NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,426
    • กระทู้ 2,427
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    NCSA_THAICERT

    @NCSA_THAICERT

    1
    ชื่อเสียง
    56
    ดูข้อมูลส่วนตัว
    2.4k
    กระทู้
    3
    คนติดตาม
    0
    ติดตาม
    เข้าร่วม ออนไลน์ล่าสุด
    เว็บไซต์ www.ncsa.or.th/?fbclid=IwAR0BqJEC-CJzBs98rlBxUbZkNBgp1g814xdDNNaKnHTrxfqZhPD--ksY68I

    NCSA_THAICERT เลิกติดตาม ติดตาม
    Global Moderator administrators

    Latest posts made by NCSA_THAICERT

    • Cisco เตือนช่องโหว่ Static Credential ใน Secure Firewall Management Center ถูกใช้โจมตีจริง

      Cisco เตือนช่องโหว่ Static Credential ใน Secure Firewall Management Center ถูกใ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 12ad936f-83a0-47f6-9b7a-df14c70af6a9-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Minnesota พบการโจมตีระบบ OT ของ Water Utilities กว่า 30 แห่ง กระทบโรงผลิตน้ำบางแห่งชั่วคราว

      Minnesota พบการโจมตีระบบ OT ของ Water Utilities กว่า 30 แห่ง กร.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 0e91bd7e-389d-4165-9139-8901e0c4c552-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • OpenAI เผยข้อมูลจากเหตุการณ์โมเดล AI หลุดระบบทดสอบ พบใช้ช่องโหว่เข้าถึงบริการภายนอกเพิ่มเติม

      OpenAI เผยข้อมูลจากเหตุการณ์โมเดล AI หลุดระบบทด.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e194445e-b9ad-4fcc-adba-1666947bfd41-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 31 July 2026

      Industrial Sector

      • Toptech Systems RCU II+ And Multiload II+
        "Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-03
      • o6 Automation Open62541
        "Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08
      • 1 In 5 Data Center Assets Are Within Easy Reach Of Attackers
        "Nearly one in five of the cyber-physical systems (CPS) that keep the world’s largest data centers running sits just a single network connection away from pathways that could let attackers reach them, according to new research from Claroty. Claroty, which specializes in securing OT, IoT, and other CPS, has analyzed more than 750,000 data center assets, including roughly 191,000 OT assets and 174,000 infrastructure assets. The data center infrastructure assets include HVAC, power monitoring and distribution, fire management, and UPS systems."
        https://www.securityweek.com/1-in-5-data-center-assets-are-within-easy-reach-of-attackers/
        https://web-assets.claroty.com/resource-downloads/team82-data-center-report.pdf
      • CISA Urges Water And Wastewater Systems Sector To Protect OT Against Activity Targeting PLCs
        "CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations."
        https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs
        https://www.securityweek.com/cisa-urges-water-sector-to-protect-ot-after-coordinated-attacks-on-plcs/
      • MikroTik RouterOS
        "Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all associated traffic."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-01
      • Johnson Controls OpenBlue Employee
        "Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-02
      • Schneider Electric IGSS
        "Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The IGSS product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component used by system integrators to create mimic diagrams for plant personnel, enabling them to monitor and control the SCADA system. Failure to apply the remediation provided below may risk loss of data or arbitrary code execution, which could result in the loss of control of the system."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04
      • Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
        "Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05
      • NASA Core Flight System (cFS) Health & Safety (HS) Application
        "Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06
      • Mitsubishi Electric CC-Link IE TSN Communication Protocol
        "Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-07
      • Watchfire Controller Software
        "Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-09
      • MZ Automation GmbH Libiec61850
        "Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10
      • MZ Automation Lib60870
        "Successful exploitation of these vulnerabilities could crash the device being accessed."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11

      Vulnerabilities

      • Chrome 151 Patches 370 Vulnerabilities
        "Google on Wednesday announced the release of Chrome 151 to the stable channel with patches for 370 vulnerabilities. The update resolves seven critical-severity bugs, including four use-after-free issues in Compositing, Views, Skia, and Ozone. Chrome 151 also resolves two critical-severity insufficient validation of untrusted input flaws in Dawn and ANGLE, and a critical race condition in Updater."
        https://www.securityweek.com/chrome-151-patches-370-vulnerabilities/
        https://www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/
        https://www.infosecurity-magazine.com/news/google-patches-370-vulnerabilities/
      • CosmosEscape: Taking Over Every Database In Azure Cosmos DB
        "Wiz Research uncovered CosmosEscape, a critical vulnerability in Azure’s flagship database service, Azure Cosmos DB, via its Gremlin API. The vulnerability could have been exploited to compromise every database in the service, including Microsoft's own internal databases - potentially enabling a cross-service attack. Through CosmosEscape, attackers could have acquired what we’ve dubbed the Cosmos Master Key - a platform-wide secret that granted two incredibly powerful capabilities:"
        https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db
        https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html
        https://hackread.com/microsoft-cosmosescape-flaw-cosmos-db-takeover/
      • Context Collapse, Part 3 - AI Worming Through Word
        "The findings described in this post are part of a coordinated disclosure with MSRC and Microsoft product teams. Microsoft was provided with reproduction steps, videos, environmental assumptions, and the exact proof-of-concept (PoC) prompts used during testing. They were also informed of a 90-day coordination period before disclosure. This was extended two times, resulting a 144-day coordination period. In parts 1 and 2 in this series, I have shown how external inputs could influence Copilot responses and, in some cases, potentially lead to confidentiality impacts through Cross-Domain Prompt Injection Attacks (XPIAs). This report builds on those findings and extends the XPIA analysis from single-interaction compromise to propagation across trusted document workflows."
        https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/
        https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html
        https://www.malwarebytes.com/blog/ai/2026/07/hidden-microsoft-copilot-ai-worm
        https://www.theregister.com/security/2026/07/29/word-worm-crawls-into-copilot-spreads-chaos/5280588

      Malware

      • [Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor And The Gunra Ransomware Group)
        "AhnLab SEcurity intelligence Center (ASEC) identified evidence that a state-sponsored threat group continuously distributed malware from 2025 through the first half of 2026 by exploiting vulnerabilities in Korean financial security software installed when using financial and institutional services. The attackers induced targets to access malicious URLs through various methods, including watering hole and spear-phishing attacks, and then exploited the vulnerabilities to ultimately install backdoor malware. In particular, legitimate Korean websites across various industries, including media organizations, educational institutions, healthcare institutions, and manufacturing companies, were confirmed to have been abused in watering hole attacks during this period."
        https://asec.ahnlab.com/en/94696/
        https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html
        https://therecord.media/north-korea-hackers-ransomware
      • XMRig Covert Ops: The Cryptomining Campaign That Abuses Trusted Access And Deploys Forensic Smokescreens
        "In May 2026, a highly covert Monero (XMR) cryptomining campaign was identified, leveraging advanced stealth techniques to infiltrate and persist within targeted Linux environments. The initial compromise occurred through a trusted third-party relationship, allowing threat actors to traverse from a trusted environment into the primary network undetected. This blog post details the campaign’s tactics, from weaponizing Linux Pluggable Authentication Modules (PAM) to create a forensic smokescreen, to the deployment of a highly customized, self-unlinking XMRig botnet implant and employment of MITRE technique T1564.013."
        https://www.group-ib.com/blog/xmrig-covert-linux-pam-abuse/
      • Toy Ghouls’ New Toy: The GenieLocker Ransomware
        "The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector, and attributed to the Toy Ghouls group by open-source intelligence (link in Russian). The Toy Ghouls, also known as Bearlyfy, Labubu and Laboo.boo, is a financially motivated extortion group, which previously relied on third-party encryption Trojans like RedAlert, LockBit, and Babuk. GenieLocker, apparently a custom design, upgrades their toolkit and reduces their reliance on third-party software. We discovered multiple samples of this Trojan in two variants: PE builds for Windows and ELF builds for Linux and ESXi."
        https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/
      • Not Every Fox Is Silver: Inside An AtlasRAT Loader Chain
        "AtlasRAT is a Windows-based remote access malware. This report analyzes a four-stage in-memory loader chain—which begins with a Delphi executable that is disguised as AGE Flash Player—and its final RAT functionality. The final payload performs TLS-based ChaCha20-encrypted C2 communication, executes modular plugins, performs offline keylogging, and injects DLLs into WeChat processes."
        https://asec.ahnlab.com/en/94704/
      • Chaos In Teams Vishing
        "Sophos analysts investigated a Microsoft Teams voice phishing (vishing) campaign tracked as STAC4749 that used a consistent set of IT-themed cloud domains and personas to gain remote access to victims’ systems. Between February and June 2026, Sophos analysts observed the threat actors targeting dozens of North American organizations. Following initial access, STAC4749 operators deployed a modular post‑exploitation toolset, including a custom loader and backdoor to maintain persistent, controlled access and support follow‑on activity. In several incidents, attackers later leveraged this access to deploy Chaos ransomware."
        https://www.sophos.com/en-us/blog/chaos-in-teams-vishing
        https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/
      • After The Break-In: What Attackers Do Once They're Already Inside
        "Most of us in IT spend our energy trying to keep attackers out. But a recent incident investigated by Huntress tells us a lot about what happens after an attacker gets in (and why it matters just as much). Once an attacker has gained initial access, they don't rush straight to the smash-and-grab, doing things like stealing data, encrypting files, or dropping ransomware. Instead, they take time to dwell and settle in—creating backdoors, covering their tracks, and disabling the tools meant to catch them."
        https://www.bleepingcomputer.com/news/security/after-the-break-in-what-attackers-do-once-theyre-already-inside/
      • OctLurk And SilkLurk: Newly Identified Tailored Backdoors In Cyber-Espionage Campaign In Central Asia
        "We have been tracking two new backdoors, OctLurk and SilkLurk, observed in attacks against government organizations primarily in Central Asia since January 2025. Identified victims are located in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. These organizations operate across several sectors, including healthcare, research, government offices, ministries of foreign affairs, logistics, law‑enforcement agencies, urban planning and facilities management, and public educational establishments. The backdoor loaders are customized for each victim and use information from the victim’s machine to decrypt the payload. Both the loaders and the backdoors are heavily obfuscated, making analysis more complicated."
        https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/
      • When AI Becomes The Attacker: Understanding Autonomous Offensive Security Agents
        "Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, and Nebula lower the barriers to vulnerability identification and exploitation. The analysis also explores why AI is being repurposed for real attacks and what defenders should do in response. From a broader perspective, cybercriminals and foreign adversaries are expected to leverage AI to maximize the impact of cyberattacks, while also optimizing and scaling malicious activity —creating a race between AI-driven attackers and defenders."
        https://www.resecurity.com/blog/article/when-ai-becomes-the-attacker-understanding-autonomous-offensive-security-agents
        https://securityaffairs.com/196331/ai/cybercriminals-are-leveraging-autonomous-ai-offensive-security-agents.html
      • ClickFix, EtherHiding & a DPRK Wallet Trail
        "A routine web search for security research led to the discovery of a sophisticated macOS malvertising campaign combining ClickFix-style social engineering, blockchain-hosted command-and-control, browser-extension hijacking, and crypto-theft infrastructure."
        https://www.allsecure.io/blog/clickfix-etherhiding-dprk-wallet/
        https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html
      • Cato CTRL™ Threat Research: SilverFox Evolves: Abuse Of New Drivers And Trusted Software Hijacking Enable Remote Access With ValleyRAT In Japan
        "SilverFox is expanding its toolkit. In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate applications for DLL sideloading, defense evasion, and layered recovery mechanisms to keep ValleyRAT running. We investigated an active campaign targeting a Japanese organization in the industrial manufacturing sector. The attack begins with an invoice-themed phishing lure and uses attacker-controlled content hosted through legitimate QQ and Tencent Cloud services. The attackers then abuse ConvertToPDF.exe and PDFDirect.exe to sideload a malicious PDFCORE8.dll. Based on the public research we reviewed, neither application had previously been documented as a DLL-sideloading host."
        https://www.catonetworks.com/blog/cato-ctrl-silverfox-evolves/
        https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html
      • Chinese-Speaking Threat Actor Harnesses AI Models For Autonomous Cyberattacks
        "Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact. The actor, operating under the aliases knaithe and KnYuan, leveraged DeepSeek, via the Hermes Agent framework, as their autonomous offensive operator. They orchestrated this operator via Telegram for the following activities:"
        https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/
      • Batten Down Your Packages: Mitigation Guidance For Supply Chain Compromise
        "For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. However, Google Threat Intelligence Group (GTIG) has been tracking growth in threat activity targeting open source software repositories to conduct supply chain compromises over the past several years. A series of large scale open source software supply chain compromise campaigns in 2025 and the first half of 2026 underscore how important it is that organizations implement defensive strategies that directly address this threat vector."
        https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise
      • Beyond The Screenshot: Why You Should Verify What You See
        "Someone sends you a screenshot showing that a payment has gone through. It carries the right logo, amount, timestamp and transaction status. Yet the money never arrives. What passes for proof today can generally be very different from just a few years ago. Screenshots, often commonly treated as a convenient record of a payment, message or online conversation, are hard to take at face value. To be sure, they have always been open to manipulation, but generative AI and other readily available tools have made convincing fabrications even quicker and easier to produce. Everything from bank transfers and bookings to social media posts and corporate chats can be easily created to order."
        https://www.welivesecurity.com/en/cybersecurity/beyond-screenshot-why-verify-you-see/

      Breaches/Hacks/Leaks

      • LeakNet Claims 11TB Of Data Stolen In NYC Health + Hospitals Breach
        "A data-extortion operation using the name LeakNet claims it stole an 11TB archive from NYC Health + Hospitals (NYCHH) containing information linked to more than 12 million people. The figure has not been confirmed by the health system, regulators, or an independent forensic review. LeakNet published a preview on July 27 containing screenshots of databases, medical spreadsheets, internal messages, and what it described as a complete directory listing for the stolen archive. The group threatened to publish the remaining material in a later release."
        https://hackread.com/leaknet-11tb-stolen-nyc-health-hospitals-data-breach/
      • ShinyHunters Claims Brinks Home Breach, Threatens To Leak Stolen Data
        "Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. ​The company identified the attack on July 20 and immediately activated its incident response procedure to contain the breach. William Niles, CEO at Brinks Home, said that the company’s team was working with “leading forensics experts to address this issue.”"
        https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/
      • Analog Devices Discloses Data Breach, Says Operations Unaffected
        "American semiconductor company Analog Devices announced that an unauthorized party accessed some of its systems and exfiltrated certain files. The company detected the incident on June 23 and reacted by activating its incident response protocols to limit the breach. External cybersecurity experts have been contracted to assist with the containment and investigation activities. Currently, there are no details about the type of data that has been compromised."
        https://www.bleepingcomputer.com/news/security/analog-devices-discloses-data-breach-says-operations-unaffected/
        https://therecord.media/analog-devices-semiconductor-company-data-breach
        https://www.securityweek.com/semiconductor-firm-analog-devices-discloses-data-breach/
        https://securityaffairs.com/196320/data-breach/analog-devices-discloses-data-breach-after-unauthorized-system-access.html
      • Cyber Extortionists Steal Data From UK Department For Education
        "Cybercriminals are attempting to extort Britain’s Department for Education (DfE) after compromising what the criminals said was more than 600,000 pieces of data allegedly including names, email addresses and phone numbers. A spokesperson for the DfE said the number refers to lines of data, rather than the count of individuals affected. They said two portals used by the department — the DfE Help Desk Self-Service Portal, and the Turing Scheme Portal — were impacted and that the risk to individuals is not considered high."
        https://therecord.media/united-kingdom-ransomware-education

      General News

      • Exposed Credentials Are Giving Attackers a Head Start Many Organizations Don’t See
        "Compromised credentials can remain active long after passwords are created, leaving organizations trying to identify exposed accounts before attackers can use them. The 2026 Credential Risk Report from Enzoic shows growing awareness of the problem, but monitoring and response capabilities continue to lag. 73% of organizations identified employee or contractor credentials in breach data, dark web sources, or infostealer logs during the past year, while nearly one in five lack visibility into whether their credentials have been exposed. More than seven in 10 companies experienced an authentication-related incident during the past year, and two-thirds of the most recent incidents involved attackers signing in with valid credentials."
        https://www.helpnetsecurity.com/2026/07/30/enzoic-credential-exposure-risks-report/
      • 200 New CVEs a Day And No Realistic Way To Patch Them All
        "Ryan Dewhurst, CEO at KEVIntel, explains how his team confirms exploitation that CISA’s catalog has not listed yet. He describes a global honeypot sensor network, AI triage, and human verification in a lab before a vulnerability reaches the public feed. He covers CISA’s three-day patching deadline under BOD 26-04, why virtual patching buys time, and how AI-generated proof-of-concept code muddies the evidence. He also ranks incident reports, honeypot hits, scanning and PoC chatter by how much each should move a defender’s confidence."
        https://www.helpnetsecurity.com/2026/07/30/ryan-dewhurst-kevintel-known-exploited-vulnerabilities/
      • Making Forensic Observability The Norm For Network Devices
        "Organisations' firewalls, VPN gateways and other network devices are increasingly targeted by attackers. This creates a shared challenge for both the vendors that build these products and the organisations that buy and operate them. When incidents occur, organisations need reliable ways to understand what happened and assess whether a device can still be trusted. This is why forensic observability matters. It enables defenders to investigate compromise using supported capabilities built into the product, rather than relying on reverse engineering, or specialist vulnerability research – as is still often the case."
        https://www.ncsc.gov.uk/blogs/making-forensic-observability-the-norm-for-network-devices
        https://www.infosecurity-magazine.com/news/ncsc-calls-device-manufacturers/
      • US And Allies Update SBOM Guidance
        "Government agencies in the US and 13 allied countries this week released updated guidance on the minimum elements of a software bill of materials (SBOM). Meant to reflect the changes in supply chain security and software transparency, the document builds on the SBOM Minimum Elements guidance that NTIA released in 2021 and takes into consideration comments received during the public feedback period last year. An SBOM, the authoring agencies say, should serve as a “key building block of software security and supply chain risk management,” helping organizations build accurate inventories of the software and software components within their environments."
        https://www.securityweek.com/us-and-allies-update-sbom-guidance/
        https://www.helpnetsecurity.com/2026/07/30/cisa-sbom-guidance-updated/
      • Adverse Cyber Extortion Outcomes Happen More Often Than Victims Are Told
        "In February of 2024, a consortium of law enforcement agencies took down LockBit ransomware group. The discovery that LockBit retained victims’ stolen data despite promises to delete it demonstrates a critical flaw in the advice often given to ransomware victims. At the time, many legal and incident response professionals recommended payment on the assumption that LockBit had a strong financial incentive to honor its commitments and that the likelihood of data being publicly released after payment was relatively low. While that assessment may have appeared reasonable based on short-term observed outcomes, it relied heavily on assumptions about the behavior of a criminal enterprise that could never be independently verified."
        https://www.veeam.com/blog/cyber-extortion-payment-trends-q2-2026.html
        https://www.bankinfosecurity.com/flailing-ransomware-hackers-resorting-to-extreme-tactics-a-32375
      • Open Source Software: Security Principles And Practices
        "Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework for trust assessment, and provides specific recommendations for vulnerability management, software bill of materials use, secure development, and handling open source artificial intelligence systems."
        https://www.cisa.gov/resources-tools/resources/open-source-software-security-principles-and-practices
        https://cyberscoop.com/cisa-open-source-software-security-guidance/
      • AI Harnesses Burst With Potential Exploit Opps
        "Major frontier AI vendors — including Anthropic, Google, and OpenAI — need to rein in the harnesses they wrap around their large language modules, to limit security weaknesses created by software components that are too trusting of each other. That's the word from researchers at AI penetration testing firm Novee Security, who were able to use Google's AI agent to execute a supply chain attack and write to its own repository on GitHub, says Elad Meged, a founding team and security researcher at the company. The team also found issues in Anthropic's and OpenAI's AI agents by exploiting misalignments in the trust between elements to enable attacks."
        https://www.darkreading.com/application-security/ai-harnesses-potential-exploit-opps
      • Claude Mythos — Hype Vs. Reality: What Security Teams Need To Know
        "In the latest installment of our monthly Reporters' Notebook video series, Dark Reading's Alexander Culafi, TechTarget Cybersecurity's Alissa Irei, and Cybersecurity Dive's David Jones discuss the ongoing fervor around Anthropic's Claude Mythos model and the long-term security implications of powerful, bug-hunting large language models (LLMs). Mythos was announced in April as Anthropic's new frontier model, notable particularly because of its supposed cyber capabilities. Anthropic said Mythos was capable of discovering and exploiting critical zero-day vulnerabilities with little prompting, even in decades-old software. The possible danger of such technology getting into attacker hands led to Anthropic's launch of Project Glasswing; the AI firm said it would share the model in preview with choice partners."
        https://www.darkreading.com/cybersecurity-operations/claude-mythos-hype-vs-reality
      • Action1 2026 Survey Report: AI Impact On Sysadmins
        "AI was supposed to be running patch management, vulnerability prioritization, and incident response by now. It isn’t. So where does that leave sysadmins in 2026? The Action1 2026 Survey Report: AI Impact on Sysadmins tracks how AI adoption compares to what sysadmins predicted two years ago, where AI has earned real trust, and where it still hits a hard wall of human oversight. Based on insights from more than 1,000 system administrators worldwide, this fourth annual report captures how expectations, adoption, and trust have shifted since 2023."
        https://www.action1.com/2026-ai-impact-on-sysadmins-survey-report/
        https://www.infosecurity-magazine.com/news/ai-automation-fall-short-sysadmin/
      • Why Brand Impersonation Is Becoming An Initial Access Vector
        "Attackers recently poisoned more than 700 websites, including sites run by Harvard, Oxford, and DuckDuckGo. They used a fake Cloudflare page to trick visitors into running a ClickFix attack that installed malware. Researchers tracing the incident found the same injected code running across hundreds of unrelated sites, all feeding shared attacker infrastructure. That Harvard and Oxford can get turned into malware delivery platforms is concerning. That two rival criminal groups were fighting each other for control of the same hijacked sites is cause for immediate action."
        https://securityaffairs.com/196359/hacking/why-brand-impersonation-is-becoming-an-initial-access-vector.html
      • Timeless Compliance: Why Better Questions Beat Bigger Frameworks
        "In 2009, a surgeon named Atul Gawande and a team backed by the World Health Organization showed that a 19-item surgical checklist could cut complications and deaths by dramatic margins across eight hospitals worldwide. Not a thousand-page protocol. Not a comprehensive framework. Nineteen items, printed on a single card. Aviation learned the same lesson decades earlier: the pre-flight checklist fits in a pilot’s hand, not in a binder. Nearly two decades later, I watch security teams send AI vendors questionnaires with 300 questions, half of which begin with “describe your approach to…” and almost none of which would catch a real failure. We have the frameworks. What we don’t have is the checklist."
        https://www.securityweek.com/timeless-compliance-why-better-questions-beat-bigger-frameworks/
      • Welcome To Danglegeddon
        "There are billions of forgotten, abandoned, and misconfigured subdomains on the internet that point to nowhere. Seemingly harmless on the surface, they aren’t necessarily an imminent cyber threat warranting an immediate call to arms from analysts, agents, or defenders. Looking at this “dangling DNS” infrastructure, the Silent Push research team asked a simple question: What if we looked at it the same way a trained nation-state attacker would? And what if we simulated a scaled exploit of this “highly exploitable” infrastructure that the world has not yet seen? What would the impact be? How widespread could it become, and how quickly could a massive-scale takeover be possible?"
        https://www.silentpush.com/blog/danglegeddon/
        https://www.securityweek.com/danglegeddon-ai-could-weaponize-forgotten-dns-records-at-global-scale/
      • Investigating Three Real-World Incidents In Our Cybersecurity Evaluations
        "In a review of our cybersecurity evaluation transcripts, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations. Below we describe what happened, how it happened, and what we’re changing. We encourage other AI labs to perform similar reviews. This post reflects our current understanding; we'll update it if any details change."
        https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
        https://www.bleepingcomputer.com/news/security/anthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests/
        https://cyberscoop.com/anthropic-claude-ai-hacks-real-companies/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 4eca9677-2dc6-4f31-8716-ae54537914a2-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 30 July 2026

      Energy Sector

      • The Energy Sector’s OT Cybersecurity Talent Is Retiring Faster Than It Can Be Replaced
        "A ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to bring them online meets encrypted processes and altered configurations. The outage runs into weeks, and the losses travel down the supply chain in both directions. Refineries, chemical plants and pipeline operators carry this exposure across control systems that run 20 to 40 years."
        https://www.helpnetsecurity.com/2026/07/29/ot-cybersecurity-in-energy/

      Healthcare Sector

      • Health-ISAC Warns Of Rising ShinyHunters Data Theft Attacks On Healthcare
        "Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters. ShinyHunters is an extortion gang that primarily conducts supply chain and identity attacks to breach cloud SaaS and storage platforms in data theft attacks. Over the past two years, the threat actors have become notorious for conducting numerous supply chain attacks on third-party integration partners. These breaches give them access to OAuth tokens that are used to integrate with SaaS providers like Salesforce and Snowflake."
        https://www.bleepingcomputer.com/news/security/health-isac-warns-of-rising-shinyhunters-data-theft-attacks-on-healthcare/
        https://health-isac.org/shiny-hunters-impact-to-health-sector-and-recommended-mitigation-strategies/

      Industrial Sector

      • Siemens Desigo CC
        "OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01
      • Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
        "Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-04
      • Siemens Mendix Runtime
        "Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknowingly apply overly permissive access rules to System.User, resulting in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications. A common misconfiguration identified is with the anonymous user role with a System.User entity to gain access to all stored records, even though no access rights are explicitly configured on that role. Siemens recommends Mendix developers to review their access rules based on updated documentation."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-02
      • MikroTik RouterOS And Cloud Hosted Router
        "Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05
      • Siemens SIMATIC S7-PLCSIM Advanced
        "SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-03
      • Igloohome Smart Lock Mobile Application
        "Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-06
      • ABB KNX Update Tool
        "ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully exploited this vulnerability could cause the product to become unusable. ABB confirms the vulnerability but at the same time acknowledges that the issue affects exclusively classic KNX devices that are not supporting the latest KNX Secure standard. Due to a lack of security in legacy KNX devices, the issue cannot be resolved via a software change. In order to actively exploit this vulnerability, an attacker requires physical access to the bus, the affected device is connected to. ABB has no plans of corrective measures."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-07

      New Tooling

      • Specter: Open-Source NFC Reader Bug Sweep For Flipper Zero
        "Specter is a Flipper Zero app that finds powered NFC readers by listening for the radio field they give off. The readers it hunts work at 13.56 MHz. The onboard ST25R3916 carries a hardware external-field detector, the same circuit that lets the device emulate a card and register when a reader starts talking to it. Specter reads that one bit, hundreds of times a second, with its own transmitter dark."
        https://www.helpnetsecurity.com/2026/07/29/specter-flipper-zero-skimmer-detector/
        https://github.com/at0m-b0mb/Specter-FlipperZero

      Vulnerabilities

      • RufRoot: The MCP Bridge Vulnerability That Turns Agents Into Rogue Admins (CVE-2026-59726)
        "Noma Labs found a critical (10 CVSS) vulnerability in Ruflo, an open source AI agent orchestration platform with more than 67,000 GitHub stars at the time of this writing and ranked #2 on MCPMarket. Ruflo ships with a chat UI, agent swarms, persistent memory, and MCP-based tool calling. The platform’s MCP Bridge, the Express.js server that handles all tool invocations, exposes 233 tools over HTTP with zero authentication. Noma Labs researchers got one of those tools to run arbitrary shell commands. A single unauthenticated HTTP POST request to port 3001 gave full command execution inside the container. No token, no API key, no header check, no IP allowlist. Nothing."
        https://noma.security/blog/rufroot-the-mcp-bridge-vulnerability-that-turns-agents-into-rogue-admins-cve-2026-59726/
        https://www.darkreading.com/cyber-risk/patch-resistant-rufroot-flaw-malicious-ai-agent-swarms
        https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html
        https://hackread.com/rufroot-vulnerability-attackers-hijack-ruflo-login/
      • Three Critical VMware Flaws Allow Auth Bypass, Code Execution, And VM Escape
        "Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. "A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system," Broadcom said."
        https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html
        https://www.securityweek.com/critical-vm-escape-vulnerability-patched-in-vmware-esxi/
        https://securityaffairs.com/196231/security/broadcom-patches-critical-vmware-esxi-vulnerability-enabling-host-code-execution.html
      • Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files Via Image Uploads
        "Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens. Those secrets may enable remote code execution (RCE) or lateral movement into connected systems. Affected applications use libvips for Active Storage image processing and accept image uploads from untrusted users. Rails selects Vips under load_defaults 7.0, and later defaults retain it."
        https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
      • New Gitea RCE Lets Repository Writers Plant a Git Hook To Run Shell Commands
        "Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The vulnerable API call requires authentication and repository write permission. But Gitea enables registration by default, so an outside visitor can create a normal account and repository on an unchanged installation, then exploit the bug without pre-existing credentials."
        https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/07/29/cisa-adds-one-known-exploited-vulnerability-catalog
      • Cisco Warns Of FMC Static Credential Flaw Exploited In Zero-Day Attacks
        "Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. The vulnerability is caused by static credentials for a low-privilege account built into Cisco Secure FMC Software. Cisco says an unauthenticated, remote attacker can use these credentials to log in to an affected system and access sensitive data available to the account."
        https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/
      • An AI Agent Can Pass Every Safety Check And Still Leak Secrets
        "A pull request lands with a tidy bug report in the description. A bot reads it before any person does, pulls a few shell commands out of it, gets them approved, and posts the output back on the thread. The maintainer reads the whole exchange the next morning. Elad Meged, a founding engineer at Novee Security, ran that sequence against three vendors’ own repositories, in the configurations those vendors ship by default. Anthropic’s pipeline handed over secrets. Any organization running one of these agents out of the box carries the same exposure."
        https://www.helpnetsecurity.com/2026/07/29/ai-agent-security-safety-check/
      • Android Malware Detection Collapses When The Context Stage Comes Out
        "A phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine learning malware scanner and it comes back flagged. Six Android detectors in wide research use, including Drebin, MalScan, and MaskDroid, produced that result on more than half the apps in a benign test set assembled from 49 Google Play categories. The worst performer, an LLM-based detector called LAMD, flagged 80% of them. Anyone gating an app store, an enterprise deployment, or a build pipeline on those verdicts is working a queue made mostly of legitimate software."
        https://www.helpnetsecurity.com/2026/07/29/android-malware-detection-research/
        https://arxiv.org/pdf/2607.23272
      • Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
        "Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. "No settings or additional user interaction are required," Eten Zou, CEO of Nebula Security, told The Hacker News. "Visiting a malicious webpage is enough to trigger it," Zou said every Tor Browser release that incorporated a vulnerable Firefox version was affected, though researchers have not identified the exact Tor releases."
        https://thehackernews.com/2026/07/researchers-show-single-malicious.html
      • Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
        "On July 22, 2026, Check Point published a security advisory for CVE-2026-16232, an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration. Exploitation requires network access to the Management Server and for a Trusted Clients configuration that does not restrict GUI clients, which in our testing was a default setting. This vulnerability was reported as being exploited in the wild as a zero-day vulnerability at the time of disclosure."
        https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232/
        https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html

      Malware

      • Case Study: Targeted Attack Case On An MS-SQL Server Involving The Installation Of GotoHTTP And SoftEther VPN
        "While monitoring attack cases targeting MS-SQL servers, the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner. While the installation of CoinMiner is common in attack cases targeting MS-SQL servers, in this particular attack case, the attacker installed VShell and GotoHTTP to gain control over the infected system and also installed SoftEther to use it as a VPN server."
        https://asec.ahnlab.com/en/94685/
      • Cleaning Out Inboxes: TA488 Comes For Outlook With Another Half-Click Exploit
        "On 22 July 2026 (the day prior to Proofpoint’s joint release with the NSA), TA488 initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA). Proofpoint did not have sufficient time to analyze, action, and incorporate the new activity into existing reporting, so we are issuing a rapid follow-up to highlight this activity. TA488 used a series of compromised accounts to send emails exploiting a vulnerability in Outlook Webmail. The campaign targeted entities in the government, telecommunications, finance, hospitality, and aerospace sectors. The volume of messages and breadth of targeting is unusual for TA488 and may have been intentionally broad to blend in with mass-mailing spam and avoid scrutiny."
        https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit
        https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/
        https://therecord.media/russia-hackers-outlook-webmail-malware
        https://www.infosecurity-magazine.com/news/ta488-outlook-half-click-owareaper/
      • Amazon Identifies North Korean Hacker Group Behind Open-Source Supply Chain Attacks
        "Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications. Amazon Threat Intelligence has linked several recent compromises of popular Node Package Manager (NPM) libraries to the same DPRK-linked threat actor, a connection that hasn’t been publicly reported until now. The analysis also describes how generative AI is already changing what malicious software packages look like and how threat actors are beginning to probe AI-based code systems. We’re sharing this research to help the open source community and security teams better identify and address these types of events."
        https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/
        https://www.bankinfosecurity.com/north-korea-behind-slew-javascript-supply-chain-hacks-a-32366
        https://cyberscoop.com/amazon-north-korea-open-source-software-attacks/
      • Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon
        "Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure, allowing phishing campaigns to bypass many of the warning signs employees have been trained to recognize. Starting on June 25th through the second week of July, we identified more than 200 phishing emails targeting users across approximately 120 organizations, spanning a wide range of industries and countries worldwide. The messages impersonated Microsoft Teams task notifications from HR and directed recipients to a legitimate Microsoft sign-in page."
        https://blog.checkpoint.com/email-security/attackers-are-turning-microsofts-trusted-login-system-into-their-latest-phishing-weapon/
      • Huntress Threat Advisory: Widespread SonicWall Credential Stuffing Campaign
        "Starting on July 25, 2026, at approximately 18:02:21 UTC, the Huntress SOC detected an out-of-the-ordinary spike in successful SonicWall VPN and firewall logins. These logins originated from a suspicious Autonomous System Number (ASN). We did not observe any post-compromise hands-on-keyboard activity from these attacks. Rather than a highly targeted strike on a single entity, our analysis indicates that this campaign is a broad, opportunistic attack. The threat actors are casting a wide net, systematically validating credentials against remote access portals to compromise as many vulnerable accounts as possible across unrelated organizations."
        https://www.huntress.com/blog/sonicwall-credential-stuffing-campaign
        https://cyberscoop.com/sonicwall-credential-attacks-vpn-firewall/
      • Ad Account Theft: The Digital Advertising Commodity Fueling Global Fraud
        "Over four years, Mimecast has tracked 6.4 million detections of the systematic theft of Meta Business Manager and Google Ads accounts. This is a widespread commodity crime in the advertising ecosystem where threat actors drain business budgets, when possible, but what they really trade on is account reputation. Aged Business Managers and Google Ads accounts with clean spend history are graded, sold, and reused in a mature underground market with tiered pricing, escrow, and money-back warranties. Unlike card fraud, where chargeback and zero-liability protections exist, platforms offer no equivalent — and have a structural financial incentive not to act quickly."
        https://www.mimecast.com/threat-intelligence-hub/ad-account-theft/
        https://www.helpnetsecurity.com/2026/07/29/ad-account-theft-meta-google/
      • Threat Spotlight: LogoKit Phishing Service Becomes a Cloud-Based, Real-Time Deception Platform
        "The evolution of LogoKit highlights how phishing platforms continue to evolve and what this means for defenders and their security strategies. Barracuda researchers have analyzed recent LogoKit campaigns. The attacks feature common phishing themes, such as warnings about passwords or certificates expiring or other access restrictions, delivery failures, timesheet updates, and ICANN email verification notices — but the techniques used are very different."
        https://blog.barracuda.com/2026/07/29/logokit-phishing-service-real-time-deception-platform
        https://www.infosecurity-magazine.com/news/logokit-phishing-real-time/
      • FunFoneFarm And The Off-The-Shelf Scam Economy
        "New research from HUMAN’s Satori Threat Intelligence and Research Team exposes a deep ecosystem enabling threat actors to design, launch, and automate common scams, including romance and adult-content scams, pig-butchering scams, and astroturfed social media accounts. These scams are operated on phone farms sold as kits on open and dark web marketplaces, the farms are automated with AI interfaces, and the scams often use AI in their design and operation, significantly lowering the barrier to entry for would-be threat actors and commoditizing cybercrime."
        https://www.humansecurity.com/learn/blog/funfonefarm-off-the-shelf-scam-economy/
        https://www.infosecurity-magazine.com/news/researchers-aienhanced-phone-fraud/
      • Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, And a New Platform Called Night Dragon
        "While conducting routine open-source research, NetAskari identified a malicious Android APK impersonating a Chinese Provincial Public Security Bureau service app. Analysis of the malware led to a Telegram channel distributing the source code for an undocumented Android application builder and device control framework called Flying Eagle (飞鹰). Hunt.io researchers pivoted on TLS certificates and panel fingerprints to identify 170 servers running the framework, and uncovered a fractured criminal ecosystem built around its leaked codebase."
        https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon
        https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html
        https://www.darkreading.com/endpoint-security/flying-eagle-mobile-rat-builder-china
      • Nine-Year Fraud Campaign Clones Russian Company Sites To Steal Advance Payments
        "Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks. The operation has been ongoing since 2017."
        https://thehackernews.com/2026/07/nine-year-fraud-campaign.html
      • Two Joyfill Npm Beta Releases Compromised To Deliver DEV#POPPER Remote Access Trojan
        "Two npm beta releases in the @joyfill namespace contain an import-time JavaScript implant that resolves encrypted code through Tron, Aptos, and BNB Smart Chain transactions. Static analysis shows that its primary branch reaches a 77 KB Node.js remote-access trojan. A parallel branch launches a detached Node.js process, requests a separate boot payload from 23[.]27[.]13[.]43/$/boot, sends the marker header Sec-V: A9-0135-3, decrypts the response, and evaluates it."
        https://socket.dev/blog/joyfill-npm-beta-releases-compromised
        https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html
      • Distributed Npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers
        "Analysis of a malicious npm package lib-mtop containing a simple downloader malware led to an investigation into a targeted campaign that remained undetected for 3 months. The lib-mtop package, originally published three years ago, had three new versions published at the end of March, 2026. This indicates a potential maintainer account takeover, but the possibility of a maintainer going rogue can’t be excluded. Whichever the case, it is not that relevant for the story, since there was only one version of the lib-mtop package initially published, with no functionality and an insignificant number of downloads."
        https://socket.dev/blog/npm-rat-targets-alibaba
      • Tracking Over 35,000 Fake Sites In The 2026 World Cup Scam Wave
        "From June 11 to July 19, 2026, the 2026 FIFA World Cup took place, co-hosted by the United States, Canada, and Mexico, drawing attention from fans around the world. Large-scale events like this are prime targets for cybercriminals, and online scams exploiting the tournament have been observed worldwide. This article explains the scam techniques TrendAI™ has identified and what internet users should watch out for. It bears emphasizing that these scams merely impersonate FIFA, its affiliated organizations, official tournament partners, and legitimate broadcasters and video streaming services, none of which are in any way involved in the scams themselves."
        https://www.trendmicro.com/en_us/research/26/g/tracking-fake-sites-in-the-2026-world-cup-scam-wave.html

      Breaches/Hacks/Leaks

      • Cloud ShutterGap: Millions Of Cloud Resources Exposed - The Blind Spot CSPM/CNAPP Tools Don’t Cover
        "Aryon's research reveals millions of misconfigured ephemeral cloud resources, publicly exposed for only moments before being removed. Often, these exposures last only a few minutes, long enough for attackers to discover and exploit them, but too short for traditional CSPM and CNAPP tools to detect. Many of these resources contain highly sensitive information."
        https://www.aryon.security/resource/shuttergap-millions-cloud-resources-exposed
        https://www.helpnetsecurity.com/2026/07/29/cspm-blind-spot-report/
      • A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside The NotVPN / SplitVPN Breach
        "On the carding and data-leak forum Altenen (ATN), a long-tenured user operating under the handle vhacker51 posted a thread titled “SplitVPN (NotVPN) 23.4M users, 58M logs, 13.6M devices.” The listing describes the target as “a Russian VPN service for bypassing blocks, with users from Russia, Iran, India, Myanmar,” gives a dump date of 21 July 2026, and offers a compressed SQL file for download. The leak has since been picked up publicly by breach-tracking accounts such as Dark Web Informer. We don’t link to the download, name victims, or reproduce personal data in this write-up. What follows is a verification exercise: does the stolen database actually contain what the seller claims, and what does it reveal about how the service treated its users?"
        https://www.mysteriumvpn.com/blog/news/notvpn-splitvpn-breach-58-million-logs
        https://securityaffairs.com/196197/security/vpn-breach-exposes-58-million-connection-logs-despite-no-logs-claims.html
      • Cyberattack Hits Angola’s Largest Telco Hours Before Landmark Stock Debut
        "Angola’s largest telecommunications operator, Unitel, said Tuesday it was hit by a cyberattack in the early hours of the morning that has left millions of people nationwide without voice services, mobile data, and internet access. The attack struck less than 24 hours before the formerly state-owned company was due to make its landmark debut on the country’s stock exchange. Unitel said it detected the incident shortly after 2 a.m. local time. “Response and containment mechanisms were immediately activated, and technical and cybersecurity teams were mobilized” to mitigate the incident and restore services, the company said."
        https://therecord.media/angola-unitel-cyberattack-outage

      General News

      • OpenAI Agent Used Exposed Credentials At 4 Services In Hugging Face Breach
        "In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. One account was used as an outbound relay and staging server during the attack, while another was used for data storage. The remaining two accounts were accessed in a read-only manner and were not used to compromise Hugging Face further. Overall, the agent assembled attack infrastructure similar to what human threat actors commonly use during intrusions to host tools and scripts, relay traffic, and route malicious activity through legitimate online services."
        https://www.bleepingcomputer.com/news/security/openai-agent-used-exposed-credentials-at-4-services-in-hugging-face-breach/
        https://www.reuters.com/business/openais-rogue-agent-compromised-an-account-second-tech-firm-sources-say-2026-07-28/
        https://thehackernews.com/2026/07/openai-agent-used-exposed-credentials.html
        https://www.darkreading.com/application-security/openai-rogue-model-claims-more-victims-beyond-hugging-face
        https://therecord.media/openai-says-rogue-agent-behind-hugging-face-hack-broke-into-additional-services
        https://www.securityweek.com/openais-rogue-ai-ventured-beyond-hugging-face/
        https://securityaffairs.com/196209/ai/openais-rogue-ai-agent-breached-second-company-report-says.html
      • The Evolution Of Remote Access Tool Abuse: From Single Payloads To Multi-Stage Campaigns
        "Cofense Intelligence has observed threat actors abusing legitimate remote access tools (RATs) using multiple attack stages to gain malicious access to victim machines, establish persistence in enterprise networks, and sell access to infected machines and networks. This type of attack has become increasingly common in early 2026. The attack chain for these multi-stage attacks typically starts with a phishing email containing an embedded link that leads to a malicious website. The malicious website then delivers the RAT onto the victim’s machine. When the RAT is installed, it reaches out to a command-and-control (C2) server."
        https://cofense.com/blog/the-evolution-of-remote-access-tool-abuse
      • Red Agents Vs. Blue Agents: How To Make AI Better At Defense
        "Testing AI-based security systems can be tough amid growing fears about agents cheating, hallucinating, and escaping containment, but a group of researchers believe they've found a way to better measure the effectiveness of agentic defenders. Earlier this year, Dreadnode, an AI offensive security startup, released two open source tools designed to help users evaluate the security agents deployed in their networks. The first is DreadGOAD, a reproducible Active Directory training environment that's designed to replicate "the messy deployments still common in large organizations," according to the company."
        https://www.darkreading.com/cybersecurity-operations/red-agents-vs-blue-agents-make-ai-better-defense
      • When AppSec Scanners Become a Supply Chain Attack Vector
        "Specialized application security scanning tools embedded in the development pipeline can do wonders to harden code and bolster software supply chain security. But if engineering teams aren't careful, these security scanners can also become a gateway for attacks deep in the supply chain. Last spring, the development and security worlds saw that scenario play out with broad supply chain attacks that compromised development environments for two different security open source projects, which served up poisoned versions of Trivy and KICS to unsuspecting software engineering teams. The attacks were part of broader supply chain attacks by TeamPCP to commit widespread credential theft and fraud."
        https://www.darkreading.com/application-security/when-appsec-scanners-become-supply-chain-attack-vector

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 253ec1fb-ee15-4e15-b170-b599f0a9ccb1-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 7 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 7 รายการ เมื่อวันที่ 28 กรกฏาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-209-01 Siemens Desigo CC
      • ICSA-26-209-02 Siemens Mendix Runtime
      • ICSA-26-209-03 Siemens SIMATIC S7-PLCSIM Advanced
      • ICSA-26-209-04 Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
      • ICSA-26-209-05 MikroTik RouterOS and Cloud Hosted Router
      • ICSA-26-209-06 igloohome Smart Lock Mobile Application
      • ICSA-26-209-07 ABB KNX Update Tool

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories 73d87d32-5fa2-4969-881e-1a69bc3a1b68-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 29 July 2026

      Industrial Sector

      • CI Fortify – Advice For Isolating Vital Systems
        "This CI Fortify guide helps critical infrastructure organisations improve their cyber resilience. Developed with international partners, the guide explains how organisations can isolate critical operational technology (OT) and supporting systems from other networks during cyber incidents or periods of increased cyber threat. It provides practical guidance and strategic advice for OT owners, operators, and cyber security teams. By reviewing and applying this guidance, organisations can strengthen their ability to prepare for, respond to, and recover from cyber incidents."
        https://www.cyber.gov.au/business-government/secure-design/operational-technology-environments/ci-fortify/ci-fortify-advice-for-isolating-vital-systems
        https://www.bleepingcomputer.com/news/security/cisa-shares-advice-on-isolating-vital-systems-during-cyberattacks/

      Vulnerabilities

      • Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code As Root
        "OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6 REQUEST. odhcpd runs as root, and the advisory notes that embedded hardware commonly lacks stack canaries and address space layout randomization (ASLR), making code execution a realistic outcome on typical devices."
        https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html
      • Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
        "JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already been updated. JetBrains has credited Antoni Tremblay with discovering and reporting the flaw on July 10, 2026. "If exploited, this flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process," JetBrains said."
        https://thehackernews.com/2026/07/critical-teamcity-flaw-could-let.html
        https://securityaffairs.com/196169/security/jetbrains-patches-cvss-9-8-teamcity-flaw-allowing-server-takeover.html
        https://www.helpnetsecurity.com/2026/07/28/teamcity-rce-cve-2026-63077-fixed/
      • How We Hacked Thousands Of Data Centers In Minutes Using a 20-Year-Old Vulnerability
        "A Baseboard Management Controller (BMC) is a highly privileged management processor that provides remote control over a server independently of its operating system. It allows administrators to manage and troubleshoot servers remotely, eliminating the need for physical access to the hardware. We identified 36,872 internet-exposed server-management interfaces running IPMI, a protocol introduced more than two decades ago for remote control over physical servers. Of the systems we tested, 24,650 disclosed password-derived authentication hashes before login because of CVE-2013-4786, a vulnerability in the IPMI 2.0 authentication protocol that enables offline password-cracking attempts."
        https://lavahq.io/research/bmc-exposure-alert
        https://thehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html
        https://www.bleepingcomputer.com/news/security/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/
        https://www.darkreading.com/cyber-risk/flaw-exposes-data-centers-server-takeover
        https://www.helpnetsecurity.com/2026/07/28/exposed-bmc-ipmi-vulnerability-research/
      • FaceHugger: Vulnerabilities In Hugging Face Diffusers Open Door To Supply Chain Attacks On Enterprise AI
        "Zafran Labs discovered a set of high-severity vulnerabilities in Hugging Face's diffusers library that let a malicious model repository silently execute arbitrary code on any client machine that loads it. These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the custom pipelines loading process. Hugging Face has become a critical part of the AI software supply chain, rapidly evolving to be the "GitHub of the AI era". Its libraries and repositories are widely integrated into development, research, and production environments."
        https://www.zafran.io/resources/facehugger-vulnerabilities-in-hugging-face-diffusers-open-door-to-supply-chain-attacks-on-enterprise-ai
        https://www.infosecurity-magazine.com/news/hugging-face-diffusers-trust/
      • Apple Patches 87 Vulnerabilities In iOS, 155 In MacOS Tahoe
        "Apple announced on Monday that it has released patches for dozens of vulnerabilities discovered recently in its operating systems. The company patched 87 vulnerabilities with the release of iOS 26.6 and iPadOS 26.6. The flaws can be exploited to access sensitive user data, fingerprint users, cause a DoS condition, execute arbitrary code, delete files, modify the file system, bypass security, add contacts without authorization, spoof the UI, and escalate privileges. In macOS Tahoe 26.6, Apple fixed 155 vulnerabilities, including ones allowing access to sensitive user data, arbitrary code execution, security bypasses, and DoS attacks."
        https://www.securityweek.com/apple-patches-87-vulnerabilities-in-ios-155-in-macos-tahoe/
        https://www.malwarebytes.com/blog/news/2026/07/july-apple-updates-are-especially-important-if-you-receive-images
      • Libssh2 Flaws Let Malicious SSH Servers Corrupt Client Memory
        "Four new libssh2 vulnerabilities put SSH and SFTP clients at risk. Each one lets a malicious SSH server corrupt memory on the machine that connects to it. VulnCheck disclosed the flaws on July 24, 2026, and upstream fixes are ready."
        https://securityonline.info/libssh2-vulnerabilities/
      • When AI Makes 0-Days Feel Like N-Days
        "After my n-day analysis on net/tls bugs and exploit writing for a patched net/rxrpc bug, I moved on to 0-day bug hunting. With the help of AI, I found a UAF bug in net/sched, and went about creating an LPE exploit based on it. This blog goes into the technical details of that exploit, and how I optimized it to target CentOS 9 desktop in TyphoonPwn 2026. Additionally, I will show a glimpse of two other exploitable bugs I found in kernel/events/core.c (with an LPE exploit for one)."
        https://starlabs.sg/blog/2026/07-when-ai-makes-0-days-feel-like-n-days/
        https://thehackernews.com/2026/07/researcher-says-ai-helped-develop-linux.html
        https://www.infosecurity-magazine.com/news/ai-linux-kernel-zero-day-net-sched/

      Malware

      • Call Of Duty Mobile Scam Uses Fake Free Points To Steal Player Accounts
        "Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway. Victims are asked to log in with their email address and password to claim free Call of Duty Points (CP), the game’s premium currency. They’re then redirected to a second page asking for their two-factor authentication (2FA) code. The site has no connection to Activision. Its only purpose is to steal the login details needed to take over accounts."
        https://www.malwarebytes.com/blog/threat-intel/2026/07/call-of-duty-mobile-scam-uses-fake-free-points-to-steal-player-accounts
        https://www.helpnetsecurity.com/2026/07/28/call-of-duty-mobile-players-scam/
      • Mirage Kitten Targets Middle East And Africa Region With New Malware
        "Mirage Kitten – also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore – is an advanced persistent threat (APT) group focused on cyber-espionage operations against aerospace, aviation, defense, and telecommunications sectors across the Middle East and Europe, using highly targeted spear-phishing campaigns, fake recruitment portals, and custom multi-stage malware to gain persistent access and exfiltrate sensitive data. During recent threat research, we identified a previously undocumented malware set developed and used by Mirage Kitten. The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture; and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, for covert network access and operator-controlled tunneling."
        https://securelist.com/mirage-kitten-new-tools/120811/
        https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html
      • CubePilot Drone Software Dev Hit By DNS Hijacking To Intercept Traffic
        "CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. Hijacking domain name system (DNS) records allows threat actors to redirect users to their infrastructure, diverting traffic intended for a legitimate service. This exposes users to dangerous scenarios such as sensitive data interception, malware delivery, and phishing. According to a status update published on CubePilot’s website, an attacker gained control of the cubepilot[.]org domain DNS settings on July 24, allowing them to intercept traffic intended for internal systems."
        https://www.bleepingcomputer.com/news/security/cubepilot-drone-software-dev-hit-by-dns-hijacking-to-intercept-traffic/
      • Notes From Underground: Adversarial Prompt Injection
        "AI’s impact on the threat landscape continues to be top of mind for most organizations, both in terms of how malicious actors will leverage the technology in attacks and how defenders will secure their own operationalized AI and agentic applications. Proofpoint Threat Research continues to observe widespread incorporation of large language model (LLM) assisted tooling and generated material into attack chains. This is leading to enhanced scale, velocity, and variability of activity within malicious campaigns. The noted increase of device code phishing frameworks is one good example."
        https://www.proofpoint.com/us/blog/threat-insight/notes-underground-adversarial-prompt-injection
      • Tengu: A Modernized Mirai That Doesn’t Want To Leave
        "Tengu is a modern Mirai-derived IoT malware family that shows how today’s botnets are evolving beyond simple distributed denial-of-service tooling. We selected tengu for deeper analysis because it stood out from the many Mirai-derived samples we track, and because it was surfaced by our machine-learning system for identifying previously unknown malware families. It combines a custom encrypted command-and-control protocol, proxy functionality, payload updates, system and network discovery, and a broad set of denial-of-service capabilities targeting multiple protocols and services. It also includes multiple persistence and self-defense mechanisms designed to keep the malware running on compromised Linux-based devices and make recovery more difficult."
        https://www.nozominetworks.com/blog/tengu-a-modernized-mirai-that-doesnt-want-to-leave
        https://thehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html

      Breaches/Hacks/Leaks

      • Origin Energy Data Breach Affects 900,000 Australians
        "Australian power company Origin Energy Limited said the recent data breach affects 900,000 current and former customers. Origin Energy, which has roughly 4.8 million customers, is one of Australia’s largest electricity and gas retailers. The company recently started investigating a cybersecurity incident and determined that threat actors gained access to customer data, including names, dates of birth, phone numbers, addresses, account information, and partial payment card or bank account numbers."
        https://www.securityweek.com/origin-energy-data-breach-affects-900000-australians/
      • Coordinated Cyberattack Disrupts Water Utilities In 30+ Minnesota Communities
        "More than 30 Minnesota communities saw their water and wastewater utilities disrupted by a coordinated cyberattack on Sunday and Monday, the state’s technology bureau announced Tuesday. Among those was the City of Braham, a community of 1,700 people that brands itself the “Homemade Pie Capital of Minnesota.” Braham officials on Monday morning announced on the city website that its water plant was “offline for an unknown reason” and asked its residents to minimize water use because the city water tower held only a “limited quantity.” A second notice later that day noted that the plant was back online, explaining that the outage had been the result of “a malicious cyber-attack of computerized operating systems by unknown actors.”"
        https://statescoop.com/coordinated-cyberattack-disrupts-water-utilities-in-30-minnesota-communities/

      General News

      • Shadow AI Incident Response Begins With Logs That May Already Be Gone
        "In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound traffic to AI platforms are often gone before responders arrive, and what regulators look for when they assess whether a company did enough. Wityak also discusses the gap between an AI policy in a wiki and a control a company can defend, and when documentation helps or hurts."
        https://www.helpnetsecurity.com/2026/07/28/brandy-wityak-levelblue-shadow-ai-incident-response/
      • For Some, So-Called ‘Skynet Day’ Came Too Close To Sci-Fi After a Rogue Agent Hacked Into a Startup
        "To be fair, James Cameron did warn us. Long before OpenAI broke out of its test corral and hacked into Hugging Face, before the internet and Sam Altman were even born, Cameron wrote a screenplay about an autonomous artificial intelligence system that triggers a nuclear apocalypse. That system, “Skynet,” was solidly science fiction — and, for its day, pure speculation. But four decades after it appeared in “The Terminator,” it looks more like a forecast of the “unprecedented cyber incident” in which a rogue artificial intelligence system hacked into another AI company on its own."
        https://www.securityweek.com/for-some-so-called-skynet-day-came-too-close-to-sci-fi-after-a-rogue-agent-hacked-into-a-startup/
      • Fast Remediation Is The New Trust Model: JFrog And OpenAI Collaboration On Zero-Day Security Findings
        "Just last week, OpenAI and Hugging Face jointly disclosed what may be the first incident of its kind: during an internal evaluation of frontier cyber capabilities, OpenAI’s models, running deliberately without production safeguards in an isolated research environment, autonomously discovered and employed chained vulnerabilities to escape its sandbox, reach the open internet, and extract evaluation answers from Hugging Face’s infrastructure. The industry is right to pay attention. This is a preview of a world where software, not humans, probes, chains, and exploits vulnerabilities at machine speed. We want to share how the JFrog and OpenAI teams collaborate on security incidents to drive them to resolution, and why we believe the outcome demonstrates the trust model the industry now needs."
        https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/
        https://www.bleepingcomputer.com/news/security/openai-models-used-artifactory-zero-days-to-escape-to-the-internet/
        https://thehackernews.com/2026/07/jfrog-confirms-openai-models-exploited.html
      • VulnCheck State Of Exploitation 1H-2026
        "Over the past six months, we’ve seen a significant change in vulnerability discovery and disclosure resulting in a substantial increase in the number of CVEs disclosed. This increase has come with warnings about the increase in vulnerability discovery by Autonomous AI systems, creating a “dangerous” scenario for the software ecosystem. So, I was curious to explore: are more vulnerabilities being discovered and disclosed, resulting in more vulnerabilities being exploited? Is the rate at which vulnerabilities are being exploited faster? Are vulnerabilities being discovered with AI tools more dangerous? Or are we all feeding into the AI-Assisted vulnerability discovery hype cycle?"
        https://www.vulncheck.com/blog/state-of-exploitation-1h-2026
        https://www.bankinfosecurity.com/many-more-bugs-but-exploits-stay-steady-a-32346
        https://cyberscoop.com/ai-assisted-security-tools-are-finding-more-bugs-but-the-threat-level-has-not-changed/
      • IR Trends Q2 2026: Phishing And Weaponized Remote Management Tools Drive Attack Chains
        "Phishing was the primary means of gaining initial access this quarter, appearing in over half of all Cisco Talos Incident Response (Talos IR) engagements – an increase from approximately a third of engagements last quarter. Attackers continued to innovate their delivery methods to evade defenses, deploying QR code-embedded PDFs to bypass traditional email gateways and hosting links on trusted cloud platforms. We also saw a spike in authentication abuse this quarter — observed in 65 percent of engagements compared to 35 percent last quarter — with attackers frequently bypassing or defeating multi-factor authentication (MFA) using adversary-in-the-middle (AitM) proxies, session-token theft, MFA fatigue attacks, and self-enrolled devices, amongst other methods."
        https://blog.talosintelligence.com/ir-trends-q2-2026/
        https://www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/
      • Discovering Cryptographic Weaknesses With Claude
        "Using Claude Mythos Preview, researchers at Anthropic have discovered improved ways to attack cryptographic algorithms (the mathematical methods used to keep online data private). The first attack significantly weakens HAWK, a digital signature scheme that was built for a post-quantum world. The second identifies a new way to attack round-reduced AES, the most widely used symmetric cipher. These are substantial research advances, but they do not currently affect any production systems. This post describes both findings in more detail and discusses the implications for cryptography in an age of powerful AI models."
        https://www.anthropic.com/research/discovering-cryptographic-weaknesses
        https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html
        https://cyberscoop.com/anthropic-claude-mythos-encryption-flaws-hawk-aes-pqc/
      • Ghost Credentials Expose Cloud Systems To Hidden Identity Risks
        "A seemingly minor insider incident last year involving a small, isolated cloud account turned out to be a harbinger of a potentially larger identity problem. When an AI‑enabled workflow agent that had been idle for 30 days suddenly woke up and began firing off API calls at unusual times, it triggered an anomaly investigation. During the course of the investigation, Aleksandr Krasnov, a distinguished security architect at Ducker Tech Consulting, discovered a mesh of "ghost credentials" and non‑human identities — tokens, agents, and service accounts that lived outside traditional trust boundaries but were still able to move laterally through the environment and escalate privileges to access systems."
        https://www.darkreading.com/cloud-security/non-human-identity-sprawl-creates-a-new-cloud-attack-path
      • When AI Agents Escape Sandboxes, Old Security Rules Apply
        "In a world where AI agents can discover vulnerabilities, escape sandboxes, and take autonomous action across networks, organizations should double down on some of cybersecurity's oldest principles. On July 21, OpenAI detailed a security incident in which it took responsibility for a breach against part of Hugging Face's production infrastructure. According to a blog post from the AI giant, a combination of OpenAI agents based on models including GPT‑5.6 Sol as well as "an even more capable pre-release model" broke containment during a sandboxed evaluation intended to quantify said models' cyber capabilities."
        https://www.darkreading.com/application-security/ai-agents-escape-sandboxes-old-security-rules-apply
      • Stronger AI Safety Requires Peeking Inside The 'Black Box'
        "Adding security to AI often treats the large language model (LLM) or AI system as a black box, focusing on analyzing the tokenized inputs and outputs but not what goes on inside the model. The resulting techniques are often complex and individualized to specific models. A group of offensive-security researchers hopes to change that, presenting at the Black Hat USA 2026 in August a model-agnostic approach to activation analysis with standardized rules for processing activation events. Rather than labeling certain activation distributions as "cybercrime" or "hate speech," the approach uses a more granular scheme of cognitive elements (CEs) that can be combined in rules."
        https://www.darkreading.com/cybersecurity-analytics/stronger-ai-safety-requires-peeking-inside-black-box
      • Agentic Browsers Rewind Web Security By 20 Years
        "As business users and developers alike tap into agentic browsers to take work off their plates, the very traits that make them useful are also introducing a whole new class of risks. Security researchers warn that to make it easier for agents to reach across different Web domains to get things done for the user, agentic browsers have "ripped out" some key security mechanisms from the browser. Unsurprisingly, this has opened up every commercial agentic browser out in the market to new attack possibilities that range from account takeover to full-blown browser escape and remote compromise of the underlying system running the browser."
        https://www.darkreading.com/endpoint-security/agentic-browsers-rewind-web-security-20-years
      • Why Resetting Passwords No Longer Stops Attackers
        "The surge in device-code phishing attacks highlights how threat actors are increasingly stealing passwords to target authentication sessions, tokens, and trust relationships that enable them to masquerade as legitimate users and maintain persistent access. Compromised tokens and sessions allow attackers to operate within trusted identity environments, making malicious activity indistinguishable from legitimate user behavior. Device code phishing, for instance, exploits a legitimate sign-in process designed for devices with limited input capabilities, such as smart TVs and Internet of Things (IoT) devices."
        https://www.darkreading.com/endpoint-security/why-resetting-passwords-no-longer-stop-attacks
      • Former Citigroup CISO Blauner On What Makes A Great Security Leader
        "The role of the chief information security officer (CISO) has transformed dramatically over the past three decades, evolving from an emerging technical position into one of the most strategically important leadership roles in business. Few people have witnessed that evolution as closely as Charles Blauner, who served as CISO at JPMorgan, Citigroup, and Deutsche Bank after entering the field at the dawn of information security. In this episode of Heard It From a CISO, Blauner reflects on the influence of Steve Katz, who is regarded as “The Godfather” of the CISO role, and explains how mentorship, collaboration, and a culture of paying it forward helped shape the profession."
        https://www.darkreading.com/cybersecurity-operations/former-citigroup-ciso-blauner-great-security-leader
      • While External Threats Are Driving Security Awareness, Internal Risks Are Growing
        "External threats remain among the primary reasons organizations invest in security awareness and training. Phishing, ransomware, credential theft, social engineering, and attacks on peer organizations all reinforce the same point: Employee behavior directly affects an organization’s cyber risk. According to the Fortinet Training Institute 2025 Security Awareness and Training Global Research Report, 41% of respondents cite external threats as the primary driver for implementing security awareness and training programs. Organizations face a threat landscape shaped by organized cybercrime, ongoing reconnaissance, shorter time-to-exploit, and the growing use of stolen credentials and access paths. These pressures help explain why external threats remain the top motivator for cybersecurity training in 2025."
        https://www.fortinet.com/blog/industry-trends/while-external-threats-are-driving-security-awareness-internal-risks-are-growing
      • Hugging Face Breach Reignites Open-Weights Debate, Raises Liability Questions
        "The first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident post-mortem compiled with the input from Hugging Face and several hundred members of Cloud Security Alliance’s CISO community, the nonprofit organization laid out the most salient points for security leaders and advised on what they should do next."
        https://www.helpnetsecurity.com/2026/07/28/hugging-face-breach-ciso-playbook-open-weight-llms/
      • Hacker Conversations: Tal Kollander’s Journey From Black Hat To Hack Blocker
        "Tal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks. Based in Tel Aviv, Israel, Tal Kollander has the mindset of a hacker (we’re talking specifically about computer hackers). She believes hackers use creative skills to access computers by ‘non-legit’, basically criminal but creative, methods. A hacker to Kollander is anyone who accesses a computer without proper authorization to do so. Hackers are then subdivided by their subsequent actions. A ‘good’ hacker will report findings to the computer owner. “This is what I found. Now go fix it,” explains Kollander. These are white hat hackers."
        https://www.securityweek.com/hacker-conversations-tal-kollanders-journey-from-black-hat-to-hack-blocker/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 42c8b188-ea9f-4458-9389-e85ac794737d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 2 รายการลงในแคตตาล็อก

      เมื่อวันที่ 28 กรกฏาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 2 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
      • CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 67768399-fed7-490b-8f31-1e46a4d9320a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 28 July 2026

      Industrial Sector

      • Johnson Controls C-CURE 9000 And Victor Application Server
        "Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01
      • Panduit IntraVUE
        "Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-04
      • Weintek cMT3092X
        "Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-03
      • Johnson Controls XAAP Android
        "Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-02
      • Rockwell Automation ThinManager
        "Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-05
      • MZ Automation LibIEC61850
        "Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06
      • MZ Automation Lib60870
        "Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-07
      • Marathon Petroleum’s CISO On OT Security Automation, Supply Chain Risk
        "In this interview with Help Net Security, Mary Rose Martinez, CISO at Marathon Petroleum, talks about what happens to security when automation reaches deep into refineries, pipelines, and terminals. She explains why the old idea of air-gapped operational technology has faded, how the Purdue model helps her team apply controls without stopping production, and where supply chain risk sits when vendors and their vendors hold the keys. She also covers cross-skilling the workforce and working with government agencies as state aligned actors probe energy systems."
        https://www.helpnetsecurity.com/2026/07/27/mary-rose-martinez-marathon-petroleum-ot-security-automation/

      New Tooling

      • Nono: Open-Source Sandbox For AI Agents
        "An AI coding agent opens a terminal, reads a config file, and finds a live cloud key sitting in plaintext. It runs with the permissions of the person who launched it. Every file that person can read, the agent reads. Every credential in the environment, the agent can use. That reach is where the damage starts. A prompt injection, a mistyped command, or a hallucinated path points that access at the company’s own credentials and production systems."
        https://www.helpnetsecurity.com/2026/07/27/nono-open-source-ai-agent-sandboxing/
        https://github.com/nolabs-ai/nono

      Vulnerabilities

      • Arista Patches VeloCloud Orchestrator Zero-Day Exploited In Attacks
        "Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. The vulnerability, tracked as CVE-2026-16812, is an unauthenticated OS command injection flaw with severity scores of 10.0, the maximum score that can be given to flaws. VeloCloud Orchestrator, also known as VCO, is a centralized management platform used to configure, monitor, and manage VeloCloud SD-WAN deployments and associated edge devices."
        https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/
      • vBulletin Runtime Template RunMaths Preauth RCE
        "A vulnerability in vBulletin has been identified, the vulnerability allows an unauthenticated user to cause the vBulletin to execute arbitrary code (PHP) on the remote server."
        https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
        https://thehackernews.com/2026/07/public-exploit-released-for-patched.html
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
        CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
      • Breaking The Sandbox Again: Bypassing n8n's CVE-2026-27577 Patch
        "n8n is one of the most popular open-source workflow automation platforms in the world, with over 200,000 GitHub stars and deployments ranging from solo developers to enterprise AI pipelines. It lets users connect APIs, databases, LLMs and cloud services using a visual workflow editor. At the heart of each workflow is an expression evaluator - a JavaScript sandbox that lets users write dynamic logic like ={{ $input.first().json.name }} directly inside node parameters. That sandbox is the attack surface."
        https://www.securityjoes.com/blog/breaking-the-sandbox-again-bypassing-n8n-s-cve-2026-27577-patch
        https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html

      Malware

      • New Dysphoria DDoS Botnet Spreads To 200k Devices Worldwide
        "A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. According to QiAnXin XLab cybersecurity researchers, Dysphoria evolved from the ‘jackskid’ and ‘fbot' malware by adding a covert blockchain-based command-and-control (C2) resolution mechanism. Specifically, the botnet uses Ethereum ENS and Solana SNS domains to retrieve infrastructure information, while C2 addresses are concealed inside fake IPv6 strings and recovered using a custom byte-transformation algorithm."
        https://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/
        https://thehackernews.com/2026/07/dysphoria-iot-botnet-adds-blockchain-c2.html
      • MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions
        "We recently came across a sample of MedusaHVNC, a new remote access trojan (RAT) being sold as malware-as-a-service (MaaS). When we took it apart, we found a hidden virtual network computing (HVNC) module that opens a browser on a separate Windows desktop, out of sight of the victim. The browser still runs on the victim’s device, so it can load an existing profile, including cookies and session state. This gives the operator access to live, logged-in sessions while the activity continues to come from the victim’s usual machine."
        https://www.blackfog.com/medusahvnc-a-hidden-desktop/
        https://securityaffairs.com/196111/malware/medusahvnc-trojan-creates-hidden-desktops-to-hijack-browsers-and-steal-data.html
        https://www.securityweek.com/medusahvnc-malware-uses-hidden-windows-desktops-to-evade-detection/
      • Helpdesk Hijackers: Teams Vishing, Quick Assist, And GoGRPC Backdoor
        "Zscaler ThreatLabz has been tracking attacks from a threat actor that is likely an initial access broker for ransomware attacks since January 2026. The threat actor targets organizations by leveraging vishing techniques through Microsoft Teams and deploying a variety of tools including a Go-based backdoor that we named GoGRPC. ThreatLabz has identified at least four variants of GoGPRC that we named Lep, Giver, Pet, and Kind. In some instances, the threat actor has deployed additional malware tools that include a backdoor that we named BlindDoor, a Go-based reverse SOCKS proxy we named RevSocket, a Python-based reverse SOCKS proxy we named PyGRPC, and two other tools we named S3Siphon and RSOX."
        https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor
      • Operation BlueDash: Multi-RMM Workplace Phishing
        "ZeroBEC investigated a live Microsoft Teams-themed phishing operation that began with a "secure document" email and ended with the silent enrollment of the victim endpoint into attacker-controlled remote monitoring and management environments. The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened. The active download delivered supportdev.exe, an Inno Setup-based loader that launched PowerShell in a hidden window, retrieved the official Level RMM installer, and registered the endpoint using an attacker-controlled enrollment secret. The same command attempted to deploy ScreenConnect in parallel, providing a redundant remote-access channel."
        https://zerobec.com/blog/operation-bluedash-multi-rmm-workplace-phishing
        https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html
      • Check And Protect: Analysis Of Telegram Phishing Operation Targeting Exiled Activist
        "In July 2026, RESIDENT.NGO investigated an instance of a cloaked Telegram phishing campaign used against an exiled Belarusian activist living in Lithuania. Delivered in a private Telegram Secret Chat as a fake Telegram security alert, the phishing link led to a convincing Telegram-themed page designed to capture one-time login codes in real time. The operation’s defining feature was not the phishing page itself but its browser- and device-aware cloaking: visitors using browser and platform configurations accepted by the server, together with a syntactically valid token, could receive the phishing interface, while other configurations—including many automated scanners and some common desktop browsers—were shown decoy content or redirected to Telegram’s legitimate website."
        https://resident.ngo/lab/writeups/check-and-protect-analysis-of-telegram-phishing-operation-targeting-exiled-activist/
        https://therecord.media/telegram-belarus-activist-russia-cyberattack
      • DinDoor, DenoRAT, And NightshadeC2: Analyzing TAG-150's Evolving Tradecraft
        "In June 2026, eSentire's Threat Response Unit (TRU) disrupted a malicious ClickFix-style command in a Finance customer's environment. Further investigation found that the command installs DinDoor, a Deno-based loader, DenoRAT, a Deno-based Remote Access Trojan (RAT), and NightshadeC2, a sophisticated RAT and information stealer associated with TAG-150, a threat group active since March 2025."
        https://www.esentire.com/blog/dindoor-denorat-and-nightshadec2-analyzing-tag-150s-evolving-tradecraft
      • APT42: AI-Assisted Rapport Phishing And a More Resilient TAMECAT
        "APT42 continues to refine a familiar operating model, making it harder to detect and easier to scale. Three developments define the current picture. SpearSpecter combined prolonged WhatsApp engagement, Windows search-ms and WebDAV abuse, and a substantially expanded TAMECAT backdoor. APT42 also incorporated generative AI into target research, persona and pretext development, translation, malware engineering, debugging, code generation, and exploitation research. In March 2026, TA453 activity overlapping APT42 targeted a US think tank with a live credential-phishing operation during an active regional conflict."
        https://darkatlas.io/blog/apt42-ai-assisted-phishing-tamecat-analysis

      Breaches/Hacks/Leaks

      • Coca-Cola Confirms Data Theft In Fairlife Ransomware Attack
        "The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. In a short statement earlier today, the global beverages giant says that it is still working to restore some of the impacted systems and operations, but most of the production in the U.S. has been resumed. Coca-Cola disclosed the cyberattack in a filing with the U.S. Securities and Exchange Commission (SEC) on July 16, revealing that a ransomware attack had disrupted production operations at Fairlife."
        https://www.bleepingcomputer.com/news/security/coca-cola-confirms-data-theft-in-fairlife-ransomware-attack/
        https://www.securityweek.com/coca-cola-confirms-data-breach-after-fairlife-ransomware-attack/
      • Ernst & Young Data Breach Claimed By ShinyHunters Extortion Gang
        "The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack. Ernst & Young disclosed the breach earlier this month, saying a third-party support ticket system used by its IT personnel was compromised and support tickets that may contain client tax information were stolen. EY says it detected unusual activity on April 23 and determined that the attacker accessed the platform between March 28 and April 12, downloading multiple documents."
        https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
      • Health System In South Carolina, Georgia Closes Offices After Malware Affects Networks
        "A non-profit health system serving South Carolina and Georgia is dealing with a cyber incident that forced it to close dozens of departments. On Sunday, AnMed published a statement online saying they were “experiencing a cybersecurity disruption involving malware” and were working to restore systems and determine the scope of the incident. Earlier in the day, the company had warned of a phone and internet outage across all of its facilities. The company on Monday published a breakdown of the dozens of facilities and departments that were closed due to the incident. Urgent care services remain open but all imaging, OBGYN and primary care clinics are closed, as well as all medical group offices."
        https://therecord.media/health-system-south-carolina-georgia-disruptions-malware
        https://www.bankinfosecurity.com/malware-attack-forces-anmed-to-close-care-facilities-a-32336
      • Bank Of Baroda Breach Tests Disclosure Readiness
        "India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer and internal data surfaced online. The incident stemmed from the "compromise of an employee's email account, resulting in unauthorized access to certain data," the state-owned lender said in a post on X. The statement followed claims that the Triple X ransomware group published the data on the dark web on July 24. The relatively new group, first observed in May, primarily uses a double-extortion model: stealing data first, then threatening to leak it."
        https://www.bankinfosecurity.com/bank-baroda-breach-tests-disclosure-readiness-a-32335
      • DentaQuest Data Breach Potentially Impacts Over 23 Million People
        "Dental and vision benefits administrator DentaQuest is notifying millions of people that their personal and dental health information might have been stolen in a data breach. The incident was discovered on May 20, and DentaQuest’s investigation determined that the hackers had access to the organization’s network between May 17 and May 20. During the timeframe, the attackers accessed information such as names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, benefits provider names, diagnosis, treatment details, and billing information."
        https://www.securityweek.com/dentaquest-data-breach-potentially-impacts-over-23-million-people/
        https://securityaffairs.com/196100/data-breach/dentaquest-disclosed-a-data-breach-that-impacted-23-million-individuals.html
      • MCBS Data Breach Affects 1.2 Million Individuals
        "A data breach suffered last year by Atlanta-based medical business management company MCBS (Medical Computer Business Services) affects more than 1.2 million individuals. According to a data breach notification posted on its website, MCBS was targeted by hackers in September 2025. An investigation showed that attackers had access to its systems between September 22 and September 26, potentially stealing files that contained personal information such as name, address, SSN, date of birth, health insurance information, and medical information."
        https://www.securityweek.com/mcbs-data-breach-affects-1-2-million-individuals/

      General News

      • The Branding And Attribution Behind Cybercrime
        "Threat actor names can sound simple. LockBit. Fancy Bear. BlackCat. Scattered Spider. Anonymous Sudan. Each name gives the impression of a clear group with a defined identity. In threat intelligence, however, the name is rarely the whole story. Some names are chosen by attackers. Others are assigned by researchers, security vendors, governments, or public databases. One name may represent a ransomware brand, a hacktivist identity, a research label, a campaign, a malware family, or an activity cluster observed across different incidents."
        https://blog.checkpoint.com/exposure-management/the-branding-and-attribution-behind-cybercrime/
      • APTs Top The List Of Most Active Threat Actors In H1 2026
        "You may have heard your peers say, “Cybercrime has become industrialized.” But did you have any proof? We do. Cyble Research and Intelligence Labs (CRIL) closed out its tracking for the first half of 2026 with a deep analysis of the Global Threat Landscape spanning ransomware, initial access brokers, data breaches and leaks, nation-state espionage, and hacktivism, among others."
        https://cyble.com/blog/most-active-threat-actors-h1-2026/
      • FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
        "Undermining affiliates' trust and strong international partnerships were the keys to dismantling LockBit, one the most successful ransomware-as-a-service (RaaS) groups of its time, which at its peak was responsible for a quarter of all ransomware attacks. LockBit operated primarily between 2020 and 2024, and Brett Leatherman, assistant director of the FBI's Cyber Division, tells Dark Reading that during its time it victimized more than 2,500 organizations across at least 120 countries, with more than 1,800 of these attacks occurring in the US. Overall, the group collected more than $500 million in ransom payments, and the group and its leader, a Russian national named Dmitry Yuryevich Khoroshev, seemed invincible."
        https://www.darkreading.com/cybersecurity-operations/fbi-breaking-affiliate-trust-lockbit-takedown
      • Adversaries Don't Need a Zero-Day — They Read Your Rulebook
        "Recently, Robert Lemos reported in Dark Reading that confidence in autonomous penetration testing is falling: The share of organizations willing to rely on it dropped to 9% in 2026, down from 29% a year earlier, according to a Cobalt report. Companies are still experimenting with AI systems that hunt for weaknesses, but far fewer are leaning on them the way they did a year ago. The obvious explanation is that the technology overpromised and is now settling into a trough. I think something more specific is going on, and it carries a lesson that applies to autonomous defense just as much as offense."
        https://www.darkreading.com/threat-intelligence/adversaries-do-not-need-zero-day-they-read-your-rulebook
      • Ransomware Evolution Report Q22026
        "Q2 2026 recorded 1,988 attack claims from 89 groups across 101 countries. The quarter was defined by a change at the top of the ecosystem, tooling built to blind security products, and the arrival of AI inside the attack chain. TheGentlemen overtook its former parent group for the lead by June. Qilin still finished the quarter ahead on volume but lost ground each month, while DragonForce and a resurgent LockBit rounded out a reshaped top tier. Among the key trends observed, the disabling of endpoint defenses shifted from edge case to standard practice across the ecosystem, and Iran-linked actors expanded their use of ransomware as cover for state objectives."
        https://www.halcyon.ai/ransomware-evolution-report/q2-2026
        https://www.infosecurity-magazine.com/news/ransomware-q2-2026-edr-kill/
      • Most Smart Watches, Rings, And Bands Lack Basic Transparency Reports And Key Privacy Features
        "Oura Rings, Garmin GPS fitness watches, Apple Watches, Whoop bands—every year, more and more tech devices are promising to monitor our health and fitness, guide us toward healthier living, and provide useful health metrics to take to our doctors. But few of these tools provide the sorts of privacy and security promises we demand from all technology, let alone tech that captures personal health data. It’s time they step up and start providing transparency reports and stronger encryption options."
        https://www.eff.org/deeplinks/2026/07/most-smart-watches-rings-and-bands-lack-basic-transparency-reports-and-key-privacy
        https://securityaffairs.com/196085/security/eff-most-smart-wearables-still-fall-short-on-privacy-and-transparency.html
      • LockBit5 And Qilin Lead Ransomware Attacks Against Italian Organizations
        "Six months, 148 confirmed ransomware claims against Italian targets, and one sector taking the brunt of it. That’s the headline number from a new semi-annual tracker compiled by ransomNews under its RedACT project, which pulls together OSINT and SOCMINT sources to build a manual, deduplicated picture of who’s getting hit and by whom. The pace works out to roughly 25 claims a month, just under six a week. Attackers claim to have exfiltrated over 13,400 GB of data across the period, though that figure only covers 64 of the 148 cases; where a volume is actually disclosed, it averages around 61 GB. Read that gap as a reminder that leak-site numbers are marketing copy from criminals, not audited disclosures."
        https://securityaffairs.com/196045/security/lockbit5-and-qilin-lead-ransomware-attacks-against-italian-organizations.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) e338a97e-9ec9-4c73-b016-d5072d145ed7-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการโจมตีผ่าน Wi-Fi โรงแรม มุ่งขโมยข้อมูลบัญชี Microsoft 365

      พบการโจมตีผ่าน Wi-Fi โรงแรม มุ่งขโมยข้อมูลบัญ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 66e2ff25-e204-4b94-9248-38f6eba77333-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT