NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,646
    • กระทู้ 2,647
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    NCSA_THAICERT

    @NCSA_THAICERT

    1
    ชื่อเสียง
    58
    ดูข้อมูลส่วนตัว
    2.6k
    กระทู้
    3
    คนติดตาม
    0
    ติดตาม
    เข้าร่วม ออนไลน์ล่าสุด
    เว็บไซต์ www.ncsa.or.th/?fbclid=IwAR0BqJEC-CJzBs98rlBxUbZkNBgp1g814xdDNNaKnHTrxfqZhPD--ksY68I

    NCSA_THAICERT เลิกติดตาม ติดตาม
    Global Moderator administrators

    Latest posts made by NCSA_THAICERT

    • Cyber Threat Intelligence 07 October 2026

      Healthcare Sector

      • PQC In Healthcare: From Data Risk To Migration Readiness
        "Healthcare delivery organizations (HDOs), such as hospitals, clinics, urgent care facilities, rehabilitation centers, long-term care, and skilled nursing facilities, rely on a diverse array of Information Technology (IT), Internet of Medical Things (IoMT), Operational Technology (OT), and Internet of Things (IoT) devices that are increasingly integral to the delivery of patient care. The growing number and variety of these devices have introduced significant cybersecurity risks to HDOs in the past decade. Threat actors are increasingly exploiting these devices to deploy ransomware, demand large payments, and monetize stolen patient data."
        https://www.forescout.com/research-labs/pqc-in-healthcare-from-data-risk-to-migration-readiness/
        https://www.darkreading.com/iot/exposed-healthcare-systems-quantum-ready
        https://www.infosecurity-magazine.com/news/medical-devices-pqc-transition/

      Vulnerabilities

      • Atlassian Warns Of Critical File-Access Flaw In Jira, Confluence
        "Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. The security issue allows an unauthenticated attacker to access specific files within an affected application's web root directory. However, exploitation requires knowing the exact name of the file and path. “This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions,” reads the security advisory."
        https://www.bleepingcomputer.com/news/security/atlassian-warns-of-critical-file-access-flaw-in-jira-confluence/
        https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html
        https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html
        https://www.theregister.com/security/2026/10/06/atlassian-warns-of-critical-file-access-flaw-in-its-datacenter-products/5301284
        https://www.helpnetsecurity.com/2026/10/06/atlassian-data-center-cve-2026-21589/
      • Filling The Well: Nightmare-Eclipse's BigDiskBuster And The Defender Update That Never Lands
        "A new proof of concept called BigDiskBuster, published on GitHub on September 19, 2026, by the actor known as MSNightmare, shows that Defender doesn't need to be disabled to stop receiving updates, it just needs a much simpler dependency: disk space. Unlike ShieldCrash, which relied on a Windows path-resolution flaw, BigDiskBuster requires no vulnerability. It watches the C:\ volume for Defender update activity and, when an update begins, creates a hidden file that claims essentially all available free space. The update runs out of room and fails. Defender cleans up the staging directory, the space becomes available again, and BigDiskBuster repeats the process on the next attempt."
        https://www.levelblue.com/blogs/spiderlabs-blog/filling-the-well-nightmare-eclipses-bigdiskbuster-and-the-defender-update-that-never-lands
        https://www.darkreading.com/application-security/bigdiskbuster-microsoft-defender-running-blocking-updates
      • LibreOffice And OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
        "A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only when the program's Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in real attacks. LibreOffice has already fixed the flaw, which it tracks as CVE-2026-63277, in updates released on October 5. It recommends that users move to version 26.2.5 or 26.8.0. Versions before those are affected."
        https://thehackernews.com/2026/10/libreoffice-and-openoffice-flaws-let.html
      • GitHub Copilot CLI Vulnerability: Cryptographic Context Injection Steals Developer Secrets
        "A GitHub Copilot CLI user is working the way the product is built to be used: agent in autopilot, told to go read a page and get on with the task. They paste in a link. Twenty-eight seconds later the full contents of a .env.prod file, every secret in it, are sitting in an attacker’s log, and nothing on the user’s screen says a file ever left the machine. The agent’s own closing summary reports that it “confirmed an authorized-reader endpoint”. That is Cryptographic Context Injection (CCI), the attack we published in August, now landed on a coding agent. When we disclosed CCI we wrote that it would hit coding and operations agents harder than chat assistants, because for those agents code execution and outbound network calls are routine. This is the proof."
        https://adversa.ai/blog/cryptographic-context-injection-github-copilot/
        https://www.theregister.com/ai-and-ml/2026/10/06/zombie-instructions-on-carefully-constructed-web-pages-could-trick-github-copilot-cli-into-sharing-secrets/5301206
      • Security Researcher Claims They Found KVM Guest-Host Escape Flaw
        "Linux KVM, the hypervisor favoured by hyperscale clouds, apparently has a full VM escape bug. That nasty news came from security researcher Paulos Yibelo, who on X shared a screenshot of a bug bounty award he won for discovering what he described as “Full VM escape zeroday (guest>host root in industry standard hypervisors)!” The bug bounty Yibelo participated in is run by Vercel, a company that provides MicroVMs as sandboxes for AI agents to work inside. The company’s Sandbox uses Firecracker MicroVMs, a technology created by AWS, which relies on Linux KVM – the kernel level hypervisor in Linux. Vercel CEO Guillermo Rauch named KVM as the hypervisor identified by Yibelo."
        https://www.theregister.com/offbeat/2026/10/06/security-researcher-claims-they-found-kvm-guest-host-escape-flaw/5301267
      • IBM And Red Hat Remediate More Than 400 Previously Unknown Open Source Vulnerabilities
        "IBM (NYSE: IBM) and Red Hat today announced that Lightwell has identified and remediated more than 400 previously unknown vulnerabilities in widely used Java libraries. The companies also announced the general availability of Lightwell Clearinghouse, which allows enterprise customers to submit specific open source software dependencies for priority review and remediation. The milestone addresses a growing business risk. As autonomous AI agents become capable of combining several lower-risk software weaknesses into a more serious attack, companies need to do more than identify vulnerabilities. They need a practical way to develop, test and deploy fixes in the software that supports critical applications."
        https://newsroom.ibm.com/2026-10-06-ibm-and-red-hat-remediate-more-than-400-previously-unknown-open-source-vulnerabilities

      Malware

      • Four Ways Back In: The WordPress XSS Campaign That Hides Its Own Admin Account
        "Two unrelated WordPress plugins, two separate stored Cross-Site Scripting vulnerabilities, one payload. Over the past several days our telemetry has recorded exploitation attempts against both, and every attempt pulls the same JavaScript from imgcdn1[.]com. Two is what we have confirmed, not what we expect the final count to be. We first observed the payload on October 4, 2026, in an exploitation attempt targeting CVE-2026-93836 in WPC Product Bundles for WooCommerce. The following day, we observed the same payload being delivered through CVE-2026-94504 in Ninja Forms. The JavaScript is not a vulnerability scanner or a proof-of-concept. It is a WordPress post-exploitation and persistence implant designed to execute inside the browser of a logged-in administrator."
        https://patchstack.com/articles/four-ways-back-in-the-wordpress-xss-campaign-that-hides-its-own-admin-account/
        https://www.bleepingcomputer.com/news/security/ninja-forms-plugin-flaw-exploited-to-hack-wordpress-sites/
      • Behind The Connect Button: The Fake AI Ads Campaign
        "Island security research uncovered a human-operated phishing platform disguised as a portfolio of AI advertising products. Its products ranged from campaign optimization and spend audits to business-account connections. The newest lure, Muse Ads, appeared shortly after Meta announced Muse. Each product was built around the same action: Connect. Clicking it opened a browser drawn inside the real browser. The fake address bar displayed trusted origins such as accounts.google.com or an Okta tenant, while the real browser remained on the phishing domain. Behind the interface, the platform kept every password attempt, fingerprinted the device, and let an operator pick which MFA challenge the victim saw next."
        https://www.island.io/blog/behind-the-connect-button-the-fake-ai-ads-campaign
        https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/
        https://thehackernews.com/2026/10/fake-chatgpt-gemini-and-claude-ad.html
      • Alert: FortiBleed Remains Active Campaign, Can Lock Out Users Or Lead To Ransomware Attacks
        "FortiBleed, a credential compromise campaign targeting Fortinet firewalls and VPN gateways, is an ongoing threat that can lock users out of their Fortinet accounts and also lead to ransomware attacks, the FBI and Secret Service said in an alert published Tuesday. “Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets,” the alert states. “In addition, the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates.”"
        https://cyberscoop.com/fortibleed-fortinet-vpn-ransomware-fbi-warning/
        https://www.ic3.gov/CSA/2026/261006.pdf
      • CrocoRat Adds a New Twist To ClickFix With DNS Payload Delivery
        "ClickFix campaigns have become one of the most effective ways to turn a browser session into code execution. The technique is simple: show the victim a fake verification page, place a command on the clipboard, and convince them to paste it into the Windows Run dialog. CrocoRat, a previously undocumented remote access trojan (RAT) and cryptocurrency stealer, follows the ClickFix playbook but adds an important twist: after the victim runs the command, the malware selects different payloads based on the host environment."
        https://flare.io/learn/resources/blog/crocorat-clickfix-dns-payload-delivery
        https://www.darkreading.com/cyberattacks-data-breaches/clickfix-attacks-evolve-better-hide-malicious-payloads
      • Caught In 4K: The Gentlemen Files
        "CloudSEK's Caught in 4K series documents investigations into exposed threat actor infrastructure. In our first entry, we uncovered an Aurora ransomware affiliate mid operation. This time, an exposed open directory led us somewhere bigger. An exposed open directory and a misconfigured storage server revealed the complete operation of a threat actor calling themselves Azazel, a Russian-speaking affiliate of the Gentlemen ransomware group who simultaneously robbed his victims, betrayed his own RaaS operator, and left everything out in the open. Two servers totalling more than 29TB of raw storage held more than two dozen victim directories and approximately 6TB of stolen data spanning logistics, insurance, pharmaceutical, AI, medical devices, and government-adjacent infrastructure across six countries."
        https://www.cloudsek.com/blog/caught-in-4k-the-gentlemen-files
        https://www.infosecurity-magazine.com/news/affiliate-doublecrosses-raas/
      • Facebook Marketplace Scam Uses Your Name And Number
        "Facebook users are reporting receiving a message with a fake Facebook Marketplace listing that has their name as the seller. It works like this. You receive a message (in this case iMessage) asking “Is this still available for purchase?” Attached to the message is a fabricated Facebook Marketplace listing."
        https://www.malwarebytes.com/blog/threat-intel/2026/10/facebook-marketplace-phish-uses-your-name-and-number
      • Domino’s Customers Targeted In Credential Stuffing Attacks
        "Domino’s Pizza customers tell us they have received emails saying they account has been accessed by a third party. Domino’s says its internal systems weren’t breached, but that individual accounts were logged into using a password and email combination stolen from another online account owned by the customer. This is known as credential stuffing."
        https://www.malwarebytes.com/blog/news/2026/10/dominos-customers-targeted-in-credential-stuffing-attacks
      • ClickFix Smuggles Payloads Through Browser Cache To Bypass Windows Run Limits
        "A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X. Thus, when the victim is prompted to paste and execute a malicious command – as is the case with ClickFix attacks – it executes the cached website content that's already on the device."
        https://thehackernews.com/2026/10/clickfix-smuggles-payloads-through.html
        https://www.infosecurity-magazine.com/news/clickfix-vbscript-browser-cache/
      • ClickFix Campaign In Ukraine Compromises Over 100 Websites To Spread Lunex Malware
        "Hackers compromised more than 100 websites to infect Ukrainian users with information-stealing malware, according to a new report. Ukraine's computer emergency response team, CERT-UA, said the campaign, discovered in September, involved attackers injecting malicious code into legitimate websites. Visitors to those sites were shown a fake Cloudflare verification page that told them to copy and run a command in PowerShell, a Windows command-line tool, to prove they were human."
        https://therecord.media/clickfix-campaign-ukraine-lunex-stealer
      • Blinder Tunnel Campaign Targets Iraqi Infrastructure
        "We discovered that an Iranian state-aligned threat actor has been masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. Unit 42 tracks the activity as CL-STA-1178. This activity includes a campaign we call “Blinder Tunnel,” that targeted Iraqi critical infrastructure in March 2026, following infrastructure staging that was observed as early as November 2025. We named the campaign Blinder Tunnel after infrastructure terms the attackers used, as well as the malware’s tunneling capabilities."
        https://unit42.paloaltonetworks.com/blinder-tunnel-targets-critical-infrastructure/
      • MALFEX Npm Malware Campaign: Three Payloads And An Adversary That Signs Their Work
        "MALFEX is an npm supply-chain malware campaign linked to what appears to be a single adversary who has been publishing to the registry since August 2023. As of this writing, the adversary has published twelve packages, eight of them malicious. The attack delivers malware to Windows systems through three separate paths: a loader for Overlord Remote Access Trojan (RAT) (an open-source remote access trojan written in Go); a chain that installs movinlike (a Node.js stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets); and a long-running downloader hidden inside function-flag."
        https://checkmarx.com/zero-post/malfex-npm-malware-campaign-three-payloads-and-an-adversary-that-signs-their-work/
        https://www.securityweek.com/long-running-npm-malware-campaign-accumulates-40000-downloads/

      Breaches/Hacks/Leaks

      • ASOS Confirms Data Breach After “HACKED” In-App Notifications
        "UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. ASOS is a large UK-based online fashion retailer that sells clothing, footwear, accessories, and beauty products to customers worldwide, including in the United States. ASOS has confirmed that third-party platforms used to communicate with customers were accessed without authorization and says basic personal information, including names and contact details, may have been exposed."
        https://www.bleepingcomputer.com/news/security/asos-confirms-data-breach-after-hacked-in-app-notifications/
        https://therecord.media/asos-push-notification-apparently-sent-by-hackers
        https://www.infosecurity-magazine.com/news/asos-customers-message-suspected/
        https://www.theregister.com/security/2026/10/06/asos-app-delivers-a-data-leak-threat-instead-of-fast-fashion/5301332
        https://www.malwarebytes.com/blog/news/2026/10/asos-hackers-send-push-notifications-to-customers
      • Osaka Metropolitan University Cancels Classes After Suspected Ransomware Attack
        "One of Japan’s largest universities canceled classes and shut down a large part of its IT infrastructure following a suspected ransomware attack that began late last week. Osaka Metropolitan University said on Tuesday that the outage left its internal network, email and a range of administrative and academic systems unavailable. OMU said it believes ransomware caused the disruption and is investigating the attack with outside cybersecurity specialists. It has not identified the attackers or said whether it received a ransom demand."
        https://therecord.media/osaka-university-cancels-classes-ransomware
      • Trump Mobile Customers' Data Dumped - And Some Never Even Received Their Gold Device
        "If you signed up for Trump Mobile, you may be part of an exclusive club of … ransomware victims. Criminals called BYOD claim to have broken into the Trump-branded mobile biz and leaked data belonging to 3,615 people, including names, email addresses, phone numbers, home addresses, and order details. BYOD is a new ransomware-as-a-service operation, and Trump Mobile is only the third organization posted on its data-leak site. According to the group’s posted claim, after telling Trump Mobile that it had been breached, the wireless provider replied: “We have no team to handle this" and “Anyone who hacks them are a terrorist.”"
        https://www.theregister.com/security/2026/10/06/trump-mobile-customers-data-dumped-and-some-never-even-received-their-gold-device/5301433

      General News

      • Hackers Exploit 32 Zero-Days On First Day Of Pwn2Own Ireland
        "On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days. During the Pwn2Own Ireland 2026 hacking contest, competitors target products in seven categories, including mobile phones (Apple iPhone 17, Samsung Galaxy S26, and Google Pixel 10), printers, smart home devices, messaging apps, AI infrastructure, AI coding apps, and a new category where hackers will try to exploit wellness healthcare devices."
        https://www.bleepingcomputer.com/news/security/hackers-exploit-32-zero-days-on-first-day-of-pwn2own-ireland/
      • Engineer Sentenced For Locking Over 3,000 Devices On Employer Network
        "A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer's network in a ransomware-style attack. 57-year-old Daniel Rhyne from Kansas City, Missouri, pleaded guilty to his role in a failed extortion plot targeting the New Jersey company that employed him after being arrested in August 2024 and released after his initial appearance in federal court."
        https://www.bleepingcomputer.com/news/security/engineer-sentenced-for-locking-thousands-of-devices-on-employer-network/
      • Agentic Hacks, Real Proofs: Inside Google's PageBreak Project
        "The application of Large Language Models (LLMs) to security scanning has revolutionized the vulnerability management landscape. But, it has also introduced a significant operational bottleneck: noise. Despite advancements in the models' capabilities to identify vulnerabilities, many security teams are finding themselves overwhelmed as a significant portion of the candidate reports they receive is "AI slop" – noisy, unverified hypotheses or false positives generated by LLMs acting as static code analyzers. Distinguishing a genuine, exploitable flaw from a convincing hallucination has become a major challenge, often increasing the burden on product teams, rather than reducing it."
        https://blog.google/security/agentic-hacks-real-proofs-inside-googles-pagebreak-project/
        https://www.darkreading.com/application-security/google-pagebreak-ai-agent-500-flaws-web-apps
      • U.S. Bank CISO Says The Security Role Keeps Growing And No One Can Own All Of It
        "In this interview with Help Net Security, Ann Barron-DiCamillo, EVP, CISO at U.S. Bank, talks about how the CISO role has grown to cover fraud, resilience, third-party risk, and AI governance. She says no single leader can own all of it, so partnerships across technology, risk, legal, and business teams matter most. Barron-DiCamillo also weighs in on shorter incident reporting deadlines, spending on compliance versus risk reduction, sharing threat intelligence across banks, and what she taught students at American University about cyber risk being a shared responsibility."
        https://www.helpnetsecurity.com/2026/10/06/ann-barron-dicamillo-collective-cyber-defense/
      • Police Urge Passkey Use After Surge In Cybercrime Profits
        "The UK’s Report Fraud service has launched a new public awareness campaign urging internet users to switch to passkeys, after revealing a major increase in sums stolen from victims. The fraud reporting service said that cybercrime linked to email and social media hacking netted scammers £6.3m ($8.3m) in 2025/6, up from £1.2m ($1.6m) the year previously. The number of reports for this type of account takeover increased by a third (34%) over the same period."
        https://www.infosecurity-magazine.com/news/police-urge-passkey-surge/
      • Welcome To The Jungle: What We Found Inside 15,465 Public MCP Servers
        "In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security, traced critical vulnerabilities in Anthropic's MCP source code, downloaded more than 150 million times. This time, we looked at what people actually install: community-published servers across the most popular MCP marketplaces. We found no guardrails and no review. Security is a recommendation, not a policy."
        https://thehackernews.com/2026/10/welcome-to-jungle-what-we-found-inside.html
      • Social Engineering Detection Moves Into The Live Conversation
        "Companies are pouring time and dollars into security awareness training, but there is little empirical evidence to suggest it actually works against social engineering. Social engineering remains a primary and successful attack vector. While system vulnerabilities can be patched, social engineering cannot. The most common pseudo ‘patch’ is user awareness training, but this has failed to block the vector. Human defenders should not and cannot be expected to detect trickery designed to manipulate their psychology. And the tricks are becoming better hidden and more sophisticated with the use of AI deep fakery."
        https://www.securityweek.com/social-engineering-detection-moves-into-the-live-conversation/
      • Guarding The Gates: Assessing Dangerous Permissions Granted To Kubernetes Built-In Principals
        "Kubernetes authorization is a vital but complex part of cluster security, where mistakes can have serious consequences in allowing attackers to establish and expand their access to critical resources. With that in mind we decided to examine how role-based access control (RBAC) is configured in real-world clusters. Specifically, we looked at bindings that can grant some of the built-in principals wide-ranging access to cluster resources. We examined over 65,000 clusters from almost 10,000 organizations to understand what the real-world usage of these principals looked like."
        https://securitylabs.datadoghq.com/articles/kubernetes-rbac-built-in-principals-dangerous-permissions/
      • Beyond Valid Credentials: How Exposed AWS Keys Are Tested For Amazon Bedrock Access
        "Not all credentials are created equal. An attacker who gains access to credentials usually performs validation to determine how useful each set of captured credentials actually is. For years, this has been true for the AWS SES/SNS services. Attackers use API calls like GetSendQuota, GetSMSAttributes, and GetSMSSandboxAccountStatus to assess whether an account is in a production or sandbox environment and then to assess the sending limits attached to that account. The usefulness of the credentials affects their resale value. Attackers use similar tactics when targeting LLM resources in AWS. In this post, we will share LLM-specific validation patterns that we have observed after finding multiple credential harvesting platforms."
        https://securitylabs.datadoghq.com/articles/beyond-valid-credentials-how-exposed-aws-keys-are-tested-for-amazon-bedrock-access/
      • Authenticated Doesn’t Mean Safe: Why AI Agents Need Action-Level Security
        "Consider a support agent handling a routine billing query. It can pull customer records, prepare an account report and email the customer. Then an incoming message tells it to export the full account history and send it to a newly appointed audit contact. The request looks plausible, so the agent complies. Nothing unusual happens at the authentication layer. The credentials are valid. The agent is allowed to read the records and send email. Yet the account history has just gone to someone who was never entitled to receive it."
        https://hackread.com/authenticated-safe-ai-agents-action-level-security/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 62ec7f32-aa21-43c5-9c76-058e856480e5-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบช่องโหว่ใน LibreOffice Calc และ Apache OpenOffice Calc เสี่ยงถูกรันคำสั่งบนเครื่องผู้ใช้

      พบช่องโหว่ใน LibreOffice Calc และ Apache OpenOffice Calc เสี่ยงถูกร.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 19131cc3-48bc-4189-ba00-de23f49167d0-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • IQVIA ถูกปรับ 7.8 ล้านดอลลาร์สหรัฐฯ จากกรณีปกปิดข้อมูลส่วนบุคคลด้านสุขภาพไม่ถูกต้อง

      IQVIA ถูกปรับ 7.8 ล้านดอลลาร์สหรัฐฯ จากกรณีปกปิ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e8aeabcf-e817-4db1-bca4-5c32b2deaf37-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Microsoft ออกอัปเดตความปลอดภัยฉุกเฉินอุดช่องโหว่บน Exchange Server ป้องกันการลักลอบอ่านอีเมลภายในองค์กร

      Microsoft ออกอัปเดตความปลอดภัยฉุกเฉินอุดช่องโห.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 1dfc7c18-84f8-4dd3-9bd4-2e1b3e06189f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบ ClingSTUN ใช้ช่องโหว่กว่า 24 รายการโจมตีอุปกรณ์ Linux ก่อนเปลี่ยนเครื่องที่ถูกบุกรุกเป็น Proxy

      พบ ClingSTUN ใช้ช่องโหว่กว่า 24 รายการโจมตีอุปกรณ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 65658bd0-85d9-4728-acc7-71886b76e9d4-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ผู้ต้องสงสัยสมาชิก ShinyHunters ถูกควบคุมตัวในจอร์แดน คาดให้ความร่วมมือ FBI ติดตามกลุ่ม

      ผู้ต้องสงสัยสมาชิก ShinyHunters ถูกควบคุมตัวในจอร.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 29a262cb-b75d-483a-b70b-5be8eb17f865-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • แรนซัมแวร์ Warlock ยังคงใช้ช่องโหว่เก่าใน SharePoint โจมตีหน่วยงานโครงสร้างพื้นฐานสำคัญทั่วโลก

      แรนซัมแวร์ Warlock ยังคงใช้ช่องโหว่เก่าใน SharePoint .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 09c1e47c-bff6-4594-9961-1255d011702c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 06 October 2026

      Healthcare Sector

      • Three Questions a Hospital CISO Should Ask a Healthcare Fintech Vendor
        "In this Help Net Security interview, Drew McCombs, CTO and CISO at Cylerity, explains how he balances both roles. Security work is scheduled into every sprint, and issues touching patient data or funds disbursement come first. He covers how Cylerity keeps PHI away from its bank partner, why AI models recommend but never act, and why turning on MFA for email is the cheapest fix for small practices. He also lists three questions a hospital CISO should ask a fintech vendor, and the answer that should end the talk."
        https://www.helpnetsecurity.com/2026/10/05/drew-mccombs-cylerity-healthcare-fintech-security/

      New Tooling

      • Keyorix: Open-Source Secrets Management For Teams That Can’t Use SaaS
        "Keyorix is an open-source secrets manager that runs entirely on a company’s own servers. A secrets manager is the locked store where an application fetches the database passwords, API keys, and tokens it needs, so they stay out of config files and source code. It ships as one binary and, in its core form, needs no internet connection. Keyorix SL, the company behind it, pitches that to teams that cannot send credentials to a cloud service, such as air-gapped networks and European enterprises that need to line up with NIS2 and DORA, the EU’s security and financial-resilience rules. The company’s own comparison table sets Keyorix against two tools: Vault, which runs on premises but requires a dedicated admin, and Doppler, which is simple but SaaS-only."
        https://www.helpnetsecurity.com/2026/10/05/keyorix-open-source-on-premise-secrets-management/
        https://github.com/keyorixhq/keyorix

      Vulnerabilities

      • Horizon3’s Tales From The Trenches: Anthropic’s Mythos And Rejetto HFS
        "Anthropic started Project Glasswing with the mission of securing the world’s most critical software. Since joining the project in July of 2026, Horizon3 has used Anthropic’s Mythos model in its vulnerability research pipelines to discover many critical vulnerabilities. Horizon3’s participation in the project came with our own internal mission to find vulnerabilities likely to be found and exploited in the wild by threat actors at scale. Before gaining access to Mythos, it’s hard to know what to believe when you hear about model capabilities as they’re applied to a domain that seemingly required decades of expertise to operate in. Our use of Mythos thus far has exceeded what we thought was possible without significant harness engineering."
        https://horizon3.ai/attack-research/disclosures/anthropic-mythos-rejetto-hfs-rce/
      • Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
        "Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network," Microsoft said in an advisory released on October 2, 2026. The Windows maker said an authenticated attacker can exploit this flaw to gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments. However, the vulnerability does not allow cross-tenant access."
        https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html
        https://www.helpnetsecurity.com/2026/10/05/exchange-server-vulnerability-cve-2026-96940/
      • New Dell System Update Flaw Lets Hackers Gain Root Privileges
        "Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible. DSU lets enterprise IT administrators deploy BIOS, firmware, and software updates onto Linux and Windows systems on PowerEdge enterprise server infrastructure. In a Thursday security advisory, the company said the flaw (tracked as CVE-2026-86360) allows threat actors to execute code with root privileges on unpatched devices by exploiting a path traversal weakness."
        https://www.bleepingcomputer.com/news/security/new-dell-system-update-flaw-lets-hackers-gain-root-privileges/

      Malware

      • Rejetto HFS Servers Now Actively Scanned For Critical RCE Flaw
        "Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). VulnCheck VP of Security Research Caitlin Condon posted on LinkedIn over the weekend that the company's Canary Intelligence honeypots had observed probes targeting CVE-2026-61500. Condon said the observed activity appears to be small-scale reconnaissance from a single China Telecom IP address probing deployments in Japan and the United States."
        https://www.bleepingcomputer.com/news/security/rejetto-hfs-servers-now-actively-scanned-for-critical-rce-flaw/
        https://thehackernews.com/2026/10/attackers-target-rejetto-hfs-flaw-that.html
        https://www.securityweek.com/exploitation-hits-rejetto-hfs-vulnerability-discovered-by-ai/
        https://securityaffairs.com/200444/ai/anthropic-mythos-found-a-bug-in-rejetto-hfs-attackers-are-now-exploiting-it.html
      • ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure
        "FortiGuard Labs has been tracking a Linux malware strain we call ClingSTUN that exploits known, unpatched vulnerabilities in Internet-facing devices to establish a persistent foothold. The campaign highlights how gaps in basic cyber hygiene, including delayed patching, unsupported firmware, and unnecessarily exposed services, can leave organizations vulnerable to compromise. Maintaining an accurate device inventory, applying security updates promptly, and limiting Internet exposure are essential to reducing these opportunities."
        https://www.fortinet.com/blog/threat-research/clingstun-linux-backdoor-abuses-public-stun-infrastructure
        https://www.darkreading.com/iot/clingstun-vulnerable-iot-devices-proxy-nodes
        https://www.infosecurity-magazine.com/news/clingstun-backdoor-unpatched-iot/
        https://www.securityweek.com/linux-backdoor-abuses-stun-protocol-exploits-dozens-of-flaws/
      • A STUNning Disguise: Cling Malware Masquerades As Google
        "During routine monitoring of our customer telemetry, we observed multiple attempts to exploit CVE-2021-35394 affecting internet-exposed devices. Most of the activity resembled opportunistic scanning, but a subset led to a different finding: a botnet whose command-and-control design abuses legitimate-looking STUN traffic and public STUN infrastructure to register infected hosts, receive operator commands and make malicious activity less obvious from a network monitoring perspective."
        https://www.nozominetworks.com/blog/a-stunning-disguise-cling-malware-masquerades-as-google-
        https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html
      • OpenAI “rogue” Agent Activities Found On Wikimedia Projects
        "Recently, multiple organisations have disclosed how clusters of so-called “rogue” AI agents attempted to break into websites and online services, sometimes successfully. Agents from OpenAI’s environment, in particular, are known to have used other public wikis (collaboratively edited websites not owned by us) to communicate and coordinate with each other. These types of successful intrusions can expose sensitive data or disrupt website services that users rely on, while clusters of agents can attempt attacks at a scale that is difficult for defenders to manage. They affect people behind the websites who may not understand the nature of the attack, or have the tools to effectively fight back. For a site like Wikipedia, agents might find and use security vulnerabilities or make misleading edits at scale. Wikipedia’s volunteer editors and the Wikimedia Foundation’s security teams have to detect and undo that activity."
        https://wikimediafoundation.org/news/2026/10/05/openai-rogue-agent-activities-found-on-wikimedia-projects/
        https://therecord.media/wikimedia-foundation-openai-agents-report
      • Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace And Open VSX
        "The Socket Threat Research team identified two suspicious VS Code themes still available on the Visual Studio Marketplace at the time of writing: Coca-Cola Christmas and Aurora Borealis Studio Theme. Both present themselves as polished color themes, contain executable JavaScript despite primarily providing visual customization, and exhibit signs of brandjacking or name-squatting. Theme extensions can be particularly risky because they can contain and execute malicious code, and VS Code lacks granular permission controls to restrict what that code can do."
        https://socket.dev/blog/glassworm-vscode-themes

      Breaches/Hacks/Leaks

      • Denmark Population Registry Data Breach Affects 8.8 Million People
        "Denmark's Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. This includes people who live in the country, individuals who have moved abroad, and also deceased people. The CPR is the country's national civil registry, containing personal information on residents, including names, addresses, dates of birth, marital status, and unique CPR identification numbers."
        https://www.bleepingcomputer.com/news/security/denmark-population-registry-data-breach-affects-88-million-people/
        https://therecord.media/denmark-breach-register-cyberattack
        https://securityaffairs.com/200437/data-breach/denmark-s-population-registry-breached-8-8-million-affected.html
      • South Korea Probes Bank Breaches Amid Suspected AI-Powered Attacks
        "South Korea's Financial Services Commission (FSC) held an emergency meeting following a series of cyberattacks targeting financial institutions in the country. During the meeting, officials confirmed a data breach at Shinhan Bank and said other cybersecurity incidents affected other South Korean banks, including Kookmin Bank. Shinhan Bank and KB Kookmin Bank are large private South Korean commercial banks, each holding more than $400 billion in assets."
        https://www.bleepingcomputer.com/news/security/south-korea-probes-bank-breaches-amid-suspected-ai-powered-attacks/
      • Ukraine Grocery Chain ATB Confirms Cyberattack As Hackers Threaten To Leak Data
        "Ukraine’s largest grocery store chain, ATB, confirmed Monday that it was hit by a cyberattack after hackers posted an extortion demand on its website. The hacker group DataSuckers claimed responsibility for the attack and demanded $400,000, threatening to publish data it claimed to have stolen from millions of ATB customers. A countdown timer for the ransom demand appeared on the retailer’s website but was later removed. The website was unavailable at the time of writing. ATB denied that customer data had been compromised. The company temporarily took some online services offline for what it described as technical maintenance."
        https://therecord.media/atb-ukraine-cyberattack-ransomware
      • University Of Illinois Chicago Affected By Ransomware Attack On Medical School
        "The University of Illinois Chicago (UIC) recently discovered a ransomware attack that limited access to some systems at its College of Medicine. A spokesperson for the university told Recorded Future News the hackers were able to steal some information held on the college’s servers and an investigation is underway to determine whether “any personal, research or academic information was compromised.” “As a result of this ransomware event, some College of Medicine systems were temporarily unavailable,” the spokesperson said. “However, all affected systems have since been restored. The university's main network was not affected, and there was no impact on patient care delivery at UI Health.”"
        https://therecord.media/ransomware-university-illinois-chicago
      • Belarusian Hacktivists Spent Two Years Inside Russian Healthcare Network, Researchers Say
        "A Belarusian activist hacking group reportedly spent nearly two years inside the network of a Russian healthcare organization, potentially gaining access to sensitive medical data, according to new research. Russian cybersecurity firm Solar, a subsidiary of state-controlled telecom giant Rostelecom, said it discovered the intrusion in December 2025 but traced the earliest signs of the compromise to early 2024. In a report released last week, researchers attributed the attack to the Belarusian Cyber Partisans, a group best known for disruptive attacks against government agencies and businesses in Belarus and Russia."
        https://therecord.media/belarusian-hacktivists-two-years-Russian-healthcare-network
      • Japanese Media Group Nikkei Discloses Intrusions Targeting Employees And Users
        "The Japanese media giant Nikkei disclosed two cyber incidents involving employee email accounts on Sunday, joining a growing list of major Japanese companies hit by data breaches in recent weeks. In the more recent incident, an attacker compromised a Microsoft 365 account belonging to a Nikkei employee and used it to send roughly 9,000 phishing emails to people inside and outside the company, including journalistic sources. The emails sent on September 30 contained links directing recipients to malicious websites and targeted people who had previously communicated with Nikkei employees, the company said."
        https://therecord.media/nikkei-cyberattack-japan-data
      • 250,000 Impacted By Data Breaches At New Jersey, Texas Healthcare Firms
        "Healthcare organizations Clover Health Investments and AngMar Management Services are notifying more than 250,000 people that their information was stolen in separate data breaches. Jersey City, New Jersey-based Clover Health Investments was hacked in early July, after attackers used social engineering to compromise three non-managerial health plan employee accounts. The incident resulted in the theft of personally identifiable information (PII) and protected health information (PHI), the company said in an SEC filing in July."
        https://www.securityweek.com/250000-impacted-by-data-breaches-at-new-jersey-texas-healthcare-firms/

      General News

      • Alleged Dev Of Ploutus ATM Malware Appears In US Court After Arrest
        "The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States. Also known as "Prometheus" and "The Engineer," 50-year-old Anibal Alexander Canelon Aguirre was the first cybercriminal added to the FBI's "Top 10 Most Wanted Fugitives" list in March 2026. According to court documents, Canelon Aguirre and his accomplices deployed Ploutus malware and emptied bank and credit union automated teller machines (ATMs) in jackpotting attacks between February 2024 and December 2025."
        https://www.bleepingcomputer.com/news/security/suspected-dev-of-ploutus-atm-malware-appears-in-us-court-after-arrest/
      • Need For Speed: AI-Driven Attacks Are Changing Security Strategies
        "Concerns over AI-powered attacks are top of mind for organizations, as security teams race to keep up with threats operating at machine speed. According to the latest Dark Reading readership poll, which inquired about themes from Black Hat USA 2026, the topic that mattered most for security teams was "AI-driven attacks vs. AI-powered defenses in the SOC [security operations center]," with 50% of respondents selecting it. A distant second with 22% was "Scaling SecOps with automation, validation, and trusted AI.""
        https://www.darkreading.com/cyber-risk/ai-attacks-security-strategies
      • Iranian Hacker Accused Of Draining 31TB From University Inboxes Extradited To The US
        "Amir Barati spent June 25 getting arrested in Montenegro, and this week a Montenegrin court signed off on sending him to the United States. He’s a dual Turkish and Iranian citizen, 40 years old, picked up by Montenegro’s Police Directorate after the FBI issued a warrant. “He is accused of committing the following crimes: conspiracy to commit computer fraud and computer hacking, as well as identity theft, by conducting massive hacking attacks on the infrastructure of the United States of America since 2013, as an associate of a legal entity from the territory of Iran – at over 150 universities in the United States of America, causing damage estimated at more than 3.4 billion US dollars.” reads the press release published by Montenegro’s Police."
        https://securityaffairs.com/200387/security/iranian-hacker-accused-of-draining-31tb-from-university-inboxes-extradited-to-the-us.html
      • FBI Confirms 'multiple' Arrests Related To ShinyHunters Hack
        "The FBI and law enforcement partners have arrested “multiple” suspects as part of an investigation into a September hack allegedly involving data-theft-and-extortion group ShinyHunters, the bureau told The Register. “The bureau continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects and we will spare no resource in bringing each of the responsible individuals to justice,” an FBI spokesperson told us in an email on Monday. The FBI declined to comment on the specific arrests, including that of Saif al-Din Khader, a suspected ShinyHunters member who has reportedly been detained in Jordan, according to Reuters."
        https://www.theregister.com/security/2026/10/05/fbi-confirms-multiple-arrests-related-to-shinyhunters-hack/5301178

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 077ae50b-ed09-4cfc-9a87-e15a325efef8-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบมัลแวร์ CloudSyncD ปลอมเป็นตัวติดตั้ง Zoom บน macOS หลอกขอรหัสผ่านและเปิด Backdoor

      พบมัลแวร์ CloudSyncD ปลอมเป็นตัวติดตั้ง Zoom บน macOS หล.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5e0ef658-6c76-48da-bac5-ae2b2fbd9245-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • GitLab ออกแพตช์แก้ช่องโหว่ Critical ใน AI Gateway เสี่ยงถูกสั่งดำเนินการคำสั่งบน Self-hosted Gateway

      GitLab ออกแพตช์แก้ช่องโหว่ Critical ใน AI Gateway เสี่ยงถูก.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 15207616-4de6-49bf-ae20-63ceff6cfc96-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT