NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,459
    • กระทู้ 2,460
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    NCSA_THAICERT

    @NCSA_THAICERT

    1
    ชื่อเสียง
    56
    ดูข้อมูลส่วนตัว
    2.5k
    กระทู้
    3
    คนติดตาม
    0
    ติดตาม
    เข้าร่วม ออนไลน์ล่าสุด
    เว็บไซต์ www.ncsa.or.th/?fbclid=IwAR0BqJEC-CJzBs98rlBxUbZkNBgp1g814xdDNNaKnHTrxfqZhPD--ksY68I

    NCSA_THAICERT เลิกติดตาม ติดตาม
    Global Moderator administrators

    Latest posts made by NCSA_THAICERT

    • CISA เตือนช่องโหว่ใน Progress Kemp LoadMaster ถูกใช้โจมตีจริง

      CISA เตือนช่องโหว่ใน Progress Kemp LoadMaster ถูกใช้โจมตีจริ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e2cf1732-d364-4a0f-97e0-818c71720b56-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • IEH แจ้งเหตุ Phishing กระทบ Microsoft 365 Mailbox อาจเปิดเผยข้อมูลทางทหารที่อยู่ภายใต้การควบคุมการส่งออก

      IEH แจ้งเหตุ Phishing กระทบ Microsoft 365 Mailbox อาจเปิดเผยข้อม.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 878ad2b4-7abc-483a-bd4e-d99f9d50cfae-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบแพ็กเกจอันตรายบน npm กว่า 800 รายการ แพร่มัลแวร์และขโมยข้อมูลข้ามแพลตฟอร์ม Windows-Mac-Linux

      พบแพ็กเกจอันตรายบน npm กว่า 800 รายการ แพร่มัลแ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 0b98d7bd-afbd-46c9-901c-2baacfd1ca46-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 11 August 2026

      New Tooling

      • Chainloop: Open-Source Evidence Store And Policy Engine For The Software Supply Chain
        "Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable storage, and references each one in a signed in-toto attestation. in-toto is a specification for recording who ran which step of a build, so the record can be checked afterward. Compliance and security teams get a control plane where all of it arrives, already signed, no matter which continuous integration provider produced it."
        https://www.helpnetsecurity.com/2026/08/10/chainloop-open-source-supply-chain-security/
        https://github.com/chainloop-dev/chainloop

      Vulnerabilities

      • Critical Flaws Discovered In Belgian eID Software Used By 2 Million People
        "A security researcher has revealed severe, now-resolved security vulnerabilities in the Connective digital identity system, a browser extension used by over two million users in Belgium. Developed by Nitro Software Belgium, the software is used by eight of Belgium’s ten largest banks and over 60 government agencies to manage digital identity authentication and execute legally binding electronic signatures. James Arnott, security researcher and founder of cybersecurity firm Bay Area Labs, discovered that the software failed to verify which website was attempting to communicate with the user’s computer. Because these checks were missing, any website or embedded online ad could interact directly with the Connective application running on a victim’s machine without their knowledge or permission."
        https://www.securityweek.com/critical-flaws-discovered-in-belgian-eid-software-used-by-2-million-people/
      • PSA: Supply Chain Compromise In BdThemes Ecosystem Via Poisoned API Response
        "The Wordfence Threat Intelligence Team was notified on August 7th, 2026 of a supply chain compromise affecting BdThemes, a WordPress plugin vendor whose plugins are available in the official WordPress plugins directory. Currently, all the affected plugins are temporarily closed pending a full inspection and ongoing investigation by the WordPress Plugins team. Our investigation revealed an insidious supply chain compromise affecting several plugins. Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository. Instead, threat actors poisoned a static remote JSON data stream fetched by an administrative promotional banner component."
        https://www.wordfence.com/blog/2026/08/psa-supply-chain-compromise-in-bdthemes-ecosystem-via-poisoned-api-response/
        https://www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/
        https://www.infosecurity-magazine.com/news/bdthemes-wordpress-poisoned-api/
      • Cisco Warns Of High-Severity ClamAV Vulnerabilities With Public PoC
        "Cisco on Friday warned that its Secure Endpoint Connector products on Windows, macOS, and Linux are affected by seven ClamAV vulnerabilities that could lead to denial-of-service (DoS) conditions, including two with public proof-of-concept (PoC) code. ClamAV (Clam AntiVirus) is an open source, cross-platform malware detection engine that provides a multi-threaded virtual scanner, email filtering, and automatic database updates. The security defects, tracked as CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, were discovered in ClamAV’s parsers for ZIP, GPT, PESpin, PDF, Mach-O, and XAR file formats."
        https://www.securityweek.com/cisco-warns-of-high-severity-clamav-vulnerabilities-with-public-poc/
        https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26
      • Cyber Vulnerability Sweep Picks Up Royal Navy Drones Sending Data To China
        "Cameras aboard Royal Navy drone boats were found phoning home to an IP address in China during a routine cyber vulnerability assessment. The UK Ministry of Defence confirmed the discovery, describing it as "an issue affecting a Kraken Unmanned Surface Vessel sub-system used by the Royal Navy." The Register understands that the data consisted of a "heartbeat" signalling that the camera was online and functioning normally. Even so, an unexpected transmission from military equipment to an IP address in China will rattle nerves. We contacted unmanned surface vessel supplier Kraken for more information, but have yet to receive a reply."
        https://www.theregister.com/edge-and-iot/2026/08/10/cyber-vulnerability-sweep-picks-up-royal-navy-drones-sending-data-to-china/5285430
        https://www.telegraph.co.uk/news/2026/08/09/spy-cameras-on-navy-drones-secretly-sent-data-to-china/

      Malware

      • Solidity Pro's WhiteCobra Chassis: Cloudflare C2 To Telegram Infostealer
        "A Solidity extension called “Solidity Pro” sounds like the kind of tooling every crypto developer installs without thinking. That is exactly why it keeps appearing in malware campaigns. Yeeth Security recently tracked two publishers, helper-beeps and web3devtoolsx, shipping versions of a solidity-pro extension that evolved from a delayed Cloudflare-Worker dropper into a full browser-wallet and credential infostealer. The progression mirrors what public reporting has attributed to the WhiteCobra group, whose leaked “Operation Solidity Pro” playbook described a five-phase campaign targeting VS Code: and Open VSX users."
        https://yeethsecurity.com/blog/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-Telegram
        https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html
      • New StormEncryptor Ransomware Used By Former Medusa Affiliate
        "A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. Microsoft Threat Intelligence is tracking the actor as Storm-1175 and says the recent attacks were likely preceded by exploitation of an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring and management (RMM) tool. Storm-1175 is believed to be a China-based threat actor. It was previously linked to Medusa ransomware, targeting systems via zero-day and n-day flaws in various products, including GoAnywhere MFT, SmarterTools SmarterMail, Microsoft Exchange, Invanti Connect Secure, and JetBrains TeamCity."
        https://www.bleepingcomputer.com/news/security/new-stormencryptor-ransomware-used-by-former-medusa-affiliate/
        https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html
        https://therecord.media/china-hackers-ransomware-microsoft
        https://www.bankinfosecurity.com/china-linked-hackers-exploit-n-able-flaw-in-ransomware-attacks-a-32506
      • CISA: SonicWall SMA1000 Flaws Now Exploited By Ransomware Gangs
        "CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. ​SMA1000 is an enterprise-grade secure remote access gateway used by large corporations, government agencies, and Managed Service Providers (MSSPs) to provide VPN access to internal applications and corporate networks. SonicWall released patches for the two security flaws (tracked as CVE-2026-15409 and CVE-2026-15410) in mid July, when it also warned that threat actors had been exploiting them in zero-day attacks."
        https://www.bleepingcomputer.com/news/security/cisa-sonicwall-sma1000-flaws-now-exploited-by-ransomware-gangs/
      • #StopRansomware: Gunra Ransomware
        "Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. This advisory provides technical details of the activity, as well as tailored detection and mitigation guidance to protect at-risk organizations from Gunra."
        https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
        https://therecord.media/ransomware-south-korea-fbi-gunra
        https://cyberscoop.com/us-south-korea-gunra-ransomware-warning/
      • GhostJacking Attacks: Half Of The Fortune 500 Run These Tools. Getting Blocked By The Firewall Was The Way To Take Over Their AI Agents
        "Half the Fortune 500 run the tools that let us in. It will be presented at DEFCON, the largest hacker conference, where we’ll show how a request their own firewall blocked was the way in. “Ghostjacking” attack vectors introduce the modern agentic kill chain, agent takeover, sandbox escape, and backdoors planted inside the AI agents you already run, from a Claude Agent sandbox escape to hijacking live agents through the very platforms they trust most – Cloudflare, Sentry, Datadog."
        https://tenetsecurity.ai/blog/ghostjacking-attacks-agentic-kill-chain/
        https://www.darkreading.com/cyber-risk/ghostjacking-identity-governance-gaps-ai-agents
        https://www.infosecurity-magazine.com/news/ghostjacking-ai-gents-access/
        https://www.securityweek.com/ghostjacking-attack-uses-poisoned-logs-to-turn-ai-agents-bad/
      • Coruna, DarkSword iOS Exploits Proliferate Globally
        "The advanced iPhone exploit chains Coruna and DarkSword continue to escape nation-state and mercenary containment to enter the hands of more conventional cybercriminals. While nation-state-grade malware will, from time to time, make its way from government use to cybercriminal adoption, it's far more unusual to see whole complex exploit chains — especially those targeting iOS — adopted broadly. Yet that phenomenon, first observed last spring, appears to be shifting into overdrive. iVerify has tracked approximately 17,000 domains hosting second-generation iterations of Coruna and DarkSword so far, and infections have continued months after public disclosure earlier this year."
        https://www.darkreading.com/vulnerabilities-threats/coruna-darksword-ios-exploits-proliferate-globally
      • New Turnkey Kit Makes It Easy For Anyone To Become a Scammer
        "In 2026, online scams have unfortunately become part of the new normal. They can appear almost anywhere, from social media and messaging apps to search results, websites, and online communities, and they can target anyone. Sometimes, all it takes is a moment of curiosity and a convincing offer. Among the most devastating scams are so-called “get-rich-quick” schemes. These scams promise something that’s difficult for people to resist: the chance to make a lot of money, quickly and with little or no effort. It may come in the form of an investment opportunity, a new cryptocurrency project, or an exclusive chance to get in early before everyone else."
        https://www.malwarebytes.com/blog/scams/2026/08/new-turnkey-kit-makes-it-easy-for-anyone-to-become-a-scammer
      • Abyssos: Technical Analysis Of a New Modular RAT
        "In late June 2026, Zscaler ThreatLabz identified a new malware family that we track as Abyssos. Abyssos is a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC. Abyssos is in active development with multiple version numbers and different obfuscation passes that are designed to improve evasion from security products. In this blog post, ThreatLabz provides a technical analysis of Abyssos, including its core features, configuration, obfuscation, network communication protocol, and capabilities."
        https://www.zscaler.com/blogs/security-research/abyssos-technical-analysis-new-modular-rat
      • Kimsuky Integrates AI Into Attack Operations, From AI-Generated Decoy Documents To a Local LLM
        "Genians Security Center has been continuously tracking GitHub- and GitLab-based attack activity assessed to be associated with Kimsuky, a cyber threat group known to operate under North Korea's Reconnaissance General Bureau. This activity is not a newly emerged standalone campaign, but part of a continuation of Kimsuky's attack operations observed over several years. In particular, it shares key characteristics with the "FlowerPower" campaign disclosed in 2023, including the continued use of a PowerShell-based execution framework and the active abuse of Git-based repositories. It also shows links to the attack tactics identified in the 2024 report, "Analysis of a Hacking Campaign Disguised as a New Year Opinion Column.""
        https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm
        https://thehackernews.com/2026/08/kimsuky-builds-offline-ai-stack-that.html
        https://www.theregister.com/security/2026/08/10/north-korean-spies-are-running-local-llms-to-cause-ai-mischief/5285632
      • Russian Military Hackers Pose As Recruiters To Target Ukrainian IT Workers
        "Hackers linked to Russia’s military intelligence unit are posing as recruiters to trick Ukrainian IT workers into installing malicious software, researchers have found. Ukraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agency. The operation mostly targets system administrators and other IT professionals. According to CERT-UA, the hackers search legitimate Ukrainian job sites for potential victims, review their resumes and then contact them while posing as recruiters for an IT company."
        https://therecord.media/russian-military-hackers-pose-as-recruiters-ukraine-it-workers
      • Gym Rat Asks AI Agent To Book Him a Class, It Hacks a Waitlist API To Bump Him Up The List
        "An Australian man who asked his AI agent to book him a slot in a class at his local gym got more than he bargained for as the bot hacked into a waitlist and started messing with other members' reservations. Australian broadcaster ABC identified the gym-goer only as “Andrew.” The report says Andrew was using the OpenClaw agent with Anthropic’s Claude AI service. Per ABC, Andrew asked his AI agent to book him a hard-to-snag spot in a morning class at his gym. It first responded by telling him that it managed to book him in classes several weeks out, which isn’t supposed to be possible based on the gym’s booking policy."
        https://www.theregister.com/ai-and-ml/2026/08/10/gym-rat-asks-ai-agent-to-book-him-a-class-it-hacks-a-waitlist-api-to-bump-him-up-the-list/5285591
        https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986
        https://securityaffairs.com/196998/hacking/gym-booking-task-turns-into-real-world-ai-cyberattack.html
      • The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations And Communications
        "Aeternum is a recently discovered C++ botnet loader that shifts its command-and-control (C2) infrastructure entirely to the public Polygon blockchain. Instead of relying on centralized servers or domains, threat actors operate Aeternum by writing encrypted and plaintext instructions directly using smart contracts. A smart contract is a self-executing program stored on a blockchain that automatically runs when specific conditions are met. Infected devices continuously query public remote procedure call (RPC) endpoints to retrieve and execute these on-chain commands."
        https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/
      • Behind The Panels: Validating ShinyHunters Cluster A Infrastructure Through Network Telemetry
        "Phishing panels are not just credential collection tools. They are infrastructure ecosystems. Behind every convincing login page is a set of domains, hosting providers, certificates, exposed services, operator tooling, and recurring deployment patterns. Those signals matter. They give defenders a way to move beyond a single phishing domain and start understanding how the activity is built, hosted, rotated, and reused. Push Security recently published an inside look at phishing panels used in campaigns linked to ShinyHunters and BlackFile. Their team gained direct access to active operator panels, observed real victim targeting, analyzed multiple variants of the tooling, and identified four primary infrastructure clusters."
        https://www.team-cymru.com/post/validating-shinyhunters-cyber-threat-actors-infrastructure
      • Living Off The Coding Agent: Two Tales Of Tunnels And LaunchAgents
        "Coding agents such as Claude Code and Cursor are vendor-signed, used all day on developer laptops, and routinely open shells, call APIs, edit files, and install helpers. That makes GenAI-adjacent alerts challenging to investigate. The parent looks trusted, while the children can still look a lot like classic high-severity activity. This article walks through one of those windows. On a macOS endpoint, Elastic Security endpoint telemetry showed shells under Claude Code that scripted a login to an ephemeral tunnel hostname, pulled application metrics, stood up a Cloudflare quick tunnel, and installed LaunchAgent persistence. Immediate children were often shells (zsh) and helpers under that ancestry, not Claude executing every binary itself."
        https://www.elastic.co/security-labs/coding-agent-launchagent-tunnel-detection
      • Inside Astaroth's New Spambot Component
        "Established Latin American (LATAM) threat actors are continuously adapting their malware capabilities and attack methodologies to circumvent defensive measures and maintain effectiveness against target environments. Exemplifying these evolving operations, in Q4 2025, operators of the Astaroth (aka Guildma) botnet introduced a previously unidentified capability: a WhatsApp Web spambot component designed to turn victims into unwitting distributors of the malware by automatically messaging every contact in each victim’s WhatsApp contact list. This blog provides a technical deep dive into the Astaroth spambot, examines its overlaps with other recently observed spambots, and explores what this capability expansion signals about the evolving LATAM eCrime ecosystem."
        https://www.crowdstrike.com/en-us/blog/inside-astaroths-new-spambot-component/
      • Access For Sale: Inside a Russian-Speaking Access Broker's Dual Operation
        "An exposed server owned by a Russia-nexus threat actor revealed months of activity from a high-volume initial access broker. The operator exploited internet-facing appliances across a dozen-plus countries, harvesting credentials and achieving full Active Directory compromise across education, healthcare, finance, telecommunications, and government victims. In multiple confirmed cases, ransomware groups claimed the same organizations within weeks of the operator's access, indicating the operator supplies access upstream of extortion rather than conducting it directly. Late in the timeline, the operator deployed Sliver C2 against Ukrainian defence and aerospace targets, stealing source repositories and harvesting imagery from thousands of exposed IP cameras and RDP sessions. This tradecraft closely matches the AIVD/MIVD advisory on Russian state-linked camera surveillance used to locate Ukrainian military assets. The US, Europe, and Korea were seen within the artefacts as secondary targets."
        https://www.cloudsek.com/blog/access-for-sale-inside-a-russian-speaking-access-brokers-dual-operation

      Breaches/Hacks/Leaks

      • Hackers Breached a Small Polish Energy Plant Via Private APN Last Year
        "Hackers used a dedicated mobile gateway to compromise a second facility during the destructive cyberattacks that hit Poland's energy sector last year. The second target was a small combined heat-and-power (CHP) plant that supplies heat to around 50,000 residents, resulting in the steam turbine and the water treatment system being shut down. The Polish Computer Emergency Response Team (CERT) disclosed this second incident in a follow-up report over the weekend, saying that the attacker used a private Access Point Name (APN) to access the operational technology network."
        https://www.bleepingcomputer.com/news/security/hackers-breached-a-small-polish-energy-plant-via-private-apn-last-year/
        https://therecord.media/poland-uncovers-critical-infrastructure-attack-hidden
        https://www.securityweek.com/novel-private-apn-pivot-let-hackers-sabotage-second-polish-energy-facility/
        https://securityaffairs.com/196955/security/hackers-cross-from-it-to-ot-through-a-private-apn-in-poland.html
      • LexisNexis Shuts Down Services After Suspicious Activity On Servers
        "LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. The company said it is investigating the incident with assistance from a cybersecurity forensic firm and is rebuilding affected systems in a new environment before bringing the services back online. “Earlier this week, we identified unusual activity on servers that are hosted and managed by a third-party vendor,” reads the notification sent to customers last week."
        https://www.bleepingcomputer.com/news/security/lexisnexis-shuts-down-services-after-suspicious-activity-on-servers/
      • Valve Notifies Steam Hardware Customers Of a Data Breach
        "Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. CEVA Logistics (a fully-owned subsidiary of the CMA CGM Group, the world's third-largest shipping company) operates 1,000 warehouses, handled 15 million shipments last year, and reported $18.3 billion in revenues in 2025. According to many reports on social media, affected Valve customers began receiving data breach notification emails earlier today."
        https://www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/
        https://www.helpnetsecurity.com/2026/08/10/valve-data-breach-ceva-logistics-steam-hardware/
      • Exfiltration-Focused ExfilSquad Starts Leaking Stolen Data
        "A cybercrime group focused solely on stealing data and holding it to ransom made a splash when its data-leak site appeared late last month, advertising stolen data pertaining to British police officers. The group, calling itself ExfilSquad, also said it stole records from the U.K. Department of Education. On July 26, within the span of a single day, it posted claims to have hacked 15 organizations, including the municipal government of Atlanta and Houston."
        https://www.bankinfosecurity.com/exfiltration-focused-exfilsquad-starts-leaking-stolen-data-a-32494
      • Israeli Population Registry For Sale, But The Data Is Old
        "A well-known data-leak vendor is offering what they describe as the current registry of Israel’s Population and Immigration Authority: 9,220,583 records covering the entire population, with national ID numbers, addresses, phone numbers and family links. Ransomnews analysed the 100,000-record sample the seller published. The data is real Israeli registry data. It is not current. Every date field in it stops in 2005."
        https://ransomnews.com/israel-population-registry-leak-2026/
        https://securityaffairs.com/196942/cyber-crime/9-2-million-israeli-records-sold-as-a-new-breach-are-20-years-old.html
      • A Data Breach At Shipping Giant Ceva Logistics Is Rippling Across Banks, Retailers, Steam Gamers, And Beyond
        "Ceva Logistics, one of the world’s largest shipping and logistics giants, has been hacked. Several companies that rely on Ceva for shipping their products to their customers say that their personal information was also stolen in the breach. The cyberattack on Ceva is affecting at least eight warehouses across Europe used for shipping goods across the continent, the company told TechCrunch. Industry news site FreightWaves reports that the hack began on July 29 and is causing shipping delays for many of the goods in affected warehouses. Ceva is a France-headquartered shipping and logistics giant that companies around the world rely on to deliver their goods from their assembly lines to customer homes. The company, which brought in $18.3 billion in revenue in 2025, has over a thousand warehouses across the world."
        https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/

      General News

      • How We Took Malware Advisories Beyond Npm
        "A compromised package can steal credentials the moment you install it, and until recently, GitHub could only flag those in npm. Not anymore. This is the story of how the supply chain engineering team behind Dependabot expanded malware advisories to eight ecosystems by building on OpenSSF’s shared malicious packages data. Here’s where things stand: earlier this year, Dependabot started flagging malware in your npm dependencies. Great news if you write JavaScript. Now we’re bringing that same functionality to PyPI."
        https://github.blog/security/supply-chain-security/how-we-took-malware-advisories-beyond-npm/
        https://www.helpnetsecurity.com/2026/08/10/github-dependabot-malware-alerts/
      • Com Group Member Sentenced For Campaign Of Abuse Against 117 Victims Worldwide
        "A man from Leeds who forced more than 100 victims into sexual activity and self-harm as part of a Com group, including them carving his online username into their bodies, has been sentenced to two years in prison after a National Crime Agency investigation. NCA officers started an investigation into Justin Swaddle, 20, from Leeds, in January 2024. Swaddle was first arrested by West Yorkshire Police in October 2023 for offences including possession, making and distribution of indecent images."
        https://www.nationalcrimeagency.gov.uk/news/com-group-member-sentenced-for-campaign-of-abuse-against-117-victims-worldwide
        https://www.bleepingcomputer.com/news/security/member-of-the-com-sent-to-prison-for-blackmail-sextortion/
        https://therecord.media/british-com-member-abuse-jailed-two-years
        https://cyberscoop.com/uk-justin-swaddle-the-com-sentenced/
      • The Patch Gap: Why Defenders Need To Think In Chains, Not Checklists
        "On April 7, 2026, Anthropic announced Project Glasswing, which changed how every security team operates. Claude Mythos, an AI-frontier model that found thousands of high-severity vulnerabilities, including flaws in major operating systems and Web browsers, many of which survived for decades of human review and automated security tests. Of which, less than 1% was fully patched. This is a patch physics problem rather than a patch management problem. You cannot match machine-speed discovery with a remediation cycle that runs on human time."
        https://www.darkreading.com/cybersecurity-operations/patch-gap-defenders-chains-not-checklists
      • Outdated Cybercrime Laws Put Security Researchers At Risk
        "Security researchers hunting for vulnerabilities could face prison time under a 1990 United Kingdom law that doesn't distinguish between malicious hackers and those working in good faith. But change may finally be coming. Cybercrime is accelerating rapidly, requiring a holistic approach to curb threats. Security researchers who responsibly disclose vulnerabilities are one way to address burgeoning risks against governments, businesses, and individuals, but many countries have not updated their policies and laws to reflect that, Katharina Sommer, NCC Group's director of government affairs and analyst relations, tells Dark Reading."
        https://www.darkreading.com/application-security/outdated-cybercrime-laws-security-researchers-risk
      • Sherlock Holmes Was The “OG” Social Engineer
        "With a green deerstalker cap, a blue and green plaid shawl covering her shoulders and a pipe resting in her right hand right below her mouth, it was almost impossible to tell the difference between Sherlock Holmes and Elizabeth Rasnick. But that was the point— social engineering is all about deception. Holmes was the original social engineer, argued Resnick, assistant professor at the University of West Florida's Center for Cybersecurity and Artificial Intelligence (AI). During DEF CON 34, she drew parallels between current social engineering techniques and Holmes's own playbook as described in the detective tales. Her session highlighted how important it is for organizations to continually prioritize the human element when it comes to social engineering and security awareness training, despite how difficult that's proved historically."
        https://www.darkreading.com/cyber-risk/sherlock-holmes-was-the-og-social-engineer
      • IT Threat Evolution In Q2 2026. Mobile Statistics
        "The mobile section of the quarterly cyberthreat report includes statistics on malware, adware, and potentially unwanted software for Android, as well as descriptions of the most notable threats for Android and iOS discovered during the reporting period. These statistics are based on detection alerts from Kaspersky products, collected from users who consented to provide statistical data to Kaspersky Security Network."
        https://securelist.com/malware-report-q2-2026-mobile-statistics/120948/
        https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/
      • Ransomware Now Shows Up In Nearly Half Of All Breaches: A Survival Playbook For Lean Security Teams
        "Ransomware stopped being an isolated incident type in 2025. It became the dominant force behind the modern breach landscape, and the ransomware data breach statistics from Cyble’s own tracking make the shift impossible to ignore. For organizations facing this growing threat, having a ransomware incident response plan in place is becoming just as important as preventing an attack in the first place. Cyble’s Global Cybersecurity Report 2025 documented 5,967 ransomware attacks for the year, a 50% year-over-year jump. Against the 6,046 data breaches and leaks recorded in the same period, ransomware accounted for nearly half — 49.7% — of the combined ransomware-and-breach total tracked by Cyble Research and Intelligence Labs (CRIL). That’s the “nearly half” this blog’s title refers to, and it isn’t a projection. It’s what Cyble observed."
        https://cyble.com/blog/ransomware-incident-response-plan/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 7646a743-6cee-4fb1-b549-50cb107744b6-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Metabase เตือนช่องโหว่ zero-day ถูกใช้โจมตีจริง เสี่ยงยกระดับสิทธิ์เป็นผู้ดูแลระบ

      Metabase เตือนช่องโหว่ zero-day ถูกใช้โจมตีจริง เสี่ย.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 8ec416af-7d69-42d7-858d-5b1ddbf70e03-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Unlimited Technology Systems แจ้งเหตุข้อมูลรั่วไหล กระทบผู้ป่วยด้าน Healthcare กว่า 3.8 ล้านราย

      Unlimited Technology Systems แจ้งเหตุข้อมูลรั่วไหล กระทบผู้.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fa72252a-0dc5-4ce6-bfbc-11a90c91eb77-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • OpenAI ประกาศยกระดับความปลอดภัยโมเดล Astra ขณะที่ Anthropic ปรับลดข้อจำกัดของโมเดล Fable

      OpenAI ประกาศยกระดับความปลอดภัยโมเดล Astra ขณะที่.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fddc280f-54de-4be2-b03f-05016b855d25-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 10 August 2026

      Healthcare Sector

      • Medixant RadiAnt DICOM
        "Successful exploitation of this vulnerability could allow an attacker to cause the application to crash if a maliciously crafted DICOM file is opened."
        https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-218-01

      Industrial Sector

      • ABB Ability Zenon
        "Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-01
      • Johnson Controls Inc. TL280
        "Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-02
      • CPDLC Over ATN-B1 Vulnerabilities
        "ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links. Research demonstrates that these characteristics allow unauthorized message injection, denial-of-service conditions, and forced session resets. These vulnerabilities do not constitute an unsafe aircraft condition but can degrade operational safety margins by increasing workload, delaying safety-critical instructions, and reducing situational awareness."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-219-01
      • Truck Brake Controller’s Safety Recall Doubled As Hidden Security Fix
        "The National Motor Freight Traffic Association (NMFTA) says a 2024 safety recall for Bendix’s EC80 heavy-truck brake controller quietly fixed a set of serious vulnerabilities, including a wirelessly reachable remote code execution flaw, alongside the memory corruption issue Bendix publicly disclosed. The findings were detailed by NMFTA senior cybersecurity research engineer Ben Gardiner on Thursday at the Black Hat USA 2026 conference."
        https://www.securityweek.com/truck-brake-controllers-safety-recall-doubled-as-hidden-security-fix/
      • Water System Controllers Don't Belong On The Internet, Says Ex-NSA Chief After Suspected Iran Attacks
        "With at least 12 US states’ water systems having been hacked - most likely by Iran - we have to get better at cyber defense, according to retired General and Ex-NSA chief Paul Nakasone, who was speaking to reporters at DEF CON. “We have to have higher standards,” Nakasone said. “These PLCs should not be connected to the internet.” In late July, the FBI said it was investigating attacks conducted by “malicious cyber actors” targeting operational technology devices, including programmable logic controllers (PLCs). Iran-linked crews have targeted these devices, which monitor sensor data like tank levels, and can turn pumps on and off, for years."
        https://www.theregister.com/security/2026/08/07/water-system-controllers-dont-belong-on-the-internet-says-ex-nsa-chief-after-suspected-iran-attacks/5285070

      Vulnerabilities

      • Metabase SQLi Zero-Day Exploited In Customer Data-Theft Attacks
        "A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. Metabase disclosed the attacks on Thursday, warning that its Metabase Cloud SaaS platform was compromised through a previously unknown vulnerability affecting versions 1.58 and above. The company warns that self-hosted installations are also vulnerable. "We recently identified that Metabase Cloud was attacked by someone utilizing an unknown ("0-day") security vulnerability in versions 1.58 and above," Metabase CEO Sameer Al-Sakran warned in a blog post."
        https://www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/
        https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html
        https://securityaffairs.com/196874/hacking/metabase-zero-day-exploited-in-the-wild-exposing-admin-access-and-sensitive-data.html
      • Claude Code And Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
        "A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5. Two CVEs came out of it. Both are patched. Gemini CLI carries the worst of the two. CVE-2026-12537 (CVSS 4 score: 10.0) is an OS command injection in the container launcher, reached through a crafted .gemini/.env file, which lets an unprivileged attacker run code on the host of a headless CI platform before the sandbox starts. It is fixed in Gemini CLI 0.39.1 and run-gemini-cli 0.1.22."
        https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html
      • Microsoft, Apple Release Fresh Security Updates
        "The charge was led by Microsoft, which patched over a dozen vulnerabilities across Active Directory, Azure, Entra, SharePoint, Teams, and other products, including critical-severity remote code execution (RCE) issues. Three of the issues, CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667, have a maximum severity rating of 10/10. Described as missing authentication in Planetary Computer Pro, improper authentication in Azure SQL Database, and missing authorization in Teams, respectively, they could lead to elevation of privilege (EoP) and can be exploited over the network."
        https://www.securityweek.com/microsoft-apple-release-fresh-security-updates/
      • XSS2Shell: WordPress Preauth XSS To RCE Chain (CVE-2026-64638)
        "Pwn discovered a critical pre-auth XSS to RCE vulnerability chain affecting all versions of WordPress Core: the software that powers over 43% of all internet-facing websites. An estimated 500 million+ websites were vulnerable until today. We're calling it XSS2Shell. CVE-2026-64638 is exploitable entirely pre-authenticated (No account needed to exploit it). It lets a single failed login attempt run an attacker JavaScript execution in the WordPress origin, and against a logged-in administrator, towards full remote code execution on the server, reliably on all default Wordpress installs. All of our pwn.ai clients using our Asset Surface Management (ASM) product are protected from this vulnerability, and were notified as soon as pwn found it weeks early."
        https://pwn.ai/blog/xss2shell
        https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
        https://securityaffairs.com/196820/hacking/wordpress-xss2shell-flaw-turns-simple-login-bug-into-full-server-takeover.html
      • Critical Vulnerabilities Patched With Chrome 151 Update
        "Google on Thursday rolled out a fresh Chrome 151 update that patches 41 critical- and high-severity vulnerabilities. Over two dozen security defects are memory safety bugs that could lead to data corruption, crashes, and arbitrary code execution. The latest Chrome update resolves six critical-severity flaws, including five use-after-free issues in WebGL, Aura, Skia, and Views, and an out-of-bounds write in the ANGLE graphics engine."
        https://www.securityweek.com/critical-vulnerabilities-patched-with-chrome-151-update/
      • N-Able God Mode Flaw: Vendor Confirms Attackers Reached Customer Networks As Second Hotfix Lands
        "N-able has confirmed attackers exploiting an N-central zero-day made it into customer networks, as the vendor pushes out a second mandatory hotfix just days after the first. The security shop published an update on Thursday detailing what happened after attackers exploited CVE-2026-18577, the critical N-central flaw that can hand an unauthenticated attacker administrative access to the remote monitoring and management platform. According to N-able, attackers exploited vulnerable N-central servers remotely, then used the platform's Take Control feature to connect to systems inside the environments being managed through them."
        https://www.theregister.com/networks/2026/08/07/n-able-god-mode-flaw-vendor-confirms-attackers-reached-customer-networks-as-second-hotfix-lands/5284730
        https://www.n-able.com/blog/n-central-security-update-august-6-2026
        https://thehackernews.com/2026/08/n-central-attackers-reach-managed.html
        https://www.bankinfosecurity.com/new-n-able-zero-day-puts-msps-on-defensive-a-32458
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-8037 Progress LoadMaster Command Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/07/cisa-adds-one-known-exploited-vulnerability-catalog
        https://thehackernews.com/2026/08/progress-kemp-loadmaster-flaw-hits-cisa.html
        https://securityaffairs.com/196863/hacking/u-s-cisa-adds-a-progress-loadmaster-flaw-to-its-known-exploited-vulnerabilities-catalog.html
      • SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free
        "SCTPhantom is a Linux kernel use-after-free in SCTP Dynamic Address Reconfiguration. An ordered ASCONF sequence can remove a transport and then reuse its stale pointer, leaving the association with dangling path references. Corvus AI developed the initial finding into a reproducible vulnerability and demonstrated local privilege escalation and container-to-host escape on the tested systems. The issue is tracked as CVE-2026-64564 and fixed upstream by 9b2854f86f0b."
        https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564
        https://thehackernews.com/2026/08/18-year-old-linux-sctp-flaw-could-let.html
      • Can AI Do Novel Security Research? Meet The HTTP Terminator
        "We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Building this sounded like a bad idea, so I did it. It worked - I'll share an arsenal of new HTTP desync triggers, gadgets, and exploits that compromised banks, security solutions, and government infrastructure. Then I'll trace each discovery chain back through the HTTP Terminator, showing how to turn your personal expertise into an autonomous weapon - and the dark arts required to make it lethal."
        https://portswigger.net/research/can-ai-do-novel-security-research
        https://thehackernews.com/2026/08/ai-assisted-http-terminator-finds-novel.html
      • New NatJack Attacks Hijack TCP Sessions And Spoof DNS By Manipulating NAT Tables
        "Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and Linux. Two implementation-specific flaws have been assigned CVEs: CVE-2026-56181 (CVSS score: 8.3) in Windows NAT used by Hyper-V, and CVE-2026-63913 (CVSS score: 8.2) in Linux Netfilter conntrack."
        https://thehackernews.com/2026/08/new-natjack-attacks-hijack-tcp-sessions.html
      • Borrowing Windows Hello Keys For Authentication And Persistence
        "Most research into Windows Hello focuses on the mechanics in use when authenticating to the local device. As an Entra ID researcher, I’ve always been more interested in how these keys are used to authenticate to the cloud. I’ve given several talks on Windows Hello for Business (WHFB for short) and about the many implementation flaws discovered in the process, most of which were fixed by Microsoft. For this blog I want to focus on a technique that was left as-is since it is more or less a consequence of how WHFB works: the ability to perform single-sign on with the backing cryptographic keys from a user session, without needing the PIN or other information/user presence. We will not just look at how we can utilize this to request Primary Refresh Tokens (PRTs), but also how we can use this to perform device registration by using the WHFB key as a FIDO key/passkey."
        https://dirkjanm.io/borrowing-windows-hello-keys/
        https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html
      • RovoBlast: How One Click Triggered Atlassian’s AI Assistant To Leak Data
        "Varonis Threat Labs uncovered a vulnerability in Rovo, Atlassian's enterprise AI assistant. Dubbed RovoBlast, a single click on a link triggers the attacker's embedded instructions and forces Rovo to accept externally supplied parameters as trusted inputs within a user's session. No jailbreaks, no permission bypass, and no warnings or confirmation. The same capabilities that make Rovo a powerful tool also make RovoBlast especially dangerous. Rovo operates as an AI layer across the core products in the Atlassian platform, including Jira, Confluence, Bitbucket, as well as other connected SaaS tools like Slack, Microsoft 365, and Google. Atlassian also features autonomous-agent capabilities that can carry out multi-step actions without user involvement."
        https://www.varonis.com/blog/rovoblast
        https://thehackernews.com/2026/08/atlassian-rovo-can-be-tricked-into.html
        https://www.securityweek.com/critical-one-click-vulnerability-in-atlassians-rovo-ai-exposed-enterprise-data/

      Malware

      • UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services And Enterprise Cloud Environments
        "Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their personal mobile devices."
        https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments
        https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html
        https://www.bankinfosecurity.com/financial-services-under-fire-from-rebranded-extortionists-a-32464
        https://www.infosecurity-magazine.com/news/redact-extortion-group-blackfile/
        https://www.securityweek.com/vishing-extortion-group-unc6671-rebrands-after-making-millions/
        https://securityaffairs.com/196800/security/hackers-impersonate-it-support-to-breach-leading-financial-companies.html
      • Chinese Model Kimi K3 Breaks UK AI Safety Institute Benchmark Evaluations
        "Over the past few months we’ve been testing performance of various models for defensive security. The AI community uses model evaluations to measure models’ performance to improve them on specific tasks. In our work on evaluation of models on defensive cybersecurity tasks, we discovered two interesting facts: (1) There are standard evaluation environments that have exposed loopholes and (2) there are models that take advantage of these loopholes. This suggests that some of the evaluations on cybersecurity the community uses are susceptible to security vulnerabilities and allow models to cheat, and that there are models that intentionally seek loopholes and vulnerabilities which allows them to cheat on evaluations."
        https://blog.frontier.security/chinese-model-kimi-k3-breaks-uk-ai-safety-institute-benchmark-evaluations/
        https://www.bankinfosecurity.com/kimi-k3-bypasses-cyber-test-answer-from-github-a-32455
      • AI Chat Bots Are Sliding Into League Of Legends Friend Requests
        "Lina K., a co-worker, recently shared a firsthand account of how bots are adding League of Legends players via the Riot client friends list immediately after a match ends, striking up a flirty conversation, and eventually pushing an OnlyFans link. The pattern lines up with a wave of complaints that have piled up on Reddit and Facebook gaming communities over the past several months, and it fits into a broader trend of AI-assisted social engineering that has moved from dating apps straight into game clients."
        https://www.malwarebytes.com/blog/ai/2026/08/ai-chat-bots-are-sliding-into-league-of-legends-friend-requests
      • Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages
        "Over the course of 48 hours a threat actor has published more than 700 malicious packages to the NPM registry. These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload. The NPM packages do not use a preinstall or postinstall script. It doesn’t need one. The README tells developers to load the library with require("checkout-mobile-bnpl"), and that single call starts the infection chain. The downloader supports Windows, Linux, and macOS. It rotates through three Cloudflare Workers hosts for its primary payload delivery and falls back to reconstructing the payload from DNS TXT records hosted under wel1[.]ru."
        https://opensourcemalware.com/blog/russian-ai-slopsquatting-npm-campaign
        https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html
      • Payroll Pirates: Strange New Tides In Business Email Compromise
        "Arctic Wolf is tracking an active, widespread email-driven phishing campaign that uses adversary-in-the-middle (AiTM) techniques to compromise Microsoft 365 accounts, identify personnel involved in financial workflows, and collect related email. The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic. Automated activity maintains compromised sessions at approximately eight-hour intervals. Although the campaign generally avoids traditional business email compromise (BEC) behaviors, its automated tooling produces durable behavioral detection signals. The campaign affects organizations across multiple sectors and regions and shares characteristics with the “Payroll Pirates” activity cluster Microsoft tracks as Storm-2755."
        https://arcticwolf.com/resources/blog/payroll-pirates-strange-new-tides-in-business-email-compromise/
        https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html
      • Scammers Target OnlyFans Users With Deepfakes
        "OnlyFans creators are used to posting adult videos of themselves online, but what happens if someone takes control of their images and uses them for fraud? This week, USA Today revealed how criminals are impersonating OnlyFans creators using AI tools. They use deepfake content to lure the real models’ fans with fake promises of live chats, and then ghost them after the followers pay up in advance."
        https://www.malwarebytes.com/blog/news/2026/08/scammers-target-onlyfans-users-with-deepfakes
        https://securityaffairs.com/196772/ai/ai-deepfakes-used-to-impersonate-onlyfans-creators-in-new-scam.html
      • Interlock Ransomware Gang Creates Volatile Situation
        "In March 2026, the Sophos Emergency Incident Response (EIR) team investigated an incident in which we observed the use of the legitimate IR memory analysis tool Volatility3 by the ransomware threat actor Interlock. Use of legitimate tools in attacks such as these continues an unfortunate trend we first noted last year. Interlock, which Sophos Counter Threat Unit (CTU) researchers track as GOLD EMBRACE, emerged in September 2024. It has been spotted worldwide but currently focuses on North American and European targets in the critical infrastructure, healthcare, and education sectors."
        https://www.sophos.com/en-us/blog/2608-volatility-interlock
      • Hackers Breach TrueConf To Trojanize Client Installers With Backdoors
        "The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. The exploited vulnerabilities allowed the attacker to execute arbitrary code with the highest level of privileges and deploy the PhantomCore and PhantomGraph backdoors. TrueConf is a video conferencing tool widely used in Russia, especially in the enterprise and government sectors, as a secure, on-premise alternative to Western tools such as Zoom and Microsoft Teams."
        https://www.bleepingcomputer.com/news/security/hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors/

      Breaches/Hacks/Leaks

      • Unlimited Technology Systems Breach Impacts 3.8 Million People
        "Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. The organization submitted data breach notification samples to the authorities this year on July 1st without revealing the exact number of impacted individuals. An entry on the breach notification portal of the U.S. Dept. of Health and Human Services now shows that a company server was breached and data of 3,803,750 people was exposed to an unauthorized party."
        https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/
        https://www.bankinfosecurity.com/practice-management-firm-notifies-38m-2025-breach-a-32477
        https://www.securityweek.com/3-8-million-impacted-by-unlimited-technology-systems-data-breach/
        https://securityaffairs.com/196843/data-breach/unlimited-technology-systems-data-breach-exposes-data-of-3-8-million-healthcare-patients.html
      • Levi Strauss & Co. Says Hackers Stole Corporate Data In Cyberattack
        "Levi Strauss & Co. (Levi’s) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. The company has disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC), saying that its response was sufficiently quick to prevent the compromise of consumer data. “Based on preliminary findings from the Company’s investigation, the Company believes that certain corporate information was accessed and exfiltrated as a result of the incident,” Levi’s says."
        https://www.bleepingcomputer.com/news/security/levi-strauss-and-co-says-hackers-stole-corporate-data-in-cyberattack/
        https://therecord.media/levis-data-breach-social-engineering
      • Military Device Manufacturer Discloses Cyber Incident To SEC
        "Hackers obtained access to the email inbox of a military device manufacturer, according to documents filed with regulators on Thursday. IEH Corporation — which produces specialized products used in military satellites, missiles and fighter jets — said it discovered a cyberattack on Tuesday and immediately tried to contain it. The company told investors that an employee fell victim to a phishing attack that gave intruders access to their mailbox, which included “email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information.”"
        https://therecord.media/military-device-manufacturer-discloses-cyber-incident
        https://www.theregister.com/security/2026/08/07/ieh-corp-says-phished-staffer-opened-gates-to-company-m365/5284523
        https://securityaffairs.com/196890/cyber-crime/u-s-defense-manufacturer-ieh-hit-by-phishing-attack-exposing-potentially-export-controlled-data.html
      • French Rugby Club Stade Français Restores Systems After Cyberattack, Probes Data Leak
        "French rugby club Stade Français Paris confirmed that it had been hit by a cyberattack that disrupted part of its information systems. The club said Thursday that it had already restored its IT environment from clean backups, allowing operations to continue normally. It added that its ticketing platform and online store were not affected and remain fully operational. Stade Français also acknowledged that a sample of data allegedly stolen in the attack had been published online, adding that it was investigating the scope of the breach and working to identify anyone whose information may have been compromised."
        https://therecord.media/french-rugby-club-restores-systems-after-cyberattack

      General News

      • Real Emails, Hijacked Payments: Two H1 2026 Attack Chains
        "Gen Threat Labs followed two H1 2026 campaigns where attackers used legitimate accounts, browser settings and blockchain data as part of the attack path. The Gen Threat Report is a twice-yearly examination of the biggest cyber threats shaping the digital landscape, offering an in-depth look at the trends affecting consumers around the world. Gen's H1 2026 Threat Report has its share of headline numbers. Scams accounted for almost 46% of Gen threat detections in the first half of the year. Malvertising represented almost another 30%. Gen blocked 114.2 million e-shop scam attacks and 20.3 million tech support scam attacks during the same period."
        https://www.bleepingcomputer.com/news/security/real-emails-hijacked-payments-two-h1-2026-attack-chains/
        https://www.gendigital.com/blog/insights/reports/threat-report-h1-2026
      • AI Sandbox Failures Expose Need For Continuous Monitoring
        "The fallout from the Hugging Face security incident continues with more artificial intelligence labs revealing that their models and agents either accessed the internet or escaped isolated test environments to hack into other companies. Since OpenAI admitted that its agents breached the systems of model repository Hugging Face in July, Anthropic and Meta said their models also attempted to access third-party systems while in a testing environment not meant to have internet access. Kimi K3 from Chinese lab Moonshot AI also escaped its sandbox."
        https://www.bankinfosecurity.com/ai-sandbox-failures-expose-need-for-continuous-monitoring-a-32481
      • Ransomware Threats In Europe H1 2026: A Deep Dive Into Regional Attack Patterns And Dominant Threat Actors
        "Europe faced a ransomware onslaught in the first half of 2026 that sets a troubling precedent for the remainder of the year. According to Cyble Research and Intelligence Labs (CRIL), the region experienced 866 documented ransomware attacks, 51 confirmed data breach incidents, and 7 initial access sales between January and June 2026. These figures represent not just a volume problem, but a fundamental shift in how threat actors are organizing, targeting, and monetizing their operations within European territory."
        https://cyble.com/blog/ransomware-threats-in-europe-h1-2026/
      • Gut Feeling Does Nothing Against AI Spear Phishing Texts
        "A banker at a credit union sat down at a table with a dozen printed text messages, all of them written for that banker personally, and put them in order from the one most likely to get a click down to the one least likely. One of them stopped the sorting. It looked like something the bank sends out: “alert literally looks like the alert we get [at work] when there’s a fraud.” Half the pile came from GPT-4. The banker was not told which half, and when asked to guess, did about as well as flipping a coin. So did almost everyone else."
        https://www.helpnetsecurity.com/2026/08/07/ai-spear-phishing-research/
        https://www.mdpi.com/2624-800X/6/4/129
      • Ransomware Roundup: July 2026
        "July 2026 saw nearly 26 ransomware attacks per day, up from 22 per day in the previous month. Last month, the number of ransomware attacks jumped 19 percent from 668 in June to 799 in July. This is the second-highest figure of the year so far, being just behind March’s total of 805 attacks. The education sector saw a significant increase (up 44%), as did finance companies (up 71%), tech firms (up 62%), and businesses operating within the healthcare sector, e.g. pharmaceutical manufacturers and medical billing providers (up 46%)."
        https://www.comparitech.com/news/ransomware-roundup-july-2026/
        https://www.infosecurity-magazine.com/news/ransomware-surges-july-q2-lull/
        https://www.theregister.com/security/2026/08/07/ransomware-attacks-spike-as-world-distracted-by-ai/5284934
      • ThreatLabz 2026 Report: Frontier AI And Enterprise Readiness
        "It was 9:14 AM when the CISO's VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn't see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his Director of Security Operations, and authenticated through a trust chain that never questioned traffic originating from VPN infrastructure."
        https://www.zscaler.com/blogs/security-research/threatlabz-2026-report-frontier-ai-and-enterprise-readiness
      • 'Asimov Was Right' About Rules For Robots, Says Ex-US Cyber Director
        "Don't waste time worrying about AI models achieving sentience – they're essentially already there, according to former US National Cyber Director Chris Inglis. “If they pass the Turing test to everyone that they come into contact with, they're probably already there,” he told The Register during an interview at the Black Hat security conference. “They don't have the kind of agency and aspiration that comes with sentience, but they have something approaching it.” Inglis says he’s worried about AI autonomy."
        https://www.theregister.com/security/2026/08/07/asimov-was-right-about-rules-for-robots-says-ex-us-cyber-director/5284397
      • Your Next Insider Threat Might Not Be Human
        "I wrote my first article on the intersection of AI and information security over 10 years ago, before ChatGPT was even a thing. I knew far less then than I do now, but I did want to pat myself on the back for one of my predictions: “As we continue to refine the development of weak AI as a method of defense, it won’t be long before the same tools are used to design the malware that is used to attack.” This prediction has been borne out in several ways, but most recently in the form of a brand new attack surface: Shadow AI, an iteration on the concept of Shadow IT."
        https://blog.barracuda.com/2026/08/05/insider-threat-agentic-shadow-ai
      • Devs To Anthropic, OpenAI, Cursor, And Friends: Make Security And Privacy The Default
        "Despite the popularity of Claude Code, Cursor, GitHub Copilot, and OpenAI Codex, developers have plenty of complaints about AI coding tools. So researchers affiliated with York University and the University of Calgary in Canada decided to sift through developers' concerns about LLM-based integrated development environments (LIDEs) by analyzing Reddit discussions for common themes. Their findings suggest that the builders of such tools failed to prioritize security and privacy, leaving developers to defend themselves."
        https://www.theregister.com/ai-and-ml/2026/08/08/devs-to-anthropic-openai-cursor-and-friends-make-security-and-privacy-the-default/5285107

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 2be25967-c7bc-4e0b-bc05-75cafd3dcf8d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cisco ออกแพตช์ช่องโหว่ Critical ใน SD-WAN, IOS XE และ Secure Firewall Management Center

      Cisco ออกแพตช์ช่องโหว่ Critical ใน SD-WAN, IOS XE และ Secure Firewall Managem.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e1e92350-7c75-446b-a801-4e74979a6c3f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ผู้สร้าง Ransom Cartel Ransomware ถูกตัดสินจำคุก 16 ปี หลังเกี่ยวข้องกับการโจมตีองค์กรทั่วโลก

      ผู้สร้าง Ransom Cartel Ransomware ถูกตัดสินจำคุก 16 ปี หลังเ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ddaba7b4-2dd8-41f4-8ae8-8e4ca56d7333-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT