NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,634
    • กระทู้ 2,635
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    NCSA_THAICERT

    @NCSA_THAICERT

    1
    ชื่อเสียง
    58
    ดูข้อมูลส่วนตัว
    2.6k
    กระทู้
    3
    คนติดตาม
    0
    ติดตาม
    เข้าร่วม ออนไลน์ล่าสุด
    เว็บไซต์ www.ncsa.or.th/?fbclid=IwAR0BqJEC-CJzBs98rlBxUbZkNBgp1g814xdDNNaKnHTrxfqZhPD--ksY68I

    NCSA_THAICERT เลิกติดตาม ติดตาม
    Global Moderator administrators

    Latest posts made by NCSA_THAICERT

    • Cyber Threat Intelligence 02 October 2026

      Industrial Sector

      • Armatura LLC Armatura One
        "Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01
      • Monta Monta.app
        "Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-02
      • CISA Malcolm
        "The following versions of CISA Malcolm are affected:"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01
      • ABB Protection And Control IED Manager PCM600
        "Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-03
      • Johnson Controls EasyIO Neo Series EC And CW Controllers
        "Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-04
      • Johnson Controls EasyIO Neo Series EC And CW Controllers
        "Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-05
      • Meari IoT Cloud Platform OpenAPI Service
        "Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-06

      Vulnerabilities

      • Fortinet Warns Of Critical FortiMail Flaw Exploited In Zero-Day Attacks
        "Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. The vulnerability is rated critical, with a CVSS score of 9.8, and affects the FortiMail management interface. "An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests," Fortinet said in an advisory published Thursday."
        https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/
        https://fortiguard.fortinet.com/psirt/FG-IR-26-175
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog
      • Apple CoreGraphics PoC Emerges As WhatsApp PDF Checks Hint At Possible Delivery Path
        "Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working exploit is separate work the analysis does not demonstrate. Apple patched the flaw on September 28, crediting Meta Product Security with the discovery and noting it may have been used in an "extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.""
        https://thehackernews.com/2026/10/apple-coregraphics-poc-emerges-as.html
        https://securityaffairs.com/200175/hacking/public-poc-released-for-apple-coregraphics-zero-day-cve-2026-86950.html

      Malware

      • AI Agents Targeted U.S. And Canadian Government Websites
        "Following up on our previous blog post, we discovered several additional incidents where rogue AI agents appear to have used aggressive techniques to access publicly available data on government websites. This includes two rudimentary and failed hacking attempts, one against the U.S. Department of Education’s Civil Rights Data Collection, and one against Library and Archives Canada, a Canadian federal agency. These failed attempts connect to additional rogue activity where agents used an array of aggressive tactics short of hacking to probe U.S. government websites, often using sites in unintended ways and sometimes violating explicit usage policies. This activity targeted websites across the White House, the Departments of War, Justice, and Commerce, the CDC and SEC, and state agencies in California, Maryland, Illinois, Texas, and New York."
        https://transluce.org/us-canada-gov
        https://www.bleepingcomputer.com/news/security/autonomous-ai-agents-tried-to-hack-us-canadian-government-websites/
      • Hallucinating Credibility: China-Aligned TA419 Impersonates Its Way Into US AI Policy Circles
        "In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US. The group first sent benign conversation starter emails, which included calls to action themed around AI policy such as joining an “AI Policy Advisory Committee”, to build rapport and solicit a response from the target. Once the target replied, TA419 followed up with a multi-stage URL redirection chain that led to an Adversary-in-the-Middle (AitM) credential phish that employed a customized version of the open-source Browser-in-the-Browser (BitB) phishing tool Frameless BitB."
        https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy
        https://therecord.media/china-linked-phishing-scheme-backdoor-taiwan
        https://cyberscoop.com/china-cyber-espionage-ta419-phishing-us-ai-policy-experts/
        https://www.infosecurity-magazine.com/news/ta419-impersonates-ai-experts-us/
      • Warlock Ransomware Attackers Hit Water And Telecom Operators
        "The China-nexus group behind Warlock ransomware is still breaking into organizations through Microsoft SharePoint vulnerabilities, a tactic that brought it to prominence a year ago. In the past two months, the group, which Symantec tracks as Longlegs (aka Storm-2603), attacked at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. The victims included two critical infrastructure operators, a water utility and a telecommunications provider, along with a regional government body and a university."
        https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure
        https://www.darkreading.com/cyberattacks-data-breaches/warlock-ransomware-spanish-portuguese
      • Milk Dragon: Huge Discounts On Social Media? Think Twice Before You Buy
        "Phishing doesn’t always arrive in your inbox. In previous Group-IB blogs (GTFire Phishing Scheme and Phoenix Rising), we covered attacks that start with a suspicious email or text message. But some lures are designed to find you where your guard is at its lowest: your social media feed. Picture this. You’re doomscrolling late at night when an advertisement catches your eye. A brand you know and trust, selling products you actually want, at a discount that seems too good to pass up. No urgent warnings, no “act now or else,” no red flags screaming for attention. Just a deal that seems to pop up organically. That’s exactly what makes it dangerous: these attacks strike when your brain is on autopilot."
        https://www.group-ib.com/blog/milk-dragon-nailong-phishing-kit/
      • CloudSyncD: a Two-Stage MacOS Backdoor That Hides a Phished Password In Zero-Width Unicode
        "While performing routine monitoring of executables in VirusTotal, Jamf Threat Labs identified a macOS dropper buried within a disguised Zoom client. We are tracking this malware under the name CloudSyncD, after the daemon name its second stage runs under. We first encountered CloudSyncD on September 15, 2026, in a build that was plainly still under development. After two days of monitoring, we identified samples of the same family configured against live infrastructure across more than one command-and-control domain, indicating the operators have moved from testing toward deployment."
        https://www.jamf.com/blog/cloudsyncd-macos-backdoor-fake-zoom-installer/
        https://www.infosecurity-magazine.com/news/cloudsyncd-macos-backdoor-fake/
      • MI5 Warns Over 100 Academics Helped China's Espionage Plans
        "The UK’s domestic security agency has warned that over 100 academics have helped Beijing’s spies to improve their espionage capabilities. MI5 issued the rare espionage alert on September 30, calling out the China General Technology Research Institute (CGTRI), or China Academy of General Technology (CAGT), for its connection to China's Ministry of State Security (MSS). Unusually for a security agency, the MSS handles both domestic/counterintelligence and foreign intelligence. It is thought to employ hundreds of thousands of workers, including many hackers that have been responsible for some of China’s most audacious campaigns, via ‘groups’ such as Silk Typhoon and Salt Typhoon."
        https://www.infosecurity-magazine.com/news/mi5-alerts-academics-chinese/
      • Fake xStocks, Pendle, And Other Sites Bait Crypto Users With Rewards Votes
        "We found 70 websites that impersonate legitimate crypto projects that invite visitors to vote on the date of an upcoming rewards distribution. The pages copy the look of the real sites closely, and on most of them the offer is small and believable: Cast a vote, and as an active voter you get a 1.25x boost when the rewards are paid out. However, the vote is fake and clicking the Vote now button opens a wallet connection prompt. It’s the first step toward requests that could trick visitors into authorizing access to their tokens."
        https://www.malwarebytes.com/blog/threat-intel/2026/10/fake-xstocks-pendle-and-other-sites-bait-crypto-users-with-rewards-votes
      • SC WordPress Malware: A Self-Healing Mesh Of Loaders, Drop-Ins, And a Blockchain-Controlled Backdoor
        "During recent website cleanup work, we analyzed a WordPress compromise where the same backdoor kept returning within seconds of every removal, no matter how carefully the visible files were deleted. Throughout this article, we’ll refer to this family of malware as SC, named after the “SC_” markers found in the injected content. What makes SC worth documenting is how it survives. The payload lives in at least eight places at once, spread across files, the database, and shared memory, and every one of those places can rebuild all the others. Delete the plugin and a drop-in rewrites it. Delete the drop-in and the theme rewrites it. Clean every file on disk, and the next page load restores the whole set from the database or from a shared-memory segment. The result is a circular system with no single point you can remove to stop it."
        https://blog.sucuri.net/2026/09/sc-wordpress-malware-a-self-healing-mesh-of-loaders-drop-ins-and-a-blockchain-controlled-backdoor.html
        https://thehackernews.com/2026/10/wordpress-backdoor-rebuilds-itself.html
      • Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts And Hunt Indicators
        "CVE-2026-88771 is a critical pre-authentication command-injection vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. Citrix and security researchers have already documented the vulnerability and its underlying exploitation mechanism. This analysis focuses instead on exploitation activity identified by LevelBlue's Threat Hunt Operations & Research (THOR) team while hunting across multiple customer environments."
        https://www.levelblue.com/blogs/spiderlabs-blog/citrix-netscaler-cve-2026-88771-observed-exploitation-artifacts-and-hunt-indicators
        https://thehackernews.com/2026/10/citrix-netscaler-post-exploitation.html
      • Rogue Agents Investigation: Initial Findings
        "Asymmetric Security investigated suspicious AI agent activity on the public internet from March 6, 2026 to September 20, 2026. Below we list organizations whose data was accessed by these agents. In the vast majority of cases, all data retrieved was and is public. We also list tools the agents used to access the internet, in a capacity which we suspect was outside their remit. A more detailed writeup is now available."
        https://www.asymmetricsecurity.com/newsroom/rogue-agents-investigation-initial-findings/
        https://www.asymmetricsecurity.com/newsroom/rogue-agents-investigation/
        https://therecord.media/openai-software-attempted-to-secretly-scrape-data-from-dozens-of-websites
      • TIKTOUK: Tracing a WordPress Credential Collection Toolkit
        "TIKTOUK brings together WordPress probing, collection of exposed configuration data, recovery of encrypted email credentials, and JavaScript secret scanning. Its two Python components and Go-based Linux crawler turn website responses into structured results for a central hub: an HTTP service that distributes target tasks and receives collected data and status reports. The key security issue is the combination of exposed configuration material and encrypted plugin settings: the collection component used the corresponding keys to recover plaintext email credentials."
        https://www.levelblue.com/blogs/spiderlabs-blog/tiktouk-tracing-a-wordpress-credential-collection-toolkit

      Breaches/Hacks/Leaks

      • Metamask Discloses Security Incident Affecting Its Infrastructure
        "On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. The company is working to address the issue internally, with help from external partners and security advisors, and says there is "no immediate threat to MetaMask wallets." "As a precautionary measure, we are proactively exiting affected validators within our non-custodial staking operations, in coordination with clients and partners," MetaMask noted. "As a reminder, our staking operations are non-custodial in nature and we do not manage withdrawal keys for stake on behalf of our clients.""
        https://www.bleepingcomputer.com/news/security/metamask-discloses-security-incident-affecting-its-infrastructure/
        https://thehackernews.com/2026/10/metamask-security-incident-prompts-exit.html
      • Cyberattack On Major Polish Invoicing Platform Exposes Customer Data
        "One of Poland’s major online invoicing platforms suffered a data breach that may have exposed information belonging to its users, their customers and business partners. Fakturownia said earlier this week that an unidentified attacker exploited a vulnerability in its systems and gained unauthorized access to servers. The company, whose service is used by more than 600,000 businesses, is still trying to determine how many customers were affected."
        https://therecord.media/poland-cyberattack-invoice-software

      General News

      • Teenager Suspected Of Leading KillSec Ransomware Group As Law Enforcement Seizes Servers And Leak Site
        "On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of stolen files unless they paid a ransom. The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1 000 suspected attacks worldwide. Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds."
        https://www.europol.europa.eu/media-press/newsroom/news/teenager-suspected-of-leading-killsec-ransomware-group-law-enforcement-seizes-servers-and-leak-site
        https://www.bleepingcomputer.com/news/security/police-dismantle-killsec-ransomware-gang-allegedly-led-by-16-year-old/
        https://www.darkreading.com/cyberattacks-data-breaches/killsec-ransomware-mastermind-16-year-old
        https://thehackernews.com/2026/10/police-arrest-16-year-old-suspected-of.html
        https://therecord.media/killsec-ransomware-raas-arrests-europe
        https://www.bankinfosecurity.com/spain-arrests-teen-suspected-running-killsec-ransomware-a-33002
        https://cyberscoop.com/killsec-ransomware-group-arrests-operation-killswitch/
        https://www.securityweek.com/police-shut-down-killsec-ransomware-identify-alleged-teen-leader/
        https://securityaffairs.com/200200/cyber-crime/operation-killswitch-police-dismantle-killsec-ransomware-group.html
        https://www.helpnetsecurity.com/2026/10/01/killsec-ransomware-16-year-old-main-operator-arrested/
      • The Fine Art Of Frustrating The Adversary
        "Years ago, Cisco Talos blocked an adversary’s command-and-control (C2) traffic. The adversary responded by tweeting, “Write a rule for your a**.” A fine endorsement of our work, if I’ve ever heard one. Talos loves to see an adversary forced to change course. And if every alternative for them is slower, less stealthy, less reliable and more expensive? Chef’s kiss. Adversaries rely on certain advantages. They look for environments where tools and infrastructure allow them to blend in with normal activity. They also look for employees who can be pressured into acting before they have time to think."
        https://blog.talosintelligence.com/the-fine-art-of-frustrating-the-adversary/
      • Many Expect AI In The SOC To Make Entry Jobs Harder To Get
        "A junior analyst in a security operations center, or SOC, has usually learned the job the slow way. You work the same phishing lure dozens of times, chase the same familiar malware pattern and write up the same case note at the end of the shift. Eventually you know what normal looks like, which is how you notice when something isn’t. AI tools handle a lot of that repetitive work, and the people doing the job are glad to see it go. Nearly nine in ten respondents in a Swimlane survey of 500 security operations staff, all at organizations already using AI, say it has made their work more satisfying. The catch is who is saying it. About a quarter of respondents say AI has held back their ability to build security skills. Those analysts are just as happy with their jobs as the ones who say AI helped them learn: 91% versus 92%."
        https://www.helpnetsecurity.com/2026/10/01/ai-soc-entry-jobs/
      • Employment Scam Victims Tripled At Financial Firms In 21 Countries
        "Reported victims of employment scams more than tripled over the past 12 months at more than 370 banks and other financial institutions in 21 countries. The 258% rise outran every other scam type, while total reported scams across the same institutions grew 35%. Researchers at BioCatch, a fraud-detection vendor, compiled the figures from reports filed by the institutions that use its software. The numbers matter for anyone running fraud controls because of where the scams happen. Nine of every 10 scam sessions now start on a mobile device. Traditional unauthorized fraud, where a criminal works the account without the owner’s help, comes from mobile in 75% of cases."
        https://www.helpnetsecurity.com/2026/10/01/employment-scam-victims-research/
      • AI Threats Top Cybersecurity Preparedness Gap, PwC Finds
        "Threats targeting AI systems is the area that cybersecurity leaders currently feel last able to address, with skills, accountability and data protection gaps also looming large, according to PwC. The consulting giant polled 3934 business and tech leaders across 71 countries for its 2027 Global Digital Trust Insights report, published on October 1. Over half (52%) said adversarial AI attacks represent the biggest cyber preparedness gap. The challenge of responding to these risks is compounded by governance issues."
        https://www.infosecurity-magazine.com/news/mitigating-adversarial-ai-top/
        https://www.securityweek.com/enterprises-struggle-to-prepare-for-ai-and-quantum-threats-pwc-says/
      • Shadow AI Explained: The Work Shortcut That Could Leak Your Company’s Secrets
        "Using an AI chatbot, assistant, or browser to speed up your work is tempting, but doing it without your employer’s knowledge can put sensitive data at risk. You’re swamped, so you paste a long email thread into a free chatbot and ask for a summary. It works, it saves an hour, and nobody notices. But the thread may contain customer details or confidential plans you’ve just shared with an outside service. If your employer hasn’t approved that tool or how you’re using it, that’s shadow AI."
        https://www.malwarebytes.com/blog/ai/2026/10/shadow-ai-explained-the-work-shortcut-that-could-leak-your-companys-secrets
      • Hacker Conversations: Rob Juncker, a Knock At The Door And a Moral Compass
        "Rob Juncker is chief product and technology officer at Mimecast. Is he a hacker? “Unequivocally yes,” he says. “And I think every security leader should be able to answer ‘yes’ to that question, for so many reasons.” He started early, when his parents brought home an Apple IIc. He was 10. They wanted to use it for word processing; but within two days of it arriving he had the lid off, trying to figure out how it worked. He had a driving curiosity to understand it. This curiosity, which he describes more as a thirst for knowledge, started before the arrival of the Apple – but with hands-on access, it rapidly focused on technology."
        https://www.securityweek.com/hacker-conversations-rob-juncker-a-knock-at-the-door-and-a-moral-compass/
      • AI Has Changed Attack Speed, Not Security Fundamentals
        "People who know me well know that I am a very direct person and as such, I don’t enjoy overcomplicating terms used to describe straightforward things. In recent months, Frontier AI and other tools have allowed attackers and defenders alike to shorten the time required to identify vulnerabilities and develop exploits for those vulnerabilities. With this has come an awful lot of hype and buzz around the topic of “virtual patching.”"
        https://www.securityweek.com/ai-has-changed-attack-speed-not-security-fundamentals/
      • Treasury Blacklists Most-Wanted ATM Malware Developer And His Network
        "The US Treasury Department has sanctioned the alleged developer of malware used in ATM jackpotting attacks linked to Tren de Aragua (TdA), along with members of his network and two Mexico-based companies. Anibal Alexander Canelon Aguirre, known as ‘Prometheus,’ was added in March to the FBI’s Ten Most Wanted Fugitives list, becoming the first person on the list wanted for cybercrimes. Treasury describes him as “the alleged engineer of the malware used in ATM jackpotting attacks.” TdA typically uses the malware named Ploutus. Canelon Aguirre’s network is based in Mexico and Venezuela but targets ATMs in the United States. The stolen cash is laundered, including through cryptocurrency, and moved to TdA members in various countries."
        https://www.securityweek.com/treasury-blacklists-most-wanted-atm-malware-developer-and-his-network/
      • Microsoft Says Threat Actors Are Ahead In The Early AI Race
        "Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. This comes from Microsoft's 2026 Digital Defense Report, which strongly focuses on how artificial intelligence is changing both offensive and defensive cybersecurity operations. Microsoft says AI is reducing the time, expertise, and cost required to discover and exploit weaknesses, while allowing attackers and defenders alike to operate with greater speed, scale, and autonomy."
        https://www.bleepingcomputer.com/news/security/microsoft-says-threat-actors-are-ahead-in-the-early-ai-race/
        https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/2026-Microsoft-Digital-Defense-Report.pdf
      • Federal PQC Orders Are Here: How To Prioritize Migration Before Q-Day
        "The United States is in a race to develop its quantum capabilities and to migrate critical systems to post-quantum cryptography before standard encryption practices become obsolete. That’s because AI is merging with quantum computing and rapidly accelerating the timeline to Q-day. Frontier models can allow technologists to identify more efficient ways to design, architect, and scale quantum computers. In fact, it is now estimated that previous timelines predicting Q-day’s arrival in 2031 are even further compressed."
        https://www.forescout.com/blog/federal-pqc-orders-are-here-how-to-prioritize-migration-before-q-day/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 42ee4b28-a045-4db4-bc3c-21ea7ed6e64b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 01 October 2026

      New Tooling

      • OWASP Noir: Open-Source Static Analysis Tool
        "OWASP Noir is an open-source static analysis tool that reads an application’s source code and lists the endpoints it exposes: paths, HTTP methods, parameters, headers, and cookies, each tied to the file and line it came from. Here’s where it gets useful. Shadow APIs, the endpoints that live in the code but never made it into any documentation, show up in Noir’s inventory right next to everything else, along with deprecated routes and undocumented handlers."
        https://www.helpnetsecurity.com/2026/09/30/owasp-noir-open-source-static-analysis-tool/
        https://github.com/owasp-noir/noir

      Vulnerabilities

      • Cisco Warns Of New SD-WAN Zero-Day Exploited In Attacks
        "Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. Formerly known as SD-WAN vManage, Catalyst SD-WAN Manager is network management software that lets admins monitor and manage up to 6,000 SD-WAN devices from a single dashboard. "In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," the company warned on Wednesday. "Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.""
        https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/
        https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
        https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html
      • TeamViewer Urges Users To Patch Severe Flaws “as Soon As Possible”
        "Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. The highest-severity flaw is a remote session access control bypass (CVE-2026-92370) stemming from an improper access control weakness in TeamViewer Full Client and Host software for Windows, Linux, and macOS that could let remote threat actors perform unauthorized actions leading to remote code execution on targeted systems."
        https://www.bleepingcomputer.com/news/security/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible/
      • WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
        "WatchGuard on Tuesday announced fixes for 15 vulnerabilities in Fireware OS, including a critical-severity remote code execution (RCE) bug. Tracked as CVE-2026-86131 (CVSS score of 9.2), the flaw is described as a code injection issue in how the operating system handles BOVPN over TLS client configurations. Successful exploitation could allow a remote attacker who controls the remote VPN server to execute commands with root privileges on the connecting Firebox appliance."
        https://www.securityweek.com/watchguard-patches-critical-fireware-os-code-injection-vulnerability/
        https://securityaffairs.com/200108/security/watchguard-fixes-critical-fireware-os-flaw-allowing-remote-code-execution.html
      • Chrome, Firefox Updates Patch Over 100 Vulnerabilities
        "Google and Mozilla on Tuesday announced fresh Chrome and Firefox updates that address over 100 vulnerabilities. The latest Chrome release was rolled out with fixes for 32 security defects, including a critical-severity buffer overflow issue in ANGLE tracked as CVE-2026-102331 and reported by an external researcher. Google addressed 25 high-severity security weaknesses, most of which are uninitialized resource and use-after-free vulnerabilities. It also resolved five high-severity type confusion flaws in the V8 JavaScript and WebAssembly engine."
        https://www.securityweek.com/chrome-firefox-updates-patch-over-100-vulnerabilities/
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-76504 Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog
      • OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
        "A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way through being sent. The flaw, tracked as CVE-2026-84782, is fixed in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8. Fixed versions for the older 3.0, 1.1.1 and 1.0.2 branches go only to customers who pay for OpenSSL's premium support. OpenSSL 3.0 stopped getting public security fixes on September 7."
        https://thehackernews.com/2026/09/openssl-fixes-high-severity-dtls-flaw.html
        https://www.securityweek.com/high-severity-vulnerabilities-patched-in-openssl-wolfssl/

      Malware

      • Beware Of Malware Infection In Facebook Ads Offering Cryptocurrency Rewards
        "Just because it’s a familiar tactic doesn’t mean you can let your guard down. A similar attack method using cryptocurrency rewards as bait has recently been identified again. This time, a case was confirmed in which the Node.Js-based malware JSCEAL was distributed through Facebook ads impersonating a cryptocurrency exchange. The threat actors lured users to a site designed to resemble a real exchange, then sent different installation files depending on the operating system to execute the malware. Over the past two months, JSCEAL infections have been confirmed on approximately 1,500 PCs in Korea, with both Windows and macOS systems included as Attack Targets. Let’s take a look at how JSCEAL deceives users, from the moment they click an ad to the malware code execution."
        https://asec.ahnlab.com/en/95645/
      • Beware Of SMS Messages Claiming To Protect Your Pi Coin Account—phishing Sites Are Stealing Wallets
        "One day, out of the blue, I received a text message claiming to protect my cryptocurrency account. However, this message concealed a sinister intent: to steal the user’s wallet information. Recently, a smishing campaign was identified that impersonated Pi Coin account protection to lure users to phishing pages and steal their cryptocurrency wallet information. The threat actors present a screen designed to look like the actual Pi Network service and trick users into directly entering the confidential information needed to recover their wallets. Since this tactic has been consistently observed in various regions—including the US, Europe, India, and Vietnam—users in Korea cannot afford to let their guard down. Let’s take a closer look at the Pi Coin smishing scheme hidden behind the phrase “account protection.”"
        https://asec.ahnlab.com/en/95646/
      • SilverFox: Tracking The Distribution Of a Domestic Variant Of a Malicious Installation File Posing As KakaoTalk
        "The threat actor used SEO poisoning (a technique that exploits search results to redirect users to fake sites) to distribute a malicious installer disguised as a KakaoTalk installer. The appearance and packaging method of the installer changed continuously, and the threat actor sequentially used NSIS, Advanced Installer, and Inno Setup. It contained both legitimate installation files and malicious files. When a user ran the disguised installation file, shellcode (code loaded into memory and executed) was triggered, and the malicious payload was executed."
        https://asec.ahnlab.com/en/95642/
      • China-Nexus UAT-11587 Targets Government And Policy Organizations Across Asia With Antino Backdoor
        "Talos first identified UAT-11587’s campaign while investigating a spear-phishing campaign directed at Taiwan's academic, think tank, and civil society policy community in March 2026. The message recreated Gmail's attachment interface and directed the target into a cloud-hosted, multi-stage infection chain. Across this activity, our researchers assessed that the actor used several delivery methods, loader families, and post-compromise tools. One recurring final-stage payload was a custom Rust backdoor that Talos tracks as Antino. Antino communicates with Microsoft 365 applications and uses Outlook and OneDrive objects as dead drops, rather than depending on a conspicuous dedicated command server."
        https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/
      • Disrupting a Coordinated Model-Distillation Campaign
        "We recently identified and disrupted a coordinated campaign designed to extract protected reasoning from our models, with the earliest observed activity occurring in the first week of July. This activity is consistent with adversarial distillation: the systematic and unauthorized use of one model’s outputs or reasoning to help train, reproduce, or improve another model. Protected reasoning is the model’s internal record for working through a task; extracting it can reveal information withheld from the final answer and help others reproduce the model’s capabilities."
        https://openai.com/index/disrupting-a-coordinated-model-distillation-campaign/
        https://cyberscoop.com/openai-moonshot-ai-model-distillation-attack/
      • 2CLoader: A New Malware Loader Delivering Vidar And Remus
        "In August 2026, Zscaler ThreatLabz identified a new loader, which we track as 2CLoader. ThreatLabz has observed the loader being used to distribute information stealers including Vidar and Remus in addition to XWorm RAT. 2CLoader has the ability to perform a wide range of anti-analysis and evasion techniques, including indirect system calls, anti-analysis checks, and installing Windows API hooks. In this blog post, ThreatLabz provides a technical deep dive into 2CLoader, covering its core features, evasion techniques, loader configuration, network communication, payload decryption, and execution options."
        https://www.zscaler.com/blogs/security-research/2cloader-new-malware-loader-delivering-vidar-and-remus
      • Unauthenticated Command Injection On Internet-Facing Mail Servers: Tracking CVE-2026-73570
        "Microsoft Threat Intelligence identified and tracked exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability in the Zimbra Collaboration Suite SNMP notification path. Exploitation can be triggered by a specially crafted email against internet-facing Zimbra servers when the optional zimbra-snmp package is installed and SNMP notifications are enabled, without requiring authentication or user interaction."
        https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/
        https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html
      • Phishing Abuses RMM Tools For Persistent Access
        "In July 2026, Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed a masqueraded MSP360 Remote Monitoring and Management (RMM) installer through meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected devices and enabled threat actors to gain an initial foothold using trusted administrative software."
        https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/
        https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html
      • US-Focused CSuite Phishing Steals Microsoft 365 Sessions And Deploys RMM Tools For Remote Access
        "ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud, and persistent access to business systems."
        https://thehackernews.com/2026/09/us-focused-csuite-phishing-steals.html
      • Mobile Malware Warning From Ukrainian Researchers Includes iPhone Exploit Kit
        "Russian hackers are increasingly targeting the smartphones of Ukrainian military personnel and government officials for espionage and financially motivated attacks, according to a Ukrainian government report published this week. The hackers are going after both Android and iOS devices using malicious apps and sophisticated exploits, according to Ukraine’s State Service of Special Communications and Information Protection (SSSCIP)."
        https://therecord.media/ukraine-ssscip-mobile-malware-warning-ios-android
      • MALFEX - A Malicious Npm Postinstall No Advisory Has Caught For Fourteen Months
        "Between August 2023 and September 2026, a single operator publishing under Portuguese-language accounts uploaded at least twelve packages to npm and one payload repository to GitHub. Five packages carry MAL- advisories, three are malicious but unadvised, and four are benign tools the operator ships as cover. The three packages without advisories are the only active threats defenders can target today: function-flag (continuously malicious since 18 July 2025), cdn-img-fetch (still installable after npm seized its parent package, img-to-native), and function-color (a wrapper that pulls function-flag in as a dependency)."
        https://www.cloudsek.com/blog/malfex-malicious-npm-postinstall-supply-chain-campaign
      • AI-Assisted Attacks Still Leave a Behavioral Trace
        "AI is increasingly being used to accelerate cyber-attacks, but attackers still leave detectable behavioral traces. This blog explores how Darktrace identified suspicious file delivery, command-and-control communications, beaconing activity, and other anomalies linked to AI-assisted campaigns through behavioral analysis."
        https://www.darktrace.com/blog/ai-assisted-attacks-still-leave-a-behavioral-trace
      • TerminalFix And Lorem Ipsum Loader Enable Covert Tunneling
        "In August 2026, Sophos analysts began investigating a series of Managed Detection and Response (MDR) cases that involved ClickFix-style lures and resulted in the deployment of a Python-based tunneling implant. Instead of a typical ClickFix lure that instructs victims to open the Run dialog box, these lures direct users to open a Windows Terminal window. This ClickFix variation is known as ‘TerminalFix’. TerminalFix is not linked to a specific threat group or a single campaign. In 2026, Sophos analysts have observed several malicious campaigns that incorporated these lures (see Figure 1) and resulted in multiple infection chains."
        https://www.sophos.com/en-us/blog/terminalfix-and-lorem-ipsum-loader-enable-covert-tunneling

      Breaches/Hacks/Leaks

      • DIVD Says Zammad Zero-Days Enabled AI-Driven Network Breach
        "The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. Previously, the nonprofit organization of volunteer security researchers said the attack was “loud and very, very messy,” driven by an AI agent that moved autonomously and decided its next steps without external intervention or direction. DIVD retrieved extensive details about the attack because the AI agent left behind clear explanations of its decisions, allowing the organization to reconstruct the incident."
        https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/
      • GitHub Repos Exposed 543,699 Credentials. Nobody Revoked Them.
        "We scanned 224 million public GitHub repositories, a snapshot of public code assembled to train AI models (The Stack v3), and found 543,699 unique credentials that still authenticated when we tested them in July 2026. The median one had been sitting in a public default branch for 784 days. The oldest was committed in 2009 and still works. Just under 200,000 of them were pushed after GitHub turned push protection on by default. The block does work where it applies, roughly halving the rate at which the credentials it recognises reach public code, but 51.8 percent of what is still live is a shape it does not recognise, and nothing about it helps the half million already there."
        https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them
        https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/
      • Bitget Hacked Via Zero-Day In Third-Party Security Products
        "Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. According to Bitget, two separate investigations by blockchain security firm SlowMist and Google Cloud's cyber-defense arm Mandiant said the threat actors accessed Bitget's wallet environment after compromising two security appliances with zero-day exploits."
        https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/
      • South Africa Seeks Help After Cyberattack Targets Air Traffic Control
        "The South African state-owned company that provides air traffic control (ATC) and weather operations for approximately 10% of the world's airspace discovered ransomware-linked malware in an operational technology (OT) network, according to public documents released this month. The company, Air Traffic and Navigation Services (ATNS), believes that its technical team stopped the attack, but it issued a request for quotes (RFQ) seeking cyber-forensics firms to investigate the incident. A second attack, possibly an insider's theft of data, is also part of the investigation request."
        https://www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control
      • PixelLeak: How AI Agents Exposed Developer Screenshots From Leading Tech Companies
        "Every day, developers hand the last mile of their work to an AI coding agent: summarize your changes, attach screenshots showing the changes, then submit them for review. It’s common sense that screenshots of internal, unreleased development work should not be posted where anyone can see them. But many AI agents have been doing just that. Glow Labs has identified over 13,000 internal images published openly on GitHub by developers at over 300 organizations, including one of the world's largest tech companies, a frontier AI lab, a major enterprise software provider, and a Fortune 500 travel company. In this post we share how AI agents quietly leaked thousands of pre-release screenshots, why no security team caught it, and how to check if you're affected."
        https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies
        https://thehackernews.com/2026/09/ai-coding-agents-exposed-13000-internal.html
        https://www.helpnetsecurity.com/2026/09/30/ai-coding-agents-github-screenshot-leak/
      • OpenInfra Europe’s JFrog Artifactory Instance Breached, Packages Potentially Compromised
        "Attackers have compromised a self-hosted JFrog Artifactory instance operated by OpenInfra Europe, the regional hub of the OpenInfra Foundation warned in a security notice prominently displayed on its homepage. “Anyone who downloaded or installed artifacts from https://artifactory.nordix.org/ from August 28 and September 15, 2026 should immediately stop using them, remove them from their pipelines, and treat these packages as potentially compromised,” the message says."
        https://www.helpnetsecurity.com/2026/09/30/openinfra-jfrog-artifactory-instance-compromised/

      General News

      • August 2026 Threat Trend Report On APT Attacks (South Korea)
        "AhnLab monitored APT (Advanced Persistent Threat) attacks targeting entities in Korea using its own infrastructure. This report summarizes the types and statistics on domestic APT attacks identified during the month of August 2026."
        https://asec.ahnlab.com/en/95649/
      • Vulnerability Discovery And Exploitation Trends In The AI Era
        "Google Threat Intelligence Group (GTIG) examines vulnerability disclosure and exploitation statistics to evaluate the impact of artificial intelligence (AI) on the vulnerability threat landscape. We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered."
        https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era
        https://therecord.media/google-vulnerabilities-cyberattacks-ai
        https://www.bankinfosecurity.com/google-ai-finding-more-medium-risk-flaws-a-32979
        https://www.infosecurity-magazine.com/news/ai-found-vulnerabilities-rce/
        https://www.securityweek.com/google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery/
      • EU Cyber Resilience Act Requirements For Containers And Kubernetes
        "Starting in full force on Dec. 10, 2024, the EU Cyber Resilience Act (CRA) is a regulation (EU 2024/2847) that defines mandatory cybersecurity requirements for all products with digital elements sold in EU markets. Reporting obligations will begin on Sept. 11, 2026, with full enforcement kicking in on Dec. 11, 2027. The CRA brings new requirements for teams working with containers and Kubernetes regarding how cloud native applications are built, distributed, and maintained throughout their lifecycle."
        https://www.helpnetsecurity.com/2026/09/30/rapidfort-cra-container-compliance/
      • Most Open Critical And High Flaws Are Over 90 Days Old
        "Detectify analyzed exposure data from 1,293 of its customers in the US, the UK and the Nordics and found that most serious flaws still open on their internet-facing systems are months old. Of the critical and high-severity vulnerabilities open at the time of the snapshot, 97% in the Nordics had been exposed for more than 90 days, along with 92% in the UK and 86% in the US. The organizations already know about these flaws. Detectify says it confirms findings with payload-based testing, which sends a working attack request and checks the response, so the backlog consists of issues its scanner judged exploitable. In the best-performing market, fewer than one in seven open critical or high findings is less than three months old."
        https://www.helpnetsecurity.com/2026/09/30/research-unpatched-vulnerabilities-backlog/
      • Most Organizations Need Six Months Or Longer To Roll Out New Security Controls
        "Cisco surveyed 8,000 security professionals in 30 markets about how well their organizations defend against AI-era threats, and only 8% landed in the top group. Cisco gave the most weight in its scoring to internal friction, meaning the delays and turf problems inside a company that slow a security team when something changes. Cisco says frontier AI models can find software vulnerabilities at a scale and speed no human team working alone can match. Fewer than one in ten respondents are confident they can stay ahead of the flood of new threats. Their answers put the slowdown inside the company: procurement delays, infrastructure decisions that IT owns, and priorities the C-suite sets elsewhere. Cisco says teams have the tools, and the drag comes from how the organization runs."
        https://www.helpnetsecurity.com/2026/09/30/relentless-defense-cisco-cybersecurity-survey/
      • Your Car’s App Could Be Telling Big Tech Who You Are And Where You Go
        "A study testing 21 cars from 19 brands and 30 companion apps found connections to advertising and tracking companies, and evidence that some apps shared sensitive personal data. Modern cars can unlock remotely, route around traffic, stream entertainment, summon roadside help, and cool or heat the cabin before you get in. But those conveniences come with a privacy cost that drivers may struggle to see and are unable to refuse. We’ve covered cars and privacy a few times before, especially after Mozilla researchers described cars as a “privacy nightmare.”"
        https://www.malwarebytes.com/blog/news/2026/09/your-cars-app-could-be-telling-big-tech-who-you-are-and-where-you-go
        https://therecord.media/automakers-routinely-share-connected-car-data-third-parties
      • Ransomware Leverage Is Growing By The Terabyte: Takeaways From ThreatLabz 2026 Ransomware Report
        "Ransomware is no longer defined only by how many organizations get hit. The most important shifts are happening beneath the headline victim counts; in how attackers gain access, who they target first, and how much data they steal once they’re in. The newly released Zscaler ThreatLabz 2026 Ransomware Report examines ransomware activity from April 2025 through March 2026, with a focus on groups and affiliates, victim targeting, attack techniques, data theft, and payment patterns."
        https://www.zscaler.com/blogs/security-research/ransomware-leverage-growing-terabyte-takeaways-threatlabz-2026-ransomware
      • EvilTokens Takedown Shows Why Cybercrime Platforms Are Getting Harder To Stop
        "Microsoft’s disruption of the EvilTokens phishing-as-a-service platform highlights a growing challenge for defenders: Cybercrime infrastructure may be getting easier to rebuild than it is to dismantle. AI-assisted development, inexpensive infrastructure, and increasingly decentralized services are enabling criminal groups to recover quickly when individual platforms are taken offline."
        https://blog.barracuda.com/2026/09/30/eviltokens-takedown-cybercrime-platforms-harder-to-stop
      • Know Your Enemy: Browser-Based Attack Techniques In 2026
        "Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most dangerous techniques that should be on every security team's radar in 2026."
        https://thehackernews.com/2026/09/know-your-enemy-browser-based-attack.html
      • More Than Half Of UK Businesses Lack Confidence In Basic Cyber Skills
        "More than half of UK businesses lack confidence in their ability to perform at least one basic cybersecurity task, according to the government's latest skills survey. The annual research found 57 percent of businesses reported a basic technical skills gap, up from 49 percent last year despite tighter national standards and repeated government warnings about cyber resilience."
        https://www.theregister.com/security/2026/09/30/more-than-half-of-uk-businesses-lack-confidence-in-basic-cyber-skills/5299991

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) c8bc407b-2488-4787-9004-7305c576d79b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบมัลแวร์ SC บน WordPress ฝังตัวหลายตำแหน่งและกู้คืน Backdoor หลังถูกลบ

      พบมัลแวร์ SC บน WordPress ฝังตัวหลายตำแหน่งและกู้.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5947d358-87db-4418-a7b8-7ca731b94b3e-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • WatchGuard ออกแพตช์แก้ช่องโหว่ Critical ใน Fireware OS เสี่ยงถูกสั่งดำเนินการคำสั่งด้วยสิทธิ์ Root

      WatchGuard ออกแพตช์แก้ช่องโหว่ Critical ใน Fireware OS เสี่ยงถ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 830a225e-91c0-4a41-943d-31d358dce779-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการใช้ช่องโหว่ Zimbra (CVE-2026-73570) เพื่อติดตั้ง Web Shell และขโมยข้อมูลสำคัญ

      พบการใช้ช่องโหว่ Zimbra (CVE-2026-73570) เพื่อติดตั้ง Web Shell.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5cac0302-7e71-4f28-a6c3-0cabc617d98f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ใน TeamViewer Full Client และ Host เสี่ยงถูกรันคำสั่งและยกระดับสิทธิ์

      ช่องโหว่ใน TeamViewer Full Client และ Host เสี่ยงถูกรันคำสั.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 47197471-7679-4a2b-9190-4d62859700b9-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ANSSI เผยเหตุขโมยข้อมูลภาษี ใช้ Password เจ้าหน้าที่ที่ถูกขโมย เข้าถึงข้อมูลนาน 7 สัปดาห์โดยไม่ถูกตรวจพบ

      ANSSI เผยเหตุขโมยข้อมูลภาษี ใช้ Password เจ้าหน้าที.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand f2cfffbc-dac2-44be-a1b4-2e89e31172b4-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • นักวิจัยพบ AI ที่ใช้สรุปอีเมล ถูกหลอกให้บิดเบือนข้อมูลได้ด้วยการแทรกข้อความปลอม

      นักวิจัยพบ AI ที่ใช้สรุปอีเมล ถูกหลอกให้บิด.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 631eb31b-81be-4f14-ab48-3a3b9cec77cf-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบช่องโหว่ CoreGraphics ในอุปกรณ์ Apple เสี่ยงถูกใช้รันคำสั่งบนอุปกรณ์

      พบช่องโหว่ CoreGraphics ในอุปกรณ์ Apple เสี่ยงถูกใช้ร.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 598eb855-8bcc-4a57-8eef-c170cdf84673-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Infostealer มุ่งเป้าบัญชี AI องค์กร เสี่ยงเปิดเผย Session, API Key และข้อมูลสำคัญ

      Infostealer มุ่งเป้าบัญชี AI องค์กร เสี่ยงเปิดเผย Sessi.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 3f2cb96a-1bc2-4a0d-ac00-f201ce6b3410-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT