NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,462
    • กระทู้ 2,463
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    NCSA_THAICERT

    @NCSA_THAICERT

    1
    ชื่อเสียง
    56
    ดูข้อมูลส่วนตัว
    2.5k
    กระทู้
    3
    คนติดตาม
    0
    ติดตาม
    เข้าร่วม ออนไลน์ล่าสุด
    เว็บไซต์ www.ncsa.or.th/?fbclid=IwAR0BqJEC-CJzBs98rlBxUbZkNBgp1g814xdDNNaKnHTrxfqZhPD--ksY68I

    NCSA_THAICERT เลิกติดตาม ติดตาม
    Global Moderator administrators

    Latest posts made by NCSA_THAICERT

    • Cyber Threat Intelligence 12 August 2026

      Healthcare Sector

      • Mira Hormone Monitor, Mira Android App
        "Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts."
        https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-01
      • Pulsetto Vagus Nerve Stimulator
        "Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings."
        https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-02

      Industrial Sector

      • Industrial Ransomware Analysis For Q2 2026
        "In the second quarter (Q2) of 2026, analysis of publicly disclosed victim data and ransomware groups’ postings on Data Leak Sites (DLS) identified 1,140 ransomware incidents affecting industrial organizations worldwide, a 12% increase over the 1,020 incidents recorded in Q1. Ransomware remained the most persistent and disruptive cyber threat to industrial organizations in Q2 2026, sustaining the elevated pace established throughout 2025 and continuing to impact operational environments via the loss of enterprise IT systems, Enterprise Resource Planning (ERP) platforms, and virtualization infrastructure, versus direct manipulation of control systems."
        https://www.dragos.com/blog/dragos-industrial-ransomware-analysis-q2-2026
        https://www.helpnetsecurity.com/2026/08/11/industrial-ransomware-attacks-q2-2026/

      Telecom Sector

      • An AI Tool Found 84 Flaws In 5G Network Software And 23 Of Them Still Have No Fix
        "Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws nobody had reported before. Developers have confirmed 83 of them, and 81 now carry CVE numbers. The most serious one lets an attacker take over a subscriber’s data session, so the network delivers that subscriber’s traffic to
        https://www.helpnetsecurity.com/2026/08/11/5g-core-network-vulnerabilities-research/
        https://arxiv.org/pdf/2607.10315
      • Researchers Show How Malicious SIM Cards Can Hijack Smartphones, EV Chargers And Connected Devices
        "Subscriber Identity Modules (SIMs), the secure element used to connect devices to a mobile network, can pose severe security risks when compromised. A malicious SIM could allow attackers to gather information about a device, interfere with its connectivity, and serve as an entry point for further cyberattacks. Presenting their findings at the 2026 USENIX WOOT Conference on Offensive Technologies, in Baltimore, University of Birmingham researchers reveal a new attack surface exposed to malicious and compromised SIMs."
        https://www.birmingham.ac.uk/news/2026/researchers-show-how-malicious-sim-cards-can-hijack-smartphones-ev-chargers-and-connected-devices
        https://www.usenix.org/system/files/woot26-lisowski.pdf
        https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html
        https://www.helpnetsecurity.com/2026/08/11/malicious-sim-cards-hijack-phones-ev-chargers/

      Vulnerabilities

      • Adobe Urges Immediate Patching Of Critical ColdFusion, Campaign Classic Flaws
        "Adobe on Tuesday rolled out patches for over 50 vulnerabilities across its products, including critical-severity bugs in ColdFusion, Campaign Classic, and Commerce. With a priority 1 rating, the ColdFusion update fixes 15 security defects, including three flagged as critical that could lead to arbitrary code execution and application denial-of-service (DoS). These include an OS command injection tracked as CVE-2026-48362 (CVSS score of 10/10), an eval injection tracked as CVE-2026-48273 (CVSS score of 9.9/10), and an incorrect authorization tracked as CVE-2026-71384 (CVSS score of 9.6/10)."
        https://www.securityweek.com/adobe-urges-immediate-patching-of-critical-coldfusion-campaign-classic-flaws/
      • SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
        "Enterprise software maker SAP on Tuesday announced the release of 28 new security notes, two updates to previous notes, and a GitHub advisory. Four of the notes published on SAP’s August 2026 Security Patch Day resolve critical vulnerabilities, the most severe of which is CVE-2026-58231 (CVSS score of 10/10), an improper authorization issue in SAP Commerce Cloud (Data Hub Adapter). The bug could allow remote attackers to bypass authentication, likely leading to code execution and unauthorized access to internal components. Successful exploitation would impact the confidentiality, integrity, and availability of the application."
        https://www.securityweek.com/sap-patches-critical-code-injection-memory-corruption-vulnerabilities/
      • Cisco Warns Of ASA And FTD VPN Flaw Exploited To Crash Devices
        "Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices. The flaw, tracked as CVE-2026-20349, has a severity score of 8.6 and impacts devices running Cisco Secure Firewall Adaptive Security Appliance (ASA) or Secure Firewall Threat Defense (FTD) software with certain remote access services enabled. In a security advisory published today, Cisco said the vulnerability is caused by insufficient error checking while processing HTTP requests."
        https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-and-ftd-vpn-flaw-exploited-to-crash-devices/
        https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF
      • Microsoft August 2026 Patch Tuesday Fixes 400 Flaws, 3 Zero-Days
        "Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. Patch Tuesday addresses 42 "Critical" vulnerabilities, 37 of which are remote code execution and 5 are elevation of privilege."
        https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days/
        https://blog.talosintelligence.com/microsoft-patch-tuesday-for-august-2026/
        https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html
        https://www.darkreading.com/application-security/microsofts-patch-tuesday-deluge-continues
        https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day/
      • ZOOMSDAY
        "A critical vulnerability in Zoom, a platform used by 70% of the Fortune 100, discovered by publicly available frontier models, allows an attacker participating in a meeting a zero-click remote code execution on all meeting participants across all native clients. This research emphasizes the risk of weaponized AI and how vulnerable we are as an industry."
        https://a.security/blog/asecurity-zoomsday
        https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html
        https://www.securityweek.com/zoom-patches-zero-click-code-execution-vulnerability/
        https://securityaffairs.com/197042/hacking/zoom-patches-zoomsday-zero-click-flaw-enabling-remote-code-execution.html
      • CISA Adds Three Known Exploited Vulnerabilities To Catalog
        "CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability
        CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
        CVE-2026-72898 Metabase SQL Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog
      • CISA: Microsoft SharePoint Flaw Now Exploited In Ransomware Attacks
        "CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. Tracked as CVE-2026-45659, this security flaw stems from a deserialization of untrusted data weakness and allows attackers with low privileges to execute arbitrary code on unpatched SharePoint servers. It can also be exploited in low-complexity attacks because (as Microsoft explained in May when it released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition) "an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.""
        https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/
        https://thehackernews.com/2026/08/researchers-disclose-ai-assisted.html
      • Cursor Security Bug Allowed Repositories To Execute Commands Before Trust Verification
        "A flaw in Cursor's command-line coding agent has been found to allow a cloned repository to run any command it chose on a developer's machine before they were asked whether they trusted it, and outside the sandbox even when the sandbox had been explicitly switched on. Manifold Security said it reported the issue to Cursor on July 20 and published its findings on August 10. Cursor shipped a fix for the pre-trust behavior three days after the report, then closed the submission as informative, meaning no security impact, and published no advisory. Francisco Rosales, offensive security engineer at Manifold, found the issue in the agent's isolated worktree feature, which exists to keep an AI agent away from a developer's working tree."
        https://www.infosecurity-magazine.com/news/cursor-security-bug-command/
      • Malicious MCP Servers Can Split Instructions To Make AI Coding Agents Exfiltrate Secrets
        "A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place them in channels the assistant already uses, and let the agent stitch them together and send the data back. The attack targets coding tools that connect to outside servers over the Model Context Protocol (MCP), the open standard that lets AI assistants call external tools."
        https://thehackernews.com/2026/08/malicious-mcp-servers-can-split.html
        https://github.com/asset-group/ghostsplice

      Malware

      • Fake Popular Sites Offer a Free App, Instead Take Over PCs
        "A website built to look almost exactly like CNN’s homepage is telling visitors to download “the new CNN app.” But it’s not CNN’s app, and has nothing to do with the news company. The campaign doesn’t stop at CNN. It also uses fake Stremio and Avast installers hosted on similarly convincing lookalike sites, all targeting Windows users. The installers are part of the same campaign to trick people into installing legitimate remote-management software that’s already linked to the attacker’s account."
        https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-popular-sites-offer-a-free-app-instead-take-over-pcs
      • DeadLock Ransomware: Breaking Down a Rust-Based Encryptor With Decentralized Recovery Infrastructure
        "Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations. Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process. This architecture likely increases the resilience of portions of its communication, leak-hosting, and negotiation infrastructure, allowing DeadLock operators to recover from some disruption efforts while maintaining continuity for victims. Microsoft has observed DeadLock ransomware being deployed by multiple groups including an affiliate of the Lynx and INC ransomware ecosystems."
        https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/
        https://www.bleepingcomputer.com/news/security/deadlock-ransomware-uses-blockchain-to-resist-infrastructure-takedown/
        https://thehackernews.com/2026/08/deadlock-ransomware-uses-polygon-smart.html
      • Delta Probes Wi-Fi Deauth Attack On Flight Carrying DEF CON Attendees
        "Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention. ​The company told BleepingComputer that the incident occurred yesterday on Flight 591 and did not affect the safety of the passengers or aircraft operating systems. “We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated,” a company spokesperson said."
        https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-on-flight-carrying-def-con-attendees/
        https://cyberscoop.com/delta-flight-rogue-wifi-investigation-def-con-las-vegas/
      • State Sponsored Hackers Use Fake Job Offers To Deliver New Zero Day Exploit
        "It typically begins the same way it has for years, with an approach from a recruiter offering a role at a company the target would recognize, accompanied by a PDF describing the position in convincing detail. That approach remains one of the most effective entry points used by state sponsored threat actors today, and Check Point Research has spent recent months tracking a new wave of it. Operation Dream Job, the long running campaign attributed to the North Korea affiliated Lazarus group, has resurfaced with a previously undisclosed Windows vulnerability (CVE-2026-68820), a newly identified backdoor, and a command and control architecture built almost entirely on infrastructure the group does not own."
        https://blog.checkpoint.com/research/state-sponsored-hackers-use-fake-job-offers-to-deliver-new-zero-day-exploit/
        https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
      • Six Npm Packages Use Ethereum Transactions To Retrieve Malicious Payloads
        "On August 10, 2026, Sonatype Research Labs identified six npm packages containing the same malicious payload, including three compromised legitimate packages and three packages published with the malware already present. The payload uses Ethereum blockchain transactions to locate infrastructure hosting additional JavaScript malware. Sonatype researchers confirmed the six packages use the same Ethereum wallet address in recent activity attributed to the DPRK-linked Contagious Interview campaign. OpenSourceMalware dubbed the specific blockchain-based command-and-control technique "NullReceiver," while Contagious Interview refers to the broader campaign associated with the Lazarus APT group."
        https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-payloads
        https://www.infosecurity-magazine.com/news/npm-packages-ethereum-wallet-c2/
      • Fake CCleaner Installs GhostDesk Chrome Spyware
        "A fake version of the popular PC cleaning tool CCleaner is being used to infect Windows users with a malicious Chrome extension called GhostDesk, which acts as spyware inside the browser. With more than 2 billion downloads worldwide, CCleaner is one of the best-known Windows utilities, making it an attractive target for cybercriminals looking to distribute malware. The attack starts with a website that is a convincing imitation of the CCleaner download page. Once installed, the fake application launches an attack that modifies Chrome, installs malicious extension components, and gives attackers the ability to steal credentials, capture screenshots, and log keystrokes."
        https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
      • Kimwolf v7: An Evolution Of The Kimwolf Botnet
        "We identified a new version (v7) of the Kimwolf Android/internet-of-things (IoT) botnet. This version upgrades its distributed denial-of-service (DDoS) attack capabilities and the resilience of its command-and-control (C2) infrastructure. Kimwolf primarily affects Android TV boxes and set-top boxes. Kimwolf v7 adds an HTTP/2-based DDoS flood that constructs complete browser fingerprints. This makes attack traffic more difficult to distinguish from legitimate browsing. The threat’s binary includes five hard-coded public Ethereum-based endpoints for resolving Ethereum Name Service (ENS) domains. ENS is a blockchain-based naming system used to obtain C2 addresses."
        https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
        https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html
        https://cyberscoop.com/kimwolf-botnet-palo-alto-unit-42-android-tv-boxes/
      • Project CAV3RN Continues: Google Apps Script As C2 Relay And DNS-Based C2 Channel Selection
        "Project CAV3RN is a modular espionage framework used against targets in Israel. This report expands on two earlier publications: the first was published in June 2026 as part of our Kaspersky Threat Intelligence Reporting service, and the second was published on Securelist the following month, further documenting the framework’s evolving architecture and C2 capabilities. Continued tracking of this cluster in early August 2026 uncovered several previously undocumented components that expanded the framework’s communication and orchestration capabilities. The main finding is a complex C2 module that uses DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay for each transaction. The same DNS infrastructure can validate and replace the relay deployment ID, allowing the operator to rotate the Google channel."
        https://securelist.com/project-cav3rn-continues/120991/
      • ExfilSquad Targets New Victims, Shares Data Via Torrents
        "ExfilSquad is an emerging cybercriminal hacking group identified in mid-2026 as responsible for high-profile data breaches. Notably, the group does not typically deploy ransomware or destructive malware; instead, they threaten to leak stolen data on a dedicated onion-based Data Leak Site (DLS) unless a ransom is paid. ExfilSquad announced new victims this week and set a firm deadline - August 5, 2026 - to complete all required negotiations. Otherwise, the stolen data will be released. This time, the list of victims includes 13 organizations from the U.S., the UK, and Sweden. Notably, in July, the group was also targeting a major financial institution in Nigeria."
        https://www.resecurity.com/blog/article/exfilsquad-targets-new-victims-shares-data-via-torrents
        https://securityaffairs.com/197025/security/exfilsquad-targets-new-victims-shares-data-via-torrents.html
      • AI Sidebar Extension Monetizes Its Own Updates
        "The Chrome extension “AI Sidebar with DeepSeek AI” that Google removed from the Chrome Web Store in January 2026 for stealing AI conversation content resumed shipping code to enterprise endpoints in July 2026. The extension released a benign update removing the data theft code and acknowledged its wrongdoing. After 2 weeks it pulled the rug again with a new update. Netskope Threat Labs analyzed the new build. While it no longer contains the conversation-exfiltration code, it now contains a monetization payload that opens an affiliate link in a foreground browser tab every single time the extension updates and uninstalls. Additionally, it suppresses the redirection of DeepSeek users to ChatGPT."
        https://www.netskope.com/blog/ai-sidebar-extension-monetizes-its-own-updates
        https://www.securityweek.com/extension-banned-for-stealing-ai-chats-returns-to-chrome-store-resumes-malicious-activities/
      • Phantom Project: A Cybercrime Toolkit Bundle
        "Phantom Project is a commercial cybercrime toolkit that bundles a stealer, a crypter and a remote access tool (RAT). It follows the standard Malware-as-a-Service (MaaS) model with tiered subscriptions for basic and advanced access. Researchers have observed the toolkit in Russian- and English-language phishing campaigns targeting users in more than 100 countries. Phantom Project activity was first observed in June 2025, though researchers found its distribution site had been registered in February of that year. Phantom Project activity accelerated through the second half of 2025, with multiple independent research teams documenting separate global campaigns within the same several-month window."
        https://blog.barracuda.com/2026/08/10/phantom-project--a-cybercrime-toolkit-bundle-
      • Researchers Built a Fake Crypto Startup And Hired Three Suspected North Korean IT Workers
        "Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording. The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver's license and a New York bank account. The researchers said the image metadata showed it had been processed with Google Gemini. They also reported a SynthID watermark, the invisible marker Google embeds in images its AI tools create or edit."
        https://thehackernews.com/2026/08/researchers-built-fake-crypto-startup.html
      • Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover On Windows 11
        "Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that redirection is not allowed by default. Security researchers Alejandro Hernando and Borja Martinez described the technique in "Plug And Pwn: Weaponizing Windows PnP Auto-Install," research prepared for DEF CON 34."
        https://thehackernews.com/2026/08/researchers-turn-usb-auto-install-into.html
        https://plugandpwn.com/
      • The Multi-Layered Defenses That Harden Chrome Against Abusive Notifications
        "Push notifications are a longstanding part of the open web, allowing developers to engage with users in real-time. However, bad actors have increasingly abused this system, bombarding people with deceptive and unwanted notifications. To combat this, Chrome Security has been on a multi-year journey, in collaboration with Firebase Cloud Messaging (FCM) and Safe Browsing, to significantly reduce notification abuse and improve the security and quality of the web ecosystem for everyone. After achieving a significant reduction in unwanted notification volume, reducing notifications on Android by over 7 billion a day in Q1 alone, today we’re pulling back the curtain on the multi-layered toolkit that secured this critical feature for billions of users."
        https://blog.google/security/the-multi-layered-defenses-that-harden-chrome-against-abusive-notifications/
        https://www.bleepingcomputer.com/news/security/google-says-chrome-cuts-7-billion-unwanted-android-notifications-a-day-to-fight-abuse/

      Breaches/Hacks/Leaks

      • Mozilla Issues New Firefox GPG Key Following Exposure
        "Mozilla announced on Monday that it has issued a new GPG signing subkey used for some Firefox and Thunderbird artifacts after the previous key was accidentally exposed in a GitHub repository. In general, if a GPG private signing key used for software releases is exposed, an attacker who obtains it could create valid signatures on malicious files. This creates a supply chain attack risk: the attacker could distribute modified or malicious versions of the software that appear authentic. Successful exploitation would still require a way to deliver the signed files to users, for instance via a compromised mirror, an alternate download path, or social engineering."
        https://www.securityweek.com/mozilla-issues-new-firefox-gpg-key-following-exposure/
        https://thehackernews.com/2026/08/mozilla-revokes-firefox-and-thunderbird.html
        https://www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/
      • Wesco Confirms Security Incident After ExfilSquad Claims Data Theft
        "Global supply chain and distribution giant Wesco has confirmed in a statement to BleepingComputer that it is investigating a cybersecurity incident. The company's statement comes after data extortion group ExfilSquad claimed to have stolen sensitive information from Wesco and leaked it on their data leak site. Jennifer Sniderman, Vice President of Corporate Communications at Wesco, said that the incident involves the company's cloud CRM environment."
        https://www.bleepingcomputer.com/news/security/wesco-confirms-security-incident-after-exfilsquad-claims-data-theft/
      • Ransomware Group Hijacks Hospital System’s Facebook Page Amid Ongoing Cyberattack Fallout
        "Two weeks after a cyberattack knocked out its IT systems, the nonprofit medical system AnMed is still facing closures and the apparent hack of its Facebook page, which on Tuesday began showing ransom demands from the purported hackers. The social media page for the medical chain, which has four hospitals and other clinics in Georgia and South Carolina, was removed from Facebook shortly after a series of messages claiming to be from “The Gentlemen” ransomware group appeared."
        https://therecord.media/ransomware-group-hijacks-hospital-facebook-amid-cyberattack-response
      • Local Governments In Four States Dealing With Cyberattacks That Have Shut Down Services
        "The 911 system of a city in California was taken down by hackers during a cyberattack on Friday — one of several cyber incidents nationwide impacting government services. Suisun City, a town of 30,000 people in the Bay Area about 30 miles from Napa Valley, said on Friday that malicious software infected and compromised the city’s IT systems. The attack “hit critical public safety operations, including 911 routing, police and fire dispatch, records and City services,” according to a government notice. The city shut down the entire IT network and contacted federal and state officials for assistance. Emergency services are still available and public safety offices are routing calls through the county’s dispatch center."
        https://therecord.media/cyberattacks-ransomware-local-governments
        https://www.infosecurity-magazine.com/news/suisan-cyber-incident-government/

      General News

      • July 2026 Dark Web Breach Incident Trend Report
        "The July 2026 Dark Web Breach Incident Trend Report was compiled based on data breach cases posted on deep web and dark web forums. Due to the nature of some posts, it is difficult to fully verify their accuracy; some posts related to South Korea included AI-generated false data or cases where it could not be definitively determined whether an actual breach had occurred."
        https://asec.ahnlab.com/en/94912/
      • July 2026 Dark Web Threat Actor Trend Report
        "The July 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—active on the deep web and dark web. It is explicitly noted that the factual accuracy of some content could not be verified."
        https://asec.ahnlab.com/en/94917/
      • July 2026 Dark Web Issue Trend Report
        "The July 2026 Dark Web Issue Trend Report summarizes major issues that occurred on the deep web and dark web. Due to the nature of some sources, it may be difficult to fully verify the accuracy of certain information; therefore, it is necessary to cross-check these details against official announcements."
        https://asec.ahnlab.com/en/94918/
      • Who Will Be The Stanislav Petrov In Your Organization?
        "The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved the world. In 1983, the USSR’s early warning systems reported that the United States had launched nuclear missiles towards the Soviet Union. The officer on duty, Stanislav Petrov, did something computers still struggle to do. He applied context, experience, and human judgement to determine the warning was probably false. Thankfully, he was right. Had an automated response been allowed to proceed without meaningful human intervention, the result could have been a full blown nuclear war."
        https://www.helpnetsecurity.com/2026/08/11/governing-autonomous-ai-risks/
      • Cyber Security In Manufacturing
        "Cyber attacks are no longer just an IT issue for manufacturers. They are disrupting production lines, increasing costs and putting customer deliveries at risk. Make UK’s latest report, Cyber Security in Manufacturing, reveals the scale of cyber risk facing UK manufacturers and sets out the practical steps businesses can take to strengthen resilience."
        https://www.makeuk.org/insights/reports/cyber-security-manufacturing
        https://www.infosecurity-magazine.com/news/half-uk-manufacturers-cyber/
      • Cloudflare DDoS Threat Report H1 2026: 1 Tbps Attacks Soar As DNS Floods And Geopolitical Tensions Drive a New Wave
        "Welcome to the 25th edition of Cloudflare's DDoS Threat Report. This is the first half-year edition in the series: rather than publishing separate reports for the first and second quarters of 2026, we have combined our coverage of Q1 and Q2 into a single volume covering January through June 2026. The analysis is produced by Cloudforce One, Cloudflare’s Threat Intelligence organization, providing a comprehensive analysis of the evolving threat landscape of Distributed Denial of Service (DDoS) attacks based on data from the Cloudflare network."
        https://blog.cloudflare.com/ddos-threat-report-2026-h1/
        https://www.bleepingcomputer.com/news/security/ddos-attacks-over-1-tbps-surged-fivefold-in-the-second-quarter/
      • The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It
        "AI governance, once the purview of the legal department, is now knocking on the CEO’s door. But many C-Suite executives are still treating it as something to delay addressing until after AI regulations are set in stone. This can be a shortsighted strategy. Consider that 46% of organizations say AI governance and compliance issues are the reason why their AI underperforms, according to the GrantThornton, 2026 AI Impact Survey Report (PDF). These figures lend credence to why leadership should not wait for AI regulations to settle but should apply governance proactively."
        https://www.securityweek.com/the-ai-governance-gap-is-a-leadership-problem-waiting-wont-close-it/
        https://www.grantthornton.com/content/dam/grantthornton/website/assets/content-page-files/advisory/ai-lp/infographic/ai-impact-survey-2026/pdf/grant-thornton-2026-ai-impact-survey.pdf
      • Hacker Conversations: Marcus Hutchins And The Journey From The Gray Zone To Redemption
        "Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did. Born in Ascot, England, he was working as a cyber threat analyst for an LA-based cybersecurity company in 2017 (aged 22), when he became the world’s hero for finding a kill switch for the particularly virulent and destructive cryptoworm (ransomware spread by a worm) known as WannaCry. The ransomware decryption didn’t work, so there was no way to decrypt files once encrypted (it was effectively a wiper). But the worm worked very well, and more than 200,000 computers were affected in around 150 countries in just a few days."
        https://www.securityweek.com/hacker-conversations-marcus-hutchins/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) a01c4cb2-bba2-4e66-9941-fbc2f5393649-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 3 รายการลงในแคตตาล็อก

      เมื่อวันที่ 11 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability
      • CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
      • CVE-2026-72898 Metabase SQL Injection Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand d613dd33-2931-4f8f-811d-ff9379a3b91f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 3 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 3 รายการ เมื่อวันที่ 11 สิงหาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSMA-26-223-01 Mira Hormone Monitor, Mira Android App
      • ICSMA-26-223-02 Pulsetto Vagus Nerve Stimulator
      • ICSA-26-204-01 Johnson Controls C-CURE 9000 and Victor application server (Update A)

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 0c4215ba-6ab0-47a3-b65e-31db452f2781-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เตือนช่องโหว่ใน Progress Kemp LoadMaster ถูกใช้โจมตีจริง

      CISA เตือนช่องโหว่ใน Progress Kemp LoadMaster ถูกใช้โจมตีจริ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e2cf1732-d364-4a0f-97e0-818c71720b56-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • IEH แจ้งเหตุ Phishing กระทบ Microsoft 365 Mailbox อาจเปิดเผยข้อมูลทางทหารที่อยู่ภายใต้การควบคุมการส่งออก

      IEH แจ้งเหตุ Phishing กระทบ Microsoft 365 Mailbox อาจเปิดเผยข้อม.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 878ad2b4-7abc-483a-bd4e-d99f9d50cfae-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบแพ็กเกจอันตรายบน npm กว่า 800 รายการ แพร่มัลแวร์และขโมยข้อมูลข้ามแพลตฟอร์ม Windows-Mac-Linux

      พบแพ็กเกจอันตรายบน npm กว่า 800 รายการ แพร่มัลแ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 0b98d7bd-afbd-46c9-901c-2baacfd1ca46-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 11 August 2026

      New Tooling

      • Chainloop: Open-Source Evidence Store And Policy Engine For The Software Supply Chain
        "Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable storage, and references each one in a signed in-toto attestation. in-toto is a specification for recording who ran which step of a build, so the record can be checked afterward. Compliance and security teams get a control plane where all of it arrives, already signed, no matter which continuous integration provider produced it."
        https://www.helpnetsecurity.com/2026/08/10/chainloop-open-source-supply-chain-security/
        https://github.com/chainloop-dev/chainloop

      Vulnerabilities

      • Critical Flaws Discovered In Belgian eID Software Used By 2 Million People
        "A security researcher has revealed severe, now-resolved security vulnerabilities in the Connective digital identity system, a browser extension used by over two million users in Belgium. Developed by Nitro Software Belgium, the software is used by eight of Belgium’s ten largest banks and over 60 government agencies to manage digital identity authentication and execute legally binding electronic signatures. James Arnott, security researcher and founder of cybersecurity firm Bay Area Labs, discovered that the software failed to verify which website was attempting to communicate with the user’s computer. Because these checks were missing, any website or embedded online ad could interact directly with the Connective application running on a victim’s machine without their knowledge or permission."
        https://www.securityweek.com/critical-flaws-discovered-in-belgian-eid-software-used-by-2-million-people/
      • PSA: Supply Chain Compromise In BdThemes Ecosystem Via Poisoned API Response
        "The Wordfence Threat Intelligence Team was notified on August 7th, 2026 of a supply chain compromise affecting BdThemes, a WordPress plugin vendor whose plugins are available in the official WordPress plugins directory. Currently, all the affected plugins are temporarily closed pending a full inspection and ongoing investigation by the WordPress Plugins team. Our investigation revealed an insidious supply chain compromise affecting several plugins. Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository. Instead, threat actors poisoned a static remote JSON data stream fetched by an administrative promotional banner component."
        https://www.wordfence.com/blog/2026/08/psa-supply-chain-compromise-in-bdthemes-ecosystem-via-poisoned-api-response/
        https://www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/
        https://www.infosecurity-magazine.com/news/bdthemes-wordpress-poisoned-api/
      • Cisco Warns Of High-Severity ClamAV Vulnerabilities With Public PoC
        "Cisco on Friday warned that its Secure Endpoint Connector products on Windows, macOS, and Linux are affected by seven ClamAV vulnerabilities that could lead to denial-of-service (DoS) conditions, including two with public proof-of-concept (PoC) code. ClamAV (Clam AntiVirus) is an open source, cross-platform malware detection engine that provides a multi-threaded virtual scanner, email filtering, and automatic database updates. The security defects, tracked as CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, were discovered in ClamAV’s parsers for ZIP, GPT, PESpin, PDF, Mach-O, and XAR file formats."
        https://www.securityweek.com/cisco-warns-of-high-severity-clamav-vulnerabilities-with-public-poc/
        https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26
      • Cyber Vulnerability Sweep Picks Up Royal Navy Drones Sending Data To China
        "Cameras aboard Royal Navy drone boats were found phoning home to an IP address in China during a routine cyber vulnerability assessment. The UK Ministry of Defence confirmed the discovery, describing it as "an issue affecting a Kraken Unmanned Surface Vessel sub-system used by the Royal Navy." The Register understands that the data consisted of a "heartbeat" signalling that the camera was online and functioning normally. Even so, an unexpected transmission from military equipment to an IP address in China will rattle nerves. We contacted unmanned surface vessel supplier Kraken for more information, but have yet to receive a reply."
        https://www.theregister.com/edge-and-iot/2026/08/10/cyber-vulnerability-sweep-picks-up-royal-navy-drones-sending-data-to-china/5285430
        https://www.telegraph.co.uk/news/2026/08/09/spy-cameras-on-navy-drones-secretly-sent-data-to-china/

      Malware

      • Solidity Pro's WhiteCobra Chassis: Cloudflare C2 To Telegram Infostealer
        "A Solidity extension called “Solidity Pro” sounds like the kind of tooling every crypto developer installs without thinking. That is exactly why it keeps appearing in malware campaigns. Yeeth Security recently tracked two publishers, helper-beeps and web3devtoolsx, shipping versions of a solidity-pro extension that evolved from a delayed Cloudflare-Worker dropper into a full browser-wallet and credential infostealer. The progression mirrors what public reporting has attributed to the WhiteCobra group, whose leaked “Operation Solidity Pro” playbook described a five-phase campaign targeting VS Code: and Open VSX users."
        https://yeethsecurity.com/blog/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-Telegram
        https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html
      • New StormEncryptor Ransomware Used By Former Medusa Affiliate
        "A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. Microsoft Threat Intelligence is tracking the actor as Storm-1175 and says the recent attacks were likely preceded by exploitation of an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring and management (RMM) tool. Storm-1175 is believed to be a China-based threat actor. It was previously linked to Medusa ransomware, targeting systems via zero-day and n-day flaws in various products, including GoAnywhere MFT, SmarterTools SmarterMail, Microsoft Exchange, Invanti Connect Secure, and JetBrains TeamCity."
        https://www.bleepingcomputer.com/news/security/new-stormencryptor-ransomware-used-by-former-medusa-affiliate/
        https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html
        https://therecord.media/china-hackers-ransomware-microsoft
        https://www.bankinfosecurity.com/china-linked-hackers-exploit-n-able-flaw-in-ransomware-attacks-a-32506
      • CISA: SonicWall SMA1000 Flaws Now Exploited By Ransomware Gangs
        "CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. ​SMA1000 is an enterprise-grade secure remote access gateway used by large corporations, government agencies, and Managed Service Providers (MSSPs) to provide VPN access to internal applications and corporate networks. SonicWall released patches for the two security flaws (tracked as CVE-2026-15409 and CVE-2026-15410) in mid July, when it also warned that threat actors had been exploiting them in zero-day attacks."
        https://www.bleepingcomputer.com/news/security/cisa-sonicwall-sma1000-flaws-now-exploited-by-ransomware-gangs/
      • #StopRansomware: Gunra Ransomware
        "Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. This advisory provides technical details of the activity, as well as tailored detection and mitigation guidance to protect at-risk organizations from Gunra."
        https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
        https://therecord.media/ransomware-south-korea-fbi-gunra
        https://cyberscoop.com/us-south-korea-gunra-ransomware-warning/
      • GhostJacking Attacks: Half Of The Fortune 500 Run These Tools. Getting Blocked By The Firewall Was The Way To Take Over Their AI Agents
        "Half the Fortune 500 run the tools that let us in. It will be presented at DEFCON, the largest hacker conference, where we’ll show how a request their own firewall blocked was the way in. “Ghostjacking” attack vectors introduce the modern agentic kill chain, agent takeover, sandbox escape, and backdoors planted inside the AI agents you already run, from a Claude Agent sandbox escape to hijacking live agents through the very platforms they trust most – Cloudflare, Sentry, Datadog."
        https://tenetsecurity.ai/blog/ghostjacking-attacks-agentic-kill-chain/
        https://www.darkreading.com/cyber-risk/ghostjacking-identity-governance-gaps-ai-agents
        https://www.infosecurity-magazine.com/news/ghostjacking-ai-gents-access/
        https://www.securityweek.com/ghostjacking-attack-uses-poisoned-logs-to-turn-ai-agents-bad/
      • Coruna, DarkSword iOS Exploits Proliferate Globally
        "The advanced iPhone exploit chains Coruna and DarkSword continue to escape nation-state and mercenary containment to enter the hands of more conventional cybercriminals. While nation-state-grade malware will, from time to time, make its way from government use to cybercriminal adoption, it's far more unusual to see whole complex exploit chains — especially those targeting iOS — adopted broadly. Yet that phenomenon, first observed last spring, appears to be shifting into overdrive. iVerify has tracked approximately 17,000 domains hosting second-generation iterations of Coruna and DarkSword so far, and infections have continued months after public disclosure earlier this year."
        https://www.darkreading.com/vulnerabilities-threats/coruna-darksword-ios-exploits-proliferate-globally
      • New Turnkey Kit Makes It Easy For Anyone To Become a Scammer
        "In 2026, online scams have unfortunately become part of the new normal. They can appear almost anywhere, from social media and messaging apps to search results, websites, and online communities, and they can target anyone. Sometimes, all it takes is a moment of curiosity and a convincing offer. Among the most devastating scams are so-called “get-rich-quick” schemes. These scams promise something that’s difficult for people to resist: the chance to make a lot of money, quickly and with little or no effort. It may come in the form of an investment opportunity, a new cryptocurrency project, or an exclusive chance to get in early before everyone else."
        https://www.malwarebytes.com/blog/scams/2026/08/new-turnkey-kit-makes-it-easy-for-anyone-to-become-a-scammer
      • Abyssos: Technical Analysis Of a New Modular RAT
        "In late June 2026, Zscaler ThreatLabz identified a new malware family that we track as Abyssos. Abyssos is a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC. Abyssos is in active development with multiple version numbers and different obfuscation passes that are designed to improve evasion from security products. In this blog post, ThreatLabz provides a technical analysis of Abyssos, including its core features, configuration, obfuscation, network communication protocol, and capabilities."
        https://www.zscaler.com/blogs/security-research/abyssos-technical-analysis-new-modular-rat
      • Kimsuky Integrates AI Into Attack Operations, From AI-Generated Decoy Documents To a Local LLM
        "Genians Security Center has been continuously tracking GitHub- and GitLab-based attack activity assessed to be associated with Kimsuky, a cyber threat group known to operate under North Korea's Reconnaissance General Bureau. This activity is not a newly emerged standalone campaign, but part of a continuation of Kimsuky's attack operations observed over several years. In particular, it shares key characteristics with the "FlowerPower" campaign disclosed in 2023, including the continued use of a PowerShell-based execution framework and the active abuse of Git-based repositories. It also shows links to the attack tactics identified in the 2024 report, "Analysis of a Hacking Campaign Disguised as a New Year Opinion Column.""
        https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm
        https://thehackernews.com/2026/08/kimsuky-builds-offline-ai-stack-that.html
        https://www.theregister.com/security/2026/08/10/north-korean-spies-are-running-local-llms-to-cause-ai-mischief/5285632
      • Russian Military Hackers Pose As Recruiters To Target Ukrainian IT Workers
        "Hackers linked to Russia’s military intelligence unit are posing as recruiters to trick Ukrainian IT workers into installing malicious software, researchers have found. Ukraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agency. The operation mostly targets system administrators and other IT professionals. According to CERT-UA, the hackers search legitimate Ukrainian job sites for potential victims, review their resumes and then contact them while posing as recruiters for an IT company."
        https://therecord.media/russian-military-hackers-pose-as-recruiters-ukraine-it-workers
      • Gym Rat Asks AI Agent To Book Him a Class, It Hacks a Waitlist API To Bump Him Up The List
        "An Australian man who asked his AI agent to book him a slot in a class at his local gym got more than he bargained for as the bot hacked into a waitlist and started messing with other members' reservations. Australian broadcaster ABC identified the gym-goer only as “Andrew.” The report says Andrew was using the OpenClaw agent with Anthropic’s Claude AI service. Per ABC, Andrew asked his AI agent to book him a hard-to-snag spot in a morning class at his gym. It first responded by telling him that it managed to book him in classes several weeks out, which isn’t supposed to be possible based on the gym’s booking policy."
        https://www.theregister.com/ai-and-ml/2026/08/10/gym-rat-asks-ai-agent-to-book-him-a-class-it-hacks-a-waitlist-api-to-bump-him-up-the-list/5285591
        https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986
        https://securityaffairs.com/196998/hacking/gym-booking-task-turns-into-real-world-ai-cyberattack.html
      • The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations And Communications
        "Aeternum is a recently discovered C++ botnet loader that shifts its command-and-control (C2) infrastructure entirely to the public Polygon blockchain. Instead of relying on centralized servers or domains, threat actors operate Aeternum by writing encrypted and plaintext instructions directly using smart contracts. A smart contract is a self-executing program stored on a blockchain that automatically runs when specific conditions are met. Infected devices continuously query public remote procedure call (RPC) endpoints to retrieve and execute these on-chain commands."
        https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/
      • Behind The Panels: Validating ShinyHunters Cluster A Infrastructure Through Network Telemetry
        "Phishing panels are not just credential collection tools. They are infrastructure ecosystems. Behind every convincing login page is a set of domains, hosting providers, certificates, exposed services, operator tooling, and recurring deployment patterns. Those signals matter. They give defenders a way to move beyond a single phishing domain and start understanding how the activity is built, hosted, rotated, and reused. Push Security recently published an inside look at phishing panels used in campaigns linked to ShinyHunters and BlackFile. Their team gained direct access to active operator panels, observed real victim targeting, analyzed multiple variants of the tooling, and identified four primary infrastructure clusters."
        https://www.team-cymru.com/post/validating-shinyhunters-cyber-threat-actors-infrastructure
      • Living Off The Coding Agent: Two Tales Of Tunnels And LaunchAgents
        "Coding agents such as Claude Code and Cursor are vendor-signed, used all day on developer laptops, and routinely open shells, call APIs, edit files, and install helpers. That makes GenAI-adjacent alerts challenging to investigate. The parent looks trusted, while the children can still look a lot like classic high-severity activity. This article walks through one of those windows. On a macOS endpoint, Elastic Security endpoint telemetry showed shells under Claude Code that scripted a login to an ephemeral tunnel hostname, pulled application metrics, stood up a Cloudflare quick tunnel, and installed LaunchAgent persistence. Immediate children were often shells (zsh) and helpers under that ancestry, not Claude executing every binary itself."
        https://www.elastic.co/security-labs/coding-agent-launchagent-tunnel-detection
      • Inside Astaroth's New Spambot Component
        "Established Latin American (LATAM) threat actors are continuously adapting their malware capabilities and attack methodologies to circumvent defensive measures and maintain effectiveness against target environments. Exemplifying these evolving operations, in Q4 2025, operators of the Astaroth (aka Guildma) botnet introduced a previously unidentified capability: a WhatsApp Web spambot component designed to turn victims into unwitting distributors of the malware by automatically messaging every contact in each victim’s WhatsApp contact list. This blog provides a technical deep dive into the Astaroth spambot, examines its overlaps with other recently observed spambots, and explores what this capability expansion signals about the evolving LATAM eCrime ecosystem."
        https://www.crowdstrike.com/en-us/blog/inside-astaroths-new-spambot-component/
      • Access For Sale: Inside a Russian-Speaking Access Broker's Dual Operation
        "An exposed server owned by a Russia-nexus threat actor revealed months of activity from a high-volume initial access broker. The operator exploited internet-facing appliances across a dozen-plus countries, harvesting credentials and achieving full Active Directory compromise across education, healthcare, finance, telecommunications, and government victims. In multiple confirmed cases, ransomware groups claimed the same organizations within weeks of the operator's access, indicating the operator supplies access upstream of extortion rather than conducting it directly. Late in the timeline, the operator deployed Sliver C2 against Ukrainian defence and aerospace targets, stealing source repositories and harvesting imagery from thousands of exposed IP cameras and RDP sessions. This tradecraft closely matches the AIVD/MIVD advisory on Russian state-linked camera surveillance used to locate Ukrainian military assets. The US, Europe, and Korea were seen within the artefacts as secondary targets."
        https://www.cloudsek.com/blog/access-for-sale-inside-a-russian-speaking-access-brokers-dual-operation

      Breaches/Hacks/Leaks

      • Hackers Breached a Small Polish Energy Plant Via Private APN Last Year
        "Hackers used a dedicated mobile gateway to compromise a second facility during the destructive cyberattacks that hit Poland's energy sector last year. The second target was a small combined heat-and-power (CHP) plant that supplies heat to around 50,000 residents, resulting in the steam turbine and the water treatment system being shut down. The Polish Computer Emergency Response Team (CERT) disclosed this second incident in a follow-up report over the weekend, saying that the attacker used a private Access Point Name (APN) to access the operational technology network."
        https://www.bleepingcomputer.com/news/security/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year/
        https://therecord.media/poland-uncovers-critical-infrastructure-attack-hidden
        https://www.securityweek.com/novel-private-apn-pivot-let-hackers-sabotage-second-polish-energy-facility/
        https://securityaffairs.com/196955/security/hackers-cross-from-it-to-ot-through-a-private-apn-in-poland.html
      • LexisNexis Shuts Down Services After Suspicious Activity On Servers
        "LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. The company said it is investigating the incident with assistance from a cybersecurity forensic firm and is rebuilding affected systems in a new environment before bringing the services back online. “Earlier this week, we identified unusual activity on servers that are hosted and managed by a third-party vendor,” reads the notification sent to customers last week."
        https://www.bleepingcomputer.com/news/security/lexisnexis-shuts-down-services-after-suspicious-activity-on-servers/
      • Valve Notifies Steam Hardware Customers Of a Data Breach
        "Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. CEVA Logistics (a fully-owned subsidiary of the CMA CGM Group, the world's third-largest shipping company) operates 1,000 warehouses, handled 15 million shipments last year, and reported $18.3 billion in revenues in 2025. According to many reports on social media, affected Valve customers began receiving data breach notification emails earlier today."
        https://www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/
        https://www.helpnetsecurity.com/2026/08/10/valve-data-breach-ceva-logistics-steam-hardware/
      • Exfiltration-Focused ExfilSquad Starts Leaking Stolen Data
        "A cybercrime group focused solely on stealing data and holding it to ransom made a splash when its data-leak site appeared late last month, advertising stolen data pertaining to British police officers. The group, calling itself ExfilSquad, also said it stole records from the U.K. Department of Education. On July 26, within the span of a single day, it posted claims to have hacked 15 organizations, including the municipal government of Atlanta and Houston."
        https://www.bankinfosecurity.com/exfiltration-focused-exfilsquad-starts-leaking-stolen-data-a-32494
      • Israeli Population Registry For Sale, But The Data Is Old
        "A well-known data-leak vendor is offering what they describe as the current registry of Israel’s Population and Immigration Authority: 9,220,583 records covering the entire population, with national ID numbers, addresses, phone numbers and family links. Ransomnews analysed the 100,000-record sample the seller published. The data is real Israeli registry data. It is not current. Every date field in it stops in 2005."
        https://ransomnews.com/israel-population-registry-leak-2026/
        https://securityaffairs.com/196942/cyber-crime/9-2-million-israeli-records-sold-as-a-new-breach-are-20-years-old.html
      • A Data Breach At Shipping Giant Ceva Logistics Is Rippling Across Banks, Retailers, Steam Gamers, And Beyond
        "Ceva Logistics, one of the world’s largest shipping and logistics giants, has been hacked. Several companies that rely on Ceva for shipping their products to their customers say that their personal information was also stolen in the breach. The cyberattack on Ceva is affecting at least eight warehouses across Europe used for shipping goods across the continent, the company told TechCrunch. Industry news site FreightWaves reports that the hack began on July 29 and is causing shipping delays for many of the goods in affected warehouses. Ceva is a France-headquartered shipping and logistics giant that companies around the world rely on to deliver their goods from their assembly lines to customer homes. The company, which brought in $18.3 billion in revenue in 2025, has over a thousand warehouses across the world."
        https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/

      General News

      • How We Took Malware Advisories Beyond Npm
        "A compromised package can steal credentials the moment you install it, and until recently, GitHub could only flag those in npm. Not anymore. This is the story of how the supply chain engineering team behind Dependabot expanded malware advisories to eight ecosystems by building on OpenSSF’s shared malicious packages data. Here’s where things stand: earlier this year, Dependabot started flagging malware in your npm dependencies. Great news if you write JavaScript. Now we’re bringing that same functionality to PyPI."
        https://github.blog/security/supply-chain-security/how-we-took-malware-advisories-beyond-npm/
        https://www.helpnetsecurity.com/2026/08/10/github-dependabot-malware-alerts/
      • Com Group Member Sentenced For Campaign Of Abuse Against 117 Victims Worldwide
        "A man from Leeds who forced more than 100 victims into sexual activity and self-harm as part of a Com group, including them carving his online username into their bodies, has been sentenced to two years in prison after a National Crime Agency investigation. NCA officers started an investigation into Justin Swaddle, 20, from Leeds, in January 2024. Swaddle was first arrested by West Yorkshire Police in October 2023 for offences including possession, making and distribution of indecent images."
        https://www.nationalcrimeagency.gov.uk/news/com-group-member-sentenced-for-campaign-of-abuse-against-117-victims-worldwide
        https://www.bleepingcomputer.com/news/security/member-of-the-com-sent-to-prison-for-blackmail-sextortion/
        https://therecord.media/british-com-member-abuse-jailed-two-years
        https://cyberscoop.com/uk-justin-swaddle-the-com-sentenced/
      • The Patch Gap: Why Defenders Need To Think In Chains, Not Checklists
        "On April 7, 2026, Anthropic announced Project Glasswing, which changed how every security team operates. Claude Mythos, an AI-frontier model that found thousands of high-severity vulnerabilities, including flaws in major operating systems and Web browsers, many of which survived for decades of human review and automated security tests. Of which, less than 1% was fully patched. This is a patch physics problem rather than a patch management problem. You cannot match machine-speed discovery with a remediation cycle that runs on human time."
        https://www.darkreading.com/cybersecurity-operations/patch-gap-defenders-chains-not-checklists
      • Outdated Cybercrime Laws Put Security Researchers At Risk
        "Security researchers hunting for vulnerabilities could face prison time under a 1990 United Kingdom law that doesn't distinguish between malicious hackers and those working in good faith. But change may finally be coming. Cybercrime is accelerating rapidly, requiring a holistic approach to curb threats. Security researchers who responsibly disclose vulnerabilities are one way to address burgeoning risks against governments, businesses, and individuals, but many countries have not updated their policies and laws to reflect that, Katharina Sommer, NCC Group's director of government affairs and analyst relations, tells Dark Reading."
        https://www.darkreading.com/application-security/outdated-cybercrime-laws-security-researchers-risk
      • Sherlock Holmes Was The “OG” Social Engineer
        "With a green deerstalker cap, a blue and green plaid shawl covering her shoulders and a pipe resting in her right hand right below her mouth, it was almost impossible to tell the difference between Sherlock Holmes and Elizabeth Rasnick. But that was the point— social engineering is all about deception. Holmes was the original social engineer, argued Resnick, assistant professor at the University of West Florida's Center for Cybersecurity and Artificial Intelligence (AI). During DEF CON 34, she drew parallels between current social engineering techniques and Holmes's own playbook as described in the detective tales. Her session highlighted how important it is for organizations to continually prioritize the human element when it comes to social engineering and security awareness training, despite how difficult that's proved historically."
        https://www.darkreading.com/cyber-risk/sherlock-holmes-was-the-og-social-engineer
      • IT Threat Evolution In Q2 2026. Mobile Statistics
        "The mobile section of the quarterly cyberthreat report includes statistics on malware, adware, and potentially unwanted software for Android, as well as descriptions of the most notable threats for Android and iOS discovered during the reporting period. These statistics are based on detection alerts from Kaspersky products, collected from users who consented to provide statistical data to Kaspersky Security Network."
        https://securelist.com/malware-report-q2-2026-mobile-statistics/120948/
        https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/
      • Ransomware Now Shows Up In Nearly Half Of All Breaches: A Survival Playbook For Lean Security Teams
        "Ransomware stopped being an isolated incident type in 2025. It became the dominant force behind the modern breach landscape, and the ransomware data breach statistics from Cyble’s own tracking make the shift impossible to ignore. For organizations facing this growing threat, having a ransomware incident response plan in place is becoming just as important as preventing an attack in the first place. Cyble’s Global Cybersecurity Report 2025 documented 5,967 ransomware attacks for the year, a 50% year-over-year jump. Against the 6,046 data breaches and leaks recorded in the same period, ransomware accounted for nearly half — 49.7% — of the combined ransomware-and-breach total tracked by Cyble Research and Intelligence Labs (CRIL). That’s the “nearly half” this blog’s title refers to, and it isn’t a projection. It’s what Cyble observed."
        https://cyble.com/blog/ransomware-incident-response-plan/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 7646a743-6cee-4fb1-b549-50cb107744b6-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Metabase เตือนช่องโหว่ zero-day ถูกใช้โจมตีจริง เสี่ยงยกระดับสิทธิ์เป็นผู้ดูแลระบ

      Metabase เตือนช่องโหว่ zero-day ถูกใช้โจมตีจริง เสี่ย.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 8ec416af-7d69-42d7-858d-5b1ddbf70e03-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Unlimited Technology Systems แจ้งเหตุข้อมูลรั่วไหล กระทบผู้ป่วยด้าน Healthcare กว่า 3.8 ล้านราย

      Unlimited Technology Systems แจ้งเหตุข้อมูลรั่วไหล กระทบผู้.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fa72252a-0dc5-4ce6-bfbc-11a90c91eb77-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • OpenAI ประกาศยกระดับความปลอดภัยโมเดล Astra ขณะที่ Anthropic ปรับลดข้อจำกัดของโมเดล Fable

      OpenAI ประกาศยกระดับความปลอดภัยโมเดล Astra ขณะที่.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fddc280f-54de-4be2-b03f-05016b855d25-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT