NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,589
    • กระทู้ 2,590
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    NCSA_THAICERT

    @NCSA_THAICERT

    1
    ชื่อเสียง
    58
    ดูข้อมูลส่วนตัว
    2.6k
    กระทู้
    3
    คนติดตาม
    0
    ติดตาม
    เข้าร่วม ออนไลน์ล่าสุด
    เว็บไซต์ www.ncsa.or.th/?fbclid=IwAR0BqJEC-CJzBs98rlBxUbZkNBgp1g814xdDNNaKnHTrxfqZhPD--ksY68I

    NCSA_THAICERT เลิกติดตาม ติดตาม
    Global Moderator administrators

    Latest posts made by NCSA_THAICERT

    • ISC แก้ไขช่องโหว่ใน BIND 9 เสี่ยงกระทบการให้บริการและความถูกต้องของข้อมูล DNS

      ISC แก้ไขช่องโหว่ใน BIND 9 เสี่ยงกระทบการให้บริ.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand b0387b1f-3c09-49f7-91d6-68216db2904c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • FBI ยึดโดเมน NightmareStresser บริการ DDoS-for-Hire ภายใต้ปฏิบัติการ Operation PowerOFF

      FBI ยึดโดเมน NightmareStresser บริการ DDoS-for-Hire ภายใต้ปฏิบัติ.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 79a284a0-d1c8-4bf6-aae1-9a0721a0527b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบมัลแวร์ BambooToken อาศัยโปรโตคอล MQTT ควบคุมระบบ Windows และ Linux เพื่อหลบเลี่ยงการตรวจจับ

      พบมัลแวร์ BambooToken อาศัยโปรโตคอล MQTT ควบคุมระบบ Win.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 32f05b58-1f2f-4d28-9961-ac7a1dfedc42-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 18 September 2026

      Industrial Sector

      • Hitachi Energy FACTS Control Platform (FCP)
        "Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems with GWS component deployed from year 2020 onwards are likely affected by the above vulnerabilities. Product deployments without GWS component are not affected. • SVC Light (STATCOM) • Fixed Series Capacitor • Thyristor Controlled Series Capacitor • Static Var Compensator • Static Watt Compensator • Hybrid Synchronous Condensers Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The affected FCP versions are only applicable if GWS component is present."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-03
      • Mitsubishi Electric GX Works3 And Motion Control Settings
        "Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-02
      • Bransys ELD
        "Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-01
      • Schneider Electric Modicon M340 Controller And Communication Modules
        "Schneider Electric is aware of a vulnerability in its Modicon M340"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-04
      • Schneider Electric NetBotz 5 750/755
        "Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-05
      • ABB Ability Edgenius
        "ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-06
      • Schneider Electric PowerChute Serial Shutdown
        "Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-07
      • Ransomware Attacks On Manufacturers Surge As Supply Chain Risk Grows
        "Manufacturing remains a primary target for ransomware, possibly due to the long tail of effects. Incidents this year are 40% up on the same period last year. Throughout September 2025, Jaguar Land Rover shut down its UK plants because of an attack and halted the daily production of around 1,000 luxury vehicles. More than 5,000 other companies were affected by the shutdown, and the Bank of England suggested it was a contributory factor in a slowdown in national growth figures. The longer-term repercussions are still being felt: Jaguar Land Rover has said it will cut 4,000 jobs, blaming the cyberattack."
        https://www.securityweek.com/ransomware-attacks-on-manufacturers-surge-as-supply-chain-risk-grows/
        https://blackkite.com/reports/2026-manufacturing-distribution

      Vulnerabilities

      • Cisco Warns Of Max Severity ISE Zero-Day Exploited In Attacks
        "Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. Cisco ISE is a centralized policy platform that IT administrators use to manage endpoints, users, and device access to network resources, often while enforcing Zero Trust security models. The security flaw (tracked as CVE-2026-76460) lets remote attackers bypass authentication by exploiting a weakness in an API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of configuration."
        https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/
        https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
        https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html
        https://cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/
        https://www.infosecurity-magazine.com/news/cisco-active-exploitation-critical/
        https://www.theregister.com/security/2026/09/17/cisco-drops-another-exploited-zero-day-this-time-a-perfect-10/5297180
        https://www.securityweek.com/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day/
        https://www.helpnetsecurity.com/2026/09/17/cisco-ise-vulnerability-exploited-cve-2026-76460/
      • Critical Unbound DNSSEC Validator Flaw Could Allow RCE Via a Malicious DNS Zone
        "Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, along with eight other flaws. One of the eight, CVE-2026-82717, is a heap corruption bug in CNAME synthesis reported by Ben Morris of Anthropic. It could also lead to remote code execution "under certain systems and compilation options," NLnet Labs said."
        https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html
      • Cisco Fixes Dozens Of Flaws Across FMC, ISE And Nexus Dashboard
        "Cisco on Wednesday announced patches for dozens of critical-severity CVEs in Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard. The ISE security updates stand out with patches for 20 CVEs, including 12 critical-severity flaws. Three of the issues have already been publicly disclosed, Cisco warned. Tracked as CVE-2026-20282, CVE-2026-20283, and CVE-2026-20284, they can be exploited by remote attackers for SQL injection, data tampering, and arbitrary command execution. Administrative access is required for all three."
        https://www.securityweek.com/cisco-fixes-dozens-of-flaws-across-fmc-ise-and-nexus-dashboard/
      • BIND 9 Update Fixes 14 Flaws, Including An Unauthenticated Crash Over DNS-Over-HTTPS
        "The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH). A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG(0) signature, if the sender closes the connection before named finishes checking the signature. ISC said in its advisories that it is not aware of any of the fourteen being exploited."
        https://thehackernews.com/2026/09/bind-9-update-fixes-14-flaws-including.html
        https://www.securityweek.com/isc-patches-14-vulnerabilities-in-bind-9-security-update/
      • Plugin4Shell - Zero Click RCE Vulnerability Found In Top 4 Most Popular Coding Agents, Millions Of Agents Affected
        "Plugin4Shell is a zero-click, high-severity RCE affecting all four major AI coding agents - Claude Code, Codex, Copilot, and Gemini. In this first-of-its-kind AI supply-chain attack, a trusted plugin is silently swapped for a malicious one and auto-installed past the agent's SHA pinning - a flaw no marketplace can fix, so users must update their agent."
        https://www.air.security/blog-posts/plugin4shell
        https://www.theregister.com/security/2026/09/17/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/5297335

      Malware

      • RatHat: AI-Powered Mobile Threat Is Here For Your Credentials & Bank Accounts
        "The zLabs team has uncovered RatHat, a novel Android malware strain linked to threat actors that appear to be operating in China. RatHat incorporates novel techniques for persistence and leverage generative AI for operational control. Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses an automated multi-stage infection pipeline. Once deployed, it pairs Accessibility abuse with autonomous local ADB (Android Debug Bridge) self-pairing to break out of the standard Android application sandbox, staging independent native daemons that execute with shell-level privileges."
        https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
        https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/
        https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/
      • Brevo Supply-Chain Attack Injected ClickFix Scripts On Customer Sites
        "Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. The customer relationship management and digital marketing company says the attackers used the API key to create a malicious Cloudflare Worker that modified content at the CDN edge for approximately five and a half hours on September 14. The attack affected pages on brevo.com, sendinblue.com, login/account/my/onboarding.brevo.com, and sibforms.com. The Cloudflare worker also modified the Brevo forms script, Brevo Conversations widget, and the Brevo SDK loader scripts that customers embed on their websites."
        https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/
      • Beware The SparroWock: The Backdoor That Bites, The Commands That Catch
        "ESET Research’s ongoing monitoring of FamousSparrow has borne fruit once again. Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025."
        https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/
        https://www.bleepingcomputer.com/news/security/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks/
        https://thehackernews.com/2026/09/china-aligned-famoussparrow-deploys.html
        https://www.darkreading.com/cyberattacks-data-breaches/china-famoussparrow-spies-latin-america
        https://therecord.media/china-hackers-latin-america-espionage
        https://www.infosecurity-magazine.com/news/famoussparrow-sparrowocky-latin/
        https://www.theregister.com/security/2026/09/17/chinas-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware/5297286
      • Chatbot Conundrum: Phishing Attempts Of OpenAI’s ChatGPT
        "As generative AI tools like OpenAI’s ChatGPT become increasingly common, their large user bases create new opportunities for threat actors. ChatGPT offers subscription-based access to additional features, providing attackers with a familiar payment process to impersonate. By sending fake notifications claiming that a user’s payment method needs to be updated, threat actors can turn a routine billing request into a phishing lure designed to steal credentials and payment information."
        https://cofense.com/blog/chatbot-conundrum-phishing-attempts-of-openai-s-chatgpt
      • HEAVYGRAM: A Telegram-Based Surveillance Backdoor Linked To Handala Hack
        "Group-IB Threat Intelligence has uncovered previously undocumented samples of the HEAVYGRAM and CRUDEEXCLUDE malware families. These findings build upon public disclosures of HEAVYGRAM from the U.S. Department of Justice regarding the seizure of infrastructure linked to Iran’s Ministry of Intelligence and Security (MOIS), as well as associated indicators and technical descriptions from a recent U.S. Federal Bureau of Investigation (FBI) FLASH report."
        https://www.group-ib.com/blog/heavygram-handala-hack-telegram-c2/
      • The Odyssey And Trojans Again: MovieReaper Attacks Users In Multiple Countries Via Compromised Torrents
        "Torrent trackers have long been abused for distributing malicious software, disguised as popular films, games, and other content. Our previous research has shown that cybercriminals repeatedly turn torrents as an initial infection vector, using trojanized cracks and installers to reach a large number of users. Installation guides for pirated software routinely instruct users to disable their antivirus, conditioning them to ignore potential threats they are inviting onto their computers."
        https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/
      • SilkParasite Infrastructure: SpiceRAT Servers Tied To Energy And Government Targets Across Central Asia
        "This research was carried out jointly with researcher Guy Yasur. Together, we tracked a cluster of SpiceRAT command and control servers active from late 2025 through August 2026 across a small subset of European hosting providers. A TLS certificate issued by a Chinese state-affiliated certificate authority associated with the infrastructure impersonates Uzbekistan's state railway authority. Additionally, this cluster also shares registration-level relationships with hosts Bitdefender attributed to three separate malware families in its August 19, 2026 SilkParasite report. Detection logic built from Cisco Talos' 2024 SpiceRAT research first flagged these servers in late 2025, and in mid-March 2026, we noticed a small group of C2's coming online within days of each other. This analysis relies on internet-wide scan data, and does not address malware behavior, delivery, or initial access."
        https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure
        https://securityaffairs.com/199267/apt/silkparasite-infrastructure-links-spicerat-to-central-asian-targets.html
      • Flock Cameras Are Tracking People As Well As Cars
        "Flock Safety’s cameras are automated license plate readers (ALPRs) designed to help police find stolen cars or wanted suspects. A joint investigation by 404 Media and WIRED, based on data recovered from a physically removed Flock camera, found that its on-device software explicitly detects people as well as vehicles, bicycles, and license plates. Separately, Washington DC’s police union says the Metropolitan Police Department used Flock data to track officers under Internal Affairs investigation without their knowledge."
        https://www.malwarebytes.com/blog/privacy/2026/09/flock-cameras-are-tracking-people-as-well-as-cars

      Breaches/Hacks/Leaks

      • Gyazo Breach Exposes 23.62 Million User Records And 490 Million Image Metadata Records
        "A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up Gyazo image links. Helpfeel said those IDs could be used to view the images without permission, and that it has temporarily disabled viewing of some of them."
        https://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html
      • Hackers Claim Breach Of Russian Election Systems Days Before Parliamentary Vote
        "An anonymous hacking group claimed to have broken into computer systems connected to Russia’s election infrastructure just days before the country begins voting for a new parliament. The group, calling itself CikLeak, said it gained access to systems belonging to Russia’s Central Election Commission and companies involved in developing Vybory, the state-run platform used to administer elections. The hackers claimed to have stolen internal documents, server configurations, passwords and employee communications from the commission and its contractors, including Russian telecom giant Rostelecom."
        https://therecord.media/russia-election-hackers-breach
      • London Property Manager Breach May Have Exposed Bank Details And Lockbox Codes
        "London property management biz City Relay has warned customers that intruders may have stolen financial data, passwords, and codes used to access keys after compromising its Metabase Cloud instance. City Relay, marketing itself as "London's most trusted property management company," told landlords via email - seen by The Reg - that attackers accessed the third-party provided cloud twice "as a result of a vulnerability in the platform that we were unaware of." The message to customers stated: "Personal data was extracted from the platform.""
        https://www.theregister.com/security/2026/09/17/london-property-manager-breach-may-have-exposed-bank-details-and-lockbox-codes/5297232
      • Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
        "Hackers are demanding a $3 million ransom from the British fintech giant Revolut after siphoning data from it through fake government requests for five months. Last week, the company notified potentially affected users that their personal information, passports, email addresses, phone numbers, and financial information were compromised in the data breach. To obtain the information, the hackers posed as an official government agency. Because Revolut is required to respond to legal requests from law enforcement, it complied."
        https://www.securityweek.com/revolut-data-breach-5-months-680-high-profile-accounts-3m-ransom/
        https://www.malwarebytes.com/blog/threat-intel/2026/09/revolut-phishing-texts-appear-days-after-data-breach

