryptor Ransomware Used By Former Medusa Affiliate</strong><br />
"A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. Microsoft Threat Intelligence is tracking the actor as Storm-1175 and says the recent attacks were likely preceded by exploitation of an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring and management (RMM) tool. Storm-1175 is believed to be a China-based threat actor. It was previously linked to Medusa ransomware, targeting systems via zero-day and n-day flaws in various products, including GoAnywhere MFT, SmarterTools SmarterMail, Microsoft Exchange, Invanti Connect Secure, and JetBrains TeamCity."<br />
<a href="https://www.bleepingcomputer.com/news/security/new-stormencryptor-ransomware-used-by-former-medusa-affiliate/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/new-stormencryptor-ransomware-used-by-former-medusa-affiliate/</a><br />
<a href="https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html</a><br />
<a href="https://therecord.media/china-hackers-ransomware-microsoft" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/china-hackers-ransomware-microsoft</a><br />
<a href="https://www.bankinfosecurity.com/china-linked-hackers-exploit-n-able-flaw-in-ransomware-attacks-a-32506" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/china-linked-hackers-exploit-n-able-flaw-in-ransomware-attacks-a-32506</a></li>
<li><strong>CISA: SonicWall SMA1000 Flaws Now Exploited By Ransomware Gangs</strong><br />
"CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. ​SMA1000 is an enterprise-grade secure remote access gateway used by large corporations, government agencies, and Managed Service Providers (MSSPs) to provide VPN access to internal applications and corporate networks. SonicWall released patches for the two security flaws (tracked as CVE-2026-15409 and CVE-2026-15410) in mid July, when it also warned that threat actors had been exploiting them in zero-day attacks."<br />
<a href="https://www.bleepingcomputer.com/news/security/cisa-sonicwall-sma1000-flaws-now-exploited-by-ransomware-gangs/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/cisa-sonicwall-sma1000-flaws-now-exploited-by-ransomware-gangs/</a></li>
<li><strong>#StopRansomware: Gunra Ransomware</strong><br />
"Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. This advisory provides technical details of the activity, as well as tailored detection and mitigation guidance to protect at-risk organizations from Gunra."<br />
<a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a</a><br />
<a href="https://therecord.media/ransomware-south-korea-fbi-gunra" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/ransomware-south-korea-fbi-gunra</a><br />
<a href="https://cyberscoop.com/us-south-korea-gunra-ransomware-warning/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/us-south-korea-gunra-ransomware-warning/</a></li>
<li><strong>GhostJacking Attacks: Half Of The Fortune 500 Run These Tools. Getting Blocked By The Firewall Was The Way To Take Over Their AI Agents</strong><br />
"Half the Fortune 500 run the tools that let us in. It will be presented at DEFCON, the largest hacker conference, where we’ll show how a request their own firewall blocked was the way in. “Ghostjacking” attack vectors introduce the modern agentic kill chain, agent takeover, sandbox escape, and backdoors planted inside the AI agents you already run, from a Claude Agent sandbox escape to hijacking live agents through the very platforms they trust most – Cloudflare, Sentry, Datadog."<br />
<a href="https://tenetsecurity.ai/blog/ghostjacking-attacks-agentic-kill-chain/" target="_blank" rel="noopener noreferrer nofollow ugc">https://tenetsecurity.ai/blog/ghostjacking-attacks-agentic-kill-chain/</a><br />
<a href="https://www.darkreading.com/cyber-risk/ghostjacking-identity-governance-gaps-ai-agents" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cyber-risk/ghostjacking-identity-governance-gaps-ai-agents</a><br />
<a href="https://www.infosecurity-magazine.com/news/ghostjacking-ai-gents-access/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/ghostjacking-ai-gents-access/</a><br />
<a href="https://www.securityweek.com/ghostjacking-attack-uses-poisoned-logs-to-turn-ai-agents-bad/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/ghostjacking-attack-uses-poisoned-logs-to-turn-ai-agents-bad/</a></li>
<li><strong>Coruna, DarkSword iOS Exploits Proliferate Globally</strong><br />
"The advanced iPhone exploit chains Coruna and DarkSword continue to escape nation-state and mercenary containment to enter the hands of more conventional cybercriminals. While nation-state-grade malware will, from time to time, make its way from government use to cybercriminal adoption, it's far more unusual to see whole complex exploit chains — especially those targeting iOS — adopted broadly. Yet that phenomenon, first observed last spring, appears to be shifting into overdrive. iVerify has tracked approximately 17,000 domains hosting second-generation iterations of Coruna and DarkSword so far, and infections have continued months after public disclosure earlier this year."<br />
<a href="https://www.darkreading.com/vulnerabilities-threats/coruna-darksword-ios-exploits-proliferate-globally" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/vulnerabilities-threats/coruna-darksword-ios-exploits-proliferate-globally</a></li>
<li><strong>New Turnkey Kit Makes It Easy For Anyone To Become a Scammer</strong><br />
"In 2026, online scams have unfortunately become part of the new normal. They can appear almost anywhere, from social media and messaging apps to search results, websites, and online communities, and they can target anyone. Sometimes, all it takes is a moment of curiosity and a convincing offer. Among the most devastating scams are so-called “get-rich-quick” schemes. These scams promise something that’s difficult for people to resist: the chance to make a lot of money, quickly and with little or no effort. It may come in the form of an investment opportunity, a new cryptocurrency project, or an exclusive chance to get in early before everyone else."<br />
<a href="https://www.malwarebytes.com/blog/scams/2026/08/new-turnkey-kit-makes-it-easy-for-anyone-to-become-a-scammer" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/scams/2026/08/new-turnkey-kit-makes-it-easy-for-anyone-to-become-a-scammer</a></li>
<li><strong>Abyssos: Technical Analysis Of a New Modular RAT</strong><br />
"In late June 2026, Zscaler ThreatLabz identified a new malware family that we track as Abyssos. Abyssos is a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC. Abyssos is in active development with multiple version numbers and different obfuscation passes that are designed to improve evasion from security products. In this blog post, ThreatLabz provides a technical analysis of Abyssos, including its core features, configuration, obfuscation, network communication protocol, and capabilities."<br />
<a href="https://www.zscaler.com/blogs/security-research/abyssos-technical-analysis-new-modular-rat" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.zscaler.com/blogs/security-research/abyssos-technical-analysis-new-modular-rat</a></li>
<li><strong>Kimsuky Integrates AI Into Attack Operations, From AI-Generated Decoy Documents To a Local LLM</strong><br />
"Genians Security Center has been continuously tracking GitHub- and GitLab-based attack activity assessed to be associated with Kimsuky, a cyber threat group known to operate under North Korea's Reconnaissance General Bureau. This activity is not a newly emerged standalone campaign, but part of a continuation of Kimsuky's attack operations observed over several years. In particular, it shares key characteristics with the "FlowerPower" campaign disclosed in 2023, including the continued use of a PowerShell-based execution framework and the active abuse of Git-based repositories. It also shows links to the attack tactics identified in the 2024 report, "Analysis of a Hacking Campaign Disguised as a New Year Opinion Column.""<br />
<a href="https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm</a><br />
<a href="https://thehackernews.com/2026/08/kimsuky-builds-offline-ai-stack-that.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/kimsuky-builds-offline-ai-stack-that.html</a><br />
<a href="https://www.theregister.com/security/2026/08/10/north-korean-spies-are-running-local-llms-to-cause-ai-mischief/5285632" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/08/10/north-korean-spies-are-running-local-llms-to-cause-ai-mischief/5285632</a></li>
<li><strong>Russian Military Hackers Pose As Recruiters To Target Ukrainian IT Workers</strong><br />
"Hackers linked to Russia’s military intelligence unit are posing as recruiters to trick Ukrainian IT workers into installing malicious software, researchers have found. Ukraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agency. The operation mostly targets system administrators and other IT professionals. According to CERT-UA, the hackers search legitimate Ukrainian job sites for potential victims, review their resumes and then contact them while posing as recruiters for an IT company."<br />
<a href="https://therecord.media/russian-military-hackers-pose-as-recruiters-ukraine-it-workers" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/russian-military-hackers-pose-as-recruiters-ukraine-it-workers</a></li>
<li><strong>Gym Rat Asks AI Agent To Book Him a Class, It Hacks a Waitlist API To Bump Him Up The List</strong><br />
"An Australian man who asked his AI agent to book him a slot in a class at his local gym got more than he bargained for as the bot hacked into a waitlist and started messing with other members' reservations. Australian broadcaster ABC identified the gym-goer only as “Andrew.” The report says Andrew was using the OpenClaw agent with Anthropic’s Claude AI service. Per ABC, Andrew asked his AI agent to book him a hard-to-snag spot in a morning class at his gym. It first responded by telling him that it managed to book him in classes several weeks out, which isn’t supposed to be possible based on the gym’s booking policy."<br />
<a href="https://www.theregister.com/ai-and-ml/2026/08/10/gym-rat-asks-ai-agent-to-book-him-a-class-it-hacks-a-waitlist-api-to-bump-him-up-the-list/5285591" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/ai-and-ml/2026/08/10/gym-rat-asks-ai-agent-to-book-him-a-class-it-hacks-a-waitlist-api-to-bump-him-up-the-list/5285591</a><br />
<a href="https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986</a><br />
<a href="https://securityaffairs.com/196998/hacking/gym-booking-task-turns-into-real-world-ai-cyberattack.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/196998/hacking/gym-booking-task-turns-into-real-world-ai-cyberattack.html</a></li>
<li><strong>The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations And Communications</strong><br />
"Aeternum is a recently discovered C++ botnet loader that shifts its command-and-control (C2) infrastructure entirely to the public Polygon blockchain. Instead of relying on centralized servers or domains, threat actors operate Aeternum by writing encrypted and plaintext instructions directly using smart contracts. A smart contract is a self-executing program stored on a blockchain that automatically runs when specific conditions are met. Infected devices continuously query public remote procedure call (RPC) endpoints to retrieve and execute these on-chain commands."<br />
<a href="https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/" target="_blank" rel="noopener noreferrer nofollow ugc">https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/</a></li>
<li><strong>Behind The Panels: Validating ShinyHunters Cluster A Infrastructure Through Network Telemetry</strong><br />
"Phishing panels are not just credential collection tools. They are infrastructure ecosystems. Behind every convincing login page is a set of domains, hosting providers, certificates, exposed services, operator tooling, and recurring deployment patterns. Those signals matter. They give defenders a way to move beyond a single phishing domain and start understanding how the activity is built, hosted, rotated, and reused. Push Security recently published an inside look at phishing panels used in campaigns linked to ShinyHunters and BlackFile. Their team gained direct access to active operator panels, observed real victim targeting, analyzed multiple variants of the tooling, and identified four primary infrastructure clusters."<br />
<a href="https://www.team-cymru.com/post/validating-shinyhunters-cyber-threat-actors-infrastructure" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.team-cymru.com/post/validating-shinyhunters-cyber-threat-actors-infrastructure</a></li>
<li><strong>Living Off The Coding Agent: Two Tales Of Tunnels And LaunchAgents</strong><br />
"Coding agents such as Claude Code and Cursor are vendor-signed, used all day on developer laptops, and routinely open shells, call APIs, edit files, and install helpers. That makes GenAI-adjacent alerts challenging to investigate. The parent looks trusted, while the children can still look a lot like classic high-severity activity. This article walks through one of those windows. On a macOS endpoint, Elastic Security endpoint telemetry showed shells under Claude Code that scripted a login to an ephemeral tunnel hostname, pulled application metrics, stood up a Cloudflare quick tunnel, and installed LaunchAgent persistence. Immediate children were often shells (zsh) and helpers under that ancestry, not Claude executing every binary itself."<br />
<a href="https://www.elastic.co/security-labs/coding-agent-launchagent-tunnel-detection" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.elastic.co/security-labs/coding-agent-launchagent-tunnel-detection</a></li>
<li><strong>Inside Astaroth's New Spambot Component</strong><br />
"Established Latin American (LATAM) threat actors are continuously adapting their malware capabilities and attack methodologies to circumvent defensive measures and maintain effectiveness against target environments. Exemplifying these evolving operations, in Q4 2025, operators of the Astaroth (aka Guildma) botnet introduced a previously unidentified capability: a WhatsApp Web spambot component designed to turn victims into unwitting distributors of the malware by automatically messaging every contact in each victim’s WhatsApp contact list. This blog provides a technical deep dive into the Astaroth spambot, examines its overlaps with other recently observed spambots, and explores what this capability expansion signals about the evolving LATAM eCrime ecosystem."<br />
<a href="https://www.crowdstrike.com/en-us/blog/inside-astaroths-new-spambot-component/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.crowdstrike.com/en-us/blog/inside-astaroths-new-spambot-component/</a></li>
<li><strong>Access For Sale: Inside a Russian-Speaking Access Broker's Dual Operation</strong><br />
"An exposed server owned by a Russia-nexus threat actor revealed months of activity from a high-volume initial access broker. The operator exploited internet-facing appliances across a dozen-plus countries, harvesting credentials and achieving full Active Directory compromise across education, healthcare, finance, telecommunications, and government victims. In multiple confirmed cases, ransomware groups claimed the same organizations within weeks of the operator's access, indicating the operator supplies access upstream of extortion rather than conducting it directly. Late in the timeline, the operator deployed Sliver C2 against Ukrainian defence and aerospace targets, stealing source repositories and harvesting imagery from thousands of exposed IP cameras and RDP sessions. This tradecraft closely matches the AIVD/MIVD advisory on Russian state-linked camera surveillance used to locate Ukrainian military assets. The US, Europe, and Korea were seen within the artefacts as secondary targets."<br />
<a href="https://www.cloudsek.com/blog/access-for-sale-inside-a-russian-speaking-access-brokers-dual-operation" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cloudsek.com/blog/access-for-sale-inside-a-russian-speaking-access-brokers-dual-operation</a></li>
</ul>
<p dir="auto"><strong>Breaches/Hacks/Leaks</strong></p>
<ul>
<li><strong>Hackers Breached a Small Polish Energy Plant Via Private APN Last Year</strong><br />
"Hackers used a dedicated mobile gateway to compromise a second facility during the destructive cyberattacks that hit Poland's energy sector last year. The second target was a small combined heat-and-power (CHP) plant that supplies heat to around 50,000 residents, resulting in the steam turbine and the water treatment system being shut down. The Polish Computer Emergency Response Team (CERT) disclosed this second incident in a follow-up report over the weekend, saying that the attacker used a private Access Point Name (APN) to access the operational technology network."<br />
<a href="https://www.bleepingcomputer.com/news/security/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year/</a><br />
<a href="https://therecord.media/poland-uncovers-critical-infrastructure-attack-hidden" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/poland-uncovers-critical-infrastructure-attack-hidden</a><br />
<a href="https://www.securityweek.com/novel-private-apn-pivot-let-hackers-sabotage-second-polish-energy-facility/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/novel-private-apn-pivot-let-hackers-sabotage-second-polish-energy-facility/</a><br />
<a href="https://securityaffairs.com/196955/security/hackers-cross-from-it-to-ot-through-a-private-apn-in-poland.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/196955/security/hackers-cross-from-it-to-ot-through-a-private-apn-in-poland.html</a></li>
<li><strong>LexisNexis Shuts Down Services After Suspicious Activity On Servers</strong><br />
"LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. The company said it is investigating the incident with assistance from a cybersecurity forensic firm and is rebuilding affected systems in a new environment before bringing the services back online. “Earlier this week, we identified unusual activity on servers that are hosted and managed by a third-party vendor,” reads the notification sent to customers last week."<br />
<a href="https://www.bleepingcomputer.com/news/security/lexisnexis-shuts-down-services-after-suspicious-activity-on-servers/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/lexisnexis-shuts-down-services-after-suspicious-activity-on-servers/</a></li>
<li><strong>Valve Notifies Steam Hardware Customers Of a Data Breach</strong><br />
"Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. CEVA Logistics (a fully-owned subsidiary of the CMA CGM Group, the world's third-largest shipping company) operates 1,000 warehouses, handled 15 million shipments last year, and reported $18.3 billion in revenues in 2025. According to many reports on social media, affected Valve customers began receiving data breach notification emails earlier today."<br />
<a href="https://www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/</a><br />
<a href="https://www.helpnetsecurity.com/2026/08/10/valve-data-breach-ceva-logistics-steam-hardware/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/10/valve-data-breach-ceva-logistics-steam-hardware/</a></li>
<li><strong>Exfiltration-Focused ExfilSquad Starts Leaking Stolen Data</strong><br />
"A cybercrime group focused solely on stealing data and holding it to ransom made a splash when its data-leak site appeared late last month, advertising stolen data pertaining to British police officers. The group, calling itself ExfilSquad, also said it stole records from the U.K. Department of Education. On July 26, within the span of a single day, it posted claims to have hacked 15 organizations, including the municipal government of Atlanta and Houston."<br />
<a href="https://www.bankinfosecurity.com/exfiltration-focused-exfilsquad-starts-leaking-stolen-data-a-32494" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/exfiltration-focused-exfilsquad-starts-leaking-stolen-data-a-32494</a></li>
<li><strong>Israeli Population Registry For Sale, But The Data Is Old</strong><br />
"A well-known data-leak vendor is offering what they describe as the current registry of Israel’s Population and Immigration Authority: 9,220,583 records covering the entire population, with national ID numbers, addresses, phone numbers and family links. Ransomnews analysed the 100,000-record sample the seller published. The data is real Israeli registry data. It is not current. Every date field in it stops in 2005."<br />
<a href="https://ransomnews.com/israel-population-registry-leak-2026/" target="_blank" rel="noopener noreferrer nofollow ugc">https://ransomnews.com/israel-population-registry-leak-2026/</a><br />
<a href="https://securityaffairs.com/196942/cyber-crime/9-2-million-israeli-records-sold-as-a-new-breach-are-20-years-old.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/196942/cyber-crime/9-2-million-israeli-records-sold-as-a-new-breach-are-20-years-old.html</a></li>
<li><strong>A Data Breach At Shipping Giant Ceva Logistics Is Rippling Across Banks, Retailers, Steam Gamers, And Beyond</strong><br />
"Ceva Logistics, one of the world’s largest shipping and logistics giants, has been hacked. Several companies that rely on Ceva for shipping their products to their customers say that their personal information was also stolen in the breach. The cyberattack on Ceva is affecting at least eight warehouses across Europe used for shipping goods across the continent, the company told TechCrunch. Industry news site FreightWaves reports that the hack began on July 29 and is causing shipping delays for many of the goods in affected warehouses. Ceva is a France-headquartered shipping and logistics giant that companies around the world rely on to deliver their goods from their assembly lines to customer homes. The company, which brought in $18.3 billion in revenue in 2025, has over a thousand warehouses across the world."<br />
<a href="https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/" target="_blank" rel="noopener noreferrer nofollow ugc">https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/</a></li>
</ul>
<p dir="auto"><strong>General News</strong></p>
<ul>
<li><strong>How We Took Malware Advisories Beyond Npm</strong><br />
"A compromised package can steal credentials the moment you install it, and until recently, GitHub could only flag those in npm. Not anymore. This is the story of how the supply chain engineering team behind Dependabot expanded malware advisories to eight ecosystems by building on OpenSSF’s shared malicious packages data. Here’s where things stand: earlier this year, Dependabot started flagging malware in your npm dependencies. Great news if you write JavaScript. Now we’re bringing that same functionality to PyPI."<br />
<a href="https://github.blog/security/supply-chain-security/how-we-took-malware-advisories-beyond-npm/" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.blog/security/supply-chain-security/how-we-took-malware-advisories-beyond-npm/</a><br />
<a href="https://www.helpnetsecurity.com/2026/08/10/github-dependabot-malware-alerts/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/10/github-dependabot-malware-alerts/</a></li>
<li><strong>Com Group Member Sentenced For Campaign Of Abuse Against 117 Victims Worldwide</strong><br />
"A man from Leeds who forced more than 100 victims into sexual activity and self-harm as part of a Com group, including them carving his online username into their bodies, has been sentenced to two years in prison after a National Crime Agency investigation. NCA officers started an investigation into Justin Swaddle, 20, from Leeds, in January 2024. Swaddle was first arrested by West Yorkshire Police in October 2023 for offences including possession, making and distribution of indecent images."<br />
<a href="https://www.nationalcrimeagency.gov.uk/news/com-group-member-sentenced-for-campaign-of-abuse-against-117-victims-worldwide" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.nationalcrimeagency.gov.uk/news/com-group-member-sentenced-for-campaign-of-abuse-against-117-victims-worldwide</a><br />
<a href="https://www.bleepingcomputer.com/news/security/member-of-the-com-sent-to-prison-for-blackmail-sextortion/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/member-of-the-com-sent-to-prison-for-blackmail-sextortion/</a><br />
<a href="https://therecord.media/british-com-member-abuse-jailed-two-years" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/british-com-member-abuse-jailed-two-years</a><br />
<a href="https://cyberscoop.com/uk-justin-swaddle-the-com-sentenced/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/uk-justin-swaddle-the-com-sentenced/</a></li>
<li><strong>The Patch Gap: Why Defenders Need To Think In Chains, Not Checklists</strong><br />
"On April 7, 2026, Anthropic announced Project Glasswing, which changed how every security team operates. Claude Mythos, an AI-frontier model that found thousands of high-severity vulnerabilities, including flaws in major operating systems and Web browsers, many of which survived for decades of human review and automated security tests. Of which, less than 1% was fully patched. This is a patch physics problem rather than a patch management problem. You cannot match machine-speed discovery with a remediation cycle that runs on human time."<br />
<a href="https://www.darkreading.com/cybersecurity-operations/patch-gap-defenders-chains-not-checklists" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cybersecurity-operations/patch-gap-defenders-chains-not-checklists</a></li>
<li><strong>Outdated Cybercrime Laws Put Security Researchers At Risk</strong><br />
"Security researchers hunting for vulnerabilities could face prison time under a 1990 United Kingdom law that doesn't distinguish between malicious hackers and those working in good faith. But change may finally be coming. Cybercrime is accelerating rapidly, requiring a holistic approach to curb threats. Security researchers who responsibly disclose vulnerabilities are one way to address burgeoning risks against governments, businesses, and individuals, but many countries have not updated their policies and laws to reflect that, Katharina Sommer, NCC Group's director of government affairs and analyst relations, tells Dark Reading."<br />
<a href="https://www.darkreading.com/application-security/outdated-cybercrime-laws-security-researchers-risk" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/application-security/outdated-cybercrime-laws-security-researchers-risk</a></li>
<li><strong>Sherlock Holmes Was The “OG” Social Engineer</strong><br />
"With a green deerstalker cap, a blue and green plaid shawl covering her shoulders and a pipe resting in her right hand right below her mouth, it was almost impossible to tell the difference between Sherlock Holmes and Elizabeth Rasnick. But that was the point— social engineering is all about deception. Holmes was the original social engineer, argued Resnick, assistant professor at the University of West Florida's Center for Cybersecurity and Artificial Intelligence (AI). During DEF CON 34, she drew parallels between current social engineering techniques and Holmes's own playbook as described in the detective tales. Her session highlighted how important it is for organizations to continually prioritize the human element when it comes to social engineering and security awareness training, despite how difficult that's proved historically."<br />
<a href="https://www.darkreading.com/cyber-risk/sherlock-holmes-was-the-og-social-engineer" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cyber-risk/sherlock-holmes-was-the-og-social-engineer</a></li>
<li><strong>IT Threat Evolution In Q2 2026. Mobile Statistics</strong><br />
"The mobile section of the quarterly cyberthreat report includes statistics on malware, adware, and potentially unwanted software for Android, as well as descriptions of the most notable threats for Android and iOS discovered during the reporting period. These statistics are based on detection alerts from Kaspersky products, collected from users who consented to provide statistical data to Kaspersky Security Network."<br />
<a href="https://securelist.com/malware-report-q2-2026-mobile-statistics/120948/" target="_blank" rel="noopener noreferrer nofollow ugc">https://securelist.com/malware-report-q2-2026-mobile-statistics/120948/</a><br />
<a href="https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/" target="_blank" rel="noopener noreferrer nofollow ugc">https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/</a></li>
<li><strong>Ransomware Now Shows Up In Nearly Half Of All Breaches: A Survival Playbook For Lean Security Teams</strong><br />
"Ransomware stopped being an isolated incident type in 2025. It became the dominant force behind the modern breach landscape, and the ransomware data breach statistics from Cyble’s own tracking make the shift impossible to ignore. For organizations facing this growing threat, having a ransomware incident response plan in place is becoming just as important as preventing an attack in the first place. Cyble’s Global Cybersecurity Report 2025 documented 5,967 ransomware attacks for the year, a 50% year-over-year jump. Against the 6,046 data breaches and leaks recorded in the same period, ransomware accounted for nearly half — 49.7% — of the combined ransomware-and-breach total tracked by Cyble Research and Intelligence Labs (CRIL). That’s the “nearly half” this blog’s title refers to, and it isn’t a projection. It’s what Cyble observed."<br />
<a href="https://cyble.com/blog/ransomware-incident-response-plan/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyble.com/blog/ransomware-incident-response-plan/</a></li>
</ul>
<p dir="auto"><strong>อ้างอิง</strong><br />
Electronic Transactions Development Agency (ETDA) <img src="/assets/uploads/files/1786436303910-7646a743-6cee-4fb1-b549-50cb107744b6-image.png" alt="7646a743-6cee-4fb1-b549-50cb107744b6-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3176/cyber-threat-intelligence-11-august-2026</link><generator>RSS for Node</generator><lastBuildDate>Tue, 11 Aug 2026 13:27:10 GMT</lastBuildDate><atom:link href="https://webboard-nsoc.ncsa.or.th/topic/3176.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 11 Aug 2026 08:18:25 GMT</pubDate><ttl>60</ttl></channel></rss>