NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 2
    • กระทู้ 2,199
    • กระทู้ 2,200
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    NCSA_THAICERT

    @NCSA_THAICERT

    1
    ชื่อเสียง
    55
    ดูข้อมูลส่วนตัว
    2.2k
    กระทู้
    2
    คนติดตาม
    0
    ติดตาม
    เข้าร่วม ออนไลน์ล่าสุด
    เว็บไซต์ www.ncsa.or.th/?fbclid=IwAR0BqJEC-CJzBs98rlBxUbZkNBgp1g814xdDNNaKnHTrxfqZhPD--ksY68I

    NCSA_THAICERT เลิกติดตาม ติดตาม
    Global Moderator administrators

    Latest posts made by NCSA_THAICERT

    • Cyber Threat Intelligence 25 May 2026

      Financial Sector

      • April 2026 Security Issues In Korean & Global Financial Sector
        "attack Stage 1 Phishing, Attack Stage 2 Backdoor-Downloader-Dropper, and Attack Stage 3 Infostealer-Ransomware were identified as the top malware in the financial sector. The actual distribution files were identified based on MD5 Hash, and it was explained that there may be many variants of the same family."
        https://asec.ahnlab.com/en/93805/

      Vulnerabilities

      • Ubiquiti Patches Three Max Severity UniFi OS Vulnerabilities
        "Ubiquiti has released security updates to patch three maximum severity vulnerabilities in UniFi OS that can be exploited by remote attackers without privileges. UniFi OS is a unified operating system that powers UniFi Consoles and helps manage IT infrastructure, including networking, security, and other services, as well as UniFi applications such as UniFi Network, UniFi Protect, UniFi Access, UniFi Talk, and UniFi Connect."
        https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-unifi-os-vulnerabilities/
      • LiteSpeed cPanel Plugin CVE-2026-48172 Exploited To Run Scripts As Root
        "A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incorrect privilege assignment that an attacker could abuse to run arbitrary scripts with elevated permissions. "Any cPanel user (including an attacker or a compromised account) may exploit the lsws.redisAble function to execute arbitrary scripts as root," LiteSpeed said."
        https://thehackernews.com/2026/05/litespeed-cpanel-plugin-cve-2026-48172.html
        https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/
      • Trend Micro Warns Of Apex One Zero-Day Exploited In The Wild
        "Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems. Apex One is Trend Micro's enterprise-grade endpoint security platform that protects corporate networks from a wide range of security threats, including malware, ransomware, fileless attacks, and web-based threats. Tracked as CVE-2026-34926, this directory traversal vulnerability in the Apex One (on-premises) server allows local attackers with admin privileges to inject malicious code."
        https://www.bleepingcomputer.com/news/security/trend-micro-warns-of-apex-one-zero-day-exploited-in-attacks/
        https://www.securityweek.com/trendai-patches-apex-one-zero-day-exploited-in-the-wild/
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-9082 Drupal Core SQL Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/05/22/cisa-adds-one-known-exploited-vulnerability-catalog
        https://securityaffairs.com/192566/uncategorized/u-s-cisa-adds-a-flaw-in-drupal-core-to-its-known-exploited-vulnerabilities-catalog.html
        https://thehackernews.com/2026/05/drupal-core-sql-injection-bug-actively.html
        https://www.securityweek.com/drupal-vulnerability-in-hacker-crosshairs-shortly-after-disclosure/

      Malware

      • RondoDox Botnet Exploits 2018 Flaw In Asus Routers
        "Operators behind a botnet picked up on a nearly decade-old flaw in Asus routers allowing an unauthenticated attacker to achieve remote code execution as a root user. Researchers at VulnCheck flagged in-the-wild exploitation of CVE-2018-5999, a critical flaw carrying a 9.8 CVSS score, to the RondoDox botnet. The botnet, which surfaced in mid-2025 and focuses on Linux systems, is often classed as a variant of the Mirai botnet. "Unlike Mirai, this malware’s sole purpose is to execute DoS attacks, while Mirai is not only capable of doing DoS attacks but also scan and exploit other systems," wrote Bitsight in March."
        https://www.bankinfosecurity.com/rondodox-botnet-exploits-2018-flaw-in-asus-routers-a-31768
        https://hackread.com/rondodox-botnet-2018-vulnerability-hijack-asus-routers/
      • Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns
        "Unit 42 researchers have observed evidence of cyberattacks by the Iran-nexus advanced persistent threat (APT) group Screening Serpens (aka UNC1549, Smoke Sandstorm and Iranian Dream Job). Based on our visibility, we believe that the group targeted entities in the U.S., Israel and the United Arab Emirates, and likely two additional Middle Eastern entities. This research follows an evolution through cyberattacks in mid-February through April 2026. The timing of these campaigns aligns closely with that of the regional conflict that started in the Middle East on Feb. 28, 2026. We discovered six new remote access Trojan (RAT) variants developed and deployed between February and April 2026."
        https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/
        https://www.bankinfosecurity.com/iranian-hackers-using-fake-job-sites-to-breach-defense-firms-a-31762
      • Megalodon: Mass GitHub Repo Backdooring Via CI Workflows
        "On May 18, 2026, an automated campaign codenamed megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories in a six-hour window. Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected GitHub Actions workflows containing base64-encoded bash payloads that exfiltrate CI secrets, cloud credentials, SSH keys, OIDC tokens, and source code secrets to a C2 server at 216[.]126[.]225[.]129:8443. The campaign deployed two payload variants. The mass variant (SysDiag) adds a new workflow triggered on every push and pull request, maximizing automated execution. A targeted variant (Optimize-Build) replaced existing workflows with workflow_dispatch triggers, creating dormant backdoors that the attacker can fire on demand via the GitHub API. The npm package @tiledesk/tiledesk-server versions 2.18.6 through 2.18.12 carry the targeted variant, propagated to npm through routine publishes by the legitimate maintainer from the compromised GitHub repository."
        https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/
        https://thehackernews.com/2026/05/megalodon-github-attack-targets-5561.html
        https://hackread.com/github-repositories-megalodon-supply-chain-attack/
        https://www.theregister.com/security/2026/05/22/megalodon-chums-the-waters-in-55k-github-repo-poisonings/5245342
      • SEO Poisoning Campaign Leverages Gemini And Claude Code Impersonation To Deliver Infostealer
        "Financially motivated eCrime actors will likely continue to expand opportunistic campaigns by impersonating AI platforms. These campaigns generate direct supply chain risk for enterprises, as threat actors target software developer tooling, including AI coding assistants and package managers, to compromise developer workstations. In early March 2026, EclecticIQ analysts identified an ongoing infostealer campaign targeting Gemini CLI and Claude Code users. Threat actors use SEO poisoning to surface fake domains above legitimate results, directing victims to attacker-controlled infrastructure that mimics genuine AI agent installation pages."
        https://blog.eclecticiq.com/seo-poisoning-campaign-leverages-gemini-and-claude-code-impersonation-to-deliver-infostealer
        https://www.infosecurity-magazine.com/news/gemini-claude-infostealers-seo/
      • Ghostwriter Targets Ukraine Government Entities With Prometheus Phishing Malware
        "The Belarus-aligned threat actor known as Ghostwriter (aka UAC-0057 and UNC1151Ukraine's National Security and Defense Council) has been observed using lures related to Prometheus, a Ukrainian online learning platform, to target government organizations in the country. The activity, per the Computer Emergency Response Team of Ukraine (CERT-UA), involves sending phishing emails to government entities using compromised accounts. It's been active since the spring of 2026."
        https://thehackernews.com/2026/05/ghostwriter-targets-ukraine-government.html
        https://therecord.media/oysterfresh-belarus-linked-campaign-targets-ukraine
        https://securityaffairs.com/192538/apt/ghostwriter-is-back-using-a-ukrainian-learning-platform-as-bait-to-hit-government-targets.html
      • FBI Warns Of Kali365 Phishing-As-a-Service After April Microsoft 365 Attacks
        "Cybercriminals are using a new, easy-to-use service to trick people into giving them access to their Microsoft 365 accounts, according to the FBI. The law enforcement agency published an advisory on Thursday about Kali365 — a Telegram-based service for cybercriminals that allows them to capture legitimate "OAuth" tokens enabling widespread access to Microsoft 365 environments. Multiple cybersecurity companies warned last month that they were seeing hundreds of attacks enabled by Kali365. The tool, which the FBI referred to as a Phishing-as-a-Service platform, “lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities.”"
        https://therecord.media/fbi-warns-of-kali365-phishing-attacks
        https://www.ic3.gov/PSA/2026/PSA260521
        https://cyberscoop.com/fbi-phishing-kali365-microsoft365-access-tokens/
        https://hackread.com/fbi-kali365-phishing-service-microsoft-365-account/
        https://www.helpnetsecurity.com/2026/05/22/kali365-microsoft-365-phishing-fbi-warning/
      • Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware
        "Void Dokkaebi, also tracked as Famous Chollima, is a North Korea-aligned intrusion set that systematically targets software developers who hold cryptocurrency wallet credentials, signing keys, and access to continuous integration/continuous delivery (CI/CD) pipelines and production infrastructure. As previously documented by TrendAI™ Research, the group poses as recruiters from cryptocurrency and AI firms, luring developers into cloning and executing code repositories as part of fabricated job interviews. TrendAI™ Research observed that InvisibleFerret, a Python-based malware family composed of multiple modules and delivered through the infection chain, has been obfuscated using Cython."
        https://www.trendmicro.com/en_us/research/26/e/analyzing-void-dokkaebi-invisibleferret-malware.html
      • Paved With Intent: ROADtools And Nation-State Tactics In The Cloud
        "ROADtools is an open-source framework written in Python and built for red-teaming and research. It primarily targets the identity and authentication layers of Azure, and focuses on how accounts, applications and tokens operate in tenants. To avoid detection, ROADtools operates through legitimate Microsoft APIs and can mimic typical traffic. Further defense evasion can be achieved by configuring request attributes such as user-agent strings. These capabilities have made ROADtools a valuable asset for attackers. Nation-state threat actors have used it in recent cloud intrusions for discovery, persistence and defense evasion. Attackers involved in a targeted phishing campaign in early 2025 used tooling that matches ROADtools' token management capabilities."
        https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/
      • A New SonicWall Scanning Spike Echoes The Pattern That Preceded CVE-2026-0400
        "Between May 9 and May 18, 2026, GreyNoise observed a significant new spike in scanning of SonicWall SonicOS management interfaces. The May 12 peak — approximately 597,000 sessions — was the largest single-day total recorded on the SonicWall SonicOS API Scanner tag in the past 90 days, roughly 46× the typical daily volume for this tag in the 30 days before the elevation. Similar elevations in activity against this GreyNoise tag have preceded new vulnerability disclosures affecting SonicWall (Ten Days Before Zero, GreyNoise 2026). Activity on this tag spiked three times in an earlier sequence — on January 18, January 30, and February 14 — at 37, 25, and 10 days before the February 24 disclosure of CVE-2026-0400. The current spike may be a similar early warning."
        https://www.greynoise.io/blog/sonicwall-scanning-spike-echoes-pattern-preceded-cve-2026-0400
      • Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten To Steal CI Secrets
        "On May 22, 2026, an attacker with push access to the Laravel-Lang GitHub organization rewrote every git tag across multiple popular Composer packages within a single 15 minute window. Anyone running composer update or installing fresh against laravel-lang/http-statuses, laravel-lang/actions, or laravel-lang/attributes now pulls a payload that exfiltrates CI secrets to a typosquatted attacker domain. StepSecurity confirmed end to end exploitation in an isolated runner and has filed security issues in all four repositories."
        https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack
        https://socket.dev/blog/laravel-lang-compromise
        https://www.aikido.dev/blog/supply-chain-attack-targets-laravel-lang-packages-with-credential-stealer
        https://www.bleepingcomputer.com/news/security/laravel-lang-packages-hijacked-to-deploy-credential-stealing-malware/
        https://thehackernews.com/2026/05/laravel-lang-php-packages-compromised.html
      • Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist And Node.js Projects
        "Socket researchers identified a coordinated supply chain campaign affecting eight packages on Packagist whose upstream repositories were modified to include the same malicious postinstall script. The script attempted to download a Linux binary from a GitHub Releases URL, save it to /tmp/.sshd, make it executable, and run it in the background. Although the affected packages were all Composer packages, the malicious code was not added to composer.json. Instead, it was inserted into package.json, targeting projects that ship JavaScript build tooling alongside PHP code. That cross-ecosystem placement is notable because developers and security teams reviewing PHP dependencies may focus on Composer metadata while overlooking package.json lifecycle hooks bundled inside the package."
        https://socket.dev/blog/malicious-postinstall-hook-found-across-700-github-repos
        https://thehackernews.com/2026/05/packagist-supply-chain-attack-infects-8.html
      • Foul Play: Fake FIFA Websites Target Soccer Fans Looking For World Cup Tickets, Merchandise
        "As the FIFA World Cup 2026™ in the United States, Canada, and Mexico draws closer, anticipation is building toward fever pitch. Many soccer fans may still be hunting for tickets, merchandise, travel and hospitality packages – and scammers know exactly how to exploit this demand. In other words, many people are already in the state of mind that scammers count on: interested, impatient and, indeed, maybe a little worried that the tickets or other goods will sell out. Which is ultimately what makes these scams so effective."
        https://www.welivesecurity.com/en/cybersecurity/foul-play-fake-fifa-world-cup-websites-tickets/
      • Ghost CMS SQL Injection Flaw Exploited In Large-Scale ClickFix Campaign
        "A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows. The campaign was discovered by XLab threat intelligence researchers at Chinese cybersecurity company Qianxin, who confirmed impact on more than 700 domains, including university portals, AI/SaaS companies, media outlets, fintech firms, security sites, and personal blogs. According to the researchers, threat actors planted malicious code on the websites of Harvard University, Oxford University, Auburn University, and DuckDuckGo."
        https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/

      Breaches/Hacks/Leaks

      • FBI Director’s Former Apparel Brand Hit By Malware
        "Two months after Iran-linked hackers exfiltrated FBI Director Kash Patel's personal email inbox, the government official's name is tangled up in another cyber incident - this time through a MAGA swag shop he founded. A ClickFix attack on the Based Apparel site tried to trick shoppers into running a malicious command though a fake Cloudflare verification page on Thursday. The entire merchandise shop has been taken offline Friday."
        https://www.bankinfosecurity.com/fbi-directors-former-apparel-brand-hit-by-malware-a-31767
      • Hackers Steal Patient And Billing Data From German Hospitals Via Third-Party Provider
        "German university hospitals are grappling with a large-scale patient data breach after unknown hackers targeted an external billing service provider used by medical centers across the country, according to statements from several affected medical institutions. The attack reportedly hit Unimed, a company that handles billing services for privately insured and self-paying patients on behalf of numerous German hospitals. Hospitals said the breach did not compromise their own clinical infrastructure or disrupt patient treatment."
        https://therecord.media/hackers-steal-patient-billing-data-german-hospitals
      • Techie Claims Trump Mobile Website Was Leaking Thousands Of People's Data
        "The US President’s oft-maligned Trump Mobile venture may be facing another setback after a security buff claims he discovered a now-plugged website vulnerability that he says was leaking what could be tens of thousands of suckers' customers' details. The individual behind the discovery, who goes by "Louis," says he's a self-taught tech tinkerer and described himself as "just a nerd between jobs with too much time on my hands." He reckons the website’s data could be scooped up with a simple POST request."
        https://www.theregister.com/security/2026/05/22/trump-mobile-site-leaks-customer-data-as-phone-finally-ships/5244828

      General News

      • The Proliferation And Evolution Of AI-Powered Hacking Tools – From Dark Web Distribution To Autonomous Attacks
        "since the emergence of WormGPT in June 2023, AI-based hacking tools have spread to the dark web, Telegram, GitHub, and Hugging Face. the market has evolved into a mix of paid subscription SaaS and free open-source distributions. key capabilities have been segmented into phishing automation, malware development, reconnaissance, brute force, vulnerability exploitation, and social engineering."
        https://asec.ahnlab.com/en/93816/
      • Netherlands Seizes 800 Servers Of Hosting Firm Enabling Cyberattacks
        "Financial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled cyberattacks, interference operations, and disinformation campaigns. FIOD arrested a 57-year-old suspect, who was the company director, and a 39-year-old who headed a separate firm that provided internet connectivity. According to the authorities, the suspects indirectly provided economic resources to Russian and Belarusian entities sanctioned by the European Union (EU)."
        https://www.bleepingcomputer.com/news/security/netherlands-seizes-800-servers-of-hosting-firm-enabling-cyberattacks/
      • Former US Execs Plead Guilty To Aiding Tech Support Scammers
        "Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide. Former CEO Adam Young (from Miami, Florida) and former CSO Harrison Gevirtz (from Las Vegas, Nevada) admitted to a misprision of a felony charge, which carries a maximum penalty of three years in federal prison, a fine of up to $250,000, or both, and are scheduled for sentencing on June 16."
        https://www.bleepingcomputer.com/news/security/former-us-execs-plead-guilty-to-aiding-tech-support-scammers/
      • When The Scanner Starts Thinking: Learnings From Mythos & GPT 5.5 Cyber In Security Testing
        "Frontier AI models like Anthropic Mythos and OpenAI GPT 5.5 Cyber present a critical inflection point for enterprise security. While they unlock transformative potential for security engineers seeking to embed AI into their workflows, they also expand the attack surface for organizations facing increasingly sophisticated attacks when used by threat actors. Mythos and GPT 5.5 Cyber do something fundamentally different from previous models. They reason across attack paths, weigh exploitability, and generate security-relevant workflows. The threat chain remains the same. Attackers will continue to find what’s exposed, break in through a weak point, move laterally, and steal data. What’s changed is the expertise required, speed, and scale."
        https://www.zscaler.com/blogs/security-research/when-scanner-starts-thinking-learnings-mythos-gpt-5-5-cyber-security
      • AI Attacks Are No Longer Experimental: Key Findings From The March-April 2026 AI Threat Landscape
        "Between late December 2025 and mid-February 2026, Gambit found that a single operator compromised nine Mexican government agencies, reaching tax records, civil registry data, patient files, and electoral infrastructure across a two-month campaign. What made it remarkable was not the scope but the method: the attacker ran the entire operation with commercial AI handling the exploitation work, and researchers only discovered what had happened after recovering materials from attacker-controlled servers. AI was not a productivity tool running in the background. It was the operational core of the attack."
        https://blog.checkpoint.com/research/ai-attacks-are-no-longer-experimental-key-findings-from-the-march-april-2026-ai-threat-landscape/
      • Downtime Has Become a $600 Billion Business Problem
        "The average cost of downtime has reached $600 billion for the Global 2000, a 50% increase in two years. According to Splunk’s The Hidden Costs of Downtime report, unplanned outages and service degradation cost each company an average of $300 million. Delayed product launches, brand damage, and stock declines continue to affect companies after systems return online. Customer expectations, cybersecurity threats, rising incident costs, and regulatory pressure have made downtime a priority for technology leaders."
        https://www.helpnetsecurity.com/2026/05/22/splunk-average-downtime-cost-report/
      • The New Economics Of Fraud: Cheaper, Faster, More Convincing
        "Scams have become one of the fastest-growing consumer risks, driven by AI-enabled impersonation, social engineering, and sophisticated attack methods, according to Visa’s Spring 2026 Biannual Threats Report. Fraud involves behavioral manipulation, fragmented ecosystems, and faster attack cycles that use AI to pressure people into authorizing payments themselves. The payments ecosystem continues to strengthen core defenses. Token fraud declined 9.6% and enumeration losses fell 16% from July through December 2025 compared with the same period in 2024. Improvements in tokenization, authentication, and network-level detection contributed to those results."
        https://www.helpnetsecurity.com/2026/05/22/visa-consumer-payment-fraud-report/
      • Cloud Atlas Activity In The Second Half Of 2025 And Early 2026: New Tools And a New Payload
        "In 2025, we observed pervasive SSH tunnel activity, which has remained active into 2026, affecting many government organizations and commercial companies in Russia and Belarus. Behind some of this activity is Cloud Atlas, a group we have known since 2014. During our investigation, we identified new tools used by this group, as well as indicators of compromise. The group is back to sending out archives containing malicious shortcuts that launch PowerShell scripts. This technique is employed in addition to the previously described use of malicious documents, which exploit an old vulnerability in the Microsoft Office Equation Editor process (CVE-2018-0802) to download and execute malicious code. We have observed the use of third-party public utilities (Tor/SSH/RevSocks) to gain a foothold in infected systems and create additional backup control channels."
        https://securelist.com/cloud-atlas-2026/119895/
      • Italy Disrupts CINEMAGOAL Piracy App That Stole Streaming Auth Codes
        "Italian authorities have dismantled a piracy ecosystem centered around the CINEMAGOAL app that provided access to various streaming platforms, including Netflix, Disney+, and Spotify. Unlike typical IPTV service providers that openly market themselves online and expose their operations, CINEMAGOAL's approach was stealthier, as it used an app that customers installed on their devices. During the large-scale anti-piracy operation called “Tutto Chiaro” (All Clear), Italian law enforcement conducted 100 searches across the country and seized materials that could help investigators identify involved individuals, as well as determine the amount of illegal profits."
        https://www.bleepingcomputer.com/news/legal/italy-disrupts-cinemagoal-piracy-app-that-stole-streaming-auth-codes/
        Why Pure Extortion Is Replacing Traditional Ransomware
        "Ransomware groups are quietly changing strategy in 2026. Instead of encrypting systems and causing immediate disruption, many attackers are now focusing on pure extortion: stealing sensitive data and threatening to leak it publicly if victims refuse to pay. This shift is happening for a simple reason. Encryption is noisy, risky, and easier for defenders to detect. Data theft is often faster, quieter, and in many cases more profitable. Several recent reports suggest attackers are increasingly prioritizing credential theft, long-term access, and exfiltration over traditional ransomware deployment. The pressure point is changing too. Companies are no longer paying just to restore operations, they are paying to avoid reputational damage, regulatory fallout, and exposure of sensitive internal documents."
        https://securityaffairs.com/192550/cyber-crime/why-pure-extortion-is-replacing-traditional-ransomware.html
      • Claude Mythos AI Finds 10,000 High-Severity Flaws In Widely Used Software
        "Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the world since the cybersecurity initiative went live last month. Project Glasswing is a defensive effort launched by the artificial intelligence (AI) company to secure critical global software infrastructure. It grants a small set of about 50 partners exclusive, early access to Claude Mythos Preview, a frontier model with capabilities to autonomously identify vulnerabilities in widely-used software before bad actors can exploit them."
        https://thehackernews.com/2026/05/claude-mythos-ai-finds-10000-high.html
        https://www.anthropic.com/research/glasswing-initial-update
        https://securityaffairs.com/192576/ai/anthropics-glasswing-10000-vulnerabilities-found-in-one-month-and-the-patching-problem-has-never-been-more-obvious.html
      • Dirty Frag, Copy Fail, Fragnesia: The Start Of a Worrisome Linux Security Trend
        "Dirty Frag, Copy Fail, and Fragnesia are less a random cluster of Linux bugs and more the public unveiling of how AI tools can pry open security holes with just a prompt or two. What they also have in common is their shared abuse of a core kernel abstraction: The page cache. What does this mean for you and me? Is this the rainstorm before a downpour of killer Linux security problems, or is this just a shower? It depends on who you ask."
        https://www.theregister.com/security/2026/05/23/dirty-frag-copy-fail-fragnesia-the-start-of-a-worrisome-linux-security-trend/5244742

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) c15ceb14-6c52-4892-900c-0f3ded3d7a33-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cisco อุดช่องโหว่วิกฤติ CVE-2026-20223 ใน Secure Workload เสี่ยงถูกยึดสิทธิ์ Site Admin ผ่าน REST API

      Cisco อุดช่องโหว่วิกฤติ CVE-2026-20223 ใน Secure Workload เสี่ยงถ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand a587a8bc-8adc-43ff-87ef-f8d4e1b45dd9-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Verizon DBIR เผย AI ช่วยแฮกเกอร์เร่งโจมตีช่องโหว่ซอฟต์แวร์ เกี่ยวข้องกับ 31% ของเหตุข้อมูลรั่วไหลล่าสุด

      รายงาน Verizon DBIR ชี้ AI ถูกใช้ช่วยโจมตีและแสวงหา.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5d893ac3-d338-471d-9158-c7d77e25fe55-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการโจมตีช่องโหว่บนอุปกรณ์ SonicWall VPN ข้ามผ่านระบบ MFA หลังผู้ใช้งานไม่อัปเดตการตั้งค่าให้สมบูรณ์

      พบการโจมตีช่องโหว่บนอุปกรณ์ SonicWall VPN ข้ามผ่า.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 75da9d8d-f636-405b-a1c5-17f3d87f1b49-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • 🛑 Microsoft ออกแพตช์แก้ไขช่องโหว่ Zero-Day ใน Microsoft Defender

      ศูนย์ประสานการรักษาความมั่นคงปลอดภัยระบบคอมพิวเตอร์แห่งชาติ (ThaiCERT) ได้ติดตามสถานการณ์ข่าวสารภัยคุกคามทางไซเบอร์ พบ Microsoft ออกแพตช์แก้ไขช่องโหว่ Zero-Day ใน Microsoft Defender หลังพบว่าช่องโหว่ดังกล่าวถูกนำไปใช้ในการโจมตีจริง [1]

      1. รายละเอียดเหตุการณ์
        Microsoft ออกแพตช์แก้ไขช่องโหว่ Zero-Day ใน Microsoft Defender โดยมีช่องโหว่ที่สำคัญจำนวน 2 รายการดังนี้
        1.1 CVE-2026-41091 (CVSS v3.1: 7.8) เป็นช่องโหว่ประเภท Elevation of Privilege (EoP) ใน Microsoft Defender เกิดจากข้อบกพร่อง Improper Link Resolution Before File Access (Link Following / Symlink Handling) ซึ่งทำให้ Microsoft Defender ตรวจสอบหรือเข้าถึงไฟล์ผ่านลิงก์ (symbolic link / hard link) อย่างไม่ปลอดภัย ส่งผลให้ผู้โจมตีที่มีสิทธิ์ในเครื่องอยู่แล้วสามารถใช้ช่องโหว่นี้เพื่อยกระดับสิทธิ์ (Local Privilege Escalation) ไปสู่สิทธิ์ที่สูงขึ้นในระบบได้ [2]
        1.2 CVE-2026-45498 (CVSS v3.1: 7.5) เป็นช่องโหว่ประเภท Denial of Service (DoS) ใน Microsoft Defender ซึ่งอาจทำให้ผู้โจมตีสามารถทำให้บริการหรือกระบวนการของ Microsoft Defender หยุดทำงานหรือไม่สามารถให้บริการได้ (Availability Impact) ส่งผลให้ระบบป้องกันมัลแวร์อาจทำงานผิดปกติหรือหยุดตอบสนองชั่วคราว [3]

      2. ผลกระทบที่อาจเกิดขึ้น
        2.1 ยกระดับสิทธิ์จากผู้ใช้ทั่วไปไปเป็น SYSTEM-level privileges
        2.2 ปิดการทำงานหรือหลบเลี่ยงการป้องกันของ Microsoft Defender
        2.3 เข้าถึงข้อมูลสำคัญหรือ Credential ภายในระบบ
        2.4 ใช้เป็นฐานการโจมตีไปยังระบบอื่น
        2.5 เพิ่มความสามารถในการคงอยู่ในระบบ (Persistence) และหลบเลี่ยงการตรวจจับของระบบรักษาความปลอดภัย

      3. ระบบที่ได้รับผลกระทบ
        ระบบที่ใช้งาน Microsoft Defender Antivirus หรือ Microsoft Defender for Endpoint

      4. แนวทางการป้องกันและแก้ไข
        4.1 ติดตั้งแพตช์ความปลอดภัยล่าสุดจาก Microsoft ทันที
        4.2 ตรวจสอบการยกระดับสิทธิ์ที่ผิดปกติ
        4.3 ตรวจสอบการปิดการทำงานของ Defender

      5. มาตรการชั่วคราว (กรณียังไม่สามารถอัปเดตได้ทันที)
        5.1 จำกัดสิทธิ์ผู้ใช้งานภายใน
        5.2 เปิดใช้งาน Tamper Protection เพื่อป้องกันการแก้ไขค่าของ Microsoft Defender
        5.3 ใช้ Application Control / WDAC / AppLocker เพื่อลดโอกาสการรันโค้ดที่ไม่ได้รับอนุญาต
        5.4 เฝ้าระวัง Event Logs ที่เกี่ยวข้องกับ Defender Service, Security Center และ Privilege Escalation
        5.5 แยกระบบที่มีความเสี่ยงสูงออกจากเครือข่ายสำคัญ
        F3EB4B71-2EA3-488D-927B-BAED2A9E85A2.png
        แหล่งอ้างอิง
        [1] https://dg.th/7w6lp1cg0u
        [2] https://dg.th/h9a71ny8k2
        [3] https://dg.th/lm57t0a1wx

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • 🛑 Microsoft แจ้งเตือนการโจมตีผ่าน ASP.NET Machine Key และ ASP.NET Core

      ศูนย์ประสานการรักษาความมั่นคงปลอดภัยระบบคอมพิวเตอร์แห่งชาติ (ThaiCERT) ได้ติดตามสถานการณ์ข่าวสารภัยคุกคามทางไซเบอร์ พบ Microsoft ออกมาตรการป้องกันและแก้ไขช่องโหว่ความปลอดภัยใน ASP.NET Machine Key และ ASP.NET Core [1]

      1. รายละเอียดช่องโหว่
        บริษัท Microsoft ได้ออกประกาศแจ้งเตือนด้านความมั่นคงปลอดภัยไซเบอร์เกี่ยวกับการโจมตีที่มุ่งเป้าไปยังระบบเว็บแอปพลิเคชันที่พัฒนาด้วย ASP.NET และ ASP.NET Core หมายเลข CVE-2026-45585 (CVSS v3.1: 6.8) หรือที่เรียกว่า “YellowKey” โดยพบว่าผู้ไม่หวังดีสามารถใช้ Machine Key ที่เปิดเผยสู่สาธารณะ หรือใช้ประโยชน์จากช่องโหว่ด้านการตรวจสอบ Cryptographic Signature Verification เพื่อปลอมแปลงข้อมูลยืนยันตัวตนและยกระดับสิทธิ์ในระบบได้ [2]

      ทั้งนี้ หน่วยงานสามารถดูรายละเอียดเพิ่มเติมได้ที่ https://dg.th/wc6dv0xjog

      1. ระบบที่ได้รับผลกระทบ ได้แก่
        • Microsoft.AspNetCore.DataProtection เวอร์ชัน 10.0.0 ถึง 10.0.6 โดยเฉพาะระบบที่ทำงานบน Linux, macOS และระบบ Non-Windows

      2. พฤติกรรมการโจมตี
        ผู้โจมตีสามารถใช้ Machine Keys ที่รั่วไหลหรือถูกเผยแพร่สาธารณะ สร้าง ViewState ปลอมที่ผ่านการตรวจสอบความถูกต้องของระบบ ASP.NET ได้ เมื่อเซิร์ฟเวอร์ประมวลผลข้อมูลดังกล่าว ระบบจะทำการถอดรหัสและรันโค้ดอันตรายภายในหน่วยความจำของ IIS Web Server ส่งผลให้ผู้โจมตีสามารถควบคุมระบบจากระยะไกล (Remote Code Execution: RCE)

      3. ผลกระทบ
        4.1 เข้าควบคุมเว็บเซิร์ฟเวอร์หรือระบบงานสำคัญ
        4.2 เข้าถึงข้อมูลสำคัญหรือข้อมูลส่วนบุคคล รวมถึงแก้ไขข้อมูลสำคัญภายในระบบ
        4.3 ปลอมแปลง Session, Cookie หรือ Password Reset Token
        4.4 ใช้ระบบที่ถูกโจมตีเป็นฐานสำหรับโจมตีระบบอื่นภายในองค์กร
        4.5 แก้ไขหรือลบข้อมูลสำคัญขององค์กร

      4. แนวทางการป้องกันและลดความเสี่ยง
        5.1 อัปเดต Microsoft.AspNetCore.DataProtection เป็นเวอร์ชัน 10.0.7 หรือเวอร์ชันล่าสุดโดยทันที
        5.2 ตรวจสอบไฟล์ web.config และการตั้งค่าของ IIS ว่ามีการกำหนดค่า Machine Keys แบบ Static หรือไม่
        5.3 ตรวจสอบระบบย้อนหลังเพื่อค้นหาร่องรอยการฝัง Web Shell, Godzilla Framework เป็นต้น

      5. มาตรการชั่วคราว (กรณียังไม่สามารถอัปเดตได้ทันที)
        6.1 Rotate ASP.NET Machine Keys และ Data Protection Keys ใหม่ทันที โดยสร้างกุญแจใหม่ที่มีความซับซ้อนสูง และไม่ใช้ค่าที่คัดลอกจากสาธารณะ หรือ Git Repository
        6.2 ปิดการใช้งาน Machine Keys แบบ Static
        6.3 จำกัดการเข้าถึงระบบจากภายนอก
        6.4 เปิดใช้งาน Web Application Firewall (WAF)
        6.5 ปิดฟังก์ชันหรือบริการที่ไม่จำเป็นชั่วคราว
        6.6 บังคับ Reset Session และ Authentication Token เป็นระยะ
        ASP.NET Core22.png
        แหล่งอ้างอิง
        [1] https://dg.th/tfcokpxrz0
        [2] https://dg.th/wuarfe8z9j

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 2 รายการลงในแคตตาล็อก

      เมื่อวันที่ 21 พฤษภาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 2 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2025-34291 Langflow Origin Validation Error Vulnerability
      • CVE-2026-34926 Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/05/21/cisa-adds-two-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 2aead5dc-0a10-4461-9f01-9038c13b0021-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Anthropic อุดช่องโหว่ใน Claude Code หลังพบความเสี่ยงข้ามข้อจำกัด Sandbox

      Anthropic อุดช่องโหว่ใน Claude Code หลังพบความเสี่ยงข้า.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 9ffc2431-b890-410c-8b48-a85ecc9d9597-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • GitHub ยืนยันเหตุข้อมูลรั่วไหลจากส่วนขยาย VS Code อันตราย กระทบ Repository กว่า 3,800 รายการ

      GitHub ยืนยันเหตุข้อมูลรั่วไหลจากส่วนขยาย VS Code .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 4a0fd293-7532-4b62-9a73-bbf79b141f1b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบช่องโหว่ความรุนแรงระดับสูงสุดบน ChromaDB เสี่ยงให้ผู้ไม่หวังดีเข้าควบคุมเซิร์ฟเวอร์

      พบช่องโหว่ความรุนแรงระดับสูงสุดบน ChromaDB เสี.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand bf41176d-f352-4eca-8c30-a3c86864d36a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT