NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,563
    • กระทู้ 2,564
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    NCSA_THAICERT

    @NCSA_THAICERT

    1
    ชื่อเสียง
    57
    ดูข้อมูลส่วนตัว
    2.6k
    กระทู้
    3
    คนติดตาม
    0
    ติดตาม
    เข้าร่วม ออนไลน์ล่าสุด
    เว็บไซต์ www.ncsa.or.th/?fbclid=IwAR0BqJEC-CJzBs98rlBxUbZkNBgp1g814xdDNNaKnHTrxfqZhPD--ksY68I

    NCSA_THAICERT เลิกติดตาม ติดตาม
    Global Moderator administrators

    Latest posts made by NCSA_THAICERT

    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 2 รายการลงในแคตตาล็อก

      เมื่อวันที่ 10 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 2 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
      • CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand dd97e004-14d0-4651-b264-9352948152c6-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 4 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 4 รายการ เมื่อวันที่ 10 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      ICSMA-26-253-01 NextGen Mirth Connect
      ICSMA-26-253-02 Orthanc DICOM Server
      ICSA-26-253-01 AVEVA Pipeline Integrity Monitor
      ICSA-26-183-01 ST Engineering iDirect iQ-Series Terminals (Update A)

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 79d6973d-9d0c-4173-85fe-31aec01f48ec-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 8 รายการลงในแคตตาล็อก

      เมื่อวันที่ 8-9 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 8 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
      • CVE-2026-81963 Microsoft Windows Link Following Vulnerability
      • CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability
      • CVE-2026-86218 N-able N-central Static Code Injection Vulnerability
      • CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
      • CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
      • CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability
      • CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog
      https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 501a514a-b633-4249-8113-0ea4d282fa64-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบเครือข่ายร้านค้าออนไลน์ปลอม DoppelCart ใช้กว่า 119,000 โดเมน หลอกขโมยข้อมูลบัตรชำระเงิน

      พบเครือข่ายร้านค้าออนไลน์ปลอม DoppelCart ใช้กว่า 119,000 โดเมน หลอกขโมยข้อมูลบัตรชำระเงิน.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand dd5e4a01-a3ac-4763-b1eb-d5be9a1ac387-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบ Plex Media Server กว่า 36,000 เครื่องเปิดสู่อินเทอร์เน็ต ยังไม่ได้แพตช์ช่องโหว่ล่าสุด

      พบ Plex Media Server กว่า 36,000 เครื่องเปิดสู่อินเทอร์เน.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 7b1ba684-04b8-4a37-84f0-1e4213bfe1c1-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบแคมเปญ Phishing อาศัยบริการของ Google สร้างลิงก์ส่งต่อหลายทอดเพื่อขโมยข้อมูลและควบคุมเครื่อง

      พบแคมเปญ Phishing อาศัยบริการของ Google สร้างลิงก์ส.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ec8cec7e-88dd-44ae-9b63-6f62af7aa697-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 10 September 2026

      Industrial Sector

      • ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
        "Industrial giants Schneider Electric, Siemens, and Aveva have published September 2026 Patch Tuesday advisories, informing customers about vulnerabilities found in their ICS products. Schneider Electric published four new security advisories and updated four others, including one originally released in 2019. The most severe of the newly addressed issues is a critical authentication vulnerability in Modicon M580 and Modicon M580 Safety controllers. Tracked as CVE-2026-3869, the flaw has a CVSS score of 9.2."
        https://www.securityweek.com/ics-patch-tuesday-schneider-electric-siemens-fix-critical-flaws/

      New Tooling

      • AI-Infra-Guard: Open-Source Security Scanner For AI Systems
        "Tencent’s Zhuque Lab built AI-Infra-Guard, an open-source security scanner for AI systems. It fingerprints running services such as Ollama, vLLM and ComfyUI and checks them against more than 1,600 known CVEs, inspects MCP servers and agent skills across 14 categories of risk, and runs jailbreak evaluations against a target model. To check a skill, the platform asks a language model whether it looks malicious. Zhuque Lab scores that call against SkillTrustBench, a public set of 5,520 human-labeled samples across nine risk categories. False positive rates there run from 1.20 percent to 18.67 percent, depending on which model does the judging."
        https://www.helpnetsecurity.com/2026/09/09/ai-infra-guard-open-source-security-scanner-ai-systems/
        https://github.com/Tencent/AI-Infra-Guard

      Vulnerabilities

      • Active Exploitation Of Cisco Secure Firewall Management Center Vulnerabilities
        "Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account."
        https://blog.talosintelligence.com/fmc-ongoing-exploitation/
        https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/
      • Fortinet Patches Critical Vulnerabilities In FortiMonitorOnSight, Chrome Extension
        "Fortinet on Tuesday released patches for 10 vulnerabilities across its products, including critical security defects. The first critical bug, tracked as CVE-2026-84390 (CVSS score of 9.6), is described as an inclusion of sensitive information in source code issue affecting the FortiMonitorOnSight web portal. A remote, unauthenticated attacker could exploit the flaw to bypass authentication via a forged or reused JSON Web Token (JWT). The second critical vulnerability is an improper authentication issue in the Fortinet Privileged Access Agent Chrome extension, tracked as CVE-2026-84388 (CVSS score of 9.1)."
        https://www.securityweek.com/fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension/
      • Ivanti Patches Critical Flaws Across Enterprise Security Products
        "Ivanti on Tuesday announced security updates that address vulnerabilities rated critical and high severity in its Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM) products. Neurons for ITSM received fixes for the largest number of security defects. Of the eight bugs, six are critical-severity issues that could lead to remote code execution, Ivanti warns. These include CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646 (CVSS score of 9.9/10), described as missing authorization issues; and CVE-2026-12650 (CVSS score of 9.9/10), CVE-2026-12744, and CVE-2026-12745 (CVSS score of 9.8/10), described as deserialization of untrusted data weaknesses."
        https://www.securityweek.com/ivanti-patches-critical-flaws-across-enterprise-security-products/
      • Google Fixes Yet Another Actively Exploited Chrome Zero-Day (CVE-2026-87491)
        "Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. “Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in a Tuesday security advisory. The fix has been shipped in Chrome 153.0.8010.36 and .37 for Windows and macOS and Chrome 153.0.8010.36 for Linux."
        https://www.helpnetsecurity.com/2026/09/09/google-chrome-cve-2026-87491-zero-day-flaw/
        https://www.bleepingcomputer.com/news/security/google-patches-seventh-chrome-zero-day-exploited-in-attacks-this-year/
        https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html
        https://www.securityweek.com/chrome-153-patches-seventh-zero-day-of-2026/
        https://securityaffairs.com/198757/security/google-fixes-the-seventh-actively-exploited-chrome-zero-day-of-2026.html
      • DeepSeek Harness < 0.1.2-Alpha.1 Authentication Bypass Via Host Header Spoofing
        "DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP control-plane API that allows attackers to gain full agent control by supplying a spoofed Host header, as the server validates only the client-supplied Host header value rather than the actual TCP connection origin. Attackers can exploit this flaw to invoke privileged commands such as commands/execute with danger-full-access permissions, escalate session approval policies to unconfined execution, and retrieve all stored conversations without any credential or API key."
        https://www.vulncheck.com/advisories/deepseek-harness-alpha-1-authentication-bypass-via-host-header-spoofing
        https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html
      • Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
        "Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through v1.18.5, all released before August 2025, and Alby said one user has been affected so far."
        https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html
      • CISA Adds Four Known Exploited Vulnerabilities To Catalog
        "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
        CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
        CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability
        CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog
      • Skullcandy Dime 3 Wireless Earbuds Contain An Unauthenticated Bluetooth Pairing Vulnerability
        "Skullcandy Dime 3 wireless earbuds, running firmware version 1.0.0.28, accept a new Bluetooth Classic (BR/EDR) pairing request from an unpaired device without requiring the earbuds to be placed into pairing mode or requiring any physical confirmation or interaction from the owner."
        https://kb.cert.org/vuls/id/859658
        https://www.bleepingcomputer.com/news/security/skullcandy-dime-3-earbuds-expose-users-to-bluetooth-hijacking/
      • Over 36,000 Exposed Plex Servers Vulnerable To Recent Flaws
        "Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. Plex urged users a week ago to secure their media servers immediately against security issues that still lack CVE IDs for easy tracking. While the company didn't provide additional details on Tuesday when it issued the warning, these security flaws are known to affect Plex Media Server v1.43.2 and earlier."
        https://www.bleepingcomputer.com/news/security/over-36-000-plex-servers-unpatched-against-recently-disclosed-flaws/
      • New Microsoft Defender 'ShieldCrash' Zero-Day Grants SYSTEM Access
        "An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. ShieldCrash is described as a bypass for the ShieldBreak Defender privilege escalation flaw patched on Thursday, which itself bypassed RoguePlanet, another Defender flaw disclosed in June and patched by Microsoft in July."
        https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldcrash-zero-day-grants-system-access/
        https://thehackernews.com/2026/09/researcher-drops-new-microsoft-defender.html
        https://securityaffairs.com/198726/security/chaotic-eclipse-released-shieldcrash-a-poc-for-microsoft-defender-zero-day.html
        https://www.theregister.com/security/2026/09/09/serial-microsoft-0-day-hunter-drops-yet-another-defender-exploit/5295335
      • Android’s September 2026 Updates Patch 180 Vulnerabilities
        "After two ‘no security vulnerabilities’ bulletins in July and August, Google on Tuesday announced the release of patches for 180 vulnerabilities as part of the September 2026 Android security updates. As usual, the updates are split into two parts. The first part arrives on devices as the 2026-09-01 security patch level and resolves 95 bugs across Android runtime, Framework, System, Setup Wizard, and multiple Project Mainline components (patched via Google Play system updates). “The most severe of these issues is a critical security vulnerability in the System component that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation,” Google notes in its advisory."
        https://www.securityweek.com/androids-september-2026-updates-patch-180-vulnerabilities/
      • Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories
        "Major chipmakers AMD, Arm, and Nvidia published new security advisories on Tuesday to notify customers of vulnerabilities recently discovered in their products. AMD announced fixes for CVE-2026-43603, a NULL pointer dereference flaw in its Linux GPU kernel driver that could lead to system crashes and a denial-of-service (DoS) condition. The company credited Maxime Rossi Bellom and Ramtine Tofighi Shirazi from SecMate for reporting the security defect."
        https://www.securityweek.com/chipmaker-patch-tuesday-nvidia-amd-arm-issue-security-advisories/
      • New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code As Root
        "cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected. The flaw is tracked as CVE-2026-67401. cPanel's advisory calls it an SQL injection issue in EmailTrack, but does not say which cPanel feature or privilege an account needs. cPanel's developer documentation lists an EmailTrack module that tracks email statistics, and the advisory does not say whether that is the affected code."
        https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html
      • One Blank Field Bypasses Direct Send Control
        "ReliaQuest observed that an empty Simple Mail Transfer Protocol (SMTP) envelope sender can bypass RejectDirectSend, a Microsoft 365 control in Exchange Online intended to block unauthenticated Direct Send emails from an organization’s domain. An external sender can omit the envelope domain while retaining an internal-looking address, making phishing messages more likely to be trusted. Direct Send allows devices and applications to send email to recipients in the same Microsoft 365 tenant without authentication. RejectDirectSend evaluates the domain in the SMTP envelope sender, but an empty value means there’s no domain to check. In testing, changing only this field caused Microsoft 365 to accept and queue a message it otherwise rejected."
        https://reliaquest.com/blog/threat-spotlight-one-blank-field-bypasses-direct-send-control

      Malware

      • Once In a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome And Windows Zero-Days
        "Beginning in late August and continuing into September 2026, Proofpoint identified multiple espionage-motivated threat actors rapidly adopting the BlueMoon exploit kit in targeted spearphishing campaigns. Several characteristics of this activity are consistent with a capability that was opportunistically adopted and deployed ahead of an anticipated patch. While the chain exploited vulnerabilities present in the latest stable versions of Chrome and Chromium-based browsers (such as Microsoft Edge), it was paired with a Windows LPE vulnerability present only in older Windows builds. This pairing substantially narrows the pool of viable targets and reduces the chain's overall probability of success."
        https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit
        https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html
        https://therecord.media/china-hackers-chrome-browser-zero-day-multiple-groups
        https://cyberscoop.com/china-espionage-groups-exploit-chain-zero-days/
        https://www.theregister.com/research/2026/09/09/novel-blue-moon-kit-targeting-chrome-and-windows-reflects-new-reality-of-ai-driven-exploits/5295399
      • Workflow Identity Hijacking: The Silent Backdoor In AI Workflows
        "An attacker sends a benign message to a company’s public support email. Minutes later, the attacker receives the quarterly sales numbers from the Finance Director's most recent email. The company's AI workflow read the message, understood the request, searched for the requested information, and replied. No prompt injection was required, no account was breached, and no workflow was hijacked. All the attacker had to do was ask."
        https://noma.security/noma-labs/workflow-identity-hijacking-the-silent-backdoor-in-ai-workflows
        https://www.darkreading.com/threat-intelligence/identity-based-ai-attack-security-enterprise-data
      • Vwork: Weaponized Open-Source Software As An Addon For Gigabud
        "During the “Hook for Gold” research, Group-IB discovered an application called Vwork that was installed within minutes after initial Gigabud infection along with tampered banking applications. Trials to find a sample of Vwork lead to Gigabud samples that are intentionally built to interact with Vwork. The significance of this finding meant that Vwork on infected devices cannot be considered a coincidence anymore. This article reveals what Vwork is, and how it is related to Gigabud."
        https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
        https://www.infosecurity-magazine.com/news/gigabud-android-app-cloning-fraud/
      • Threat Spotlight: Phishing Pages That Exist Only Inside The Victim’s Browser
        "Most phishing campaigns rely on a hosted webpage that security tools can retrieve, analyze, categorize, and eventually block. A recent campaign analyzed by Barracuda researchers breaks that model. Instead of delivering a phishing page from a web server, the malicious content is assembled inside the victim’s browser using a blob URL — a temporary browser-generated URL that points to content stored locally in memory rather than on a website. By the time the phishing page appears, the victim has already been routed through legitimate Microsoft services, including Microsoft OAuth and Microsoft Teams, with little visible indication that anything malicious is taking place."
        https://blog.barracuda.com/2026/09/09/browser-based-phishing-blob-urls-microsoft-redirects
        https://www.securityweek.com/new-phishing-attack-creates-malicious-pages-inside-the-victims-browser/
      • Signing In Without Actually Signing In
        "The price of AI tokens and subscriptions is increasing as AI model providers seek to recoup investment costs. As a result, these accounts are becoming more valuable targets for account takeover. Stopping this is paramount for enterprises. AI theft increases token bills. In three recent cases, it was to the tune of nearly $1 million for one organization, a shock $25,000 bill for a software architect and $600,000 in AI credits for an AI testing organization due to a stolen API key. Some AI providers are detecting this abuse and automatically logging affected users out and removing their payment cards on record to limit the damage. Malware developers and phishing operators have shown interest in applying AI to their operations, and attackers have been documented using stolen AI inference."
        https://www.okta.com/blog/threat-intelligence/signing_in_without_actually_signing_in/
        https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html
      • Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
        "A recent Unit 42 investigation into seemingly low-priority enterprise infections demonstrates how the most effective camouflage in cybercrime is not necessarily in the use of sophisticated techniques, but in how unremarkable the threat appears. The activities that we investigated would typically not require escalation or further inquiry. But upon closer inspection, we discovered a massive cybercrime campaign largely targeting young gamers. Tracked as CL-CRI-1171, in accordance with Unit 42’s attribution framework, the group behind this cluster has operated under the radar for at least two years, distributing an indeterminate number of payloads."
        https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
      • Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
        "GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. GreyNoise has been tracking malicious use of 45[.]142[.]193[.]132 since early July 2026 due to its use for attacks against internet facing technologies and devices from Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE."
        https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf

      Breaches/Hacks/Leaks

      • AdaptHealth Confirms 4.1 Million People Exposed In July Cyberattack
        "Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. The company provides home medical devices, supplies, and related services, including sleep-apnea and respiratory equipment, oxygen therapy, hospital beds, and mobility products. AdaptHealth first disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC) on July 2, 2026, informing that attackers accessed its systems and exfiltrated private data."
        https://www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-people-exposed-in-july-cyberattack/
      • Veradigm Warns Of Patient Data Breach After Ransomware Gang Claims Attack
        "Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. The company says the incident did not cause operational disruptions but affected a small number of customers. Formerly known as Allscripts Healthcare Solutions, Veradigm is a Chicago-based healthcare technology company that supplies medical practices with electronic health records, e-prescribing, patient-engagement, practice-management, and revenue-cycle software."
        https://www.bleepingcomputer.com/news/security/veradigm-discloses-patient-data-breach-after-gentlemen-gang-claims-attack/
        https://therecord.media/electronic-health-record-company-says-customer-data-stolen-in-breach

      General News

      • August 2026 Cyber Threat Landscape: GenAI Data Exposure Emerges As a New Enterprise Risk As Attacks, Phishing, And Ransomware Accelerate
        "August showed that cyber risk is intensifying on multiple fronts at once. Global attacks continued to rise, ransomware volumes accelerated, and phishing remained a consistent entry point for threat actors. GenAI added a more nuanced but equally important signal: while August recorded the lowest rate of high-risk for data exposure in GenAI prompts in several months, enterprise AI usage continued to expand sharply, with the average number of prompts per user rising from around 78 in June to 95 in July and 106 in August."
        https://blog.checkpoint.com/security/august-2026-cyber-threat-landscape-genai-data-exposure-emerges-as-a-new-enterprise-risk-as-attacks-phishing-and-ransomware-accelerate/
      • FBI Officials Say AI Is Bolstering Adversaries, Emphasizing Need To Focus On Cyber Basics, Patching
        "Artificial intelligence is souping up the speed and capabilities of malicious hackers, a top FBI official said Tuesday. And the speed of vulnerability discoveries is forcing organizations to patch more frequently, said another top FBI official. The officials made their remarks one day before the release of a new FBI cyber strategy Wednesday, which touches on AI, relief and justice for victims and other bureau priorities. Speaking to both CyberScoop and at the Billington CyberSecurity Summit, Jason Bilnoski, deputy assistant director of the FBI’s cyber division, said AI is “taking actors to the next level.”"
        https://cyberscoop.com/fbi-cyber-strategy-ai-threats-patching/
      • The Anthropic Glasswing Receipts Are Starting To Trickle In
        "Anthropic’s Project Glasswing is approaching 5 months old, and Anthropic published its Vulnerability Disclosure Ledger on May 22nd. It hadn't received an update until this past week, when it backfilled the ledger with additional findings and updates, so naturally I thought it would be worthwhile to take a look at the receipts. For a bit more context, I've been tracking Project Glasswing since they launched the project on April 7, and have published a series of blog posts covering the project:"
        https://www.vulncheck.com/blog/anthropic-glasswing-receipts
        https://www.darkreading.com/application-security/mythos-vulnerability-firehose-hits-human-bottleneck
      • Gartner: 70% Of SOCs Will Pilot AI Agents. Only 15% Will See Results
        "In the Gartner report Validate the Promises of AI SOC Agents With These Key Questions, analysts Craig Lawson and Andrew Davies posit that “By 2028, 70% of large SOCs will pilot AI agents to augment Tier 1 and Tier 2 operations, but only 15% will achieve measurable improvements without structured evaluation.” Just last year, Gartner placed AI SOC Agents at the Innovation Trigger stage with single-digit adoption. As of earlier this year, Gartner’s Hype Cycle for Security Operations, 2026 put them at the Peak of Inflated Expectations."
        https://www.helpnetsecurity.com/2026/09/09/prophet-security-evaluating-ai-soc-agents/
      • 2026 SpyCloud Identity Threat Report
        "Identity exposure is measurable and fixable – yet most organizations are still navigating with an outdated map, drawn for marked trails rather than the backcountry attackers now roam. The terrain has expanded past employee credentials to session tokens, non-human identities, and third-party ecosystems, and closing the gap means surveying what’s exposed beyond the camp’s edge before attackers get there first. This year’s Identity Threat Report [1] – a survey of security leaders and practitioners across North America, UK and select European Markets – benchmarks how enterprise organizations detect, remediate, and govern identity threats – and what separates the most mature programs from the rest."
        https://spycloud.com/resource/report/identity-threat-report-2026/
        https://www.infosecurity-magazine.com/news/nhis-number-one-corporate-entry/
      • This Key Will Self-Destruct: An Open Standard For Revocable API Keys
        "Every security leader has lived some version of this incident. A researcher, a scanner, or a well-meaning stranger finds one of your API keys sitting in a public repository. Now the clock is running, but instead of a kill switch, what follows is a scavenger hunt. Which company issued this key? Who do I contact? Is there a security.txt? Does anyone read that inbox? By the time the right person revokes the right credential, hours or days have passed, and attackers needed minutes. Bots scrape public repos constantly, and the majority of leaked secrets are still active years later."
        https://www.securityweek.com/this-key-will-self-destruct-an-open-standard-for-revocable-api-keys/
      • Scam Center Strike Force Conducts Seizures Of Chinese-Run Illicit Scammer Marketplace, And Restrains $52 Million In Laundered Crypto Scammer Funds In One Day
        "U.S. Attorney Jeanine Ferris Pirro, together with major federal law enforcement and interagency partners, announced actions taken by the Department of Justice’s Scam Center Strike Force to secure America against Southeast Asian cryptocurrency-related fraud and scams. The Strike Force and the Department of the Treasury took coordinated actions against Xinbi Guarantee (“Xinbi”), an illicit marketplace for scam services, and the Strike Force deployed to Madagascar to assist in the taking down of 13 Chinese-run scam compounds. Approximately $52 million of cryptocurrency involved in scam money laundering was restrained in one day, bringing the total restrained by the Scam Center Strike Force to approximately $938 million."
        https://www.justice.gov/usao-dc/pr/scam-center-strike-force-conducts-seizures-chinese-run-illicit-scammer-marketplace-and
        https://thehackernews.com/2026/09/us-disrupts-xinbi-guarantee-scam.html
        https://therecord.media/us-disrupts-xinbi-guarantee-marketplace-cybercrime

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) c1c561a3-1bce-4607-94f6-362419364e87-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 09 September 2026

      Industrial Sector

      • CareCam Pro IP Cameras
        "Successful exploitation of this vulnerability could allow an attacker to take full control of the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-251-01

      Vulnerabilities

      • Microsoft September 2026 Patch Tuesday Fixes 966 Flaws, 2 Zero-Days
        "Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. This Patch Tuesday addresses 105 "Critical" vulnerabilities, 81 of which are remote code execution, 20 are elevation of privileges, 2 are information disclosure, and 1 security feature bypass."
        https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/
        https://blog.talosintelligence.com/microsoft-patch-tuesday-for-september-2026/
        https://www.darkreading.com/vulnerabilities-threats/patch-tuesday-another-record-974-cves
        https://therecord.media/microsoft-patch-tuesday-september-2026
        https://cyberscoop.com/microsoft-patch-tuesday-september-2026/
        https://www.securityweek.com/microsoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days/
      • SAP Warns Of Maximum Severity 'OVERPASS' Kernel Vulnerability
        "SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. Tracked as CVE-2026-44756 and dubbed OVERPASS by Onapsis security researchers who reported it, the vulnerability stems from a classic buffer overflow weakness in the Extended Passport Protocol (EPP) processing library. Successful exploitation lets unprivileged threat actors run arbitrary commands on vulnerable SAP hosts with administrative privileges, leading to full compromise of the underlying SAP processes and business data."
        https://www.bleepingcomputer.com/news/security/sap-warns-of-maximum-severity-overpass-kernel-vulnerability/
        https://onapsis.com/blog/sap-overpass-remediation/
        https://www.securityweek.com/sap-patches-critical-extended-passport-processing-vulnerability/
      • Adobe Fixes Critical Magento Zero-Day Exploited To Backdoor Servers
        "Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. E-commerce security company Sansec discovered that the flaw has been leveraged in attacks since at least September 4 to plant a backdoor on vulnerable websites. The backdoor disguised its command-and-control (C2) host as a regular Network Time Protocol (NTP) server. However, it still leaves distinct signs of activity on compromised hosts, such as "Payment Transaction Failed Reminder" emails."
        https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-magento-zero-day-exploited-to-backdoor-servers/
        https://helpx.adobe.com/security/products/magento/apsb26-146.html
        https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html
      • Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
        "Adobe has released patches for more than 170 vulnerabilities across its products, including urgent hotfixes for a critical-severity flaw in Adobe Commerce and Magento Open Source that has been exploited in the wild as a zero-day. Tracked as CVE-2026-75650 (CVSS score of 10/10), the flaw is a code injection issue that can be exploited without authentication for remote code execution (RCE)."
        https://www.securityweek.com/adobe-patches-over-170-vulnerabilities-including-commerce-zero-day/
      • FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
        "A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The FreeIPA project has already fixed its side in version 4.13.4. Red Hat says it reproduced the chain twice on a default installation, most recently on a machine with no access at all."
        https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html
      • CISA Adds Four Known Exploited Vulnerabilities To Catalog
        "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
        CVE-2026-81963 Microsoft Windows Link Following Vulnerability
        CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability
        CVE-2026-86218 N-able N-central Static Code Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog

      Malware

      • China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
        "China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) (hereafter referred to as the authoring agencies) are releasing this joint Cybersecurity Advisory to alert organizations about these malicious activities and techniques and recommend mitigations to reduce their potential impact."
        https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a
        https://cyberscoop.com/us-accuses-chinese-ai-companies-distillation/
        https://www.bankinfosecurity.com/us-warns-chinese-ai-firms-are-illicitly-distilling-models-a-32773
      • DoppelCart: 119,000 Domains In What May Be The Largest Documented Fake-Shop Network
        "Around 119,000 domains, connected by shared infrastructure and recurring features in their shop software. Product catalogs from real businesses, copied descriptions and original images. And customers whose complaints end up with the legitimate store. We investigated a fake-shop network whose scale surprised even us. We call it DoppelCart. To our knowledge, DoppelCart is the largest fake-shop cluster publicly documented to date, measured by the number of associated domains. Its .shop domains alone account for 2.72 percent of the .shop domain population in our snapshot. That is roughly one in every 37 domains."
        https://nebty-id.com/en/doppelcart-fake-shop-network/
        https://www.bleepingcomputer.com/news/security/doppelcart-fraud-network-uses-119-000-fake-shops-to-steal-credit-cards/
      • Dissecting a PHP Web Server Rootkit
        "SophosLabs recently acquired a Linux implant associated with compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components. The malware demonstrates advanced techniques including custom ELF loading, function hooking, and runtime code patching to evade detection while maintaining persistent access through hidden web shells. The implant delivers a familiar outcome – on-demand server‑side code execution commonly associated with web shells – but implements it using deeper Linux- and Apache‑specific tradecraft."
        https://www.sophos.com/en-us/blog/dissecting-a-php-web-server-rootkit
        https://www.bleepingcomputer.com/news/security/hackers-breach-f5-big-ip-apm-devices-to-deploy-linux-rootkit/
      • ClearFake WebDAV Infection Chain Delivers Amatera Stealer, ZigCryptoStealer, And NetSupport Manager
        "Cisco Talos began an investigation after observing a DLL named "verification.google" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload. Pivoting around the similar WebDAV behavior led to a second loader named "pf.ch" and allowed us to reconstruct its earlier delivery stages. The chain uses a Cloudflare Worker to inject JavaScript code stored on BNB Smart Chain and a ClickFix prompt impersonating Google CAPTCHA, leading to download and execution of Amatera stealer. The chain is likely very similar to what has caused the WebDAV-based execution at the Ukraininan government organization."
        https://blog.talosintelligence.com/clearfake-webdav-infection-chain/
      • ClickFix Moves Into The Browser: Cryptocurrency Theft With Google-Hosted C2
        "Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session. The actors use a variation on ClickFix social engineering. Instead of convincing targets to run commands against the operating system, they convince targets to paste JavaScript into the Chrome address bar or install it into the Tampermonkey browser extension, which also provides persistence."
        https://blog.talosintelligence.com/clickfix-moves-into-the-browser/
        https://www.darkreading.com/endpoint-security/clickfix-campaigns-legitimate-services-persistent-access
      • Bypassing The Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure Into a Trust Proxy
        "In addition to everyday users, Google's infrastructure is trusted by email security gateways, enterprise firewalls and automated URL detonation platforms. Threat actors know this. In this KnowBe4 Threat Lab analysis, we break down an active, wide-scale phishing campaign that routes victims through a deliberate chain of legitimate Google services before landing them on credential harvesters or deploying remote access tools. The execution here is unusually complete: six distinct Google properties abused across multiple redirect paths, a landing page that dynamically impersonates the victim's own organization in real time, and a dual-track post-redirect architecture that delivers either credential theft or persistent remote access depending on the lure context."
        https://blog.knowbe4.com/bypassing-the-gatekeepers-how-a-global-phishing-campaign-turns-googles-infrastructure-into-a-trust-proxy
        https://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaign
      • Hagaseca: Inside a Packed Android RAT Loader
        "Hagaseca is an Android malware cluster associated with exposed Android Debug Bridge (ADB) services. This analysis examines the Hagaseca Android RAT loader known as THost9. RAT stands for remote access trojan. A RAT can let an attacker control an infected device remotely. The loader hides executable code inside an Android application package (APK). It then loads tc9.dex, a separate stage with shell access, file transfer, and ADB propagation capabilities."
        https://darkatlas.io/blog/hagaseca-inside-a-packed-android-rat-loader
        https://www.infosecurity-magazine.com/news/thost9-android-rat-packed-loader/
      • WeWorm
        "At Calif, our mission is to keep the Internet together by occasionally taking it apart. We believe everyone deserves a safe and secure Internet, including the people who cannot protect themselves. Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. This is the first installment in a series exploring zero-click attack surfaces in mobile messaging apps. WeChat is an "everything app" used by virtually everyone in China and by Chinese communities worldwide. Simply by calling a victim, WeWorm can hijack their account and call their friends, spreading from phone to phone. If exploited, actors can compromise over a billion phones (or accounts), upending livelihoods and breaking communities worldwide."
        https://calif.io/research/weworm
        https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html
        https://securityaffairs.com/198688/hacking/wechat-worm-can-hijack-accounts-without-victims-answering-calls.html
        https://www.helpnetsecurity.com/2026/09/08/wechat-weworm-vulnerability-exploit-account-hijacking/
      • Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
        "A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment service Pix, digital asset platforms, and financial entities' cloud environments," CrowdStrike said."
        https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html
        https://go.crowdstrike.com/rs/281-OBQ-266/images/CrowdStrike-2026-Threat-Hunting-Report.pdf
      • BengalSEO Part 1: Anatomy Of The Operation
        "In March 2026, our team identified an SEO poisoning campaign leading to malware deployment and tech support scams. Further research into this campaign revealed a sophisticated and widespread scam operation that has been operating since at least 2015. Our team attributes this operation, with high confidence, to a group of core individuals and IT service providers operating out of Rajasthan, India, which our team tracks collectively as BengalSEO. Using indicators gathered from the identified SEO poisoning campaign, our team was able to correlate this activity with information posted on scam hunting forums. This discovery led our team to a company named WeConnect Solutions LLC (previously iConnect Soft Solutions LLC), which operates a tech support call center located in Kota, Rajasthan."
        https://thedfirreport.com/2026/08/24/bengalseo-part-1-anatomy-of-the-operation/
        https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html
      • Anatomy Of a Layered, Multi-Brand Phishing Campaign
        "Barracuda Research has analyzed a multi-layered, multi-brand phishing campaign that reflects a trend for attackers to embed authentication requests inside familiar business workflows. Similar to platforms such as Kali365, which we recently reported on, the objective is to make authentication appear a routine step in a document-sharing, signing or collaboration process. However, unlike Kali365’s device-code phishing and token-focused attacks, this campaign relies on browser-in-the-browser (BitB) deception to harvest credentials directly."
        https://blog.barracuda.com/2026/09/08/browser-in-the-browser-phishing-docusign-adobe-microsoft

      Breaches/Hacks/Leaks

      • ShinyHunters Hackers Claim Breach Of Florida "DAVID" DMV Database
        "The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state. As proof of the breach, the threat actor has released a screenshot of Jeffrey Epstein's DMV record, including his address and registered vehicles. DAVID is the "Driver and Vehicle Information Database" platform operated by the Florida Highway Safety and Motor Vehicles (FLHSMV) agency, used by law enforcement and officials to look up information about a particular driver."
        https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/
        https://hackread.com/shinyhunters-florida-dmv-breach-jeffrey-epstein-proof/
      • 220 Million Traveler Records Exposed In Vietnam-Linked APIS Leak
        "An Advance Passenger Information System (APIS) database holding more than 220 million passenger and crew records, including passport numbers and flight details, was accessible online through a chain of security misconfigurations. The system appears linked to a Vietnamese organization, according to the researchers who discovered it. Advance Passenger Information Systems are used worldwide to collect identity, passport, and flight information from airlines before passengers and crew arrive at or depart from a country."
        https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/
        https://securityaffairs.com/198671/data-breach/massive-vietnam-linked-apis-database-exposes-passport-and-flight-data.html
      • Cyberattack Encrypts Systems At Bavarian Municipal Utility
        "A municipal utility in Bavaria said Monday that hackers encrypted its central IT network in a cyberattack last week. In a notice to customers, Stadtwerke Landsberg said the attack disrupted office systems but is not affecting electricity, water and other essential services. The incident began overnight on September 1, the utility said, prompting it to disconnect the affected systems from the internet, activate its crisis team and bring in external cybersecurity specialists."
        https://therecord.media/cyberattack-bavaria-germany-utility

      General News

      • GTIG AI Threat Tracker: From Prompting To Autonomy – The Evolution Of Adversarial AI
        "Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, build, and execute an agent-enabled mass credential harvesting campaign in under six hours. We also tracked UNC6780 using multiple tactics to trick AI coding assistants and large language model (LLM) security scanners into its open source software supply chain compromises."
        https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai
        https://www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-credential-theft/
        https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html
        https://www.infosecurity-magazine.com/news/ai-coding-tools-threat-actors/
        https://www.theregister.com/research/2026/09/08/extortion-crews-have-their-eyes-on-high-value-ai-data-google-warns/5294640
        https://www.helpnetsecurity.com/2026/09/08/ai-agents-cyberattacks-automation-google-research/
      • ChatGPT Let Attackers Read Victims’ Gmail Through a Hidden Channel Between Accounts
        "Enterprises are connecting AI assistants to more of their real infrastructure every month, from inboxes to file drives to internal tools, on the assumption that the isolation between users and accounts holds. Check Point Research just tested that assumption against ChatGPT and found a way to break it. Using an internal service that was never meant to carry user data at all, CPR opened a working channel between two completely separate ChatGPT accounts and used it to hand one victim’s session a task from a total stranger, all while the victim’s own conversation looked entirely normal."
        https://blog.checkpoint.com/research/chatgpt-let-attackers-read-victims-gmail-through-a-hidden-channel-between-accounts/
        https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/
        https://thehackernews.com/2026/09/chatgpt-flaw-let-planted-prompt-send.html
      • Russian National Extradited To United States For Bank Account Takeover Fraud Scheme Causing Millions Of Dollars In Losses
        "Sergei Anatolyevich Filimonov, 36, a Russian national and web developer who was allegedly involved in a transnational cyber‑fraud conspiracy responsible for large‑scale bank account takeover activity, was arraigned Friday in the Northern District of Georgia after being extradited from the Republic of Georgia. Filimonov was indicted by a federal grand jury on Nov. 4, 2025, for charges relating to a credential‑harvesting and bank‑fraud operation that targeted victims across the United States."
        https://www.justice.gov/opa/pr/russian-national-extradited-united-states-bank-account-takeover-fraud-scheme-causing
        https://therecord.media/russian-cybercrime-bank-extradition
        https://cyberscoop.com/russian-national-extradited-bank-account-takeover-sergei-filimonov/
      • Scammer Behind $245 Million Crypto Heist Pleads Guilty To RICO Charges
        "A Singaporean national pleaded guilty to racketeering charges on Tuesday for his role leading a group of scammers who stole more than $245 million in cryptocurrency. Malone Lam, 22, will appear in U.S. District Court in Washington D.C. on December 8 for more information on sentencing. Participating in a RICO conspiracy charges carry sentences ranging from 7 to 20 years. Lam was indicted on scamming charges in September 2024 after drawing law enforcement scrutiny for parlaying stolen crypto into lavish Hamptons vacations, cars and private jets. Prosecutors said Lam, known as “Anne Hathaway,” or “$$$,” ran an operation where he and others would conduct social engineering scams to steal cryptocurrency."
        https://therecord.media/scammer-behind-245-million-crypto-heist-pleads-guilty-rico
        https://www.securityweek.com/partys-over-for-crypto-scammers-who-went-on-a-spending-spree-after-a-240-million-bitcoin-theft/
      • French Prosecutors Confirm Arrest Of Suspected ZeroBytes Hacker Behind Tax Cyberattack
        "French authorities detained an 18-year-old suspected member of the ZeroBytes hacking group over cyberattacks targeting the country's tax authority and other organizations, the Paris prosecutor's office confirmed to Recorded Future News. The suspect was arrested in the Paris region on August 18 and placed in pretrial detention two days later. A second suspect, who is under 16, was arrested on August 26 and later released while investigators examine his devices, prosecutors said Tuesday in response to a media inquiry."
        https://therecord.media/france-hacker-arrest-zerobytes

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) c1c561a3-1bce-4607-94f6-362419364e87-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบบริการฟิชชิง BigBear 2.0 ข้าม MFA ของ Microsoft 365 เพื่อสวมรอยเข้าถึงบัญชี

      พบบริการฟิชชิง BigBear 2.0 ข้าม MFA ของ Microsoft 365 เพื่อสว.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand eee2494d-c57d-4417-8304-67e4adfcb70e-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Mathspace แจ้งเหตุข้อมูลรั่วไหล กระทบนักเรียน บุคลากร และผู้ปกครองกว่า 1 ล้านราย

      Mathspace แจ้งเหตุข้อมูลรั่วไหล กระทบนักเรียน บ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 8b286300-759f-4d0e-b9fe-174c23bd34da-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT