NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ

    Cyber Threat Intelligence 17 August 2026

    Cyber Security News
    1
    1
    8
    โหลดโพสเพิ่มเติม
    • เก่าสุดไปยังใหม่สุด
    • ใหม่สุดไปยังเก่าสุด
    • Most Votes
    ตอบ
    • ตอบโดยตั้งกระทู้ใหม่
    เข้าสู่ระบบเพื่อตอบกลับ
    Topic นี้ถูกลบไปแล้ว เฉพาะผู้ใช้งานที่มีสิทธิ์ในการจัดการ Topic เท่านั้นที่จะมีสิทธิ์ในการเข้าชม
    • NCSA_THAICERTN
      NCSA_THAICERT
      แก้ไขล่าสุดโดย

      Vulnerabilities

      • Chinese Loongson Processors Have Leaky Caches, Researchers Find
        "Researchers from Germany’s Helmholtz Center for Information Security have found processors made by China’s Loongson have leaky caches that attackers could use to seek specific data. Loongson has developed its own LoongArch instruction set architecture (ISA) that blends approaches used by MIPS and RISC-V. On a site called LoongLeakAttack.com, the researchers explain that they found the leaky cache using a fuzzer, then noticed that the LoongArch ISA manual mentions an instruction that leaves 32 bits of a memory register in an “uncertain” state."
        https://www.theregister.com/security/2026/08/13/chinese-loongson-processors-have-leaky-caches-researchers-find/5287137
        https://loongleakattack.com/
      • Unpatched GeoServer Zero-Day Targeted In Active Exploitation Attempts, Can Lead To RCE
        "A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remains unpatched. It was first disclosed on August 12, 2026, at 10:46 UTC, by a researcher named @q1uf3ng on X. "GeoServer jsonArrayContains unauthorized SQL injection, and in the case of the sa [system administrator] database, it's naturally possible to achieve RCE," the researcher said."
        https://thehackernews.com/2026/08/unpatched-geoserver-zero-day-targeted.html
        https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/
        https://securityaffairs.com/197216/hacking/geoserver-zero-day-is-already-being-probed-thats-the-problem.html

      Malware

      • Hackers Exploit MacOS Screen Sharing Flaw To Deploy Monero Miner
        "The Netherlands’ National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. The security issue lies in macOS Screen Sharing, a built-in remote desktop feature that allows remote desktop control over a network, using the VNC protocol over TCP port 5900. Apple fixed CVE-2026-65400 on August 6 in macOS Tahoe 26.6.1 and earlier releases. The flaw allows network-based attackers to gain access without valid credentials."
        https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/
        https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html
        https://securityaffairs.com/197234/uncategorized/macos-screen-sharing-flaw-exploited-to-deploy-monero-miners.html
      • Max Severity SAP Commerce Cloud Flaw Now Targeted In Attacks
        "A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. Commerce Cloud (formerly known as SAP Hybris) is a cloud-based e-commerce platform used by online stores owned by high-profile global brands and large retailers. Tracked as CVE-2026-58231, this critical flaw stems from an improper authorization weakness in the core Data Hub Adapter extension for Commerce Cloud that threat actors without privileges can exploit in low-complexity attacks to execute arbitrary code."
        https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/
        https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html
        https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html
      • ExfilSquad: New Data Extortion Group Leaks Microsoft D365 Data, Likely Linked To Misconfigured Power Pages
        "Fortra Intelligence and Research Experts (FIRE) have developed specialist tooling to support certain customers when faced with ransomware and data extortion claims. We monitor for new disclosures, including public and dark web sources, to provide early alerting to customers and support investigations. As part of this process, we also see activity that is not directly related to customers. When there is a significant interest, and we have new intelligence to share, we aim to share information with the security community to aid understanding of ransomware and extortion actors and campaigns."
        https://www.fortra.com/blog/exfilsquad-data-extortion-group-ransoming-microsoft-d365-data
        https://www.infosecurity-magazine.com/news/exfilsquads-13-organizations/
      • AmnesiaStealer: a Multi-Stage Rust-Based MacOS Infostealer That Hijacks Chromium Browsers
        "Jamf Threat Labs discovers and investigates AmnesiaStealer, a multi-stage Rust-based macOS infostealer spread through a counterfeit GitHub download page that captures the login password, reaches for macOS bypasses Apple has already patched, and can hand the operator live, hidden control of the victim's Chromium browser to steal authenticated sessions."
        https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/
        https://thehackernews.com/2026/08/amnesiastealer-hijacks-chromium.html
        https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/
        https://www.infosecurity-magazine.com/news/macos-infostealer-spread-clickfix/
        https://www.securityweek.com/amnesiastealer-macos-malware-steals-data-controls-browser-sessions/
        https://securityaffairs.com/197190/malware/amnesiastealer-gives-attackers-live-control-of-victims-macos-browsers.html
      • APT Group HoneyMyte Upgrades CoolClient: The Backdoor Gets a Kernel-Level Windows Rootkit
        "CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia. It supports such capabilities as keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and plugin-based extensions. Since its first public disclosure by Sophos in 2022 and subsequent analysis by Trend Micro in 2023, CoolClient has continued to evolve. In 2025, we analyzed a newer variant that introduced clipboard theft and HTTP traffic interception for credential harvesting."
        https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
        https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html
        https://securityaffairs.com/197274/apt/mustang-panda-upgrades-coolclient-with-a-kernel-rootkit.html
      • Return Of The Cookie Monster
        "In Dough No! Revisiting Cookie Theft, we looked at how Chromium’s Application Bound Encryption (ABE) in Windows made cookie theft significantly harder. For operators, this meant they needed to inject into a browser process, utilize remote debugging, or install an extension to steal cookies. This blog post dives deeper how to enable the remote debugging protocol without having to launch it via the --remote-debugger-port argument. With the release of Chrome 136+, Google announced additional protections against stealing cookies via remote debugging. To enable the Chrome DevTools Protocol (CDP) an alternate --user-data-dir needed to be supplied with --remote-debugger-port causing the existing cookies to be abandoned as a new data directory would be used. These changes forced operators to think more carefully about their process context before stealing cookies."
        https://specterops.io/blog/2026/08/13/chrome-devtools-protocol-cookie-theft/
        https://thehackernews.com/2026/08/chrome-devtools-technique-enables.html
      • Fake Zoom Installer Uses .NET Downloader To Deliver Overlord RAT On MacOS
        "Jamf Threat Labs recently identified a campaign using a fake Zoom installer to deliver a configured build of Overlord, an open-source remote access framework, hosted on attacker-controlled infrastructure. The downloader is a macOS ARM64 Mach-O binary named ZoomMeetings, built as a self-contained .NET 10 single-file application with the .NET runtime bundled inside. Rather than the Go or Rust we typically see in macOS malware, this downloader uses .NET, whose cross-platform support means the same codebase also targets Windows. Building macOS malware using the .NET framework is fairly uncommon, so naturally this caught our attention. Our curiosity led to a number of interesting finds that we'll share in this blog post."
        https://www.jamf.com/blog/fake-zoom-installer-delivers-overlord-rat-macos/
      • Large-Scale DDoS Attacks Disrupted Threema Secure Messaging Service
        "Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. ​Organizations using Threema On-Prem did not experience any issues because they rely on their own infrastructure. In a post-mortem report on Friday, the end-to-end encrypted instant messaging service said that the attacks were difficult to defend against because the threat actor constantly changed patterns."
        https://www.bleepingcomputer.com/news/security/large-scale-ddos-attacks-disrupted-threema-secure-messaging-service/
        https://securityaffairs.com/197353/hacking/ddos-attacks-cause-major-threema-outages.html
      • PATCHCORD: New Malware Cluster Targets Afghan Telecom And South Asian Critical Infrastructure
        "Acronis Threat Research Unit (TRU) has identified an ongoing campaign delivering a previously undocumented custom backdoor against Afghan telecom providers and South Asian critical infrastructure organizations. The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools. Infrastructure pivoting uncovered SHEETCORD, a Go-based implant that builds on PATCHCORD's capabilities while abusing Google Sheets for C2 communication. The malware was actively distributed through a domain impersonating India's National Informatics Centre (NIC)."
        https://www.acronis.com/en/tru/posts/patchcord-new-malware-cluster-targets-afghan-telecom-and-south-asian-critical-infrastructure/
        https://securityaffairs.com/197266/intelligence/apt36-suspected-in-patchcord-espionage-campaign-using-google-sheets-c2.html

      Breaches/Hacks/Leaks

      • Shell Investigates 'potential Incident' After Clop Data Theft Claims
        "Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. Shell is a British multinational energy conglomerate and one of the world's top three oil and gas companies, after Chevron and ExxonMobil. It has 85,000 employees in more than 70 countries and operates a massive network of tens of thousands of service and recharge stations that serve over 20 million customers daily. According to a recent post on Clop's dark web data leak site, the allegedly stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans."
        https://www.bleepingcomputer.com/news/security/shell-investigates-potential-incident-after-clop-data-theft-claims/
      • RingCentral Data Breach Exposed Info Of 1.6 Million Accounts
        "The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned. RingCentral is a cloud-based collaboration and communication platform used by over 600,000 businesses for services such as calling, messaging, and voicemail. The company disclosed the incident on July 28, revealing that its systems were compromised following what it described as a "sophisticated social engineering campaign.""
        https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/
        https://haveibeenpwned.com/Breach/RingCentral
        https://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/
      • Scottish Govt Suffers Potentially Widening Data Breach At Prosecutor's Office
        "A contractor has leaked Scottish government employees' personal information, and the full scope of the breach may be far greater than what is currently being reported. On Aug. 13, Scotland's Crown Office and Procurator Fiscal Service (COPFS) — the government's public prosecution service and death investigation authority — disclosed that an unidentified external supplier had experienced a data breach. The breach affected some of its employees' personally identifying information (PII)."
        https://www.darkreading.com/cyberattacks-data-breaches/scottish-govt-data-breach-prosecutors-office
      • 7.3M Chess.com Records Leaked, And The Data Is Real
        "A 15.5 GB file containing 7,337,395 chess.com user records is being handed out free on two data-leak forums. It carries email addresses, usernames, real names, countries, ratings, subscription tiers and internal advertising-audience tags. Ransomnews verified the data against the file itself. It is genuine chess.com data, and it is days old, not a recycled dump. What it is not, on the evidence, is a break-in: every structural signal points to large-scale scraping of a non-public interface rather than a compromise of chess.com’s systems."
        https://ransomnews.com/chess-com-leak-7-million-2026/
        https://securityaffairs.com/197174/breaking-news/chess-com-leak-exposes-7-3-million-users-evidence-points-to-scraping.html
      • LiteLLM Supply Chain Attack: Inside The AI Breach That Exposed 2,500+ Companies
        "New analysis published in August 2026 has overturned the original timeline of the LiteLLM supply chain attack. The well-known 40-minute PyPI window was not the beginning of the exposure. It was the final stage of a five-day collection run that started with the compromise of the Trivy scanner. Record-level data now maps exposure across more than 2,500 organizations and roughly 434,000 captured CI/CD files. SOCRadar’s analysis found that 95% of affected organizations appeared in the dataset before the malicious LiteLLM packages were published on March 24."
        https://socradar.io/blog/litellm-supply-chain-attack/
        https://www.securityweek.com/trivy-not-litellm-behind-the-2500-org-compromise/
      • France Investigates Tax Authority Breach After Hacker Claims 600,000 Victims
        "France’s tax authority has confirmed that hackers breached its information systems and extracted data on individuals and businesses. France’s Economy Ministry said late Thursday that an attacker gained unauthorized access to systems at the Directorate General of Public Finances, or DGFiP, in late June after stealing or misusing someone’s identity. The intrusion allowed the attacker “to view and extract data belonging to individuals and businesses,” according to the ministry."
        https://therecord.media/french-tax-authority-dgfip-confirms-data-breach
        https://securityaffairs.com/197287/cyber-crime/sophisticated-cyberattack-exposes-data-of-678000-french-taxpayers.html
      • Uber Freight Keeps On Trucking After Extortion Crew Breaks In
        "Uber Freight says it is investigating a "data security incident" days after the Helix extortion group listed the company on its data leak site on August 6. Helix claims to have stolen nearly 1 million files from mailboxes, OneDrive accounts, the accounts receivable department, and other repositories. An Uber Freight spokesperson told The Register that the incident was under investigation but had not disrupted the company's daily operations."
        https://www.theregister.com/security/2026/08/12/uber-freight-keeps-on-trucking-after-extortion-crew-breaks-in/5286782
      • SafePal Data Breach Impacts 39,798 Customers, Stolen Info For Sale
        "Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. SafePal says the breach impacts customers who placed orders between March 2, 2025, and April 11, 2026, exposing their names, email addresses, shipping addresses, phone numbers, and purchase information."
        https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-39-798-customers-stolen-info-for-sale/

      General News

      • Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw
        "Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers’ bank accounts. The theft, investigated by the Brazilian and German federal police agencies, occurred over four days in November 2023 and caused losses of around €30 million ($34.6 million). While neither the Brazilian Federal Police nor Germany's BKA named the affected German financial institution, Brazilian media identified it as Commerzbank, a major European financial institution that generates more than €11.1 billion ($12.8 billion) in annual revenue."
        https://www.bleepingcomputer.com/news/security/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw/
        https://therecord.media/investigation-into-banking-hack-leads-to-arrests-germany-brazil
      • Data Analyst Sent To Prison For Stealing Data, Extorting Employer
        "A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. Brightly is a Software-as-a-Service (SaaS) company formerly known as SchoolDude, which was acquired by Siemens in August 2022. Brightly employs over 700 people and provides asset management and maintenance software to more than 12,000 clients worldwide. 27-year-old North Carolina man Cameron Curry (also known as "Loot") was found guilty in March of orchestrating an "extensive cyber extortion scheme" targeting his employer."
        https://www.bleepingcomputer.com/news/security/data-analyst-sent-to-prison-for-stealing-data-extorting-employer/
      • Ransomware Threats In The Americas H1 2026: Dissecting The Regional Attack Patterns And Dominant Actors
        "The Americas carried the heaviest ransomware burden of any region on the planet in the first half of 2026. According to Cyble Research and Intelligence Labs (CRIL), North and South America combined experienced 2,188 documented ransomware attacks between January and June 2026. That single figure — 2,188 attacks — represents more than 57% of the 3,836 ransomware incidents CRIL tracked worldwide, making the Americas the undisputed center of gravity for global ransomware operations."
        https://cyble.com/blog/ransomware-threats-in-america-h1-2026/
      • What Boards Need To Know About Tech Risk
        "Most boardrooms are built to evaluate opportunity, growth initiatives, tech acquisitions, and operational improvements. The discussion centers on a familiar equation: investing in X to generate Y return. That mindset is essential for scaling a business. But it often creates dangerous blind spots in digital infrastructure. Unlike revenue-generating projects, many of the most important technology investments don't produce visible upsides."
        https://www.darkreading.com/cyber-risk/what-boards-must-know-tech-risk
      • The Hardest Part Of Agentic AI May Be Rebuilding The Business
        "Organizations expect AI agents to change how work gets done, driving productivity and growth while allowing employees to focus on higher-value tasks. Few, however, have the processes and workflows needed to realize those benefits, according to Deloitte’s latest research. About half of surveyed leaders say they understand how AI agents will affect their future operating model. Three main challenges limit wider adoption: the lack of a unified and accessible data foundation, limited trust in and governance of AI agents, and the cost and complexity of integration."
        https://www.helpnetsecurity.com/2026/08/14/deloitte-agentic-ai-readiness-gap-report/
      • Weak IAM Affects Up To 98% Of Cloud Environments
        "Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing encryption, exposed services, and logging gaps. CISA now mandates baseline cloud configuration practices for US federal agencies. More than two-thirds of midmarket organizations use multiple cloud providers, each with its own security model, terminology, and configuration settings. The same security issue can manifest differently across AWS, Azure, and Google Cloud, often requiring a different approach to identify and remediate, according to Intruder’s 2026 Cloud Security Index report."
        https://www.helpnetsecurity.com/2026/08/14/intruder-cloud-misconfiguration-trends-report/
      • Black Hat USA 2026: Will Vulnerability Discovery Eventually Decline In The AI Era?
        "The accelerated discovery of previously unknown software vulnerabilities has been making headlines for months. It’s an issue that has even led the US government to create a vulnerability clearing house named Gold Eagle to coordinate research efforts in vulnerability discovery, mitigation and fixes. An indication of the broader pressure facing cyber-defenders can be drawn from the sheer number of patches being delivered in Microsoft’s Patch Tuesday through the last four months: 169 CVEs in April, 118 CVEs in May, 571 CVEs overall in June (including 208 direct Microsoft CVEs) and another 622 vulnerabilities in July that included zero-days under active exploitation."
        https://www.welivesecurity.com/en/business-security/black-hat-usa-2026-vulnerability-discovery-decline-ai-era/
      • North Korean Remote Workers Are Infiltrating Government And Businesses: How To Expose Them Before Hiring
        "Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems companies spend millions trying to protect. That risk is no longer theoretical. The FBI is now investigating a North Korean remote IT worker who reportedly worked for a U.S. federal agency. For CISOs, the priority is clear: spot the warning signs before a fraudulent hire becomes trusted access."
        https://thehackernews.com/2026/08/north-korean-remote-workers-are.html
      • AI Can Find Bugs, But Human Knowledge Still Proves Them
        "Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, explain unfamiliar APIs, and run repetitive testing workflows at impressive speed. That is a real advantage for security teams. It also creates a new kind of pressure, because the industry can now produce more vulnerability-looking output than ever before."
        https://www.sans.org/blog/ai-can-find-bugs-but-human-knowledge-still-proves-them
      • Drop Something? Don’t Worry, Someone Caught It
        "Every day, tens of thousands of domain names expire and become available for registration. Some fade away and are never seen again. Others get a second chance. We refer to these as dropcatch domains: the domain was dropped, became available again, and someone caught it. This isn’t just our name; it’s widely used. There’s even an auction service called DropCatch[.]com. During the first half of 2026, we observed over 50k dropcatch domains a day in the gTLDs alone—when we add in various ccTLDs that number rises to around 65k. That’s an astounding number when you put it next to the total of new registrations every day. For the gTLDs, nearly 20% of all observed registrations are dropcatch. In other words, one of every five newly registered domains had a prior life, sometimes several."
        https://www.infoblox.com/blog/threat-intelligence/drop-something-dont-worry-someone-caught-it/
        https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html
        https://securityaffairs.com/197251/uncategorized/crooks-are-buying-your-expired-domains-and-using-them-to-deliver-malware.html
      • AI Won't Solve Cybersecurity Burnout. Better Leadership Might
        "Cybersecurity has spent years talking about workforce shortages. More recently, AI has entered the conversation as a possible solution. It can help teams analyze alerts, identify threats, automate investigations, and complete routine tasks faster than ever. That shift is already underway. According to SANS workforce research, 74% of cybersecurity teams are changing structures and role assignments because of AI, with entry-level SOC and security analyst roles among the most affected. Yet workloads, complexity and stress continue to rise. The latest ISSA workforce study found that 68% of professionals believe their jobs have become harder over the past two years, and nearly half have considered leaving their current role."
        https://blog.barracuda.com/2026/08/14/ai-won-t-solve-cybersecurity-burnout--better-leadership-might

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 7b745a34-7080-45b9-8405-28899a9c7f37-image.png

      1 การตอบกลับ คำตอบล่าสุด ตอบ คำอ้างอิง 0
      • First post
        Last post