      General News

      • Our Framework For Reporting Model Misalignment
        "We are sharing a new framework for tracking, investigating, and disclosing instances of model misalignment at OpenAI, along with six reports on unexpected or concerning model behavior we’ve observed in the last six months. In the past, so as to better inform researchers, AI developers, policymakers, and the general public, we’ve sought to make our findings about misalignment public. But without a systematic approach to reporting these findings, our disclosures have been ad hoc and less frequent than ideal: we’ve often waited until we could collate several instances into one report, or added them to system cards for newly released models."
        https://openai.com/index/model-misalignment-reporting-framework/
        https://www.bleepingcomputer.com/news/security/openai-details-more-cases-of-ai-agents-taking-unauthorized-actions/
        https://thehackernews.com/2026/09/openai-reveals-six-model-incidents.html
        https://www.bankinfosecurity.com/openai-finds-models-writing-their-own-rogue-instructions-a-32862
        https://www.securityweek.com/openai-says-its-models-hunted-github-for-leaked-api-keys-during-training/
        https://securityaffairs.com/199302/ai/openai-admits-its-models-lie-to-cover-their-own-mistakes.html
      • FBI Seizes DDoS-For-Hire Domains As Part Of Continuing District Of Alaska Crackdown On ‘Booter’ And ‘Stresser’ DDoS Services
        "The Justice Department today announced the court-authorized seizure of internet domains associated with one of the world’s longest running Distributed Denial of Service (DDoS) for-hire services known as “NightmareStresser.” Federal law enforcement has seized websites maintained by criminal service providers that allow paying customers to launch powerful DDoS attacks targeting victims in the District of Alaska and worldwide as part of coordinated actions to disrupt so called “Booter” or “Stresser” operators."
        https://www.justice.gov/usao-ak/pr/fbi-seizes-ddos-hire-domains-part-continuing-district-alaska-crackdown-booter-and
        https://thehackernews.com/2026/09/us-seizes-nightmarestresser-domains.html
        https://www.bleepingcomputer.com/news/security/fbi-seizes-nightmarestresser-service-linked-to-thousands-of-ddos-attacks/
        https://cyberscoop.com/fbi-seizes-nightmarestresser-ddos-for-hire-domains/
        https://securityaffairs.com/199251/cyber-crime/nightmarestresser-goes-offline-in-global-ddos-for-hire-crackdown.html
        https://www.helpnetsecurity.com/2026/09/17/fbi-nightmarestresser-ddos-for-hire-service-seized/
      • AI Models Broke Their Own Containment: Key Findings From The July-August 2026 AI Threat Landscape
        "Between mid-July and early August 2026, models being evaluated internally by OpenAI, Anthropic, and Meta reached real production systems outside their test environments. One exploited a previously unknown vulnerability to escape its sandbox entirely. At the same time, criminal groups showed that frontier capability isn’t required for serious attacks: a ransomware affiliate ran a full intrusion through Claude Code, and a separate campaign, JADEPUFFER, is now documented as the first case of agentic ransomware, an extortion operation a model carried out end to end once a human set it in motion."
        https://blog.checkpoint.com/artificial-intelligence/ai-models-broke-their-own-containment-key-findings-from-the-july-august-2026-ai-threat-landscape/
      • Ransomware Incidents In Japan In The First Half Of 2026: Investigation Of The Gentlemen’s Infrastructure And Evidence Of Qilin's AI Use
        "Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat. In Japan, The Gentlemen was the most active ransomware group in the first half of 2026. Attackers continue to primarily target small- and medium-sized enterprises, with organizations capitalized at less than JPY 1 billion accounting for approximately 80% of the total — an increase of around 13% from the previous year."
        https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/
      • The AI Hacking Apocalypse Is Not Inevitable
        "The past few weeks have “felt very strange” for Juan Andres Guerrero-Saade. Like many, he is trying to sort through the spate of frontier-model AI agents from OpenAI, Anthropic, Meta and others hacking their way onto the open internet over the past few months, particularly amid the already-heated national debate around the emerging technology and its impact on society."
        https://cyberscoop.com/ai-agent-hacking-apocalypse-cybersecurity/
      • Fake AI Trading Agent Steals Crypto Wallet Passwords
        "Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim’s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between April and June 2026. The Needle campaign targets people who download AI agents from search results or ads, and users of seven browser wallet extensions, among them MetaMask, Coinbase Wallet and Phantom. HP also caught QR code phishing that moves victims onto their phones."
        https://www.helpnetsecurity.com/2026/09/17/fake-ai-trading-agent-research/
      • The AI Security Question Leaders Should Be Asking Instead
        "In this Help Net Security interview, Frederic Bull, Security Officer at Gremlin, talks about what AI means for security teams. The conversation covers why asking what data a model was trained on is only part of the picture, and why least privilege and access controls still matter for AI agents. It also looks at how AI has narrowed the skill gap between attackers and defenders, how the team handled about nine times as many vulnerabilities with the same staff, and why hiring now favors people with the experience to catch confident but wrong AI output."
        https://www.helpnetsecurity.com/2026/09/17/frederic-bull-gremlin-ai-in-cybersecurity-gap/
      • Agentic Self-Modification In Open-Weights Systems
        "We studied a self-hosted system in which the same open-weights model powered both a coding agent and an AI application that the coding agent was asked to maintain. This architecture is particularly relevant in self-hosted environments where one capable model is reused across multiple roles, including coding agents and other AI applications. Given a routine software-maintenance task to fix incorrect application responses, the agent identified the shared model as the source of the problem, fine-tuned it, and replaced the model powering both the application and future instances of the agent itself. It did so without being instructed to train, modify the model, or deploy a replacement."
        https://www.irregular.com/research/agentic-self-modification-in-open-weights-systems
        https://www.securityweek.com/ai-agents-can-retrain-own-models-mid-task-leaking-secrets-and-erasing-refusals/
        https://www.theregister.com/security/2026/09/16/ai-agents-can-modify-themselves-without-humans-telling-them-to-do-so/5296991

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) ce961060-8d5b-4fe5-8b8b-c113d92e110e-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบช่องโหว่ในปลั๊กอิน The Events Calendar บน Wordpress เสี่ยงถูกใช้รันคำสั่งและยึดเว็บไซต์

      พบช่องโหว่ในปลั๊กอิน The Events Calendar บน Wordpress เสี่ยงถ.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 0a415252-45f5-4378-a50f-68bd822d6397-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Google ออกแพตช์ Android Zero-Day บนอุปกรณ์ Pixel หลังพบการโจมตี

      Google ออกแพตช์ Android Zero-Day บนอุปกรณ์ Pixel หลังพบการโจม.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fee872ee-86c8-4a79-b9bc-ff47a38a6046-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบมัลแวร์ KREMLIN โจมตีผู้ใช้งานเบราว์เซอร์ Chrome และ Edge เพื่อขโมยข้อมูลบัญชีธนาคาร

      พบมัลแวร์ KREMLIN โจมตีผู้ใช้งานเบราว์เซอร์ Chrome .jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand b76daab4-3a46-460a-ac9e-61572ca2afdd-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 17 September 2026

      Industrial Sector

      • Digital Watchdog VMAX DVR And NVR Product Lineups
        "Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-01
      • MySCADA MyPRO Manager
        "Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-03
      • Siemens Reyrolle 7SR5
        "Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-05
      • Wärtsilä FOS-Onboard
        "Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-02
      • Siemens Mendix SAML
        "Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-06
      • Schneider Electric SCADAPack x70 Products
        "Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-04
      • Siemens Teamcenter
        "A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-07
      • CareCam CM2507
        "Successful exploitation of these vulnerabilities could allow an attacker to access live video and sensitive device information, enable unauthorized services, execute arbitrary code, modify device operation, and recover stored credentials."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-08

      New Tooling

      • DeepZero: Open-Source Hunting For Vulnerable Windows Drivers
        "DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, scans them, throws most of them away, and asks a language model whether what survives can be attacked. Pipelines are written in YAML, the code is Python 3.11 and up. Rehman Ahmadzai, who maintains the project, said DeepZero has “found multiple verified vulnerabilities in a subset of the Snappy Driver Installer corpus, with some still undergoing the disclosure process.” The bundled pipeline targets BYOVD, short for bring your own vulnerable driver: an attacker loads a legitimately signed driver that contains a flaw and uses it to reach the kernel."
        https://www.helpnetsecurity.com/2026/09/16/vulnerable-windows-drivers-deepzero-open-source/
        https://github.com/416rehman/DeepZero

      Vulnerabilities

      • Oracle Patches 800+ Vulnerabilities In September 2026 Security Update
        "Oracle on Tuesday announced the release of 673 new security patches as part of its September 2026 Critical Security Patch Update (CSPU). The security updates appear to resolve more than 800 vulnerabilities: there are 672 unique CVEs in the 17 risk matrices included in the September 2026 CSPU advisory, but Oracle also notes that more than 130 additional CVEs have been resolved with the patches for other flaws. More than 100 of the newly addressed security defects are critical-severity flaws, and over 240 are remotely exploitable without authentication."
        https://www.securityweek.com/oracle-patches-800-vulnerabilities-in-september-2026-security-update/
      • Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading To Remote Code Execution In The Events Calendar Plugin
        "On August 21 and August 22, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability chains in The Events Calendar, a WordPress plugin active on more than 600,000 websites. Both chains begin in the plugin’s widget-rendering pipeline and can ultimately lead to Remote Code Execution without authentication through two separate methods. The first chain uses PHP Object Injection to execute arbitrary operating system commands on the underlying server. The second chain bypasses the object-injection guard and abuses an arbitrary-callable primitive to reset an administrator’s password, after which an attacker can upload a malicious plugin and take complete control of the site."
        https://www.wordfence.com/blog/2026/09/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin/
        https://www.securityweek.com/unauthenticated-rce-flaws-could-expose-200000-wordpress-sites-to-takeover/
        https://hackread.com/critical-calendar-wordpress-plugin-flaws-site-takeover/
      • Google Fixes Actively Exploited Android Zero-Day On Pixel Devices
        "Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. "There are indications that CVE-2026-58704 may be under limited, targeted exploitation," the company warned on Wednesday. "All supported Google devices will receive an update to the 2026-09-05 patch level. We encourage all customers to accept these updates to their devices.""
        https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-zero-day-on-pixel-devices/
        https://thehackernews.com/2026/09/google-patches-pixel-modem-flaw-amid.html
        https://www.malwarebytes.com/blog/mobile/2026/09/google-pixel-owners-urged-to-patch-actively-exploited-modem-flaw
        https://www.securityweek.com/pixel-modem-zero-day-exploited-in-targeted-attacks/
        https://securityaffairs.com/199193/hacking/google-patches-pixel-modem-zero-day-exploited-in-targeted-attacks.html
      • Chrome, Firefox Updates Patch 115 Vulnerabilities
        "Google and Mozilla have released fresh security updates for Chrome and Firefox users, resolving a total of 115 vulnerabilities. The new Chrome 153 release patches 42 security defects, including three critical-severity and 28 high-severity bugs. The critical flaws include CVE-2026-91726, an out-of-bounds read in WebGL, and CVE-2026-91721 and CVE-2026-91749, use-after-free issues in Internals and Workers, respectively."
        https://www.securityweek.com/chrome-firefox-updates-patch-115-vulnerabilities/
      • Issabel Framework Hard-Coded JWT Key RCE Via Pbxapi/manager/originate
        "The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09."
        https://www.vulncheck.com/advisories/issabel-pbx-hard-coded-jwt-key-rce-via-pbxapi-manager-originate
        https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html
      • Authentication Bypass And DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 In TP-Link Tapo Cameras
        "TP-Link Tapo cameras are widely used smart security devices designed for home and small-business monitoring. As network-connected cameras, these devices combine video streaming, remote management, mobile application integration, and other services within a compact embedded system. This connectivity also makes security especially important. A vulnerability that allows an attacker to bypass authentication or access privileged functionality could compromise the camera and potentially provide a foothold within the network where the device is deployed."
        https://www.opswat.com/blog/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras
        https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras/
      • ParaShells: Parallels Desktop Turns Appliance Install Into a Root Shell
        "Your Mac runs a vulnerable version of Parallels Desktop. A malicious package, compromised CI job, or other unprivileged process is already running on it. No admin access. No Parallels-signed client. One appliance-install request later, attacker-controlled code runs as root. While testing Desktop 26.4.0 (build 57513) on Apple silicon, we found that an unprivileged local user could execute code as root through prl_disp_service. The exploit combines its world-writable Unix socket with weak local-client authentication and argument injection in the appliance extraction path."
        https://jfrog.com/blog/parallels-desktop-turns-appliance-install-into-root-shell/
        https://www.helpnetsecurity.com/2026/09/16/parallels-desktop-cve-2026-90894-parashells-vulnerability/
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-58704 Google Pixel Improper Authorization Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-one-known-exploited-vulnerability-catalog
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
        CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-two-known-exploited-vulnerabilities-catalog

      Malware

      • Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
        "A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. "JWT authentication can be bypassed when a token is signed using an unsupported algorithm, allowing unauthorized access," according to an advisory released by WSO2 in May 2026. "Successful exploitation of the vulnerability may lead to unauthorized access, including potential compromise of administrative accounts and full account takeover.""
        https://thehackernews.com/2026/09/active-exploitation-attempts-target.html
        https://www.securityweek.com/enterprises-warned-of-attacks-exploiting-wso2-vulnerability/
      • Critical ScreenConnect Flaw Now Actively Exploited In Attacks
        "Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). ConnectWise shared temporary mitigation measures for this missing-authorization flaw on September 7, advising security teams to disable TransferFiles permissions to block potential attacks. The vulnerability (now tracked as CVE-2026-84869 and patched in ScreenConnect 26.6.5 and later) affects ScreenConnect clients and can let threat actors with basic privileges transfer or execute files in low-complexity attacks that don't require user interaction."
        https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-screenconnect-flaw/
      • AI Helps Scammers Build Convincing Antivirus Renewal Pages
        "Antivirus renewal scams often begin with a message claiming that your subscription has automatically renewed. When you follow the instructions to cancel it, you are taken to a fake page designed to collect your contact details. The renewal charge never existed. Receiving a message that names the antivirus software you use does not necessarily mean the sender has access to your device or account. Scammers impersonate popular brands and send the same message to large numbers of people, knowing that some recipients will be customers."
        https://www.malwarebytes.com/blog/threat-intel/2026/09/ai-helps-scammers-build-convincing-antivirus-renewal-pages
      • NightEagle Targets Russian Companies
        "Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia, as we reported previously. We have now identified attacks by the group targeting businesses in Russia. This post examines both known and new tools NightEagle used in its latest campaign."
        https://securelist.com/tr/nighteagle-apt-ghostcontainer-and-tunneling/121323/
        https://thehackernews.com/2026/09/three-threat-groups-target-russian.html
      • Atomic MacOS (AMOS) Stealer Activity
        "This article reviews an Atomic macOS (AMOS) stealer malware infection generated in a lab environment. While several sources have published articles analyzing AMOS stealer, the associated indicators constantly change. This article presents a snapshot of indicators seen in early August 2026 and is designed to help readers better understand AMOS stealer."
        https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/
      • Scammers Are Watching Airline Complaints And Posing As Customer Support
        "A delayed flight. Missing luggage. A refund that never arrived. For frustrated customers, social media has become a direct route to customer support. They tag the company, explain the problem, and wait for a response. However, threat actors are watching those same conversations. A Check Point Exposure Management investigation uncovered a coordinated social engineering campaign in which scammers monitor public complaints, impersonate customer support accounts, and approach customers seeking help. Researchers engaged directly with the scammers and followed the attack from the first social media interaction through WhatsApp conversations and payment flows."
        https://blog.checkpoint.com/exposure-management/scammers-are-watching-airline-complaints-and-posing-as-customer-support/
      • N0va Phishkit Targets US And EU Businesses: A New Challenge For Identity Security
        "N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud resources. The longer that access goes unnoticed, the greater the potential for wider compromise, operational disruption, and financial loss."
        https://thehackernews.com/2026/09/n0va-phishkit-targets-us-and-eu.html
      • BragJack: How We Hijacked 5 Of The World's Most Popular Browsers Using Their Built-In AI Assistants
        "We just hacked 5 of the world’s most popular browsers using a brand-new technique that relies on AI. And we don’t mean “some AI hacking model that we trained”. No no no… we mean the browser’s own built-in AI assistants that you probably have installed right now. Yes, if you’re using Google Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, or Claude in Chrome… that means you. The interesting thing is that we didn’t even have to bypass the AI’s guardrails to do it. In fact, we didn’t even use prompt injection, because we discovered something worse."
        https://forever.security/blog/bragjack-hijacking-5-browsers-via-built-in-ai-assistants
        https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html
        https://www.darkreading.com/endpoint-security/bragjack-browser-agentic-ai
      • Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, And BASHNATCH
        "In August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity in January 2026, APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. During our investigation, ThreatLabz discovered new malware families and post-compromise tools, as well as significant post-compromise activity. The new tools include the RUSTYSHADE backdoor, the RUSTYMOVE post-compromise tool, and the PSNATCH and BASHNATCH file-stealing tools."
        https://www.zscaler.com/blogs/security-research/operation-rapidrust-apt36-deploys-rustyshade-rustymove-psnatch-and
      • PhantomRaven: An LLM-Generated Information Stealer Developed For Bug Bounty Hunting
        "CrowdStrike Counter Adversary Operations identified a financially motivated threat actor who works as a bug bounty hunter and who developed and distributed the JavaScript (JS)-based information stealer PhantomRaven via npm, a platform on which developers can access open-source packages to build applications and software. The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns."
        https://www.crowdstrike.com/en-us/blog/phantomraven-llm-generated-information-stealer-for-bug-bounty-hunting/
        https://hackread.com/crowdstrike-ai-phantomraven-malware-bug-bounty-hunter/
      • Silent Push Exposes North Korean IT Worker Recruiting Facilitators Through Discord Servers
        "Silent Push identified a North Korean fake job recruitment scam channel hosted on a Discord server by a defender colleague, and we engaged the recruitment representative to ask about their offering and determine whether the individual was actually a North Korean IT worker. After connecting via Telegram, we asked the suspect NK persona “Tec Guru” about virtual private networks (VPNs); they advised us to use Astrill VPN, a VPN often used by North Korean IT workers We identified the threat actor’s primary tactic as identity and proxy theft, under the guise of a front/facilitator recruitment scheme."
        https://www.silentpush.com/blog/nk-it-worker/
      • Mythic C2 Activity At Internet Scale
        "Mythic was created as a successor to an earlier macOS-focused project (Apfell). It was designed as a language-agnostic, cross-platform framework with a web-based UI. It is provided in a dockerfile to suit your environment with the ability to choose and configure separately available agents. This modular design lets operators combine agents for different platforms with various transport profiles without modifying the core framework. These agents, C2 profiles, wrappers, and services are shared and supported by the Mythic Community."
        https://censys.com/blog/mythic-c2/
      • TrustSink: How a Rogue External MFA Provider Steals Passwords
        "Varonis Threat Labs identified a credential-phishing technique we call TrustSink. It turns a trusted external authentication provider into a persistent credential trap within a legitimate sign-in flow. While the technique can work in any provider, we demonstrated TrustSink end-to-end using Microsoft Entra. An attacker with high privileges can register a rogue External Authentication Method (EAM) and place a convincing password page inside the legitimate sign-in flow. The page captures the password in plaintext while the provider returns a valid signed token, completing the login without an error."
        https://www.varonis.com/blog/trustsink

      Breaches/Hacks/Leaks

      • 280,000 Impacted By Premier Medical Group Data Breach
        "New York healthcare provider Premier Medical Group (PMG) is notifying over 280,000 patients that their personal and medical information was stolen in a data breach. PMG offers in-depth patient care across cardiology, dermatology, gastroenterology, neurology, plastic surgery, gynecology, and internal medicine fields through multiple office locations in the Hudson Valley. The data breach occurred in June, when some of PMG’s systems were disrupted, the healthcare provider said in an incident notice."
        https://www.securityweek.com/280000-impacted-by-premier-medical-group-data-breach/
      • International Meteor Organization Says Cyberattack Dealt ‘critical Blow’ To Website
        "A cyberattack has shut down the website of the premier international organization responsible for tracking meteors. The International Meteor Organization (IMO) has continued tracking asteroids and meteor through its Facebook page, but its website now carries a static page notifying visitors of the cyberattack. “We recently suffered a cyberattack that dealt a critical blow to aging infrastructure, taking much of our site offline,” the organization said. “We expect several weeks of partial downtime as we transition to new infrastructure and services. We will bring features back as they become available.”"
        https://therecord.media/international-meteor-organization-cyberattack

      General News

      • Securing The Unpatchable In An Age Of AI-Driven Vulnerabilities
        "AI-assisted code analysis is uncovering decades of technical debt. Every new patch removes a newly identified coding mistake. Little by little, we are improving the state of software engineering, but the price is a cadence of patching that organizations may struggle to implement. These efforts leave unsupported systems, or systems that are not able to be patched for whatever reason, with unmitigated known vulnerabilities. How can such systems be secured in a world where AI is steadily improving its ability to identify new vulnerabilities?"
        https://blog.talosintelligence.com/securing-the-unpatchable-in-an-age-of-ai-driven-vulnerabilities/
      • The Adversary We Are Fighting Is Now a Full-Force Industry: Inside Cybercrime's New Economy
        "The disruption we’re witnessing isn’t because of a new threat category. It is the industrialization of conventional ones. Cybercrime went corporate years ago: affiliate programs, Ransomware-as-a-Service (RaaS), Initial Access Brokers (IABs), support desks on underground portals. AI did not start that but what it did was collapse the cost and the skill floor of every stage of the attack at the same time. Attacks did get smarter, but the part most underestimate is that mediocre attackers became competent, and competent ones became industrial."
        https://www.group-ib.com/blog/adversary-full-force-industry/
      • NIST And CISA Finalize Playbook To Stop Token Theft And Forgery
        "NIST and CISA have finalized guidelines to help federal agencies and cloud service providers (CSPs) protect identity and access tokens from forgery, theft, and misuse. The guidance, Protecting Tokens and Assertions from Forgery, Theft, and Misuse (NIST IR 8587), explains how agencies and cloud providers can strengthen key management, token verification, and token lifecycle controls. It also covers how identity providers and authorization servers should be designed and managed."
        https://www.helpnetsecurity.com/2026/09/16/nist-cisa-cloud-token-security-guidance/
        https://nvlpubs.nist.gov/nistpubs/ir/2026/NIST.IR.8587.pdf
        https://www.infosecurity-magazine.com/news/cisa-nist-cloud-identity-token/
      • What Happens When AI Agent Governance Is Missing At Scale
        "In this interview with Help Net Security, Gourab Basu, Global Head of Engineering at meshIQ, discusses governance in AI agent systems. He argues that instructions written into a prompt are not enough to control what an agent does, since agents can change their own path as they work. Real control means checking proposed actions before they reach production systems, such as pausing a large refund for human approval. He also covers what breaks when a company scales from ten agents to a thousand, and how to build governance that works across different agent frameworks."
        https://www.helpnetsecurity.com/2026/09/16/gourab-basu-meshiq-ai-agent-governance/
      • The Modern Attack Chain: Rethinking Google Workspace Security In The Age Of AI
        "Over the past two months, I’ve written about the Vercel breach and the Composio breach separately. Both offer lessons to learn on their own. But reading them together, I keep coming back to the same observation: these aren’t isolated incidents. They’re the same attack, run twice, against different targets, where email was not the entry point into the workspace. And once you see the pattern clearly, it changes what you think you need to defend. It also raises an uncomfortable question that I’ve been sitting with. The pattern I’m describing, where an OAuth grant is used to access an account, read sensitive data from email and Drive, and use that access to move past the workspace, doesn’t only describe what attackers do. It increasingly describes what AI agents do, by design, every day."
        https://www.helpnetsecurity.com/2026/09/16/material-google-workspace-attack-chains/
      • MSPs Say Nearly Half Their Customers Rely On Them For CISO Services
        "MSPs estimate that 46% of their customers, on average, look to them to act as CISOs, according to Sophos. Most of those providers do that job without the full set of compliance services, and many spread the work across several tools. Most providers expect this work to grow. For many of those customers, the MSP is the closest thing they have to a security leader."
        https://www.helpnetsecurity.com/2026/09/16/msp-ciso-services-compliance/
      • Cyber-Attacks Cost Organizations $52,000 On Average
        "Nearly a third (29%) of organizations globally have been hit by at least one successful cyber-attack in the past 12 months, with incidents having substantial financial, operational and human impacts on victims. The Hiscox Cyber Readiness Report 2026 found that those affected by cyber-attacks reported an average of four incidents over the period. UK-based firms were most likely to experience an incident, with successful attacks reported by 38% of organizations. US organizations were least likely to experience an attack, at 20%."
        https://www.infosecurity-magazine.com/news/cyberattacks-cost-organizations/
      • Major Cyber Threat Detection Vendors Shift From MITRE To UK Testing Program
        "UK-based security testing and advisory provider SE Labs is launching a new testing program to help buyers evaluate cybersecurity vendors – and has attracted some prestigious names. The six-month testing program, called PIVOT, was unveiled by SE Labs on September 15. It will evaluate how effectively cybersecurity vendors can defend against the world’s most dangerous hacking groups and attack techniques."
        https://www.infosecurity-magazine.com/news/cyber-vendors-mitre-uk-testing/
      • Mythos Has Made 2026 Patching Hell. It Might Make 2027 a Breeze
        "When Microsoft delivered over 970 patches last week, many saw a nightmare for beleaguered security staff. Gartner research vice president Craig Lawson thinks infosec workers might soon see sunlit uplands as their workloads ease. Lawson outlined that scenario at Gartner’s IT Symposium in Australia today and explained it by theorising that the increased volume of vulnerability discoveries made possible by Anthropic’s Mythos and other bug-hunting AI might be getting close to finding most of the flaws in established codebases."
        https://www.theregister.com/security/2026/09/16/mythos-has-made-2026-patching-hell-it-might-make-2027-a-breeze/5296747
      • Threat Intelligence Alone Won't Close The Exploitation Gap
        "A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to react. Intelligence is still the earliest signal defenders get, and a leaked credential turning up in a feed is proof of how useful that signal has become. The problem sits one step later, in what happens after the signal arrives."
        https://thehackernews.com/2026/09/threat-intelligence-alone-wont-close.html
      • Using Cyber Decoys To Strengthen Detection And Response
        "CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data. Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI). As organizations adopt Zero Trust models, they should assume that a malicious threat actor may gain some level of access to their environment and plan accordingly."
        https://www.cisa.gov/resources-tools/resources/using-cyber-decoys-strengthen-detection-and-response
        https://www.cisa.gov/sites/default/files/2026-09/using-cyber-decoys-to-strengthen-detection-and-response_508c.pdf
        https://cyberscoop.com/cisa-guidance-cyber-decoys-critical-infrastructure/
      • Spain's Data Agency Gets First Report Of AI-Powered Data Breach
        "The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). The organization reporting the incident said that the AI agent searched for flaws, logged into their systems, and then probed apps for additional security issues. In the final stages of the attack, the agent modified personal data and accessed financial documents. Although the Spanish agency has yet to investigate the incident and verify the information, the AEPD says the notification shows AI-related data breaches are no longer merely theoretical."
        https://www.bleepingcomputer.com/news/security/spains-data-agency-gets-first-report-of-ai-powered-data-breach/
        https://www.securityweek.com/first-agentic-ai-data-breach-reported-to-spanish-regulator/
      • AI Security Spending Jumps As Fear Outpaces Proof Of Value
        "Organizations are pouring more money into AI for cybersecurity without waiting for clear evidence of what they might be getting in return. Multiple factors are driving the spending trend. These include the rapid shift of AI from experimentation into production, the growing use of AI by attackers to automate and accelerate their operations, and in some cases, fear of being left behind as other organizations race to adopt the technology."
        https://www.darkreading.com/cybersecurity-operations/ai-security-spending-jumps-fear-outpaces-proof-value
        https://hs-50428896.f.hubspotemail.net/hubfs/50428896/2026 Security Budget Benchmark Report Budget Snapshot Version 09142026.pdf

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 7a217715-199c-48af-9a72-26a61595831a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการโจมตีช่องโหว่ใน WooCommerce Wholesale Lead Capture เสี่ยงถูกยึดเว็บไซต์ WordPress

      พบการโจมตีช่องโหว่ใน WooCommerce Wholesale Lead Capture เสี่ยงถ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand afce7416-a020-4349-a725-b019bce8e0ec-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ญี่ปุ่นเผยเหตุโจมตี VPN กระทบแพลตฟอร์มเครือข่ายกลางภาครัฐ เสี่ยงข้อมูลรั่วไหล 246,000 รายการ

      ญี่ปุ่นเผยเหตุโจมตี VPN กระทบแพลตฟอร์มเครือ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 59bf17ab-e36f-4596-ad7e-fbba23466d83-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT