NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 2
    • กระทู้ 2,217
    • กระทู้ 2,218
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    NCSA_THAICERT

    @NCSA_THAICERT

    1
    ชื่อเสียง
    55
    ดูข้อมูลส่วนตัว
    2.2k
    กระทู้
    2
    คนติดตาม
    0
    ติดตาม
    เข้าร่วม ออนไลน์ล่าสุด
    เว็บไซต์ www.ncsa.or.th/?fbclid=IwAR0BqJEC-CJzBs98rlBxUbZkNBgp1g814xdDNNaKnHTrxfqZhPD--ksY68I

    NCSA_THAICERT เลิกติดตาม ติดตาม
    Global Moderator administrators

    Latest posts made by NCSA_THAICERT

    • Anthropic เสริมความปลอดภัย Claude Code เพิ่มปลั๊กอินตรวจจับโค้ดเสี่ยงระหว่างพัฒนา

      Anthropic เสริมความปลอดภัย Claude Code เพิ่มปลั๊กอินตรว.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 9bea56c4-d869-4471-8bf0-a2330a689bf6-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • บริษัทรักษาความปลอดภัยไซเบอร์ร่วมปิด Glassworm Botnet หลังพบใช้แพ็กเกจและเครื่องมือปลอมโจมตีนักพัฒนา

      บริษัทรักษาความปลอดภัยไซเบอร์ร่วมปิด Glassworm .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand c8bd68ba-7672-43b7-8589-89a6d0e82175-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการโจมตีผ่านช่องโหว่ Zero-Day บนระบบ KnowledgeDeliver เพื่อติดตั้งเว็บเชลล์และฝังมัลแวร์

      พบการโจมตีผ่านช่องโหว่ Zero-Day บนระบบ KnowledgeDeliver เพ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 343c3cef-e278-45e0-8df2-290a65871083-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 28 May 2026

      New Tooling

      • Introducing EvidenceForge: Synthetic Security Logs That Don’t Look (as) Fake
        "A lot of important work in security depends on having realistic log data to work with, and a lot of that work gets blocked, watered down, or quietly skipped because the data just isn’t available. The use cases come up constantly: teaching threat hunters, incident responders, and detection engineers with datasets that have known ground truth; validating that a detection fires on the right activity without drowning in false positives; and training ML models that need labeled, balanced, multi-source telemetry at scale. These are different problems with the same root cause. You need realistic, labeled security logs and you can’t get them easily."
        https://blog.talosintelligence.com/introducing-evidenceforge-synthetic-security-logs-that-dont-look-as-fake/
        https://github.com/Cisco-Talos/EvidenceForge
      • Vigolium: Open-Source Vulnerability Scanner
        "Vigolium, an open-source vulnerability scanner that combines deterministic scanning with AI-driven auditing, launched its initial open-source release this month. The project ships 235+ scanner modules and an in-process agent runtime called olium that handles autonomous endpoint discovery, attack planning, and finding triage. The tool exposes two scanning paths. vigolium scan runs a multi-phase deterministic pipeline covering content discovery, browser-based spidering, and active and passive auditing. vigolium agent hands control to an LLM-driven harness that selects modules, generates custom JavaScript extensions, and runs source-code audits alongside dynamic scans."
        https://www.helpnetsecurity.com/2026/05/27/vigolium-open-source-vulnerability-scanner/
        https://github.com/vigolium/vigolium
      • Ebpf101
        "Liz Rice's Learning eBPF — via the Isovalent tutorial — was our starting point, one chapter per directory. The repo has since gone well beyond it. The opening chapters retrace the tutorial's arc (BCC → libbpf/CO-RE → kprobes/uprobes); from there it keeps going — the verifier as a gate, the bpftool workflow, the XDP and tc datapath, tail calls, LSM BPF (policy enforcement), BPF iterators, and two applied capstones the tutorial never reaches: an XDP firewall and a rule-based intrusion-detection system, drawn respectively from a Columbia EECS6891 lecture (Yannis Zarkadas, Spring 2024) and a research paper (arXiv:2102.09980). All 23 chapters are built and run live on this machine; every program is written to be read."
        https://github.com/douglasmun/ebpf101

      Vulnerabilities

      • CISA Adds Three Known Exploited Vulnerabilities To Catalog
        "CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-8398 Daemon Tools Lite Embedded Malicious Code Vulnerability
        CVE-2026-45321 TanStack Unspecified Vulnerability
        CVE-2026-48027 Nx Console Embedded Malicious Code Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/05/27/cisa-adds-three-known-exploited-vulnerabilities-catalog
      • MediaArea Heap-Based Buffer Overflow Vulnerabilities
        "Cisco Talos’ Vulnerability Discovery & Research team recently disclosed four vulnerabilities in MediaArea MediaInfoLib library. The vulnerabilities mentioned in this blog post have been patched by their respective vendor, in adherence to Cisco’s third-party vulnerability disclosure policy."
        https://blog.talosintelligence.com/mediaarea-heap-based-buffer-overflow-vulnerabilities/
      • All Major LLMs Exposed To Multi-Turn Manipulation, Warn Researchers
        "The safety guardrails of several prominent large language models (LLM) can be bypassed if a user tricks the LLM into having a multi-pronged, ongoing conversation, researchers at Cisco have warned. The researchers examined commonly used LLMs and frontier AI models including OpenAI’s ChatGPT, Anthropic’s Claude, Google Gemini, Amazon Nova, xAI’s Grok and others to test how their built-in safety guardrails held up against potential threats from real-world attackers. They found that many of the models could be tricked into performing actions they should not be able to."
        https://www.infosecurity-magazine.com/news/all-major-llms-exposed-to-multi/
      • How To Get a 100% Conference Acceptance Rate, The Novee Way: A High-Severity CVE In Leading Call-For-Papers Software
        "As a founding engineer and security researcher at Novee, my job is to think like an attacker – and to train Novee’s AI agents to do the same. When I discovered this particular exploit, however, I was doing something ordinary: preparing conference submissions. Different events, different review committees, different deadlines, but I noticed the same submission form kept appearing under different logos. Much of the technical conference world runs its CFPs on pretalx, an open-source platform behind everything from hacker camps to academic symposiums. From the outside, each event looks independent. Underneath, it is one codebase serving them all."
        https://novee.security/blog/pretalx-stored-xss-vulnerability-account-takeover/
        https://www.securityweek.com/vulnerability-in-popular-conference-software-granted-attackers-a-100-talk-acceptance-rate/
        https://www.theregister.com/security/2026/05/27/pretalx-xss-flaw-exposed-conference-cfp-systems/5246598
      • CVE-2026-27771: NoScope Discovered 30,000+ Gitea Instances Exposing Private Container Images For 4 Years
        "CVE-2026-27771 allowed unauthenticated access to private container images on Gitea instances. 30,000+ deployments were affected. The flaw went undetected for 4 years. NoScope discovered and responsibly disclosed it. If you run Gitea Update to v1.26.2 immediately. If you can't update right now, set [service].REQUIRE_SIGNIN_VIEW=true in your Gitea configuration as a temporary stopgap. Note this stopgap isn't suitable if you intentionally expose some containers publicly."
        https://www.noscope.com/blog/gitea-instances-exposing-private-container
        https://thehackernews.com/2026/05/gitea-vulnerability-exposes-private.html

      Malware

      • Don’t Trust ‘secure Mail’! Malicious Files Impersonating Credit Card Companies Are Being Distributed
        "ahnLab recently confirmed the distribution of malicious files disguised as security emails from a major credit card company in Korea. this attack has a similar flow to the Kimsuky group’s past malicious LNK distribution case of disguising password files, but it is characterized by a change in the command execution of the initial LNK file. in particular, the execution of additional files and malicious files and the behavior of the malicious files changed depending on whether the security service of the infected environment was enabled or disabled. let’s take a look at the main behavior of this case and user precautions."
        https://asec.ahnlab.com/en/93855/

      • From Poisoned Search Results To GPU Mining: A Cryptojacking Campaign Abusing ScreenConnect And Microsoft .NET Utilities
        "Microsoft Defender Experts identified an active cryptojacking campaign in which malicious download sites are surfaced not only through traditional search engine poisoning, but also through AI chatbot interactions. This emerging delivery technique extends social engineering beyond conventional search results and increases the visibility of malicious software recommendations. The campaign impersonates trusted system utilities including CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear to target users likely to own high-performance GPUs. Rather than maximizing infection volume, the threat actor appears focused on compromising systems with higher mining value."
        https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/
        https://thehackernews.com/2026/05/ai-chatbot-recommendations-redirect.html
        https://www.bleepingcomputer.com/news/security/gpu-mining-malware-spreads-via-seo-poisoning-ai-chatbots/
        https://www.helpnetsecurity.com/2026/05/27/ai-chatbot-cryptojacking-campaign/

      • Disrupting Glassworm: Inside CrowdStrike’s Takedown Of a Developer-Targeting Botnet
        "On May 26, 2026, at 14:00 UTC, the CrowdStrike Counter Adversary Operations team executed a coordinated takedown of the Glassworm botnet, a global threat targeting software developers through the open-source supply chain. In collaboration with Google and the Shadowserver Foundation, we struck all four of Glassworm's command-and-control (C2) channels simultaneously, severing the operators from their infected machines and their ability to deliver new malicious payloads. This takedown matters beyond the botnet. Glassworm marked a significant shift in the threat landscape that should serve as a wake-up call for every organization that ships or consumes software. Adversaries are no longer just targeting products, they're targeting the developers who build them."
        https://www.crowdstrike.com/en-us/blog/inside-crowdstrike-takedown-of-a-developer-targeting-botnet/
        https://www.bleepingcomputer.com/news/security/glassworm-botnet-disrupted-after-resilient-c2-infrastructure-takedown/
        https://thehackernews.com/2026/05/glassworm-malware-takedown-disrupts.html
        https://www.bankinfosecurity.com/glassworm-group-software-supply-chain-attackers-disrupted-a-31792
        https://www.infosecurity-magazine.com/news/crowdstrike-google-takedown/
        https://cyberscoop.com/crowdstrike-glassworm-botnet-takedown/
        https://www.securityweek.com/glassworm-botnet-disrupted/
        https://securityaffairs.com/192749/cyber-crime/how-cybersecurity-firms-took-down-glassworm-botnet-in-one-shot.html
        https://www.theregister.com/cyber-crime/2026/05/27/crowdstrike-google-shatter-glassworm-botnet/5247337

      • FBI Warns Of In-Person Data Theft Attacks From Extortion Gang
        "The FBI warned on Tuesday that the Silent Ransom Group (SRG) extortion gang is now targeting U.S.-based law firms in in-person data theft attacks. "As of Spring 2026, SRG actors use a social engineering scheme to pose as an employee from the victim's IT department. SRG actors either directly call or send phishing emails to urge employees to call the SRG actor posing as IT support," the FBI warned in a Tuesday flash alert. "While on the phone, the SRG actor directs the employee to grant access to a remote desktop session. If that attempt fails, SRG sends a threat actor to the victim's location to gain access to insert a storage device into the victim's computer.""
        https://www.bleepingcomputer.com/news/security/fbi-warns-of-silent-ransom-group-in-person-data-theft-attacks/
        https://www.ic3.gov/CSA/2026/260526.pdf
        https://www.darkreading.com/cyberattacks-data-breaches/ransomware-actors-steal-law-firm-data
        https://therecord.media/fbi-warns-hackers-visit-law-firms-to-steal-data
        https://cyberscoop.com/fbi-warning-silent-ransom-group-law-firms/
        https://www.securityweek.com/fbi-hackers-sending-operatives-in-person-to-insert-usb-drives-and-steal-data/
        https://www.theregister.com/security/2026/05/27/fbi-crooks-enter-legal-offices-and-steal-data-via-usb-drive/5247212
        https://www.helpnetsecurity.com/2026/05/27/fbi-silent-ransom-group-law-firms-social-engineering/

      • OverlayPhantom: The Android Banking Trojan Hiding In Plain Sight
        "Cyble Research and Intelligence Labs (CRIL) has identified a novel Android banking trojan, dubbed OverlayPhantom, actively distributed in the wild via malicious URLs. The malware employs a two-stage infection chain, using a dropper application that impersonates trusted platforms, including the official Austrian government identity application, ID Austria, and the widely used consumer platform TikTok, to deceive victims into installing it. Once deployed, OverlayPhantom masquerades as “Google Play Services” and abuses Android’s Accessibility Service to gain persistent, elevated control of the infected device."
        https://cyble.com/blog/overlayphantom-android-banking-trojan/

      • The GHOST STADIUM Score: Billions At Stake At The World’s Largest Football Tournament
        "The 2026 FIFA World Cup is set to be the largest sporting event in history. Hosted across three nations — the United States, Canada, and Mexico — the tournament will take place from June 11 to July 19, 2026, featuring 104 matches played in 16 cities. The scale is unprecedented: FIFA estimates that more than six million fans will fill stadiums, with an average of 450,000 visitors per city. More than 150 million tickets were requested within the first 15 days of the sales window alone, making this edition approximately 30 times oversubscribed compared to previous tournaments. For context, the 2022 Qatar World Cup drew over 3.4 million in-stadium fans with an average attendance capacity of 96.3 per cent. The 2026 edition is expected to nearly double that figure."
        https://www.group-ib.com/blog/ghost-stadium-football-fraud/
        https://www.infosecurity-magazine.com/news/ghost-stadium-fifa-world-cup-fraud/

      • Fake LinkedIn Emails Abuse Adobe To Track Victims
        "Cybercriminals are abusing Adobe infrastructure in a LinkedIn phishing campaign that steals passwords and redirects victims to the legitimate LinkedIn site afterward. The phishing email masquerades as a business inquiry designed to look like it’s come via LinkedIn and includes a fake “contract” attachment. But it contains a number of red flags:"
        https://www.malwarebytes.com/blog/threat-intel/2026/05/fake-linkedin-emails-abuse-adobe-to-track-victims

      • ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems
        "Trust and automation are key to many attacks; and trust with automation is inherent in the use of AI coding agents. Malicious repositories are a frequent factor in many supply chain attacks, estimated at between 20% and 40%. Such repositories can be used to fool a developer using an AI coding agent into generating bad code that can silently slip into the CI pipeline. That is just one possibility of the SymJack attack described by Adversa AI. The attack requires three elements: attacker control of the coding agent repo, a ready-made malicious MCP server, and a developer’s use of an AI coding tool."
        https://www.securityweek.com/symjack-attack-turns-ai-coding-agents-into-supply-chain-attack-delivery-systems/
        https://adversa.ai/blog/the-approval-prompt-is-lying-to-you-symlink-rce-in-five-ai-coding-agents-claude-code-cursor-antigravity-copilot-grok-build

      • Grandoreiro Malware Campaign Targets Europe And Latin America
        "WatchGuard telemetry identified a campaign associated to Grandoreiro that uses the DLL Side-Loading technique abusing four different softwares, targeting banks in Portugal. Also, it was identified cases of a known campaign that uses a malicious VBS to deliver the malware, targeting companies in Spain, Portugal, Mexico and Latin America. Grandoreiro has been active since at least 2016 and is now one of the most widespread banking trojans globally. Despite the disruption of some operators and the joint operations with INTERPOL and local law enforcement resulting in the arrest of gang members in Spain, Brazil, and Argentina, that occurred in 2021 and 2024, they’re still active due to only part of the gang was arrested and the ones that was not arrested are continuing the operations."
        https://www.watchguard.com/wgrd-security-hub/secplicity-blog/grandoreiro-malware-campaign-targets-europe-and-latin-america

      • Malware-Slop: New Malicious Npm Package Leaks Its Own GitHub Private Token
        "A malicious npm package that reads and uploads files from “/mnt/user-data” was uploaded to GitHub. OX Security observed around 7 active exfiltration in the threat actor’s GitHub repository before it was taken down, most of them are probably tests conducted by the threat actor itself. The malware reached 676 downloads, and is still live on npm (at time of publishing)."
        https://www.ox.security/blog/malware-slop-new-malicious-npm-package-leaks-its-own-github-private-token/
        https://thehackernews.com/2026/05/malicious-npm-package-stole-files-from.html

      • Ababil Of Minab: How An Iran-Linked Crew Exfiltrated Data From Four Countries And Destroyed IT, Backups, And Recovery At a Subset Of Victims
        "Gambit Security Threat Intelligence team investigated an intrusion campaign targeting organizations in the United States, Israel, Saudi Arabia, and Turkey: exfiltration across all of them, with destructive operations at a subset. The activity surfaced publicly in late March and early April 2026, after a pro-Iranian persona calling itself Ababil of Minab claimed to have compromised the Los Angeles County Metropolitan Transportation Authority (LACMTA / LA Metro), destroyed systems, and exfiltrated data. Our investigation found that Ababil of Minab is unlikely to be a new, standalone hacktivist crew as they claim."
        https://gambit.security/blog-posts/babil-of-minab-iran-mois-destruction-campaign
        https://therecord.media/iranian-intelligence-behind-hack-of-la-transit-system
        https://www.securityweek.com/la-metro-cyberattack-linked-to-iranian-state-sponsored-hackers/
        https://securityaffairs.com/192764/hacktivism/the-la-metro-attack-wasnt-hacktivism-it-was-a-state-operation-with-a-costume-on.html

      • Attackers Disguising Phishing As Google AppSheet Notifications
        "Phishing campaigns have become significantly more sophisticated and convincing in recent years. Sender addresses are now nearly identical to the real deal, emails are flawlessly written, and users are called by their names. But what do you do when a suspicious email comes from a clearly legitimate email address? Lately, phishers have been exploiting the Google AppSheet platform to set up email blasts that originate from an official Google-linked address. Following a successful attack, they walk away with their victims’ accounts and sensitive data."
        https://www.kaspersky.com/blog/appsheet-phishing-emails/55827/

      • Breaches/Hacks/Leaks

      • Latin American Cybercriminals Hoover Up Government Data
        "Cyber threat groups in Latin and South America have increasingly targeted government agencies and contractors, stealing and monetizing citizen data at a rate that has made the public-administration sector in the region the most-breached in the past year. In mid-May, a group known as La Pampa Leaks claimed to have compromised Uruguay's government-sponsored identity service managed by telecommunications provider Antel, reportedly monetizing the information as a citizen-data lookup service. In February, a hacking collective known as the Chronus Group claimed to have stolen data from 25 different Mexican government agencies and groups. And, in Colombia, cyberattackers targeted the nation's health ministry with more than 23 million attempted attacks during the month of March."
        https://www.darkreading.com/cyberattacks-data-breaches/latin-american-cybercriminals-government-data

      • UK Visa Portal Exposed Thousands Of Applicants’ Passports And Selfies — Then Called The Lawyers On Us
        "A website called UK Visa Portal publicly exposed thousands of passports and selfie photos of applicants who paid the site to obtain a U.K. immigration visa, TechCrunch has learned. An anonymous person notified TechCrunch about the security lapse, saying that the website was exposing at least 100,000 documents from people who uploaded their passports and selfies to the website as part of the application process. The website is not affiliated with the U.K. government, and some have complained that they mistakenly paid a fee to this company instead of using the official GOV.UK website."
        https://techcrunch.com/2026/05/27/uk-visa-portal-spilled-thousands-of-applicants-passports-and-selfies-online-and-hasnt-fixed-the-leak/

      General News

      • Dutch Police Arrests Suspect Linked To Ajax Football Club Hack
        "The Dutch National Police arrested a 35-year-old man suspected of hacking the professional football club Ajax Amsterdam (AFC Ajax) earlier this year. The suspect was arrested in Buren and, according to a Tuesday press release, he is believed to have hacked into the football club's systems multiple times. "On the morning of Tuesday, May 26, the police arrested a 35-year-old man from the municipality of Buren for computer trespassing at the Amsterdam football club Ajax. The man is suspected of deliberately unlawful intrusion into Ajax's computer systems several times," the police said."
        https://www.bleepingcomputer.com/news/security/dutch-police-arrests-suspect-linked-to-ajax-football-club-hack/
        https://therecord.media/dutch-police-arrest-man-over-cyber-breach-ajax-football
      • UK Spy Chief Labels AI ‘unstoppable Force’ With Offensive, Defensive Ramifications For Cyberspace
        "Artificial intelligence is an “unstoppable force” that allows tech to be “weaponized just below the threshold of traditional warfare,” including in cyberspace, the head of a U.K. intelligence, security and cybersecurity agency said Wednesday. We live in a world “where the latest frontier AI is rapidly unearthing fault lines in technologies our society relies on every single day,” said Anne Keast-Butler, director of the Government Communications Headquarters (GCHQ) spy agency. “The ground beneath our feet is shifting, and shifting fast. Which means cybersecurity has never been more important.”"
        https://cyberscoop.com/gchq-warns-ai-cyber-warfare-threats/
        https://www.securityweek.com/uk-cyberspying-chief-calls-ai-an-unstoppable-force-and-warns-about-russia/
      • 62% Of Critical Vulnerabilities Have Exploits Circulating Before Scanners Can Detect Them
        "Eighteen months ago, security teams had roughly four months between a new CVE and a working exploit. As of April 2026, that window is ten hours. We wanted to understand what that compression means for the detection tools most organizations depend on: vulnerability scanners. So the Cogent Research team analyzed 69,159 CVEs published between January 2025 and April 2026, tracking three timestamps for each one: when the CVE was published, when a working exploit became available, and when the major scanner vendors (Tenable, Qualys, and Rapid7) shipped detection signatures. The findings are not encouraging for teams that rely on scanner output as their primary visibility into new threats."
        https://www.cogent.com/blog/2026-q2-detection-gap-report-findings
        https://www.darkreading.com/threat-intelligence/ai-assisted-exploit-development-scanner-detection
      • Coinflow CISO On Crypto Payments Security Under AI Pressure
        "Crypto payment firms sit near the top of the target list for advanced persistent threat groups, and the workload on their security leaders keeps growing. Malcolm Portelli, CISO at Coinflow, runs the company’s security program from Malta. Coinflow is headquartered in the United States and operates across multiple jurisdictions. Portelli sat down for this interview at the Span Cyber Security Arena conference. Portelli says the sector drives his threat model more than the location. “It’s more the industry which we operate in. So, financial services, Web3, and crypto and all that comes with that. Crypto is a big target, especially for the big APTs. They’re always looking at how they can get into crypto firms because that’s their chosen money.”"
        https://www.helpnetsecurity.com/2026/05/27/malcolm-portelli-coinflow-crypto-payments-security/
      • 68% Of UK Firms Plan To Increase Cyber Spending As AI Risks Rise
        "More than two-thirds of UK businesses have said they plan to increase cybersecurity spending over the next 12 months as AI adoption and geopolitical uncertainty reshape technology budgets. According to the Q1 2026 Barclays Business Prosperity Index, 68% of UK business leaders expect to increase cybersecurity investment, while 46% believe new technologies are increasing their exposure to cybersecurity risks."
        https://www.infosecurity-magazine.com/news/uk-firms-cyber-spending-ai-risks/
      • More CVEs, Same Playbook: 2026 Vulnerability Exploitation In The Wild
        "Proofpoint's dual telemetry streams — targeted attack visibility covering hundreds of millions of messages daily, and a global network sensor array that generated over 3 million alerts and identified four undisclosed CVEs in 2026 to date — present a consistent picture: attackers are opportunistic. They grab newly published CVEs when public proof-of-concept code appears, chain them with established techniques, and move on. What has changed is the volume of vulnerabilities feeding that pipeline. NIST reported that CVE submissions in Q1 2026 were nearly one-third higher than the same quarter last year, and that the National Vulnerability Database still cannot keep pace with enrichment. The widely-cited driver is AI-assisted vulnerability discovery: frontier models are enabling both defenders and researchers — and, increasingly, anyone with access to an open-weights model — to surface bugs at machine speed. The exploit window is narrowing, but the exploitation pattern remains recognizable."
        https://www.proofpoint.com/us/blog/threat-insight/more-cves-same-playbook-2026-vulnerability-exploitation-wild
      • The Credential Crisis: How Stolen Credentials Defeat Modern Security
        "The modern cyber use of the word ‘credentials’ stems from the Latin ‘creder’: to believe. As society evolved into the Middle Ages, the early notion of ‘Believe me. I am Socrates’ became, ‘Believe this physical letter that proves I am Socrates.’ Those physical letters became known as ‘credentialis’, or a paper that authenticated the bearer. In today’s cyber world, we call that paper ‘credentials. It is no longer physical, but virtual, and the meaning has expanded to ‘you can trust in the belief that I am who I say I am and you can treat me as such: I am Socrates.’ Socrates is the identity, and the credentials prove it."
        https://www.securityweek.com/the-credential-crisis-how-stolen-credentials-defeat-modern-security/
      • Expecting The Unexpected: Monitoring For Drift In ML Systems
        "Imagine the following scenario: you and a team of cyber experts have been tasked with protecting your organization from cyberattacks. You’ve developed a machine learning (ML) model to screen incoming and outgoing traffic. You feel you can rest easy, as your model achieves near-perfect performance during test and evaluation. One day, you are awakened by a frantic call from your CEO—your customers’ private data have been leaked. How could this happen? you think to yourself, as you begin investigating why your model failed to stop this attack."
        https://www.sei.cmu.edu/blog/expecting-the-unexpected-monitoring-for-drift-in-ml-systems/
      • SOC Threat Radar — May 2026
        "Attackers are successfully signing in to Microsoft 365 accounts using IP addresses that look more like legitimate users. To do this, attackers are using VPNs or frequently changing IP addresses. This helps their activity to blend in with everyday employee logins. Researchers noted that in April there was an increase of around 25% in malicious logins coming from low-risk countries such as the UK and the U.S., rather than regions that are more usually associated with suspicious logins."
        https://blog.barracuda.com/2026/05/27/soc-threat-radar-may-2026
      • Romanian National Sentenced For Selling Access To Networks Of Oregon State Government Office And Other U.S. Victims
        "A Romanian national was sentenced yesterday to 56 months in prison in connection with an online intrusion into an Oregon state government office in 2021 and other cyber-attacks on U.S. victims. According to court documents, Catalin Dragomir, 46, formerly of Constanta, Romania, sold access to a computer on the network of an Oregon state government office after obtaining unauthorized access to it in June of 2021. During the sale, Dragomir provided the prospective buyer with samples of personal identifying information from the computer. He also sold access to the computer networks of numerous other victims in the United States, causing losses of at least $250,000."
        https://www.justice.gov/opa/pr/romanian-national-sentenced-selling-access-networks-oregon-state-government-office-and-other
        https://therecord.media/romanian-national-sentenced-to-over-4-years-oregon-hack
        https://www.securityweek.com/romanian-hacker-sentenced-to-prison-in-us-for-selling-access-to-state-network/
        https://securityaffairs.com/192770/cyber-crime/romanian-hacker-gets-nearly-5-years-in-us-prison-over-network-intrusion.html
      • Out Of The Crypt: The Evolving Cyber Extortion Economy
        "This blog dives into the growing trend of data theft and extortion activities which no longer require the use of ransomware to pressure victims into paying a demand. We examine the financially-motivated threat actors using both single and double extortion techniques and what this means for organizations going forward, especially with the arrival of frontier AI models."
        https://unit42.paloaltonetworks.com/cyber-extortion-economy/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) e2ee252e-5106-4b36-8581-c689ab4c1007-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Microsoft ออกอัปเดตความปลอดภัย แก้ช่องโหว่ RCE ใน SharePoint Server

      Microsoft ออกอัปเดตความปลอดภัย แก้ช่องโหว่ RCE ใน Sha.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e3df951c-aabb-485e-8586-a3d81e17e2b5-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Lazarus APT ใช้มัลแวร์ RemotePE แบบ Fileless RAT ทำงานในหน่วยความจำเพื่อหลบเลี่ยงการตรวจจับ

      Lazarus APT ใช้มัลแวร์ RemotePE แบบ Fileless RAT ทำงานในหน่วยคว.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand c8ba6196-7fc4-4366-8249-3c0b7f376b94-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • การโจมตีห่วงโซ่อุปทาน Megalodon กระทบคลังข้อมูล GitHub กว่า 5,500 แห่ง มุ่งขโมยข้อมูลลับของระบบ

      การโจมตีห่วงโซ่อุปทาน Megalodon กระทบคลังข้อมูล.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 19c05d9f-e6e7-4ab9-aab1-d155eb178cb2-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 26 พฤษภาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-48172 LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/05/26/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 2d3cac18-ca3d-4ce7-b601-5bd15b824bb5-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ เมื่อวันที่ 26 พฤษภาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-146-01 ABB Terra AC
      • ICSA-26-146-02 ABB AC500 V2
      • ICSA-26-146-03 ABB AbilityTM Zenon Remote Transport Vulnerability
      • ICSA-26-146-04 ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager
      • ICSA-26-146-05 ABB Ability Camera Connect
      • ICSA-26-146-06 ABB LVS MConfig
      • ICSMA-26-146-01 Eppendorf BioFlo 320
      • ICSA-25-259-01 Schneider Electric Multiple Altivar Process Drives and Communication Modules (Update B)

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories 05450887-823c-43a2-98d7-49e84e66f999-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 27 May 2026

      Healthcare Sector

      • Eppendorf BioFlo 320
        "Successful exploitation of this vulnerability could allow an attacker to gain full access to functionality and data with the bioreactor."
        https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-146-01

      Industrial Sector

      • ABB B&R Automation Runtime DoS Vulnerability In System Diagnostics Manager (SDM)
        "An update is available that resolves a vulnerability identified by B&Rs internal security analysis in the product versions listed as affected in this advisory. An attacker who successfully exploited this vulnerability could cause the product to stop."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-146-04
      • ABB Ability Camera Connect
        "ABB is aware of public reports of vulnerabilities in a 3rd party component VLC media player Version 2.2.4 which was delivered together with the installation package of Camera Connect Version 1.5.0.14 and below. An update is available that resolves a privately reported outdated 3rd party component with vulnerabilities in the product versions listed as affected in this advisory. An attacker who successfully exploited any of these vulnerabilities in the 3rd party component could potentially compromise the system in different ways."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-146-05
      • ABB Terra AC Wallbox
        "ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-146-01
      • ABB AC500 V2
        "ABB became aware of vulnerabilities in AC500 V2 listed as affected in the advisory. An attacker who successfully exploited this vulnerability could access fragments of Modbus telegrams that have been sent earlier by that PLC"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-146-02
      • ABB AbilityTM Zenon Remote Transport Vulnerability
        "ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. The vulnerability enables unauthorized access to the Reboot OS function within the Remote Transport Service, allowing an attacker to trigger a system reboot without the required authentication. This functionality initiates a system reboot on the target machine. However, remote exploitation of this vulnerability is not feasible unless the attacker has already gained access to the network where the affected ABB Ability™ zenon system is deployed. At the time of writing, there is no evidence that this vulnerability is being actively exploited in the wild."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-146-03
      • ABB LVS MConfig
        "ABB became aware of an internally discovered vulnerability in the MConfig product versions listed as affected in the advisory. An attacker with access to local networks who successfully exploits vulnerability could have access to application’s sensitive information. ABB strongly advises customers to update MConfig with latest software version."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-146-06

      Vulnerabilities

      • Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
        "Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without requiring any specialized conditions to be met. The vulnerability, tracked as CVE-2026-45659, carries a CVSS score of 8.8. It has been assigned an important severity. "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network," Microsoft said in an advisory released last week."
        https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html
        https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659
        https://www.helpnetsecurity.com/2026/05/26/sharepoint-vulnerability-cve-2026-45659/
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-48172 LiteSpeed cPanel Plugin Privilege Escalation Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/05/26/cisa-adds-one-known-exploited-vulnerability-catalog
      • Exploitation Of KnowledgeDeliver Via ViewState Deserialization Vulnerability
        "In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver. KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (RCE). An unknown threat actor leveraged this access to inject malicious code into the LMS platform, with the goal of infecting users visiting the site. This vulnerability stems from the use of identical pre-shared ASP.NET machine keys across multiple customer deployments. The vulnerability was initially exploited as a zero-day, now tracked as CVE-2026-5426."
        https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability
        https://thehackernews.com/2026/05/knowledgedeliver-lms-flaw-exploited-to.html
        https://www.bleepingcomputer.com/news/security/knowledgedeliver-flaw-exploited-as-a-zero-day-to-install-web-shells/
        https://www.securityweek.com/hackers-exploited-knowledgedeliver-zero-day-for-web-shell-deployment/

      Malware
      INTRUSION ANALYSIS: China-Nexus Adversary Targeting Southeast Asian Edge Network Infrastructure
      "A China-nexus intrusion set has been identified conducting a large-scale campaign targeting edge network devices across Southeast Asia. The adversary deploys a custom Linux ELF implant (router.elf) directly onto compromised border routers, establishing persistent command-and-control (C2) via DNS over HTTPS (DoH) while simultaneously weaponizing the router's iptables subsystem to hijack downstream DNS traffic at scale. Correlated Windows-side tradecraft leverages a cracked Cobalt Strike 4.4 Beacon delivered via DLL sideloading (version.dll), sharing identical C2 infrastructure and malleable C2 profiles with the router implant — confirming unified operational control."
      https://qiita.com/Y4er/items/0b6071745e4b7b240b3e

      • Phishing Campaign Deploys JavaScript-Driven PureLogs Variant To Steal Sensitive Data
        "FortiGuard Labs recently identified a phishing campaign distributing a PureLogs variant designed to collect sensitive data from the victim’s device. The analysis provides an in-depth examination of the campaign, including the phishing emails and the mechanisms by which the JavaScript file operates on the victim's device. This campaign uses deceptive emails disguised as purchase orders, a tactic commonly used to trick recipients into opening malicious attachments."
        https://www.fortinet.com/blog/threat-research/phishing-campaign-deploys-javascript-driven-purelogs-variant-to-steal-sensitive-data
      • 2 PhaaS 2 Furious: The Evolution Of Chinese-Language Phishing Services
        "While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current PhaaS offerings in the Chinese underground, all of them mature services and many likely tied intricately to the broader criminal ecosystem in that region. These services not only lower the barrier to entry for Chinese cyber criminals, but reveal broader patterns on the evolution of social engineering and credential theft. Late last year, Google took legal action against one PhaaS provider and has worked since then to endorse legislation and enact technical safeguards against these types of scams."
        https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-services
        https://www.infosecurity-magazine.com/news/chinese-phishing-live-credential/
        https://www.helpnetsecurity.com/2026/05/26/chinese-language-phishing-services/
      • BTMOB: A Stealthy RAT Burrowing Deep Into Android Devices
        "Our recent review of threat detections in Brazil surfaced BTMOB, an Android remote access trojan (RAT) that is less notable for detection volume than for the damage it can wreak. The combination of phishing-led delivery, ready-made app-building tooling and device takeover capabilities makes BTMOB a threat to watch well beyond Brazil or Latin America."
        https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/
        https://www.infosecurity-magazine.com/news/btmob-android-rat-maas-builder/
      • Fast And Furious – Nimbus Manticore Operations During The Iranian Conflict
        "During the recent geopolitical tensions in the Middle East, we reported on multiple Iran-nexus threat actors advancing Iran’s strategic objectives through cyber operations. These activities included targeting internet-connected cameras, conducting destructive attacks against US and Israeli entities, and exfiltrating data from cloud environments to support broader kinetic and intelligence-gathering efforts. Nimbus Manticore (also tracked as UNC1549) is an IRGC-affiliated threat actor who primarily targets the defense, aviation and telecommunication sectors through career-themed phishing campaigns. Nimbus Manticore stands out compared to other Iranian-linked groups due to its complex malware toolset. In 2025, we documented the MiniJunk malware framework used by Nimbus Manticore to target high-profile organizations across Western Europe and the Middle East."
        https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/
        https://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.html
        https://www.infosecurity-magazine.com/news/iranian-hackers-us-aviation/
        https://www.securityweek.com/iranian-apt-targets-aviation-software-companies-with-updated-tools/
        https://securityaffairs.com/192689/apt/nimbus-manticore-expanded-attacks-with-ai-assisted-malware-and-fake-zoom-installers.html
      • Fake Software On GitHub And SourceForge Distribute Deno RAT
        "During our threat hunting activities, we found fake installers and plugins impersonating popular software including ChatGPT, Claude, AutoTune, and Kontakt on GitHub and SourceForge distributing a Deno backdoor known as DinDoor. Attackers are using compromised YouTube channels to distribute links to these platforms. DinDoor ultimately drops different types of malware, including a stealthy remote access Trojan (RAT), which also uses the Deno JavaScript runtime."
        https://www.malwarebytes.com/blog/threat-intel/2026/05/fake-software-on-github-and-sourceforge-distribute-deno-rat
      • Smart Contracts For C&C: How ClearFake Hid In Plain Sight On BSC Testnet
        "TrendAI™ Research analyzed in May 2026 an intrusion where threat actors used a technique known as EtherHiding to store payload routing instructions inside BNB Smart Chain (formerly Binance Smart Chain or BSC) smart contracts. Unlike traditional command-and-control (C&C) infrastructure, this routing layer cannot be altered, suspended, or seized by security vendors, registrars, or law enforcement due to the immutable nature of the blockchain. TrendAI™ found that the injected JavaScript on compromised websites queried these contracts to retrieve and route victims to the next stage of the attack chain."
        https://www.trendmicro.com/en_us/research/26/e/smart-contracts-for-command-and-control.html
      • Living Off The Land With VS Code: Inside a Sophisticated Phishing Campaign
        "In this blog post, we examine a multi-stage phishing campaign targeting staff members of the Punjab Safe Cities Authority (PSCA) and PPIC3 in Pakistan. The attack leveraged two distinct infection vectors, both relying on the same underlying infrastructure. The phishing email was analyzed by Joe Reverser in the report available here: https://www.joesandbox[.]com/joereverser/analysis/download/ff6db592-b57e-4d21-9d46-e69c2719d8a5?type=html. The Capability Preview image below already offers a comprehensive overview of the kill chain:"
        https://joesecurity.org/blog/8858614039441223943
      • Dark Web Profile: CoinbaseCartel
        "CoinbaseCartel is a financially motivated threat actor that emerged on the Dark Web in September 2025. Unlike traditional ransomware groups, the group does not encrypt victim systems. Instead, it relies exclusively on data theft, threatening to publish exfiltrated data on its dark web leak site unless victims pay a ransom. This approach is commonly described as a single-extortion model. The group’s name carries no connection to the legitimate cryptocurrency exchange Coinbase. On its leak site, CoinbaseCartel describes itself as “redefining data extortion” and explicitly states that its operations have no political, personal, or activist agenda."
        https://socradar.io/blog/dark-web-profile-coinbasecartel/

      Breaches/Hacks/Leaks

      • Charter Confirms Data Breach After ShinyHunters Extortion Threat
        "U.S. telecommunications giant Charter Communications has confirmed it suffered a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid. Charter Communications is one of the largest broadband providers in the United States, serving tens of millions of residential and business customers through its Spectrum brand. In a statement shared this weekend, the company said it is alerting authorities about the incident and that no sensitive personal customer information was stolen."
        https://www.bleepingcomputer.com/news/security/charter-confirms-data-breach-after-shinyhunters-extortion-threat/
      • 7-Eleven Data Breach Exposes Personal Information Of 185,000 People
        "The ShinyHunters extortion gang stole the personal information of over 183,000 people after hacking the systems of convenience store chain giant 7-Eleven in April, according to data breach notification service Have I Been Pwned. Founded in 1927, 7-Eleven now operates, franchises, and licenses more than 86,000 stores worldwide, including 13,000 stores in the U.S. and Canada. 7-Eleven also operates and franchises Speedway, Stripes, Laredo Taco Company, and Raise the Roost Chicken and Biscuits locations, and its 7Rewards and Speedy Rewards loyalty programs also have over 100 million members."
        https://www.bleepingcomputer.com/news/security/7-eleven-data-breach-exposes-personal-information-of-185-000-people/
        https://haveibeenpwned.com/Breach/7-Eleven
        https://www.securityweek.com/185000-likely-impacted-by-7-eleven-data-breach/
        https://www.helpnetsecurity.com/2026/05/26/7-eleven-data-breach-shinyhunters/
      • Lithuania Suspects Foreign Involvement In Data Leak Of Over 600,000 National Register Entries
        "Lithuanian authorities are on high alert after a massive data leak involving more than 600,000 entries from national data registers, which is believed to have been executed by another country. The Lithuanian general prosecutor’s office on Friday announced the leak was primarily from registers of real estate and legal entities accessed by using login credentials of institutions authorized to receive the data. The head of the State Enterprise Centre of Registers, Adrijus Jusas, resigned Monday following the leak."
        https://www.securityweek.com/lithuania-suspects-foreign-involvement-in-data-leak-of-over-600000-national-register-entries/
        https://therecord.media/lithuania-investigates-theft-of-state-records
      • MyPillow Must Decide Whether To Be Firm Or Soft As Ransomware Crims Demand Pay
        "Crims found the soft spot in the company's security. MyPillow, the US-based bedding brand founded by election conspiracy theorist Mike Lindell, has been listed by Play ransomware extortionists as an alleged victim. The pillow shop first appeared on Play’s name-and-shame data leak site on Monday, with the gang threatening to leak stolen data by Friday if MyPillow execs don’t pay the ransom demand."
        https://www.theregister.com/cyber-crime/2026/05/26/mypillow-appears-on-play-ransomware-leak-site/5246513

      General News

      • April 2026 Threat Trend Report On APT Attacks (South Korea)
        "ahnLab utilized its infrastructure to monitor Advanced Persistent Threat (APT) attacks on targets in Korea. this report summarizes the classification, statistics, and features of each type of APT attacks identified in Korea during the month of April 2026."
        https://asec.ahnlab.com/en/93831/
      • 2026 Cloud Security Report: Why Traditional Network, Cloud, And Security Architecture Are Lagging Behind The AI Transformation
        "As AI rapidly reshapes industries, the role of the cloud has become even more critical. From automated customer experiences to intelligent cyber security and predictive analytics, AI transformations are increasingly being built on a cloud-first foundation. Over the past two years, AI has swiftly moved from an experimental state to an operational reality, with every leading organization embedding AI into the core of how they build, operate, and compete. However, security architectures have not kept pace with the AI transformation. Closing that gap requires more than incremental fixes. It demands a rethinking of how security is designed, deployed, and enforced across hybrid environments."
        https://blog.checkpoint.com/securing-the-cloud/2026-cloud-security-report-why-traditional-network-cloud-and-security-architecture-are-lagging-behind-the-ai-transformation/
      • Why Network Segmentation Projects Fail: Four Patterns
        "In previous blogs, I’ve discussed why segmentation matters, the challenges of getting it right, and the benefits that organizations see when they fully commit to both macro- and micro-segmentation. Today, I want to flip the question around. Instead of asking what happens when segmentation succeeds, let’s ask: why do so many segmentation projects fail. That question is the focus of the newly released Cisco 2026 Segmentation Report, which draws on a survey of 400 failed segmentation projects at U.S.-based organizations with 500 or more employees. The findings are illuminating—and occasionally surprising."
        https://blogs.cisco.com/security/why-network-segmentation-projects-fail-four-patterns
        https://www.cisco.com/c/en/us/products/collateral/security/hypershield/segmentation-report-2026.pdf
      • The Hackers Behind Shai-Hulud: Lucky Or Skilled?
        "TeamPCP has made a name for itself as a scourge of the open source community following its particular waves of the Shai-Hulud attacks, but the group's attack history is less "sophisticated threat actor" and more "right place, right time" luck. A financially motivated threat actor, TeamPCP formally emerged in late 2025, making a name exploiting the React2Shell vulnerability as well as targeting misconfigured Docker APIs and Next.js. As researchers from Flare recently noted, the group would historically use opportunistic compromises to conduct ransomware, steal data to turn around and sell, and mine cryptocurrency."
        https://www.darkreading.com/application-security/shai-hulud-hackers-teampcp-lucky-skilled
      • What Happens When Security Teams Inherit Identity
        "At the Span Cyber Security Arena conference, I sat down with Eric Woodruff, Chief Identity Architect at Semperis, to talk about how organizations perceive identity and the challenges those perceptions create for security. He shared his perspective on where organizations struggle with identity, why identity platforms can become difficult to manage, how phishing-resistant authentication is viewed in practice, and what non-human identities and AI could mean for security."
        https://www.helpnetsecurity.com/2026/05/26/eric-woodruff-semperis-identity-security/
      • CERT-In Recommends 12-Hour Patching For Internet-Facing Flaws Amid AI-Assisted Attacks
        "The Indian Computer Emergency Response Team (CERT-In) has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of being flagged where "feasible" to safeguard against potential threats stemming from threat actors' abuse of artificial intelligence (AI) tools and large language models (LLMs) to automate vulnerability discovery and exploitation, and enhance the scale and velocity of cyber attacks. "AI-assisted cyber exploitation reduces the time required for adversaries to identify, weaponize, and exploit vulnerabilities, exposed services, weak identities, insecure APIs, and misconfigured systems," CERT-In said in a 38-page blueprint published Monday."
        https://thehackernews.com/2026/05/cert-in-mandates-12-hour-patching-for.html
        https://www.cert-in.org.in/s2cMainServlet?pageid=GUIDLNVIEW02&refcode=CISG-2026-02
        https://www.infosecurity-magazine.com/news/cert-in-12-hour-patch-deadline-ai/
      • 62% Of Database Ransom Wallets Were Never Paid
        "We built a five-year census of 65,907 exposed databases on the public internet. 30,515 of them (46.3%) carry a ransom or wipe marker. We then validated every bitcoin address inside those notes, ending with 514 distinct attacker wallets. When we priced the 512 we could resolve on-chain, 318 had received zero bitcoin. The 9.78 BTC (around $753,000) that did move concentrated into a handful of operators. Mass database extortion is industrial, automated, mostly unpaid, and still doing enormous damage."
        https://ransomnews.com/database-ransom-economics-2026/
        https://securityaffairs.com/192711/cyber-crime/the-hidden-ransomware-economy-running-on-exposed-databases.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 8701eea1-ff1d-4ff4-ab9c-60b44f67ff28-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT