NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ

    Cyber Threat Intelligence 09 September 2026

    Cyber Security News
    1
    1
    20
    โหลดโพสเพิ่มเติม
    • เก่าสุดไปยังใหม่สุด
    • ใหม่สุดไปยังเก่าสุด
    • Most Votes
    ตอบ
    • ตอบโดยตั้งกระทู้ใหม่
    เข้าสู่ระบบเพื่อตอบกลับ
    Topic นี้ถูกลบไปแล้ว เฉพาะผู้ใช้งานที่มีสิทธิ์ในการจัดการ Topic เท่านั้นที่จะมีสิทธิ์ในการเข้าชม
    • NCSA_THAICERTN
      NCSA_THAICERT
      แก้ไขล่าสุดโดย

      Industrial Sector

      • CareCam Pro IP Cameras
        "Successful exploitation of this vulnerability could allow an attacker to take full control of the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-251-01

      Vulnerabilities

      • Microsoft September 2026 Patch Tuesday Fixes 966 Flaws, 2 Zero-Days
        "Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. This Patch Tuesday addresses 105 "Critical" vulnerabilities, 81 of which are remote code execution, 20 are elevation of privileges, 2 are information disclosure, and 1 security feature bypass."
        https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/
        https://blog.talosintelligence.com/microsoft-patch-tuesday-for-september-2026/
        https://www.darkreading.com/vulnerabilities-threats/patch-tuesday-another-record-974-cves
        https://therecord.media/microsoft-patch-tuesday-september-2026
        https://cyberscoop.com/microsoft-patch-tuesday-september-2026/
        https://www.securityweek.com/microsoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days/
      • SAP Warns Of Maximum Severity 'OVERPASS' Kernel Vulnerability
        "SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. Tracked as CVE-2026-44756 and dubbed OVERPASS by Onapsis security researchers who reported it, the vulnerability stems from a classic buffer overflow weakness in the Extended Passport Protocol (EPP) processing library. Successful exploitation lets unprivileged threat actors run arbitrary commands on vulnerable SAP hosts with administrative privileges, leading to full compromise of the underlying SAP processes and business data."
        https://www.bleepingcomputer.com/news/security/sap-warns-of-maximum-severity-overpass-kernel-vulnerability/
        https://onapsis.com/blog/sap-overpass-remediation/
        https://www.securityweek.com/sap-patches-critical-extended-passport-processing-vulnerability/
      • Adobe Fixes Critical Magento Zero-Day Exploited To Backdoor Servers
        "Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. E-commerce security company Sansec discovered that the flaw has been leveraged in attacks since at least September 4 to plant a backdoor on vulnerable websites. The backdoor disguised its command-and-control (C2) host as a regular Network Time Protocol (NTP) server. However, it still leaves distinct signs of activity on compromised hosts, such as "Payment Transaction Failed Reminder" emails."
        https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-magento-zero-day-exploited-to-backdoor-servers/
        https://helpx.adobe.com/security/products/magento/apsb26-146.html
        https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html
      • Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
        "Adobe has released patches for more than 170 vulnerabilities across its products, including urgent hotfixes for a critical-severity flaw in Adobe Commerce and Magento Open Source that has been exploited in the wild as a zero-day. Tracked as CVE-2026-75650 (CVSS score of 10/10), the flaw is a code injection issue that can be exploited without authentication for remote code execution (RCE)."
        https://www.securityweek.com/adobe-patches-over-170-vulnerabilities-including-commerce-zero-day/
      • FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
        "A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The FreeIPA project has already fixed its side in version 4.13.4. Red Hat says it reproduced the chain twice on a default installation, most recently on a machine with no access at all."
        https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html
      • CISA Adds Four Known Exploited Vulnerabilities To Catalog
        "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
        CVE-2026-81963 Microsoft Windows Link Following Vulnerability
        CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability
        CVE-2026-86218 N-able N-central Static Code Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog

      Malware

      • China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
        "China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) (hereafter referred to as the authoring agencies) are releasing this joint Cybersecurity Advisory to alert organizations about these malicious activities and techniques and recommend mitigations to reduce their potential impact."
        https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a
        https://cyberscoop.com/us-accuses-chinese-ai-companies-distillation/
        https://www.bankinfosecurity.com/us-warns-chinese-ai-firms-are-illicitly-distilling-models-a-32773
      • DoppelCart: 119,000 Domains In What May Be The Largest Documented Fake-Shop Network
        "Around 119,000 domains, connected by shared infrastructure and recurring features in their shop software. Product catalogs from real businesses, copied descriptions and original images. And customers whose complaints end up with the legitimate store. We investigated a fake-shop network whose scale surprised even us. We call it DoppelCart. To our knowledge, DoppelCart is the largest fake-shop cluster publicly documented to date, measured by the number of associated domains. Its .shop domains alone account for 2.72 percent of the .shop domain population in our snapshot. That is roughly one in every 37 domains."
        https://nebty-id.com/en/doppelcart-fake-shop-network/
        https://www.bleepingcomputer.com/news/security/doppelcart-fraud-network-uses-119-000-fake-shops-to-steal-credit-cards/
      • Dissecting a PHP Web Server Rootkit
        "SophosLabs recently acquired a Linux implant associated with compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components. The malware demonstrates advanced techniques including custom ELF loading, function hooking, and runtime code patching to evade detection while maintaining persistent access through hidden web shells. The implant delivers a familiar outcome – on-demand server‑side code execution commonly associated with web shells – but implements it using deeper Linux- and Apache‑specific tradecraft."
        https://www.sophos.com/en-us/blog/dissecting-a-php-web-server-rootkit
        https://www.bleepingcomputer.com/news/security/hackers-breach-f5-big-ip-apm-devices-to-deploy-linux-rootkit/
      • ClearFake WebDAV Infection Chain Delivers Amatera Stealer, ZigCryptoStealer, And NetSupport Manager
        "Cisco Talos began an investigation after observing a DLL named "verification.google" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload. Pivoting around the similar WebDAV behavior led to a second loader named "pf.ch" and allowed us to reconstruct its earlier delivery stages. The chain uses a Cloudflare Worker to inject JavaScript code stored on BNB Smart Chain and a ClickFix prompt impersonating Google CAPTCHA, leading to download and execution of Amatera stealer. The chain is likely very similar to what has caused the WebDAV-based execution at the Ukraininan government organization."
        https://blog.talosintelligence.com/clearfake-webdav-infection-chain/
      • ClickFix Moves Into The Browser: Cryptocurrency Theft With Google-Hosted C2
        "Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session. The actors use a variation on ClickFix social engineering. Instead of convincing targets to run commands against the operating system, they convince targets to paste JavaScript into the Chrome address bar or install it into the Tampermonkey browser extension, which also provides persistence."
        https://blog.talosintelligence.com/clickfix-moves-into-the-browser/
        https://www.darkreading.com/endpoint-security/clickfix-campaigns-legitimate-services-persistent-access
      • Bypassing The Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure Into a Trust Proxy
        "In addition to everyday users, Google's infrastructure is trusted by email security gateways, enterprise firewalls and automated URL detonation platforms. Threat actors know this. In this KnowBe4 Threat Lab analysis, we break down an active, wide-scale phishing campaign that routes victims through a deliberate chain of legitimate Google services before landing them on credential harvesters or deploying remote access tools. The execution here is unusually complete: six distinct Google properties abused across multiple redirect paths, a landing page that dynamically impersonates the victim's own organization in real time, and a dual-track post-redirect architecture that delivers either credential theft or persistent remote access depending on the lure context."
        https://blog.knowbe4.com/bypassing-the-gatekeepers-how-a-global-phishing-campaign-turns-googles-infrastructure-into-a-trust-proxy
        https://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaign
      • Hagaseca: Inside a Packed Android RAT Loader
        "Hagaseca is an Android malware cluster associated with exposed Android Debug Bridge (ADB) services. This analysis examines the Hagaseca Android RAT loader known as THost9. RAT stands for remote access trojan. A RAT can let an attacker control an infected device remotely. The loader hides executable code inside an Android application package (APK). It then loads tc9.dex, a separate stage with shell access, file transfer, and ADB propagation capabilities."
        https://darkatlas.io/blog/hagaseca-inside-a-packed-android-rat-loader
        https://www.infosecurity-magazine.com/news/thost9-android-rat-packed-loader/
      • WeWorm
        "At Calif, our mission is to keep the Internet together by occasionally taking it apart. We believe everyone deserves a safe and secure Internet, including the people who cannot protect themselves. Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. This is the first installment in a series exploring zero-click attack surfaces in mobile messaging apps. WeChat is an "everything app" used by virtually everyone in China and by Chinese communities worldwide. Simply by calling a victim, WeWorm can hijack their account and call their friends, spreading from phone to phone. If exploited, actors can compromise over a billion phones (or accounts), upending livelihoods and breaking communities worldwide."
        https://calif.io/research/weworm
        https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html
        https://securityaffairs.com/198688/hacking/wechat-worm-can-hijack-accounts-without-victims-answering-calls.html
        https://www.helpnetsecurity.com/2026/09/08/wechat-weworm-vulnerability-exploit-account-hijacking/
      • Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
        "A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment service Pix, digital asset platforms, and financial entities' cloud environments," CrowdStrike said."
        https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html
        https://go.crowdstrike.com/rs/281-OBQ-266/images/CrowdStrike-2026-Threat-Hunting-Report.pdf
      • BengalSEO Part 1: Anatomy Of The Operation
        "In March 2026, our team identified an SEO poisoning campaign leading to malware deployment and tech support scams. Further research into this campaign revealed a sophisticated and widespread scam operation that has been operating since at least 2015. Our team attributes this operation, with high confidence, to a group of core individuals and IT service providers operating out of Rajasthan, India, which our team tracks collectively as BengalSEO. Using indicators gathered from the identified SEO poisoning campaign, our team was able to correlate this activity with information posted on scam hunting forums. This discovery led our team to a company named WeConnect Solutions LLC (previously iConnect Soft Solutions LLC), which operates a tech support call center located in Kota, Rajasthan."
        https://thedfirreport.com/2026/08/24/bengalseo-part-1-anatomy-of-the-operation/
        https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html
      • Anatomy Of a Layered, Multi-Brand Phishing Campaign
        "Barracuda Research has analyzed a multi-layered, multi-brand phishing campaign that reflects a trend for attackers to embed authentication requests inside familiar business workflows. Similar to platforms such as Kali365, which we recently reported on, the objective is to make authentication appear a routine step in a document-sharing, signing or collaboration process. However, unlike Kali365’s device-code phishing and token-focused attacks, this campaign relies on browser-in-the-browser (BitB) deception to harvest credentials directly."
        https://blog.barracuda.com/2026/09/08/browser-in-the-browser-phishing-docusign-adobe-microsoft

      Breaches/Hacks/Leaks

      • ShinyHunters Hackers Claim Breach Of Florida "DAVID" DMV Database
        "The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state. As proof of the breach, the threat actor has released a screenshot of Jeffrey Epstein's DMV record, including his address and registered vehicles. DAVID is the "Driver and Vehicle Information Database" platform operated by the Florida Highway Safety and Motor Vehicles (FLHSMV) agency, used by law enforcement and officials to look up information about a particular driver."
        https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/
        https://hackread.com/shinyhunters-florida-dmv-breach-jeffrey-epstein-proof/
      • 220 Million Traveler Records Exposed In Vietnam-Linked APIS Leak
        "An Advance Passenger Information System (APIS) database holding more than 220 million passenger and crew records, including passport numbers and flight details, was accessible online through a chain of security misconfigurations. The system appears linked to a Vietnamese organization, according to the researchers who discovered it. Advance Passenger Information Systems are used worldwide to collect identity, passport, and flight information from airlines before passengers and crew arrive at or depart from a country."
        https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/
        https://securityaffairs.com/198671/data-breach/massive-vietnam-linked-apis-database-exposes-passport-and-flight-data.html
      • Cyberattack Encrypts Systems At Bavarian Municipal Utility
        "A municipal utility in Bavaria said Monday that hackers encrypted its central IT network in a cyberattack last week. In a notice to customers, Stadtwerke Landsberg said the attack disrupted office systems but is not affecting electricity, water and other essential services. The incident began overnight on September 1, the utility said, prompting it to disconnect the affected systems from the internet, activate its crisis team and bring in external cybersecurity specialists."
        https://therecord.media/cyberattack-bavaria-germany-utility

      General News

      • GTIG AI Threat Tracker: From Prompting To Autonomy – The Evolution Of Adversarial AI
        "Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, build, and execute an agent-enabled mass credential harvesting campaign in under six hours. We also tracked UNC6780 using multiple tactics to trick AI coding assistants and large language model (LLM) security scanners into its open source software supply chain compromises."
        https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai
        https://www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-credential-theft/
        https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html
        https://www.infosecurity-magazine.com/news/ai-coding-tools-threat-actors/
        https://www.theregister.com/research/2026/09/08/extortion-crews-have-their-eyes-on-high-value-ai-data-google-warns/5294640
        https://www.helpnetsecurity.com/2026/09/08/ai-agents-cyberattacks-automation-google-research/
      • ChatGPT Let Attackers Read Victims’ Gmail Through a Hidden Channel Between Accounts
        "Enterprises are connecting AI assistants to more of their real infrastructure every month, from inboxes to file drives to internal tools, on the assumption that the isolation between users and accounts holds. Check Point Research just tested that assumption against ChatGPT and found a way to break it. Using an internal service that was never meant to carry user data at all, CPR opened a working channel between two completely separate ChatGPT accounts and used it to hand one victim’s session a task from a total stranger, all while the victim’s own conversation looked entirely normal."
        https://blog.checkpoint.com/research/chatgpt-let-attackers-read-victims-gmail-through-a-hidden-channel-between-accounts/
        https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/
        https://thehackernews.com/2026/09/chatgpt-flaw-let-planted-prompt-send.html
      • Russian National Extradited To United States For Bank Account Takeover Fraud Scheme Causing Millions Of Dollars In Losses
        "Sergei Anatolyevich Filimonov, 36, a Russian national and web developer who was allegedly involved in a transnational cyber‑fraud conspiracy responsible for large‑scale bank account takeover activity, was arraigned Friday in the Northern District of Georgia after being extradited from the Republic of Georgia. Filimonov was indicted by a federal grand jury on Nov. 4, 2025, for charges relating to a credential‑harvesting and bank‑fraud operation that targeted victims across the United States."
        https://www.justice.gov/opa/pr/russian-national-extradited-united-states-bank-account-takeover-fraud-scheme-causing
        https://therecord.media/russian-cybercrime-bank-extradition
        https://cyberscoop.com/russian-national-extradited-bank-account-takeover-sergei-filimonov/
      • Scammer Behind $245 Million Crypto Heist Pleads Guilty To RICO Charges
        "A Singaporean national pleaded guilty to racketeering charges on Tuesday for his role leading a group of scammers who stole more than $245 million in cryptocurrency. Malone Lam, 22, will appear in U.S. District Court in Washington D.C. on December 8 for more information on sentencing. Participating in a RICO conspiracy charges carry sentences ranging from 7 to 20 years. Lam was indicted on scamming charges in September 2024 after drawing law enforcement scrutiny for parlaying stolen crypto into lavish Hamptons vacations, cars and private jets. Prosecutors said Lam, known as “Anne Hathaway,” or “$$$,” ran an operation where he and others would conduct social engineering scams to steal cryptocurrency."
        https://therecord.media/scammer-behind-245-million-crypto-heist-pleads-guilty-rico
        https://www.securityweek.com/partys-over-for-crypto-scammers-who-went-on-a-spending-spree-after-a-240-million-bitcoin-theft/
      • French Prosecutors Confirm Arrest Of Suspected ZeroBytes Hacker Behind Tax Cyberattack
        "French authorities detained an 18-year-old suspected member of the ZeroBytes hacking group over cyberattacks targeting the country's tax authority and other organizations, the Paris prosecutor's office confirmed to Recorded Future News. The suspect was arrested in the Paris region on August 18 and placed in pretrial detention two days later. A second suspect, who is under 16, was arrested on August 26 and later released while investigators examine his devices, prosecutors said Tuesday in response to a media inquiry."
        https://therecord.media/france-hacker-arrest-zerobytes

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) c1c561a3-1bce-4607-94f6-362419364e87-image.png

      1 การตอบกลับ คำตอบล่าสุด ตอบ คำอ้างอิง 0
      • First post
        Last post