NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ

    Cyber Threat Intelligence 04 September 2026

    Cyber Security News
    1
    1
    6
    โหลดโพสเพิ่มเติม
    • เก่าสุดไปยังใหม่สุด
    • ใหม่สุดไปยังเก่าสุด
    • Most Votes
    ตอบ
    • ตอบโดยตั้งกระทู้ใหม่
    เข้าสู่ระบบเพื่อตอบกลับ
    Topic นี้ถูกลบไปแล้ว เฉพาะผู้ใช้งานที่มีสิทธิ์ในการจัดการ Topic เท่านั้นที่จะมีสิทธิ์ในการเข้าชม
    • NCSA_THAICERTN
      NCSA_THAICERT
      แก้ไขล่าสุดโดย

      Vulnerabilities

      • HPE Patches Critical ArubaOS-CX Remote Code Execution Flaw
        "Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. Tracked as CVE-2026-73749, the security issue is a buffer overflow that allows unauthenticated remote attackers to send specially crafted packets to an affected daemon process, achieving code execution with elevated privileges. “Multiple vulnerabilities exist in a daemon of ArubaOS-CX that may allow for improper processing of malformed input,” reads HPE’s bulletin."
        https://www.bleepingcomputer.com/news/security/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw/
      • Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code As Root
        "Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is a case of binding to an unrestricted IP address that leaves TCP ports 43210 and 43211 reachable in the default Layer 3 virtual routing and forwarding (VRF) instance."
        https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html
        https://www.securityweek.com/cisco-warns-of-unpatched-secure-email-flaws-patches-critical-switch-vulnerabilities/
        https://securityaffairs.com/198366/security/cisco-fixed-critical-rce-in-nexus-9000-series-switches.html
      • Plex Warns Users To Patch Security Vulnerabilities Immediately
        "Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. These flaws have not yet been assigned CVE IDs for easy tracking, and while Plex didn't provide additional details on Tuesday, the security issues are known to affect Plex Media Server v1.43.2 and earlier. Plex also emailed users running affected versions and asked them to update as soon as possible to address these security flaws."
        https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/
      • VMSA-2026-0007: VMware Workstation And Fusion Updates Address Integer-Overflow And Buffer Overflow Vulnerabilities (CVE-2026-59346, CVE-2026-59347)
        "An integer-overflow and a buffer-overflow vulnerabilities in VMware Workstation and Fusion were privately reported to Broadcom. Updates are available to remediate these vulnerabilities in affected Broadcom products."
        https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38288
      • Attackers Actively Exploiting Critical Vulnerability In Elementor Pro Plugin
        "On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more than 6,000,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site takeover. The vendor released the fully patched version on August 19th, 2026, and we originally disclosed this vulnerability in the Wordfence Intelligence vulnerability database on the same day. The Wordfence Firewall has already blocked over 190,000 exploit attempts targeting this vulnerability."
        https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-elementor-pro-plugin/
        https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploited-to-take-over-wordpress-sites/

      Malware

      • Coder's Registry Infrastructure Compromised To Push Malicious Modules
        "Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. The Coder platform enables organizations to provide developers with secure, self-hosted cloud development environments for building and deploying software, including AI applications. The project is used by prominent private and government organizations, including Dropbox, Palantir, Square, Mercedes-Benz, KKR, EnBW, the U.S. government, and defense companies."
        https://www.bleepingcomputer.com/news/security/coders-registry-infrastructure-compromised-to-push-malicious-modules/
      • The NDA Was The Payload: Inside Phantom Deal, a Fake Acquisition Fraud Campaign
        "It started with an innocent WhatsApp message. “Hi David, I hope you are well. Are you at the office?” The sender claimed to be a real Gen executive based in Dublin. The profile used his name, photograph and an Irish telephone number. Nothing in the opening message mentioned money, urgency or an acquisition. It was simply designed to establish whether the recipient was available and willing to respond. The recipient, whom we will call David, worked in Gen’s legal team and knew the colleague being impersonated. The unfamiliar telephone number raised suspicion, and the first phone conversation confirmed it: the caller’s voice did not match."
        https://www.gendigital.com/blog/insights/research/phantom-deal
        https://www.darkreading.com/cyberattacks-data-breaches/large-enterprises-fake-merger-acquisition-scams
      • Someone Else Is Using Your AI
        "Generative AI is quickly becoming one of the more lucrative uses for stolen cloud credentials. Attackers no longer need to set up crypto miners or exfiltrate data to cash in on a leaked IAM key. They can instead subscribe to foundation models through AWS Marketplace and resell inference access, a technique called LLMjacking, first documented in 2024. FortiCNAPP recently investigated a case that shows how fast and mechanical that pivot has become. FortiGuard Labs recently analyzed a long-lived AWS IAM access key with administrator privileges that was used to create a new IAM identity, subscribe it to foundation models on AWS Marketplace, and begin invoking them."
        https://www.fortinet.com/blog/threat-research/someone-else-is-using-your-ai
      • The Outsider Phishing Kit: A Resilient Threat In The Face Of Law Enforcement Action
        "During an investigation into phishing kits sold, Group-IB researchers uncovered the “Outsider Phishing Kit” (局外人), a sophisticated Phishing-as-a-Service (PaaS) platform operated by the threat actor known as “ChenLun.” The kit incorporates Adversary-in-the-Middle (AiTM) capabilities, enabling attackers to intercept authentication flows and bypass multi-factor authentication (MFA). The scale of this operation is staggering. From December 2025 to May 2026, Group-IB has identified over 100,000 phishing pages targeting 54+ countries, leveraging 267 (and growing) phishing templates. These numbers underscore the increasingly low barrier to entry for threat actors to launch and operate large-scale phishing campaigns."
        https://www.group-ib.com/blog/chenlun-outsider-phaas-kit/
        https://www.infosecurity-magazine.com/news/outsider-phishing-kit-survives/
      • Attackers Expose Ongoing AI Tool Use Targeting Organizations In Latin America
        "We have analyzed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America. Corroborating recent findings from the broader threat intelligence community, we observed attackers leveraging artificial intelligence (AI) to enhance their capabilities."
        https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/
      • US Becomes Top Target In RMM Phishing Campaign Spanning 46 Countries
        "An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses fake documents to trick victims into installing legitimate remote monitoring and management (RMM) software. The attackers adapt their lures to different targets, using shipping and UPS communications, Adobe PDFs, tax notices, US Social Security Administration themes, invoices, and other documents. Rapidly rotated, disposable Vercel infrastructure makes the campaign harder to track and detect."
        https://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.html
      • Node.js: Old Technique Makes a Comeback
        "Between March and July 2026, attackers who compromised a technology start-up in Asia ran into a problem: almost every payload they attempted to deploy, including AdaptixC2 agents and Cobalt Strike Beacon, was blocked on the victim's network. Their response was to download the official Node.js installer from nodejs.org and use the trusted, signed runtime to execute a malicious implant. The implant maintained its foothold for months and made repeated connections to Ethereum blockchain gateways, most likely to retrieve commands or additional payloads hidden in a blockchain smart contract, a technique known as EtherHiding."
        https://www.security.com/threat-intelligence/node-js-returns-ransomware
        https://thehackernews.com/2026/09/attackers-turn-trusted-nodejs-runtime.html
      • Shai-Hulud's Reach Just Grew To 469 Credential Locations. Here's What That Means
        "In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs. Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have stopped trying to break trust relationships and started using the credentials that already make those relationships work. Software supply chains have always depended on trust."
        https://thehackernews.com/2026/09/shai-huluds-reach-just-grew-to-469.html
      • Researcher Releases FalconFlank PoC Showing Privilege Escalation In CrowdStrike Falcon
        "The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in a GitHub README file, adding the cybersecurity company may already have detections for the flaw by now. "So if you want to test, you either have to add it to the exclusions or obfuscate the PoC and change the DLL load technique.""
        https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html
        https://securityaffairs.com/198342/hacking/chaotic-eclipse-releases-crowdstrike-falcon-zeroday-falconflank.html
      • Impersonating IT Support: How Threat Actors Turn a Remote Session Into Enterprise-Wide Access
        "Microsoft Threat Intelligence has observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into granting an interactive remote session. Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node.js runtime and an obfuscated JavaScript implant that provides persistent command execution and command and control (C2)."
        https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/

      Breaches/Hacks/Leaks

      • US And Canadian Court Data Exposed In Thomson Reuters Breach
        "Sealed court information and sensitive personal data were exposed in a breach of a Thomson Reuters records platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands and Canada, the company publicly disclosed Wednesday. Thomson Reuters has not said how the attacker gained access, who was responsible or how much data was taken. The number of people affected also remains unclear. The company stressed the breach occurred within its environment and was not caused by the networks, systems or data security of the affected courts."
        https://therecord.media/thomson-reuters-cyberattack-data
        https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html
        https://www.infosecurity-magazine.com/news/us-canada-court-breach-thomson/
        https://www.helpnetsecurity.com/2026/09/03/thomson-reuters-reveals-breach-that-exposed-u-s-and-canadian-court-records/
      • Manchester Airports Group Data On 8.8 Million People Leaked After Ransom Refusal
        "Data allegedly stolen from the Manchester Airports Group (MAG) and leaked online this week includes the email addresses and phone numbers of 8.8 million people. MAG disclosed the incident last week, warning that hackers had breached its systems, stealing car park, lounge, and Fast Track booking data, along with in-airport Wi-Fi sign-ups at the Manchester, London Stansted, and East Midlands airports. The airport operator disclosed that hackers had exfiltrated email addresses, phone numbers, vehicle registrations, and postcodes, noting that its operations were not affected by the incident."
        https://www.securityweek.com/manchester-airports-group-data-on-8-8-million-people-leaked-after-ransom-refusal/
      • 412,000 The Town 2025 Ticket Buyers’ Data Hits The Dark Web
        "A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, claiming over 412,000 Latin American purchase records with a heavy concentration of Brazilian data. Ransomnews’s analysis confirms the sample is genuine ticket-buyer data from The Town 2025, the São Paulo music festival, though who actually lost the data and how remains unconfirmed. “The listing is headed “SELLING NEW TICKETMASTER DATABASE” and describes a global ticketing platform, Latin America region, with an internal ticketing database as the source and a breach date of 28 August 2026."
        https://securityaffairs.com/198354/data-breach/412000-the-town-2025-ticket-buyers-data-hits-the-dark-web.html
      • Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline
        "Recently leaked records show that Bauman Moscow State Technical University’s Department No. 4 operated as a long-term training pipeline for Russian military intelligence and cyber operations. The department served several elements of the Russian General Staff and trained roughly 250 career and reserve students across three specialties: special intelligence (“Служба специальной разведки”), operational information-technical effects (“Применение сил и средств информационно-технического воздействия и защиты от информационно-технического воздействия”), and information-technology protection (”3ащита информационных технологий”). The curriculum combined both offensive and defensive techniques for cyber defense, as well as offensive doctrine for active measures campaigns and GRU activities. Field placements then moved students from classroom instruction into military units and academies aligned with their specialties, giving them supervised exposure to intelligence operations and preparing them for military and government operations careers."
        https://dti.domaintools.com/research/threat-intelligence-report-university-leak-exposes-russias-military-cyber-training-pipeline
        https://securityaffairs.com/198332/intelligence/2000-leaked-documents-reveal-how-russia-turns-engineering-students-into-gru-cyber-operators.html

      General News

      • G7 Says Migrating To PQC Early Is Cheaper Than Later
        "An international public-private cyber alliance is making a call to action on transitioning to post-quantum cryptography and offers strategies to lower the cost of the strenuous effort. The G7 Cybersecurity Working Group of government agencies and banks from seven economically advanced countries along with the European Union outlined many risks that can happen after quantum computers break classic encryption and told every country to consider PQC as a "foreseeable evolution of cryptographic best practices" that cannot be avoided."
        https://www.bankinfosecurity.com/g7-says-migrating-to-pqc-early-cheaper-than-later-a-32738
        https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/asset_files/external/g7preparingfortheqostquantumeraacalltoaction.pdf
        https://cyberscoop.com/g7-quantum-computing-encryption-warning/
      • Crypto Agility: Why PQC Is Not a One-Time Upgrade
        "Crypto agility is the ability to update cryptographic algorithms, protocols, libraries, and implementations while minimizing disruption and avoiding unnecessary replacement of the underlying infrastructure. For networks, that means adopting post-quantum cryptography (PQC) while preserving the ability to accommodate future standards and defenses primarily through software. This capability matters because networking platforms often take years to develop and may remain deployed for a decade or longer."
        https://blogs.cisco.com/security/crypto-agility-why-pqc-is-not-a-one-time-upgrade
      • Supply Chain Attacks In 2026: Why Threat Intelligence Is The Only Early Warning System That Works
        "Supply chain attacks in 2026 are no longer an edge-case risk buried in a vendor questionnaire — they are a primary breach vector that regulators, incident responders, and CISOs now treat as a first-order threat. Verizon’s 2026 Data Breach Investigations Report found third-party involvement in 48% of breaches, up 60% year over year, following the 2025 edition, which already recorded a jump from 15% to 30%. Every vendor integration, every open-source dependency, and every managed file transfer tool expands the attack surface that an organization does not directly control. That is the core problem with supply chain security today: the weakest link is rarely the enterprise itself."
        https://cyble.com/blog/supply-chain-attacks-in-2026-vendor-risk/
      • Your AI Agent’s System Prompt Is Not a Security Control
        "An AI agent told in its system prompt to show a user only what that user is cleared to see will hand over more the moment someone talks it into doing so. Gee Rittenhouse, who oversees Security Hub, GuardDuty, and Inspector at AWS, and Eric Johnson, a fellow at the SANS Institute, put the fix one layer down: scope the query to the user’s permissions at retrieval time, inside the role-based or attribute-based access system the company already runs, and filter the results before they reach the model’s context window."
        https://www.helpnetsecurity.com/2026/09/03/sans-aws-agentic-ai-security/
      • Your Threat Feed Is Someone Else’s Database: What Ingesting Malware Intel At Scale Takes
        "The advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is the operating manual, because the access was never the hard part. A threat feed is someone else’s database. Someone else’s processes built it, someone else’s judgement calls shaped it, and someone else’s bad Tuesday is sitting it right now, waiting for the automation to act on it. I lead the team that runs Dependabot at GitHub, which monitors more than 30 million repositories for vulnerable and malicious dependencies as of 2026. This year we extended malicious-package advisories from npm, where we had been flagging malware since March, to eight package ecosystems, by ingesting community intelligence from OpenSSF’s malicious-packages repository."
        https://www.helpnetsecurity.com/2026/09/03/github-threat-intelligence-feed-ingestion/
      • When AI Quietly Breaks Things, Who Pays?
        "David Halbreich, an insurance recovery partner at Reed Smith, breaks down how AI companies should handle coverage gaps that come up as the industry grows. He covers straddle claims that fall between tail and go-forward D&O policies after a merger, how governance disclosures in applications can turn into warranties an insurer uses to deny a claim, who should sign off on AI use questions, when the claim clock starts for slow-building model degradation, and how business interruption coverage applies to outages at cloud and compute vendors."
        https://www.helpnetsecurity.com/2026/09/03/david-halbreich-reed-smith-ai-insurance-coverage-gaps/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) e52ccc9b-7672-4b70-bd36-017039b11b7b-image.png

      1 การตอบกลับ คำตอบล่าสุด ตอบ คำอ้างอิง 0
      • First post
        Last post