<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cyber Threat Intelligence 12 August 2026]]></title><description><![CDATA[<p dir="auto"><strong>Healthcare Sector</strong></p>
<ul>
<li><strong>Mira Hormone Monitor, Mira Android App</strong><br />
"Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts."<br />
<a href="https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-01" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-01</a></li>
<li><strong>Pulsetto Vagus Nerve Stimulator</strong><br />
"Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings."<br />
<a href="https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-02" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-02</a></li>
</ul>
<p dir="auto"><strong>Industrial Sector</strong></p>
<ul>
<li><strong>Industrial Ransomware Analysis For Q2 2026</strong><br />
"In the second quarter (Q2) of 2026, analysis of publicly disclosed victim data and ransomware groups’ postings on Data Leak Sites (DLS) identified 1,140 ransomware incidents affecting industrial organizations worldwide, a 12% increase over the 1,020 incidents recorded in Q1. Ransomware remained the most persistent and disruptive cyber threat to industrial organizations in Q2 2026, sustaining the elevated pace established throughout 2025 and continuing to impact operational environments via the loss of enterprise IT systems, Enterprise Resource Planning (ERP) platforms, and virtualization infrastructure, versus direct manipulation of control systems."<br />
<a href="https://www.dragos.com/blog/dragos-industrial-ransomware-analysis-q2-2026" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.dragos.com/blog/dragos-industrial-ransomware-analysis-q2-2026</a><br />
<a href="https://www.helpnetsecurity.com/2026/08/11/industrial-ransomware-attacks-q2-2026/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/11/industrial-ransomware-attacks-q2-2026/</a></li>
</ul>
<p dir="auto"><strong>Telecom Sector</strong></p>
<ul>
<li><strong>An AI Tool Found 84 Flaws In 5G Network Software And 23 Of Them Still Have No Fix</strong><br />
"Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws nobody had reported before. Developers have confirmed 83 of them, and 81 now carry CVE numbers. The most serious one lets an attacker take over a subscriber’s data session, so the network delivers that subscriber’s traffic to<br />
<a href="https://www.helpnetsecurity.com/2026/08/11/5g-core-network-vulnerabilities-research/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/11/5g-core-network-vulnerabilities-research/</a><br />
<a href="https://arxiv.org/pdf/2607.10315" target="_blank" rel="noopener noreferrer nofollow ugc">https://arxiv.org/pdf/2607.10315</a></li>
<li><strong>Researchers Show How Malicious SIM Cards Can Hijack Smartphones, EV Chargers And Connected Devices</strong><br />
"Subscriber Identity Modules (SIMs), the secure element used to connect devices to a mobile network, can pose severe security risks when compromised. A malicious SIM could allow attackers to gather information about a device, interfere with its connectivity, and serve as an entry point for further cyberattacks. Presenting their findings at the 2026 USENIX WOOT Conference on Offensive Technologies, in Baltimore, University of Birmingham researchers reveal a new attack surface exposed to malicious and compromised SIMs."<br />
<a href="https://www.birmingham.ac.uk/news/2026/researchers-show-how-malicious-sim-cards-can-hijack-smartphones-ev-chargers-and-connected-devices" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.birmingham.ac.uk/news/2026/researchers-show-how-malicious-sim-cards-can-hijack-smartphones-ev-chargers-and-connected-devices</a><br />
<a href="https://www.usenix.org/system/files/woot26-lisowski.pdf" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.usenix.org/system/files/woot26-lisowski.pdf</a><br />
<a href="https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html</a><br />
<a href="https://www.helpnetsecurity.com/2026/08/11/malicious-sim-cards-hijack-phones-ev-chargers/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/11/malicious-sim-cards-hijack-phones-ev-chargers/</a></li>
</ul>
<p dir="auto"><strong>Vulnerabilities</strong></p>
<ul>
<li><strong>Adobe Urges Immediate Patching Of Critical ColdFusion, Campaign Classic Flaws</strong><br />
"Adobe on Tuesday rolled out patches for over 50 vulnerabilities across its products, including critical-severity bugs in ColdFusion, Campaign Classic, and Commerce. With a priority 1 rating, the ColdFusion update fixes 15 security defects, including three flagged as critical that could lead to arbitrary code execution and application denial-of-service (DoS). These include an OS command injection tracked as CVE-2026-48362 (CVSS score of 10/10), an eval injection tracked as CVE-2026-48273 (CVSS score of 9.9/10), and an incorrect authorization tracked as CVE-2026-71384 (CVSS score of 9.6/10)."<br />
<a href="https://www.securityweek.com/adobe-urges-immediate-patching-of-critical-coldfusion-campaign-classic-flaws/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/adobe-urges-immediate-patching-of-critical-coldfusion-campaign-classic-flaws/</a></li>
<li><strong>SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities</strong><br />
"Enterprise software maker SAP on Tuesday announced the release of 28 new security notes, two updates to previous notes, and a GitHub advisory. Four of the notes published on SAP’s August 2026 Security Patch Day resolve critical vulnerabilities, the most severe of which is CVE-2026-58231 (CVSS score of 10/10), an improper authorization issue in SAP Commerce Cloud (Data Hub Adapter). The bug could allow remote attackers to bypass authentication, likely leading to code execution and unauthorized access to internal components. Successful exploitation would impact the confidentiality, integrity, and availability of the application."<br />
<a href="https://www.securityweek.com/sap-patches-critical-code-injection-memory-corruption-vulnerabilities/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/sap-patches-critical-code-injection-memory-corruption-vulnerabilities/</a></li>
<li><strong>Cisco Warns Of ASA And FTD VPN Flaw Exploited To Crash Devices</strong><br />
"Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices. The flaw, tracked as CVE-2026-20349, has a severity score of 8.6 and impacts devices running Cisco Secure Firewall Adaptive Security Appliance (ASA) or Secure Firewall Threat Defense (FTD) software with certain remote access services enabled. In a security advisory published today, Cisco said the vulnerability is caused by insufficient error checking while processing HTTP requests."<br />
<a href="https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-and-ftd-vpn-flaw-exploited-to-crash-devices/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-and-ftd-vpn-flaw-exploited-to-crash-devices/</a><br />
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF" target="_blank" rel="noopener noreferrer nofollow ugc">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF</a></li>
<li><strong>Microsoft August 2026 Patch Tuesday Fixes 400 Flaws, 3 Zero-Days</strong><br />
"Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. Patch Tuesday addresses 42 "Critical" vulnerabilities, 37 of which are remote code execution and 5 are elevation of privilege."<br />
<a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days/</a><br />
<a href="https://blog.talosintelligence.com/microsoft-patch-tuesday-for-august-2026/" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.talosintelligence.com/microsoft-patch-tuesday-for-august-2026/</a><br />
<a href="https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html</a><br />
<a href="https://www.darkreading.com/application-security/microsofts-patch-tuesday-deluge-continues" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/application-security/microsofts-patch-tuesday-deluge-continues</a><br />
<a href="https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day/</a></li>
<li><strong>ZOOMSDAY</strong><br />
"A critical vulnerability in Zoom, a platform used by 70% of the Fortune 100, discovered by publicly available frontier models, allows an attacker participating in a meeting a zero-click remote code execution on all meeting participants across all native clients. This research emphasizes the risk of weaponized AI and how vulnerable we are as an industry."<br />
<a href="https://a.security/blog/asecurity-zoomsday" target="_blank" rel="noopener noreferrer nofollow ugc">https://a.security/blog/asecurity-zoomsday</a><br />
<a href="https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html</a><br />
<a href="https://www.securityweek.com/zoom-patches-zero-click-code-execution-vulnerability/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/zoom-patches-zero-click-code-execution-vulnerability/</a><br />
<a href="https://securityaffairs.com/197042/hacking/zoom-patches-zoomsday-zero-click-flaw-enabling-remote-code-execution.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/197042/hacking/zoom-patches-zoomsday-zero-click-flaw-enabling-remote-code-execution.html</a></li>
<li><strong>CISA Adds Three Known Exploited Vulnerabilities To Catalog</strong><br />
"CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.<br />
CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability<br />
CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability<br />
CVE-2026-72898 Metabase SQL Injection Vulnerability"<br />
<a href="https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog</a></li>
<li><strong>CISA: Microsoft SharePoint Flaw Now Exploited In Ransomware Attacks</strong><br />
"CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. Tracked as CVE-2026-45659, this security flaw stems from a deserialization of untrusted data weakness and allows attackers with low privileges to execute arbitrary code on unpatched SharePoint servers. It can also be exploited in low-complexity attacks because (as Microsoft explained in May when it released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition) "an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.""<br />
<a href="https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/</a><br />
<a href="https://thehackernews.com/2026/08/researchers-disclose-ai-assisted.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/researchers-disclose-ai-assisted.html</a></li>
<li><strong>Cursor Security Bug Allowed Repositories To Execute Commands Before Trust Verification</strong><br />
"A flaw in Cursor's command-line coding agent has been found to allow a cloned repository to run any command it chose on a developer's machine before they were asked whether they trusted it, and outside the sandbox even when the sandbox had been explicitly switched on. Manifold Security said it reported the issue to Cursor on July 20 and published its findings on August 10. Cursor shipped a fix for the pre-trust behavior three days after the report, then closed the submission as informative, meaning no security impact, and published no advisory. Francisco Rosales, offensive security engineer at Manifold, found the issue in the agent's isolated worktree feature, which exists to keep an AI agent away from a developer's working tree."<br />
<a href="https://www.infosecurity-magazine.com/news/cursor-security-bug-command/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/cursor-security-bug-command/</a></li>
<li><strong>Malicious MCP Servers Can Split Instructions To Make AI Coding Agents Exfiltrate Secrets</strong><br />
"A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place them in channels the assistant already uses, and let the agent stitch them together and send the data back. The attack targets coding tools that connect to outside servers over the Model Context Protocol (MCP), the open standard that lets AI assistants call external tools."<br />
<a href="https://thehackernews.com/2026/08/malicious-mcp-servers-can-split.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/malicious-mcp-servers-can-split.html</a><br />
<a href="https://github.com/asset-group/ghostsplice" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/asset-group/ghostsplice</a></li>
</ul>
<p dir="auto"><strong>Malware</strong></p>
<ul>
<li><strong>Fake Popular Sites Offer a Free App, Instead Take Over PCs</strong><br />
"A website built to look almost exactly like CNN’s homepage is telling visitors to download “the new CNN app.” But it’s not CNN’s app, and has nothing to do with the news company. The campaign doesn’t stop at CNN. It also uses fake Stremio and Avast installers hosted on similarly convincing lookalike sites, all targeting Windows users. The installers are part of the same campaign to trick people into installing legitimate remote-management software that’s already linked to the attacker’s account."<br />
<a href="https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-popular-sites-offer-a-free-app-instead-take-over-pcs" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-popular-sites-offer-a-free-app-instead-take-over-pcs</a></li>
<li><strong>DeadLock Ransomware: Breaking Down a Rust-Based Encryptor With Decentralized Recovery Infrastructure</strong><br />
"Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations. Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process. This architecture likely increases the resilience of portions of its communication, leak-hosting, and negotiation infrastructure, allowing DeadLock operators to recover from some disruption efforts while maintaining continuity for victims. Microsoft has observed DeadLock ransomware being deployed by multiple groups including an affiliate of the Lynx and INC ransomware ecosystems."<br />
<a href="https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/</a><br />
<a href="https://www.bleepingcomputer.com/news/security/deadlock-ransomware-uses-blockchain-to-resist-infrastructure-takedown/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/deadlock-ransomware-uses-blockchain-to-resist-infrastructure-takedown/</a><br />
<a href="https://thehackernews.com/2026/08/deadlock-ransomware-uses-polygon-smart.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/deadlock-ransomware-uses-polygon-smart.html</a></li>
<li><strong>Delta Probes Wi-Fi Deauth Attack On Flight Carrying DEF CON Attendees</strong><br />
"Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention. ​The company told BleepingComputer that the incident occurred yesterday on Flight 591 and did not affect the safety of the passengers or aircraft operating systems. “We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated,” a company spokesperson said."<br />
<a href="https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-on-flight-carrying-def-con-attendees/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-on-flight-carrying-def-con-attendees/</a><br />
<a href="https://cyberscoop.com/delta-flight-rogue-wifi-investigation-def-con-las-vegas/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/delta-flight-rogue-wifi-investigation-def-con-las-vegas/</a></li>
<li><strong>State Sponsored Hackers Use Fake Job Offers To Deliver New Zero Day Exploit</strong><br />
"It typically begins the same way it has for years, with an approach from a recruiter offering a role at a company the target would recognize, accompanied by a PDF describing the position in convincing detail. That approach remains one of the most effective entry points used by state sponsored threat actors today, and Check Point Research has spent recent months tracking a new wave of it. Operation Dream Job, the long running campaign attributed to the North Korea affiliated Lazarus group, has resurfaced with a previously undisclosed Windows vulnerability (CVE-2026-68820), a newly identified backdoor, and a command and control architecture built almost entirely on infrastructure the group does not own."<br />
<a href="https://blog.checkpoint.com/research/state-sponsored-hackers-use-fake-job-offers-to-deliver-new-zero-day-exploit/" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.checkpoint.com/research/state-sponsored-hackers-use-fake-job-offers-to-deliver-new-zero-day-exploit/</a><br />
<a href="https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/" target="_blank" rel="noopener noreferrer nofollow ugc">https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/</a></li>
<li><strong>Six Npm Packages Use Ethereum Transactions To Retrieve Malicious Payloads</strong><br />
"On August 10, 2026, Sonatype Research Labs identified six npm packages containing the same malicious payload, including three compromised legitimate packages and three packages published with the malware already present. The payload uses Ethereum blockchain transactions to locate infrastructure hosting additional JavaScript malware. Sonatype researchers confirmed the six packages use the same Ethereum wallet address in recent activity attributed to the DPRK-linked Contagious Interview campaign. OpenSourceMalware dubbed the specific blockchain-based command-and-control technique "NullReceiver," while Contagious Interview refers to the broader campaign associated with the Lazarus APT group."<br />
<a href="https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-payloads" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-payloads</a><br />
<a href="https://www.infosecurity-magazine.com/news/npm-packages-ethereum-wallet-c2/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/npm-packages-ethereum-wallet-c2/</a></li>
<li><strong>Fake CCleaner Installs GhostDesk Chrome Spyware</strong><br />
"A fake version of the popular PC cleaning tool CCleaner is being used to infect Windows users with a malicious Chrome extension called GhostDesk, which acts as spyware inside the browser. With more than 2 billion downloads worldwide, CCleaner is one of the best-known Windows utilities, making it an attractive target for cybercriminals looking to distribute malware. The attack starts with a website that is a convincing imitation of the CCleaner download page. Once installed, the fake application launches an attack that modifies Chrome, installs malicious extension components, and gives attackers the ability to steal credentials, capture screenshots, and log keystrokes."<br />
<a href="https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware</a></li>
<li><strong>Kimwolf v7: An Evolution Of The Kimwolf Botnet</strong><br />
"We identified a new version (v7) of the Kimwolf Android/internet-of-things (IoT) botnet. This version upgrades its distributed denial-of-service (DDoS) attack capabilities and the resilience of its command-and-control (C2) infrastructure. Kimwolf primarily affects Android TV boxes and set-top boxes. Kimwolf v7 adds an HTTP/2-based DDoS flood that constructs complete browser fingerprints. This makes attack traffic more difficult to distinguish from legitimate browsing. The threat’s binary includes five hard-coded public Ethereum-based endpoints for resolving Ethereum Name Service (ENS) domains. ENS is a blockchain-based naming system used to obtain C2 addresses."<br />
<a href="https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/" target="_blank" rel="noopener noreferrer nofollow ugc">https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/</a><br />
<a href="https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html</a><br />
<a href="https://cyberscoop.com/kimwolf-botnet-palo-alto-unit-42-android-tv-boxes/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/kimwolf-botnet-palo-alto-unit-42-android-tv-boxes/</a></li>
<li><strong>Project CAV3RN Continues: Google Apps Script As C2 Relay And DNS-Based C2 Channel Selection</strong><br />
"Project CAV3RN is a modular espionage framework used against targets in Israel. This report expands on two earlier publications: the first was published in June 2026 as part of our Kaspersky Threat Intelligence Reporting service, and the second was published on Securelist the following month, further documenting the framework’s evolving architecture and C2 capabilities. Continued tracking of this cluster in early August 2026 uncovered several previously undocumented components that expanded the framework’s communication and orchestration capabilities. The main finding is a complex C2 module that uses DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay for each transaction. The same DNS infrastructure can validate and replace the relay deployment ID, allowing the operator to rotate the Google channel."<br />
<a href="https://securelist.com/project-cav3rn-continues/120991/" target="_blank" rel="noopener noreferrer nofollow ugc">https://securelist.com/project-cav3rn-continues/120991/</a></li>
<li><strong>ExfilSquad Targets New Victims, Shares Data Via Torrents</strong><br />
"ExfilSquad is an emerging cybercriminal hacking group identified in mid-2026 as responsible for high-profile data breaches. Notably, the group does not typically deploy ransomware or destructive malware; instead, they threaten to leak stolen data on a dedicated onion-based Data Leak Site (DLS) unless a ransom is paid. ExfilSquad announced new victims this week and set a firm deadline - August 5, 2026 - to complete all required negotiations. Otherwise, the stolen data will be released. This time, the list of victims includes 13 organizations from the U.S., the UK, and Sweden. Notably, in July, the group was also targeting a major financial institution in Nigeria."<br />
<a href="https://www.resecurity.com/blog/article/exfilsquad-targets-new-victims-shares-data-via-torrents" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.resecurity.com/blog/article/exfilsquad-targets-new-victims-shares-data-via-torrents</a><br />
<a href="https://securityaffairs.com/197025/security/exfilsquad-targets-new-victims-shares-data-via-torrents.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/197025/security/exfilsquad-targets-new-victims-shares-data-via-torrents.html</a></li>
<li><strong>AI Sidebar Extension Monetizes Its Own Updates</strong><br />
"The Chrome extension “AI Sidebar with DeepSeek AI” that Google removed from the Chrome Web Store in January 2026 for stealing AI conversation content resumed shipping code to enterprise endpoints in July 2026. The extension released a benign update removing the data theft code and acknowledged its wrongdoing. After 2 weeks it pulled the rug again with a new update. Netskope Threat Labs analyzed the new build. While it no longer contains the conversation-exfiltration code, it now contains a monetization payload that opens an affiliate link in a foreground browser tab every single time the extension updates and uninstalls. Additionally, it suppresses the redirection of DeepSeek users to ChatGPT."<br />
<a href="https://www.netskope.com/blog/ai-sidebar-extension-monetizes-its-own-updates" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.netskope.com/blog/ai-sidebar-extension-monetizes-its-own-updates</a><br />
<a href="https://www.securityweek.com/extension-banned-for-stealing-ai-chats-returns-to-chrome-store-resumes-malicious-activities/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/extension-banned-for-stealing-ai-chats-returns-to-chrome-store-resumes-malicious-activities/</a></li>
<li><strong>Phantom Project: A Cybercrime Toolkit Bundle</strong><br />
"Phantom Project is a commercial cybercrime toolkit that bundles a stealer, a crypter and a remote access tool (RAT). It follows the standard Malware-as-a-Service (MaaS) model with tiered subscriptions for basic and advanced access. Researchers have observed the toolkit in Russian- and English-language phishing campaigns targeting users in more than 100 countries. Phantom Project activity was first observed in June 2025, though researchers found its distribution site had been registered in February of that year. Phantom Project activity accelerated through the second half of 2025, with multiple independent research teams documenting separate global campaigns within the same several-month window."<br />
<a href="https://blog.barracuda.com/2026/08/10/phantom-project--a-cybercrime-toolkit-bundle-" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.barracuda.com/2026/08/10/phantom-project--a-cybercrime-toolkit-bundle-</a></li>
<li><strong>Researchers Built a Fake Crypto Startup And Hired Three Suspected North Korean IT Workers</strong><br />
"Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording. The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver's license and a New York bank account. The researchers said the image metadata showed it had been processed with Google Gemini. They also reported a SynthID watermark, the invisible marker Google embeds in images its AI tools create or edit."<br />
<a href="https://thehackernews.com/2026/08/researchers-built-fake-crypto-startup.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/researchers-built-fake-crypto-startup.html</a></li>
<li><strong>Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover On Windows 11</strong><br />
"Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that redirection is not allowed by default. Security researchers Alejandro Hernando and Borja Martinez described the technique in "Plug And Pwn: Weaponizing Windows PnP Auto-Install," research prepared for DEF CON 34."<br />
<a href="https://thehackernews.com/2026/08/researchers-turn-usb-auto-install-into.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/researchers-turn-usb-auto-install-into.html</a><br />
<a href="https://plugandpwn.com/" target="_blank" rel="noopener noreferrer nofollow ugc">https://plugandpwn.com/</a></li>
<li><strong>The Multi-Layered Defenses That Harden Chrome Against Abusive Notifications</strong><br />
"Push notifications are a longstanding part of the open web, allowing developers to engage with users in real-time. However, bad actors have increasingly abused this system, bombarding people with deceptive and unwanted notifications. To combat this, Chrome Security has been on a multi-year journey, in collaboration with Firebase Cloud Messaging (FCM) and Safe Browsing, to significantly reduce notification abuse and improve the security and quality of the web ecosystem for everyone. After achieving a significant reduction in unwanted notification volume, reducing notifications on Android by over 7 billion a day in Q1 alone, today we’re pulling back the curtain on the multi-layered toolkit that secured this critical feature for billions of users."<br />
<a href="https://blog.google/security/the-multi-layered-defenses-that-harden-chrome-against-abusive-notifications/" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.google/security/the-multi-layered-defenses-that-harden-chrome-against-abusive-notifications/</a><br />
<a href="https://www.bleepingcomputer.com/news/security/google-says-chrome-cuts-7-billion-unwanted-android-notifications-a-day-to-fight-abuse/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/google-says-chrome-cuts-7-billion-unwanted-android-notifications-a-day-to-fight-abuse/</a></li>
</ul>
<p dir="auto"><strong>Breaches/Hacks/Leaks</strong></p>
<ul>
<li><strong>Mozilla Issues New Firefox GPG Key Following Exposure</strong><br />
"Mozilla announced on Monday that it has issued a new GPG signing subkey used for some Firefox and Thunderbird artifacts after the previous key was accidentally exposed in a GitHub repository. In general, if a GPG private signing key used for software releases is exposed, an attacker who obtains it could create valid signatures on malicious files. This creates a supply chain attack risk: the attacker could distribute modified or malicious versions of the software that appear authentic. Successful exploitation would still require a way to deliver the signed files to users, for instance via a compromised mirror, an alternate download path, or social engineering."<br />
<a href="https://www.securityweek.com/mozilla-issues-new-firefox-gpg-key-following-exposure/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/mozilla-issues-new-firefox-gpg-key-following-exposure/</a><br />
<a href="https://thehackernews.com/2026/08/mozilla-revokes-firefox-and-thunderbird.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/mozilla-revokes-firefox-and-thunderbird.html</a><br />
<a href="https://www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/</a></li>
<li><strong>Wesco Confirms Security Incident After ExfilSquad Claims Data Theft</strong><br />
"Global supply chain and distribution giant Wesco has confirmed in a statement to BleepingComputer that it is investigating a cybersecurity incident. The company's statement comes after data extortion group ExfilSquad claimed to have stolen sensitive information from Wesco and leaked it on their data leak site. Jennifer Sniderman, Vice President of Corporate Communications at Wesco, said that the incident involves the company's cloud CRM environment."<br />
<a href="https://www.bleepingcomputer.com/news/security/wesco-confirms-security-incident-after-exfilsquad-claims-data-theft/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/wesco-confirms-security-incident-after-exfilsquad-claims-data-theft/</a></li>
<li><strong>Ransomware Group Hijacks Hospital System’s Facebook Page Amid Ongoing Cyberattack Fallout</strong><br />
"Two weeks after a cyberattack knocked out its IT systems, the nonprofit medical system AnMed is still facing closures and the apparent hack of its Facebook page, which on Tuesday began showing ransom demands from the purported hackers. The social media page for the medical chain, which has four hospitals and other clinics in Georgia and South Carolina, was removed from Facebook shortly after a series of messages claiming to be from “The Gentlemen” ransomware group appeared."<br />
<a href="https://therecord.media/ransomware-group-hijacks-hospital-facebook-amid-cyberattack-response" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/ransomware-group-hijacks-hospital-facebook-amid-cyberattack-response</a></li>
<li><strong>Local Governments In Four States Dealing With Cyberattacks That Have Shut Down Services</strong><br />
"The 911 system of a city in California was taken down by hackers during a cyberattack on Friday — one of several cyber incidents nationwide impacting government services. Suisun City, a town of 30,000 people in the Bay Area about 30 miles from Napa Valley, said on Friday that malicious software infected and compromised the city’s IT systems. The attack “hit critical public safety operations, including 911 routing, police and fire dispatch, records and City services,” according to a government notice. The city shut down the entire IT network and contacted federal and state officials for assistance. Emergency services are still available and public safety offices are routing calls through the county’s dispatch center."<br />
<a href="https://therecord.media/cyberattacks-ransomware-local-governments" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/cyberattacks-ransomware-local-governments</a><br />
<a href="https://www.infosecurity-magazine.com/news/suisan-cyber-incident-government/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/suisan-cyber-incident-government/</a></li>
</ul>
<p dir="auto"><strong>General News</strong></p>
<ul>
<li><strong>July 2026 Dark Web Breach Incident Trend Report</strong><br />
"The July 2026 Dark Web Breach Incident Trend Report was compiled based on data breach cases posted on deep web and dark web forums. Due to the nature of some posts, it is difficult to fully verify their accuracy; some posts related to South Korea included AI-generated false data or cases where it could not be definitively determined whether an actual breach had occurred."<br />
<a href="https://asec.ahnlab.com/en/94912/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/94912/</a></li>
<li><strong>July 2026 Dark Web Threat Actor Trend Report</strong><br />
"The July 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—active on the deep web and dark web. It is explicitly noted that the factual accuracy of some content could not be verified."<br />
<a href="https://asec.ahnlab.com/en/94917/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/94917/</a></li>
<li><strong>July 2026 Dark Web Issue Trend Report</strong><br />
"The July 2026 Dark Web Issue Trend Report summarizes major issues that occurred on the deep web and dark web. Due to the nature of some sources, it may be difficult to fully verify the accuracy of certain information; therefore, it is necessary to cross-check these details against official announcements."<br />
<a href="https://asec.ahnlab.com/en/94918/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/94918/</a></li>
<li><strong>Who Will Be The Stanislav Petrov In Your Organization?</strong><br />
"The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved the world. In 1983, the USSR’s early warning systems reported that the United States had launched nuclear missiles towards the Soviet Union. The officer on duty, Stanislav Petrov, did something computers still struggle to do. He applied context, experience, and human judgement to determine the warning was probably false. Thankfully, he was right. Had an automated response been allowed to proceed without meaningful human intervention, the result could have been a full blown nuclear war."<br />
<a href="https://www.helpnetsecurity.com/2026/08/11/governing-autonomous-ai-risks/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/11/governing-autonomous-ai-risks/</a></li>
<li><strong>Cyber Security In Manufacturing</strong><br />
"Cyber attacks are no longer just an IT issue for manufacturers. They are disrupting production lines, increasing costs and putting customer deliveries at risk. Make UK’s latest report, Cyber Security in Manufacturing, reveals the scale of cyber risk facing UK manufacturers and sets out the practical steps businesses can take to strengthen resilience."<br />
<a href="https://www.makeuk.org/insights/reports/cyber-security-manufacturing" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.makeuk.org/insights/reports/cyber-security-manufacturing</a><br />
<a href="https://www.infosecurity-magazine.com/news/half-uk-manufacturers-cyber/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/half-uk-manufacturers-cyber/</a></li>
<li><strong>Cloudflare DDoS Threat Report H1 2026: 1 Tbps Attacks Soar As DNS Floods And Geopolitical Tensions Drive a New Wave</strong><br />
"Welcome to the 25th edition of Cloudflare's DDoS Threat Report. This is the first half-year edition in the series: rather than publishing separate reports for the first and second quarters of 2026, we have combined our coverage of Q1 and Q2 into a single volume covering January through June 2026. The analysis is produced by Cloudforce One, Cloudflare’s Threat Intelligence organization, providing a comprehensive analysis of the evolving threat landscape of Distributed Denial of Service (DDoS) attacks based on data from the Cloudflare network."<br />
<a href="https://blog.cloudflare.com/ddos-threat-report-2026-h1/" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.cloudflare.com/ddos-threat-report-2026-h1/</a><br />
<a href="https://www.bleepingcomputer.com/news/security/ddos-attacks-over-1-tbps-surged-fivefold-in-the-second-quarter/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/ddos-attacks-over-1-tbps-surged-fivefold-in-the-second-quarter/</a></li>
<li><strong>The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It</strong><br />
"AI governance, once the purview of the legal department, is now knocking on the CEO’s door. But many C-Suite executives are still treating it as something to delay addressing until after AI regulations are set in stone. This can be a shortsighted strategy. Consider that 46% of organizations say AI governance and compliance issues are the reason why their AI underperforms, according to the GrantThornton, 2026 AI Impact Survey Report (PDF). These figures lend credence to why leadership should not wait for AI regulations to settle but should apply governance proactively."<br />
<a href="https://www.securityweek.com/the-ai-governance-gap-is-a-leadership-problem-waiting-wont-close-it/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/the-ai-governance-gap-is-a-leadership-problem-waiting-wont-close-it/</a><br />
<a href="https://www.grantthornton.com/content/dam/grantthornton/website/assets/content-page-files/advisory/ai-lp/infographic/ai-impact-survey-2026/pdf/grant-thornton-2026-ai-impact-survey.pdf" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.grantthornton.com/content/dam/grantthornton/website/assets/content-page-files/advisory/ai-lp/infographic/ai-impact-survey-2026/pdf/grant-thornton-2026-ai-impact-survey.pdf</a></li>
<li><strong>Hacker Conversations: Marcus Hutchins And The Journey From The Gray Zone To Redemption</strong><br />
"Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did. Born in Ascot, England, he was working as a cyber threat analyst for an LA-based cybersecurity company in 2017 (aged 22), when he became the world’s hero for finding a kill switch for the particularly virulent and destructive cryptoworm (ransomware spread by a worm) known as WannaCry. The ransomware decryption didn’t work, so there was no way to decrypt files once encrypted (it was effectively a wiper). But the worm worked very well, and more than 200,000 computers were affected in around 150 countries in just a few days."<br />
<a href="https://www.securityweek.com/hacker-conversations-marcus-hutchins/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/hacker-conversations-marcus-hutchins/</a></li>
</ul>
<p dir="auto"><strong>อ้างอิง</strong><br />
Electronic Transactions Development Agency (ETDA) <img src="/assets/uploads/files/1786551239648-a01c4cb2-bba2-4e66-9941-fbc2f5393649-image.png" alt="a01c4cb2-bba2-4e66-9941-fbc2f5393649-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3182/cyber-threat-intelligence-12-august-2026</link><generator>RSS for Node</generator><lastBuildDate>Wed, 12 Aug 2026 18:13:21 GMT</lastBuildDate><atom:link href="https://webboard-nsoc.ncsa.or.th/topic/3182.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 12 Aug 2026 16:14:01 GMT</pubDate><ttl>60</ttl></channel></rss>