<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cyber Threat Intelligence 25 August 2026]]></title><description><![CDATA[<p dir="auto"><strong>Financial Sector</strong></p>
<ul>
<li><strong>Security Issues In The Korean &amp; Global Financial Sector In July 2026</strong><br />
"In Attack Stage 1, phishing (a technique that tricks users into opening malicious links or attachments) had the highest rate at 1.7, Down from 2.3 The previous month. In Attack Stage 2, Dropper/Downloader (a type that downloads additional malware) was the most prevalent at 1.7, Up from 1.4 The previous month. In Stage 3, Infostealers (malware designed to steal information) were the most prevalent at 0.2, While Ransomware and CoinMiner each accounted for 0.1."<br />
<a href="https://asec.ahnlab.com/en/95109/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/95109/</a></li>
<li><strong>Venezuelan Gets Record Federal Prison Term For ATM Jackpotting</strong><br />
"A Venezuelan national has been sentenced to 8 years in prison for his role in an ATM jackpotting scheme that caused millions of dollars in losses, the US Justice Department announced on Friday. According to the DOJ, 27-year-old Juan Manuel Gouveia-Aguilera has been sentenced to 96 months in prison, 5 years of supervised release, and ordered to pay restitution after pleading guilty to bank fraud, bank burglary, and cyber-enabled fraud charges. “The Court found Gouveia-Aguilera to be responsible for more than $3.5 million in losses and this sentence is believed to be the longest federal sentence imposed for an individual’s role in ATM jackpotting,” the DOJ said."<br />
<a href="https://www.securityweek.com/venezuelan-gets-record-federal-prison-term-for-atm-jackpotting/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/venezuelan-gets-record-federal-prison-term-for-atm-jackpotting/</a></li>
</ul>
<p dir="auto"><strong>Vulnerabilities</strong></p>
<ul>
<li><strong>One Slug, Seven Editions: The MiniOrange SAML SSO Bug That Let Anyone Log In As Your WordPress Admin</strong><br />
"Most vulnerability write-ups are about the bug. This is primarily about everything around the bug, where the actual risk ended up living. The DigitalOcean security team identified a critical gap the hard way, based on their defense-in-depth controls. The version-level analysis that follows, which no public vulnerability database had, came out of DigitalOcean’s work. Two critical authentication bypasses (CVSS 9.8) were publicly disclosed in July 2026 for the miniOrange SAML 2.0 Single Sign On plugin (opens in new tab)<img src="https://webboard-nsoc.ncsa.or.th/assets/plugins/nodebb-plugin-emoji/emoji/android/2197.png?v=2sqmsl7eedm" class="not-responsive emoji emoji-android emoji--arrow_upper_right" style="height:23px;width:auto;vertical-align:middle" title=":arrow_upper_right:" alt="↗" />. Both allow an unauthenticated attacker to forge a SAML assertion and land in /wp-admin as any existing user, including administrators."<br />
<a href="https://patchstack.com/articles/one-slug-seven-editions-the-miniorange-saml-sso-bug-that-let-anyone-log-in-as-your-wordpress-admin/" target="_blank" rel="noopener noreferrer nofollow ugc">https://patchstack.com/articles/one-slug-seven-editions-the-miniorange-saml-sso-bug-that-let-anyone-log-in-as-your-wordpress-admin/</a><br />
<a href="https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks/</a></li>
<li><strong>Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account</strong><br />
"Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as the CVE Numbering Authority (CNA) for the flaw. It has been classified as a weak password recovery mechanism for a forgotten password (CWE-640). Users of upstream Keycloak are advised to update to version 26.7.2, released August 19, 2026, while customers running Red Hat build of Keycloak (RHBK) should apply the updates shipped for 26.4.15 and 26.6.6."<br />
<a href="https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html</a></li>
<li><strong>91 Vulnerabilities Patched In Spring Application Framework</strong><br />
"The developers of Broadcom’s Spring application development framework last week announced the release of updates that patch 91 vulnerabilities. Spring is an open source application framework for the Java platform that simplifies the creation of enterprise applications through features such as dependency injection, aspect-oriented programming, and modular support for web, data, and messaging architectures. After years under VMware’s stewardship, it transitioned to Broadcom following its acquisition of VMware."<br />
<a href="https://www.securityweek.com/91-vulnerabilities-patched-in-spring-application-framework/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/91-vulnerabilities-patched-in-spring-application-framework/</a></li>
<li><strong>CISA Adds One Known Exploited Vulnerability To Catalog</strong><br />
"CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.<br />
CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability"<br />
<a href="https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog</a></li>
<li><strong>Calix GS7 XGS GS5239XG Residential Router Contains Missing Authentication Vulnerability</strong><br />
"The Calix GS7 XGS GS5239XG router running firmware EXOS/6.6.47 contains a missing authentication vulnerability that exposes its UPnP (Universal Plug and Play) WANIPConnection service on the public WAN interface. Calix GS7 XGS GS5239XG is a residential gateway that provides routing, NAT, and firewall functionality for home networks. The device includes the Universal Plug and Play (UPnP) service implemented via MiniUPnPd 2.3.7, a lightweight software program that provides features such as automatic port forwarding for applications and devices on the LAN. By default, the UPnP service is exposed on the device’s WAN interface and does not require authentication."<br />
<a href="https://kb.cert.org/vuls/id/756733" target="_blank" rel="noopener noreferrer nofollow ugc">https://kb.cert.org/vuls/id/756733</a><br />
<a href="https://www.bleepingcomputer.com/news/security/unpatched-calix-flaw-lets-hackers-bypass-nat-to-expose-internal-devices/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/unpatched-calix-flaw-lets-hackers-bypass-nat-to-expose-internal-devices/</a></li>
<li><strong>Russian Backdoor Found In Slovak Traffic Cameras</strong><br />
"Efforts to modernize state infrastructure and update traffic surveillance have been stalled by critical security issues the Slovakian government reported in newly acquired high-speed traffic cameras. The National Security Authority - Slovakia's watchdog cybersecurity agency - discovered backdoors embedded in a module in 279 NERO R-ONE high-speed cameras. The now disabled cameras - acquired through a 30 million euro European Union-backed modernization fund - contained a collection of Russian-linked phone numbers that enable backdoor access to the country's traffic systems."<br />
<a href="https://www.bankinfosecurity.com/russian-backdoor-found-in-slovak-traffic-cameras-a-32645" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/russian-backdoor-found-in-slovak-traffic-cameras-a-32645</a><br />
<a href="https://securityaffairs.com/197764/hacking/slovakia-warns-of-cyber-risks-in-road-speed-cameras.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/197764/hacking/slovakia-warns-of-cyber-risks-in-road-speed-cameras.html</a></li>
<li><strong>Cudy WR3000 Router Flaws Can Be Chained To Gain Root Access</strong><br />
"Independent security researchers Hunt &amp; Benito have released public exploit tools that reproduce a two-vulnerability chain affecting Cudy WR3000 routers. The code can extract authentication data from the router firmware, forge a valid token, and, when the required network access exists, execute operating-system commands as root. The toolkit was published on August 20, 2026, one day after GitHub published advisories for the vulnerabilities. Its release turns the technical findings into a repeatable exploitation process, although there is no evidence that either flaw is being exploited in real attacks."<br />
<a href="https://hackread.com/cudy-wr3000-router-flaws-chained-root-access/" target="_blank" rel="noopener noreferrer nofollow ugc">https://hackread.com/cudy-wr3000-router-flaws-chained-root-access/</a></li>
</ul>
<p dir="auto"><strong>Malware</strong></p>
<ul>
<li><strong>A Social Engineering Attempt Against ReliaQuest: What We Found</strong><br />
"On August 22, 2026, ReliaQuest was the target of a social engineering attack. While unsuccessful beyond temporarily exposing one identity, the attempt was an important reminder of the persistent tactics of threat actor groups and what all organizations can do to guard against them. We are sharing the full details of this attempt for transparency and so others can learn from this playbook. The threat actor registered a lookalike domain and stood up a fake ReliaQuest single sign-on (SSO) page behind a content delivery network. The threat actor then called multiple ReliaQuest teammates, each time posing as a security employee by name in an attempt to steer them towards the fake page. One teammate entered their password and approved the push notification on their phone. That handed the attacker a brief session on our identity dashboard."<br />
<a href="https://reliaquest.com/blog/threat-spotlight-social-engineering-attempt-against-reliaquest-what-we-found/" target="_blank" rel="noopener noreferrer nofollow ugc">https://reliaquest.com/blog/threat-spotlight-social-engineering-attempt-against-reliaquest-what-we-found/</a><br />
<a href="https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/</a><br />
<a href="https://www.securityweek.com/reliaquest-confirms-shinyhunters-hack-but-says-impact-was-limited/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/reliaquest-confirms-shinyhunters-hack-but-says-impact-was-limited/</a></li>
<li><strong>AliExpress Webpage Keeping Multipoint Bluetooth Headphones Active With WebAudio Fingerprinting</strong><br />
"Recently I ran into a strange problem with my Bluetooth headphones. They support multipoint Bluetooth audio, so they can be connected to my PC and phone at the same time. Normally the PC takes priority playing audio, with my phone being able to play audio when nothing is playing on the PC. Usually I listen to music on my phone but with notifications or Youtube playing through the PC, this works reliably until I open an AliExpress page in Firefox or Chrome (other browsers untested). Shortly after loading the AliExpress homepage, audio from my phone would stop playing. Closing the AliExpress tab fixes it immediately. Muting the tab/Firefox/Windows does not help, and there is no visible video, music, or other media playing on the page."<br />
<a href="https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html</a><br />
<a href="https://www.bankinfosecurity.com/alibabas-aliexpress-uses-hidden-audio-to-fingerprint-devices-a-32646" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/alibabas-aliexpress-uses-hidden-audio-to-fingerprint-devices-a-32646</a><br />
<a href="https://www.malwarebytes.com/blog/privacy/2026/08/aliexpress-caught-using-silent-audio-to-fingerprint-visitors-browsers" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/privacy/2026/08/aliexpress-caught-using-silent-audio-to-fingerprint-visitors-browsers</a></li>
<li><strong>WordlistLoader Delivering Amatera Via ClearFake Campaigns</strong><br />
"Over the past few months, Amatera Stealer (also often referred to as ACR Stealer) has been actively developed and has gradually become one of the most prevalent infostealer in our user base. Most recently, we've been observing Amatera being distributed via ClearFake campaigns leveraging FakeCaptchas. Although FakeCaptcha, as a technique, is well-known and has been documented countless times, it has proven to be one of the most effective social engineering techniques for luring victims into infecting their own machines, which is why we still keep seeing it so often in malware campaigns, and why we proactively defend against these types of attacks with our Clipboard protection."<br />
<a href="https://www.gendigital.com/blog/insights/research/wordlistloader-delivering-amatera-via-clearfake-campaigns" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.gendigital.com/blog/insights/research/wordlistloader-delivering-amatera-via-clearfake-campaigns</a><br />
<a href="https://www.darkreading.com/data-privacy/wordlistloader-disguises-malware-ordinary-text" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/data-privacy/wordlistloader-disguises-malware-ordinary-text</a><br />
<a href="https://thehackernews.com/2026/08/wordlistloader-delivers-amatera-via.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/wordlistloader-delivers-amatera-via.html</a></li>
<li><strong>The "Chameleon" Threat: Unmasking And Mitigating Cloaked SEO Poisoning In Financial Services</strong><br />
"In Q2 2026, Fortra Intelligence and Research Experts (FIRE) observed a more than 40% increase of threat actors weaponizing trust through a new tactic dubbed by researchers as “Chameleon SEO Poisoning.” The tactic uses cloaked search engine results to deploy phishing payloads such as credential theft and session hijacking. This allows them to remain invisible to standard security scanners and remain active longer. To successfully detect and mitigate these campaigns, security teams should move beyond relying solely on static automated sweeps and integrate context-aware, emulated scanning that mirrors a victim’s search journey."<br />
<a href="https://www.fortra.com/blog/the-chameleon-threat" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.fortra.com/blog/the-chameleon-threat</a><br />
<a href="https://www.helpnetsecurity.com/2026/08/24/chameleon-seo-poisoning-fake-banking-websites-phishing/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/24/chameleon-seo-poisoning-fake-banking-websites-phishing/</a></li>
<li><strong>Cato CTRL Insights: When Trust Becomes The Payload In a Fake Codex ClickFix Campaign</strong><br />
"Attackers are using a fake Codex download experience to trick macOS users into pasting a malicious command into Terminal. This technique, known as ClickFix, relies on social engineering rather than a conventional malware download: the victim is persuaded to perform the execution step themselves. We analyzed sponsored search results leading to convincing Google Sites pages, a no-code website-building and hosting service provided by Google. An attacker-controlled embedded page then presented the fake installer and the Terminal instruction."<br />
<a href="https://www.catonetworks.com/blog/cato-ctrl-when-trust-becomes-payload-in-fake-codex-clickfix-campaign/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.catonetworks.com/blog/cato-ctrl-when-trust-becomes-payload-in-fake-codex-clickfix-campaign/</a><br />
<a href="https://www.infosecurity-magazine.com/news/fake-codex-download-google-sites/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/fake-codex-download-google-sites/</a></li>
<li><strong>DOUBLOON DREDGER Token Harvesting: Notion Abuse, EvilTokens, And a Side Of Tycoon2FA</strong><br />
"In July 2026, a Sublime customer reached out about having observed Notion abuse for the purpose of delivering phishing attacks. In parallel, Sublime Threat Intelligence &amp; Research (STIR) had identified similar phishing activity directed at another customer in a similar vertical. In these attacks, the threat actor abuses Notion by creating a fake account and then invites targets to view a PDF that contains a malicious link. The payload link then takes the target to an EvilTokens device code harvesting page."<br />
<a href="https://sublime.security/blog/doubloon-dredger-token-harvesting-notion-abuse-eviltokens-and-a-side-of-tycoon2fa/" target="_blank" rel="noopener noreferrer nofollow ugc">https://sublime.security/blog/doubloon-dredger-token-harvesting-notion-abuse-eviltokens-and-a-side-of-tycoon2fa/</a><br />
<a href="https://www.infosecurity-magazine.com/news/doubloon-dredger-notion/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/doubloon-dredger-notion/</a></li>
<li><strong>Fake GTA 6 Extended Look And Demo Sites Deliver An Infostealer</strong><br />
"GTA 6 footage really has leaked online, and Rockstar has an official Extended Look coming to Netflix on August 27. But cybercriminals are exploiting the hype with fake Rockstar sites that lead visitors to password-stealing malware. We identified a network of sites appearing in searches for a GTA 6 demo and impersonating Rockstar Games. One Google result advertises an “Official Download,” but visitors who follow the sites’ “Play Now” links can instead end up downloading gta6_installer.exe."<br />
<a href="https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-gta-6-extended-look-and-demo-sites-deliver-an-infostealer" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-gta-6-extended-look-and-demo-sites-deliver-an-infostealer</a><br />
<a href="https://www.tomshardware.com/video-games/fake-gta-vi-iso-circulates-on-the-internet-a-few-days-after-leak-internet-sleuths-claim-113gb-download-is-padded-malware-testers-claim-file-is-99-99-percent-empty-zeroes-with-50kb-virus-embedded" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.tomshardware.com/video-games/fake-gta-vi-iso-circulates-on-the-internet-a-few-days-after-leak-internet-sleuths-claim-113gb-download-is-padded-malware-testers-claim-file-is-99-99-percent-empty-zeroes-with-50kb-virus-embedded</a><br />
<a href="https://securityaffairs.com/197772/malware/cybercriminals-turn-gta-vi-leaks-into-malware-bait.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/197772/malware/cybercriminals-turn-gta-vi-leaks-into-malware-bait.html</a></li>
<li><strong>Fake Microsoft Security Scans Trick Victims Into Uninstalling Their Antivirus</strong><br />
"A wave of websites is offering to check whether your antivirus is working. They call themselves SysScan, carry Microsoft branding, and all reach the same conclusion: Your computer has serious problems, and the cause is the antivirus software you installed. Windows, they claim, no longer supports third-party antivirus. Uninstall it immediately. That is false, and it is the first step in a refund scam designed to get victims onto the phone, remove their security software, and ultimately hand over personal, banking, and remote-access information."<br />
<a href="https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-microsoft-security-scans-trick-victims-into-uninstalling-their-antivirus" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-microsoft-security-scans-trick-victims-into-uninstalling-their-antivirus</a></li>
<li><strong>Tracking PavinLoader Across ClickFix And Fake Download Campaigns</strong><br />
"In our previous analysis of the malicious RenPy campaigns, we identified a multi-stage loader deployed as part of the infection chain. Further threat hunting has since shown that the same loader, which we track as PavinLoader, is being used across several different campaigns, including ClickFix attacks and fake software downloads. Despite differences in how these campaigns reach victims, we found several common elements."<br />
<a href="https://www.malwarebytes.com/blog/threat-intel/2026/08/tracking-pavinloader-across-clickfix-and-fake-download-campaigns" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/threat-intel/2026/08/tracking-pavinloader-across-clickfix-and-fake-download-campaigns</a></li>
<li><strong>Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats Via VHD-Delivered Go Backdoor</strong><br />
"Seqrite APT Team has been tracking threat activity across the globe, with a focus on campaigns targeting different industries and regions. During our recent research, we found a campaign targeting Myanmar that uses a Burmese-language graduation ceremony invitation from Myanmar’s Information Technology and Cyber Security Department as lure. The threat actor delivers the malware through a Virtual Hard Disk (VHD) file. While analyzing the VHD, we discovered several interesting artifacts. we also recovered files from the Recycle Bin that appear to have been unintentionally left behind by the threat actor. These overlooked files provided valuable context that helped us better understand the campaign’s attribution."<br />
<a href="https://www.seqrite.com/blog/operation-quicsilver-china-nexus-actor-targets-myanmar-diplomats-via-vhd-delivered-go-backdoor/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.seqrite.com/blog/operation-quicsilver-china-nexus-actor-targets-myanmar-diplomats-via-vhd-delivered-go-backdoor/</a><br />
<a href="https://thehackernews.com/2026/08/operation-quicsilver-targets-myanmar.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/operation-quicsilver-targets-myanmar.html</a></li>
<li><strong>Active Exploitation Of a Software Development Platform Within Australia</strong><br />
"The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has observed active exploitation of a vulnerability affecting TeamCity On-Premises servers within Australia. TeamCity is a Continuous Integration and Continuous Deployment (CI/CD) server to automate the processes of building, testing, and deploying software. CVE 2026-63077 may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands."<br />
<a href="https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/active-exploitation-of-a-software-development-platform-within-australia" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/active-exploitation-of-a-software-development-platform-within-australia</a></li>
<li><strong>Connecting The Dots: Securing The Overlooked Corners Of The Software Development Lifecycle (SDLC) Supply Chain</strong><br />
"While supply chain threats have been quietly compounding over the past decade, the last 12–18 months have triggered a drastic shift in the scale and velocity of these attacks. Rather than just hunting for bugs in finished software, attackers are targeting the everyday tools and code developers rely on. Unit 42 research shows this happening at every step of the building process. We've observed attackers spending years pretending to be helpful contributors just to hide backdoors in core software, as seen in the XZ Utils vulnerability (CVE-2024-3094). We've seen attackers hijack accounts to drop malware into popular libraries, like in the Axios supply chain attack. And we've seen them misuse setup scripts to automatically steal credentials using the Shai-Hulud npm worm."<br />
<a href="https://unit42.paloaltonetworks.com/sdlc-supply-chain/" target="_blank" rel="noopener noreferrer nofollow ugc">https://unit42.paloaltonetworks.com/sdlc-supply-chain/</a></li>
</ul>
<p dir="auto"><strong>General News</strong></p>
<ul>
<li><strong>July 2026 Threat Trend Report On Ransomware</strong><br />
"The July 2026 Threat Trend Report on Ransomware summarizes major Korean &amp; global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Statistics on targeted businesses were compiled based on information published on DLS (Dedicated Leak Sites, also referred to as ransomware PR sites or PR pages) operated by ransomware groups."<br />
<a href="https://asec.ahnlab.com/en/95112/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/95112/</a></li>
<li><strong>Treasury Launches Unprecedented Campaign Against Iranian Regime On Economic D-Day</strong><br />
"Today, at President Trump’s direction, the U.S. Department of the Treasury has begun Operation Economic Outcast: an unprecedented, whole-of-government, economic campaign against the Islamic Republic of Iran and its enablers. “In the Second World War, D-Day marked the historic beginning of a campaign with our allies to target and drive the enemy from its positions, including those in third countries. Today, in that same spirit, we are launching an economic onslaught against Iran’s financial connections around the globe."<br />
<a href="https://home.treasury.gov/news/press-releases/sb0613/" target="_blank" rel="noopener noreferrer nofollow ugc">https://home.treasury.gov/news/press-releases/sb0613/</a><br />
<a href="https://therecord.media/iran-cyberattacks-us-uk" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/iran-cyberattacks-us-uk</a><br />
<a href="https://cyberscoop.com/us-treasury-sanctions-iranian-hackers-economic-dday/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/us-treasury-sanctions-iranian-hackers-economic-dday/</a></li>
<li><strong>The Vulnerability Gap: Why Discovery Is Outrunning Repair</strong><br />
"For decades, finding a serious vulnerability in widely used open source software was specialized work. It took a skilled researcher weeks, sometimes months, to trace a flaw and responsibly bring it to a maintainer. That timeline has effectively collapsed. Advanced AI models can now produce vulnerability reports in hours, demolishing what a seasoned professional would have taken weeks to develop. That's not hypothetical: it's what the open source security community has watched happen since the fall of last year, as tools built on frontier models and strong open-weight models alike started turning out findings that are, frankly, good."<br />
<a href="https://www.darkreading.com/cybersecurity-operations/vulnerability-gap-why-discovery-is-outrunning-repair" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cybersecurity-operations/vulnerability-gap-why-discovery-is-outrunning-repair</a></li>
<li><strong>CISA Releases Foundational, Flexible Guidance To Help Federal Agencies Implement Effective Logging, Visibility And Operational Standards</strong><br />
"Today, the Cybersecurity and Infrastructure Security Agency (CISA) published the Logging Reference Architecture, an outcome-driven guide for federal civilian executive branch (FCEB) agencies to establish logging, visibility and operational standards in an Agency Logging Plan, as required in Office of Management and Budget (OMB) Memorandum M-26-14. Developed in collaboration with OMB and the Chief Information Security Officers (CISO) Council, this guidance implements a practical, risk-based, prioritized logging approach that improves agency network monitoring. In alignment with the objectives of M-26-14, CISA’s Logging Reference Architecture guidance directly helps agencies achieve priority logging capabilities that support continuous event monitoring, threat hunting, incident response, and forensics. Agencies will be able to utilize this guidance to update enterprise logging strategies, which will inform an Agency Logging Plan that agencies are required to submit to OMB and CISA by November 18, 2026. The M-26-14 Agency Logging Plan Template, provided by CISA, offers a structured format to streamline planning."<br />
<a href="https://www.cisa.gov/news-events/news/cisa-releases-foundational-flexible-guidance-help-federal-agencies-implement-effective-logging" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/news/cisa-releases-foundational-flexible-guidance-help-federal-agencies-implement-effective-logging</a><br />
<a href="https://www.cisa.gov/resources-tools/resources/logging-reference-architecture" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/resources-tools/resources/logging-reference-architecture</a><br />
<a href="https://www.cisa.gov/sites/default/files/2026-08/logging-reference-architecture.pdf" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/sites/default/files/2026-08/logging-reference-architecture.pdf</a><br />
<a href="https://www.helpnetsecurity.com/2026/08/24/cybersecurity-logging-guidelines-strategy/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/24/cybersecurity-logging-guidelines-strategy/</a></li>
<li><strong>New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims</strong><br />
"As organizations race to future-proof their systems against quantum-enabled attacks, questions remain around how to verify whether hardware is quantum-safe. A new industry benchmark aims to answer that question. The Trusted Computing Group (TCG) released new guidance on August 24 that helps prove that trusted platform modules (TPMs) genuinely meet essential PQC requirements. TCG is a nonprofit organization tasked with promoting vendor-neutral standards for hardware-based security products like TPMs."<br />
<a href="https://www.infosecurity-magazine.com/news/guidance-verify-quantum-safe/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/guidance-verify-quantum-safe/</a><br />
<a href="https://trustedcomputinggroup.org/is-your-tpm-truly-pqc-ready/" target="_blank" rel="noopener noreferrer nofollow ugc">https://trustedcomputinggroup.org/is-your-tpm-truly-pqc-ready/</a></li>
<li><strong>Multi-Cloud Architecture Challenges: Security And Compliance Implications</strong><br />
"NIST Internal Report (IR) 8613 ipd (initial public draft), Multi-Cloud Architecture Challenges, identifies, categorizes, and analyzes the security and compliance challenges that are unique to or significantly amplified by multi-cloud architectures. This analysis by the NIST Multi-Cloud Security Public Working Group (MCSPWG) addresses security and Authorization to Operate (ATO) challenges and highlights areas where additional community research could meaningfully reduce risk. The MCSPWG identified 23 consolidated challenge areas that represent novel friction points and architectural misalignments that emerge when orchestrating control across autonomous cloud silos."<br />
<a href="https://csrc.nist.gov/pubs/ir/8613/ipd" target="_blank" rel="noopener noreferrer nofollow ugc">https://csrc.nist.gov/pubs/ir/8613/ipd</a><br />
<a href="https://www.infosecurity-magazine.com/news/nist-risks-multi-cloud/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/nist-risks-multi-cloud/</a></li>
<li><strong>Hired For One Job, Judged On Another: The CISO’s Real Problem</strong><br />
"Industry surveys have long put CISO tenure below that of other C-suite roles, and part of the reason is a double standard. During recruitment, the focus is technical depth, security experience, and leadership. But when budget season arrives and the board weighs a leader’s performance, the lens is cost, growth, customer trust, and brand protection. Many CISOs feel this acutely. They came up through security, or through risk and compliance, and that is where they are fluent. Their board is not. It wakes up thinking about cost, growth, and customer commitments, and a security leader who cannot connect their work to that language will be seen as important, but rarely as strategic."<br />
<a href="https://www.securityweek.com/hired-for-one-job-judged-on-another-the-cisos-real-problem/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/hired-for-one-job-judged-on-another-the-cisos-real-problem/</a></li>
</ul>
<p dir="auto"><strong>อ้างอิง</strong><br />
Electronic Transactions Development Agency (ETDA) <img src="/assets/uploads/files/1787645268322-34425d3f-e25e-4d0e-9986-33f5ddb7307d-image.png" alt="34425d3f-e25e-4d0e-9986-33f5ddb7307d-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3220/cyber-threat-intelligence-25-august-2026</link><generator>RSS for Node</generator><lastBuildDate>Tue, 25 Aug 2026 12:47:16 GMT</lastBuildDate><atom:link href="https://webboard-nsoc.ncsa.or.th/topic/3220.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 25 Aug 2026 08:07:49 GMT</pubDate><ttl>60</ttl></channel></rss>