NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,404
    • กระทู้ 2,405
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    NCSA_THAICERT

    @NCSA_THAICERT

    1
    ชื่อเสียง
    56
    ดูข้อมูลส่วนตัว
    2.4k
    กระทู้
    3
    คนติดตาม
    0
    ติดตาม
    เข้าร่วม ออนไลน์ล่าสุด
    เว็บไซต์ www.ncsa.or.th/?fbclid=IwAR0BqJEC-CJzBs98rlBxUbZkNBgp1g814xdDNNaKnHTrxfqZhPD--ksY68I

    NCSA_THAICERT เลิกติดตาม ติดตาม
    Global Moderator administrators

    Latest posts made by NCSA_THAICERT

    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 2 รายการลงในแคตตาล็อก

      เมื่อวันที่ 22 กรกฏาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 2 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability
      • CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/07/22/cisa-adds-two-known-exploited-vulnerabilities-catalog

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ab3c93ee-3efb-4417-977a-48ad69c66734-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 23 July 2026

      Financial Sector

      • Beyond The Vault: What Banking Sites Quietly Share Before You Ever Log In
        "Banks present themselves as the most careful custodians of personal and financial data. Customers expect that trust to extend to every digital interaction including public websites and online application flows. Yet Jscrambler’s Security Research Team found that many banking experiences transmit sensitive information to third-party advertising, analytics, and personalization platforms. In many cases, the data leaves the browser before the user has made a consent choice. In others, it continues to flow even after users have rejected tracking technologies."
        https://jscrambler.com/blog/beyond-the-vault-what-banking-sites-share
        https://www.darkreading.com/data-privacy/eu-financial-institutions-cookie-trackers
        https://www.bankinfosecurity.com/pixels-tracking-every-loan-you-take-on-eu-bank-websites-a-32296

      Industrial Sector

      • Federal Agencies Broaden Alert On Iran-Linked OT Attacks
        "The federal government has expanded a warning that it issued in April about attacks on internet-facing operational technology (OT) by hackers affiliated with the Iranian regime. The initial advisory focused on programmable logic controllers (PLCs) from manufacturers Rockwell Automation and Allen-Bradley. Wednesday’s revision “expands the manufacturer scope to include observed targeting of Schneider Electric, Siemens and possible other PLC manufacturers,” according to a news release from CISA."
        https://therecord.media/federal-agencies-broaden-alert-on-iran-linked-ot-attacks

      New Tooling

      • Snowpick: Open-Source ServiceNow Exposure Scanner
        "An employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and get records back. Bishop Fox ran that test across 166 ServiceNow instances during authorized penetration tests. The firm published the results along with the Go tool it used, Snowpick."
        https://www.helpnetsecurity.com/2026/07/22/servicenow-data-exposure-snowpick-open-source-scanner/
        https://github.com/BishopFox/snowpick
      • Now In Preview: Find And Fix Software Vulnerabilities With CodeMender
        "As adversarial AI threats accelerate attacks on code, security teams must counter them with machine-speed defenses that can automate code remediation and fight AI with AI. CodeMender is our managed code security agent, and starting today, we're bringing its code scanning and remediation capabilities directly to you in preview. CodeMender offers access to our generally available models via Gemini Enterprise Agent Platform, or it can be deployed as a core component of AI Threat Defense."
        https://cloud.google.com/blog/products/identity-security/find-and-fix-software-vulnerabilities-with-codemender
        https://www.infosecurity-magazine.com/news/google-codemender-available-ai/

      Vulnerabilities

      • Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
        "Oracle has patched more than 1,400 vulnerabilities with its July 2026 Critical Patch Update (CPU), with a vast majority of the flaws likely identified by artificial intelligence. According to Oracle, the latest quarterly CPU includes 1,449 security patches, addressing 1,434 unique CVEs across 334 products. Vulnerabilities have been patched in products such as Database Server, APEX, Autonomous Health Framework, Essbase, Global Lifecycle Management, GoldenGate, NoSQL Database, Spatial Studio, SQL Developer, TimesTen In-Memory Database, Application Testing Suite, Commerce, Communications, Construction and Engineering, and E-Business Suite."
        https://www.securityweek.com/oracle-patches-over-1400-vulnerabilities-with-quarterly-security-updates/
        https://www.oracle.com/security-alerts/cpujul2026.html
      • CVE-2026-8933: Local Privilege Escalation In Set-Capabilities Snap-Confine
        "The Qualys Threat Research Unit (TRU) has identified a Local Privilege Escalation (LPE) vulnerability in snap-confine (CVE-2026-8933). This flaw allows an unprivileged local user to gain full root access on default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The issue stems from a security hardening change that inadvertently introduced a race condition during sandbox initialization."
        https://blog.qualys.com/vulnerabilities-threat-research/2026/07/21/cve-2026-8933-snap-confine-local-privilege-escalation
        https://thehackernews.com/2026/07/ubuntu-snap-confine-flaw-could-give.html
        https://www.infosecurity-magazine.com/news/ubuntu-snap-confine-local-root-cve/
        https://hackread.com/ubuntu-desktop-vulnerability-local-access-root-control/
        https://securityaffairs.com/195833/security/cve-2026-8933-ubuntu-security-flaw-breaks-snap-sandbox-protections.html
      • Security Advisory – Action Required – July 2026 Security Update
        "As part of Check Point’s Frontier AI Readiness Program, we are releasing a jumbo hotfix with security and hardening fixes for our firewall and management products. This update includes a number of security hardening improvements and fixes, the most significant of which are outlined below. During a routine BLAST review, we discovered a few vulnerabilities. Following a thorough analysis, we identified one of those in the wild, affecting a handful of customers. This only affects a very specific configuration — when Management is exposed directly to the internet without IP restrictions. We’ve already notified the affected customers."
        https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/
      • When Your AI Reviewer Works For The Attacker: A Confused-Deputy Bug In Microsoft's Azure DevOps MCP Server
        "An invisible comment in an Azure DevOps pull request can turn a developer's own AI agent against them. Microsoft ships an official Azure DevOps MCP server that lets AI agents read and act on Azure DevOps (pull requests, pipelines, wikis, work items) on the user's behalf. An attacker with access to a single project can hide instructions inside an HTML comment, invisible in the Azure DevOps UI, delivered verbatim into the agent's context. When a victim asks their agent to review the PR, the hidden instructions hijack the agent's goal. Because the agent is holding the victim's credentials, it performs actions across projects the attacker can't reach on their own."
        https://www.manifold.security/blog/azure-devops-mcp-server-vulnerability
        https://thehackernews.com/2026/07/microsoft-azure-devops-mcp-flaw-lets.html
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability
        CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/07/22/cisa-adds-two-known-exploited-vulnerabilities-catalog
      • New InfraTrust Report Reveals Infrastructure Flaws Admins Should Patch First
        "Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. The monthly report aggregates security advisories from major infrastructure vendors and highlights the vulnerabilities administrators should prioritize based on a flaw's exploitability, exposure, and real-world risk rather than severity scores alone."
        https://www.bleepingcomputer.com/news/security/new-infratrust-report-reveals-infrastructure-flaws-admins-should-patch-first/
        https://pulse.infra-trust.org/july-2026/
      • HermeticReader: The Vulnerability That Turned Adobe's 300M-Install Extension Into a Full WhatsApp Takeover
        "A single click on a malicious web page could turn the Adobe Acrobat Chrome extension, installed on roughly 329 million browsers, into a one-click WhatsApp exfiltration tool, quietly handing a visitor's entire WhatsApp clear-text chats, contacts, and private info to the attacker's hands. Here at Guardio Labs we uncovered a chain of vulnerabilities in the extension that compounds into a single powerful cross-origin exfiltration chain. A working, runtime-confirmed exploit followed within hours, thanks to our AI harness specially built to secure the browser extensions domain. Adobe's response to our full disclosure was phenomenal: acknowledged, patched, and shipped over a single weekend, with CVE-2026-48294 issued days later."
        https://guard.io/labs/hermeticreader---the-vulnerability-that-turned-adobe-300m-install-extension-into-a-full-whatsapp-takeover
        https://www.bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-let-sites-access-private-whatsapp-chats/
        https://thehackernews.com/2026/07/adobe-acrobat-extension-flaw-let.html
        https://www.securityweek.com/flaw-in-adobe-extension-with-300m-installs-enabled-whatsapp-data-theft/
        https://securityaffairs.com/195805/hacking/adobe-acrobat-chrome-extension-bug-enabled-silent-whatsapp-data-theft.html
      • Hackers Exploit Windmill Flaw To Read Arbitrary Server Files Without Authentication
        "A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log_file" endpoint ("/api/w/{workspace}/jobs_u/get_log_file/{filename}")."
        https://thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html
      • Open Directory Stages NGINX Rift And Ghost CMS Exploits Against Government And Finance Across Eleven Countries
        "NGINX sits in front of a large share of the internet's web traffic and Ghost CMS powers well over 100,000 publishing sites. Within months of each other earlier this year, critical vulnerabilities were found in both: NGINX Rift (CVE-2026-42945), a long-standing heap overflow in the rewrite module, and a blind SQL injection in the Ghost Content API (CVE-2026-26980). Exploit code for both became public quickly. What we found was a single host staging them alongside five other exploits, wired to confirm its own hits over out-of-band callbacks."
        https://hunt.io/blog/open-directory-nginx-rift-ghost-cms-multi-cve
      • Langflow Exploited To Build Custom DDoS Gafgyt Botnets
        "The cybersecurity world spent the last few years worrying about advanced AI threats — such as automated phishing, deepfakes, and autonomous malware. However, threat actors are proving that their immediate goals are much more pragmatic. They don't just want to manipulate AI; they want to hijack its underlying infrastructure to fuel traditional, high-volume cybercrime. Recent threat intelligence reveals a fascinating intersection of modern AI deployment and classic botnet architecture: Attackers are actively exploiting CVE-2025-3248 (an RCE vulnerability in Langflow) to drop a highly customized variant of the veteran Gafgyt/BASHLITE DDoS bot. In this blog post, I’ll describe how attackers are actively exploiting CVE-2025-3248 to turn cutting-edge AI frameworks into brute-force network weapons."
        https://www.akamai.com/blog/security-research/2026/jul/langflow-exploited-build-custom-ddos-gafgyt-botnets

      Malware

      • The Perfect Heist: NuGet Typosquat Targets Betting Platform To Rig Results
        "The JFrog Security Research team has discovered and disclosed a typosquatted NuGet package named Newtonsoftt.Json.Net. Note the double t and the .Net suffix. This package has been masquerading as the popular Newtonsoft.Json library while quietly shipping a trojanized fork. The trojan rigs Digitain, an online betting platform, and in later generations, exfiltrates rigged round results to an attacker-controlled server, utilizing the header X-Seq-ApiKey: theperfectheist2025. The author published seven versions under the same package, all sharing the same target-specific payload."
        https://jfrog.com/blog/nuget-typosquat-targets-betting-platform/
        https://thehackernews.com/2026/07/trojanized-newtonsoftjson-fork-hides.html
      • Denying The Worm: Detecting SANDWORM_MODE And The Emerging Class Of AI Toolchain Supply Chain Attacks
        "In February 2026, Socket.dev published research on a multi-stage npm supply chain worm operating under the internal flag SANDWORM_MODE. The campaign spanned 19 malicious packages in total across two unique publisher aliases and demonstrated a new class of supply chain attacks that targeted AI-augmented development workflows. Many recently observed supply chain attacks target build outputs, inject static backdoors, or conduct mass credential harvesting, but SANDWORM_MODE was unique in its exploitation of the runtime behaviors of AI coding assistants, CI automation, and LLM toolchains."
        https://www.crowdstrike.com/en-us/blog/denying-the-worm-sandworm-mode-and-ai-toolchain-supply-chain-attacks/
        https://www.darkreading.com/cyber-risk/attackers-live-off-ai-toolchain
        https://cyberscoop.com/sandworm-mode-malware-ai-supply-chain-crowdstrike/
      • How a Fake Bahrain Civil-Defense App Turns a Phone Into a Listening Post
        "Throughout July and including the day that this article is being published, Gulf states, including Bahrain and Kuwait have been activating civil-defense sirens and public-safety guidance for residents in the wake of Iranian missiles. During active air-defense events, official emergency-alert applications see sharp spikes in install demand. Some actors treat that demand as a distribution opportunity. On July 17, Dream researchers analyzed an Android application that impersonates a Bahraini Civil Defense “BH Alert” siren app."
        https://dreamgroup.com/blog/how-a-fake-bahrain-civil-defense-app-turns-a-phone-into-a-listening-post
        https://www.darkreading.com/mobile-security/fake-bahrain-alert-apps-android-surveillance-malware
      • Inside a TrickBot Variant Using DNS Tunneling For C2
        "FortiGuard Labs recently captured several malicious samples that were sending malformed DNS queries. After conducting an in-depth analysis, I determined that these samples are TrickBot variants that use DNS tunneling to communicate with their command-and-control (C2) servers. TrickBot is a modular malware family that FortiGuard Labs has repeatedly captured over the past decade. Its modular architecture enables it to extend its capabilities by downloading and executing additional modules on compromised devices. Previously observed TrickBot variants primarily relied on HTTP to communicate with its C2 servers."
        https://www.fortinet.com/blog/threat-research/inside-a-trickbot-variant-using-dns-tunneling-for-c2
        https://www.infosecurity-magazine.com/news/trickbot-dns-tunneling-c2/
      • Analysis Of Kimsuky's Attack On a South Korean Groupware Vendor Using a New Gomir Family Variant
        "The ENKI WhiteHat Threat Research Team tracked a campaign by Kimsuky, a North Korea-linked threat group, that infiltrated the internal networks of South Korean groupware vendors between 2025 and early 2026. Our analysis revealed that Kimsuky gained control of internet-facing servers through vulnerability exploitation and spear-phishing, and deployed Gomir and its variants. Kimsuky developed Gomir variants with significantly altered C2 communication methods to evade detection, including leveraging Google Drive as a C2 channel and implementing a new custom protocol. We also observed indicators of aggressive lateral movement, including compromising customer servers that used the affected vendors' groupware and tampering with groupware login pages to harvest employee credentials."
        https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant
        https://therecord.media/kimsuky-north-korea-espionage-groupware-companies
      • Device Code Phishing: Turning a Convenience Feature Into An MFA Bypass
        "For years, the advice to users was simple: turn on multi-factor authentication (MFA), and most account takeovers can be prevented. That advice still holds, and MFA still blocks most password-based attacks. The problem is that attackers adapt, and the more an organization relies on a single control, the more attention that control attracts. The first big shift was adversary-in-the-middle phishing, where a proxy site sits between the user and Microsoft and relays the login in real time to capture the session cookie. Device code phishing is the next step, and in some ways, it is cleaner for the attacker. There is no fake login site to build or to get blocked, and there is nothing visually wrong for the user to notice, because the page they enter their password on really is Microsoft. The only unusual thing is a short code and a plausible reason to enter it."
        https://www.trendmicro.com/en_us/research/26/g/device-code-phishing.html

      Breaches/Hacks/Leaks

      • Chick-Fil-A Discloses Data Breach After Credential Stuffing Attacks
        "American fast food restaurant chain Chick-fil-A is notifying an undisclosed number of customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. Self-described as the third-largest quick-service restaurant company in the United States, Chick-fil-A operates a network of more than 3,000 restaurants and provides catering services across the U.S., Canada, Puerto Rico, the United Kingdom, and Singapore. The company revealed in data breach notification letters sent to affected individuals and filed with multiple Attorney General offices that it detected the attacks after identifying suspicious login activity to certain Chick-fil-A One accounts."
        https://www.bleepingcomputer.com/news/security/chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks/
        https://www.malwarebytes.com/blog/data-breaches/2026/07/chick-fil-a-loyalty-accounts-hijacked-using-stolen-passwords
      • OpenAI Says Its AI Models Hacked Hugging Face During Testing
        "OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. As the company explained, instead of focusing on finding a solution for the ExploitGym public AI cybersecurity benchmark on their own, the AI models tried to cheat by stealing the test solutions by hacking Hugging Face after inferring that they could get the test solutions directly from its production database. In one of their attempts, the OpenAI agents chained zero-day vulnerabilities and used stolen credentials to find a remote code execution attack vector while trying to gain access to Hugging Face servers."
        https://www.bleepingcomputer.com/news/security/openai-says-its-ai-models-hacked-hugging-face-during-testing/
        https://openai.com/index/hugging-face-model-evaluation-security-incident/
        https://thehackernews.com/2026/07/openai-says-its-own-ai-models-escaped.html
        https://therecord.media/openai-cyberattack-hugging-face
        https://www.darkreading.com/cyber-risk/openai-models-autonomously-hack-hugging-face
        https://www.infosecurity-magazine.com/news/open-ai-hacked-another-company/
        https://www.securityweek.com/openai-says-its-ai-models-broke-loose-and-hacked-hugging-face/
        https://securityaffairs.com/195774/ai/openai-ai-models-exploited-zero-days-to-reach-hugging-face-in-benchmark-test.html
        https://hackread.com/openai-models-breached-hugging-face/
        https://www.helpnetsecurity.com/2026/07/22/hugging-face-breach-openai-testing/
      • Upbound Says Hack Caused $13 Million In Fraudulent Acima Leases
        "The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. In a filing with the U.S. Securities and Exchange Commission (SEC), the company says that it "experienced cybersecurity incidents in which certain non-sensitive customer information and other documents were obtained without authorization." The threat actor used the information to commit fraud in lease-to-own agreements, resulting in financial losses of about $13 million in the Acima segment in the second quarter of this year."
        https://www.bleepingcomputer.com/news/security/upbound-says-hack-caused-13-million-in-fraudulent-acima-leases/
      • South Korea Discloses Data Breach Impacting Diplomats Worldwide
        "South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. The incident occurred in April 2025 after an unknown threat actor exploited a vulnerability in the Academy's server. It impacts at least 6,000 individuals, 350 of them being current government attachés dispatched abroad. The education platform was set up in 2022 to support remote training during the COVID-19 pandemic, and has since been used for government personnel training and video-conferencing."
        https://www.bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide/
      • Swiss Rail Giant Stadler Rejects $12.3M Ransom Demand After Cyberattack
        "Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. The threat actor has not publicly claimed the attack, but the Swiss company says that it received an extortion letter from Everest ransomware asking for a ransom of 10 million Swiss francs. The company responded by saying that it will not pay the threat actor and filed a criminal complaint with the Thurgau cantonal police."
        https://www.bleepingcomputer.com/news/security/swiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack/

      General News

      • Security Issues In The Korean & Global Financial Sector In June 2026
        "In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third Attack Stage, demonstrating that multi-stage attack chains—progressing from the initial distribution of bait to the installation of additional malware and ultimately to Information Theft—are widely used."
        https://asec.ahnlab.com/en/94543/
      • Small Teams Are The Heaviest Users Of AI Coding Agents
        "The pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to read it. On GitHub that somebody is usually one developer sitting alone with the diff, and the rest of the project never sees the code. Maliha Noushin Raida and Daqing Hou at Rochester Institute of Technology sorted 25,264 agentic pull requests by who reviewed them and who committed to them. The repositories all carry at least 100 stars, the agents are the ones most developers have already met, GitHub Copilot and OpenAI Codex and Claude Code, and the window runs from May through July 2025."
        https://www.helpnetsecurity.com/2026/07/22/users-of-ai-coding-agents/
      • Security Teams Keep Finding Critical Flaws After Scheduled Testing Ends
        "Enterprise environments change between scheduled security assessments, leaving organizations with periods where new vulnerabilities can go undetected. Synack’s State of Continuous Security Validation report found that 95% of surveyed organizations identified high- or critical-severity vulnerabilities outside planned testing windows during the past year, with 42% encountering them at least once a month."
        https://www.helpnetsecurity.com/2026/07/22/continuous-security-testing-gaps-report/
      • Cloud Operations Become The Next Big Role For Agentic AI
        "Companies are using agentic AI to manage growing application environments, automate routine tasks, and support decisions. Business and IT leaders increasingly see the technology as part of cloud application management, according to Unisys’ AI & Cloud Insights Report. Most organizations remain in testing or early deployment. Nearly one quarter have started scaling agentic AI across business functions. Early uses center on employee productivity and cloud management. Spending plans show continued interest, with half of respondents planning higher investment during the next year."
        https://www.helpnetsecurity.com/2026/07/22/agentic-ai-cloud-operations-report/
      • Vibe-Coded Apps Riddled With Exploitable Security Flaws
        "Vibe-coding is increasing. Vibe-coded apps tend to be buggy. Is this a worrying sign for the future? Vibe coding, the use of AI to assist or perform code generation, is increasing dramatically. In May 2026, Hostinger reported, “90% of developers regularly use at least one AI tool at work as of January 2026.” This is likely to increase through the basic business pressure that applies to everything: we need more, faster and cheaper. But while vibe coding is increasing in volume, so are concerns over the security of vibe-developed apps."
        https://www.securityweek.com/vibe-coded-apps-riddled-with-exploitable-security-flaws/
        https://go.xint.io/the-top-security-vulnerabilities-generated-by-ai-code
      • When Identity Verification Fails: Lessons From a Real-World SIM Swap And Near Account Takeover
        "For years, organizations have encouraged users to enable multi-factor authentication (MFA), use one-time passwords (OTPs), and protect their accounts with passcodes. Those controls remain important. However, a recent attack against my own wireless services account demonstrated that point-in-time authentication is no longer sufficient against determined identity-focused adversaries. What began as a seemingly routine customer service call quickly evolved into a coordinated attack that combined social engineering, identity impersonation, stolen personal information, SIM swapping, session hijacking, and unauthorized account changes."
        https://www.securityweek.com/when-identity-verification-fails-lessons-from-a-real-world-sim-swap-and-near-account-takeover/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 0ab0f750-7528-4021-968d-eeaac841a990-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 4 รายการลงในแคตตาล็อก

      เมื่อวันที่ 21 กรกฏาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 4 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability
      • CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
      • CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability
      • CVE-2026-60137 WordPress Core SQL Injection Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand a5b71026-0cee-43a3-ba5f-96ab381a8916-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 10 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 10 รายการ เมื่อวันที่ 21 กรกฏาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-202-01 Tycon Systems TPDIN-Monitor-WEB2
      • ICSA-26-202-02 Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
      • ICSA-26-202-03 Siemens Opcenter X
      • ICSA-26-202-04 Siemens SIDIS Secured SmartPlug
      • ICSA-26-202-05 Siemens IAM Client
      • ICSA-26-202-06 Siemens CADRA
      • ICSA-26-202-07 Rockwell Automation FactoryTalk Services Platform
      • ICSA-26-202-08 Rockwell Automation 1718-AENTR/1719-AENTR
      • ICSA-26-202-09 Rockwell Automation 1734 POINT I/O
      • ICSA-26-202-10 Rockwell Automation Studio 5000 Logix Designer

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories 26245063-2214-4993-9369-9423c9b4fd7e-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 22 July 2026

      Industrial Sector

      • Tycon Systems TPDIN-Monitor-WEB2
        "Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01
      • Siemens Opcenter X
        "Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-03
      • Siemens SIDIS Secured SmartPlug
        "SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-04
      • Siemens CADRA
        "CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-06
      • The Air Gap Is a Myth And Other OT Security Truths
        "Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth. Bachmann covers how containment plans get negotiated before an incident, how to build visibility on old equipment through network monitoring, and how ransomware crews price their demands on downtime. He also questions the idea that people are the weakest link in OT security."
        https://www.helpnetsecurity.com/2026/07/21/benjamin-bachmann-bilfinger-ot-security/
      • Siemens RUGGEDCOM APE1808 With Palo Alto Networks Virtual NGFW
        "Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-02
      • Siemens IAM Client
        "Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-05
      • Rockwell Automation FactoryTalk Services Platform
        "Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-07
      • Rockwell Automation 1718-AENTR/1719-AENTR
        "Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-08
      • Rockwell Automation 1734 POINT I/O
        "Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-09
      • Rockwell Automation Studio 5000 Logix Designer
        "Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-10

      Vulnerabilities

      • Zimbra Update Patches Critical Vulnerabilities
        "Zimbra on Monday announced patches for several critical-severity vulnerabilities, including a command injection bug disclosed in late June. The critical command injection impacts the SNMP monitoring component of the collaboration suite if SNMP notifications are enabled and the integrated Swatchdog service is running. An unauthenticated attacker could send crafted payloads to execute arbitrary OS commands in the background and compromise the email server."
        https://www.securityweek.com/zimbra-update-patches-critical-vulnerabilities/
        https://thehackernews.com/2026/07/zimbra-patches-critical-snmp-command.html
        https://securityaffairs.com/195752/security/zimbra-10-1-20-patches-multiple-security-issues-including-a-critical-command-injection-bug.html
      • Windows LegacyHive Zero-Day Flaw Gets Free, Unofficial Patches
        "Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. The vulnerability (dubbed LegacyHive and without a CVE ID for easy tracking) was found by a security researcher using the "Nightmare Eclipse" handle in the Windows User Profile Service. Nightmare Eclipse disclosed it the day Microsoft released its July 2026 Patch Tuesday updates, together with a stripped proof-of-concept exploit designed to make it harder for threat actors to weaponize this security issue in attacks."
        https://www.bleepingcomputer.com/news/security/windows-legacyhive-zero-day-flaw-gets-free-unofficial-patches/
      • Broken Access Control In Meta.com Customer Support Infrastructure
        "I discovered a critical broken access control vulnerability within Meta’s support infrastructure. What initially appeared to be a product-specific authorization issue ultimately revealed a broader weakness affecting multiple support experiences built on shared backend infrastructure. The vulnerability allowed unauthorized access to sensitive customer support interactions, including Meta.com support emails, support cases, customer support chats, and internal case information. Additionally, certain support workflows could be modified without possessing the intended permissions."
        https://whiteauth.com/2026/07/17/broken-access-control-in-meta-com-support-infrastructure/
        https://www.securityweek.com/meta-pays-78000-bounty-for-vulnerability-exposing-customer-support-data/
      • CISA Adds Four Known Exploited Vulnerabilities To Catalog
        "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability
        CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
        CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability
        CVE-2026-60137 WordPress Core SQL Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog
      • Using LLMs To Find And Prioritize Vulnerabilities Is No Easy Task
        "Current methods of prioritizing vulnerabilities are falling flat, with too many false positives, poor prioritization, and a failure to take into account reachability. So far, large language models (LLMs) have not really helped. In tests of more than a dozen application-scanning tools, more than 60% of flagged vulnerabilities continue to be false positives, are in unreachable code, or are low severity, says Arshan Dabirsiaghi, chief technology officer and co-founder at Pixee, an AI-powered application-security (AppSec) startup. In a presentation at Black Hat USA in August, Dabirsiaghi plans to detail results from those tests and show that the lack of context in stock models means that AI models are not the solution."
        https://www.darkreading.com/application-security/finding-and-prioritizing-vulnerabilities-no-easy-task
      • Apple Fixes Hide My Email Bug That Exposed Real Addresses In Mail Logs
        "Apple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermining the feature's privacy guarantees. 404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, after more than a year, when it was disclosed to the company by Tyler Murphy, co-founder of EasyOptOuts."
        https://thehackernews.com/2026/07/apple-fixes-hide-my-email-bug-that.html
      • When The AI Edits Its Own Trust Boundary: Remote Code Execution Vulnerability In AWS's Agentic IDE
        "AI coding agents are powerful, highly capable, and equipped with risky tools, such as the ability to execute shell commands. Which raises the question, how can we protect our environment from them? The answer is built around a simple safety promise, the risky actions happen only when a human approves them. The user stays in the loop, reviews what the agent wants to do, and clicks “allow.” That approval step is the security boundary. We found a vulnerability in Kiro, AWS’s agentic IDE, that breaks this promise. By planting hidden instructions in a web page Kiro reads, an attacker can make Kiro rewrite its own MCP (Model Context Protocol) server configuration file and gain arbitrary code execution on the developer’s machine. No suspicious approval prompt is ever shown to the user. All the developer asked Kiro to do was perform a legitimate action."
        https://research.intezer.com/blog/2026/07/remote-code-execution-kiro/
        https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html
      • Open-Source Android AI Agents Could Let Invisible Screen Text Run Code On Host PCs
        "An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent. Researchers demonstrated that chain, plus six other attacks, against five open-source mobile agent frameworks: AppAgent, AppAgentX, Mobile-Agent-v3, Open-AutoGLM, and MobA. Everyone fell to at least six of the seven."
        https://thehackernews.com/2026/07/open-source-android-ai-agents-could-let.html
        https://arxiv.org/abs/2607.00333

      Malware

      • Exploitation In The Wild Of Wp2shell
        "Wiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137). Attackers are deploying persistent webshells on vulnerable servers. Organizations should prioritize patching or applying WAF mitigations."
        https://www.wiz.io/blog/wp2shell-cve-2026-63030-cve-2026-60137
        https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html
        https://www.bleepingcomputer.com/news/security/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells/
      • Cookie Crumbles: How Exploitation Of CVE-2026-0257 Leads To Qilin Ransomware
        "During June 2026, Arctic Wolf Labs investigated multiple intrusions during which threat actors exploited CVE-2026-0257 as a consistent initial access vector, rapidly transitioning from perimeter compromise to domain-wide Qilin ransomware encryption across distinct victim environments."
        https://arcticwolf.com/resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/
        https://www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/
        https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html
        https://securityaffairs.com/195730/cyber-crime/qilin-ransomware-affiliates-abuse-cve-2026-0257-to-gain-unauthorized-vpn-access.html
      • Who Needs a Job? DPRK ClickFake Interview Campaign Drops PylangGhost And GolangGhost RATs
        "This article by SOCRadar Threat Research Unit (STRU) analyzes the latest ClickFake Interview campaign, a North Korean social engineering operation that targets cryptocurrency and Web3 professionals with fake job interviews. Operators posing as recruiters walk targets through a bogus skill assessment that ends in a copy-and-paste command, delivering the PylangGhost RAT on Windows and the GolangGhost RAT on macOS. North Korea, officially the Democratic People’s Republic of Korea (DPRK), is well known for their financially motivated cyber operations. To circumvent international sanctions, they persistently attack organizations to steal funds and support the regime’s missile, nuclear, and espionage programs. From historically targeting SWIFT transactions and ATMs, they now focus on stealing crypto assets, with $643M stolen so far this year."
        https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/
        https://www.infosecurity-magazine.com/news/north-korean-clickfake-campaign/
      • New Project CAV3RN Module Abuses Outlook Calendar Events For C2 And DNS AAAA Records For Configuration Recovery
        "In June 2026, as part of our Kaspersky Threat Intelligence Reporting service, we published extensive research on Project CAV3RN, a sophisticated modular framework used for cyberespionage activity against targets in Israel. We have been tracking this cluster since December 2025, and in late April 2026 we observed a major architectural shift: the developers moved from a three-component framework consisting of a downloader, executor, and uploader to a controller-based architecture with a dedicated WebSocket-enabled C2 communication component and a more extensible plugin system designed to support modular post-exploitation capabilities."
        https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/
      • Critical SharePoint RCE Flaw Exploited To Steal Machine Keys
        "Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. An attacker obtaining them can create valid authentication tokens to impersonate users and access available resources such as SharePoint sites and documents with the privileges of the forged identity. Microsoft describes the security issue as a deserialization-of-untrusted-data flaw that allows a remote attacker to execute code over a network without authentication."
        https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/
        https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html
        https://securityaffairs.com/195760/security/public-poc-triggers-active-exploitation-of-critical-sharepoint-rce-vulnerability-cve-2026-50522.html
      • Click To Sync: From Google Ads Maintenance Notice To Credential Theft
        "Threat actors continue to exploit trusted brands to lure users into phishing attacks. Using social engineering techniques that create scenarios that mimic parts of a user’s daily routine, they leverage a sense of urgency and familiarity to manipulate people’s behavior. The Cofense Phishing Defense Center (PDC) has observed a new phishing campaign targeting Google Ads Sync Accounts (MMC), in which attackers send fake system upgrade notifications that urge recipients to synchronize their accounts immediately. Brand impersonation remains one of the most common tactics used to establish trust with victims."
        https://cofense.com/blog/click-to-sync-from-google-ads-maintenance-notice-to-credential-theft
      • From Payroll To Pyongyang: The DPRK IT Worker Money Trail
        "A year ago, DTEX detailed how DPRK IT workers and cyber operators function as a coordinated arm of the regime. A year of open-source and multilateral reporting has since reinforced the model mapped, one built on infiltrating global hiring pipelines and blending of full spectrum cyber operations. New DTEX i³ research, expanded on by reporting through April 2026, picks up where the employment story ends. It follows the money through how payments are reported, who controls the process, and how funds move through internal DPRK channels tied to state activity. At the center of the research is a new interactive map that traces the money through the DPRK system, providing context to where it ultimately leads."
        https://www.dtex.ai/blog/dprk-it-worker-money-trail/
        https://cyberscoop.com/north-korea-it-worker-scheme-funds-russia-war-ukraine/
      • Cato CTRL™ Insights: How One Threat Actor Turned Frontier AI Into An Offensive Platform
        "A Russian-speaking threat actor known as “Trim” has spent the better part of 2026 systematically dismantling the guardrails on publicly available frontier AI models and rebuilding them as offensive tools. What started in March as a knowledge-sharing post on a Russian cybercrime forum detailing how to break Claude Opus into writing malware, had evolved by June into a fully productized, commercially marketed AI-powered penetration testing platform. Trim didn’t need a vulnerability to exploit. He didn’t need to build a novel AI, steal model weights, or compromise a datacenter. He simply picked powerful models off the shelf, figured out how to talk to them in the right way, and turned them into weapons. His story is not just one threat actor’s journey, it is a blueprint that the entire criminal underground is beginning to follow, and in his latest post he shares he is also utilizing a modified system prompt leaked from Fable!"
        https://www.catonetworks.com/blog/cato-ctrl-how-one-threat-actor-turned-frontier-ai-into-an-offensive-platform/
        https://www.darkreading.com/cyber-risk/hacker-ai-jailbreaks-offensive-attack-platform
        https://www.infosecurity-magazine.com/news/trim-jailbroken-claude-ai-pentest/
      • Fake FBI Agents Use IC3 Complaint Scams To Target Fraud Victims
        "The FBI is warning that scammers are impersonating its personnel and offering to help with Internet Crime Complaint Center complaints. Some scammers claim they have recovered stolen money or can help victims retrieve it, but their real aim is to steal information or money from people who have already suffered financial fraud. An updated FBI public service announcement, issued July 20, describes an ongoing scheme involving AI-generated videos, fake social media profiles and websites designed to resemble IC3.gov, the official website for the Internet Crime Complaint Center (IC3)."
        https://hackread.com/fake-fbi-agents-ic3-complaints-scam-victims/
        https://www.ic3.gov/PSA/2026/PSA260720
        https://www.infosecurity-magazine.com/news/fbi-deepfake-videos-ic3/
        https://www.malwarebytes.com/blog/news/2026/07/dont-trust-that-fbi-agent-in-your-dms
        https://www.helpnetsecurity.com/2026/07/21/fbi-ic3-impersonation-scam-warning/
      • A New Extortion Cocktail: Office Printers, Small Ransoms, And BitLocker
        "Recently, our teams in Latin America investigated a series of incidents involving misconfiguration, the deployment of BitLocker, and the exploitation of corporate printers. Attackers used the devices to notify organizations that their infrastructure had been compromised and they had to pay a ransom to recover their data. This article analyzes two incidents that occurred in June in Colombia and in May in Mexico. We highlight the similarities in the attackers’ communications and outline emerging trends in ransom amounts."
        https://securelist.com/new-extortion-scheme-printers-bitlocker/120718/

      Breaches/Hacks/Leaks

      • Clover Health Investments Discloses Data Breach
        "Healthcare technology company Clover Health Investments has disclosed a data breach impacting customers’ personal and health information. Discovered on July 4, the incident was the result of a social engineering attack that compromised three non-managerial health plan employee accounts. Clover Health Investments says it activated its response plan immediately after discovering the attack, and engaged third-party cybersecurity experts to contain and investigate the intrusion."
        https://www.securityweek.com/clover-health-investments-discloses-data-breach/
      • Anubis Ransomware Claims Coca-Cola Fairlife Attack, Threatens Data Leak
        "The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. Fairlife is one of Coca-Cola's dairy brands and produces a range of ultra-filtered milk products, protein shakes, and nutrition drinks sold throughout the United States. The company's product lineup includes Ultra-Filtered Milk, Core Power Protein Shakes, and Nutrition Plan. On July 16, The Coca-Cola Company disclosed that a ransomware attack had disrupted Fairlife's operations, forcing the company to suspend production at its U.S. facilities."
        https://www.bleepingcomputer.com/news/security/anubis-ransomware-claims-coca-cola-fairlife-attack-threatens-data-leak/
      • Kenya Probes Hack Of President's Website After Bitcoin Ransom Demand
        "Kenya is investigating a cyberattack that temporarily defaced the president's official website with an anti-government message demanding a ransom of five bitcoins (about $330,000). The website was hacked on Saturday, when its homepage was replaced with a message displaying a cryptocurrency wallet address and threatening to publish unspecified information about President William Ruto unless the ransom was paid."
        https://therecord.media/kenya-probes-hack-of-presidents-website-after-ransom-demand
      • AI Music Platform Suno Hits Bum Note As 55M Users Exposed In Data Breach, Claims Infosec Expert
        "A data breach at AI music generator platform Suno exposed more than 55 million user accounts, according to Troy Hunt's Have I Been Pwned service, which ingested the files. The dump consisted mostly of email addresses, although phone numbers were also included where users had signed up with them instead, HIBP said. Tens of thousands of Stripe records further revealed data such as names, physical addresses, purchase amounts, as well as partial credit card data, such as card type, expiry date, and the last four digits of the card number."
        https://www.theregister.com/security/2026/07/21/breach-of-ai-music-platform-suno-affected-55m-user-accounts/5275514

      General News

      • Nobody Was Checking The Drives That Encrypt Your Laptop
        "A drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG Opal2 standard. Milan Brož and three colleagues bought 38 of those drives and ran them through a test bench. Brož maintains cryptsetup, the tool that configures disk encryption on most Linux systems. The drives came from Samsung, Western Digital, Micron, Kioxia, and others, a mix of new stock and secondhand units pulled from laptops. The team treated each one as a black box and sent it only the commands the Opal2 documentation defines."
        https://www.helpnetsecurity.com/2026/07/21/hdd-self-encrypting-drive-security/
      • PR3TACK Preemptive Framework Maps Threats Before Attackers Use Them
        "Defensive frameworks in cybersecurity record what attackers have already done. Analysts study a breach, document the method, and build detections around confirmed activity. This cycle leaves a gap between the moment an attacker invents a technique and the moment defenders learn to catch it. PR3TACK, the Preemptive Tactics and Countermeasures Knowledgebase, aims to close that gap. Vishal Thakur of Atlassian built the open framework that catalogs plausible attacker tactics, techniques, and procedures that remain unobserved in the wild."
        https://www.helpnetsecurity.com/2026/07/21/first-pr3tack-preemptive-framework/
      • AI Agents Are Still Logging In As Humans
        "Most large companies run more than one AI platform at the same time. Developers pull up coding assistants, marketing teams lean on writing tools, and analysts query enterprise search across separate vendors. Single-provider setups keep giving way to mixed stacks as companies keep their options open. Sanctioned tools and personal accounts sit side by side inside many organizations. Anonymized sign-on data from more than 20,000 organizations on the Okta tracked this spread from June 2022 through June 2026. Each new tool arrives with its own set of logins and permissions."
        https://www.helpnetsecurity.com/2026/07/21/report-enterprise-ai-identity-risk/
      • Police Dismantle Kratos Phishing Platform, Arrest Developer
        "Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. During the operation, authorities seized more than 200 servers, effectively disrupting the malicious service and rendering it inoperable. The action was led by Frankfurt’s Prosecutor General Office (ZIT), Germany’s Federal police (BKA), which worked in collaboration with U.S. law enforcement agencies."
        https://www.bleepingcomputer.com/news/security/police-dismantle-kratos-phishing-platform-arrest-developer/
        https://www.theregister.com/security/2026/07/21/german-authorities-lead-takedown-of-kratos-phishing-platform/5275666
      • Cheating Behaviour In Frontier Model Evaluations
        "Can you trust an AI model to do what you intended? This is a central question both for those deploying AI systems and for those seeking to evaluate their capabilities. In deployment, a model that pursues a goal through unintended or unauthorised means may cause harm, particularly in high-stakes use cases. In an AI capability evaluation, the same behaviour may undermine the validity of the result: the model may appear to demonstrate a capability by completing a difficult task, when it has instead exploited the task or its environment."
        https://www.aisi.gov.uk/blog/cheating-behaviour-in-frontier-model-evaluations
        https://cyberscoop.com/ai-models-cheat-deceive-users-aisi-report/
      • 2026 Ransomware Report
        "Black Kite tracked 7,551 publicly disclosed ransomware victims between April 2025 and March 2026. That's a 24.9% increase over the previous reporting period, and the fourth straight year that ransomware disclosures have set a new high. The threat actor ecosystem grew right alongside the victim count, reaching 127 active groups by the close of the period and 146 by June 2026. This report analyzes those 7,551 victims by geography, industry, and revenue band, then goes further. It pairs victim data with Black Kite's own security posture signals, captured before disclosure and rechecked after, to show what ransomware groups could already see and what stayed visible once the incident closed. It also maps five distinct actor models operating inside the same 12 months, tracks how trusted vendor platforms became attack paths, and measures where AI is already lowering the cost of running a ransomware operation."
        https://blackkite.com/reports/2026-ransomware-report
        https://www.darkreading.com/cyberattacks-data-breaches/ransomware-is-accelerating-not-ai
        https://www.infosecurity-magazine.com/news/new-ransomware-weekly/
      • Choose Wisely: AI-Generated Coding Risk Varies, a Lot
        "There may not be a clear winner in terms of which AI model is the best or worst for coding, but there are better (and far worse) models for organizations depending on the development environment or framework one codes in. Software governance firm Secure Code Warrior today unveiled its AI Trust Index, a body of data attempting to quantify the risk established via large language model (LLM)-powered coding tools. AI-assisted development has become exceedingly popular at the organizational level, using tools to generate code, test for vulnerabilities, and audit for general integrity. It is by no means a secret that these tools are expensive, while introducing both vulnerabilities and risk, no matter the efficiency gains."
        https://www.darkreading.com/application-security/choose-wisely-ai-generated-coding-risk-varies
      • CISO Conversations: Andreas Gaetje – From Economics To CISO At Körber AG
        "Korber AG is the holding company of a diverse German technology and manufacturing organization with around 13,000 employees in 100 locations around the world. “Take Pharma,” comments Andreas Gaetje. “Probably every vaccine you ever received has been through our machines.” Korber services companies that supply consumers. So, despite its size and importance, it is rarely known to or recognized by the eventual consumer. Gaetje is the CISO at Korber AG."
        https://www.securityweek.com/ciso-conversations-andreas-gaetje-from-economics-to-ciso-at-korber-ag/
      • Understanding Illicit Ecosystems: Inside Rehub’s Rise As a Primary Ransomware Marketplace
        "Rehub, also known as ReHub or RehubCom, is a Russian-language cybercrime forum founded in August 2025 by a former XSS moderator following its shutdown in the summer of 2025. Rehub dedicates itself to the commercial and marketplace use of ransomware, while its counterpart, DamageLib, serves as a knowledge base archive and exchange. Operating both on Clear Web domains and an onion domain, the forum positions itself as free from state and law enforcement interference, framing existing XSS iterations as compromised. After law enforcement seized the RAMP (RAMP4U) forum in January 2026, Rehub absorbed a significant portion of the displaced cybercriminal community and became one of the primary destinations for ransomware operators."
        https://flashpoint.io/blog/understanding-illicit-ecosystems-inside-rehub-ransomware-marketplace/
      • Volume Is Not Risk: Making Sense Of The “Vulnpocalypse”
        "Around 66,000 common vulnerabilities and exposures (CVEs) are projected to be disclosed this 2026, according to the FIRST 2026 Mid-Year Vulnerability Forecast. Vulnerability researcher Jerry Gamblin revealed that disclosures in the first half of the year ran nearly 50% ahead of the same window in 2025, which itself finished at a record 48,185 CVEs. His analysis draws on National Vulnerability Database (NVD) and CVE Program data. The steep climb from the roughly 40,000 CVEs recorded in 2024 might make the “vulnpocalypse” panic justified."
        https://www.trendmicro.com/en_us/research/26/g/making-sense-of-the-vulnpocalypse.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 4c091242-b697-4b6d-80b3-41afeabe53d4-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Microsoft ออกอัปเดตนอกกำหนดการ แก้ปัญหา Dell บางรุ่นปิดตัวลงเอง

      Microsoft ออกอัปเดตนอกกำหนดการ แก้ปัญหา Dell บางรุ่.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 04fb66d5-69d9-4a83-9e1d-d50fc96a3076-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Estée Lauder แจ้งเหตุข้อมูลรั่วไหล หลังระบบ Oracle E-Business Suite ถูกใช้โจมตี

      Estée Lauder แจ้งเหตุข้อมูลรั่วไหล หลังระบบ Oracle E-Busines.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 238dd9ab-dfbf-4277-9400-dfbd8bb0563c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • เตือนภัยมัลแวร์ HollowGraph ใช้ปฏิทินบน Microsoft 365 เป็นช่องทางลับสั่งการและขโมยข้อมูล

      เตือนภัยมัลแวร์ HollowGraph ใช้ปฏิทินบน Microsoft 365 เป็น.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 0b97e94a-d471-4b5f-b7fb-3b67ba80c091-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Chrome ออกแพตช์แก้ช่องโหว่ Memory Safety ระดับ Critical หลายรายการ

      Chrome ออกแพตช์แก้ช่องโหว่ Memory Safety ระดับ Critical หลายร.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5d364bb0-51ef-4c76-a799-04284c9bf231-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ServiceNow เตือนช่องโหว่ RCE ร้ายแรงใน AI Platform เริ่มถูกใช้โจมตีจริง

      ServiceNow เตือนช่องโหว่ RCE ร้ายแรงใน AI Platform เริ่มถูก.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand dd4f85cf-8782-47d3-83b7-9f4949e43973-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT