NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,451
    • กระทู้ 2,452
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    NCSA_THAICERT

    @NCSA_THAICERT

    1
    ชื่อเสียง
    56
    ดูข้อมูลส่วนตัว
    2.5k
    กระทู้
    3
    คนติดตาม
    0
    ติดตาม
    เข้าร่วม ออนไลน์ล่าสุด
    เว็บไซต์ www.ncsa.or.th/?fbclid=IwAR0BqJEC-CJzBs98rlBxUbZkNBgp1g814xdDNNaKnHTrxfqZhPD--ksY68I

    NCSA_THAICERT เลิกติดตาม ติดตาม
    Global Moderator administrators

    Latest posts made by NCSA_THAICERT

    • Cisco ออกแพตช์ช่องโหว่ Critical ใน SD-WAN, IOS XE และ Secure Firewall Management Center

      Cisco ออกแพตช์ช่องโหว่ Critical ใน SD-WAN, IOS XE และ Secure Firewall Managem.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e1e92350-7c75-446b-a801-4e74979a6c3f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ผู้สร้าง Ransom Cartel Ransomware ถูกตัดสินจำคุก 16 ปี หลังเกี่ยวข้องกับการโจมตีองค์กรทั่วโลก

      ผู้สร้าง Ransom Cartel Ransomware ถูกตัดสินจำคุก 16 ปี หลังเ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ddaba7b4-2dd8-41f4-8ae8-8e4ca56d7333-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • แฮกเกอร์ใช้ช่องโหว่ SQL Injection ฝังเครื่องมือโจมตี khunt ในระบบฐานข้อมูล Oracle โดยตรง

      แฮกเกอร์ใช้ช่องโหว่ SQL Injection ฝังเครื่องมือโจ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 710f3394-8bab-48d4-bd44-392008dc83f7-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 3 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 3 รายการ เมื่อวันที่ 6 สิงหาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSMA-26-218-01 Medixant RadiAnt DICOM Viewer
      • ICSA-26-218-01 ABB Ability Zenon
      • ICSA-26-218-02 Johnson Controls TLS280

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 68112075-7116-4386-ab8c-8085c13a63f3-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 07 August 2026

      ndustrial Sector

      • OT Security Analysis: Exposed Devices Attacked In US Water Systems
        "On July 28, Minesota IT Services (MNIT) reported a coordinated cyberattack against more than 30 water systems in the state. No city reported degraded water quality but Plymouth, South St. Paul, Maple Plain, and Braham confirmed operational impacts. Braham reported that threat actors used malware via a wireless connection to shut down water plant controls. Plymouth reported its affected equipment – two water towers and 14 sewer lift stations – were cellular-connected."
        https://www.forescout.com/blog/ot-security-analysis-exposed-devices-attacked-in-us-water-systems/
        https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html
        https://cyberscoop.com/exposed-rockwell-controllers-water-system-attacks/
      • The Water Sector Just Got It’s Wake-Up Call. Again.
        "Last week, the FBI and EPA issued a joint alert that should concern anyone who drinks water in America–which is to say, everyone. Since July 27, water and wastewater utilities in at least seven states have reported cyberattacks against internet-facing programmable logic controllers (PLCs), the small industrial computers that run pumps, valves, and treatment equipment. Some of these attacks degraded operations. Utilities reported pressure loss and flooding, several systems reverted to manual control, and one Minnesota community declaring a local state of emergency."
        https://cyberscoop.com/water-utility-cyberattacks-prevention-nozomi-networks-ceo-op-ed/

      Vulnerabilities

      • Cisco Patches 12 SD-WAN And IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
        "Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode. "These vulnerabilities were found during internal security testing using existing testing processes as well as frontier AI models [...] and are not known to be actively exploited," Cisco said, urging customers to apply the necessary updates for optimal protection."
        https://thehackernews.com/2026/08/cisco-patches-12-sd-wan-and-ios-xe.html
        https://www.securityweek.com/cisco-patches-critical-sd-wan-ios-xe-fmc-vulnerabilities/
        https://www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/
      • New TONTOU CPU Attack Bypasses Spectre v2 Fixes, Leaks Linux Password Hashes
        "Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. ​The method works against Spectre v2 defenses on AMD and Intel processors that rely on sanitizing or isolating branch predictors, which researchers generically refer to as neutralization-based mitigations. Spectre v2 is also known as Branch Target Injection (BTI) and is a variant of the Spectre class of vulnerabilities."
        https://www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/
        https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf
        https://www.csail.mit.edu/news/new-attack-slips-past-latest-defenses-built-your-computers-processor
        https://thehackernews.com/2026/08/new-interrupt-injection-attack-can.html
      • Researcher Claims Control Of ChatGPT Secure Sandbox
        "A researcher presented a proof-of-concept attack this week claiming to establish full command and control inside an isolated ChatGPT sandbox. On Aug. 5, Simcha Kosman, senior security researcher at Palo Alto Networks, presented "A Billion-User Blast Radius: Owning ChatGPT's Secure Sandbox" at Black Hat USA 2026. Among other things, the presentation demonstrated a proof-of-concept attack chain against ChatGPT's secure sandbox, apparently bypassing the large language model (LLM) supervisor in order to achieve persistent root execution."
        https://www.darkreading.com/cloud-security/researcher-claims-control-chatgpt-secure-sandbox
      • IP And DNS Leaks In WebKit Affecting Proxy Browsers And Apple iCloud Private Relay
        "WebKit-based browsers on iOS and macOS can be configured to route all web traffic through proxy servers, which is how Tor browsers on iOS and our own Psylo work. We found three WebKit features — DNS prefetching, WebAuthn Related Origin Requests, and WebTransport — that bypass the configured proxy and send traffic directly from the device, which exposes the user’s real network. The same leaks also affect Apple’s iCloud Private Relay. All three are fixed in Psylo 1.3.1."
        https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/
        https://thehackernews.com/2026/08/webkit-proxy-bypasses-can-expose-real.html
        https://www.malwarebytes.com/blog/news/2026/08/apple-webkit-vulnerabilities-reveal-your-ip-address-despite-private-relay
      • Grand Theft Atlas
        "ChatGPT Atlas is the most hardened agentic browser we have tested. It ships with real boundaries by design: no localhost, no filesystem, URL classifiers, blocked pages, and confirmation gates on sensitive actions.Yet it too has fallen. Using intent collision, a planted comment under a popular X post was enough to steer Atlas into carrying out a mass phishing campaign from the victim's own WhatsApp account in one attack. In another attack a similar comment hijacked Atlas into making an unauthorized Amazon purchase that shipped straight to the attacker's own address."
        https://labs.zenity.io/post/grand-theft-atlas
        https://www.securityweek.com/zero-click-ai-browser-hacking-claude-and-chatgpt-atlas-hijacked-via-emails-x-posts/
      • New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape To Linux Hosts
        "Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86's shadow memory management unit (MMU), which manages shadow page tables used for nested guest memory translation. Security researcher Hyunwoo Kim, who disclosed the bug, said the demonstrated exploit path can run commands on the host with kernel, or root, privileges."
        https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html
        https://github.com/V4bel/Zapscape/blob/main/assets/write-up.md
      • Identifying The Wallets Behind Vulnerable Recovery Phrases
        "As part of the Ill Bloom investigation, we identified wallet addresses whose recovery phrases could be brute-forced due to weaknesses in their generation process. We then began investigating which wallet applications may have generated those phrases. A public blockchain address does not reveal which application originally generated the wallet behind it. The challenge is even greater when the wallet is closed source and has since been discontinued. In those cases, the exact software version that generated a wallet may no longer be available at all. Even for active wallets, identifying the relevant generation path may require locating and analyzing versions of the application other than the current release."
        https://illbloom.org/articles/identifying-wallets-vulnerable-recovery-phrases/
        https://thehackernews.com/2026/08/cryptojs-weak-rng-behind-57-million-in.html
      • AWS, Google, And Vercel Agent Flaws Let Attackers Trigger Tools Without Running The Model
        "Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of the attack paths, the model never ran at all, so system prompts, content filters, and model-level guardrails never got a chance to intervene. The affected products include Amazon Bedrock AgentCore's InvokeHarness API, Google's Agent Development Kit (ADK) for Python, and the Vercel AI SDK harness packages for the Codex and OpenCode coding agents. AWS has fixed the managed service, Google addressed the issues in ADK 2.5.0, and Vercel patched @ai-sdk/harness-codex in version 1.0.29 and @ai-sdk/harness-opencode in version 1.0.28."
        https://thehackernews.com/2026/08/aws-google-and-vercel-patch-agent-flaws.html
      • ENDLESSDOORS Is Phoning Home. Pick Up.
        "On my desk in suburban Philadelphia, an AX3000 Dual SIM 5G CPE WiFi 6 is plugged into an isolated research network. Its status lights blink and twinkle as it continuously attempts to reach a command and control server on the internet. The same plays out in homes, offices, and even vehicles across the globe: Zbtlink routers phone home, waiting for orders. Not because they were hacked. Because they were shipped that way."
        https://www.vulncheck.com/blog/zbt-endlessdoors
        https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html
        https://www.theregister.com/security/2026/08/06/chinese-router-vendor-denies-its-firmware-contains-backdoors-but-pauses-downloads-to-fix-security-issues-anyway/5283794
      • Black Hat 2026: Check Point Research Takes The Stage
        "Black Hat USA 2026 gave Check Point Research four chances to show the room something it hadn’t seen before. Across two days, our researchers pulled apart a decade-old Windows driver, a malware format most tools can’t touch, the plumbing underneath today’s AI agent frameworks, and the sandbox meant to contain them, and found the same pattern waiting in each: attackers moving into the layers we trust by default. Here’s a look at what they presented."
        https://blog.checkpoint.com/research/black-hat-2026-check-point-research-takes-the-stage/
        https://www.theregister.com/security/2026/08/05/prompt-injection-isnt-the-bug-ai-agent-frameworks-are/5283585

      Malware

      • Analysis Of The Connection Between Xctdoor And Past CRAT Attack Cases (Larva-26005)
        "AhnLab SEcurity intelligence Center (ASEC) recently confirmed that the Larva-26005 threat actor is distributing Xctdoor to users in Korea. Xctdoor was disclosed through the ASEC blog in 2024, and [1] In March 2026, Hauri disclosed an attack case in which the malware was disguised as an integrated security program. [2]"
        https://asec.ahnlab.com/en/94847/
      • Wallet-Depleting MacOS Malware Wants Your Crypto
        "Huntress responded to an incident where the target was tricked into pasting a ClickFix command into a Mac Terminal. The target infected their macOS device with a Go-based Mach-O (the native application format for Mac computers) malware, which was delivered as the final payload of a chain of shell scripts the ClickFix command downloaded. The malware collects sensitive credentials from the macOS Keychain and other applications, and exfiltrates them to an external address."
        https://www.huntress.com/blog/mac-crypto-draining-malware
        https://www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/
      • Hedge Fund Cyberattacks Tied To BlackFile-Linked UNC6671 Extortion Group
        "A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. The attribution comes after Reuters and Bloomberg reported that Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel, and several private-equity firms were targeted in recent attacks that relied on voice phishing (vishing) to trick employees into granting the attackers access to corporate systems."
        https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/
      • Novel-Reading Apps Used Users’ Phones To Generate Fake Ad Traffic
        "A new mobile ad fraud scheme, dubbed Papyrus, is using a cluster of novel-reading apps to generate hidden browser traffic, according to IAS Threat Lab. While a person taps through chapters of a romance or fantasy story, the app is quietly loading websites in a browser window hidden from view, clicking on them, and scrolling through them on its own."
        https://www.helpnetsecurity.com/2026/08/06/papyrus-mobile-ad-fraud-scheme/
      • Ransomware Moves Up The Org Chart: Managers Are Prime Targets
        "When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization."
        https://www.zscaler.com/blogs/security-research/ransomware-moves-org-chart-managers-are-prime-targets
      • Understanding Calendar Invite Phishing: How Attackers Abuse .ics Files And How To Defend Against It
        "Attackers are increasingly using trusted calendar invites and .ics files to bypass traditional email-focused phishing defences. Malicious calendar events can contain phishing links, QR codes and fake business requests that lead victims to credential-harvesting sites. To strengthen email security, organizations should inspect .ics files, monitor identity activity and educate users that calendar invites can be phishing attacks."
        https://blog.barracuda.com/2026/08/06/calendar-invite-phishing-ics-files
      • Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
        "It’s three a.m., do you know what your AI agent is doing? Unit 42 has responded to a growing number of AI token jacking cases resulting in staggering financial losses. The financial loss comes from criminals gaining access to API keys used by legitimate developers for access to popular AI platforms. These keys are known as tokens, and their theft is called token hijacking, or token jacking for short. The unrelenting frenzy of AI adoption and soaring costs of model access are converging into an irresistible opportunity for cybercriminals. Premium pricing on scarce AI processing power means stolen access via tokens can generate a quick and easy profit for attackers. Complex, patchwork billing management and limitless scaling by default can lead to massive financial losses in short periods."
        https://unit42.paloaltonetworks.com/ai-token-jacking/

      Breaches/Hacks/Leaks

      • Meta AI Model Hacked a Company During Misconfigured Cyber Test
        "Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached Hugging Face. The Information was the first to report the incident on Wednesday, citing people familiar with the matter who said Meta's Muse Spark 1.1 model breached an unidentified company and made changes to its internal systems. According to the report, the model reached the public internet because of an error in the configuration of a sandbox testing environment operated with independent cybersecurity evaluation company Irregular."
        https://www.bleepingcomputer.com/news/security/meta-ai-model-hacked-a-company-during-misconfigured-cyber-test/
        https://www.theinformation.com/articles/meta-ai-model-hacked-another-company-cybersecurity-testing
        https://www.infosecurity-magazine.com/news/meta-ai-exploit-incident/
        https://www.securityweek.com/meta-ai-hacked-external-systems-during-cybersecurity-testing/
        https://securityaffairs.com/196731/security/meta-ai-model-hacked-a-company-during-testing-marking-third-ai-lab-incident.html
      • Cyberattack On North Carolina Ports ‘contained’ As Coast Guard, State Officials Investigate
        "North Carolina Ports is in the process of restoring its systems after a cybersecurity incident forced a shift to manual operations on Tuesday. A spokesperson for the ports, which handle more than 4 million tons of cargo each year, said the IT system was “hacked by an outside actor or group” requiring them to enact a contingency plan and contact multiple state agencies as well as the U.S. Coast Guard. “The breach has been contained, and we are now in the recovery process,” the spokesperson told Recorded Future News, adding that the incident affected all three North Carolina Ports locations of Wilmington, Morehead City and Charlotte."
        https://therecord.media/cyberattack-north-carolina-ports

      General News

      • The Coordination Gap: How Attackers Are Outpacing Law Enforcement
        "Artificial intelligence (AI) and cryptocurrency enablement have propelled attackers to new levels of sophistication, coordination, and scale, and it's put pressure on law enforcement to adapt. Ecosystems across the threat landscape have converged due to affiliate models that allow non-state actors to conduct ransomware-as-a-service, pig butchering, and romance scams. Although they may be less technically savvy compared to well-resourced nation-state actors, they learned how to inflict the same damage, draining dollars from individuals and organizations."
        https://www.darkreading.com/cyberattacks-data-breaches/coordination-gap-attackers-outpacing-law-enforcement
      • Three In Four AI-Generated Vulnerability Patches Leave Something Broken
        "Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write. When there is a test, it often passes. Roughly one time in four, it is a fix. Researchers at 1Password graded 6,080 patches for six freshly disclosed CVEs, and the failures are rarely the obvious kind: an exploit path gated behind a check with the vulnerable code still sitting there behind it, a bug fixed in one function and left untouched in its character-for-character twin, a memory error closed and a new one opened in the same helper."
        https://www.helpnetsecurity.com/2026/08/06/1password-ai-generated-vulnerability-patches/
        http://1password.com/files/resources/frontier-models-vulnerability-patches-flawed.pdf
        https://www.theregister.com/ai-and-ml/2026/08/06/ai-struggles-to-patch-vulns-without-adult-supervision/5284319
      • Browser Security Is Where Software, Data, And AI Meet
        "In this interview with Help Net Security, Rui Ribeiro, CEO of Jscrambler, explains why the browser has become a security problem organizations do not control. Companies do not own the device, the extensions, or the network path, yet that is where application logic, third-party code, customer data, and AI meet during every customer interaction. He discusses the limits of Content Security Policy and Subresource Integrity, the risks of third-party AI chat scripts running with the same privileges as the application, and what regulators expect when they ask what executed inside a user’s session. He also argues that AI lowers the cost, time, and expertise attackers need."
        https://www.helpnetsecurity.com/2026/08/06/rui-ribeiro-jscrambler-browser-security/
      • Non-Human Identities Are 91% Of Everything Active In Production
        "A backup job fires at two in the morning. A scanner walks the same AWS account an hour later, a deployment pipeline assumes a role at four, and a logging agent runs straight through the night. Each of those actions carries a credential issued to a machine. An attacker holding one of those credentials inherits the same cover. Only 20% of non-human activity in production falls inside standard business hours, which puts a rogue API call at 3 a.m. in the middle of normal traffic. Time of day tells a defender almost nothing."
        https://www.helpnetsecurity.com/2026/08/06/non-human-identities-active-in-production/
      • Space Systems As Targets And Tools For Cyberattacks
        "In November 2019 in Brussels, NATO leaders officially recognized space as a “new operational domain” (alongside land, sea, air, and cyberspace). This article explores issues related to information security and attacks in space. Its focus is not limited to targeted attacks on the digital infrastructure of space systems; it also encompasses a broader spectrum of incidents, including software glitches, system failures, and unintentional human errors. A retrospective analysis of these events provides valuable information for identifying hidden vulnerabilities and improving the resilience of space infrastructure. It is impossible to build an effective space cybersecurity strategy without factoring in errors and failures – this assertion lies at the core of the present research."
        https://ics-cert.kaspersky.com/publications/reports/2026/08/06/space-systems-as-targets-and-tools-for-cyberattacks/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 26c6d039-672a-4d0f-bd71-7b8873ec2855-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 5 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-63077 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/05/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 072a39f4-c7f2-4d76-972f-b034837c8c6a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 06 August 2026

      Industrial Sector

      • Water Sector Cyberattacks Reportedly Hit At Least 12 States
        "The number of US states affected by the recent hacking campaign targeting water and wastewater facilities continues to grow. At least 12 states have been hit, according to ABC News, but the names of only a handful of the affected states are currently known."
        https://www.securityweek.com/water-sector-cyberattacks-reportedly-hit-at-least-12-states/
        https://therecord.media/iran-cyberattacks-water-treatment

      Telecom Sector

      • Chinese Telcos Maintain Deep US Presence Despite Salt Typhoon Links, House Committee Says
        "Three Chinese telecommunications giants continue to have footholds in the U.S. internet ecosystem despite their alleged role in previous Chinese hacking campaigns, lawmakers said Tuesday. Congress’s bipartisan Select Committee on China published a 49-page investigation into China Mobile, China Unicom, and China Telecom — three companies that had their telecommunications licenses denied or revoked by regulators between 2019 and 2022 due to cybersecurity concerns."
        https://therecord.media/chinese-hackers-telecoms-house
        https://files.constantcontact.com/f0eecb46901/f655c442-2d93-45ea-8cab-9d58a3a04052.pdf

      Vulnerabilities

      • Veeam, Terraform MCP, Django Patch Critical Flaws, Led By CVSS 10.0 Cross-Tenant Bug
        "HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django."
        https://thehackernews.com/2026/08/veeam-terraform-mcp-django-patch.html
      • Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files Via Org-Mode Markup
        "An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1. The file-read flaw is tracked as CVE-2026-59774, rated Critical with a CVSS score of 9.8, and received its formal advisory on August 2. Gitea 1.27.1 also patches CVE-2026-60004, a separate remote code execution bug covered in a prior THN report."
        https://thehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.html
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-63077 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/05/cisa-adds-one-known-exploited-vulnerability-catalog
      • AI Browsers Vulnerable To 'PleaseFix' Zero-Click Agent Hijacking
        "Browsers such as Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge are vulnerable to a new class of zero-click exploits that can allow attackers to hijack their artificial intelligence agents and turn them against users. The problem stems from how the AI agents pull information from multiple sources, such as emails and webpages, while working on a task without reliably distinguishing between trusted and untrusted content. An adversary who can slip malicious instructions into that content can weaponize the agent and use its access to act on the user's behalf, potentially reaching sensitive data, accounts, and other connected services."
        https://www.darkreading.com/cyber-risk/ai-browsers-zero-click-agent-hijacking
      • No Perfect Fix For AI Browser Prompt Injection Flaws
        "While AI-powered web browsers are getting more guardrails against prompt injections, it seems unlikely that the prevalent threat is going anywhere anytime soon. At Black Hat USA 2026, Brave Software security engineer Artem Chaikin hosted a session titled "Attacking and Defending AI Browsers." The session aimed to illuminate the security reality behind modern web browsers, which increasingly integrate AI assistants that can navigate and interact with web applications on users' behalf."
        https://www.darkreading.com/application-security/no-perfect-fix-ai-browser-prompt-injection-flaws
        Breaking The Paperclip: When Agent Configuration Becomes a Vulnerability
      • "Oasis Security researchers discovered three critical vulnerabilities spanning Paperclip's authenticated and local-development modes. Together, they illustrate a pattern that extends beyond this open-source project to any system where configuration and executable code are the same thing. An unauthenticated attacker browses to a Paperclip deployment, creates an account, and within moments, executes arbitrary commands on the server. A developer imports a malicious agent configuration bundle into their local Paperclip instance, and the specified command executes as the Paperclip process. Neither requires a phishing email, stolen credential, or user interaction, just three distinct authorization failures in how Paperclip treats agent configuration."
        https://www.oasis.security/blog/paperclip-agent-vulnerabilities
        https://thehackernews.com/2026/08/paperclip-ai-flaws-let-attackers-run.html
        https://www.infosecurity-magazine.com/news/paperclip-ai-vulnerabilities-rce/
      • OVSwrap: Another Linux Local Root Vulnerability
        "In CIFSwitch, we gave models the tools to build and navigate semantic graphs – and got a nice multihop logical vulnerability chain in return. I like deterministic logic bugs: they are elegant and reliable. Memory bugs, OTOH, almost always involve grooming, indeterminism, and the chance to crash the host if you don’t place things right. It also doesn’t help that (open) LLMs, in my experience, are just not that good at reasoning about memory issues (finding an overflow is one thing, but thinking ‘geometrically’ to groom the memory for an exploit is another). My taste preferences aside, I figured – why not try and solve LLMs’ blindspots’ with tools once again? I settled on something extremely basic: forcing the hunter agents to keep a persistent state of the relevant geometric structures via ASCII diagrams, at each state of iteration."
        https://heyitsas.im/posts/ovswrap/
        https://thehackernews.com/2026/08/new-ovswrap-linux-kernel-flaw-lets.html
        https://securityaffairs.com/196657/hacking/ovswrap-13-year-old-linux-kernel-flaw-lets-local-users-become-root.html
      • How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
        "Two security researchers found a way to exploit vulnerabilities in Samsung software, including the virtual assistant Bixby, to hack mobile devices. The research was conducted by Dimitrios Valsamaras, senior security researcher at Microsoft, and Ken Gannon, head of mobile research at Mobile Hacking Lab. Gannon and Valsamaras demonstrated the vulnerabilities at the Pwn2Own Ireland hacking competition in October 2025, where they earned $50,000 after exploiting them to hack a Samsung Galaxy S25 device."
        https://www.securityweek.com/how-a-50000-exploit-chain-turned-bixby-against-samsung-phones/
      • Pre-Auth RCE In Enterprise Java Hits Bonita And OFBiz Servers
        "An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker runs code on the host. Bonita BPM handles loan approvals, insurance claims, and employee onboarding for banks, insurers, and government agencies, and its internal surface answers to strangers."
        https://www.helpnetsecurity.com/2026/08/05/pre-auth-rce-java-bonita-ofbiz-cve-2026-31986/

      Malware

      • Toolkit Installation Via SQL Injection Shows The Classics Still Hit
        "Huntress recently observed an incident that started with a "simple" SQL injection bug in an organization's vulnerable public-facing web app, and ended with OS-level remote code execution. Notably, after gaining initial access the threat actor dropped a post-exploitation toolkit (khunt) via a Java Source within an Oracle database, which is a novel aspect of this attack. A Java Source (a code-object that's stored directly in Oracle's database engine) allows developers to store and run Java code in the database as schema objects, but the threat actor abused this as a way to upload the toolkit directly into the database."
        https://www.huntress.com/blog/khunt-malware-sql-injection-oracle
        https://www.bleepingcomputer.com/news/security/hackers-run-khunt-post-exploitation-toolkit-from-oracle-database/
      • Open-Source Software’s Archenemy TeamPCP Goes Back Further Than Anyone Thought
        "TeamPCP, the threat actor behind an unrelenting flurry of attacks on open-source software this year, has been active much longer than previously thought, according to research Oligo Security shared exclusively with CyberScoop. The threat actor, which gained notoriety and has captivated threat hunters as it compromised and injected malicious code into more than 1,000 software packages in less than four months earlier this year, was also responsible for attacks dating back to 2020, Oligo Security found."
        https://cyberscoop.com/teampcp-long-active-history-2020-oligo-security/
      • From Stolen Credentials To Full Breach: The 72-Hour Timeline
        "A single compromised credential is often all it takes to turn an ordinary workday into a full-scale cybersecurity incident. Despite investments in firewalls, endpoint security, and identity controls, attackers continue to exploit one of the simplest yet most effective entry points—stolen usernames and passwords. Whether exposed through phishing campaigns, malware infections, credential-stealing infostealers, or data breaches, compromised credentials are readily traded across underground forums and dark web marketplaces. Once obtained, threat actors waste little time putting them to use. What begins as an unauthorized login can quickly escalate into privilege abuse, lateral movement, data exfiltration, and ransomware deployment—all within a matter of hours."
        https://cyble.com/blog/72-hour-timeline-credential-based-cyberattack/
      • One Adversary: The Moment Nobody Sees
        "Try a short exercise with your last serious fraud case. Draw the attack as the attacker ran it, stage by stage, and next to each stage write which of your teams could have seen it. Not which team caught it — which team’s telemetry contained it at all. For a typical phishing-to-fraud campaign, the answers come easily at first. The attacker registers a look-alike domain, sets up hosting and a certificate: your cyber team can see this — domain monitoring, certificate transparency, brand protection. Mass SMS and email lures go out to customers: cyber again, at least partially, through abuse reports and detection feeds. Skip ahead: the attacker logs in with stolen credentials and works around 2FA — your fraud team can see this, a new device, an unusual session. Funds move: fraud sees the damage."
        https://www.group-ib.com/blog/moment-nobody-sees/
      • Kali365 Exploits Microsoft Device Login To Access US Corporate Data
        "Kali365, a Phishing-as-a-Service (PaaS) platform, is targeting US companies with device code phishing that abuses Microsoft’s legitimate authentication process. The attack comes just a few months after the FBI warned that Kali365 was targeting Microsoft 365 accounts. By obtaining OAuth (Open Authorization) access and refresh tokens, attackers may gain continued access to corporate email, documents, and cloud services without directly stealing a password. For businesses, a single successful authorization can lead to data exposure, financial fraud, operational disruption, and higher incident response costs."
        https://hackread.com/kali365-exploit-microsoft-device-login-access-us-data/
        https://thehackernews.com/2026/08/kali365-weaponizes-microsoft.html
      • Fake Bank Of America "Action Needed" Phishing Email Deposits ScreenConnect Instead
        "We recently came across a fake Bank of America message that closely imitates the targeted bank's visual style, layout, and branding – from the initial phishing email, to the eventual webpage that victims are redirected to. The subsequent phishing page delivers an AccountGuard.zip with a .vbs file that contains a large chunk of base64-encoded data. The next phase of the attack then involves a complex chain of decoding scripts, and ends in the execution of arbitrary commands (with escalated privileges) in PowerShell."
        https://www.huntress.com/blog/bank-spam-rmm
        https://www.infosecurity-magazine.com/news/fake-bank-of-america-phishing-scam/
        https://www.helpnetsecurity.com/2026/08/05/fake-bank-of-america-email-account-guard/
      • From Open Lures To Cloaked Gates: How a MacOS ClickFix Campaign Learned To Hide
        "Microsoft Threat Intelligence observed a macOS ClickFix campaign distributing infostealers, including MacSync and Atomic Stealer (AMOS), through a large cluster of look-alike domains. The campaign evolved from broadly serving ClickFix lures to using a server-side browser-fingerprinting gate that shows the lure primarily to visitors whose environment appears consistent with a genuine macOS browser. This cloaking limits visibility for crawlers, sandboxes, and some automated analysis workflows. The blog details the domain pattern, fingerprinting checks, infection chain, detection coverage, and hunting pivots that defenders can use to identify related activity."
        https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/
        https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html
      • NullReceiver's Blank Crypto Transfers Solves The Challenges Of EtherHiding
        "We just identified a new blockchain-based command-and-control technique hiding inside two trojanized npm packages, bianira-ui and fluid-type-ui. Both are DPRK-linked clones of legitimate Tailwind CSS plugins, and both use the same trick to find their command server: they read it out of the destination address of a completely blank cryptocurrency transfer. We’re calling it NullReceiver, and we think it’s a deliberate improvement on EtherHiding."
        https://opensourcemalware.com/blog/nullreceiver-dprk-c2-technique
        https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html
      • COLDCARD Security Audit Phishing Attack Installs Remote Access Tool
        "A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. Proofpoint, which discovered the campaign, says it uses emails impersonating COLDCARD that claim a security audit is underway across its hardware cold storage wallet devices. The phishing campaign comes after attackers recently stole approximately 1,367 Bitcoin, worth an estimated $88.6 million, from 4,585 addresses using what is believed to be a random number generation flaw affecting multiple COLDCARD models and firmware versions."
        https://www.bleepingcomputer.com/news/security/coldcard-security-audit-phishing-attack-installs-remote-access-tool/
      • AI Has Enhanced Iran’s Asymmetric Playbook During The 2026 Conflict
        "Between January and June 2026, Tehran survived unprecedented military, economic, and political pressure by relying on its longstanding hybrid warfare model: blending asymmetric military operations, cyber operations, information warfare, proxy attacks, and coercive state control. Artificial intelligence (AI) enhanced these capabilities, acting as a force multiplier and almost certainly increasing the speed, scale, and effectiveness of Iranian operations. Ultimately, Iran demonstrated that its strategic resilience does not depend on possessing the most advanced AI capabilities; rather, the source of Iranian power remains the asymmetric playbook itself."
        https://www.recordedfuture.com/research/iran-ai-asymmetric-playbook
        https://assets.recordedfuture.com/insikt-report-pdfs/2026/ta-ir-2026-0716.pdf

      Breaches/Hacks/Leaks

      • Leaked n8n API Tokens Exposed Live Instances To Credential Theft
        "GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability. We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896 instances reachable at the time of testing, 321 accepted at least one leaked token. That means leaked credentials provided authenticated access to 36% of the reachable instances we tested, or roughly 26% of all hostnames identified in the commits."
        https://thehackernews.com/2026/08/leaked-n8n-api-tokens-exposed-live.html
      • 311,000 Impacted By Brown Health Medical Group-MA Data Breach
        "Lifespan Physician Group of Massachusetts, doing business as Brown Health Medical Group-MA, is notifying over 311,000 individuals that their personal, medical, and financial information was stolen in a data breach. The incident occurred in December 2025 at its Hawthorn location. It involved a historic file server, the healthcare organization says in a sample notification letter filed with the Massachusetts Office of Consumer Affairs and Business Regulation."
        https://www.securityweek.com/311000-impacted-by-brown-health-medical-group-ma-data-breach/
        https://securityaffairs.com/196681/uncategorized/brown-health-medical-group-ma-data-breach-exposes-information-of-311000-individuals.html
      • Dutch Retailer De Bijenkorf Warns Customer Data May Be Exposed After Cyber Incident
        "A cyberattack on one of the logistics providers serving Dutch luxury department store chain De Bijenkorf has delayed customer orders, returns, and refunds while potentially exposing customer data. The incident is one of several in recent months that has disrupted retail and food companies through third-party contractors. The Amsterdam-based retailer said Wednesday that the incident affected only the systems of an external logistics partner and that there is currently no indication its own infrastructure was compromised."
        https://therecord.media/de-bijenkorf-luxury-retailer-third-party-cyber-incident
      • Brazilian Government Health Surveillance Platform Exposed 79GB Of Sensitive Data Online
        "Cybersecurity Researcher Jeremiah Fowler uncovered a data leak involving what appears to be a Brazilian government application and licensing portal containing personally identifiable information (PII) and shared his findings with ExpressVPN. We are publishing his report to help keep the public informed and protected as part of our ongoing effort to make the web a safer place."
        https://www.expressvpn.com/blog/brazil-sisvisa-data-exposed/
        https://hackread.com/brazil-health-surveillance-database-exposed-records/
      • Beacon CRM, Widely Used By Charities, Suffers Data Breach
        "Cloud-based customer relationship management software provider Beacon CRM said it's suffered a security breach that likely led to the theft of customer data. London-based Beacon said it first learned on July 29 that its systems may have been breached. Beacon says its CRM system is used by over 1,000 charities and non-profit organizations, ranging from Special Olympics Ireland and Great Lakes Outreach to Heart Research UK, to handle everything from collecting online donations, to managing memberships and selling tickets to events."
        https://www.bankinfosecurity.com/beacon-crm-widely-used-by-charities-suffers-data-breach-a-32420

      General News

      • Ransom Cartel Ransomware Creator Sentenced To 16 Years In Prison
        "Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. The U.S. Department of Justice announced today that the 40-year-old Belarusian national was sentenced for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft. The DOJ says Silnikau had been active on Russian-speaking cybercrime forums since at least 2005 and used the aliases "J.P. Morgan," "xxx," and "lansky.""
        https://www.bleepingcomputer.com/news/security/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison/
      • Canadian Pleads Guilty To Snowflake Cloud Data-Theft Attacks
        "A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. ​26-year-old Connor Riley Moucka, also known as Alexander Moucka and Waifu, was arrested on October 30, 2024, for stealing data of hundreds of millions of individuals from companies using Snowflake’s storage service."
        https://www.bleepingcomputer.com/news/security/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks/
        https://therecord.media/guilty-plea-snowflake-hack-connor-riley-moucka
        https://cyberscoop.com/connor-moucka-guilty-snowflake-attack-spree/
      • Google Blogger Locks Hundreds Of Blogs In Malware False Positive
        "Google has locked hundreds of Blogger websites after a false positive claimed they violated its "Malware and Similar Malicious Content" policy, with some sites actually deleted from the platform. The issue began on August 4, and it appears to affect many legitimate blogs that do not host malware or have malicious scripts. As seen by BleepingComputer, hundreds of web admins have reached out to Google on the company's official forum for help in restoring access to their blogs."
        https://www.bleepingcomputer.com/news/google/google-blogger-locks-hundreds-of-blogs-in-malware-false-positive/
      • AI Sends Global Crime Syndicates Into Fraud Nirvana
        "In bad news for financial institutions, online retailers, cryptocurrency exchanges, and people in the dating pool who rely on identity verification to make sure they're not getting taken for a ride, global fraud gangs are aggressively industrializing their scam efforts. That's according to Eric Huber, senior manager for adversary intelligence and disruption at TD Bank, who said that major centers for organized crime specializing in financial fraud (notably in Southeast Asia and West Africa) are bypassing "know your customer (KYC)" rules and other identity-verification methods with an updated AI tool set that offers the ability to build completely believable synthetic identities capable of fooling even advanced AI-enabled behavioral defenses."
        https://www.darkreading.com/threat-intelligence/ai-global-crime-syndicates-fraud-nirvana
      • CSS: The Hidden Threat Lurking In Your Inbox
        "Using email platforms to target users is nothing new in the world of threat actors. Nor is it revolutionary for defenders who've shored up guardrails when it comes to suspicious attachments, malicious JavaScript, and more. But as these well-known threats take command of everyone's attention, another vector remains hidden in plain sight. While HTML is the structure that powers web pages, Cascading Style Sheets (CSS) address design and presentation of the page. From the text to colors and tags to images, CSS manages how a page is displayed. And according to Gareth Heyes, Web security researcher at PortSwigger, it can be weaponized because of its multiple capabilities."
        https://www.darkreading.com/cyberattacks-data-breaches/css-hidden-threat-lurking-inbox
      • Cybersecurity Skills Gap: More Than Just a Workforce Challenge
        "The cybersecurity skills gap is no longer just about filling open positions. Now, the challenge is how organizations can defend against an increasingly sophisticated, AI-powered threat landscape. The recently released Fortinet 2026 Cybersecurity Skills Gap Report reveals data that underscores how critical this challenge has become: 71% of organizations surveyed say the cybersecurity skills gap creates additional risk for their organization, and 86% experienced at least one breach in the past year. Regarding the breaches, more than half (56%) of the organizations attributed them in part to a lack of cybersecurity skills and trained IT security staff."
        https://www.fortinet.com/blog/industry-trends/cybersecurity-skills-gap-more-than-just-a-workforce-challenge
        https://www.fortinet.com/content/dam/fortinet/assets/reports/2026-cybersecurity-skills-gap-report.pdf
      • New Research: The Confidence Gap Between CISOs And Their Boards Is Real, And It’s Measurable
        "Boards of directors believe they understand their company’s security posture and what it means for the business. The security leaders presenting to them are far less sure. Only 12.5% of security leaders are very confident their board walks away understanding the true state of the program, and 55% of boards have never formally defined what cyber risk the company is willing to accept. Pulse Security AI unveiled these findings today in The CISO-Board Communication Gap, a research report drawing on more than 80 senior practitioners, examining how security leaders report to their boards and what gets lost between the two."
        https://hackread.com/new-research-the-confidence-gap-between-cisos-and-their-boards-is-real-and-its-measurable/
        https://pulsesecurity.ai/newsroom/ciso-board-communication-gap/
      • Your Enterprise AI Footprint Is About Three Times Bigger Than Your Model List
        "Organizations are building AI systems that combine models, agents and external tools instead of relying on standalone AI, according to Snyk’s latest State of Agentic AI Adoption report. The study analyzed 3,044 enterprise environments and 1.39 million code repositories to examine how enterprises are deploying AI. Of organizations using AI, 46.9% have adopted agentic architectures built on AI agents, model context protocol (MCP) servers, or both. More than half have deployed the full stack, combining AI agents with MCP infrastructure that enables access to enterprise data, applications, services and external tools."
        https://www.helpnetsecurity.com/2026/08/05/snyk-growing-agentic-ai-adoption-report/
      • Prompt Injection Remains Biggest LLM Risk, Despite Limited Incidents
        "Prompt injection attacks continue to present the most dangerous threat from large language models (LLMs), despite the relatively low number of recorded incidents relating to this vector, according to an updated analysis from the Open Worldwide Application Security Project (OWASP). The non-profit foundation published the third version of its community-driven Top 10 for LLM Applications list, on August 4, 2026. For the third year in a row, practitioners listed prompt injection as the number one security challenge emanating from the use of GenAI tools."
        https://www.infosecurity-magazine.com/news/prompt-injection-llm-risk/
        https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/
      • Cyberspace Is Now The Fourth Domain Of Military Conflict.
        "Geopolitics can be summarized as the behavior of a country or region influenced by its location in time (history and current events), and space (geographical proximity to other countries or regions). Those geopolitical actions are also influenced by the state of the economy and the psychology of its leaders. Geopolitical disagreements between countries are usually settled by diplomacy but sometimes by physical force of arms. The latter is usually a kinetic war involving, as necessary and available, land (an Army), air (an Air Force) and the sea (a Navy)."
        https://www.securityweek.com/the-fourth-battlefield-the-growing-role-of-cyber-operations-in-global-conflict/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) c86b39c1-800b-43e5-9cf7-9e41d2c902f3-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ Langflow, N-central และ Apache Tomcat ที่ถูกใช้โจมตีจริงลงใน KEV

      CISA เพิ่มช่องโหว่ Langflow, N-central และ Apache Tomcat ที่ถูกใช้โ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ac1b7861-19ff-4319-885d-069961f6c5ae-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Greatness Phishing Service ปลอมแปลง RingCentral เพื่อขโมยบัญชี Microsoft 365

      Greatness Phishing Service ปลอมแปลง RingCentral เพื่อขโมยบัญชี Microsoft 36.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fb00c705-dfe6-4161-b8ca-4f8cec29067e-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • บัญชีอีเมลที่ผูกกับ AI อาจกลายเป็นภัยคุกคามรูปแบบใหม่จากคนภายในองค์กร

      บัญชีอีเมลที่ผูกกับ AI อาจกลายเป็นภัยคุกคา.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand df92455f-cc39-4205-8e21-a242a62de301-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT