<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cyber Threat Intelligence 27 August 2026]]></title><description><![CDATA[<p dir="auto"><strong>Industrial Sector</strong></p>
<ul>
<li><strong>CISA: Over 100 Internet-Exposed Water Systems Targeted In July Cyberattacks</strong><br />
"The Cybersecurity and Infrastructure Security Agency (CISA) says it’s aware of 100 internet-exposed water systems targeted in cyberattacks in July. The information was shared as part of guidance released by CISA to help organizations reduce the internet exposure of systems that could be targeted by threat actors. “In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem,” CISA noted."<br />
<a href="https://www.securityweek.com/cisa-over-100-internet-exposed-water-systems-targeted-in-july-cyberattacks/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/cisa-over-100-internet-exposed-water-systems-targeted-in-july-cyberattacks/</a><br />
<a href="https://www.cisa.gov/resources-tools/resources/exposure-reduction" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/resources-tools/resources/exposure-reduction</a><br />
<a href="https://www.bankinfosecurity.com/attackers-targeted-over-100-us-water-systems-in-july-hacks-a-32659" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/attackers-targeted-over-100-us-water-systems-in-july-hacks-a-32659</a></li>
</ul>
<p dir="auto"><strong>Vulnerabilities</strong></p>
<ul>
<li><strong>Wordfence Argus Finds Complex 6 Step Critical RCE In Avada Theme With 1 Million Sales</strong><br />
"A year ago we wrote that we’d put AI to work across the whole company, turning everyone on the team into a capable AI operator so our defenders could stay ahead of the threat actors attacking the sites we protect. In April we showed where it was heading: in the space of a few months, AI-assisted reports to our bug bounty program had gone from 16% to about two-thirds of everything we received, and it wasn’t slowing down. As we continue to see AI driven innovation in cybersecurity, the Wordfence team continues to accelerate our own pace of AI enabled innovation. PRISM, our autonomous research agent, is now the most prolific researcher we have, with over 300 vulnerabilities to its name and the top spot on our leaderboard over the last 30 days."<br />
<a href="https://www.wordfence.com/blog/2026/08/wordfence-argus-finds-complex-6-step-critical-rce-in-avada-theme-with-1-million-sales/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.wordfence.com/blog/2026/08/wordfence-argus-finds-complex-6-step-critical-rce-in-avada-theme-with-1-million-sales/</a><br />
<a href="https://www.bleepingcomputer.com/news/security/critical-avada-wordpress-theme-flaw-enables-zero-click-rce/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/critical-avada-wordpress-theme-flaw-enables-zero-click-rce/</a></li>
<li><strong>Ubiquiti Patches Three Max Severity Security Vulnerabilities</strong><br />
"Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. The first (tracked as CVE-2026-77537) lets unauthenticated attackers compromise unpatched devices by exploiting an improper input validation weakness in the UniFi Protect Application video surveillance management platform. Ubiquiti also addressed a CRLF injection flaw (CVE-2026-77550) that remote attackers without privileges can exploit to bypass authentication on UniFi OS devices or instances."<br />
<a href="https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-security-vulnerabilities/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-security-vulnerabilities/</a><br />
<a href="https://cyberscoop.com/ubiquiti-unifi-critical-vulnerabilities-patched/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/ubiquiti-unifi-critical-vulnerabilities-patched/</a></li>
<li><strong>Adobe And Nvidia Patch Dozens Of Vulnerabilities</strong><br />
"Adobe and Nvidia on Tuesday announced patches for dozens of vulnerabilities affecting their products, including flaws rated critical severity."<br />
<a href="https://www.securityweek.com/adobe-and-nvidia-patch-dozens-of-vulnerabilities/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/adobe-and-nvidia-patch-dozens-of-vulnerabilities/</a></li>
<li><strong>Chrome 152 Patches Over 300 Vulnerabilities</strong><br />
"Google on Tuesday announced the release of Chrome 152, with patches for more than 300 vulnerabilities, the majority of which were discovered internally using AI. Ten vulnerabilities have been assigned a critical severity rating. Most are use-after-free issues in components such as Angle, Aura, Chromecast, Views, and SafeBrowsing. Sixty-one flaws have been rated as high severity, while the rest have medium or low severity."<br />
<a href="https://www.securityweek.com/chrome-152-patches-over-300-vulnerabilities/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/chrome-152-patches-over-300-vulnerabilities/</a><br />
<a href="https://www.malwarebytes.com/blog/bugs/2026/08/update-chrome-before-you-browse-again" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/bugs/2026/08/update-chrome-before-you-browse-again</a></li>
<li><strong>Not Another Log4Shell: A Serialized-Event Receiver Boundary</strong><br />
"An upstream report raised an alarming possibility: a class filter around Log4j2’s Java-serialized event receiver could approve an outer event and still lose control of what was deserialized inside it. The report then disappeared before final vendor guidance was available, leaving two bad options: dismiss an unverified claim, or repeat the phrase “Log4j RCE” without knowing what it actually applied to. We chose a third option. Pruva reconstructed the boundary, exercised the real Apache sample TCP receiver, and ran the same network input against vulnerable and controlled targets. The result was receiver-side command execution in two fresh JVMs. It was also much narrower than the phrase “the next Log4Shell” suggests."<br />
<a href="https://www.pruva.dev/research/log4j2-serialized-event-filter-boundary" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.pruva.dev/research/log4j2-serialized-event-filter-boundary</a><br />
<a href="https://www.pruva.dev/reproductions/REPRO-2026-00338" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.pruva.dev/reproductions/REPRO-2026-00338</a></li>
<li><strong>CISA Adds Six Known Exploited Vulnerabilities To Catalog</strong><br />
"CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.<br />
CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability<br />
CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability<br />
CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability<br />
CVE-2021-23758 <a href="http://Ajax.NET" target="_blank" rel="noopener noreferrer nofollow ugc">Ajax.NET</a> Professional Deserialization of Untrusted Data Vulnerability<br />
CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability<br />
CVE-2026-8452 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability"<br />
<a href="https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog</a></li>
<li><strong>New GPUThor Attack Defeats NVIDIA ECC Protection For Root Access</strong><br />
"A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. In a paper published by the University of Toronto, researchers say that GPUThor achieves far more practical bit-flip rates than past concepts like their own GPUHammer or GPUBreach, which became irrelevant after ECC was introduced. The attack was demonstrated against Ampere-class NVIDIA workstation GPUs with GDDR6 memory, including the RTX A4000, RTX A4500, RTX A5000, and RTX A6000, all widely used in AI and cloud infrastructure."<br />
<a href="https://www.bleepingcomputer.com/news/security/new-gputhor-attack-defeats-nvidia-ecc-protection-for-root-access/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/new-gputhor-attack-defeats-nvidia-ecc-protection-for-root-access/</a><br />
<a href="https://gururaj-s.github.io/assets/pdf/CCS26_GPUThor.pdf" target="_blank" rel="noopener noreferrer nofollow ugc">https://gururaj-s.github.io/assets/pdf/CCS26_GPUThor.pdf</a><br />
<a href="https://gputhor.com/" target="_blank" rel="noopener noreferrer nofollow ugc">https://gputhor.com/</a></li>
<li><strong>Remote Code Execution And Arbitrary File Read Vulnerabilities In Kaltura Servers</strong><br />
"The Kaltura HTML5 Player Library (mwEmbed / html5lib) contains two vulnerabilities, both involving the same insecure deserialization flaw, that enable arbitrary file read and remote code execution. Affected versions include html5lib v2.45, v2.103 and earlier, and other v2.x releases that expose the vulnerable mwEmbedLoader.php endpoint. Until a vendor patch is available, users are advised to restrict access to the affected endpoint or disable it entirely."<br />
<a href="https://www.kb.cert.org/vuls/id/308749" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.kb.cert.org/vuls/id/308749</a><br />
<a href="https://thehackernews.com/2026/08/unpatched-kaltura-mwembed-flaws-could.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/unpatched-kaltura-mwembed-flaws-could.html</a></li>
<li><strong>Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations In Tests</strong><br />
"Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an OpenClaw agent running Opus 4.6 to book him into a gym class. The agent booked sessions months beyond the window the site allowed."<br />
<a href="https://thehackernews.com/2026/08/claude-opus-46-bypasses-gym-booking.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/claude-opus-46-bypasses-gym-booking.html</a></li>
</ul>
<p dir="auto"><strong>Malware</strong></p>
<ul>
<li><strong>Tortoiseshell: New Toolset And Operational Infrastructure Exposed</strong><br />
"Group-IB Threat Intelligence began investigating Tortoiseshell activity following public reporting by Kaspersky (Securelist). Through enrichment of the reported indicators and our own hunting rules, we identified additional infrastructure, broader targeting, and previously unreported malware samples associated with the group. Tortoiseshell is an Iranian-linked threat actor that has been active since at least 2018, primarily targeting defence, aerospace, IT service providers, and military organisations in the Middle East and the United States. The group is known for its use of supply chain compromises, watering hole attacks, fake recruitment websites, and custom backdoors, and has been linked to operations supporting Iran’s Islamic Revolutionary Guard Corps (IRGC)."<br />
<a href="https://www.group-ib.com/blog/tortoiseshell-apt-toolset-infrastructure/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.group-ib.com/blog/tortoiseshell-apt-toolset-infrastructure/</a><br />
<a href="https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html</a><br />
<a href="https://therecord.media/iran-linked-hackers-expand-infrastructure-europe-middle-east" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/iran-linked-hackers-expand-infrastructure-europe-middle-east</a><br />
<a href="https://www.infosecurity-magazine.com/news/tortoiseshell-new-backdoor-ssh/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/tortoiseshell-new-backdoor-ssh/</a></li>
<li><strong>Beware Of Fake Indeed Interview Apps Used To Install Spyware</strong><br />
"From several independent reports, we’ve seen evidence of scammers using fake Android “interview” apps to target job seekers on the Indeed platform. Indeed is one of the world’s largest employment websites, giving scammers access to a huge pool of potential victims, especially in a competitive job market."<br />
<a href="https://www.malwarebytes.com/blog/scams/2026/08/beware-of-fake-indeed-interview-apps-used-to-install-spyware" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/scams/2026/08/beware-of-fake-indeed-interview-apps-used-to-install-spyware</a></li>
<li><strong>Hackers Target Microsoft SharePoint RCE Chain With PoC Exploit</strong><br />
"Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. The first (tracked as CVE-2026-55040) is an authentication bypass flaw in the JWT token validation pipeline that attackers without privileges can exploit to perform operations as a SharePoint site user or administrator. The second (CVE-2026-63520) is a vulnerability in SharePoint's Business Connectivity Services (BCS) that unauthenticated attackers can chain after successfully exploiting CVE-2026-55040 for remote code execution (RCE) on a targeted SharePoint Server."<br />
<a href="https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/</a></li>
<li><strong>Dark Caracal Reloaded: New Malware, Same Hunting Grounds</strong><br />
"In June 2026, Arctic Wolf Labs investigated a targeted intrusion affecting a communications organization in Venezuela. We assess with medium confidence that this activity is linked to Dark Caracal, a cyberespionage group associated with Lebanon’s General Directorate of General Security (GDGS) that has historically targeted governments, businesses, journalists, and activists. The intrusion used delivery methods consistent with the SVG-based Dark Caracal campaign previously documented by Kaspersky, but the malware deployed after initial access was different. Arctic Wolf Labs identified a previously undocumented, modular Go-based framework that we call GoCaracal, deployed alongside an updated variant of Bandook."<br />
<a href="https://arcticwolf.com/resources/blog/dark-caracal-reloaded-new-malware-same-hunting-grounds/" target="_blank" rel="noopener noreferrer nofollow ugc">https://arcticwolf.com/resources/blog/dark-caracal-reloaded-new-malware-same-hunting-grounds/</a><br />
<a href="https://www.darkreading.com/cyberattacks-data-breaches/dark-caracal-adds-new-malware-cyber-espionage-arsenal" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cyberattacks-data-breaches/dark-caracal-adds-new-malware-cyber-espionage-arsenal</a></li>
<li><strong>Insights Into Suspected DPRK Workers: Red Flags To Look Out For</strong><br />
"North Korean workers (sometimes referred to as FAMOUS CHOLLIMA) have significantly improved and increased their activity over the past few years. These actors will pretend to be legitimate workers, apply for remote positions at companies, and once hired and onboarded funnel wages back to the North Korean regime in an effort to help North Korea generate revenue while evading international sanctions. Some public reports also cite DPRK workers infiltrating companies to exfiltrate data, deploy malware, or extort their employers once discovered."<br />
<a href="https://www.huntress.com/blog/huntress-dprk-remote-worker-investigation" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.huntress.com/blog/huntress-dprk-remote-worker-investigation</a><br />
<a href="https://www.darkreading.com/insider-threats/red-flags-expose-fake-north-korean-it-workers" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/insider-threats/red-flags-expose-fake-north-korean-it-workers</a></li>
<li><strong>NovaCookies At Scale: Inside The $320 Phishing Service Targeting Hundreds Of Organizations</strong><br />
"Advertised at $320 a month, NovaCookies packages real-time Microsoft 365 session theft as a subscription phishing service. Campaign artifacts reviewed across our research sources show hundreds of organizations targeted across multiple regions, while the service’s infrastructure expanded sharply from mid-May and continued appearing through August 2026. Nearly 90% of the organizations in the reviewed set were associated with lures hosted on .vu domains. A companion IOC release documents 755 domains assessed as dedicated malicious infrastructure."<br />
<a href="https://www.island.io/blog/novacookies-at-scale-inside-the-320-phishing-service-targeting-hundreds-of-organizations" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.island.io/blog/novacookies-at-scale-inside-the-320-phishing-service-targeting-hundreds-of-organizations</a><br />
<a href="https://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html</a><br />
<a href="https://www.darkreading.com/endpoint-security/novacookies-steals-microsoft-365-sessions-320-a-month" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/endpoint-security/novacookies-steals-microsoft-365-sessions-320-a-month</a></li>
<li><strong>ModeloRAT Malware: How The CrashFix Campaign Delivers a Python RAT</strong><br />
"ModeloRAT is a Python-based Windows Remote Access Trojan first observed in January 2026, delivered only to domain-joined hosts in enterprise environments where a single foothold opens the way to Active Directory and lateral movement. It arrives as the final payload of the CrashFix campaign, which starts with a malicious Chrome extension named NexShield that crashes the victim's browser on purpose, then displays a fake repair prompt that talks the user into running an attacker-supplied command [1]. In this blog, we explain how ModeloRAT works and how to validate your security controls against this malware."<br />
<a href="https://www.picussecurity.com/resource/blog/modelorat-malware-how-the-crashfix-campaign-delivers-a-python-rat" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.picussecurity.com/resource/blog/modelorat-malware-how-the-crashfix-campaign-delivers-a-python-rat</a></li>
<li><strong>‘The Gentlemen’ Profile: Why This Ransomware Group Wants In Before It Locks You Out</strong><br />
"The Gentlemen is a financially motivated ransomware group that combines data theft with encryption to increase pressure on victims. They first came onto the threat scene in July 2025. Rather than relying on encryption alone, the group exfiltrates sensitive business data before locking files, leaving organizations to deal with both operational disruption and the risk of stolen information being exposed."<br />
<a href="https://www.bitsight.com/blog/the-gentlemen-ransomware-group-threat-actor-deep-dive" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bitsight.com/blog/the-gentlemen-ransomware-group-threat-actor-deep-dive</a></li>
</ul>
<p dir="auto"><strong>Breaches/Hacks/Leaks</strong></p>
<ul>
<li><strong>An ID Check Breach Timeline: 2011–2026</strong><br />
"Every year, more of the internet demands that you prove who you are before you may use it: KYC checks to open an account, a driver’s license to join a dating app, a passport scan to check into a hotel, a face scan to read an adult site in the UK, a government ID to appeal a Discord ban. Every one of those checks creates a copy of the most permanent data you have. This timeline compiles what happened to those copies. We found 88 publicly documented incidents since 2011 in which data collected specifically to verify identity or age – government ID scans, verification selfies, biometric templates, KYC files, national ID registries – was breached, exposed, or put up for sale."<br />
<a href="https://www.mysteriumvpn.com/blog/data-and-research/id-check-breach-timeline" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.mysteriumvpn.com/blog/data-and-research/id-check-breach-timeline</a><br />
<a href="https://securityaffairs.com/197855/reports/88-id-verification-breaches-show-the-cost-of-collecting-identity-data.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/197855/reports/88-id-verification-breaches-show-the-cost-of-collecting-identity-data.html</a></li>
<li><strong>Boston Scientific Says Cyberattack Disrupted Operations Globally</strong><br />
"Medical technology company Boston Scientific has been targeted in a cyberattack that disrupted some of its IT systems, causing operational disruptions globally. The company detected the incident on August 25 and says in an announcement today that it caused a network outage and "impacted access to certain operating systems and business applications, including the ability to process and ship customer orders." After identifying the intrusion, Boston Scientific activated its incident response procedures and contracted external cybersecurity experts to investigate the impact and help with containment efforts."<br />
<a href="https://www.bleepingcomputer.com/news/security/boston-scientific-says-cyberattack-disrupted-operations-globally/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/boston-scientific-says-cyberattack-disrupted-operations-globally/</a><br />
<a href="https://therecord.media/boston-scientific-cyberattack-disrupts-shipment-processes" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/boston-scientific-cyberattack-disrupts-shipment-processes</a><br />
<a href="https://www.bankinfosecurity.com/cyberattack-disrupts-boston-scientifics-global-operations-a-32660" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/cyberattack-disrupts-boston-scientifics-global-operations-a-32660</a></li>
</ul>
<p dir="auto"><strong>General News</strong></p>
<ul>
<li><strong>SOC Threat Radar — August 2026</strong><br />
"CVE-2026-0257 is a vulnerability affecting Palo Alto’s OS-agnostic GlobalProtect services. Successful exploitation could allow an attacker to bypass normal authentication controls, establish a VPN session as if they were a legitimate user, gain access to internal resources reachable through the VPN, and create a foothold for further activity such as reconnaissance, credential theft or lateral movement. Barracuda Managed XDR’s SOC team has detected two waves of inbound scanning activity originating from known attacker infrastructure and targeting publicly exposed GlobalProtect services in Belgium. The attackers are likely to be probing for vulnerable or unpatched systems following public disclosure of the CVE."<br />
<a href="https://blog.barracuda.com/2026/08/26/soc-threat-radar-august-2026-remote-access-threats" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.barracuda.com/2026/08/26/soc-threat-radar-august-2026-remote-access-threats</a></li>
<li><strong>Production Data In Testing Is Still Common, And Tricentis’ CISO Wants It Gone</strong><br />
"In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught a prompt injection gap in red-teaming and held a release for a week until it was fixed. Dean describes what gets an AI vendor rejected, mostly vague answers about where data lives and how long it is kept. She also lists three things a small security team should build first, even with limited headcount."<br />
<a href="https://www.helpnetsecurity.com/2026/08/26/erika-dean-tricentis-production-data-in-testing/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/26/erika-dean-tricentis-production-data-in-testing/</a></li>
<li><strong>AI Vulnerability Discovery Scores The Highest Impact Of 20 Emerging Risks</strong><br />
"Risk managers, auditors and senior executives at 316 companies spent April and May ranking 20 threats they have not yet felt. AI discovery of cyber vulnerabilities came back first, according to Gartner. Three months earlier the same quarterly survey put information integrity risk at the top and left AI vulnerability discovery out of the top five. Two things changed underneath that number. AI systems scan for previously unknown flaws at a volume no patching team can absorb, and the step from finding a flaw to holding working attack code has shrunk to close to nothing. Writing the exploit used to be the part that kept most attackers out. It no longer is. A defender inherits a backlog of unpatched critical vulnerabilities growing faster than it can be cleared, inside systems that AI integration has made harder to see into."<br />
<a href="https://www.helpnetsecurity.com/2026/08/26/ai-vulnerability-discovery-emerging-risks/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/26/ai-vulnerability-discovery-emerging-risks/</a></li>
<li><strong>CISA Vulnerability Review</strong><br />
"Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the risk they pose. The CISA Vulnerability Review provides organizations with critical insights into the root causes of insecure software and practical steps they can take to address these flaws to prevent exploitation. Analyzing CISA and open source data from fiscal years 2024 and 2025, the review establishes a baseline of today’s vulnerability landscape before AI-enabled vulnerability discovery becomes more widespread."<br />
<a href="https://www.cisa.gov/resources-tools/resources/cisa-vulnerability-review" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/resources-tools/resources/cisa-vulnerability-review</a><br />
<a href="https://www.cisa.gov/sites/default/files/2026-08/cisa-vulnerability-review-fy-2024-2025.pdf" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/sites/default/files/2026-08/cisa-vulnerability-review-fy-2024-2025.pdf</a><br />
Justice Department And FBI Seize Platforms Operated And Used By China State-Sponsored Hackers * <strong>To Target U.S. Critical Infrastructure</strong><br />
"The Justice Department and FBI announced court-authorized domain seizures today to deny malicious cyber actors access to two complementary hacking platforms known as “QScan” and “QTRouter,” used to target U.S. critical infrastructure and other sensitive networks. As described in court documents unsealed in the Southern District of California, a People’s Republic of China (PRC) state-sponsored group known as “QTFY,” employed by China-based Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司), created and operated QScan and QTRouter. Among the victims of QTFY computer intrusion activity are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate."<br />
<a href="https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers</a><br />
<a href="https://www.bleepingcomputer.com/news/security/fbi-disrupts-proxy-network-enabling-chinese-espionage-operations/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/fbi-disrupts-proxy-network-enabling-chinese-espionage-operations/</a><br />
<a href="https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html</a><br />
<a href="https://therecord.media/qscan-qtrouter-us-takedown-alleged-china-hacking-tools" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/qscan-qtrouter-us-takedown-alleged-china-hacking-tools</a><br />
<a href="https://www.bankinfosecurity.com/fbi-doj-seize-chinese-hacker-infrastructure-on-us-soil-a-32658" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/fbi-doj-seize-chinese-hacker-infrastructure-on-us-soil-a-32658</a><br />
<a href="https://cyberscoop.com/qtfy-china-espionage-group-infrastructure-seized/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/qtfy-china-espionage-group-infrastructure-seized/</a><br />
<a href="https://securityaffairs.com/197873/apt/fbi-seizes-china-linked-hacking-platforms-qscan-and-qtrouter-used-against-critical-infrastructure.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/197873/apt/fbi-seizes-china-linked-hacking-platforms-qscan-and-qtrouter-used-against-critical-infrastructure.html</a></li>
<li><strong>German Industry Reports Escalating Nation-State Cyberattacks</strong><br />
"German businesses are increasingly under attack from hackers with links to foreign intelligence services, according to a major new study from digital industry association Bitkom. And that shift is clouding businesses' visibility into their own vulnerability. Bitkom's research arm polled over a thousand companies with 10 or more employees and annual German revenues of at least a million euros, and found that almost all - 96% - had either definitely or likely been affected by data theft, industrial espionage or sabotage in the last year."<br />
<a href="https://www.bankinfosecurity.com/german-industry-reports-escalating-nation-state-cyberattacks-a-32657" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/german-industry-reports-escalating-nation-state-cyberattacks-a-32657</a></li>
<li><strong>Understanding Browser Trust Abuse: Exploiting Enterprise’s Most Trusted Interface</strong><br />
"The biggest change in browser-related threats is not a new flaw in browser software. It is a shift in how threat actors operate. Instead of breaking into the browser, they increasingly trick the people using it by exploiting the trust employees place in familiar browser experiences and workflows. By mimicking legitimate login screens, software update prompts, authentication requests, and security checks that people see every day, threat actors persuade users to disclose credentials, grant access to their computers, or install malware. As a result, any browser-enabled device can become a target, making browser patching alone insufficient to prevent these attacks."<br />
<a href="https://cofense.com/blog/understanding-browser-trust-abuse-exploiting-enterprise-s-most-trusted-interface" target="_blank" rel="noopener noreferrer nofollow ugc">https://cofense.com/blog/understanding-browser-trust-abuse-exploiting-enterprise-s-most-trusted-interface</a></li>
<li><strong>Four In Five AI Tools Run With No IT Oversight, New Research Finds</strong><br />
"Security researchers have warned that major gaps in IT oversight, surging numbers of published vulnerabilities, and MCP security risks are making the AI agent ecosystem increasingly risky. AI security vendor Reco analyzed anonymized platform telemetry from large enterprises, publicly available Model Context Protocol servers, and vulnerability disclosures from the National Vulnerability Database to compile its report, The State of Agent Security 2026. It found that 80% of AI tools operate with no oversight, while in SMBs, there are an estimated 414 unsanctioned tools per 1000 employees."<br />
<a href="https://www.infosecurity-magazine.com/news/four-in-five-ai-tools-no-it/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/four-in-five-ai-tools-no-it/</a><br />
<a href="https://www.reco.ai/state-of-agent-security-2026-form" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.reco.ai/state-of-agent-security-2026-form</a></li>
<li><strong>Average Cyber Insurance Losses Increase Despite Fewer Claims</strong><br />
"The average cost of cybersecurity insurance claims made by large and middle-market companies surged in 2025, despite a significant drop in the volume of claims, according to Chubb’s 2026 Cyber Claims Report. The insurer said the growing severity of claims in the US has been largely driven by the increasing cost of both data breach and privacy-related litigation, alongside rising business interruption expenses. In the US, the average cost of claims rose by 22% for middle-market firms in 2025 compared to 2024, while for large companies, an enormous 100% rise was observed."<br />
<a href="https://www.infosecurity-magazine.com/news/cyber-insurance-losses-increase/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/cyber-insurance-losses-increase/</a></li>
<li><strong>Exploits And Vulnerabilities In Q2 2026</strong><br />
"The vulnerability landscape shifted significantly in Q2 2026. First, the number of registered CVEs reached an unprecedented level. This is driven primarily by the widespread adoption of AI, both for application development and search for security flaws. This resulted in entire new classes of vulnerabilities emerging, particularly in the Linux networking subsystem. Second, security researchers have been publishing exploits for unpatched vulnerabilities more frequently. Publications like these can generate significant fallout, since they potentially open the door for attackers to target unprotected systems."<br />
<a href="https://securelist.com/vulnerabilities-and-exploits-in-q2-2026/121091/" target="_blank" rel="noopener noreferrer nofollow ugc">https://securelist.com/vulnerabilities-and-exploits-in-q2-2026/121091/</a></li>
<li><strong>The MFA Identity Trap: When Authentication Creates a False Sense Of Security</strong><br />
"Multi-factor authentication (MFA) has become one of cybersecurity’s most important controls. Roughly 70% of enterprise workforce users are now protected by it. But its success has created an unintended problem. Organizations increasingly treat successful authentication as proof of identity. They assume that because someone passed MFA, they have verified who that person is. They may also assume that the identity itself has not been compromised. Neither is it necessarily true."<br />
<a href="https://www.securityweek.com/the-mfa-identity-trap-when-authentication-creates-a-false-sense-of-security/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/the-mfa-identity-trap-when-authentication-creates-a-false-sense-of-security/</a></li>
<li><strong>Software Supply Chain Security Requires Decisions Rather Than Defaults</strong><br />
"A bridge stays in service for fifty years on a fixed inspection schedule, load-tested and maintained the entire time. A jet engine flies the same design for decades under continuous regulatory oversight. In most engineering disciplines, a stable, proven design paired with active maintenance is the goal. Newer designs are treated with far more scrutiny, because they’ve never been truly tested. But for some reason, in software engineering, the opposite is true. The newest release is treated as the safest. And that instinct has backfired badly in the past. A backdoor sat inside two specific releases of xz-utils, versions 5.6.0 and 5.6.1, planted by an infiltrator who’d spent two to three years plotting up release authority."<br />
<a href="https://www.aikido.dev/blog/software-supply-chain-security-decisions-not-defaults" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.aikido.dev/blog/software-supply-chain-security-decisions-not-defaults</a></li>
<li><strong>Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense</strong><br />
"Mexico faces an increasingly complex cyber threat landscape, including ransomware, state-sponsored espionage, financial malware, data breaches, hacktivism, and cyber-enabled organized crime. Its 2025–2030 National Cybersecurity Plan seeks to address these challenges through stronger governance, new legislation, a national operations center, integrated incident-response teams, cyber exercises, AI-enabled defenses, and expanded regional cooperation. Insikt Group assesses ransomware as the leading threat while highlighting growing risks from foreign threat actors and credential theft. We recommend leveraging threat intelligence, applying international security frameworks, and fostering cyber education. Ultimately, Mexico’s progress will depend on turning an ambitious roadmap into durable institutions, effective regulation, and sustained international cooperation."<br />
Priority: 3 - Important<br />
Relevance: General<br />
<a href="https://www.recordedfuture.com/blog/mexico-cybersecurity-plan" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.recordedfuture.com/blog/mexico-cybersecurity-plan</a></li>
</ul>
<p dir="auto"><strong>อ้างอิง</strong><br />
Electronic Transactions Development Agency (ETDA) <img src="/assets/uploads/files/1787821273617-c6ab90db-397c-47af-8b2e-3926426af603-image.png" alt="c6ab90db-397c-47af-8b2e-3926426af603-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3228/cyber-threat-intelligence-27-august-2026</link><generator>RSS for Node</generator><lastBuildDate>Thu, 27 Aug 2026 11:41:17 GMT</lastBuildDate><atom:link href="https://webboard-nsoc.ncsa.or.th/topic/3228.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 27 Aug 2026 09:01:30 GMT</pubDate><ttl>60</ttl></channel></rss>