<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cyber Threat Intelligence 28 August 2026]]></title><description><![CDATA[<p dir="auto"><strong>Industrial Sector</strong></p>
<ul>
<li><strong>Xiiaozet LK100W</strong><br />
"Successful exploitation of these vulnerabilities could allow an attacker to take control over the device."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01</a></li>
<li><strong>Applied Systems Engineering ASE2000 V2 Communications Test Set</strong><br />
"Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-04" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-04</a></li>
<li><strong>Ebyte NA111-M</strong><br />
"Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-05" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-05</a></li>
<li><strong>All-Line Equipment Company Fuel-Boss</strong><br />
"Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-02" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-02</a></li>
<li><strong>Rockwell Automation OTTO Fleet Manager</strong><br />
"Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes."<br />
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-03" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-03</a></li>
</ul>
<p dir="auto"><strong>Vulnerabilities</strong></p>
<ul>
<li><strong>PaperCut Warns Of NG, MF Flaw Exploited In Zero-Day Attacks</strong><br />
"PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company says it is aware of confirmed attacks on customers and is urging organizations with Internet-exposed PaperCut Application Servers to immediately restrict access to the web interfaces to trusted IP addresses. "PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF," reads an urgent security advisory published Thursday."<br />
<a href="https://www.bleepingcomputer.com/news/security/papercut-warns-of-ng-mf-flaw-exploited-in-zero-day-attacks/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/papercut-warns-of-ng-mf-flaw-exploited-in-zero-day-attacks/</a><br />
<a href="https://www.helpnetsecurity.com/2026/08/27/papercut-ng-mf-vulnerability-attack/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/27/papercut-ng-mf-vulnerability-attack/</a></li>
<li><strong>Next.js Patches Critical AVIF And Windows Flaws Enabling Unauthenticated RCE</strong><br />
"Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE-2026-75604 (CVSS score: 9.0), affects Next.js applications that use both the Pages Router and App Router without Cache Components when the server uses a Windows filesystem."<br />
<a href="https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html</a></li>
<li><strong>CISA Adds Three Known Exploited Vulnerabilities To Catalog</strong><br />
"CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.<br />
CVE-2023-49105 ownCloud Improper Authentication Vulnerability<br />
CVE-2026-53362 Linux Kernel Unspecified Vulnerability<br />
CVE-2026-66384 JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability"<br />
<a href="https://www.cisa.gov/news-events/alerts/2026/08/27/cisa-adds-three-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/alerts/2026/08/27/cisa-adds-three-known-exploited-vulnerabilities-catalog</a></li>
<li><strong>Power Leak: Amazon Kiro IDE Prompt Injection Enables Data Exfiltration</strong><br />
"Mindgard discovered a data-exfiltration vulnerability in Amazon Kiro IDE , an AI-assisted development environment that can interact with project content and invoke tools as part of developer workflows. The issue allowed attacker-controlled repository content to influence the Kiro agent and ultimately cause sensitive local information to be transmitted to an external endpoint. Testing was performed against Kiro IDE version 0.7.45 on Windows, and the behavior was reproduced in both trusted and untrusted workspaces."<br />
<a href="https://mindgard.ai/blog/amazon-kiro-data-exfiltration" target="_blank" rel="noopener noreferrer nofollow ugc">https://mindgard.ai/blog/amazon-kiro-data-exfiltration</a><br />
<a href="https://thehackernews.com/2026/08/amazon-kiro-prompt-injection-can.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/amazon-kiro-prompt-injection-can.html</a></li>
</ul>
<p dir="auto"><strong>Malware</strong></p>
<ul>
<li><strong>Carry-On Compromise: TA4922 Packs PackClient</strong><br />
"Proofpoint researchers recently discovered a RAT framework we named PackClient. PackClient is being used by at least one threat actor, Chinese-speaking TA4922, and appears to be actively sold on Telegram. PackClient is a full featured, modular command and control (C2) framework that supports data theft, surveillance, and downloading of additional plugins and payloads."<br />
<a href="https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient</a><br />
<a href="https://www.bankinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670</a></li>
<li><strong>JavaScript Obfuscation: From Party Trick To Phishing Kit</strong><br />
