NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ

    Cyber Threat Intelligence 30 September 2026

    Cyber Security News
    1
    1
    24
    โหลดโพสเพิ่มเติม
    • เก่าสุดไปยังใหม่สุด
    • ใหม่สุดไปยังเก่าสุด
    • Most Votes
    ตอบ
    • ตอบโดยตั้งกระทู้ใหม่
    เข้าสู่ระบบเพื่อตอบกลับ
    Topic นี้ถูกลบไปแล้ว เฉพาะผู้ใช้งานที่มีสิทธิ์ในการจัดการ Topic เท่านั้นที่จะมีสิทธิ์ในการเข้าชม
    • NCSA_THAICERTN
      NCSA_THAICERT
      แก้ไขล่าสุดโดย

      Industrial Sector

      • Toptech TMS7 And TopHAT
        "Successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02
      • VIVOTEK Camera Firmware
        "Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03
      • Anjvision YSSD-RTMP-H5
        "Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05
      • MikroTik RouterOS
        "Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06
      • Viidure Dashcam Android Application
        "Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire platform."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07
      • Lantronix G520 Series Cellular Gateway
        "Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-01
      • Baicells Nova 430H
        "Successful exploitation of this vulnerability could allow an attacker to inject malformed messages which may lead to a denial-of-service condition."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-04

      New Tooling

      • OperTraitors: How Kubernetes Operators Betray Your Security Posture
        "Kubernetes operators are coded to drastically reduce operational toil by acting as automated site reliability engineers. However, their reliance on highly privileged service accounts introduces a severe, often overlooked security weak spot. To quantify and combat threats aiming to take advantage of this weak spot, we have released OperTraitor, an open-source, large language model (LLM)-powered analysis engine. OperTraitor ingests raw role-based access control (RBAC) configurations directly from locally installed operators and the OperatorHub catalog. Upon doing so, it calculates the difference between an operator's documented functionality and its actual granted privileges."
        https://unit42.paloaltonetworks.com/agentic-ai-kubernetes-operator-risks/
        https://github.com/paloaltonetworks/opertraitor

      Vulnerabilities

      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-86950 Apple Multiple Products Out-of-Bounds Write Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/29/cisa-adds-one-known-exploited-vulnerability-catalog
      • New Spectre v2 Attack Variant Leaks Linux Root Password Hash In Minutes
        "A new Spectre v2 attack variant called Branch Target Reuse (BTR) can recover root password hashes from Intel computers running Linux in just a few minutes. A BTR attack exploits stale information in a processor's branch predictor after a just-in-time (JIT) engine reuses memory for new code. By manipulating this leftover information, an attacker can trick the processor into temporarily executing the wrong instructions and potentially expose sensitive data."
        https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/
        https://www.vusec.net/projects/btr
        https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html
        https://www.securityweek.com/new-spectre-v2-variant-exposes-intel-amd-arm-cpus-to-data-leaks/
      • Kiteworks Patches Critical Flaw, Brings Customer Systems Online
        "American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. Formerly known as Accellion, it operates a Private Content Network (PCN) that integrates enterprise email, file sharing, Managed File Transfer (MFT), APIs, and web forms into a single platform. Kiteworks provides services to thousands of global corporations and government agencies, and its Private Data Network has over 100 million end-users."
        https://www.bleepingcomputer.com/news/security/kiteworks-lifts-shutdown-warning-after-patching-critical-flaw/
        https://www.kiteworks.com/company/press-releases/kiteworks-restores-systems-credible-threat/
        https://thehackernews.com/2026/09/kiteworks-fixes-critical-flaw-found.html
        https://cyberscoop.com/kiteworks-lifts-shutdown-advisory-after-credible-threat-intelligence-from-federal-authorities/
        https://www.infosecurity-magazine.com/news/kiteworks-customers-restart/
      • Look, Don't Load: Model Inspection In Unsloth Studio Leads To Critical Arbitrary Code Execution
        "What is Unsloth. Unsloth is one of the most popular open-source libraries for fine-tuning and quantizing LLMs, and it makes work that used to require deep systems knowledge accessible to a very large community. Studio is its browser-based front end, currently in beta. Enterprise relevance. Unsloth is part of established AI development workflows: Databricks includes the library in its AI v5 environment. Its role also extends to model distribution. Hugging Face ranks Unsloth as the third-largest source of model derivatives on the Hub, behind Qwen and Google, and a Forbes analysis highlights the need for enterprises to track the third-party artifacts they consume. These facts establish Unsloth’s relevance to enterprise AI teams, though they do not measure adoption of the affected Studio interface."
        https://www.pillar.security/blog/look-dont-load-model-inspection-in-unsloth-studio-leads-to-critical-arbitrary-code-execution
        https://www.darkreading.com/application-security/unsloth-studio-flaw-model-inspection-code-execution
      • Package Name To Role Credentials In Code Interpreter: Two RCE CVEs In The AgentCore Python SDK
        "One package name was all it took: the BeyondTrust Phantom Labs team turned a routine pip install into remote code execution inside an Amazon Bedrock AgentCore Code Interpreter sandbox twice, and, where the customer had configured the interpreter with an execution role, into that role's AWS credentials. This blog breaks down both CVEs in the AgentCore Python SDK and the proof-of-concept exploits behind them."
        https://www.beyondtrust.com/blog/entry/amazon-bedrock-agentcore-python-sdk-rce-cves
        https://www.infosecurity-magazine.com/news/aws-agentcore-sdk-flaws-ai/
      • Cycode Uncovers Account Takeover In MCP Python SDK
        "A malicious MCP server tricked the SDK into sending login credentials to the attacker instead of the real login provider. The Model Context Protocol (MCP) is an open standard introduced by Anthropic and donated to the Linux Foundation’s Agentic AI Foundation (AAF), which maintains it."
        https://cycode.com/blog/mcp-python-sdk-oauth-account-takeover/
        https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html
      • Self-Replicating Prompt Injections Exist
        "We show the existence of a new variety of prompt injection, which can self-propagate akin to a computer worm. No impact was observed outside of the simulated tool calls in training and evaluation; we are sharing this due to the novel nature of the prompt injection, not because of any incident."
        https://alignment.openai.com/misalignment-reports/self-replicating-prompt-injections-exist/
        https://www.theregister.com/security/2026/09/29/add-one-more-ai-worry-to-the-nightmare-scenario-self-replicating-prompt-injections/5299922

      Malware

      • Swarming Against Citrix 0-Day Exploitation
        "GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. GreyNoise also expands the GOG through Project Swarm, which enables the broader security community to join the effort. The activity discussed in this blog was derived from a Swarm participant sensor."
        https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation
        https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances
        https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/
        https://cyberscoop.com/citrix-netscaler-zero-day-attacks-three-weeks-undetected/
        https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867
        https://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/
      • Beware Of Phishing Emails Disguised As Quote Requests
        "Recently, the AhnLab SEcurity intelligence Center (ASEC) confirmed that phishing emails disguised as requests for project quotes are being circulated. The email body is disguised as a request to submit a quote for discussing the project budget and prompts recipients to download an attached compressed file for verification."
        https://asec.ahnlab.com/en/95599/
      • Beware Of Phishing Emails That Disguise Themselves As Project Material Purchase Requests
        "Recently, the AhnLab SEcurity intelligence Center (ASEC) identified a case of phishing emails that disguise themselves as project material purchase request forms. These emails impersonate employees of a specific company in Korea and trick recipients into opening a malicious XLS file attached to the email, which is disguised as a project material purchase request form."
        https://asec.ahnlab.com/en/95598/
      • Attackers Abuse ChatGPT Custom GPTs To Deliver RAT Via ClickFix
        "Attackers are abusing ChatGPT Custom GPTs to impersonate legitimate product offerings, then directing victims to a malicious "backup" site through a trusted ChatGPT-hosted interface. Huntress researchers found two Custom GPTs linked to the same campaign that were being used in this manner. The campaign uses a ClickFix lure to trick victims into running PowerShell, which downloads a malicious MSI and begins a multi-stage, obfuscated infection chain. The payload establishes resilient access through dual persistence and DLL sideloading, using a Canon-signed executable (and, in a later wave, a Stardock-signed one) to load malicious code. Huntress investigated at least 40 related incidents, including two confirmed Custom GPT-driven infections."
        https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat
        https://www.bleepingcomputer.com/news/security/custom-chatgpts-push-clickfix-attacks-to-deploy-rat-malware/
        https://www.securityweek.com/hackers-use-chatgpt-custom-gpts-in-clickfix-attacks/
        https://www.helpnetsecurity.com/2026/09/29/malicious-chatgpt-custom-gpt-malware-via-clickfix/
      • Star Blizzard Refines Phishing And Malware Delivery With The RedFlick Technique
        "Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique that Microsoft tracks as “RedFlick”. These changes represent a notable shift in the actor’s operational tradecraft and support ongoing cyberespionage activity targeting Ukrainian individuals and institutions as well as international non-government organizations (NGOs), Western think tanks, governments, and other organizations associated with international policy—particularly those with a nexus in supporting Ukraine."
        https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/
        https://cyberscoop.com/microsoft-star-blizzard-redflick-phishing-campaigns/
      • From BlackCat To Panda Workshop: Inside The Evolving C2 Panel Behind RATHat
        "RATHat is an Android banking trojan recently documented in public reporting, distinguished by an architecture in which the malicious application is only the entry point. Once granted the Accessibility Service, the application enables wireless debugging on its own, pairs with the device's ADB daemon to obtain a shell, and uses it to stage a native Go service and an FRP client that opens a reverse tunnel to the operator. The service runs outside the application's process and permission model, keeps its own channel to the C2, and survives the removal of the application until the next reboot. A shell that the malware grants itself, rather than a permission the user grants the application, is a model other families may adopt, and security controls should extend to this scope."
        https://www.cleafy.com/cleafy-labs/from-blackcat-to-panda-workshop-inside-the-evolving-c2-panel-behind-rathat
        https://www.infosecurity-magazine.com/news/rathat-c2-panel-malware-as-a/
      • Fake iPhone Duo Preorder Scam Triggers DarkSword Attack
        "Apple announced its first foldable iPhone on September 9, and scammers were ready to ‘deliver’ one before anyone could buy it. Most of what we found around the launch of the iPhone Duo and iPhone 18 Pro was familiar fraud. But one fake preorder page was different."
        https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-iphone-duo-preorder-scam-triggers-darksword-attack
      • From EDU Account Takeover To Job Scam Abuse: West African Fraud Actors Target Universities
        "Proofpoint is tracking a cluster of threat activity specifically targeting U.S. universities. The fraud ecosystem observed in campaigns aligns with known advance fee fraud (AFF) tactics. The campaigns begin with credential harvesting attempts that lead to job scam monetization leveraging AFF. University students, staff, and alumni are a perennial target for many different types of cybercrime, including job scams, fake scholarships, and account takeover (ATO) activities. Threat actors find higher education email accounts valuable for a variety of reasons including: younger students may have less experience with email correspondence and are new to engaging with potential work or money-making opportunities; alumni may still have active email accounts, but may not use them frequently, providing an opportunity for threat actors to hijack their contact lists; and staff and faculty are constantly receiving communications from students, parents, community members, etc. from a variety of personal and university emails."
        https://www.proofpoint.com/us/blog/threat-insight/edu-account-takeover-job-scam-abuse-west-african-fraud-actors-target
      • PhantomSub: Malicious Npm Campaign Secretly Adds Users To WhatsApp Spam Channels
        "The OX Research team identified 101 npm packages as part of a malicious WhatsApp group subscriber campaign. The malicious packages abuse the “Baileys” WhatsApp open source project to add the victims to groups without their consent. 16 of those packages were removed from npm as of September 28, 2026. Earlier reports of Baileys WhatsApp campaign were made by SafeDep, OSV and Xygeni back in August and September 2026. Baileys is an open source project containing an unofficial implementation of the WhatsApp API used by developers to automate actions through their WhatsApp accounts – such as customer support bots, chat managers or data scraping."
        https://www.ox.security/blog/phantomsub-malicious-npm-campaign-secretly-adds-users-to-whatsapp-spam-channels/
        https://thehackernews.com/2026/09/101-malicious-npm-packages-add.html
      • Operation Master: Deconstructing a Multi-Tiered Intrusion And Monetization Pipeline
        "SOCRadar Threat Research Unit (STRU) has uncovered an end-to-end cybercrime operation dubbed Operation Master, in which a threat actor compromised enterprise networks, stole customer and billing databases, offered portions of the data for sale on underground forums, and later repurposed those exact assets to power an automated, multi-tenant invoice fraud platform. Operating across multiple countries, the threat actor compromised critical network infrastructure, including VPN gateways via a GlobalProtect authentication bypass (CVE-2026-0257), while concurrently executing advanced web application exploits, deploying the AdaptixC2 framework, and leveraging an AI-assisted development workflow."
        https://socradar.io/blog/operation-master-intrusion-monetization-pipeline/

      Breaches/Hacks/Leaks

      • It Was a Matter Of When, Not If...
        "Security people always say it’s not a matter of if, but when you get hacked. It took us (almost) seven years but we can now say that we’re the hackers that got hacked. We noticed suspicious activity, investigated, and came to the inevitable conclusion that damn, we got hacked. So what do hackers do when they get hacked? Handle it the way we think it should be handled. That is open, transparent and honest, even if it sucks. So far, we’ve been in full incident response mode, blocked access to our infrastructure and started a forensics investigation with the assistance of a third party incident response team."
        https://www.divd.nl/newsroom/articles/when-no-if/
        https://www.bleepingcomputer.com/news/security/automated-ai-agent-used-to-breach-cybersecurity-nonprofit-divd/
      • French Tax Data Theft Using Stolen Staff Passwords Went Undetected For Seven Weeks
        "An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a report (in French) published on Tuesday: it worked because of weak login protection, poorly separated networks and gaps in monitoring. The tax administration, known as the DGFIP, runs France's tax website, impots.gouv.fr. The data came from E-Contact, the tool taxpayers use to message the tax administration."
        https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html
      • Russian Pizza Chain With 1,500 Locations Confirms Cyberattack Following Hacker Claims
        "Hackers breached the systems of popular Russian fast-food chain Dodo Pizza and gained access to some customers’ personal information, the company said Monday. According to Dodo Pizza, the potentially compromised information included customers’ names, addresses, email addresses, phone numbers, dates of birth and order details. The company said it does not store customers’ payment information and that payment data was therefore not compromised. “The attackers’ access has been blocked, and an internal investigation is ongoing,” Dodo Pizza said, adding that it had notified Russian communications regulator Roskomnadzor about the incident."
        https://therecord.media/russian-pizza-chain-dodo-confirms-data-breach
      • Arizona Supreme Court Says Hackers Stole Residents’ Personal Data
        "The Arizona Supreme Court announced Friday that the state’s court system was attacked by hackers who stole the personal information of “many Arizonans.” Arizona Supreme Court Chief Justice Ann Scott Timmer said in a statement that the state court system was targeted by criminal hackers “or their bots.” “Court leaders believe the criminal hackers copied personally identifiable information about many Arizonans,” Timmer said. “The Supreme Court’s Administrative Office of the Courts is in the process of alerting as many people as possible whose information it believes the criminal hackers copied.”"
        https://therecord.media/arizona-supreme-court-says-hackers-stole-data
      • Pentagon Personnel Agency Data Breach Impacts 3 Million People
        "The US Defense Manpower Data Center (DMDC), which maintains personnel records for the Pentagon, has started notifying people that their personal information was exposed. According to the DMDC’s notice, unauthorized users had access to one of its file-sharing servers for roughly nine months. A copy of the notification letter, dated September 18 and shared online by a recipient, says the problem was discovered in mid-July."
        https://www.securityweek.com/pentagon-personnel-agency-data-breach-impacts-3-million-people/
        https://securityaffairs.com/200017/uncategorized/three-million-affected-in-pentagon-personnel-agency-data-breach.html

      General News

      • Former US Air Force Members Sent To Prison Over BEC Attacks
        "Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. According to court documents, 25-year-old Chijioke Timothy Odimegwu and 26-year-old Harafat Mogaji carried out these attacks while stationed at Dover Air Force Base in Delaware."
        https://www.bleepingcomputer.com/news/security/former-us-air-force-members-sent-to-prison-over-bec-attacks/
        https://therecord.media/us-air-force-members-given-6-year-sentence-cyber
      • Vietnamese Man Charged In $16 Million 'pig Butchering' Crypto Scam
        "A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. 37-year-old Trung Nguyen Van entered the United States through the San Ysidro, California / Mexico pedestrian border entry point on September 22 and was arrested before boarding a flight to Taiwan out of Los Angeles International Airport on September 24. One of Van's victims transferred about $16 million in cryptocurrency between June and August 2024 in transfers directly traceable to Van's cryptocurrency wallet, believing they were investing in a crypto investment platform called "Triangle.""
        https://www.bleepingcomputer.com/news/security/vietnamese-man-charged-in-16-million-pig-butchering-crypto-scam/
      • Pro-Russia Hacktivists Increase OT Intrusion Claims Across EU
        "Claims of cyberattacks against operational technology and industrial environments increased significantly in 2025 - particularly those involving pro-Russia hacktivist groups, the European Union Agency for Cybersecurity warned. ENISA released its annual Threat Landscape report last week, finding that ideology-driven malicious cyberattacks accounted for 57.3% of all incidents the agency recorded in 2025, followed by financially motivated activity at about 30%. In total, there were 4,709 hacktivist claims against European Union member states last year, 89.5% of which involved distributed denial-of-service attacks. The rest involved unauthorized access."
        https://www.bankinfosecurity.com/pro-russia-hacktivists-increase-ot-intrusion-claims-across-eu-a-32966
        https://www.enisa.europa.eu/sites/default/files/2026-09/ENISA Threat Landscape 2026_Final.pdf
      • OpenAI’s GPT-6 Astra Ran Supply Chain Attacks Despite Being Told Not To
        "OpenAI’s GPT-6 Astra carried out supply chain attacks on software outside the scope of a security test, according to the UK AI Security Institute (AISI). AISI tested the model before its public release. The tests ran inside a simulation, so no live systems were touched. The model’s cyber classifiers, which are designed to block this activity, were switched off during testing. “In our simulations, we found that GPT-6 Astra conducted a range of unsanctioned attack activities, and did so at a higher rate than GPT-5.6 Sol and GPT-5.5. Attack activities included GPT-6 Astra creating fake identities which it used to deceive developers, posting comments from fake accounts arguing against the results of accurate security reviews, and delivering malicious payloads to open-source codebases,” the UK government research organization wrote."
        https://www.helpnetsecurity.com/2026/09/29/openai-gpt-6-astra-supply-chain-attacks-test-simulations/
        https://www.aisi.gov.uk/blog/gpt-6-astra-performs-unsanctioned-supply-chain-attacks-in-simulations
        https://securityaffairs.com/199947/ai/gpt-6-astra-and-the-supply-chain-attack-it-wasnt-asked-to-launch.html
      • OpenAI Agents Go Rogue: When AI Agents Bypass Guardrails
        "Recently and rather quietly, there have been reports that describe an alarming case where thousands of AI agents used a dormant wiki as a coordination mechanism. On the surface, it’s a fascinating technical story. But for technology leaders, it serves as something more important: a case study or a cautionary tale of how autonomous systems behave when given marching orders, tools, and enough freedom to pursue and produce outcomes."
        https://blog.barracuda.com/2026/09/29/openai-agents-go-rogue-ai-agent-governance
      • Four Cyber Threats Harboring Big Plans For The Future
        "Not unlike the fictional Skynet sending increasingly sophisticated ‘Terminators’ as older versions of the monster failed to achieve their earthly missions, cyberattacks are growing more persistent and automated, further testing an organization’s security maturity. To stay in tune with future risks, it has become imperative to treat resilience as an operational objective in constant flux."
        Priority: 3 - Important
        Relevance: General
        https://www.securityweek.com/four-cyber-threats-harboring-big-plans-for-the-future/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 032a1bd9-803f-4861-9aca-1f06b4e89063-image.png

      1 การตอบกลับ คำตอบล่าสุด ตอบ คำอ้างอิง 0
      • First post
        Last post