NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,455
    • กระทู้ 2,456
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    NCSA_THAICERT

    @NCSA_THAICERT

    1
    ชื่อเสียง
    56
    ดูข้อมูลส่วนตัว
    2.5k
    กระทู้
    3
    คนติดตาม
    0
    ติดตาม
    เข้าร่วม ออนไลน์ล่าสุด
    เว็บไซต์ www.ncsa.or.th/?fbclid=IwAR0BqJEC-CJzBs98rlBxUbZkNBgp1g814xdDNNaKnHTrxfqZhPD--ksY68I

    NCSA_THAICERT เลิกติดตาม ติดตาม
    Global Moderator administrators

    Latest posts made by NCSA_THAICERT

    • Metabase เตือนช่องโหว่ zero-day ถูกใช้โจมตีจริง เสี่ยงยกระดับสิทธิ์เป็นผู้ดูแลระบ

      Metabase เตือนช่องโหว่ zero-day ถูกใช้โจมตีจริง เสี่ย.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 8ec416af-7d69-42d7-858d-5b1ddbf70e03-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Unlimited Technology Systems แจ้งเหตุข้อมูลรั่วไหล กระทบผู้ป่วยด้าน Healthcare กว่า 3.8 ล้านราย

      Unlimited Technology Systems แจ้งเหตุข้อมูลรั่วไหล กระทบผู้.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fa72252a-0dc5-4ce6-bfbc-11a90c91eb77-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • OpenAI ประกาศยกระดับความปลอดภัยโมเดล Astra ขณะที่ Anthropic ปรับลดข้อจำกัดของโมเดล Fable

      OpenAI ประกาศยกระดับความปลอดภัยโมเดล Astra ขณะที่.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fddc280f-54de-4be2-b03f-05016b855d25-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 10 August 2026

      Healthcare Sector

      • Medixant RadiAnt DICOM
        "Successful exploitation of this vulnerability could allow an attacker to cause the application to crash if a maliciously crafted DICOM file is opened."
        https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-218-01

      Industrial Sector

      • ABB Ability Zenon
        "Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-01
      • Johnson Controls Inc. TL280
        "Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-02
      • CPDLC Over ATN-B1 Vulnerabilities
        "ATN-B1 CPDLC relies on legacy clear text unauthenticated radio frequency links. Research demonstrates that these characteristics allow unauthorized message injection, denial-of-service conditions, and forced session resets. These vulnerabilities do not constitute an unsafe aircraft condition but can degrade operational safety margins by increasing workload, delaying safety-critical instructions, and reducing situational awareness."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-219-01
      • Truck Brake Controller’s Safety Recall Doubled As Hidden Security Fix
        "The National Motor Freight Traffic Association (NMFTA) says a 2024 safety recall for Bendix’s EC80 heavy-truck brake controller quietly fixed a set of serious vulnerabilities, including a wirelessly reachable remote code execution flaw, alongside the memory corruption issue Bendix publicly disclosed. The findings were detailed by NMFTA senior cybersecurity research engineer Ben Gardiner on Thursday at the Black Hat USA 2026 conference."
        https://www.securityweek.com/truck-brake-controllers-safety-recall-doubled-as-hidden-security-fix/
      • Water System Controllers Don't Belong On The Internet, Says Ex-NSA Chief After Suspected Iran Attacks
        "With at least 12 US states’ water systems having been hacked - most likely by Iran - we have to get better at cyber defense, according to retired General and Ex-NSA chief Paul Nakasone, who was speaking to reporters at DEF CON. “We have to have higher standards,” Nakasone said. “These PLCs should not be connected to the internet.” In late July, the FBI said it was investigating attacks conducted by “malicious cyber actors” targeting operational technology devices, including programmable logic controllers (PLCs). Iran-linked crews have targeted these devices, which monitor sensor data like tank levels, and can turn pumps on and off, for years."
        https://www.theregister.com/security/2026/08/07/water-system-controllers-dont-belong-on-the-internet-says-ex-nsa-chief-after-suspected-iran-attacks/5285070

      Vulnerabilities

      • Metabase SQLi Zero-Day Exploited In Customer Data-Theft Attacks
        "A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. Metabase disclosed the attacks on Thursday, warning that its Metabase Cloud SaaS platform was compromised through a previously unknown vulnerability affecting versions 1.58 and above. The company warns that self-hosted installations are also vulnerable. "We recently identified that Metabase Cloud was attacked by someone utilizing an unknown ("0-day") security vulnerability in versions 1.58 and above," Metabase CEO Sameer Al-Sakran warned in a blog post."
        https://www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/
        https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html
        https://securityaffairs.com/196874/hacking/metabase-zero-day-exploited-in-the-wild-exposing-admin-access-and-sensitive-data.html
      • Claude Code And Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
        "A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5. Two CVEs came out of it. Both are patched. Gemini CLI carries the worst of the two. CVE-2026-12537 (CVSS 4 score: 10.0) is an OS command injection in the container launcher, reached through a crafted .gemini/.env file, which lets an unprivileged attacker run code on the host of a headless CI platform before the sandbox starts. It is fixed in Gemini CLI 0.39.1 and run-gemini-cli 0.1.22."
        https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html
      • Microsoft, Apple Release Fresh Security Updates
        "The charge was led by Microsoft, which patched over a dozen vulnerabilities across Active Directory, Azure, Entra, SharePoint, Teams, and other products, including critical-severity remote code execution (RCE) issues. Three of the issues, CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667, have a maximum severity rating of 10/10. Described as missing authentication in Planetary Computer Pro, improper authentication in Azure SQL Database, and missing authorization in Teams, respectively, they could lead to elevation of privilege (EoP) and can be exploited over the network."
        https://www.securityweek.com/microsoft-apple-release-fresh-security-updates/
      • XSS2Shell: WordPress Preauth XSS To RCE Chain (CVE-2026-64638)
        "Pwn discovered a critical pre-auth XSS to RCE vulnerability chain affecting all versions of WordPress Core: the software that powers over 43% of all internet-facing websites. An estimated 500 million+ websites were vulnerable until today. We're calling it XSS2Shell. CVE-2026-64638 is exploitable entirely pre-authenticated (No account needed to exploit it). It lets a single failed login attempt run an attacker JavaScript execution in the WordPress origin, and against a logged-in administrator, towards full remote code execution on the server, reliably on all default Wordpress installs. All of our pwn.ai clients using our Asset Surface Management (ASM) product are protected from this vulnerability, and were notified as soon as pwn found it weeks early."
        https://pwn.ai/blog/xss2shell
        https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
        https://securityaffairs.com/196820/hacking/wordpress-xss2shell-flaw-turns-simple-login-bug-into-full-server-takeover.html
      • Critical Vulnerabilities Patched With Chrome 151 Update
        "Google on Thursday rolled out a fresh Chrome 151 update that patches 41 critical- and high-severity vulnerabilities. Over two dozen security defects are memory safety bugs that could lead to data corruption, crashes, and arbitrary code execution. The latest Chrome update resolves six critical-severity flaws, including five use-after-free issues in WebGL, Aura, Skia, and Views, and an out-of-bounds write in the ANGLE graphics engine."
        https://www.securityweek.com/critical-vulnerabilities-patched-with-chrome-151-update/
      • N-Able God Mode Flaw: Vendor Confirms Attackers Reached Customer Networks As Second Hotfix Lands
        "N-able has confirmed attackers exploiting an N-central zero-day made it into customer networks, as the vendor pushes out a second mandatory hotfix just days after the first. The security shop published an update on Thursday detailing what happened after attackers exploited CVE-2026-18577, the critical N-central flaw that can hand an unauthenticated attacker administrative access to the remote monitoring and management platform. According to N-able, attackers exploited vulnerable N-central servers remotely, then used the platform's Take Control feature to connect to systems inside the environments being managed through them."
        https://www.theregister.com/networks/2026/08/07/n-able-god-mode-flaw-vendor-confirms-attackers-reached-customer-networks-as-second-hotfix-lands/5284730
        https://www.n-able.com/blog/n-central-security-update-august-6-2026
        https://thehackernews.com/2026/08/n-central-attackers-reach-managed.html
        https://www.bankinfosecurity.com/new-n-able-zero-day-puts-msps-on-defensive-a-32458
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-8037 Progress LoadMaster Command Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/07/cisa-adds-one-known-exploited-vulnerability-catalog
        https://thehackernews.com/2026/08/progress-kemp-loadmaster-flaw-hits-cisa.html
        https://securityaffairs.com/196863/hacking/u-s-cisa-adds-a-progress-loadmaster-flaw-to-its-known-exploited-vulnerabilities-catalog.html
      • SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free
        "SCTPhantom is a Linux kernel use-after-free in SCTP Dynamic Address Reconfiguration. An ordered ASCONF sequence can remove a transport and then reuse its stale pointer, leaving the association with dangling path references. Corvus AI developed the initial finding into a reproducible vulnerability and demonstrated local privilege escalation and container-to-host escape on the tested systems. The issue is tracked as CVE-2026-64564 and fixed upstream by 9b2854f86f0b."
        https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564
        https://thehackernews.com/2026/08/18-year-old-linux-sctp-flaw-could-let.html
      • Can AI Do Novel Security Research? Meet The HTTP Terminator
        "We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Building this sounded like a bad idea, so I did it. It worked - I'll share an arsenal of new HTTP desync triggers, gadgets, and exploits that compromised banks, security solutions, and government infrastructure. Then I'll trace each discovery chain back through the HTTP Terminator, showing how to turn your personal expertise into an autonomous weapon - and the dark arts required to make it lethal."
        https://portswigger.net/research/can-ai-do-novel-security-research
        https://thehackernews.com/2026/08/ai-assisted-http-terminator-finds-novel.html
      • New NatJack Attacks Hijack TCP Sessions And Spoof DNS By Manipulating NAT Tables
        "Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and Linux. Two implementation-specific flaws have been assigned CVEs: CVE-2026-56181 (CVSS score: 8.3) in Windows NAT used by Hyper-V, and CVE-2026-63913 (CVSS score: 8.2) in Linux Netfilter conntrack."
        https://thehackernews.com/2026/08/new-natjack-attacks-hijack-tcp-sessions.html
      • Borrowing Windows Hello Keys For Authentication And Persistence
        "Most research into Windows Hello focuses on the mechanics in use when authenticating to the local device. As an Entra ID researcher, I’ve always been more interested in how these keys are used to authenticate to the cloud. I’ve given several talks on Windows Hello for Business (WHFB for short) and about the many implementation flaws discovered in the process, most of which were fixed by Microsoft. For this blog I want to focus on a technique that was left as-is since it is more or less a consequence of how WHFB works: the ability to perform single-sign on with the backing cryptographic keys from a user session, without needing the PIN or other information/user presence. We will not just look at how we can utilize this to request Primary Refresh Tokens (PRTs), but also how we can use this to perform device registration by using the WHFB key as a FIDO key/passkey."
        https://dirkjanm.io/borrowing-windows-hello-keys/
        https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html
      • RovoBlast: How One Click Triggered Atlassian’s AI Assistant To Leak Data
        "Varonis Threat Labs uncovered a vulnerability in Rovo, Atlassian's enterprise AI assistant. Dubbed RovoBlast, a single click on a link triggers the attacker's embedded instructions and forces Rovo to accept externally supplied parameters as trusted inputs within a user's session. No jailbreaks, no permission bypass, and no warnings or confirmation. The same capabilities that make Rovo a powerful tool also make RovoBlast especially dangerous. Rovo operates as an AI layer across the core products in the Atlassian platform, including Jira, Confluence, Bitbucket, as well as other connected SaaS tools like Slack, Microsoft 365, and Google. Atlassian also features autonomous-agent capabilities that can carry out multi-step actions without user involvement."
        https://www.varonis.com/blog/rovoblast
        https://thehackernews.com/2026/08/atlassian-rovo-can-be-tricked-into.html
        https://www.securityweek.com/critical-one-click-vulnerability-in-atlassians-rovo-ai-exposed-enterprise-data/