"We open a JavaScript artifact hoping for code, and instead get string arrays, strangely named functions, encoded URLs, runtime decoders, and eval statements. That is the point where “reading the script” stops being enough. Obfuscated JavaScript is still code, but it is code with the useful context stripped out, the names ruined, the strings hidden, and the real behavior pushed into runtime. It shows up in phishing pages, malware loaders, sketchy browser scripts, and occasionally in legitimate software protection that has wandered into suspicious-looking territory. Over the last few years, I’ve spent a fair amount of time pulling apart suspicious JavaScript from phishing kits, malware packages, compromised sites, and other places where the readable source has been deliberately buried. I might not be a world-class JavaScript reverser, but I’ve learned enough useful tricks to make the mess explain itself."<br />
<a href="https://blog.talosintelligence.com/javascript-obfuscation-from-party-trick-to-phishing-kit/" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.talosintelligence.com/javascript-obfuscation-from-party-trick-to-phishing-kit/</a></li>
<li><strong>One Adversary, Two Outcomes: The 0.027% Proof</strong><br />
"Strip away the architecture debates and one question remains: does Cyber-Fraud Fusion change outcomes by enough to matter? The fairest way to answer is a natural experiment: one live criminal campaign, hitting many institutions at once, some running a fused defence and some not. Between July 2025 and January 2026, exactly that experiment ran across Indonesia. The campaign, operated by a Chinese-speaking threat cluster tracked as GoldFactory, targeted taxpayers by impersonating the national tax platform: a service with 67 million registered users and, crucially, no official mobile app, so citizens had no reference point for spotting fakes."<br />
<a href="https://www.group-ib.com/blog/one-adversary-two-outcomes-0027-proof/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.group-ib.com/blog/one-adversary-two-outcomes-0027-proof/</a></li>
<li><strong>Chinese Hacker Group QTFY Uses Custom-Built Platforms To Target US Infrastructure, FBI Warns</strong><br />
"A sophisticated Chinese hacking group known as QTFY is actively targeting US government and critical infrastructure systems via an ecosystem of custom-built malicious platforms, the FBI has warned. The group has focused on critical infrastructure sectors including defense industrial base (DIB), communications, government and higher education for close to a decade since being established in 2018. In 2024, QTFY successfully exfiltrated data from over 300 organizations in the US and globally after leveraging an exploit for a Check Point Quantum Gateway vulnerability. Victims included US defense contractors, financial institutions and universities."<br />
<a href="https://www.infosecurity-magazine.com/news/chinese-qtfy-us-infrastructure-fbi/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/chinese-qtfy-us-infrastructure-fbi/</a><br />
<a href="https://www.ic3.gov/CSA/2026/260826.pdf" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.ic3.gov/CSA/2026/260826.pdf</a></li>
<li><strong>Fake Listings Can Turn Trusted Platforms Into Scam Springboards</strong><br />
"Recently, we found a listing on BuzzFeed from someone pretending to be Malwarebytes Support. It reminded us why we need to be cautious about content on platforms where anyone can create an entry. Based on the phone number, we suspect the people behind this listing are trying to draw callers into a tech support scam. The scammer may use social engineering to persuade victims to grant remote access to their devices."<br />
<a href="https://www.malwarebytes.com/blog/scams/2026/08/fake-listings-can-turn-trusted-platforms-into-scam-springboards" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/scams/2026/08/fake-listings-can-turn-trusted-platforms-into-scam-springboards</a></li>
<li><strong>Fake Apple Pay Charge Brings The Classic Tech Support Scam To Your Phone</strong><br />
"iPhone users are being targeted in a new tech support scam, using a fake Apple Pay notification to trick users. Tech support scams that use fake warnings to push victims into calling a phone number have been around for years, but this page has been designed specifically for phones. Instead of a desktop warning claiming your computer has a virus, the scam imitates familiar iPhone features including Apple Pay, Face ID, and App Store payments. It even uses the phone’s own text-to-speech capabilities and attempts to interfere with mobile navigation."<br />
<a href="https://www.malwarebytes.com/blog/scams/2026/08/fake-apple-pay-charge-brings-the-classic-tech-support-scam-to-your-phone" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/scams/2026/08/fake-apple-pay-charge-brings-the-classic-tech-support-scam-to-your-phone</a></li>
<li><strong>Cambodia-Focused Cluster Uses Multistage Infection Chain With Localized Lures</strong><br />
"Acronis’ Threat Research Unit (TRU) identified a recent campaign focused on Cambodia. The analyzed archives, discovered while hunting for related activity, use several lure themes, including Cambodian government notices, public health announcements, dental examination records, real estate documents, and promotional offers. Cambodia has become an increasingly significant regional security and geopolitical focal point, with deepening China–Cambodia security cooperation and continued reporting of China-linked cyber activity targeting Cambodian organizations."<br />
<a href="https://www.acronis.com/en/tru/posts/cambodia-focused-cluster-uses-multi-stage-infection-chain-with-localized-lures/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.acronis.com/en/tru/posts/cambodia-focused-cluster-uses-multi-stage-infection-chain-with-localized-lures/</a><br />
<a href="https://thehackernews.com/2026/08/spark-rat-targets-cambodia-abuses.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/spark-rat-targets-cambodia-abuses.html</a></li>
</ul>
<p dir="auto"><strong>Breaches/Hacks/Leaks</strong></p>
<ul>
<li><strong>ATF Confirms “major Incident” After Recent Qilin Breach Claims</strong><br />
"ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang. This follows Qilin adding the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives to its dark web data leak portal on Wednesday, without saying whether it had stolen files from ATF's systems or demanded a ransom. The same day, the ATF published a press release saying that a standalone system was breached in what it described as a "major incident," which is now being investigated in collaboration with the Department of Justice."<br />
<a href="https://www.bleepingcomputer.com/news/security/atf-confirms-major-incident-after-recent-qilin-breach-claims/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/atf-confirms-major-incident-after-recent-qilin-breach-claims/</a><br />
<a href="https://therecord.media/doj-atf-cyberattack-qilin-ransomware" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/doj-atf-cyberattack-qilin-ransomware</a></li>
<li><strong>Manchester Airports Group Says Hackers Stole Travelers' Data</strong><br />
"The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports. The intruder did not access customer payment details, and the attack had no impact on airport operations, the company said. A statement from the company today notes that the exfiltrated data also "relates to car park, lounge and Fast Track bookings." The list of compromised details includes customers' email addresses, phone numbers, vehicle registration numbers, and postcodes."<br />
<a href="https://www.bleepingcomputer.com/news/security/manchester-airports-group-says-hackers-stole-travelers-data/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/manchester-airports-group-says-hackers-stole-travelers-data/</a><br />
<a href="https://therecord.media/cyberattack-on-manchester-airports-group-exposes-millions-customer-info" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/cyberattack-on-manchester-airports-group-exposes-millions-customer-info</a><br />
<a href="https://www.infosecurity-magazine.com/news/manchester-airports-data-breach/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/manchester-airports-data-breach/</a></li>
<li><strong>Carhartt Data Breach Exposes Information Of 12.9 Million Accounts</strong><br />
"The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. Founded in 1889, Carhartt is an American apparel company with workwear and streetwear manufacturing facilities in Kentucky and Tennessee and more than 3,000 employees in the United States and Europe."<br />
<a href="https://www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes-information-of-129-million-accounts/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes-information-of-129-million-accounts/</a><br />
<a href="https://haveibeenpwned.com/Breach/Carhartt" target="_blank" rel="noopener noreferrer nofollow ugc">https://haveibeenpwned.com/Breach/Carhartt</a></li>
<li><strong>Kidney Transplant Registry Hack Raises Safety Concerns</strong><br />
"A Connecticut-based organization that helps facilitate organ transplants across the United States is latest healthcare victim of a cybercrime group. Experts say it's a prime example of how hackers don't care about the potential disruption to critical suppliers and ultimately the patients who depend on the services."<br />
<a href="https://www.bankinfosecurity.com/kidney-transplant-registry-hack-raises-safety-concerns-a-32672" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/kidney-transplant-registry-hack-raises-safety-concerns-a-32672</a></li>
</ul>
<p dir="auto"><strong>General News</strong></p>
<ul>
<li><strong>AI Will Not Fix a Governance Problem In Your Camera Estate</strong><br />
"Camera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator is gone, the documentation is lost, and nobody holds the admin credentials. He explains why products should let customers recover control on their own, and how secure-by-default settings reduce the damage of predictable installation mistakes. He also weighs source code escrow, country-of-origin rules, and what evidence vendors can and cannot offer critical infrastructure operators."<br />
<a href="https://www.helpnetsecurity.com/2026/08/27/rob-janssens-hikvision-europe-surveillance-camera-security/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/27/rob-janssens-hikvision-europe-surveillance-camera-security/</a></li>
<li><strong>The Best Human Hacking Team Still Out-Solved The Best AI Team</strong><br />
"Bring an AI agent to a hacking competition and you would expect to find it propping up the teams who were struggling. In the 2026 Global Cyber Skills Benchmark, agents showed up in 17 of the Top 25 finishers. The people who least needed help were the ones who brought it. The people who might have used a hand mostly did not, and they did not close the gap. “Our data shows that AI is appearing most often alongside some of the strongest practitioners, not instead of them. As agents become more capable, human judgment, validation and hands-on technical skill become more important, not less,” said Haris Pylarinos, CEO of Hack The Box."<br />
<a href="https://www.helpnetsecurity.com/2026/08/27/ai-ctf-security-teams/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/27/ai-ctf-security-teams/</a></li>
<li><strong>The Hugging Face Incident And The Road Ahead</strong><br />
"In July 2026, during internal cybersecurity evaluations, OpenAI models circumvented controls designed to isolate them from the internet and compromised parts of OpenAI’s internal research infrastructure and Hugging Face’s systems⁠. The incident occurred during cybersecurity evaluations of several OpenAI models, and was primarily driven by a highly capable, internal-only research model comparable in scale to GPT‑5.6 Sol. The models, operating under reduced safeguards, took actions that were misaligned with the goals of their assigned tasks—they communicated through unauthorized channels, exploited vulnerabilities in shared infrastructure, gained internet access, and accessed third-party systems."<br />
<a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/" target="_blank" rel="noopener noreferrer nofollow ugc">https://openai.com/index/hugging-face-incident-and-the-road-ahead/</a><br />
<a href="https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf" target="_blank" rel="noopener noreferrer nofollow ugc">https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face Incident-Technical-Report.pdf</a><br />
<a href="https://www.bleepingcomputer.com/news/security/nearly-700-rogue-ai-agents-coordinated-in-the-hugging-face-attack/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/nearly-700-rogue-ai-agents-coordinated-in-the-hugging-face-attack/</a><br />
<a href="https://thehackernews.com/2026/08/openai-says-reward-hacking-drove-ai.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/openai-says-reward-hacking-drove-ai.html</a><br />
<a href="https://www.infosecurity-magazine.com/news/openai-hugging-face-warning-shot/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/openai-hugging-face-warning-shot/</a><br />
<a href="https://www.securityweek.com/openai-agents-coordinated-via-makeshift-message-board-ahead-of-hugging-face-hack/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/openai-agents-coordinated-via-makeshift-message-board-ahead-of-hugging-face-hack/</a></li>
<li><strong>Australia Arrests Alleged TeamPCP Hackers Behind Supply-Chain Attacks</strong><br />
"Australian authorities have arrested and charged two young men accused of being part of the TeamPCP hacking group linked to a string of far-reaching developer supply chain attacks. TeamPCP is a hacking group known for widespread supply-chain attacks over the past year that targeted open-source software and developer platforms to steal credentials, authentication secrets, and source code. High-profile attacks attributed to TeamPCP have impacted Trivy, LiteLLM, Telnyx, SAP, and TanStack packages, while the group has also breached the European Commission, Mistral AI, OpenAI, and GitHub."<br />
<a href="https://www.bleepingcomputer.com/news/security/australia-arrests-alleged-teampcp-hackers-behind-supply-chain-attacks/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/australia-arrests-alleged-teampcp-hackers-behind-supply-chain-attacks/</a><br />
<a href="https://thehackernews.com/2026/08/alleged-teampcp-hackers-charged-in.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/08/alleged-teampcp-hackers-charged-in.html</a><br />
<a href="https://therecord.media/australia-teampcp-hackers-arrested" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/australia-teampcp-hackers-arrested</a><br />
<a href="https://www.bankinfosecurity.com/two-australian-men-charged-in-teampcp-supply-chain-attacks-a-32675" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/two-australian-men-charged-in-teampcp-supply-chain-attacks-a-32675</a><br />
<a href="https://cyberscoop.com/teampcp-cybercrime-arrests-supply-chain-attacks/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/teampcp-cybercrime-arrests-supply-chain-attacks/</a><br />
<a href="https://securityaffairs.com/197929/security/two-arrests-one-supply-chain-attack-and-a-lot-of-stolen-credentials.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/197929/security/two-arrests-one-supply-chain-attack-and-a-lot-of-stolen-credentials.html</a><br />
<a href="https://www.securityweek.com/australia-arrests-2-alleged-teampcp-hackers/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/australia-arrests-2-alleged-teampcp-hackers/</a><br />
<a href="https://www.helpnetsecurity.com/2026/08/27/alleged-teampcp-hackers-arrested-australia/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/08/27/alleged-teampcp-hackers-arrested-australia/</a></li>
<li><strong>A Call For Collective Action On Cyber Defense</strong><br />
"We have a limited window to strengthen cyber defenses. In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable. The companies and public services our communities depend on—from hospitals to water treatment plants to the infrastructure that powers the internet—are at risk. Today’s AI advances are already giving defenders new ways to fix weaknesses that have accumulated for years. If we act decisively, we can use the defenders’ window to make our digital world much more secure."<br />
<a href="https://openai.com/collective-cyberdefense/" target="_blank" rel="noopener noreferrer nofollow ugc">https://openai.com/collective-cyberdefense/</a><br />
<a href="https://cyberscoop.com/ai-cyber-defense-global-surge/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/ai-cyber-defense-global-surge/</a></li>
<li><strong>'HTTP Terminator' Hunts For Novel Desync Attacks</strong><br />
"James Kettle wanted to find out if AI tools could go beyond finding new vulnerabilities and actually develop new attack techniques and exploits — so he built a Terminator. An "HTTP Terminator," to be exact. And as scary as the open source tool may sound, it worked — HTTP Terminator autonomously developed novel desync attacks, also known as HTTP request smuggling, that successfully hacked into real enterprise websites, including those of several financial services companies."<br />
<a href="https://www.darkreading.com/application-security/http-terminator-hunts-novel-desync-attacks" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/application-security/http-terminator-hunts-novel-desync-attacks</a></li>
<li><strong>CISO Conversations: Chris Wheeler – Trust Is The Job, From The Navy To The C-Suite</strong><br />
"Chris Wheeler is the CISO at Resilience. He has a long history in cybersecurity: a threat researcher and analyst at Efflux Systems and then threat analytics manager at Arbor Networks. He joined Resilience as threat intelligence lead but left in 2020 to become VP and SOAR lead at Morgan Stanley. He returned to Resilience four years later, first as VP of information security, and subsequently CISO. It is fair to suggest he has security in his blood. His father was a university IT administrator. “He was always kind of tinkering with these different systems, and I inherited the same kind of curiosity and interest in information technology.”"<br />
<a href="https://www.securityweek.com/ciso-conversations-chris-wheeler-trust-is-the-job-from-the-navy-to-the-c-suite/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/ciso-conversations-chris-wheeler-trust-is-the-job-from-the-navy-to-the-c-suite/</a></li>
<li><strong>The Future Of AI-Driven Security Depends On Complete Data</strong><br />
"I’ve always been drawn to investigative documentaries — the kind where detectives reconstruct an entire crime from fragments of evidence. The breakthrough never comes from a single clue. It comes from connecting everything: movements, relationships, timing, and intent. Miss one piece and the case stalls, or worse, you chase the wrong suspect. Cybersecurity works the same way."<br />
<a href="https://www.securityweek.com/the-future-of-ai-driven-security-depends-on-complete-data/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/the-future-of-ai-driven-security-depends-on-complete-data/</a></li>
<li><strong>Russian Hackers Phish EU Officials Over Messaging Apps</strong><br />
"The European Union (EU) confirmed that state-sponsored hackers have been spear-phishing government officials on popular messaging apps rather than email. Nation-state advanced persistent threats (APTs) commonly socially engineer their nation-state targets over email, impersonating quotidian business to trick targets into opening malicious websites or attachments. Yet email is where most employees expect malicious messages to come from. Messaging apps don't carry the same reputation, and encrypted ones — like WhatsApp and Signal in particular — add an extra sheen of trusted security."<br />
<a href="https://www.darkreading.com/cyberattacks-data-breaches/russian-hackers-phish-eu-officials-messaging-apps" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cyberattacks-data-breaches/russian-hackers-phish-eu-officials-messaging-apps</a></li>
</ul>
<p dir="auto"><strong>อ้างอิง</strong><br />
Electronic Transactions Development Agency (ETDA) <img src="/assets/uploads/files/1787906651910-3ef802d4-061a-4583-a06c-642611eebf86-image.png" alt="3ef802d4-061a-4583-a06c-642611eebf86-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3232/cyber-threat-intelligence-28-august-2026</link><generator>RSS for Node</generator><lastBuildDate>Fri, 28 Aug 2026 12:36:02 GMT</lastBuildDate><atom:link href="https://webboard-nsoc.ncsa.or.th/topic/3232.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 28 Aug 2026 08:44:13 GMT</pubDate><ttl>60</ttl></channel></rss>