NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ

    Cyber Threat Intelligence 02 October 2026

    Cyber Security News
    1
    1
    8
    โหลดโพสเพิ่มเติม
    • เก่าสุดไปยังใหม่สุด
    • ใหม่สุดไปยังเก่าสุด
    • Most Votes
    ตอบ
    • ตอบโดยตั้งกระทู้ใหม่
    เข้าสู่ระบบเพื่อตอบกลับ
    Topic นี้ถูกลบไปแล้ว เฉพาะผู้ใช้งานที่มีสิทธิ์ในการจัดการ Topic เท่านั้นที่จะมีสิทธิ์ในการเข้าชม
    • NCSA_THAICERTN
      NCSA_THAICERT
      แก้ไขล่าสุดโดย

      Industrial Sector

      • Armatura LLC Armatura One
        "Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01
      • Monta Monta.app
        "Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-02
      • CISA Malcolm
        "The following versions of CISA Malcolm are affected:"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01
      • ABB Protection And Control IED Manager PCM600
        "Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-03
      • Johnson Controls EasyIO Neo Series EC And CW Controllers
        "Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-04
      • Johnson Controls EasyIO Neo Series EC And CW Controllers
        "Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-05
      • Meari IoT Cloud Platform OpenAPI Service
        "Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-06

      Vulnerabilities

      • Fortinet Warns Of Critical FortiMail Flaw Exploited In Zero-Day Attacks
        "Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. The vulnerability is rated critical, with a CVSS score of 9.8, and affects the FortiMail management interface. "An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests," Fortinet said in an advisory published Thursday."
        https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/
        https://fortiguard.fortinet.com/psirt/FG-IR-26-175
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog
      • Apple CoreGraphics PoC Emerges As WhatsApp PDF Checks Hint At Possible Delivery Path
        "Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working exploit is separate work the analysis does not demonstrate. Apple patched the flaw on September 28, crediting Meta Product Security with the discovery and noting it may have been used in an "extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.""
        https://thehackernews.com/2026/10/apple-coregraphics-poc-emerges-as.html
        https://securityaffairs.com/200175/hacking/public-poc-released-for-apple-coregraphics-zero-day-cve-2026-86950.html

      Malware

      • AI Agents Targeted U.S. And Canadian Government Websites
        "Following up on our previous blog post, we discovered several additional incidents where rogue AI agents appear to have used aggressive techniques to access publicly available data on government websites. This includes two rudimentary and failed hacking attempts, one against the U.S. Department of Education’s Civil Rights Data Collection, and one against Library and Archives Canada, a Canadian federal agency. These failed attempts connect to additional rogue activity where agents used an array of aggressive tactics short of hacking to probe U.S. government websites, often using sites in unintended ways and sometimes violating explicit usage policies. This activity targeted websites across the White House, the Departments of War, Justice, and Commerce, the CDC and SEC, and state agencies in California, Maryland, Illinois, Texas, and New York."
        https://transluce.org/us-canada-gov
        https://www.bleepingcomputer.com/news/security/autonomous-ai-agents-tried-to-hack-us-canadian-government-websites/
      • Hallucinating Credibility: China-Aligned TA419 Impersonates Its Way Into US AI Policy Circles
        "In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US. The group first sent benign conversation starter emails, which included calls to action themed around AI policy such as joining an “AI Policy Advisory Committee”, to build rapport and solicit a response from the target. Once the target replied, TA419 followed up with a multi-stage URL redirection chain that led to an Adversary-in-the-Middle (AitM) credential phish that employed a customized version of the open-source Browser-in-the-Browser (BitB) phishing tool Frameless BitB."
        https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy
        https://therecord.media/china-linked-phishing-scheme-backdoor-taiwan
        https://cyberscoop.com/china-cyber-espionage-ta419-phishing-us-ai-policy-experts/
        https://www.infosecurity-magazine.com/news/ta419-impersonates-ai-experts-us/
      • Warlock Ransomware Attackers Hit Water And Telecom Operators
        "The China-nexus group behind Warlock ransomware is still breaking into organizations through Microsoft SharePoint vulnerabilities, a tactic that brought it to prominence a year ago. In the past two months, the group, which Symantec tracks as Longlegs (aka Storm-2603), attacked at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. The victims included two critical infrastructure operators, a water utility and a telecommunications provider, along with a regional government body and a university."
        https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure
        https://www.darkreading.com/cyberattacks-data-breaches/warlock-ransomware-spanish-portuguese
      • Milk Dragon: Huge Discounts On Social Media? Think Twice Before You Buy
        "Phishing doesn’t always arrive in your inbox. In previous Group-IB blogs (GTFire Phishing Scheme and Phoenix Rising), we covered attacks that start with a suspicious email or text message. But some lures are designed to find you where your guard is at its lowest: your social media feed. Picture this. You’re doomscrolling late at night when an advertisement catches your eye. A brand you know and trust, selling products you actually want, at a discount that seems too good to pass up. No urgent warnings, no “act now or else,” no red flags screaming for attention. Just a deal that seems to pop up organically. That’s exactly what makes it dangerous: these attacks strike when your brain is on autopilot."
        https://www.group-ib.com/blog/milk-dragon-nailong-phishing-kit/
      • CloudSyncD: a Two-Stage MacOS Backdoor That Hides a Phished Password In Zero-Width Unicode
        "While performing routine monitoring of executables in VirusTotal, Jamf Threat Labs identified a macOS dropper buried within a disguised Zoom client. We are tracking this malware under the name CloudSyncD, after the daemon name its second stage runs under. We first encountered CloudSyncD on September 15, 2026, in a build that was plainly still under development. After two days of monitoring, we identified samples of the same family configured against live infrastructure across more than one command-and-control domain, indicating the operators have moved from testing toward deployment."
        https://www.jamf.com/blog/cloudsyncd-macos-backdoor-fake-zoom-installer/
        https://www.infosecurity-magazine.com/news/cloudsyncd-macos-backdoor-fake/
      • MI5 Warns Over 100 Academics Helped China's Espionage Plans
        "The UK’s domestic security agency has warned that over 100 academics have helped Beijing’s spies to improve their espionage capabilities. MI5 issued the rare espionage alert on September 30, calling out the China General Technology Research Institute (CGTRI), or China Academy of General Technology (CAGT), for its connection to China's Ministry of State Security (MSS). Unusually for a security agency, the MSS handles both domestic/counterintelligence and foreign intelligence. It is thought to employ hundreds of thousands of workers, including many hackers that have been responsible for some of China’s most audacious campaigns, via ‘groups’ such as Silk Typhoon and Salt Typhoon."
        https://www.infosecurity-magazine.com/news/mi5-alerts-academics-chinese/
      • Fake xStocks, Pendle, And Other Sites Bait Crypto Users With Rewards Votes
        "We found 70 websites that impersonate legitimate crypto projects that invite visitors to vote on the date of an upcoming rewards distribution. The pages copy the look of the real sites closely, and on most of them the offer is small and believable: Cast a vote, and as an active voter you get a 1.25x boost when the rewards are paid out. However, the vote is fake and clicking the Vote now button opens a wallet connection prompt. It’s the first step toward requests that could trick visitors into authorizing access to their tokens."
        https://www.malwarebytes.com/blog/threat-intel/2026/10/fake-xstocks-pendle-and-other-sites-bait-crypto-users-with-rewards-votes
      • SC WordPress Malware: A Self-Healing Mesh Of Loaders, Drop-Ins, And a Blockchain-Controlled Backdoor
        "During recent website cleanup work, we analyzed a WordPress compromise where the same backdoor kept returning within seconds of every removal, no matter how carefully the visible files were deleted. Throughout this article, we’ll refer to this family of malware as SC, named after the “SC_” markers found in the injected content. What makes SC worth documenting is how it survives. The payload lives in at least eight places at once, spread across files, the database, and shared memory, and every one of those places can rebuild all the others. Delete the plugin and a drop-in rewrites it. Delete the drop-in and the theme rewrites it. Clean every file on disk, and the next page load restores the whole set from the database or from a shared-memory segment. The result is a circular system with no single point you can remove to stop it."
        https://blog.sucuri.net/2026/09/sc-wordpress-malware-a-self-healing-mesh-of-loaders-drop-ins-and-a-blockchain-controlled-backdoor.html
        https://thehackernews.com/2026/10/wordpress-backdoor-rebuilds-itself.html
      • Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts And Hunt Indicators
        "CVE-2026-88771 is a critical pre-authentication command-injection vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. Citrix and security researchers have already documented the vulnerability and its underlying exploitation mechanism. This analysis focuses instead on exploitation activity identified by LevelBlue's Threat Hunt Operations & Research (THOR) team while hunting across multiple customer environments."
        https://www.levelblue.com/blogs/spiderlabs-blog/citrix-netscaler-cve-2026-88771-observed-exploitation-artifacts-and-hunt-indicators
        https://thehackernews.com/2026/10/citrix-netscaler-post-exploitation.html
      • Rogue Agents Investigation: Initial Findings
        "Asymmetric Security investigated suspicious AI agent activity on the public internet from March 6, 2026 to September 20, 2026. Below we list organizations whose data was accessed by these agents. In the vast majority of cases, all data retrieved was and is public. We also list tools the agents used to access the internet, in a capacity which we suspect was outside their remit. A more detailed writeup is now available."
        https://www.asymmetricsecurity.com/newsroom/rogue-agents-investigation-initial-findings/
        https://www.asymmetricsecurity.com/newsroom/rogue-agents-investigation/
        https://therecord.media/openai-software-attempted-to-secretly-scrape-data-from-dozens-of-websites
      • TIKTOUK: Tracing a WordPress Credential Collection Toolkit
        "TIKTOUK brings together WordPress probing, collection of exposed configuration data, recovery of encrypted email credentials, and JavaScript secret scanning. Its two Python components and Go-based Linux crawler turn website responses into structured results for a central hub: an HTTP service that distributes target tasks and receives collected data and status reports. The key security issue is the combination of exposed configuration material and encrypted plugin settings: the collection component used the corresponding keys to recover plaintext email credentials."
        https://www.levelblue.com/blogs/spiderlabs-blog/tiktouk-tracing-a-wordpress-credential-collection-toolkit

      Breaches/Hacks/Leaks

      • Metamask Discloses Security Incident Affecting Its Infrastructure
        "On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. The company is working to address the issue internally, with help from external partners and security advisors, and says there is "no immediate threat to MetaMask wallets." "As a precautionary measure, we are proactively exiting affected validators within our non-custodial staking operations, in coordination with clients and partners," MetaMask noted. "As a reminder, our staking operations are non-custodial in nature and we do not manage withdrawal keys for stake on behalf of our clients.""
        https://www.bleepingcomputer.com/news/security/metamask-discloses-security-incident-affecting-its-infrastructure/
        https://thehackernews.com/2026/10/metamask-security-incident-prompts-exit.html
      • Cyberattack On Major Polish Invoicing Platform Exposes Customer Data
        "One of Poland’s major online invoicing platforms suffered a data breach that may have exposed information belonging to its users, their customers and business partners. Fakturownia said earlier this week that an unidentified attacker exploited a vulnerability in its systems and gained unauthorized access to servers. The company, whose service is used by more than 600,000 businesses, is still trying to determine how many customers were affected."
        https://therecord.media/poland-cyberattack-invoice-software

      General News

      • Teenager Suspected Of Leading KillSec Ransomware Group As Law Enforcement Seizes Servers And Leak Site
        "On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of stolen files unless they paid a ransom. The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1 000 suspected attacks worldwide. Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds."
        https://www.europol.europa.eu/media-press/newsroom/news/teenager-suspected-of-leading-killsec-ransomware-group-law-enforcement-seizes-servers-and-leak-site
        https://www.bleepingcomputer.com/news/security/police-dismantle-killsec-ransomware-gang-allegedly-led-by-16-year-old/
        https://www.darkreading.com/cyberattacks-data-breaches/killsec-ransomware-mastermind-16-year-old
        https://thehackernews.com/2026/10/police-arrest-16-year-old-suspected-of.html
        https://therecord.media/killsec-ransomware-raas-arrests-europe
        https://www.bankinfosecurity.com/spain-arrests-teen-suspected-running-killsec-ransomware-a-33002
        https://cyberscoop.com/killsec-ransomware-group-arrests-operation-killswitch/
        https://www.securityweek.com/police-shut-down-killsec-ransomware-identify-alleged-teen-leader/
        https://securityaffairs.com/200200/cyber-crime/operation-killswitch-police-dismantle-killsec-ransomware-group.html
        https://www.helpnetsecurity.com/2026/10/01/killsec-ransomware-16-year-old-main-operator-arrested/
      • The Fine Art Of Frustrating The Adversary
        "Years ago, Cisco Talos blocked an adversary’s command-and-control (C2) traffic. The adversary responded by tweeting, “Write a rule for your a**.” A fine endorsement of our work, if I’ve ever heard one. Talos loves to see an adversary forced to change course. And if every alternative for them is slower, less stealthy, less reliable and more expensive? Chef’s kiss. Adversaries rely on certain advantages. They look for environments where tools and infrastructure allow them to blend in with normal activity. They also look for employees who can be pressured into acting before they have time to think."
        https://blog.talosintelligence.com/the-fine-art-of-frustrating-the-adversary/
      • Many Expect AI In The SOC To Make Entry Jobs Harder To Get
        "A junior analyst in a security operations center, or SOC, has usually learned the job the slow way. You work the same phishing lure dozens of times, chase the same familiar malware pattern and write up the same case note at the end of the shift. Eventually you know what normal looks like, which is how you notice when something isn’t. AI tools handle a lot of that repetitive work, and the people doing the job are glad to see it go. Nearly nine in ten respondents in a Swimlane survey of 500 security operations staff, all at organizations already using AI, say it has made their work more satisfying. The catch is who is saying it. About a quarter of respondents say AI has held back their ability to build security skills. Those analysts are just as happy with their jobs as the ones who say AI helped them learn: 91% versus 92%."
        https://www.helpnetsecurity.com/2026/10/01/ai-soc-entry-jobs/
      • Employment Scam Victims Tripled At Financial Firms In 21 Countries
        "Reported victims of employment scams more than tripled over the past 12 months at more than 370 banks and other financial institutions in 21 countries. The 258% rise outran every other scam type, while total reported scams across the same institutions grew 35%. Researchers at BioCatch, a fraud-detection vendor, compiled the figures from reports filed by the institutions that use its software. The numbers matter for anyone running fraud controls because of where the scams happen. Nine of every 10 scam sessions now start on a mobile device. Traditional unauthorized fraud, where a criminal works the account without the owner’s help, comes from mobile in 75% of cases."
        https://www.helpnetsecurity.com/2026/10/01/employment-scam-victims-research/
      • AI Threats Top Cybersecurity Preparedness Gap, PwC Finds
        "Threats targeting AI systems is the area that cybersecurity leaders currently feel last able to address, with skills, accountability and data protection gaps also looming large, according to PwC. The consulting giant polled 3934 business and tech leaders across 71 countries for its 2027 Global Digital Trust Insights report, published on October 1. Over half (52%) said adversarial AI attacks represent the biggest cyber preparedness gap. The challenge of responding to these risks is compounded by governance issues."
        https://www.infosecurity-magazine.com/news/mitigating-adversarial-ai-top/
        https://www.securityweek.com/enterprises-struggle-to-prepare-for-ai-and-quantum-threats-pwc-says/
      • Shadow AI Explained: The Work Shortcut That Could Leak Your Company’s Secrets
        "Using an AI chatbot, assistant, or browser to speed up your work is tempting, but doing it without your employer’s knowledge can put sensitive data at risk. You’re swamped, so you paste a long email thread into a free chatbot and ask for a summary. It works, it saves an hour, and nobody notices. But the thread may contain customer details or confidential plans you’ve just shared with an outside service. If your employer hasn’t approved that tool or how you’re using it, that’s shadow AI."
        https://www.malwarebytes.com/blog/ai/2026/10/shadow-ai-explained-the-work-shortcut-that-could-leak-your-companys-secrets
      • Hacker Conversations: Rob Juncker, a Knock At The Door And a Moral Compass
        "Rob Juncker is chief product and technology officer at Mimecast. Is he a hacker? “Unequivocally yes,” he says. “And I think every security leader should be able to answer ‘yes’ to that question, for so many reasons.” He started early, when his parents brought home an Apple IIc. He was 10. They wanted to use it for word processing; but within two days of it arriving he had the lid off, trying to figure out how it worked. He had a driving curiosity to understand it. This curiosity, which he describes more as a thirst for knowledge, started before the arrival of the Apple – but with hands-on access, it rapidly focused on technology."
        https://www.securityweek.com/hacker-conversations-rob-juncker-a-knock-at-the-door-and-a-moral-compass/
      • AI Has Changed Attack Speed, Not Security Fundamentals
        "People who know me well know that I am a very direct person and as such, I don’t enjoy overcomplicating terms used to describe straightforward things. In recent months, Frontier AI and other tools have allowed attackers and defenders alike to shorten the time required to identify vulnerabilities and develop exploits for those vulnerabilities. With this has come an awful lot of hype and buzz around the topic of “virtual patching.”"
        https://www.securityweek.com/ai-has-changed-attack-speed-not-security-fundamentals/
      • Treasury Blacklists Most-Wanted ATM Malware Developer And His Network
        "The US Treasury Department has sanctioned the alleged developer of malware used in ATM jackpotting attacks linked to Tren de Aragua (TdA), along with members of his network and two Mexico-based companies. Anibal Alexander Canelon Aguirre, known as ‘Prometheus,’ was added in March to the FBI’s Ten Most Wanted Fugitives list, becoming the first person on the list wanted for cybercrimes. Treasury describes him as “the alleged engineer of the malware used in ATM jackpotting attacks.” TdA typically uses the malware named Ploutus. Canelon Aguirre’s network is based in Mexico and Venezuela but targets ATMs in the United States. The stolen cash is laundered, including through cryptocurrency, and moved to TdA members in various countries."
        https://www.securityweek.com/treasury-blacklists-most-wanted-atm-malware-developer-and-his-network/
      • Microsoft Says Threat Actors Are Ahead In The Early AI Race
        "Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. This comes from Microsoft's 2026 Digital Defense Report, which strongly focuses on how artificial intelligence is changing both offensive and defensive cybersecurity operations. Microsoft says AI is reducing the time, expertise, and cost required to discover and exploit weaknesses, while allowing attackers and defenders alike to operate with greater speed, scale, and autonomy."
        https://www.bleepingcomputer.com/news/security/microsoft-says-threat-actors-are-ahead-in-the-early-ai-race/
        https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/2026-Microsoft-Digital-Defense-Report.pdf
      • Federal PQC Orders Are Here: How To Prioritize Migration Before Q-Day
        "The United States is in a race to develop its quantum capabilities and to migrate critical systems to post-quantum cryptography before standard encryption practices become obsolete. That’s because AI is merging with quantum computing and rapidly accelerating the timeline to Q-day. Frontier models can allow technologists to identify more efficient ways to design, architect, and scale quantum computers. In fact, it is now estimated that previous timelines predicting Q-day’s arrival in 2031 are even further compressed."
        https://www.forescout.com/blog/federal-pqc-orders-are-here-how-to-prioritize-migration-before-q-day/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 42ee4b28-a045-4db4-bc3c-21ea7ed6e64b-image.png

      1 การตอบกลับ คำตอบล่าสุด ตอบ คำอ้างอิง 0
      • First post
        Last post