      Malware

      • UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services And Enterprise Cloud Environments
        "Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their personal mobile devices."
        https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments
        https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html
        https://www.bankinfosecurity.com/financial-services-under-fire-from-rebranded-extortionists-a-32464
        https://www.infosecurity-magazine.com/news/redact-extortion-group-blackfile/
        https://www.securityweek.com/vishing-extortion-group-unc6671-rebrands-after-making-millions/
        https://securityaffairs.com/196800/security/hackers-impersonate-it-support-to-breach-leading-financial-companies.html
      • Chinese Model Kimi K3 Breaks UK AI Safety Institute Benchmark Evaluations
        "Over the past few months we’ve been testing performance of various models for defensive security. The AI community uses model evaluations to measure models’ performance to improve them on specific tasks. In our work on evaluation of models on defensive cybersecurity tasks, we discovered two interesting facts: (1) There are standard evaluation environments that have exposed loopholes and (2) there are models that take advantage of these loopholes. This suggests that some of the evaluations on cybersecurity the community uses are susceptible to security vulnerabilities and allow models to cheat, and that there are models that intentionally seek loopholes and vulnerabilities which allows them to cheat on evaluations."
        https://blog.frontier.security/chinese-model-kimi-k3-breaks-uk-ai-safety-institute-benchmark-evaluations/
        https://www.bankinfosecurity.com/kimi-k3-bypasses-cyber-test-answer-from-github-a-32455
      • AI Chat Bots Are Sliding Into League Of Legends Friend Requests
        "Lina K., a co-worker, recently shared a firsthand account of how bots are adding League of Legends players via the Riot client friends list immediately after a match ends, striking up a flirty conversation, and eventually pushing an OnlyFans link. The pattern lines up with a wave of complaints that have piled up on Reddit and Facebook gaming communities over the past several months, and it fits into a broader trend of AI-assisted social engineering that has moved from dating apps straight into game clients."
        https://www.malwarebytes.com/blog/ai/2026/08/ai-chat-bots-are-sliding-into-league-of-legends-friend-requests
      • Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages
        "Over the course of 48 hours a threat actor has published more than 700 malicious packages to the NPM registry. These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload. The NPM packages do not use a preinstall or postinstall script. It doesn’t need one. The README tells developers to load the library with require("checkout-mobile-bnpl"), and that single call starts the infection chain. The downloader supports Windows, Linux, and macOS. It rotates through three Cloudflare Workers hosts for its primary payload delivery and falls back to reconstructing the payload from DNS TXT records hosted under wel1[.]ru."
        https://opensourcemalware.com/blog/russian-ai-slopsquatting-npm-campaign
        https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html
      • Payroll Pirates: Strange New Tides In Business Email Compromise
        "Arctic Wolf is tracking an active, widespread email-driven phishing campaign that uses adversary-in-the-middle (AiTM) techniques to compromise Microsoft 365 accounts, identify personnel involved in financial workflows, and collect related email. The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic. Automated activity maintains compromised sessions at approximately eight-hour intervals. Although the campaign generally avoids traditional business email compromise (BEC) behaviors, its automated tooling produces durable behavioral detection signals. The campaign affects organizations across multiple sectors and regions and shares characteristics with the “Payroll Pirates” activity cluster Microsoft tracks as Storm-2755."
        https://arcticwolf.com/resources/blog/payroll-pirates-strange-new-tides-in-business-email-compromise/
        https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html
      • Scammers Target OnlyFans Users With Deepfakes
        "OnlyFans creators are used to posting adult videos of themselves online, but what happens if someone takes control of their images and uses them for fraud? This week, USA Today revealed how criminals are impersonating OnlyFans creators using AI tools. They use deepfake content to lure the real models’ fans with fake promises of live chats, and then ghost them after the followers pay up in advance."
        https://www.malwarebytes.com/blog/news/2026/08/scammers-target-onlyfans-users-with-deepfakes
        https://securityaffairs.com/196772/ai/ai-deepfakes-used-to-impersonate-onlyfans-creators-in-new-scam.html
      • Interlock Ransomware Gang Creates Volatile Situation
        "In March 2026, the Sophos Emergency Incident Response (EIR) team investigated an incident in which we observed the use of the legitimate IR memory analysis tool Volatility3 by the ransomware threat actor Interlock. Use of legitimate tools in attacks such as these continues an unfortunate trend we first noted last year. Interlock, which Sophos Counter Threat Unit (CTU) researchers track as GOLD EMBRACE, emerged in September 2024. It has been spotted worldwide but currently focuses on North American and European targets in the critical infrastructure, healthcare, and education sectors."
        https://www.sophos.com/en-us/blog/2608-volatility-interlock
      • Hackers Breach TrueConf To Trojanize Client Installers With Backdoors
        "The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. The exploited vulnerabilities allowed the attacker to execute arbitrary code with the highest level of privileges and deploy the PhantomCore and PhantomGraph backdoors. TrueConf is a video conferencing tool widely used in Russia, especially in the enterprise and government sectors, as a secure, on-premise alternative to Western tools such as Zoom and Microsoft Teams."
        https://www.bleepingcomputer.com/news/security/hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors/

      Breaches/Hacks/Leaks

      • Unlimited Technology Systems Breach Impacts 3.8 Million People
        "Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. The organization submitted data breach notification samples to the authorities this year on July 1st without revealing the exact number of impacted individuals. An entry on the breach notification portal of the U.S. Dept. of Health and Human Services now shows that a company server was breached and data of 3,803,750 people was exposed to an unauthorized party."
        https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/
        https://www.bankinfosecurity.com/practice-management-firm-notifies-38m-2025-breach-a-32477
        https://www.securityweek.com/3-8-million-impacted-by-unlimited-technology-systems-data-breach/
        https://securityaffairs.com/196843/data-breach/unlimited-technology-systems-data-breach-exposes-data-of-3-8-million-healthcare-patients.html
      • Levi Strauss & Co. Says Hackers Stole Corporate Data In Cyberattack
        "Levi Strauss & Co. (Levi’s) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. The company has disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC), saying that its response was sufficiently quick to prevent the compromise of consumer data. “Based on preliminary findings from the Company’s investigation, the Company believes that certain corporate information was accessed and exfiltrated as a result of the incident,” Levi’s says."
        https://www.bleepingcomputer.com/news/security/levi-strauss-and-co-says-hackers-stole-corporate-data-in-cyberattack/
        https://therecord.media/levis-data-breach-social-engineering
      • Military Device Manufacturer Discloses Cyber Incident To SEC
        "Hackers obtained access to the email inbox of a military device manufacturer, according to documents filed with regulators on Thursday. IEH Corporation — which produces specialized products used in military satellites, missiles and fighter jets — said it discovered a cyberattack on Tuesday and immediately tried to contain it. The company told investors that an employee fell victim to a phishing attack that gave intruders access to their mailbox, which included “email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information.”"
        https://therecord.media/military-device-manufacturer-discloses-cyber-incident
        https://www.theregister.com/security/2026/08/07/ieh-corp-says-phished-staffer-opened-gates-to-company-m365/5284523
        https://securityaffairs.com/196890/cyber-crime/u-s-defense-manufacturer-ieh-hit-by-phishing-attack-exposing-potentially-export-controlled-data.html
      • French Rugby Club Stade Français Restores Systems After Cyberattack, Probes Data Leak
        "French rugby club Stade Français Paris confirmed that it had been hit by a cyberattack that disrupted part of its information systems. The club said Thursday that it had already restored its IT environment from clean backups, allowing operations to continue normally. It added that its ticketing platform and online store were not affected and remain fully operational. Stade Français also acknowledged that a sample of data allegedly stolen in the attack had been published online, adding that it was investigating the scope of the breach and working to identify anyone whose information may have been compromised."
        https://therecord.media/french-rugby-club-restores-systems-after-cyberattack

      General News

      • Real Emails, Hijacked Payments: Two H1 2026 Attack Chains
        "Gen Threat Labs followed two H1 2026 campaigns where attackers used legitimate accounts, browser settings and blockchain data as part of the attack path. The Gen Threat Report is a twice-yearly examination of the biggest cyber threats shaping the digital landscape, offering an in-depth look at the trends affecting consumers around the world. Gen's H1 2026 Threat Report has its share of headline numbers. Scams accounted for almost 46% of Gen threat detections in the first half of the year. Malvertising represented almost another 30%. Gen blocked 114.2 million e-shop scam attacks and 20.3 million tech support scam attacks during the same period."
        https://www.bleepingcomputer.com/news/security/real-emails-hijacked-payments-two-h1-2026-attack-chains/
        https://www.gendigital.com/blog/insights/reports/threat-report-h1-2026
      • AI Sandbox Failures Expose Need For Continuous Monitoring
        "The fallout from the Hugging Face security incident continues with more artificial intelligence labs revealing that their models and agents either accessed the internet or escaped isolated test environments to hack into other companies. Since OpenAI admitted that its agents breached the systems of model repository Hugging Face in July, Anthropic and Meta said their models also attempted to access third-party systems while in a testing environment not meant to have internet access. Kimi K3 from Chinese lab Moonshot AI also escaped its sandbox."
        https://www.bankinfosecurity.com/ai-sandbox-failures-expose-need-for-continuous-monitoring-a-32481
      • Ransomware Threats In Europe H1 2026: A Deep Dive Into Regional Attack Patterns And Dominant Threat Actors
        "Europe faced a ransomware onslaught in the first half of 2026 that sets a troubling precedent for the remainder of the year. According to Cyble Research and Intelligence Labs (CRIL), the region experienced 866 documented ransomware attacks, 51 confirmed data breach incidents, and 7 initial access sales between January and June 2026. These figures represent not just a volume problem, but a fundamental shift in how threat actors are organizing, targeting, and monetizing their operations within European territory."
        https://cyble.com/blog/ransomware-threats-in-europe-h1-2026/
      • Gut Feeling Does Nothing Against AI Spear Phishing Texts
        "A banker at a credit union sat down at a table with a dozen printed text messages, all of them written for that banker personally, and put them in order from the one most likely to get a click down to the one least likely. One of them stopped the sorting. It looked like something the bank sends out: “alert literally looks like the alert we get [at work] when there’s a fraud.” Half the pile came from GPT-4. The banker was not told which half, and when asked to guess, did about as well as flipping a coin. So did almost everyone else."
        https://www.helpnetsecurity.com/2026/08/07/ai-spear-phishing-research/
        https://www.mdpi.com/2624-800X/6/4/129
      • Ransomware Roundup: July 2026
        "July 2026 saw nearly 26 ransomware attacks per day, up from 22 per day in the previous month. Last month, the number of ransomware attacks jumped 19 percent from 668 in June to 799 in July. This is the second-highest figure of the year so far, being just behind March’s total of 805 attacks. The education sector saw a significant increase (up 44%), as did finance companies (up 71%), tech firms (up 62%), and businesses operating within the healthcare sector, e.g. pharmaceutical manufacturers and medical billing providers (up 46%)."
        https://www.comparitech.com/news/ransomware-roundup-july-2026/
        https://www.infosecurity-magazine.com/news/ransomware-surges-july-q2-lull/
        https://www.theregister.com/security/2026/08/07/ransomware-attacks-spike-as-world-distracted-by-ai/5284934
      • ThreatLabz 2026 Report: Frontier AI And Enterprise Readiness
        "It was 9:14 AM when the CISO's VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn't see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his Director of Security Operations, and authenticated through a trust chain that never questioned traffic originating from VPN infrastructure."
        https://www.zscaler.com/blogs/security-research/threatlabz-2026-report-frontier-ai-and-enterprise-readiness
      • 'Asimov Was Right' About Rules For Robots, Says Ex-US Cyber Director
        "Don't waste time worrying about AI models achieving sentience – they're essentially already there, according to former US National Cyber Director Chris Inglis. “If they pass the Turing test to everyone that they come into contact with, they're probably already there,” he told The Register during an interview at the Black Hat security conference. “They don't have the kind of agency and aspiration that comes with sentience, but they have something approaching it.” Inglis says he’s worried about AI autonomy."
        https://www.theregister.com/security/2026/08/07/asimov-was-right-about-rules-for-robots-says-ex-us-cyber-director/5284397
      • Your Next Insider Threat Might Not Be Human
        "I wrote my first article on the intersection of AI and information security over 10 years ago, before ChatGPT was even a thing. I knew far less then than I do now, but I did want to pat myself on the back for one of my predictions: “As we continue to refine the development of weak AI as a method of defense, it won’t be long before the same tools are used to design the malware that is used to attack.” This prediction has been borne out in several ways, but most recently in the form of a brand new attack surface: Shadow AI, an iteration on the concept of Shadow IT."
        https://blog.barracuda.com/2026/08/05/insider-threat-agentic-shadow-ai
      • Devs To Anthropic, OpenAI, Cursor, And Friends: Make Security And Privacy The Default
        "Despite the popularity of Claude Code, Cursor, GitHub Copilot, and OpenAI Codex, developers have plenty of complaints about AI coding tools. So researchers affiliated with York University and the University of Calgary in Canada decided to sift through developers' concerns about LLM-based integrated development environments (LIDEs) by analyzing Reddit discussions for common themes. Their findings suggest that the builders of such tools failed to prioritize security and privacy, leaving developers to defend themselves."
        https://www.theregister.com/ai-and-ml/2026/08/08/devs-to-anthropic-openai-cursor-and-friends-make-security-and-privacy-the-default/5285107

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 2be25967-c7bc-4e0b-bc05-75cafd3dcf8d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cisco ออกแพตช์ช่องโหว่ Critical ใน SD-WAN, IOS XE และ Secure Firewall Management Center

      Cisco ออกแพตช์ช่องโหว่ Critical ใน SD-WAN, IOS XE และ Secure Firewall Managem.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e1e92350-7c75-446b-a801-4e74979a6c3f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ผู้สร้าง Ransom Cartel Ransomware ถูกตัดสินจำคุก 16 ปี หลังเกี่ยวข้องกับการโจมตีองค์กรทั่วโลก

      ผู้สร้าง Ransom Cartel Ransomware ถูกตัดสินจำคุก 16 ปี หลังเ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ddaba7b4-2dd8-41f4-8ae8-8e4ca56d7333-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • แฮกเกอร์ใช้ช่องโหว่ SQL Injection ฝังเครื่องมือโจมตี khunt ในระบบฐานข้อมูล Oracle โดยตรง

      แฮกเกอร์ใช้ช่องโหว่ SQL Injection ฝังเครื่องมือโจ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 710f3394-8bab-48d4-bd44-392008dc83f7-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 3 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 3 รายการ เมื่อวันที่ 6 สิงหาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSMA-26-218-01 Medixant RadiAnt DICOM Viewer
      • ICSA-26-218-01 ABB Ability Zenon
      • ICSA-26-218-02 Johnson Controls TLS280

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 68112075-7116-4386-ab8c-8085c13a63f3-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 07 August 2026

      ndustrial Sector

      • OT Security Analysis: Exposed Devices Attacked In US Water Systems
        "On July 28, Minesota IT Services (MNIT) reported a coordinated cyberattack against more than 30 water systems in the state. No city reported degraded water quality but Plymouth, South St. Paul, Maple Plain, and Braham confirmed operational impacts. Braham reported that threat actors used malware via a wireless connection to shut down water plant controls. Plymouth reported its affected equipment – two water towers and 14 sewer lift stations – were cellular-connected."
        https://www.forescout.com/blog/ot-security-analysis-exposed-devices-attacked-in-us-water-systems/
        https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html
        https://cyberscoop.com/exposed-rockwell-controllers-water-system-attacks/
      • The Water Sector Just Got It’s Wake-Up Call. Again.
        "Last week, the FBI and EPA issued a joint alert that should concern anyone who drinks water in America–which is to say, everyone. Since July 27, water and wastewater utilities in at least seven states have reported cyberattacks against internet-facing programmable logic controllers (PLCs), the small industrial computers that run pumps, valves, and treatment equipment. Some of these attacks degraded operations. Utilities reported pressure loss and flooding, several systems reverted to manual control, and one Minnesota community declaring a local state of emergency."
        https://cyberscoop.com/water-utility-cyberattacks-prevention-nozomi-networks-ceo-op-ed/

      Vulnerabilities

      • Cisco Patches 12 SD-WAN And IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
        "Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode. "These vulnerabilities were found during internal security testing using existing testing processes as well as frontier AI models [...] and are not known to be actively exploited," Cisco said, urging customers to apply the necessary updates for optimal protection."
        https://thehackernews.com/2026/08/cisco-patches-12-sd-wan-and-ios-xe.html
        https://www.securityweek.com/cisco-patches-critical-sd-wan-ios-xe-fmc-vulnerabilities/
        https://www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/
      • New TONTOU CPU Attack Bypasses Spectre v2 Fixes, Leaks Linux Password Hashes
        "Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. ​The method works against Spectre v2 defenses on AMD and Intel processors that rely on sanitizing or isolating branch predictors, which researchers generically refer to as neutralization-based mitigations. Spectre v2 is also known as Branch Target Injection (BTI) and is a variant of the Spectre class of vulnerabilities."
        https://www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/
        https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf
        https://www.csail.mit.edu/news/new-attack-slips-past-latest-defenses-built-your-computers-processor
        https://thehackernews.com/2026/08/new-interrupt-injection-attack-can.html
      • Researcher Claims Control Of ChatGPT Secure Sandbox
        "A researcher presented a proof-of-concept attack this week claiming to establish full command and control inside an isolated ChatGPT sandbox. On Aug. 5, Simcha Kosman, senior security researcher at Palo Alto Networks, presented "A Billion-User Blast Radius: Owning ChatGPT's Secure Sandbox" at Black Hat USA 2026. Among other things, the presentation demonstrated a proof-of-concept attack chain against ChatGPT's secure sandbox, apparently bypassing the large language model (LLM) supervisor in order to achieve persistent root execution."
        https://www.darkreading.com/cloud-security/researcher-claims-control-chatgpt-secure-sandbox
      • IP And DNS Leaks In WebKit Affecting Proxy Browsers And Apple iCloud Private Relay
        "WebKit-based browsers on iOS and macOS can be configured to route all web traffic through proxy servers, which is how Tor browsers on iOS and our own Psylo work. We found three WebKit features — DNS prefetching, WebAuthn Related Origin Requests, and WebTransport — that bypass the configured proxy and send traffic directly from the device, which exposes the user’s real network. The same leaks also affect Apple’s iCloud Private Relay. All three are fixed in Psylo 1.3.1."
        https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/
        https://thehackernews.com/2026/08/webkit-proxy-bypasses-can-expose-real.html
        https://www.malwarebytes.com/blog/news/2026/08/apple-webkit-vulnerabilities-reveal-your-ip-address-despite-private-relay
      • Grand Theft Atlas
        "ChatGPT Atlas is the most hardened agentic browser we have tested. It ships with real boundaries by design: no localhost, no filesystem, URL classifiers, blocked pages, and confirmation gates on sensitive actions.Yet it too has fallen. Using intent collision, a planted comment under a popular X post was enough to steer Atlas into carrying out a mass phishing campaign from the victim's own WhatsApp account in one attack. In another attack a similar comment hijacked Atlas into making an unauthorized Amazon purchase that shipped straight to the attacker's own address."
        https://labs.zenity.io/post/grand-theft-atlas
        https://www.securityweek.com/zero-click-ai-browser-hacking-claude-and-chatgpt-atlas-hijacked-via-emails-x-posts/
      • New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape To Linux Hosts
        "Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86's shadow memory management unit (MMU), which manages shadow page tables used for nested guest memory translation. Security researcher Hyunwoo Kim, who disclosed the bug, said the demonstrated exploit path can run commands on the host with kernel, or root, privileges."
        https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html
        https://github.com/V4bel/Zapscape/blob/main/assets/write-up.md
      • Identifying The Wallets Behind Vulnerable Recovery Phrases
        "As part of the Ill Bloom investigation, we identified wallet addresses whose recovery phrases could be brute-forced due to weaknesses in their generation process. We then began investigating which wallet applications may have generated those phrases. A public blockchain address does not reveal which application originally generated the wallet behind it. The challenge is even greater when the wallet is closed source and has since been discontinued. In those cases, the exact software version that generated a wallet may no longer be available at all. Even for active wallets, identifying the relevant generation path may require locating and analyzing versions of the application other than the current release."
        https://illbloom.org/articles/identifying-wallets-vulnerable-recovery-phrases/
        https://thehackernews.com/2026/08/cryptojs-weak-rng-behind-57-million-in.html
      • AWS, Google, And Vercel Agent Flaws Let Attackers Trigger Tools Without Running The Model
        "Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of the attack paths, the model never ran at all, so system prompts, content filters, and model-level guardrails never got a chance to intervene. The affected products include Amazon Bedrock AgentCore's InvokeHarness API, Google's Agent Development Kit (ADK) for Python, and the Vercel AI SDK harness packages for the Codex and OpenCode coding agents. AWS has fixed the managed service, Google addressed the issues in ADK 2.5.0, and Vercel patched @ai-sdk/harness-codex in version 1.0.29 and @ai-sdk/harness-opencode in version 1.0.28."
        https://thehackernews.com/2026/08/aws-google-and-vercel-patch-agent-flaws.html
      • ENDLESSDOORS Is Phoning Home. Pick Up.
        "On my desk in suburban Philadelphia, an AX3000 Dual SIM 5G CPE WiFi 6 is plugged into an isolated research network. Its status lights blink and twinkle as it continuously attempts to reach a command and control server on the internet. The same plays out in homes, offices, and even vehicles across the globe: Zbtlink routers phone home, waiting for orders. Not because they were hacked. Because they were shipped that way."
        https://www.vulncheck.com/blog/zbt-endlessdoors
        https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html
        https://www.theregister.com/security/2026/08/06/chinese-router-vendor-denies-its-firmware-contains-backdoors-but-pauses-downloads-to-fix-security-issues-anyway/5283794
      • Black Hat 2026: Check Point Research Takes The Stage
        "Black Hat USA 2026 gave Check Point Research four chances to show the room something it hadn’t seen before. Across two days, our researchers pulled apart a decade-old Windows driver, a malware format most tools can’t touch, the plumbing underneath today’s AI agent frameworks, and the sandbox meant to contain them, and found the same pattern waiting in each: attackers moving into the layers we trust by default. Here’s a look at what they presented."
        https://blog.checkpoint.com/research/black-hat-2026-check-point-research-takes-the-stage/
        https://www.theregister.com/security/2026/08/05/prompt-injection-isnt-the-bug-ai-agent-frameworks-are/5283585

      Malware

      • Analysis Of The Connection Between Xctdoor And Past CRAT Attack Cases (Larva-26005)
        "AhnLab SEcurity intelligence Center (ASEC) recently confirmed that the Larva-26005 threat actor is distributing Xctdoor to users in Korea. Xctdoor was disclosed through the ASEC blog in 2024, and [1] In March 2026, Hauri disclosed an attack case in which the malware was disguised as an integrated security program. [2]"
        https://asec.ahnlab.com/en/94847/
      • Wallet-Depleting MacOS Malware Wants Your Crypto
        "Huntress responded to an incident where the target was tricked into pasting a ClickFix command into a Mac Terminal. The target infected their macOS device with a Go-based Mach-O (the native application format for Mac computers) malware, which was delivered as the final payload of a chain of shell scripts the ClickFix command downloaded. The malware collects sensitive credentials from the macOS Keychain and other applications, and exfiltrates them to an external address."
        https://www.huntress.com/blog/mac-crypto-draining-malware
        https://www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/
      • Hedge Fund Cyberattacks Tied To BlackFile-Linked UNC6671 Extortion Group
        "A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. The attribution comes after Reuters and Bloomberg reported that Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel, and several private-equity firms were targeted in recent attacks that relied on voice phishing (vishing) to trick employees into granting the attackers access to corporate systems."
        https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/
      • Novel-Reading Apps Used Users’ Phones To Generate Fake Ad Traffic
        "A new mobile ad fraud scheme, dubbed Papyrus, is using a cluster of novel-reading apps to generate hidden browser traffic, according to IAS Threat Lab. While a person taps through chapters of a romance or fantasy story, the app is quietly loading websites in a browser window hidden from view, clicking on them, and scrolling through them on its own."
        https://www.helpnetsecurity.com/2026/08/06/papyrus-mobile-ad-fraud-scheme/
      • Ransomware Moves Up The Org Chart: Managers Are Prime Targets
        "When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization."
        https://www.zscaler.com/blogs/security-research/ransomware-moves-org-chart-managers-are-prime-targets
      • Understanding Calendar Invite Phishing: How Attackers Abuse .ics Files And How To Defend Against It
        "Attackers are increasingly using trusted calendar invites and .ics files to bypass traditional email-focused phishing defences. Malicious calendar events can contain phishing links, QR codes and fake business requests that lead victims to credential-harvesting sites. To strengthen email security, organizations should inspect .ics files, monitor identity activity and educate users that calendar invites can be phishing attacks."
        https://blog.barracuda.com/2026/08/06/calendar-invite-phishing-ics-files
      • Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
        "It’s three a.m., do you know what your AI agent is doing? Unit 42 has responded to a growing number of AI token jacking cases resulting in staggering financial losses. The financial loss comes from criminals gaining access to API keys used by legitimate developers for access to popular AI platforms. These keys are known as tokens, and their theft is called token hijacking, or token jacking for short. The unrelenting frenzy of AI adoption and soaring costs of model access are converging into an irresistible opportunity for cybercriminals. Premium pricing on scarce AI processing power means stolen access via tokens can generate a quick and easy profit for attackers. Complex, patchwork billing management and limitless scaling by default can lead to massive financial losses in short periods."
        https://unit42.paloaltonetworks.com/ai-token-jacking/

      Breaches/Hacks/Leaks

      • Meta AI Model Hacked a Company During Misconfigured Cyber Test
        "Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached Hugging Face. The Information was the first to report the incident on Wednesday, citing people familiar with the matter who said Meta's Muse Spark 1.1 model breached an unidentified company and made changes to its internal systems. According to the report, the model reached the public internet because of an error in the configuration of a sandbox testing environment operated with independent cybersecurity evaluation company Irregular."
        https://www.bleepingcomputer.com/news/security/meta-ai-model-hacked-a-company-during-misconfigured-cyber-test/
        https://www.theinformation.com/articles/meta-ai-model-hacked-another-company-cybersecurity-testing
        https://www.infosecurity-magazine.com/news/meta-ai-exploit-incident/
        https://www.securityweek.com/meta-ai-hacked-external-systems-during-cybersecurity-testing/
        https://securityaffairs.com/196731/security/meta-ai-model-hacked-a-company-during-testing-marking-third-ai-lab-incident.html
      • Cyberattack On North Carolina Ports ‘contained’ As Coast Guard, State Officials Investigate
        "North Carolina Ports is in the process of restoring its systems after a cybersecurity incident forced a shift to manual operations on Tuesday. A spokesperson for the ports, which handle more than 4 million tons of cargo each year, said the IT system was “hacked by an outside actor or group” requiring them to enact a contingency plan and contact multiple state agencies as well as the U.S. Coast Guard. “The breach has been contained, and we are now in the recovery process,” the spokesperson told Recorded Future News, adding that the incident affected all three North Carolina Ports locations of Wilmington, Morehead City and Charlotte."
        https://therecord.media/cyberattack-north-carolina-ports

      General News

      • The Coordination Gap: How Attackers Are Outpacing Law Enforcement
        "Artificial intelligence (AI) and cryptocurrency enablement have propelled attackers to new levels of sophistication, coordination, and scale, and it's put pressure on law enforcement to adapt. Ecosystems across the threat landscape have converged due to affiliate models that allow non-state actors to conduct ransomware-as-a-service, pig butchering, and romance scams. Although they may be less technically savvy compared to well-resourced nation-state actors, they learned how to inflict the same damage, draining dollars from individuals and organizations."
        https://www.darkreading.com/cyberattacks-data-breaches/coordination-gap-attackers-outpacing-law-enforcement
      • Three In Four AI-Generated Vulnerability Patches Leave Something Broken
        "Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write. When there is a test, it often passes. Roughly one time in four, it is a fix. Researchers at 1Password graded 6,080 patches for six freshly disclosed CVEs, and the failures are rarely the obvious kind: an exploit path gated behind a check with the vulnerable code still sitting there behind it, a bug fixed in one function and left untouched in its character-for-character twin, a memory error closed and a new one opened in the same helper."
        https://www.helpnetsecurity.com/2026/08/06/1password-ai-generated-vulnerability-patches/
        http://1password.com/files/resources/frontier-models-vulnerability-patches-flawed.pdf
        https://www.theregister.com/ai-and-ml/2026/08/06/ai-struggles-to-patch-vulns-without-adult-supervision/5284319
      • Browser Security Is Where Software, Data, And AI Meet
        "In this interview with Help Net Security, Rui Ribeiro, CEO of Jscrambler, explains why the browser has become a security problem organizations do not control. Companies do not own the device, the extensions, or the network path, yet that is where application logic, third-party code, customer data, and AI meet during every customer interaction. He discusses the limits of Content Security Policy and Subresource Integrity, the risks of third-party AI chat scripts running with the same privileges as the application, and what regulators expect when they ask what executed inside a user’s session. He also argues that AI lowers the cost, time, and expertise attackers need."
        https://www.helpnetsecurity.com/2026/08/06/rui-ribeiro-jscrambler-browser-security/
      • Non-Human Identities Are 91% Of Everything Active In Production
        "A backup job fires at two in the morning. A scanner walks the same AWS account an hour later, a deployment pipeline assumes a role at four, and a logging agent runs straight through the night. Each of those actions carries a credential issued to a machine. An attacker holding one of those credentials inherits the same cover. Only 20% of non-human activity in production falls inside standard business hours, which puts a rogue API call at 3 a.m. in the middle of normal traffic. Time of day tells a defender almost nothing."
        https://www.helpnetsecurity.com/2026/08/06/non-human-identities-active-in-production/
      • Space Systems As Targets And Tools For Cyberattacks
        "In November 2019 in Brussels, NATO leaders officially recognized space as a “new operational domain” (alongside land, sea, air, and cyberspace). This article explores issues related to information security and attacks in space. Its focus is not limited to targeted attacks on the digital infrastructure of space systems; it also encompasses a broader spectrum of incidents, including software glitches, system failures, and unintentional human errors. A retrospective analysis of these events provides valuable information for identifying hidden vulnerabilities and improving the resilience of space infrastructure. It is impossible to build an effective space cybersecurity strategy without factoring in errors and failures – this assertion lies at the core of the present research."
        https://ics-cert.kaspersky.com/publications/reports/2026/08/06/space-systems-as-targets-and-tools-for-cyberattacks/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 26c6d039-672a-4d0f-bd71-7b8873ec2855-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 5 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-63077 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/05/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 072a39f4-c7f2-4d76-972f-b034837c8c6a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT