<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cyber Threat Intelligence 01 October 2026]]></title><description><![CDATA[<p dir="auto"><strong>New Tooling</strong></p>
<ul>
<li><strong>OWASP Noir: Open-Source Static Analysis Tool</strong><br />
"OWASP Noir is an open-source static analysis tool that reads an application’s source code and lists the endpoints it exposes: paths, HTTP methods, parameters, headers, and cookies, each tied to the file and line it came from. Here’s where it gets useful. Shadow APIs, the endpoints that live in the code but never made it into any documentation, show up in Noir’s inventory right next to everything else, along with deprecated routes and undocumented handlers."<br />
<a href="https://www.helpnetsecurity.com/2026/09/30/owasp-noir-open-source-static-analysis-tool/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/09/30/owasp-noir-open-source-static-analysis-tool/</a><br />
<a href="https://github.com/owasp-noir/noir" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/owasp-noir/noir</a></li>
</ul>
<p dir="auto"><strong>Vulnerabilities</strong></p>
<ul>
<li><strong>Cisco Warns Of New SD-WAN Zero-Day Exploited In Attacks</strong><br />
"Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. Formerly known as SD-WAN vManage, Catalyst SD-WAN Manager is network management software that lets admins monitor and manage up to 6,000 SD-WAN devices from a single dashboard. "In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," the company warned on Wednesday. "Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.""<br />
<a href="https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/</a><br />
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU" target="_blank" rel="noopener noreferrer nofollow ugc">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU</a><br />
<a href="https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html</a></li>
<li><strong>TeamViewer Urges Users To Patch Severe Flaws “as Soon As Possible”</strong><br />
"Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. The highest-severity flaw is a remote session access control bypass (CVE-2026-92370) stemming from an improper access control weakness in TeamViewer Full Client and Host software for Windows, Linux, and macOS that could let remote threat actors perform unauthorized actions leading to remote code execution on targeted systems."<br />
<a href="https://www.bleepingcomputer.com/news/security/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible/</a></li>
<li><strong>WatchGuard Patches Critical Fireware OS Code Injection Vulnerability</strong><br />
"WatchGuard on Tuesday announced fixes for 15 vulnerabilities in Fireware OS, including a critical-severity remote code execution (RCE) bug. Tracked as CVE-2026-86131 (CVSS score of 9.2), the flaw is described as a code injection issue in how the operating system handles BOVPN over TLS client configurations. Successful exploitation could allow a remote attacker who controls the remote VPN server to execute commands with root privileges on the connecting Firebox appliance."<br />
<a href="https://www.securityweek.com/watchguard-patches-critical-fireware-os-code-injection-vulnerability/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/watchguard-patches-critical-fireware-os-code-injection-vulnerability/</a><br />
<a href="https://securityaffairs.com/200108/security/watchguard-fixes-critical-fireware-os-flaw-allowing-remote-code-execution.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://securityaffairs.com/200108/security/watchguard-fixes-critical-fireware-os-flaw-allowing-remote-code-execution.html</a></li>
<li><strong>Chrome, Firefox Updates Patch Over 100 Vulnerabilities</strong><br />
"Google and Mozilla on Tuesday announced fresh Chrome and Firefox updates that address over 100 vulnerabilities. The latest Chrome release was rolled out with fixes for 32 security defects, including a critical-severity buffer overflow issue in ANGLE tracked as CVE-2026-102331 and reported by an external researcher. Google addressed 25 high-severity security weaknesses, most of which are uninitialized resource and use-after-free vulnerabilities. It also resolved five high-severity type confusion flaws in the V8 JavaScript and WebAssembly engine."<br />
<a href="https://www.securityweek.com/chrome-firefox-updates-patch-over-100-vulnerabilities/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/chrome-firefox-updates-patch-over-100-vulnerabilities/</a></li>
<li><strong>CISA Adds One Known Exploited Vulnerability To Catalog</strong><br />
"CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.<br />
CVE-2026-76504 Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability"<br />
<a href="https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog</a></li>
<li><strong>OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted</strong><br />
"A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way through being sent. The flaw, tracked as CVE-2026-84782, is fixed in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8. Fixed versions for the older 3.0, 1.1.1 and 1.0.2 branches go only to customers who pay for OpenSSL's premium support. OpenSSL 3.0 stopped getting public security fixes on September 7."<br />
<a href="https://thehackernews.com/2026/09/openssl-fixes-high-severity-dtls-flaw.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/09/openssl-fixes-high-severity-dtls-flaw.html</a><br />
<a href="https://www.securityweek.com/high-severity-vulnerabilities-patched-in-openssl-wolfssl/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/high-severity-vulnerabilities-patched-in-openssl-wolfssl/</a></li>
</ul>
<p dir="auto"><strong>Malware</strong></p>
<ul>
<li><strong>Beware Of Malware Infection In Facebook Ads Offering Cryptocurrency Rewards</strong><br />
"Just because it’s a familiar tactic doesn’t mean you can let your guard down. A similar attack method using cryptocurrency rewards as bait has recently been identified again. This time, a case was confirmed in which the Node.Js-based malware JSCEAL was distributed through Facebook ads impersonating a cryptocurrency exchange. The threat actors lured users to a site designed to resemble a real exchange, then sent different installation files depending on the operating system to execute the malware. Over the past two months, JSCEAL infections have been confirmed on approximately 1,500 PCs in Korea, with both Windows and macOS systems included as Attack Targets. Let’s take a look at how JSCEAL deceives users, from the moment they click an ad to the malware code execution."<br />
<a href="https://asec.ahnlab.com/en/95645/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/95645/</a></li>
<li><strong>Beware Of SMS Messages Claiming To Protect Your Pi Coin Account—phishing Sites Are Stealing Wallets</strong><br />
"One day, out of the blue, I received a text message claiming to protect my cryptocurrency account. However, this message concealed a sinister intent: to steal the user’s wallet information. Recently, a smishing campaign was identified that impersonated Pi Coin account protection to lure users to phishing pages and steal their cryptocurrency wallet information. The threat actors present a screen designed to look like the actual Pi Network service and trick users into directly entering the confidential information needed to recover their wallets. Since this tactic has been consistently observed in various regions—including the US, Europe, India, and Vietnam—users in Korea cannot afford to let their guard down. Let’s take a closer look at the Pi Coin smishing scheme hidden behind the phrase “account protection.”"<br />
<a href="https://asec.ahnlab.com/en/95646/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/95646/</a></li>
<li><strong>SilverFox: Tracking The Distribution Of a Domestic Variant Of a Malicious Installation File Posing As KakaoTalk</strong><br />
"The threat actor used SEO poisoning (a technique that exploits search results to redirect users to fake sites) to distribute a malicious installer disguised as a KakaoTalk installer. The appearance and packaging method of the installer changed continuously, and the threat actor sequentially used NSIS, Advanced Installer, and Inno Setup. It contained both legitimate installation files and malicious files. When a user ran the disguised installation file, shellcode (code loaded into memory and executed) was triggered, and the malicious payload was executed."<br />
<a href="https://asec.ahnlab.com/en/95642/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/95642/</a></li>
<li><strong>China-Nexus UAT-11587 Targets Government And Policy Organizations Across Asia With Antino Backdoor</strong><br />
"Talos first identified UAT-11587’s campaign while investigating a spear-phishing campaign directed at Taiwan's academic, think tank, and civil society policy community in March 2026. The message recreated Gmail's attachment interface and directed the target into a cloud-hosted, multi-stage infection chain. Across this activity, our researchers assessed that the actor used several delivery methods, loader families, and post-compromise tools. One recurring final-stage payload was a custom Rust backdoor that Talos tracks as Antino. Antino communicates with Microsoft 365 applications and uses Outlook and OneDrive objects as dead drops, rather than depending on a conspicuous dedicated command server."<br />
<a href="https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/</a></li>
<li><strong>Disrupting a Coordinated Model-Distillation Campaign</strong><br />
"We recently identified and disrupted a coordinated campaign designed to extract protected reasoning from our models, with the earliest observed activity occurring in the first week of July. This activity is consistent with adversarial distillation: the systematic and unauthorized use of one model’s outputs or reasoning to help train, reproduce, or improve another model. Protected reasoning is the model’s internal record for working through a task; extracting it can reveal information withheld from the final answer and help others reproduce the model’s capabilities."<br />
<a href="https://openai.com/index/disrupting-a-coordinated-model-distillation-campaign/" target="_blank" rel="noopener noreferrer nofollow ugc">https://openai.com/index/disrupting-a-coordinated-model-distillation-campaign/</a><br />
<a href="https://cyberscoop.com/openai-moonshot-ai-model-distillation-attack/" target="_blank" rel="noopener noreferrer nofollow ugc">https://cyberscoop.com/openai-moonshot-ai-model-distillation-attack/</a></li>
<li><strong>2CLoader: A New Malware Loader Delivering Vidar And Remus</strong><br />
"In August 2026, Zscaler ThreatLabz identified a new loader, which we track as 2CLoader. ThreatLabz has observed the loader being used to distribute information stealers including Vidar and Remus in addition to XWorm RAT. 2CLoader has the ability to perform a wide range of anti-analysis and evasion techniques, including indirect system calls, anti-analysis checks, and installing Windows API hooks. In this blog post, ThreatLabz provides a technical deep dive into 2CLoader, covering its core features, evasion techniques, loader configuration, network communication, payload decryption, and execution options."<br />
<a href="https://www.zscaler.com/blogs/security-research/2cloader-new-malware-loader-delivering-vidar-and-remus" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.zscaler.com/blogs/security-research/2cloader-new-malware-loader-delivering-vidar-and-remus</a></li>
<li><strong>Unauthenticated Command Injection On Internet-Facing Mail Servers: Tracking CVE-2026-73570</strong><br />
"Microsoft Threat Intelligence identified and tracked exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability in the Zimbra Collaboration Suite SNMP notification path. Exploitation can be triggered by a specially crafted email against internet-facing Zimbra servers when the optional zimbra-snmp package is installed and SNMP notifications are enabled, without requiring authentication or user interaction."<br />
<a href="https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/</a><br />
<a href="https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html</a></li>
<li><strong>Phishing Abuses RMM Tools For Persistent Access</strong><br />
"In July 2026, Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed a masqueraded MSP360 Remote Monitoring and Management (RMM) installer through meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected devices and enabled threat actors to gain an initial foothold using trusted administrative software."<br />
<a href="https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/</a><br />
<a href="https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html</a></li>
<li><strong>US-Focused CSuite Phishing Steals Microsoft 365 Sessions And Deploys RMM Tools For Remote Access</strong><br />
"ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud, and persistent access to business systems."<br />
<a href="https://thehackernews.com/2026/09/us-focused-csuite-phishing-steals.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/09/us-focused-csuite-phishing-steals.html</a></li>
<li><strong>Mobile Malware Warning From Ukrainian Researchers Includes iPhone Exploit Kit</strong><br />
"Russian hackers are increasingly targeting the smartphones of Ukrainian military personnel and government officials for espionage and financially motivated attacks, according to a Ukrainian government report published this week. The hackers are going after both Android and iOS devices using malicious apps and sophisticated exploits, according to Ukraine’s State Service of Special Communications and Information Protection (SSSCIP)."<br />
<a href="https://therecord.media/ukraine-ssscip-mobile-malware-warning-ios-android" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/ukraine-ssscip-mobile-malware-warning-ios-android</a></li>
<li><strong>MALFEX - A Malicious Npm Postinstall No Advisory Has Caught For Fourteen Months</strong><br />
"Between August 2023 and September 2026, a single operator publishing under Portuguese-language accounts uploaded at least twelve packages to npm and one payload repository to GitHub. Five packages carry MAL- advisories, three are malicious but unadvised, and four are benign tools the operator ships as cover. The three packages without advisories are the only active threats defenders can target today: function-flag (continuously malicious since 18 July 2025), cdn-img-fetch (still installable after npm seized its parent package, img-to-native), and function-color (a wrapper that pulls function-flag in as a dependency)."<br />
<a href="https://www.cloudsek.com/blog/malfex-malicious-npm-postinstall-supply-chain-campaign" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cloudsek.com/blog/malfex-malicious-npm-postinstall-supply-chain-campaign</a></li>
<li><strong>AI-Assisted Attacks Still Leave a Behavioral Trace</strong><br />
"AI is increasingly being used to accelerate cyber-attacks, but attackers still leave detectable behavioral traces. This blog explores how Darktrace identified suspicious file delivery, command-and-control communications, beaconing activity, and other anomalies linked to AI-assisted campaigns through behavioral analysis."<br />
<a href="https://www.darktrace.com/blog/ai-assisted-attacks-still-leave-a-behavioral-trace" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darktrace.com/blog/ai-assisted-attacks-still-leave-a-behavioral-trace</a></li>
<li><strong>TerminalFix And Lorem Ipsum Loader Enable Covert Tunneling</strong><br />
"In August 2026, Sophos analysts began investigating a series of Managed Detection and Response (MDR) cases that involved ClickFix-style lures and resulted in the deployment of a Python-based tunneling implant. Instead of a typical ClickFix lure that instructs victims to open the Run dialog box, these lures direct users to open a Windows Terminal window. This ClickFix variation is known as ‘TerminalFix’. TerminalFix is not linked to a specific threat group or a single campaign. In 2026, Sophos analysts have observed several malicious campaigns that incorporated these lures (see Figure 1) and resulted in multiple infection chains."<br />
<a href="https://www.sophos.com/en-us/blog/terminalfix-and-lorem-ipsum-loader-enable-covert-tunneling" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.sophos.com/en-us/blog/terminalfix-and-lorem-ipsum-loader-enable-covert-tunneling</a></li>
</ul>
<p dir="auto"><strong>Breaches/Hacks/Leaks</strong></p>
<ul>
<li><strong>DIVD Says Zammad Zero-Days Enabled AI-Driven Network Breach</strong><br />
"The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. Previously, the nonprofit organization of volunteer security researchers said the attack was “loud and very, very messy,” driven by an AI agent that moved autonomously and decided its next steps without external intervention or direction. DIVD retrieved extensive details about the attack because the AI agent left behind clear explanations of its decisions, allowing the organization to reconstruct the incident."<br />
<a href="https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/</a></li>
<li><strong>GitHub Repos Exposed 543,699 Credentials. Nobody Revoked Them.</strong><br />
"We scanned 224 million public GitHub repositories, a snapshot of public code assembled to train AI models (The Stack v3), and found 543,699 unique credentials that still authenticated when we tested them in July 2026. The median one had been sitting in a public default branch for 784 days. The oldest was committed in 2009 and still works. Just under 200,000 of them were pushed after GitHub turned push protection on by default. The block does work where it applies, roughly halving the rate at which the credentials it recognises reach public code, but 51.8 percent of what is still live is a shape it does not recognise, and nothing about it helps the half million already there."<br />
<a href="https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them" target="_blank" rel="noopener noreferrer nofollow ugc">https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them</a><br />
<a href="https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/</a></li>
<li><strong>Bitget Hacked Via Zero-Day In Third-Party Security Products</strong><br />
"Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. According to Bitget, two separate investigations by blockchain security firm SlowMist and Google Cloud's cyber-defense arm Mandiant said the threat actors accessed Bitget's wallet environment after compromising two security appliances with zero-day exploits."<br />
<a href="https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/</a></li>
<li><strong>South Africa Seeks Help After Cyberattack Targets Air Traffic Control</strong><br />
"The South African state-owned company that provides air traffic control (ATC) and weather operations for approximately 10% of the world's airspace discovered ransomware-linked malware in an operational technology (OT) network, according to public documents released this month. The company, Air Traffic and Navigation Services (ATNS), believes that its technical team stopped the attack, but it issued a request for quotes (RFQ) seeking cyber-forensics firms to investigate the incident. A second attack, possibly an insider's theft of data, is also part of the investigation request."<br />
<a href="https://www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control</a></li>
<li><strong>PixelLeak: How AI Agents Exposed Developer Screenshots From Leading Tech Companies</strong><br />
"Every day, developers hand the last mile of their work to an AI coding agent: summarize your changes, attach screenshots showing the changes, then submit them for review. It’s common sense that screenshots of internal, unreleased development work should not be posted where anyone can see them. But many AI agents have been doing just that. Glow Labs has identified over 13,000 internal images published openly on GitHub by developers at over 300 organizations, including one of the world's largest tech companies, a frontier AI lab, a major enterprise software provider, and a Fortune 500 travel company. In this post we share how AI agents quietly leaked thousands of pre-release screenshots, why no security team caught it, and how to check if you're affected."<br />
<a href="https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies</a><br />
<a href="https://thehackernews.com/2026/09/ai-coding-agents-exposed-13000-internal.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/09/ai-coding-agents-exposed-13000-internal.html</a><br />
<a href="https://www.helpnetsecurity.com/2026/09/30/ai-coding-agents-github-screenshot-leak/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/09/30/ai-coding-agents-github-screenshot-leak/</a></li>
<li><strong>OpenInfra Europe’s JFrog Artifactory Instance Breached, Packages Potentially Compromised</strong><br />
"Attackers have compromised a self-hosted JFrog Artifactory instance operated by OpenInfra Europe, the regional hub of the OpenInfra Foundation warned in a security notice prominently displayed on its homepage. “Anyone who downloaded or installed artifacts from <a href="https://artifactory.nordix.org/" target="_blank" rel="noopener noreferrer nofollow ugc">https://artifactory.nordix.org/</a> from August 28 and September 15, 2026 should immediately stop using them, remove them from their pipelines, and treat these packages as potentially compromised,” the message says."<br />
<a href="https://www.helpnetsecurity.com/2026/09/30/openinfra-jfrog-artifactory-instance-compromised/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/09/30/openinfra-jfrog-artifactory-instance-compromised/</a></li>
</ul>
<p dir="auto"><strong>General News</strong></p>
<ul>
<li><strong>August 2026 Threat Trend Report On APT Attacks (South Korea)</strong><br />
"AhnLab monitored APT (Advanced Persistent Threat) attacks targeting entities in Korea using its own infrastructure. This report summarizes the types and statistics on domestic APT attacks identified during the month of August 2026."<br />
<a href="https://asec.ahnlab.com/en/95649/" target="_blank" rel="noopener noreferrer nofollow ugc">https://asec.ahnlab.com/en/95649/</a></li>
<li><strong>Vulnerability Discovery And Exploitation Trends In The AI Era</strong><br />
"Google Threat Intelligence Group (GTIG) examines vulnerability disclosure and exploitation statistics to evaluate the impact of artificial intelligence (AI) on the vulnerability threat landscape. We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered."<br />
<a href="https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era" target="_blank" rel="noopener noreferrer nofollow ugc">https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era</a><br />
<a href="https://therecord.media/google-vulnerabilities-cyberattacks-ai" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/google-vulnerabilities-cyberattacks-ai</a><br />
<a href="https://www.bankinfosecurity.com/google-ai-finding-more-medium-risk-flaws-a-32979" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bankinfosecurity.com/google-ai-finding-more-medium-risk-flaws-a-32979</a><br />
<a href="https://www.infosecurity-magazine.com/news/ai-found-vulnerabilities-rce/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.infosecurity-magazine.com/news/ai-found-vulnerabilities-rce/</a><br />
<a href="https://www.securityweek.com/google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.securityweek.com/google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery/</a></li>
<li><strong>EU Cyber Resilience Act Requirements For Containers And Kubernetes</strong><br />
"Starting in full force on Dec. 10, 2024, the EU Cyber Resilience Act (CRA) is a regulation (EU 2024/2847) that defines mandatory cybersecurity requirements for all products with digital elements sold in EU markets. Reporting obligations will begin on Sept. 11, 2026, with full enforcement kicking in on Dec. 11, 2027. The CRA brings new requirements for teams working with containers and Kubernetes regarding how cloud native applications are built, distributed, and maintained throughout their lifecycle."<br />
<a href="https://www.helpnetsecurity.com/2026/09/30/rapidfort-cra-container-compliance/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/09/30/rapidfort-cra-container-compliance/</a></li>
<li><strong>Most Open Critical And High Flaws Are Over 90 Days Old</strong><br />
"Detectify analyzed exposure data from 1,293 of its customers in the US, the UK and the Nordics and found that most serious flaws still open on their internet-facing systems are months old. Of the critical and high-severity vulnerabilities open at the time of the snapshot, 97% in the Nordics had been exposed for more than 90 days, along with 92% in the UK and 86% in the US. The organizations already know about these flaws. Detectify says it confirms findings with payload-based testing, which sends a working attack request and checks the response, so the backlog consists of issues its scanner judged exploitable. In the best-performing market, fewer than one in seven open critical or high findings is less than three months old."<br />
<a href="https://www.helpnetsecurity.com/2026/09/30/research-unpatched-vulnerabilities-backlog/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/09/30/research-unpatched-vulnerabilities-backlog/</a></li>
<li><strong>Most Organizations Need Six Months Or Longer To Roll Out New Security Controls</strong><br />
"Cisco surveyed 8,000 security professionals in 30 markets about how well their organizations defend against AI-era threats, and only 8% landed in the top group. Cisco gave the most weight in its scoring to internal friction, meaning the delays and turf problems inside a company that slow a security team when something changes. Cisco says frontier AI models can find software vulnerabilities at a scale and speed no human team working alone can match. Fewer than one in ten respondents are confident they can stay ahead of the flood of new threats. Their answers put the slowdown inside the company: procurement delays, infrastructure decisions that IT owns, and priorities the C-suite sets elsewhere. Cisco says teams have the tools, and the drag comes from how the organization runs."<br />
<a href="https://www.helpnetsecurity.com/2026/09/30/relentless-defense-cisco-cybersecurity-survey/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.helpnetsecurity.com/2026/09/30/relentless-defense-cisco-cybersecurity-survey/</a></li>
<li><strong>Your Car’s App Could Be Telling Big Tech Who You Are And Where You Go</strong><br />
"A study testing 21 cars from 19 brands and 30 companion apps found connections to advertising and tracking companies, and evidence that some apps shared sensitive personal data. Modern cars can unlock remotely, route around traffic, stream entertainment, summon roadside help, and cool or heat the cabin before you get in. But those conveniences come with a privacy cost that drivers may struggle to see and are unable to refuse. We’ve covered cars and privacy a few times before, especially after Mozilla researchers described cars as a “privacy nightmare.”"<br />
<a href="https://www.malwarebytes.com/blog/news/2026/09/your-cars-app-could-be-telling-big-tech-who-you-are-and-where-you-go" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.malwarebytes.com/blog/news/2026/09/your-cars-app-could-be-telling-big-tech-who-you-are-and-where-you-go</a><br />
<a href="https://therecord.media/automakers-routinely-share-connected-car-data-third-parties" target="_blank" rel="noopener noreferrer nofollow ugc">https://therecord.media/automakers-routinely-share-connected-car-data-third-parties</a></li>
<li><strong>Ransomware Leverage Is Growing By The Terabyte: Takeaways From ThreatLabz 2026 Ransomware Report</strong><br />
"Ransomware is no longer defined only by how many organizations get hit. The most important shifts are happening beneath the headline victim counts; in how attackers gain access, who they target first, and how much data they steal once they’re in. The newly released Zscaler ThreatLabz 2026 Ransomware Report examines ransomware activity from April 2025 through March 2026, with a focus on groups and affiliates, victim targeting, attack techniques, data theft, and payment patterns."<br />
<a href="https://www.zscaler.com/blogs/security-research/ransomware-leverage-growing-terabyte-takeaways-threatlabz-2026-ransomware" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.zscaler.com/blogs/security-research/ransomware-leverage-growing-terabyte-takeaways-threatlabz-2026-ransomware</a></li>
<li><strong>EvilTokens Takedown Shows Why Cybercrime Platforms Are Getting Harder To Stop</strong><br />
"Microsoft’s disruption of the EvilTokens phishing-as-a-service platform highlights a growing challenge for defenders: Cybercrime infrastructure may be getting easier to rebuild than it is to dismantle. AI-assisted development, inexpensive infrastructure, and increasingly decentralized services are enabling criminal groups to recover quickly when individual platforms are taken offline."<br />
<a href="https://blog.barracuda.com/2026/09/30/eviltokens-takedown-cybercrime-platforms-harder-to-stop" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.barracuda.com/2026/09/30/eviltokens-takedown-cybercrime-platforms-harder-to-stop</a></li>
<li><strong>Know Your Enemy: Browser-Based Attack Techniques In 2026</strong><br />
"Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most dangerous techniques that should be on every security team's radar in 2026."<br />
<a href="https://thehackernews.com/2026/09/know-your-enemy-browser-based-attack.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2026/09/know-your-enemy-browser-based-attack.html</a></li>
<li><strong>More Than Half Of UK Businesses Lack Confidence In Basic Cyber Skills</strong><br />
"More than half of UK businesses lack confidence in their ability to perform at least one basic cybersecurity task, according to the government's latest skills survey. The annual research found 57 percent of businesses reported a basic technical skills gap, up from 49 percent last year despite tighter national standards and repeated government warnings about cyber resilience."<br />
<a href="https://www.theregister.com/security/2026/09/30/more-than-half-of-uk-businesses-lack-confidence-in-basic-cyber-skills/5299991" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.theregister.com/security/2026/09/30/more-than-half-of-uk-businesses-lack-confidence-in-basic-cyber-skills/5299991</a></li>
</ul>
<p dir="auto"><strong>อ้างอิง</strong><br />
Electronic Transactions Development Agency (ETDA) <img src="/assets/uploads/files/1790951856889-c8bc407b-2488-4787-9004-7305c576d79b-image.png" alt="c8bc407b-2488-4787-9004-7305c576d79b-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://webboard-nsoc.ncsa.or.th/topic/3356/cyber-threat-intelligence-01-october-2026</link><generator>RSS for Node</generator><lastBuildDate>Fri, 02 Oct 2026 22:41:31 GMT</lastBuildDate><atom:link href="https://webboard-nsoc.ncsa.or.th/topic/3356.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 02 Oct 2026 14:37:40 GMT</pubDate><ttl>60</ttl></channel></rss>