NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ

    Cyber Threat Intelligence 07 October 2026

    Cyber Security News
    1
    1
    18
    โหลดโพสเพิ่มเติม
    • เก่าสุดไปยังใหม่สุด
    • ใหม่สุดไปยังเก่าสุด
    • Most Votes
    ตอบ
    • ตอบโดยตั้งกระทู้ใหม่
    เข้าสู่ระบบเพื่อตอบกลับ
    Topic นี้ถูกลบไปแล้ว เฉพาะผู้ใช้งานที่มีสิทธิ์ในการจัดการ Topic เท่านั้นที่จะมีสิทธิ์ในการเข้าชม
    • NCSA_THAICERTN
      NCSA_THAICERT
      แก้ไขล่าสุดโดย

      Healthcare Sector

      • PQC In Healthcare: From Data Risk To Migration Readiness
        "Healthcare delivery organizations (HDOs), such as hospitals, clinics, urgent care facilities, rehabilitation centers, long-term care, and skilled nursing facilities, rely on a diverse array of Information Technology (IT), Internet of Medical Things (IoMT), Operational Technology (OT), and Internet of Things (IoT) devices that are increasingly integral to the delivery of patient care. The growing number and variety of these devices have introduced significant cybersecurity risks to HDOs in the past decade. Threat actors are increasingly exploiting these devices to deploy ransomware, demand large payments, and monetize stolen patient data."
        https://www.forescout.com/research-labs/pqc-in-healthcare-from-data-risk-to-migration-readiness/
        https://www.darkreading.com/iot/exposed-healthcare-systems-quantum-ready
        https://www.infosecurity-magazine.com/news/medical-devices-pqc-transition/

      Vulnerabilities

      • Atlassian Warns Of Critical File-Access Flaw In Jira, Confluence
        "Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. The security issue allows an unauthenticated attacker to access specific files within an affected application's web root directory. However, exploitation requires knowing the exact name of the file and path. “This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions,” reads the security advisory."
        https://www.bleepingcomputer.com/news/security/atlassian-warns-of-critical-file-access-flaw-in-jira-confluence/
        https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html
        https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html
        https://www.theregister.com/security/2026/10/06/atlassian-warns-of-critical-file-access-flaw-in-its-datacenter-products/5301284
        https://www.helpnetsecurity.com/2026/10/06/atlassian-data-center-cve-2026-21589/
      • Filling The Well: Nightmare-Eclipse's BigDiskBuster And The Defender Update That Never Lands
        "A new proof of concept called BigDiskBuster, published on GitHub on September 19, 2026, by the actor known as MSNightmare, shows that Defender doesn't need to be disabled to stop receiving updates, it just needs a much simpler dependency: disk space. Unlike ShieldCrash, which relied on a Windows path-resolution flaw, BigDiskBuster requires no vulnerability. It watches the C:\ volume for Defender update activity and, when an update begins, creates a hidden file that claims essentially all available free space. The update runs out of room and fails. Defender cleans up the staging directory, the space becomes available again, and BigDiskBuster repeats the process on the next attempt."
        https://www.levelblue.com/blogs/spiderlabs-blog/filling-the-well-nightmare-eclipses-bigdiskbuster-and-the-defender-update-that-never-lands
        https://www.darkreading.com/application-security/bigdiskbuster-microsoft-defender-running-blocking-updates
      • LibreOffice And OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
        "A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only when the program's Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in real attacks. LibreOffice has already fixed the flaw, which it tracks as CVE-2026-63277, in updates released on October 5. It recommends that users move to version 26.2.5 or 26.8.0. Versions before those are affected."
        https://thehackernews.com/2026/10/libreoffice-and-openoffice-flaws-let.html
      • GitHub Copilot CLI Vulnerability: Cryptographic Context Injection Steals Developer Secrets
        "A GitHub Copilot CLI user is working the way the product is built to be used: agent in autopilot, told to go read a page and get on with the task. They paste in a link. Twenty-eight seconds later the full contents of a .env.prod file, every secret in it, are sitting in an attacker’s log, and nothing on the user’s screen says a file ever left the machine. The agent’s own closing summary reports that it “confirmed an authorized-reader endpoint”. That is Cryptographic Context Injection (CCI), the attack we published in August, now landed on a coding agent. When we disclosed CCI we wrote that it would hit coding and operations agents harder than chat assistants, because for those agents code execution and outbound network calls are routine. This is the proof."
        https://adversa.ai/blog/cryptographic-context-injection-github-copilot/
        https://www.theregister.com/ai-and-ml/2026/10/06/zombie-instructions-on-carefully-constructed-web-pages-could-trick-github-copilot-cli-into-sharing-secrets/5301206
      • Security Researcher Claims They Found KVM Guest-Host Escape Flaw
        "Linux KVM, the hypervisor favoured by hyperscale clouds, apparently has a full VM escape bug. That nasty news came from security researcher Paulos Yibelo, who on X shared a screenshot of a bug bounty award he won for discovering what he described as “Full VM escape zeroday (guest>host root in industry standard hypervisors)!” The bug bounty Yibelo participated in is run by Vercel, a company that provides MicroVMs as sandboxes for AI agents to work inside. The company’s Sandbox uses Firecracker MicroVMs, a technology created by AWS, which relies on Linux KVM – the kernel level hypervisor in Linux. Vercel CEO Guillermo Rauch named KVM as the hypervisor identified by Yibelo."
        https://www.theregister.com/offbeat/2026/10/06/security-researcher-claims-they-found-kvm-guest-host-escape-flaw/5301267
      • IBM And Red Hat Remediate More Than 400 Previously Unknown Open Source Vulnerabilities
        "IBM (NYSE: IBM) and Red Hat today announced that Lightwell has identified and remediated more than 400 previously unknown vulnerabilities in widely used Java libraries. The companies also announced the general availability of Lightwell Clearinghouse, which allows enterprise customers to submit specific open source software dependencies for priority review and remediation. The milestone addresses a growing business risk. As autonomous AI agents become capable of combining several lower-risk software weaknesses into a more serious attack, companies need to do more than identify vulnerabilities. They need a practical way to develop, test and deploy fixes in the software that supports critical applications."
        https://newsroom.ibm.com/2026-10-06-ibm-and-red-hat-remediate-more-than-400-previously-unknown-open-source-vulnerabilities

      Malware

      • Four Ways Back In: The WordPress XSS Campaign That Hides Its Own Admin Account
        "Two unrelated WordPress plugins, two separate stored Cross-Site Scripting vulnerabilities, one payload. Over the past several days our telemetry has recorded exploitation attempts against both, and every attempt pulls the same JavaScript from imgcdn1[.]com. Two is what we have confirmed, not what we expect the final count to be. We first observed the payload on October 4, 2026, in an exploitation attempt targeting CVE-2026-93836 in WPC Product Bundles for WooCommerce. The following day, we observed the same payload being delivered through CVE-2026-94504 in Ninja Forms. The JavaScript is not a vulnerability scanner or a proof-of-concept. It is a WordPress post-exploitation and persistence implant designed to execute inside the browser of a logged-in administrator."
        https://patchstack.com/articles/four-ways-back-in-the-wordpress-xss-campaign-that-hides-its-own-admin-account/
        https://www.bleepingcomputer.com/news/security/ninja-forms-plugin-flaw-exploited-to-hack-wordpress-sites/
      • Behind The Connect Button: The Fake AI Ads Campaign
        "Island security research uncovered a human-operated phishing platform disguised as a portfolio of AI advertising products. Its products ranged from campaign optimization and spend audits to business-account connections. The newest lure, Muse Ads, appeared shortly after Meta announced Muse. Each product was built around the same action: Connect. Clicking it opened a browser drawn inside the real browser. The fake address bar displayed trusted origins such as accounts.google.com or an Okta tenant, while the real browser remained on the phishing domain. Behind the interface, the platform kept every password attempt, fingerprinted the device, and let an operator pick which MFA challenge the victim saw next."
        https://www.island.io/blog/behind-the-connect-button-the-fake-ai-ads-campaign
        https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/
        https://thehackernews.com/2026/10/fake-chatgpt-gemini-and-claude-ad.html
      • Alert: FortiBleed Remains Active Campaign, Can Lock Out Users Or Lead To Ransomware Attacks
        "FortiBleed, a credential compromise campaign targeting Fortinet firewalls and VPN gateways, is an ongoing threat that can lock users out of their Fortinet accounts and also lead to ransomware attacks, the FBI and Secret Service said in an alert published Tuesday. “Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets,” the alert states. “In addition, the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates.”"
        https://cyberscoop.com/fortibleed-fortinet-vpn-ransomware-fbi-warning/
        https://www.ic3.gov/CSA/2026/261006.pdf
      • CrocoRat Adds a New Twist To ClickFix With DNS Payload Delivery
        "ClickFix campaigns have become one of the most effective ways to turn a browser session into code execution. The technique is simple: show the victim a fake verification page, place a command on the clipboard, and convince them to paste it into the Windows Run dialog. CrocoRat, a previously undocumented remote access trojan (RAT) and cryptocurrency stealer, follows the ClickFix playbook but adds an important twist: after the victim runs the command, the malware selects different payloads based on the host environment."
        https://flare.io/learn/resources/blog/crocorat-clickfix-dns-payload-delivery
        https://www.darkreading.com/cyberattacks-data-breaches/clickfix-attacks-evolve-better-hide-malicious-payloads
      • Caught In 4K: The Gentlemen Files
        "CloudSEK's Caught in 4K series documents investigations into exposed threat actor infrastructure. In our first entry, we uncovered an Aurora ransomware affiliate mid operation. This time, an exposed open directory led us somewhere bigger. An exposed open directory and a misconfigured storage server revealed the complete operation of a threat actor calling themselves Azazel, a Russian-speaking affiliate of the Gentlemen ransomware group who simultaneously robbed his victims, betrayed his own RaaS operator, and left everything out in the open. Two servers totalling more than 29TB of raw storage held more than two dozen victim directories and approximately 6TB of stolen data spanning logistics, insurance, pharmaceutical, AI, medical devices, and government-adjacent infrastructure across six countries."
        https://www.cloudsek.com/blog/caught-in-4k-the-gentlemen-files
        https://www.infosecurity-magazine.com/news/affiliate-doublecrosses-raas/
      • Facebook Marketplace Scam Uses Your Name And Number
        "Facebook users are reporting receiving a message with a fake Facebook Marketplace listing that has their name as the seller. It works like this. You receive a message (in this case iMessage) asking “Is this still available for purchase?” Attached to the message is a fabricated Facebook Marketplace listing."
        https://www.malwarebytes.com/blog/threat-intel/2026/10/facebook-marketplace-phish-uses-your-name-and-number
      • Domino’s Customers Targeted In Credential Stuffing Attacks
        "Domino’s Pizza customers tell us they have received emails saying they account has been accessed by a third party. Domino’s says its internal systems weren’t breached, but that individual accounts were logged into using a password and email combination stolen from another online account owned by the customer. This is known as credential stuffing."
        https://www.malwarebytes.com/blog/news/2026/10/dominos-customers-targeted-in-credential-stuffing-attacks
      • ClickFix Smuggles Payloads Through Browser Cache To Bypass Windows Run Limits
        "A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X. Thus, when the victim is prompted to paste and execute a malicious command – as is the case with ClickFix attacks – it executes the cached website content that's already on the device."
        https://thehackernews.com/2026/10/clickfix-smuggles-payloads-through.html
        https://www.infosecurity-magazine.com/news/clickfix-vbscript-browser-cache/
      • ClickFix Campaign In Ukraine Compromises Over 100 Websites To Spread Lunex Malware
        "Hackers compromised more than 100 websites to infect Ukrainian users with information-stealing malware, according to a new report. Ukraine's computer emergency response team, CERT-UA, said the campaign, discovered in September, involved attackers injecting malicious code into legitimate websites. Visitors to those sites were shown a fake Cloudflare verification page that told them to copy and run a command in PowerShell, a Windows command-line tool, to prove they were human."
        https://therecord.media/clickfix-campaign-ukraine-lunex-stealer
      • Blinder Tunnel Campaign Targets Iraqi Infrastructure
        "We discovered that an Iranian state-aligned threat actor has been masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. Unit 42 tracks the activity as CL-STA-1178. This activity includes a campaign we call “Blinder Tunnel,” that targeted Iraqi critical infrastructure in March 2026, following infrastructure staging that was observed as early as November 2025. We named the campaign Blinder Tunnel after infrastructure terms the attackers used, as well as the malware’s tunneling capabilities."
        https://unit42.paloaltonetworks.com/blinder-tunnel-targets-critical-infrastructure/
      • MALFEX Npm Malware Campaign: Three Payloads And An Adversary That Signs Their Work
        "MALFEX is an npm supply-chain malware campaign linked to what appears to be a single adversary who has been publishing to the registry since August 2023. As of this writing, the adversary has published twelve packages, eight of them malicious. The attack delivers malware to Windows systems through three separate paths: a loader for Overlord Remote Access Trojan (RAT) (an open-source remote access trojan written in Go); a chain that installs movinlike (a Node.js stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets); and a long-running downloader hidden inside function-flag."
        https://checkmarx.com/zero-post/malfex-npm-malware-campaign-three-payloads-and-an-adversary-that-signs-their-work/
        https://www.securityweek.com/long-running-npm-malware-campaign-accumulates-40000-downloads/

      Breaches/Hacks/Leaks

      • ASOS Confirms Data Breach After “HACKED” In-App Notifications
        "UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. ASOS is a large UK-based online fashion retailer that sells clothing, footwear, accessories, and beauty products to customers worldwide, including in the United States. ASOS has confirmed that third-party platforms used to communicate with customers were accessed without authorization and says basic personal information, including names and contact details, may have been exposed."
        https://www.bleepingcomputer.com/news/security/asos-confirms-data-breach-after-hacked-in-app-notifications/
        https://therecord.media/asos-push-notification-apparently-sent-by-hackers
        https://www.infosecurity-magazine.com/news/asos-customers-message-suspected/
        https://www.theregister.com/security/2026/10/06/asos-app-delivers-a-data-leak-threat-instead-of-fast-fashion/5301332
        https://www.malwarebytes.com/blog/news/2026/10/asos-hackers-send-push-notifications-to-customers
      • Osaka Metropolitan University Cancels Classes After Suspected Ransomware Attack
        "One of Japan’s largest universities canceled classes and shut down a large part of its IT infrastructure following a suspected ransomware attack that began late last week. Osaka Metropolitan University said on Tuesday that the outage left its internal network, email and a range of administrative and academic systems unavailable. OMU said it believes ransomware caused the disruption and is investigating the attack with outside cybersecurity specialists. It has not identified the attackers or said whether it received a ransom demand."
        https://therecord.media/osaka-university-cancels-classes-ransomware
      • Trump Mobile Customers' Data Dumped - And Some Never Even Received Their Gold Device
        "If you signed up for Trump Mobile, you may be part of an exclusive club of … ransomware victims. Criminals called BYOD claim to have broken into the Trump-branded mobile biz and leaked data belonging to 3,615 people, including names, email addresses, phone numbers, home addresses, and order details. BYOD is a new ransomware-as-a-service operation, and Trump Mobile is only the third organization posted on its data-leak site. According to the group’s posted claim, after telling Trump Mobile that it had been breached, the wireless provider replied: “We have no team to handle this" and “Anyone who hacks them are a terrorist.”"
        https://www.theregister.com/security/2026/10/06/trump-mobile-customers-data-dumped-and-some-never-even-received-their-gold-device/5301433

      General News

      • Hackers Exploit 32 Zero-Days On First Day Of Pwn2Own Ireland
        "On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days. During the Pwn2Own Ireland 2026 hacking contest, competitors target products in seven categories, including mobile phones (Apple iPhone 17, Samsung Galaxy S26, and Google Pixel 10), printers, smart home devices, messaging apps, AI infrastructure, AI coding apps, and a new category where hackers will try to exploit wellness healthcare devices."
        https://www.bleepingcomputer.com/news/security/hackers-exploit-32-zero-days-on-first-day-of-pwn2own-ireland/
      • Engineer Sentenced For Locking Over 3,000 Devices On Employer Network
        "A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer's network in a ransomware-style attack. 57-year-old Daniel Rhyne from Kansas City, Missouri, pleaded guilty to his role in a failed extortion plot targeting the New Jersey company that employed him after being arrested in August 2024 and released after his initial appearance in federal court."
        https://www.bleepingcomputer.com/news/security/engineer-sentenced-for-locking-thousands-of-devices-on-employer-network/
      • Agentic Hacks, Real Proofs: Inside Google's PageBreak Project
        "The application of Large Language Models (LLMs) to security scanning has revolutionized the vulnerability management landscape. But, it has also introduced a significant operational bottleneck: noise. Despite advancements in the models' capabilities to identify vulnerabilities, many security teams are finding themselves overwhelmed as a significant portion of the candidate reports they receive is "AI slop" – noisy, unverified hypotheses or false positives generated by LLMs acting as static code analyzers. Distinguishing a genuine, exploitable flaw from a convincing hallucination has become a major challenge, often increasing the burden on product teams, rather than reducing it."
        https://blog.google/security/agentic-hacks-real-proofs-inside-googles-pagebreak-project/
        https://www.darkreading.com/application-security/google-pagebreak-ai-agent-500-flaws-web-apps
      • U.S. Bank CISO Says The Security Role Keeps Growing And No One Can Own All Of It
        "In this interview with Help Net Security, Ann Barron-DiCamillo, EVP, CISO at U.S. Bank, talks about how the CISO role has grown to cover fraud, resilience, third-party risk, and AI governance. She says no single leader can own all of it, so partnerships across technology, risk, legal, and business teams matter most. Barron-DiCamillo also weighs in on shorter incident reporting deadlines, spending on compliance versus risk reduction, sharing threat intelligence across banks, and what she taught students at American University about cyber risk being a shared responsibility."
        https://www.helpnetsecurity.com/2026/10/06/ann-barron-dicamillo-collective-cyber-defense/
      • Police Urge Passkey Use After Surge In Cybercrime Profits
        "The UK’s Report Fraud service has launched a new public awareness campaign urging internet users to switch to passkeys, after revealing a major increase in sums stolen from victims. The fraud reporting service said that cybercrime linked to email and social media hacking netted scammers £6.3m ($8.3m) in 2025/6, up from £1.2m ($1.6m) the year previously. The number of reports for this type of account takeover increased by a third (34%) over the same period."
        https://www.infosecurity-magazine.com/news/police-urge-passkey-surge/
      • Welcome To The Jungle: What We Found Inside 15,465 Public MCP Servers
        "In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security, traced critical vulnerabilities in Anthropic's MCP source code, downloaded more than 150 million times. This time, we looked at what people actually install: community-published servers across the most popular MCP marketplaces. We found no guardrails and no review. Security is a recommendation, not a policy."
        https://thehackernews.com/2026/10/welcome-to-jungle-what-we-found-inside.html
      • Social Engineering Detection Moves Into The Live Conversation
        "Companies are pouring time and dollars into security awareness training, but there is little empirical evidence to suggest it actually works against social engineering. Social engineering remains a primary and successful attack vector. While system vulnerabilities can be patched, social engineering cannot. The most common pseudo ‘patch’ is user awareness training, but this has failed to block the vector. Human defenders should not and cannot be expected to detect trickery designed to manipulate their psychology. And the tricks are becoming better hidden and more sophisticated with the use of AI deep fakery."
        https://www.securityweek.com/social-engineering-detection-moves-into-the-live-conversation/
      • Guarding The Gates: Assessing Dangerous Permissions Granted To Kubernetes Built-In Principals
        "Kubernetes authorization is a vital but complex part of cluster security, where mistakes can have serious consequences in allowing attackers to establish and expand their access to critical resources. With that in mind we decided to examine how role-based access control (RBAC) is configured in real-world clusters. Specifically, we looked at bindings that can grant some of the built-in principals wide-ranging access to cluster resources. We examined over 65,000 clusters from almost 10,000 organizations to understand what the real-world usage of these principals looked like."
        https://securitylabs.datadoghq.com/articles/kubernetes-rbac-built-in-principals-dangerous-permissions/
      • Beyond Valid Credentials: How Exposed AWS Keys Are Tested For Amazon Bedrock Access
        "Not all credentials are created equal. An attacker who gains access to credentials usually performs validation to determine how useful each set of captured credentials actually is. For years, this has been true for the AWS SES/SNS services. Attackers use API calls like GetSendQuota, GetSMSAttributes, and GetSMSSandboxAccountStatus to assess whether an account is in a production or sandbox environment and then to assess the sending limits attached to that account. The usefulness of the credentials affects their resale value. Attackers use similar tactics when targeting LLM resources in AWS. In this post, we will share LLM-specific validation patterns that we have observed after finding multiple credential harvesting platforms."
        https://securitylabs.datadoghq.com/articles/beyond-valid-credentials-how-exposed-aws-keys-are-tested-for-amazon-bedrock-access/
      • Authenticated Doesn’t Mean Safe: Why AI Agents Need Action-Level Security
        "Consider a support agent handling a routine billing query. It can pull customer records, prepare an account report and email the customer. Then an incoming message tells it to export the full account history and send it to a newly appointed audit contact. The request looks plausible, so the agent complies. Nothing unusual happens at the authentication layer. The credentials are valid. The agent is allowed to read the records and send email. Yet the account history has just gone to someone who was never entitled to receive it."
        https://hackread.com/authenticated-safe-ai-agents-action-level-security/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 62ec7f32-aa21-43c5-9c76-058e856480e5-image.png

      1 การตอบกลับ คำตอบล่าสุด ตอบ คำอ้างอิง 0
      • First post
        Last post