NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,435
    • กระทู้ 2,436
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    NCSA_THAICERT

    @NCSA_THAICERT

    1
    ชื่อเสียง
    56
    ดูข้อมูลส่วนตัว
    2.4k
    กระทู้
    3
    คนติดตาม
    0
    ติดตาม
    เข้าร่วม ออนไลน์ล่าสุด
    เว็บไซต์ www.ncsa.or.th/?fbclid=IwAR0BqJEC-CJzBs98rlBxUbZkNBgp1g814xdDNNaKnHTrxfqZhPD--ksY68I

    NCSA_THAICERT เลิกติดตาม ติดตาม
    Global Moderator administrators

    Latest posts made by NCSA_THAICERT

    • Google เตรียมบล็อกส่วนขยาย Chrome ที่เปลี่ยนหน้า New Tab โดยไม่ได้รับอนุญาต

      Google เตรียมบล็อกส่วนขยาย Chrome ที่เปลี่ยนหน้า New .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 95a06120-b5c0-4cbb-9a1d-e66f78fa5e04-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CareCloud แจ้งเหตุข้อมูลรั่วไหล กระทบประชาชน 345,000 ราย หลังระบบบน AWS ถูกโจมตี

      CareCloud แจ้งเหตุข้อมูลรั่วไหล กระทบประชาชน 345,000 .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand c7ee4327-cd99-4f29-af50-d2e7d8947430-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CrowdStrike เผย AI กลายเป็นทั้ง อาวุธ และ เป้าหมาย ในการโจมตีไซเบอร์ยุคใหม่

      CrowdStrike เผย AI กลายเป็นทั้ง อาวุธ และ เป้าหมาย ใน.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 709f79d1-962a-45ad-9549-23efc717402c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 3 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 22ed4d9d-ad60-4a77-9987-6c69d62805ea-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 04 August 2026

      ndustrial Sector

      • APT And Financial Attacks On Industrial Organizations In Q2 2026
        "This summary provides an overview of reports on APT and financial attacks on industrial enterprises disclosed in Q2 2026, as well as the related activities of groups observed attacking industrial organizations. For each topic, we summarize the key facts, findings and conclusions of researchers that we believe may be useful to professionals addressing practical issues of cybersecurity in industrial enterprises."
        https://ics-cert.kaspersky.com/publications/reports/2026/08/03/apt-and-financial-attacks-on-industrial-organizations-in-q2-2026/
      • A Leaked Memo Ties Cyberattacks On Minnesota Water Utilities To Iran
        "Since the US launched its war against Iran in late February, the country’s hackers have struck back with retaliatory intrusions that have ranged from paralyzing medical supplies company Stryker to breaching the personal email of FBI director Kash Patel. Now, after an unprecedented wave of disruptive cyberattacks hit water utilities in Minnesota, a memo circulated within the water industry ties those attacks to Iran, too, in the widest and most disruptive strike yet inflicted by the country’s hackers against the US since the war began. A communication obtained by WIRED on Thursday and sent to members of the Water Information Sharing and Analysis Center, or WaterISAC, an industry group for water utilities to share cybersecurity information, links to Iran a series of cyberattacks that targeted dozens of Minnesota water and wastewater utilities."
        https://www.wired.com/story/a-leaked-memo-ties-cyberattacks-on-minnesota-water-utilities-to-iran/
        https://www.securityweek.com/us-water-cyberattacks-extend-beyond-minnesota-to-at-least-6-other-states/

      Vulnerabilities

      • N-Able Warns Of N-Central Auth Bypass Flaw Exploited In Attacks
        "N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. The company on Sunday released hotfix 2026.3.1.7 to address the security issue, which affects all versions of N-central before 2026.3. On August 1st, the vendor disclosed that it detected active exploitation and launched an investigation that uncovered additional security concerns affecting all versions of N-central, its flagship Remote Monitoring and Management (RMM) platform."
        https://www.bleepingcomputer.com/news/security/n-able-warns-of-n-central-auth-bypass-flaw-exploited-in-attacks/
        https://uptime.n-able.com/event/201456/
        https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html
        https://www.darkreading.com/vulnerabilities-threats/attackers-exploit-n-able-patch-bypass-flaw
        https://www.bankinfosecurity.com/n-able-flaw-exposes-msps-to-worst-case-scenario-a-32397
        https://hackread.com/hackers-exploit-n-able-n-central-flaw-initial-fix/
        https://www.securityweek.com/n-able-patches-vulnerability-exploited-to-hack-n-central-servers/
        https://www.helpnetsecurity.com/2026/08/03/cve-2026-18577-n-able-n-central-vulnerability/
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog
      • Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
        "Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor's July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented. Thermo Fisher tracks the issue as CVE-2026-17583 and rates it High with a CVSS v4.0 score of 8.2. Five supported product lines have received updates that add digital signatures, while three end-of-life data collection products will receive no vendor update."
        https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-could.html

      Malware

      • Analysis Of a Phishing Email Attack Case By The Larva-24009 Threat Actor
        "The Larva-24009 threat actor has been active since at least 2023, carrying out phishing email attacks targeting users both in Korea and globally to install malware. ASEC (AhnLab SEcurity intelligence Center (ASEC) has previously disclosed attack cases by this threat actor in 2024, and [1] [2] [3] Subsequently, Cyble also identified this same attack campaign and named it “HeptaX.” [4] The Larva-24009 threat actor continues to carry out attacks in 2026, and this report summarizes the attacks and malware identified in 2026."
        https://asec.ahnlab.com/en/94786/
      • Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader And DeviceManager RATs
        "SOCRadar’s Threat Research Unit (STRU) identified and analyzed DOUBLECUP, a Russian Loader-as-a-Service (LaaS) for ClickFix campaigns. Operating in a client-server architecture, each client can configure campaigns that host the DOUBLECUP logic on specific URLs. The DOUBLECUP panel provides multiple utilities to load an operator’s final payload. The first stage drops a steganographic PNG image into the browser’s cache, retrieves its hidden content, and executes the second stage. This second stage decrypts the final payload in memory via a custom SHA-256 stream cipher in Counter (CTR) mode along with bitwise XOR using the victim’s public IP address as the cryptographic key."
        https://socradar.io/blog/doublecup-clickfix-loader-devicemanager-rats/
        https://www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/
      • Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord And Forums
        "A malware campaign disguised as an “undetected” version of the Xeno Roblox script executor is directly affecting players looking to download a legitimate tool. Promoted through various gaming forums and Discord communities, the fake cheat launches a multi-stage Java infection chain built to stay hidden in plain sight. Its components imitate real Xeno files, use Windows-style names and hide inside trusted-looking directories, which includes a folder associated with Xbox Game Bar, formerly Microsoft GameDVR. The final payload goes far beyond conventional credential theft. It can steal browser cookies, Discord, Roblox and Minecraft accounts, cryptocurrency-wallet data and payment information."
        https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor
        https://www.bleepingcomputer.com/news/security/fake-roblox-xeno-script-launcher-pushes-infostealer-rat-malware/
      • Inside The Underground Business Of The Android BTMOB RAT Malware
        "BTMOB has been covered by several cybersecurity publications, primarily through technical analyses of the malware and its capabilities, but much less has been reported about the ecosystem that has developed around it. Activity observed by Flare researchers in underground forums and chat platforms reveals another story: a criminal software business that appears to have become increasingly difficult for its original operator to control. Posts reviewed by Flare show the channel presenting itself as BTMOB’s official outlet continuing to release new versions and sell access, private infrastructure, and source code."
        https://www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/
      • DarkReasoning: A Chinese LLM Attacked Our Lab, So We Made It Work For Us
        "5 days. That's how long the first live, LLM-managed cyber attack campaign we've detected hit our lab at Jesta Security. And for what? To set up proxyjacking and generate more attacks. From what we uncovered, over 1,000 victims had already been hit the same way, most likely also being used to generate fresh attacks every second. And if this is only what we stumbled onto, we believe the real number is far higher."
        https://jesta.ai/blog/darkreasoning
        https://www.darkreading.com/cyberattacks-data-breaches/chinese-actor-deepseek-ai-agent-attack-security-firm
      • Disrupting a Criminal Scam Operation
        "Earlier this year, we disrupted a Cambodia-based scam operation that used ChatGPT to support investment, romance, gambling, and law enforcement impersonation schemes. We began investigating this activity following a lead from our peers at WhatsApp and have since shared additional threat signals with industry partners and relevant authorities. The operation illustrates an important reality about modern scam networks: organized criminal groups rarely restrict themselves to a single type of scam. Instead, they opportunistically employ whatever narratives, personas, and tactics they think will be most effective to deceive victims."
        https://openai.com/index/disrupting-malicious-uses-of-ai-criminal-scam-operation/
        https://www.helpnetsecurity.com/2026/08/03/openai-disrupts-chatgpt-scam-operation/
      • Buying TikTok Views Or Followers? Here’s What You’re Really Getting
        "A whole industry has sprung up around selling TikTok “growth.” Cheap views by the hundred, pre-made ad accounts, and polished sales pages promising a repeatable path to serious revenue. None of it is officially sanctioned by TikTok, and depending on what you’re buying, you could end up wasting money, losing your account, or handing your login details to scammers."
        https://www.malwarebytes.com/blog/threat-intel/2026/07/buying-tiktok-views-or-followers-heres-what-youre-really-getting
        https://www.helpnetsecurity.com/2026/08/03/malwarebytes-tiktok-followers-scam-risks-report/
      • An Analysis Of Incidents At Brazilian Educational Institutions
        "Because of the amount of data that can be obtained and the high impact that successful attacks may have, educational institutions are frequent targets of cybercriminals. Both public and private schools and universities rely on software for managing personally identifiable information (PII) that is often insecure or insufficiently tested against known vulnerabilities. In addition, machines used by multiple people without accountability can be vulnerable to insider threats."
        https://securelist.com/incidents-at-brazilian-educational-institutions/120803/
      • Targeted Attack On Government Entities In The Middle East | Part 2
        "This is Part 2 of our two-part technical analysis on new tools used by an East Asia-linked threat actor targeting government entities in the Middle East. After ThreatLabz published Part 1 on the TELESHIM backdoor and MIXEDKEY loader, Kaspersky highlighted a related campaign in recent reporting. Building upon our initial findings, Part 2 dives into a detailed technical analysis of BINDCLOAK, a new modular stage 3 backdoor uncovered during our investigation. As detailed later in our threat attribution section, key code similarities between BINDCLOAK and OctLurk as well as shared command-and-control (C2) infrastructure directly connect the threat actor behind OctLurk to the campaign we describe in this two-part blog series."
        https://www.zscaler.com/blogs/security-research/targeted-attack-government-entities-middle-east-part-2
      • From WSProxy To Root: INC Ransomware And SonicWall SMA Exploit Chain
        "Virtual private network (VPN) appliances occupy one of the most sensitive positions in modern enterprise architecture: the boundary between the untrusted public internet and the internal corporate network. Unlike general-purpose web servers, VPN concentrators are intentionally exposed to inbound connections, designed to authenticate remote users, and granted privileged access to directory services, file shares, intranet applications, and management interfaces. They terminate encrypted tunnels, process credentials, and maintain session state at the network edge. A critical vulnerability in a VPN appliance is therefore not a peripheral remote-access issue—it is a direct network-compromise issue with cascading consequences for every downstream system the appliance was built to protect."
        https://www.resecurity.com/blog/article/from-wsproxy-to-root-inc-ransomware-and-sonicwall-sma-exploit-chain
        https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
        https://www.securityweek.com/recent-sonicwall-vulnerabilities-exploited-in-ransomware-attacks/
      • Pass The Passkey: A Novel Attack Surface In Passwordless Authentication
        "This article analyzes new attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The attacks demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts. We show how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys. After decades of breaches and billions in losses, the attack vectors that defined the era of passwords and shared secrets are finally starting to fade. Passkeys replace passwords and traditional multi-factor authentication (MFA) with public-key cryptography, decreasing entire classes of attacks that have dominated the threat landscape for years."
        https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/
        https://thehackernews.com/2026/08/google-password-manager-attacks-could.html
        https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/
      • DarkSword's Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster
        "DarkSword is a commercial iOS exploit chain, six chained vulnerabilities spanning iOS 18.4 through 18.7, that leaked publicly via a GitHub repository (ghh-jb/DarkSword) and now runs in the hands of at least seven, and probably eight, unrelated operators. The most recently identified operator is a Chinese-speaking actor running well over a hundred web properties, most of them fronted by a fake AWS sign-in page on a domain that also hosts DarkSword. The hosting concentrates in Hong Kong but reaches into Japan, the United States, and Europe. We re-scanned the cluster’s infrastructure to see how far it extended. Here is what we found."
        https://censys.com/blog/darkswords-panel-sprawl/
        https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html

      Breaches/Hacks/Leaks

      • ExfilSquad Hackers Leak Info Of Over 100,000 UK Police Officers, Staff
        "A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. The intrusion was detected on Sunday, July 26, and was later claimed by the ExfilSquad data extortion group, which alleges it stole 135,000 contact records. PNLD is an online legal resource service that has been used for more than 30 years by the 43 Home Office police forces in England and Wales, as well as the British Transport Police."
        https://www.bleepingcomputer.com/news/security/exfilsquad-hackers-leak-info-of-over-100-000-uk-police-officers-staff/
        https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html
        https://securityaffairs.com/196525/data-breach/pnld-confirms-data-breach-affecting-uk-police-and-justice-staff.html
      • Żabka Alleged Data Leak: 541k Jira Tickets, 89 Repos
        "A data-leak forum account registered on 2 August 2026 advertised an alleged Żabka Polska dataset the same afternoon, asking €5,000. The listing claims roughly 541,000 Jira issues, 229,734 IT service-desk tickets and source code from 89 GitLab repositories. Ransomnews reviewed the sample archive attached to the post. The headline counts are internally consistent, and a single GitLab access token appears in all 89 repository dumps. Żabka Group has not confirmed any breach."
        https://ransomnews.com/zabka-data-leak-2026/
        https://securityaffairs.com/196510/data-breach/alleged-zabka-breach-exposes-jira-data-source-code-and-api-keys.html
      • Hackers Steal 31,000 Records Identifying People Behind Liechtenstein Companies, Foundations
        "A cyberattack compromised tens of thousands of records related to companies, foundations and trusts in Liechtenstein, prompting the government to to form a “crisis unit” to address the breach. The unknown attackers gained access to the Register of Beneficial Owners for two days beginning on July 29, the government announced over the weekend. The register, which contains information on who owns legal entities in the country, was created in 2021 in accordance with European Union rules around money laundering and financial transparency."
        https://therecord.media/hackers-steal-records-liechtenstein-companies-foundations
      • River Bank Says Hackers Deleted Data Stolen In Ransomware Attack
        "River Financial Corporation, the bank holding company behind River Bank & Trust, says it received confirmation that data stolen in a ransomware attack was deleted. The attack occurred on June 16 and was identified three days later. River’s investigation into the incident determined that ransomware was deployed across portions of its server environment. In response, the company took the affected systems offline and disabled administrative accounts that had been compromised."
        https://www.securityweek.com/river-bank-says-hackers-deleted-data-stolen-in-ransomware-attack/
        https://securityaffairs.com/196537/cyber-crime/river-bank-obtained-assurances-from-the-attackers-that-the-stolen-data-in-the-june-attack-was-deleted.html

      General News

      • The Assets You Don’t Know You Own: Attack Surface Sprawl Is a Discovery Problem, Not a Tooling Problem
        "Modern organizations no longer operate within a fixed network perimeter. Cloud services, remote work, third-party integrations, and rapid digital expansion have made the boundary between “inside” and “outside” for the enterprise increasingly difficult to define. Attackers exploit this ambiguity by scanning continuously for weaknesses across an organization’s hardware, software, cloud, and internet-facing assets. The uncomfortable truth security leaders must confront is simple: an organization cannot secure what it does not know it has."
        https://cyble.com/blog/attack-surface-discovery-asset-visibility/
      • Anthropic: Claude Attacks Result Of Security Gaps, Not Model Issues
        "Three recent incidents in which Anthropic's AI models autonomously compromised real-world systems were less a failure of model alignment than a failure of the systems designed to keep them contained, according to the company. The compromises happened while Anthropic was testing the ability of its Claude AI models to autonomously find and exploit novel vulnerabilities in simulated cybersecurity environments. Typically, the company conducts these capture-the-flag-style exercises in environments that aren't connected to the Internet and often works with external partners to conduct the tests."
        https://www.darkreading.com/cyber-risk/anthropic-ai-issues-result-security-gaps
      • Is There Really a Fix For CISO Fatigue?
        "Only 2% of cybersecurity professionals report feeling no stress about their job, according to Omdia and ISSA's eighth annual Life and Times of Cybersecurity Professionals study. In addition, 68% say the work has become measurably harder over the past two years. The difference between those two figures is screaming that stress in this profession has moved from an occupational hazard to the default condition, and that shift changes what conclusions security leaders should draw from the gap."
        https://www.darkreading.com/cybersecurity-operations/fix-for-ciso-fatigue
      • Mapping The Malware Blast Radius a Single Alert Won’t Show You
        "In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far a malware campaign spread. He walks through the research behind the claim that each published sample hides an average of 2.4 undocumented variants, describes what counts as a related variant, and explains why Stairwell keeps every executable that runs on customer endpoints."
        https://www.helpnetsecurity.com/2026/08/03/mike-wiacek-stairwell-backstory-malware-blast-radius/
      • CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes As AI Use Accelerates
        "The CrowdStrike 2026 Threat Hunting Report illustrates the next evolution in trust abuse. Adversaries are targeting trusted users and tools across identity systems, cloud environments, SaaS applications, AI services, software supply chains, and developer workflows to blend into legitimate business activity and reach critical assets before defenders can detect them."
        https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-threat-hunting-report/
        https://www.infosecurity-magazine.com/news/chinalinked-threat-actors/
        https://cyberscoop.com/crowdstrike-annual-threat-hunting-report-2026/
      • Google Warns Open-Source Attacks Will Reach New Heights
        "Compromising the open-source supply chain is easier to execute and spreads more quickly than traditional supply-chain attacks, making it a lucrative tactic that will continue to expand, warned computing giant Google. Attacks on open-source code repositories, software dependencies and developer tools flourished in 2025 and the first months of 2026: TeamPCP's two waves of Shai-Hulud malware late last year affected 20 million weekly downloads of open-source software, while its months-long campaign this year poisoned packages accounting for 100 million weekly downloads."
        https://www.bankinfosecurity.com/google-warns-open-source-attacks-will-reach-new-heights-a-32404

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 5afe3572-6761-4eb8-9e8b-39c0821bc271-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Ruby on Rails ออกแพตช์ช่องโหว่ Critical ใน Active Storage เสี่ยงอ่านไฟล์และรันโค้ดบนเซิร์ฟเวอร์

      Ruby on Rails ออกแพตช์ช่องโหว่ Critical ใน Active Storage เสี่ยงอ่.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5fdad3e1-4048-4afd-9393-566bb4dc0ab1-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ใน Coldcard Hardware Wallet ถูกเชื่อมโยงกับเหตุขโมย Bitcoin มูลค่ากว่า 70 ล้านดอลลาร์สหรัฐ

      ช่องโหว่ใน Coldcard Hardware Wallet ถูกเชื่อมโยงกับเหตุขโ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 40ed95c8-b42f-4a02-9d7d-65e8b056b4b6-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการโจมตีทางไซเบอร์พุ่งเป้าหน่วยงานรัฐในภูมิภาคเอเชียกลาง ด้วยมัลแวร์ชนิดใหม่ OctLurk และ SilkLurk

      พบการโจมตีทางไซเบอร์พุ่งเป้าหน่วยงานรัฐ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 49fdbe03-973d-4bf5-88e0-e145af66f06a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 03 August 2026

      Telecom Sector

      • Researchers Report 84 Flaws In 4G And 5G Cores, Including a Session Hijacking Flaw
        "An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network session. The findings have been released by a group of researchers from Singapore's Nanyang Technological University in a paper titled "Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis.""
        https://thehackernews.com/2026/07/researchers-report-84-flaws-in-4g-and.html
        https://arxiv.org/abs/2607.10315

      Vulnerabilities

      • Advanced Responsive Video Embedder For Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass Via Hardcoded Backdoor In '_wplogin' Parameter
        "The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the _arve_uc_init() function — registered on WordPress's init hook at priority 1 so that it runs before any authentication checks on every request — reads an attacker-supplied token from the _wplogin (or _wpm) parameter and compares it against a hardcoded SHA-256 hash embedded directly in the plugin source, with no nonce verification, no capability check, and no password validation anywhere in the flow. Because this static hash constitutes a set of universal credentials that are publicly accessible in the plugin's source code, unauthenticated attackers can supply the known token to be authenticated as an arbitrarily selected existing administrator account, gaining full administrative control over the affected WordPress site. This was likely introduced by an attacker who gained commit access to the developers account."
        https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-responsive-video-embedder/advanced-responsive-video-embedder-for-rumble-odysee-youtube-vimeo-kick-1087-unauthenticated-authentication-bypass-via-hardcoded-backdoor-in-wplogin-parameter
        https://hackread.com/wordfence-critical-backdoor-arve-wordpress-plugin/
      • Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
        "Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in arbitrary code execution in the context of the current user without requiring any user interaction."
        https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html
        https://securityaffairs.com/196429/security/adobe-fixed-a-maximum-severity-vulnerability-flaw-in-campaign-classic.html

      Malware

      • Adform Compromised To Serve Crypto Stealer Via Supply Chain Attack
        "Adform are an advertising company used by around 14k companies, owning around a 30% share of the demand-side category. They operate by offering a Javascript embed for websites, via this URL: hxxps://s2.adform.net/banners/scripts/st/trackpoint-async.js This script was compromised to serve a crypto stealer. Adform have been hacked. As far as I can tell Adform haven’t told people."
        https://doublepulsar.com/adform-compromised-to-serve-crypto-stealer-via-supply-chain-attack-2f1ec024f33e
        https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/
        https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html
      • The Fuyao Enterprise: Building An Ad-Fraud Empire With AI And Kids’ Coding Blocks
        "In this post, we will uncover the “Fuyao Enterprise,” a previously unknown, sophisticated and highly modular botnet operating within Android TV boxes. This operation marks a shift in modern ad-fraud, where automated bots fake both clicks and views to defraud advertisers and ad-networks. While deploying novel tactics and techniques, Fuyao managed to escape public research for several years. Now, its operators openly advertise their network of over 120,000 “AI digital humans.""
        https://www.bitsight.com/blog/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks
        https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html
        https://www.helpnetsecurity.com/2026/07/31/fuyao-ad-fraud-botnet-android-tv-boxes/
      • Network Anomaly Detection In KATA
        "Once the attacker has breached the corporate network, subsequent stages of the attack often involve leveraging standard domain infrastructure protocols: using Kerberos, running DNS queries, accessing internal services, opening network shares, and other common networking actions. Because this activity is virtually indistinguishable from legitimate network traffic, it is extremely difficult to detect it with traditional network attack detection tools. Kerberoasting and DNS tunneling have long ceased to be exotic techniques. They are becoming standard methods in modern attacks because they allow attackers to execute critical compromise stages while remaining undetected by traditional security tools. A clear example of this trend is seen in latest campaigns, employing both Kerberoasting and DNS tunneling."
        https://securelist.com/tr/network-anomaly-detection-in-kata/120892/
      • Nested Trust: HollowFrame’s Layered Loader And Matryoshka Backdoors
        "Blackpoint Cyber’s Adversary Pursuit Group (APG) identified a previously undocumented, multi-stage intrusion affecting two endpoints at a law firm. The activity began with a spear phishing lure and progressed through several layers of obfuscated scripts, encrypted payloads, and trusted software components before establishing persistent remote access. The intrusion relied on a modular Go based loader tracked as HollowFrame and a Rust based malware family tracked as Matryoshka. HollowFrame provided the actor with multiple execution and persistence options. The Matryoshka family was represented by two distinct backdoor variants, one that communicated directly over HTTP and another that used GitHub for tasking and payload delivery. Together, these variants supported command execution, reconnaissance, file transfer, and follow on malware deployment."
        https://blackpointcyber.com/blog/hollowframes-layered-loader-and-matryoshka-backdoors/
        https://thehackernews.com/2026/07/hollowframe-loader-deploys-matryoshka.html
      • The Xcode Assassin Returns: A Deep Dive Into The Latest XCSSET Version
        "After months of dormancy, the attackers behind the XCSSET malware released version 40 (v40), targeting the macOS ecosystem. This version’s advanced architecture hides its core logic in memory space, reducing its digital footprint. V40 further enhances its detection evasion capabilities by combining polymorphic payload generation with fileless persistence and dynamic in-memory execution, while weakening a number of security mechanisms on the affected machine. Since early April 2026, the malware has spread through supply chain attacks by hiding itself in the Xcode projects of dozens of legitimate applications with thousands of active users. Xcode is Apple’s integrated development environment (IDE) for building apps for its various operating systems."
        https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/
      • When ScreenConnect Works For Cybercriminals
        "Leveraging legitimate software is one of cybercriminals’ tactics of choice, with remote management tools ranking among their top tools. A recent example involves the remote administration utility ScreenConnect. It’s designed for IT support teams to troubleshoot systems and configure software seamlessly in the background. However, when weaponized by threat actors, ScreenConnect becomes a versatile attack vehicle used to harvest data, deploy malware, and move laterally across corporate networks."
        https://www.kaspersky.com/blog/screenconnect-fake-software-campaign/56197/
      • CaptiveCrunch: Midnight Blizzard Targets Travelers Worldwide For Malware Delivery And Credential Theft
        "Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some tactic, technique, and procedure (TTP) similarities to the Forest Blizzard DNS hijacking operation that we publicly disclosed in April 2026, we attribute this campaign, which we call CaptiveCrunch, to Storm-2945. As reported by ReliaQuest on July 23, a portion of this activity leverages doppelganger domains mimicking Microsoft online services to conduct follow-on adversary-in-the-middle (AitM) phishing operations that abuse the device code authentication flow in Microsoft Entra ID."
        https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/
        https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html
        https://securityaffairs.com/196441/apt/russian-hackers-hijack-hotel-wi-fi-to-steal-microsoft-365-tokens.html
      • COLDCARD Wallet RNG Flaw Likely Linked To $88 Million Bitcoin Theft
        "Researchers suspect that a vulnerability in COLDCARD hardware wallet firmware was exploited to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. Digital asset research firm Galaxy Research says it identified an initial wave of transactions that it believes was likely linked to the vulnerability, draining approximately 1,083 BTC, worth $70.2 million, from 1,196 addresses on July 30. The 41-minute attack occurred approximately 30 hours before Coinkite publicly disclosed the flaw."
        https://www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/

      Breaches/Hacks/Leaks

      • Amgen Says Cloud Data Breach Exposed Patient Health, Proprietary Info
        "Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. Amgen is a California-based biotechnology company that develops and manufactures medicines for serious illnesses, including cancer, cardiovascular disease, inflammation, and rare diseases. The company said it detected the unauthorized activity in July 2026 and responded by activating its cybersecurity response plan, implementing containment measures, and hiring independent forensic experts to investigate the incident."
        https://www.bleepingcomputer.com/news/security/amgen-says-cloud-data-breach-exposed-patient-health-proprietary-info/
      • CareCloud Data Breach Impacts Over 350,000
        "Healthcare information technology company CareCloud is notifying at least 350,000 people that their information was stolen in a data breach. The incident involved an electronic health record environment within the CareCloud Health division, which was disrupted on March 16, 2026. CareCloud’s investigation determined that hackers accessed one of its AWS environments between March 10 and March 16, and likely exfiltrated data from it."
        https://www.securityweek.com/carecloud-data-breach-impacts-over-350000/
        https://securityaffairs.com/196480/cyber-crime/carecloud-breach-exposes-medical-and-financial-data-of-345000.html

      General News

      • The Morning After We Pull a Root Of Trust, Nobody Owns It
        "In June 2024, Google's Chrome Root Program said it would stop trusting new Transport Layer Security (TLS) certificates from Entrust. Behind the decision, years of compliance failures and a clear technical call. The decision was right. The fallout became someone else's responsibility. That is the part we keep getting wrong. We are good at the technical decision to remove a trust anchor. Root programs at Chrome, Mozilla, Microsoft, and Apple make that call well. What we lack is a way to coordinate what happens the morning after. Trust continuity is a national readiness problem hiding inside a browser setting."
        https://www.darkreading.com/cyber-risk/morning-after-we-pull-root-of-trust-nobody-owns-it
      • Interpol Leverages Global System To Curtail Fraud Payments
        "Earlier this month, Interpol revealed that authorities in Singapore and Oman used a worldwide network of law enforcement agencies and financial organizations to halt a $6.6 million payoff from a business email compromise (BEC) scam, part of Operation First Light 2026, which — among other milestones — blocked more than 31,000 bank accounts linked to fraud. When companies and individuals report fraud and cybercrime, it's often too late to recover transferred funds. The coalition of law enforcement agencies and financial firms, known as the Interpol Global Rapid Intervention of Payments (I-GRIP) mechanism, has been working together to cut down the time to halt transfers and recover funds."
        https://www.darkreading.com/cybersecurity-operations/interpol-leverages-global-system-curtail-fraud-payments
      • Cybercrime Goes Subscription: AI, Malware And Infrastructure On Demand
        "Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These services provide anonymity, plausible deniability, and access to short-lived infrastructure that is difficult to detect, attribute, and disrupt, enabling low-skilled actors to operate at scale, according to the Infoblox 2026 Threat Landscape Report. “Cybercrime is becoming more efficient, automated, and harder to stop. Driven by economics and fueled in part by frontier AI, it has reached an unprecedented scale. The line between financially motivated and state actors has blurred in a complex economy that allows criminals to evade disruption through segmentation and the adoption of commodity services,” said Dr. Renee Burton, Head of Infoblox Threat Intel."
        https://www.helpnetsecurity.com/2026/07/31/infoblox-domain-abuse-campaigns-report/
      • Aviation Cyber Risk Sits On The Ground, The Blindness Sits In The Air
        "In this interview with Help Net Security, Eliran Almog, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays unmonitored. He walks through GNSS jamming that leaves no trace in a SIEM, and a PX4 Autopilot flaw his team disclosed where drone command channels accept unsigned messages. He argues the Electronic Flight Bag matters less than the data loading chain behind it, makes the case for digital twins, and sets out what a 30 aircraft carrier with two security staff should do first."
        https://www.helpnetsecurity.com/2026/07/31/eliran-almong-cyviation-aviation-cyber-risk/
      • AI Agents Are Changing Where Cybersecurity Seed Funding Lands
        "Founders pitching a cybersecurity seed round this summer are joining a line that keeps getting longer. Product Hunt launches hit their highest level since late 2023 last quarter, and the Census Bureau’s count of high-propensity business applications kept climbing. Seed deal volume in cyber ticked down. Those figures come from the Q2 2026 Insights report published by DataTribe, an early-stage cybersecurity investor. The money went up the stack. Nine-figure rounds took 81% of every venture dollar invested in the second quarter, more than double the share they held at the start of 2018. Cyber Series A volume fell from Q1 and stayed inside the band it has occupied for three years."
        https://www.helpnetsecurity.com/2026/07/31/ai-agents-cybersecurity-seed-funding/
      • What An LLM Can Find: A Practical, Cheap Path To Code-Level Threat Discovery
        "GlobaLeaks, a mature whistleblowing platform that had already undergone six independent professional audits over the past thirteen years, was subjected to an LLM-assisted security review that cost roughly USD 3,140 in API calls. The review identified 29 confirmed vulnerabilities, 12 denial-of-service issues, and 42 hardening recommendations, with an average cost of about USD 77 per confirmed finding before human validation. The most important point is probably the cost. Reading an entire codebase systematically, line by line and against major known weakness classes, traditionally required weeks of specialist work and a serious budget. That assumption no longer holds in the same way: the report argues that this kind of analysis is now far more accessible than it used to be."
        https://securityaffairs.com/196395/ai/what-an-llm-can-find-a-practical-cheap-path-to-code-level-threat-discovery.html
      • AiTM Phishing Becomes Top Initial Access Threat To Law Firms
        "Adversary-in-the-middle (AiTM) phishing has become the single most common way attackers break into law firms, overtaking conventional credential theft in a sector where multifactor authentication (MFA) is now widely deployed but routinely bypassed. According to a new legal sector threat intelligence report from eSentire shared with Infosecurity, AiTM attacks accounted for 28.57% of all initial access events in the legal sector. The company's Threat Response Unit (TRU) also recorded a 20% year-over-year (YoY) increase in incidents targeting legal organizations."
        https://www.infosecurity-magazine.com/news/aitm-phishing-top-entry-point-law/
        https://esentire-dot-com-assets.s3.amazonaws.com/assets/resourcefiles/eSentire_Legal-Services-Threat-Intelligence-Spotlight.pdf
      • What The Hugging Face Breach Reveals About Defense In The Age Of Agentic AI
        "We almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models, including GPT-5.6 Sol along with an unreleased one, were responsible for the breach. OpenAI called it an unprecedented cyber incident."
        https://cyberscoop.com/hugging-face-breach-agentic-ai-security-op-ed/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) c2a27d22-ebb0-4bce-b490-0872aff6071d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cisco เตือนช่องโหว่ Static Credential ใน Secure Firewall Management Center ถูกใช้โจมตีจริง

      Cisco เตือนช่องโหว่ Static Credential ใน Secure Firewall Management Center ถูกใ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 12ad936f-83a0-47f6-9b7a-df14c70af6a9-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT