NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,548
    • กระทู้ 2,549
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    NCSA_THAICERT

    @NCSA_THAICERT

    1
    ชื่อเสียง
    57
    ดูข้อมูลส่วนตัว
    2.5k
    กระทู้
    3
    คนติดตาม
    0
    ติดตาม
    เข้าร่วม ออนไลน์ล่าสุด
    เว็บไซต์ www.ncsa.or.th/?fbclid=IwAR0BqJEC-CJzBs98rlBxUbZkNBgp1g814xdDNNaKnHTrxfqZhPD--ksY68I

    NCSA_THAICERT เลิกติดตาม ติดตาม
    Global Moderator administrators

    Latest posts made by NCSA_THAICERT

    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 4 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/04/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 1d374e2e-ff1f-4266-a1c4-04f3ab63f292-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 07 September 2026

      Industrial Sector

      • IXON VPN Client
        "Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-02
      • Pyramid Solutions NetStaX EtherNet/IP Stack
        "Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-07
      • Inductive Automation Ignition
        "Successful exploitation of this vulnerability could allow any authenticated user to create projects."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-06
      • Tycon Systems TPDIN-Monitor-WEB3
        "Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08
      • OPCFoundation OPC UA LocalDiscoveryServer (LDS)
        "Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-01
      • Rockwell Automation ControlFLASH
        "Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-03
      • Rockwell Automation ArmorStart LT
        "Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-04
      • Rockwell Automation 1756-ENBT Module
        "Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-05

      Vulnerabilities

      • Critical Citrix NetScaler Auth Bypass Now Leveraged In Attacks
        "Attackers have begun targeting a critical-severity Citrix NetScaler flaw in the wild, according to vulnerability intelligence company Previdian. Tracked as CVE-2026-19490, this security flaw can allow unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured."
        https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/
      • Google Warns Of New Chrome Zero-Day Flaw Exploited In Attacks
        "Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. The exploited security issue, identified as CVE-2026-85046, is described as a type confusion. It was reported to Google by researcher Salvatore Gulizia, known online as “Serotav.” The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the advisory reads."
        https://www.bleepingcomputer.com/news/security/google-warns-of-new-chrome-zero-day-flaw-exploited-in-attacks/
        https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html
        https://www.securityweek.com/google-patches-6th-chrome-zero-day-of-2026/
        https://securityaffairs.com/198405/security/google-fixes-the-sixth-actively-exploited-chrome-zero-day-of-2026.html
        https://www.helpnetsecurity.com/2026/09/04/google-chrome-zero-day-cve-2026-85046/
      • StyleSmuggler: Magento And Adobe Commerce 0-Day RCE Under Active Attack
        "Sansec discovered StyleSmuggler, an unpatched Magento and Adobe Commerce zero-day that gives unauthenticated attackers remote code execution. All current versions are affected, including 2.4.9. Attacks started September 4th. Sansec is rolling out emergency mitigation."
        https://sansec.io/research/stylesmuggler
        https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html
      • Critical Vulnerabilities In MikroTik RouterOS Are Being Actively Exploited. Immediate Update Recommended
        "The CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS. Combining two of them allows an attacker to take full control of the device without authentication if the device supports remote access using the SSH protocol. To make this chain easier to identify, we have given it a common name, MikroTrick. In recent days we have been observing attacks against RouterOS devices accessible from the internet. We have obtained confirmation that the attackers are exploiting this combination of vulnerabilities to take full control of devices whose SSH service is accessible from public networks. It has also been confirmed that the released patches prevent the observed attacks. We recommend applying the update immediately."
        https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
        https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html
        https://securityaffairs.com/198538/security/your-mikrotik-router-may-already-be-compromised-look-for-ssh-user-2.html
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/04/cisa-adds-one-known-exploited-vulnerability-catalog
        https://securityaffairs.com/198455/security/u-s-cisa-adds-google-chromium-v8-flaw-to-its-known-exploited-vulnerabilities-catalog-2.html
      • PostGREShell: The Database Powering Much Of The Internet Had An Open Door For 12 Years
        "Imagine you've built a fortress. Guards at the front gate, scanners at every door, a guest list checked twice. You hired the best architects, ran the audits, passed the compliance reviews. By every measure, the place is locked down. But you missed something. Around the back, there's a small, unmarked entrance used by the cleaning crew. It's been there for years, and nobody thought to put a guard on it. Then one day, someone figures out that if you walk in through that entrance wearing a cleaning uniform, the entire fortress opens up: the armory, the vault, the control room. Once you're inside, everyone assumes you belong."
        https://www.cyera.com/research/postgreshell-the-database-powering-much-of-the-internet-had-an-open-door-for-12-years
        https://thehackernews.com/2026/09/postgresql-fixes-12-year-old-logical.html
        https://www.securityweek.com/12-year-old-postgresql-vulnerability-enables-database-server-takeover/
        https://securityaffairs.com/198433/security/postgresql-hit-by-12-year-old-vulnerability-allowing-server-takeover.html

      Malware

      • Attack Cases In Korea Involving The Installation Of Radmin And UltraVNC
        "The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases that exploited Radmin and UltraVNC. Although the Initial Intrusion method remains unknown, the attackers installed Radmin—a remote control tool—and then installed UltraVNC. The threat actors exploited the remote control tools to gain control of the infected systems and installed Netch and CCProxy to use the infected systems as proxy nodes. Recently, they have been installing SoftEther VPN to exploit the infected systems as VPN servers."
        https://asec.ahnlab.com/en/95230/
      • X Money Rollout Linked To Password-Reset Attacks
        "X says attackers may be targeting accounts because its X Money payments service is now more widely available. The company is investigating a wave of unsolicited password-reset emails sent to users. While their arrival alongside the wider X Money rollout has fueled account-takeover concerns, X says it has found no evidence of a breach or successful account takeovers so far."
        https://www.malwarebytes.com/blog/scams/2026/09/x-money-rollout-linked-to-password-reset-attacks
      • Angry Birds: Toy Ghouls’ New Toys
        "We continue tracking the activity of Toy Ghouls (also known as Bearlyfy, Laboo.boo, and Feral Wolf), a financially motivated group that has been targeting Russian organizations since 2025. The attackers initially relied exclusively on tools pulled from public GitHub repositories along with leaked Babuk and LockBit ransomware builders, later shifting to their own custom ransomware, GenieLocker. In early July 2026, we observed the group using a custom backdoor for the first time. We identified two versions of this backdoor: one uses the HiveMQ MQTT broker as its C2 server, while the other relies on the Element messenger."
        https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/
      • ASCII Smuggling Crosses Over From AI Prompt Injection To Phishing Evasion
        "Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling. Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as ‘funding’ to prevent email filters from parsing them. The finding emerged from Microsoft Defender for Office 365 prompt injection protection research, showing how AI-era evasion techniques can surface in traditional phishing campaigns. In Microsoft telemetry, hits on a hunting signature designed to detect ASCII-smuggling increased sharply beginning February 9, 2026, and remained elevated on weekdays for approximately three months. Microsoft Defender for Office 365 telemetry showed that the majority of messages were flagged by layered protections rather than by reliance on a single Unicode-specific signal."
        https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/
        https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html
        https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/
        https://www.theregister.com/security/2026/09/04/ascii-smuggling-isnt-just-an-ai-security-risk/5294595
      • DPRK APTs: Ted Backdoor And CurlRAT Target South Korean Media And Automotive Sectors
        "A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engage in long-term surveillance."
        https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/
        https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html
      • Attackers Actively Exploiting Critical Vulnerability In Super Forms Plugin
        "On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. The vendor released the fully patched version on July 8th, 2026, and we disclosed this vulnerability in the Wordfence Intelligence vulnerability database on July 9th, 2026. Our records indicate that attackers started exploiting the issue on July 14th, 2026, the same day we released the firewall rule. The Wordfence Firewall has already blocked over 250,000 exploit attempts targeting this vulnerability."
        https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-super-forms-plugin/
        https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html
      • Chinese-Speaking Operator Uses AI Agents To Target Government And Education Systems Across Asia
        "In July, we published research on a Chinese-speaking operator who embedded Claude Code and DeepSeek into intrusions across four countries. This is a second, separate campaign with different infrastructure, tooling, and targets, but the same pattern: commercial AI models used as operational components. Targets included Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam. The most extensive compromise hit a Fengtai District government environment, where the operator achieved command execution, collected LSASS and registry hives, accessed government and health records, and deployed multiple Windows implants. Separate activity exposed a Chinese education AI platform and obtained root database access to a university campus-card system."
        https://hunt.io/blog/chinese-operator-secflow-claude-qwen-deepseek-asia
        https://securityaffairs.com/198417/ai/chinese-hackers-use-ai-agents-in-multi-country-cyber-campaign.html
      • Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizations
        "Datadog Security Research observed a password spraying campaign targeting the AWS root user account. The campaign ran from July 24 to August 23, 2026. During this period, attackers made repeated failed authentication attempts against AWS root user accounts at more than 150 organizations. Organizations saw a median of two attempts each, with some experiencing up to eight attempts across the campaign window."
        https://securitylabs.datadoghq.com/articles/aws-root-user-bruteforce-campaign/
      • Chained Account Takeovers: AiTM Phishing Campaign Propagating Across Healthcare And Academic Medical Institutions
        "SRA identified an active adversary-in-the-middle (AiTM) phishing campaign propagating across healthcare and healthcare-education organizations by chaining compromised accounts. SRA reconstructed one chain across a university and two health systems, where a single compromised account phished recipients at more than 90 distinct .edu domains in roughly 13 minutes. Open-source analysis shows the observed chain is a part of a broader operation that pairs credential and session theft with a parallel malware delivery track, masking its infrastructure so effectively it scores clean on public reputation tools. Organizations in healthcare and higher education should hunt for the redirect and inbox-rule patterns detailed below, confirm session-token revocation on any affected account, and prioritize phishing-resistant MFA."
        https://sra.io/blog/chained-account-takeovers-aitm-phishing-campaign-propagating-across-healthcare-and-academic-medical-institutions/
      • Anatomy Of a Silent Domain Takeover
        "Modern AD attacks use legitimate protocols end-to-end, no malware, no exploit, nothing for signature tools to fingerprint. The evidence is already in the logs; what is missing is the narrative linking five benign-looking Windows events into a single attack. A full domain takeover can be completed in 54 minutes, from the first password spray to the forged Golden Ticket, with each individual event appearing normal."
        https://blog.qualys.com/product-tech/2026/09/02/anatomy-of-a-silent-domain-takeover-ad-real-time-monitoring
      • Malware On The Blockchain: An Ongoing Campaign’s New WebRTC Twist
        "EtherHiding, a technique that uses blockchain smart contracts as takedown-resistant payload storage, has been seen across more than 5,400 compromised websites in the last few months. The compromised websites have little in common beyond being small businesses (clinics, plumbers, e-commerce shops) with no shared industry, region, or owner. These compromised sites include either an inline script or a spoofed package that calls the BSC testnet and downloads a ClickFix overlay as the next step of the attack, which instructs visitors to run a command on their PC. We also observed a newer variant that, instead of a ClickFix overlay, opens a covert WebRTC data channel for Command and Control."
        https://www.netskope.com/blog/malware-on-the-blockchain-an-ongoing-campaigns-new-webrtc-twist
        https://www.bleepingcomputer.com/news/security/over-5-400-hacked-sites-serve-clickfix-payloads-stored-on-the-blockchain/
      • Discovery Of a New OpenAI Agent Message Board
        "We found ~18,000 posts from autonomous AI agents (self-identifying as from OpenAI) using the public internet to communicate during a web-retrieval task. These AIs colluded to share answers, research their environment, and bypass sandbox restrictions. Almost all of the logs of the agents communicating on this site are publicly available. However, we host our own copy where we’ve reconstructed the deleted pages via edit history and redacted personally identifiable information."
        https://collusion.wiki/
        https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/
        https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html
        https://securityaffairs.com/198524/ai/ai-agents-hijacked-german-wiki-to-cheat-openai-delayed-disclosure.html
      • Attackers Exploit PaperCut Flaws To Steal Credentials From Schools And Universities
        "Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as create privileged accounts. "Observed post-exploitation activity included delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands used to identify hosts, users, processes, and sensitive configuration data," Arctic Wolf said."
        https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html
        https://securityaffairs.com/198476/hacking/papercut-flaws-exploited-in-attacks-on-u-s-and-european-schools.html
      • REVSTEALER Ramps Up: Analysis Of Up-And-Coming Infostealer
        "Elastic Security Labs is tracking an emerging infostealer, REVSTEALER, under REF2859. This family has gained momentum in recent months, with higher distribution volume, and has emerged as a formidable threat, featuring a comprehensive credential harvester, an embedded sandbox scoring system, and a Polygon blockchain-based dead drop for resilience. Beyond credential theft, REVSTEALER targets gaming platforms for additional monetization; the developer clearly understands that victim accounts on these platforms hold real monetary value in resale markets."
        https://www.elastic.co/security-labs/threat-command/revstealer-credential-harvesting-infostealer
        https://assets.contentstack.io/v3/assets/bltefdd0b53724fa2ce/blt9cd59668ba5a104d/6a97978bd04dac6f166ca8ce/REVSTEALER_-_White_paper.pdf
      • Detection And Removal Of The Syslogk Rootkit In a Linux Environment
        "The AhnLab SEcurity intelligence Center (ASEC) continuously monitors various threats targeting Linux environments. Techniques that modify the Linux kernel to conceal malware and signs of compromise have been used for a long time, and Syslogk is one such rootkit that operates in this manner. This document provides an analysis of the key features and operational mechanisms of the Syslogk rootkit, along with detection and remediation strategies for our products developed based on this analysis."
        https://asec.ahnlab.com/en/95254/

      Breaches/Hacks/Leaks

      • Cybercrooks Trawl Fishbrain To Net Password Hashes
        "Cybercriminals have reeled in password hashes and corresponding salts belonging to users of popular fishing app Fishbrain, opening the door to cracking attempts. Fishbrain AB, which says its eponymous app serves more than 20 million anglers, disclosed the August 19 breach to the California Attorney General's Office this week. The unknown perpetrators helped themselves to a trawl of user data, including names, dates of birth, email addresses, phone numbers, Fishbrain usernames, country information, password hashes, and salts."
        https://www.theregister.com/cyber-crime/2026/09/03/cybercrooks-trawl-fishbrain-to-net-password-hashes/5294158
      • Attackers Breached JetBrains Cadence Via Unpatched TeamCity, Extracting AWS Credentials
        "JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said. "They should also treat all executions, including their inputs and outputs in your Cadence project, as potentially untrusted.""
        https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html
      • Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
        "Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets."
        https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html

      General News

      • Why Judgment Is Emerging As Cybersecurity’s Defining Skill
        "AI is getting better at much of what security teams have long spent time on: analyzing information, identifying patterns, and providing technically sound recommendations quickly. As those capabilities become more routine, they are changing what security practitioners spend their time on. Reaching a technically sound recommendation is also getting easier, which puts more weight on the judgment about what to do with it. A recommendation can make complete sense from a security perspective and still carry consequences for the systems, people and business around it that change what the right decision is."
        https://cyberscoop.com/ai-security-operations-human-context-ciso-op-ed/
      • Insurers Search For Answers To Rein In Rogue AI
        "When Maria Long heard about OpenAI's rogue model attacking AI-model service provider Hugging Face, her first stop was to review her firm's technology errors and omissions (Tech E&O) policy. As the chief underwriting officer for cybersecurity insurance services firm Resilience, she understood that rogue AI agents causing inadvertent compromises could result in significant losses to insurers in the future. This incident showed that the future wasn't that far off. For Hugging Face, the incident would almost certainly be covered by cyber-liability insurance as a classic security breach. However, if AI agents routinely escape containment, insurers have to consider that the volume of policy claims could grow."
        https://www.darkreading.com/cyber-risk/insurers-search-answers-rogue-ai
      • What The AI Warning Letter Completely Missed
        "Recently, more than 100 technology companies — OpenAI, Anthropic, Microsoft, and Google among them — published an open letter warning that AI is about to make sophisticated cyberattacks far cheaper and far more common, and that "we have a limited window to strengthen cyber defenses." I read it twice. The first time as the head of a security organization, nodding along to very nearly every line. The second time hunting for the part about who actually does the work. I did not find it."
        https://www.darkreading.com/cyberattacks-data-breaches/ai-warning-letter-missed-people
      • Companies Have 6 Months To Prepare For Automated Attacks
        "With multiple benchmarks confirming that at least one frontier model can autonomously execute an end-to-end compromise, cybersecurity experts are warning that companies have to pick up the pace in securing their attack surfaces and adopting AI-speed defenses. On Sept. 2, consulting firm Booz Allen became the latest organization to confirm that a frontier model — Anthropic's Mythos 5 — can act as a fully autonomous hacker and compromise a production-grade enterprise network. The company also released a metric, dubbed the Cyber Weapon Index (CWI), to benchmark a model's capabilities, pairing the ability to find and exploit vulnerabilities with the ability to execute and attack a target."
        https://www.darkreading.com/cybersecurity-operations/companies-six-months-prepare-automated-attacks
      • AI Is Ending The Era Of Hidden Vulnerabilities — Are Vendors Ready?
        "Vulnerabilities are running out of places to hide, thanks to frontier AI models, and it could create problems for those that sell software. The "vulnpocalypse," or the onslaught of vulnerabilities surfaced through the proliferation of AI, is having far-reaching consequences on the economics and demands previously associated with bug hunting. Software publishers are used to operating in a world where code reviews, researcher attention, and discovery capacity are finite. But over the past two years, things have changed. Large language models (LLMs) have automated and sped up large portions of the bug discovery pipeline, and frontier models could accelerate that process even further."
        https://www.darkreading.com/vulnerabilities-threats/ai-ending-era-hidden-vulnerabilities-are-vendors-ready
      • US Offers $10 Million For Info On Iranian Allegedly Behind Cyberattacks On Critical Infrastructure
        "A $10 million reward has been posted by the State Department for information on the whereabouts of senior Iranian official Amir Yaryab. Yaryab allegedly leads the Islamic Revolutionary Guard Corps’ (IRGC) Cyber-Electronic Command (CEC). U.S. officials accused Yaryab of directing multiple Iranian hacking groups that have targeted “critical infrastructure sectors including defense, news, shipping, travel (hotels and airlines), energy, and financial and telecommunications systems in the United States, Europe, and the Middle East.”"
        https://therecord.media/us-reward-amir-yaryab-iran-irgc-cyberattacks
      • H1 2026 Malware And Vulnerability Trends
        "H1 2026 activity showed a continued adversary preference for abusing legitimate tools, trusted platforms, and routine workflows already present in enterprise and consumer environments. Threat actors used exposed software, developer tools, remote access utilities, payment workflows, and third-party services to gain access, steal credentials, move laterally, and monetize intrusions while blending into expected activity. This emphasis on evasion through normalcy rather than technical novelty increases the risk that malicious activity will progress through approved tools and trusted services before defenders recognize it, reinforcing the need for stronger exposure management, identity and credential governance, behavioral detection, developer-environment security, backup resilience, mobile fraud monitoring, and third-party oversight."
        https://www.recordedfuture.com/research/h1-2026-malware-vulnerability-trends
        https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0903.pdf

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) a0344717-380a-49ff-969f-52d35634883f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 04 September 2026

      Vulnerabilities

      • HPE Patches Critical ArubaOS-CX Remote Code Execution Flaw
        "Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. Tracked as CVE-2026-73749, the security issue is a buffer overflow that allows unauthenticated remote attackers to send specially crafted packets to an affected daemon process, achieving code execution with elevated privileges. “Multiple vulnerabilities exist in a daemon of ArubaOS-CX that may allow for improper processing of malformed input,” reads HPE’s bulletin."
        https://www.bleepingcomputer.com/news/security/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw/
      • Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code As Root
        "Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is a case of binding to an unrestricted IP address that leaves TCP ports 43210 and 43211 reachable in the default Layer 3 virtual routing and forwarding (VRF) instance."
        https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html
        https://www.securityweek.com/cisco-warns-of-unpatched-secure-email-flaws-patches-critical-switch-vulnerabilities/
        https://securityaffairs.com/198366/security/cisco-fixed-critical-rce-in-nexus-9000-series-switches.html
      • Plex Warns Users To Patch Security Vulnerabilities Immediately
        "Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. These flaws have not yet been assigned CVE IDs for easy tracking, and while Plex didn't provide additional details on Tuesday, the security issues are known to affect Plex Media Server v1.43.2 and earlier. Plex also emailed users running affected versions and asked them to update as soon as possible to address these security flaws."
        https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/
      • VMSA-2026-0007: VMware Workstation And Fusion Updates Address Integer-Overflow And Buffer Overflow Vulnerabilities (CVE-2026-59346, CVE-2026-59347)
        "An integer-overflow and a buffer-overflow vulnerabilities in VMware Workstation and Fusion were privately reported to Broadcom. Updates are available to remediate these vulnerabilities in affected Broadcom products."
        https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38288
      • Attackers Actively Exploiting Critical Vulnerability In Elementor Pro Plugin
        "On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more than 6,000,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site takeover. The vendor released the fully patched version on August 19th, 2026, and we originally disclosed this vulnerability in the Wordfence Intelligence vulnerability database on the same day. The Wordfence Firewall has already blocked over 190,000 exploit attempts targeting this vulnerability."
        https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-elementor-pro-plugin/
        https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploited-to-take-over-wordpress-sites/

      Malware

      • Coder's Registry Infrastructure Compromised To Push Malicious Modules
        "Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. The Coder platform enables organizations to provide developers with secure, self-hosted cloud development environments for building and deploying software, including AI applications. The project is used by prominent private and government organizations, including Dropbox, Palantir, Square, Mercedes-Benz, KKR, EnBW, the U.S. government, and defense companies."
        https://www.bleepingcomputer.com/news/security/coders-registry-infrastructure-compromised-to-push-malicious-modules/
      • The NDA Was The Payload: Inside Phantom Deal, a Fake Acquisition Fraud Campaign
        "It started with an innocent WhatsApp message. “Hi David, I hope you are well. Are you at the office?” The sender claimed to be a real Gen executive based in Dublin. The profile used his name, photograph and an Irish telephone number. Nothing in the opening message mentioned money, urgency or an acquisition. It was simply designed to establish whether the recipient was available and willing to respond. The recipient, whom we will call David, worked in Gen’s legal team and knew the colleague being impersonated. The unfamiliar telephone number raised suspicion, and the first phone conversation confirmed it: the caller’s voice did not match."
        https://www.gendigital.com/blog/insights/research/phantom-deal
        https://www.darkreading.com/cyberattacks-data-breaches/large-enterprises-fake-merger-acquisition-scams
      • Someone Else Is Using Your AI
        "Generative AI is quickly becoming one of the more lucrative uses for stolen cloud credentials. Attackers no longer need to set up crypto miners or exfiltrate data to cash in on a leaked IAM key. They can instead subscribe to foundation models through AWS Marketplace and resell inference access, a technique called LLMjacking, first documented in 2024. FortiCNAPP recently investigated a case that shows how fast and mechanical that pivot has become. FortiGuard Labs recently analyzed a long-lived AWS IAM access key with administrator privileges that was used to create a new IAM identity, subscribe it to foundation models on AWS Marketplace, and begin invoking them."
        https://www.fortinet.com/blog/threat-research/someone-else-is-using-your-ai
      • The Outsider Phishing Kit: A Resilient Threat In The Face Of Law Enforcement Action
        "During an investigation into phishing kits sold, Group-IB researchers uncovered the “Outsider Phishing Kit” (局外人), a sophisticated Phishing-as-a-Service (PaaS) platform operated by the threat actor known as “ChenLun.” The kit incorporates Adversary-in-the-Middle (AiTM) capabilities, enabling attackers to intercept authentication flows and bypass multi-factor authentication (MFA). The scale of this operation is staggering. From December 2025 to May 2026, Group-IB has identified over 100,000 phishing pages targeting 54+ countries, leveraging 267 (and growing) phishing templates. These numbers underscore the increasingly low barrier to entry for threat actors to launch and operate large-scale phishing campaigns."
        https://www.group-ib.com/blog/chenlun-outsider-phaas-kit/
        https://www.infosecurity-magazine.com/news/outsider-phishing-kit-survives/
      • Attackers Expose Ongoing AI Tool Use Targeting Organizations In Latin America
        "We have analyzed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America. Corroborating recent findings from the broader threat intelligence community, we observed attackers leveraging artificial intelligence (AI) to enhance their capabilities."
        https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/
      • US Becomes Top Target In RMM Phishing Campaign Spanning 46 Countries
        "An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses fake documents to trick victims into installing legitimate remote monitoring and management (RMM) software. The attackers adapt their lures to different targets, using shipping and UPS communications, Adobe PDFs, tax notices, US Social Security Administration themes, invoices, and other documents. Rapidly rotated, disposable Vercel infrastructure makes the campaign harder to track and detect."
        https://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.html
      • Node.js: Old Technique Makes a Comeback
        "Between March and July 2026, attackers who compromised a technology start-up in Asia ran into a problem: almost every payload they attempted to deploy, including AdaptixC2 agents and Cobalt Strike Beacon, was blocked on the victim's network. Their response was to download the official Node.js installer from nodejs.org and use the trusted, signed runtime to execute a malicious implant. The implant maintained its foothold for months and made repeated connections to Ethereum blockchain gateways, most likely to retrieve commands or additional payloads hidden in a blockchain smart contract, a technique known as EtherHiding."
        https://www.security.com/threat-intelligence/node-js-returns-ransomware
        https://thehackernews.com/2026/09/attackers-turn-trusted-nodejs-runtime.html
      • Shai-Hulud's Reach Just Grew To 469 Credential Locations. Here's What That Means
        "In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs. Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have stopped trying to break trust relationships and started using the credentials that already make those relationships work. Software supply chains have always depended on trust."
        https://thehackernews.com/2026/09/shai-huluds-reach-just-grew-to-469.html
      • Researcher Releases FalconFlank PoC Showing Privilege Escalation In CrowdStrike Falcon
        "The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in a GitHub README file, adding the cybersecurity company may already have detections for the flaw by now. "So if you want to test, you either have to add it to the exclusions or obfuscate the PoC and change the DLL load technique.""
        https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html
        https://securityaffairs.com/198342/hacking/chaotic-eclipse-releases-crowdstrike-falcon-zeroday-falconflank.html
      • Impersonating IT Support: How Threat Actors Turn a Remote Session Into Enterprise-Wide Access
        "Microsoft Threat Intelligence has observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into granting an interactive remote session. Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node.js runtime and an obfuscated JavaScript implant that provides persistent command execution and command and control (C2)."
        https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/

      Breaches/Hacks/Leaks

      • US And Canadian Court Data Exposed In Thomson Reuters Breach
        "Sealed court information and sensitive personal data were exposed in a breach of a Thomson Reuters records platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands and Canada, the company publicly disclosed Wednesday. Thomson Reuters has not said how the attacker gained access, who was responsible or how much data was taken. The number of people affected also remains unclear. The company stressed the breach occurred within its environment and was not caused by the networks, systems or data security of the affected courts."
        https://therecord.media/thomson-reuters-cyberattack-data
        https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html
        https://www.infosecurity-magazine.com/news/us-canada-court-breach-thomson/
        https://www.helpnetsecurity.com/2026/09/03/thomson-reuters-reveals-breach-that-exposed-u-s-and-canadian-court-records/
      • Manchester Airports Group Data On 8.8 Million People Leaked After Ransom Refusal
        "Data allegedly stolen from the Manchester Airports Group (MAG) and leaked online this week includes the email addresses and phone numbers of 8.8 million people. MAG disclosed the incident last week, warning that hackers had breached its systems, stealing car park, lounge, and Fast Track booking data, along with in-airport Wi-Fi sign-ups at the Manchester, London Stansted, and East Midlands airports. The airport operator disclosed that hackers had exfiltrated email addresses, phone numbers, vehicle registrations, and postcodes, noting that its operations were not affected by the incident."
        https://www.securityweek.com/manchester-airports-group-data-on-8-8-million-people-leaked-after-ransom-refusal/
      • 412,000 The Town 2025 Ticket Buyers’ Data Hits The Dark Web
        "A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, claiming over 412,000 Latin American purchase records with a heavy concentration of Brazilian data. Ransomnews’s analysis confirms the sample is genuine ticket-buyer data from The Town 2025, the São Paulo music festival, though who actually lost the data and how remains unconfirmed. “The listing is headed “SELLING NEW TICKETMASTER DATABASE” and describes a global ticketing platform, Latin America region, with an internal ticketing database as the source and a breach date of 28 August 2026."
        https://securityaffairs.com/198354/data-breach/412000-the-town-2025-ticket-buyers-data-hits-the-dark-web.html
      • Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline
        "Recently leaked records show that Bauman Moscow State Technical University’s Department No. 4 operated as a long-term training pipeline for Russian military intelligence and cyber operations. The department served several elements of the Russian General Staff and trained roughly 250 career and reserve students across three specialties: special intelligence (“Служба специальной разведки”), operational information-technical effects (“Применение сил и средств информационно-технического воздействия и защиты от информационно-технического воздействия”), and information-technology protection (”3ащита информационных технологий”). The curriculum combined both offensive and defensive techniques for cyber defense, as well as offensive doctrine for active measures campaigns and GRU activities. Field placements then moved students from classroom instruction into military units and academies aligned with their specialties, giving them supervised exposure to intelligence operations and preparing them for military and government operations careers."
        https://dti.domaintools.com/research/threat-intelligence-report-university-leak-exposes-russias-military-cyber-training-pipeline
        https://securityaffairs.com/198332/intelligence/2000-leaked-documents-reveal-how-russia-turns-engineering-students-into-gru-cyber-operators.html

      General News

      • G7 Says Migrating To PQC Early Is Cheaper Than Later
        "An international public-private cyber alliance is making a call to action on transitioning to post-quantum cryptography and offers strategies to lower the cost of the strenuous effort. The G7 Cybersecurity Working Group of government agencies and banks from seven economically advanced countries along with the European Union outlined many risks that can happen after quantum computers break classic encryption and told every country to consider PQC as a "foreseeable evolution of cryptographic best practices" that cannot be avoided."
        https://www.bankinfosecurity.com/g7-says-migrating-to-pqc-early-cheaper-than-later-a-32738
        https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/asset_files/external/g7preparingfortheqostquantumeraacalltoaction.pdf
        https://cyberscoop.com/g7-quantum-computing-encryption-warning/
      • Crypto Agility: Why PQC Is Not a One-Time Upgrade
        "Crypto agility is the ability to update cryptographic algorithms, protocols, libraries, and implementations while minimizing disruption and avoiding unnecessary replacement of the underlying infrastructure. For networks, that means adopting post-quantum cryptography (PQC) while preserving the ability to accommodate future standards and defenses primarily through software. This capability matters because networking platforms often take years to develop and may remain deployed for a decade or longer."
        https://blogs.cisco.com/security/crypto-agility-why-pqc-is-not-a-one-time-upgrade
      • Supply Chain Attacks In 2026: Why Threat Intelligence Is The Only Early Warning System That Works
        "Supply chain attacks in 2026 are no longer an edge-case risk buried in a vendor questionnaire — they are a primary breach vector that regulators, incident responders, and CISOs now treat as a first-order threat. Verizon’s 2026 Data Breach Investigations Report found third-party involvement in 48% of breaches, up 60% year over year, following the 2025 edition, which already recorded a jump from 15% to 30%. Every vendor integration, every open-source dependency, and every managed file transfer tool expands the attack surface that an organization does not directly control. That is the core problem with supply chain security today: the weakest link is rarely the enterprise itself."
        https://cyble.com/blog/supply-chain-attacks-in-2026-vendor-risk/
      • Your AI Agent’s System Prompt Is Not a Security Control
        "An AI agent told in its system prompt to show a user only what that user is cleared to see will hand over more the moment someone talks it into doing so. Gee Rittenhouse, who oversees Security Hub, GuardDuty, and Inspector at AWS, and Eric Johnson, a fellow at the SANS Institute, put the fix one layer down: scope the query to the user’s permissions at retrieval time, inside the role-based or attribute-based access system the company already runs, and filter the results before they reach the model’s context window."
        https://www.helpnetsecurity.com/2026/09/03/sans-aws-agentic-ai-security/
      • Your Threat Feed Is Someone Else’s Database: What Ingesting Malware Intel At Scale Takes
        "The advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is the operating manual, because the access was never the hard part. A threat feed is someone else’s database. Someone else’s processes built it, someone else’s judgement calls shaped it, and someone else’s bad Tuesday is sitting it right now, waiting for the automation to act on it. I lead the team that runs Dependabot at GitHub, which monitors more than 30 million repositories for vulnerable and malicious dependencies as of 2026. This year we extended malicious-package advisories from npm, where we had been flagging malware since March, to eight package ecosystems, by ingesting community intelligence from OpenSSF’s malicious-packages repository."
        https://www.helpnetsecurity.com/2026/09/03/github-threat-intelligence-feed-ingestion/
      • When AI Quietly Breaks Things, Who Pays?
        "David Halbreich, an insurance recovery partner at Reed Smith, breaks down how AI companies should handle coverage gaps that come up as the industry grows. He covers straddle claims that fall between tail and go-forward D&O policies after a merger, how governance disclosures in applications can turn into warranties an insurer uses to deny a claim, who should sign off on AI use questions, when the claim clock starts for slow-building model degradation, and how business interruption coverage applies to outages at cloud and compute vendors."
        https://www.helpnetsecurity.com/2026/09/03/david-halbreich-reed-smith-ai-insurance-coverage-gaps/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) e52ccc9b-7672-4b70-bd36-017039b11b7b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการโจมตีช่องโหว่ StyleSmuggler ใน Magento และ Adobe Commerce เสี่ยงรันโค้ดและฝัง Backdoor

      พบการโจมตีช่องโหว่ StyleSmuggler ใน Magento และ Adobe Commerce เสี.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5e803fd4-d4bc-42eb-8884-fac403ec6c4a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Broadcom ออกแพตช์แก้ช่องโหว่ VM Escape ระดับ Critical ใน VMware Workstation และ Fusion

      Broadcom ออกแพตช์แก้ช่องโหว่ VM Escape ระดับ Critical ใน VMware Wor.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 59e809e5-7e23-4bc9-8934-c224cd4aed7f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ตรวจพบการโจมตีผ่านช่องโหว่บนอุปกรณ์ MikroTik ควบคุมระบบได้โดยไม่ต้องยืนยันตัวตน

      ตรวจพบการโจมตีผ่านช่องโหว่บนอุปกรณ์ MikroTik ค.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 6242a404-46a1-488f-8919-31097a6e4b1c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ใน All-in-One WP Migration and Backup เสี่ยงรันโค้ดบนเว็บไซต์ WordPress

      ช่องโหว่ใน All-in-One WP Migration and Backup เสี่ยงรันโค้ดบนเว.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 2347a33f-e4f2-4386-a95c-5e5072d4bbe4-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • SonicWall ออกแพตช์แก้ 2 ช่องโหว่ Zero-Day ใน SMA 1000 VPN หลังพบถูกใช้โจมตี

      SonicWall ออกแพตช์แก้ 2 ช่องโหว่ Zero-Day ใน SMA 1000 VPN หลังพบ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand dd35ab0a-1bbe-4e84-945d-f20709927067-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • เตรียมรับมือ OpenAI ยืนยันแล้ว AI โมเดล Astra สามารถค้นหาช่องโหว่ Zero-day และสร้างโค้ดโจมตีได้โดยอัตโนมัติ

      เตรียมรับมือ OpenAI ยืนยันแล้ว AI โมเดล Astra สามารถ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 1a7058cd-8c11-4531-825b-7edebc36cbc9-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 7 รายการลงในแคตตาล็อก

      เมื่อวันที่ 2 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 7 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability
      • CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability
      • CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability
      • CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability
      • CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability
      • CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
      • CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 3c91a749-877e-4e48-8f87-4ccbaa8c6acb-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT