NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,659
    • กระทู้ 2,660
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    NCSA_THAICERT

    @NCSA_THAICERT

    1
    ชื่อเสียง
    59
    ดูข้อมูลส่วนตัว
    2.7k
    กระทู้
    3
    คนติดตาม
    0
    ติดตาม
    เข้าร่วม ออนไลน์ล่าสุด
    เว็บไซต์ www.ncsa.or.th/?fbclid=IwAR0BqJEC-CJzBs98rlBxUbZkNBgp1g814xdDNNaKnHTrxfqZhPD--ksY68I

    NCSA_THAICERT เลิกติดตาม ติดตาม
    Global Moderator administrators

    Latest posts made by NCSA_THAICERT

    • พบการโจมตี Supply Chain ผ่านแพ็กเกจ Tensorlake บน npm ขโมยข้อมูลรับรองและแพร่มัลแวร์ต่อ

      พบการโจมตี Supply Chain ผ่านแพ็กเกจ Tensorlake บน npm ขโมยข้_.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 9f07c2c3-2d32-47cf-b04f-95768017e815-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ASOS ตรวจสอบเหตุผู้โจมตีส่ง Push Notification ผ่านแอป อ้างเข้าถึงข้อมูลลูกค้าใน Snowflake

      ASOS ตรวจสอบเหตุผู้โจมตีส่ง Push Notification ผ่านแอป อ้.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 6cec9de7-6e7a-4733-84a0-9f30936c21a5-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ผู้บริหารของบริษัทรับกู้ข้อมูลระบบ ถูกตั้งข้อหาฉ้อโกงจากการแอบจ่ายเงินค่าแรนซัมแวร์ให้แฮกเกอร์ พร้อมเรียกเก็บเงินลูกค้าเกินจริง

      ผู้บริหารของบริษัทรับกู้ข้อมูลระบบ ถูกตั_.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand de768703-783c-408c-9738-c021b76c8608-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 12 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 12 รายการ เมื่อวันที่ 6 และ 8 ตุลาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-279-01 Johnson Control EasyIO FG
      • ICSA-26-279-02 Savannah lwIP
      • ICSA-26-279-03 Hitachi Energy Asset Suite
      • ICSA-26-279-04 Hitachi Energy SOI
      • ICSA-26-279-05 Hitachi Energy REB500
      • ICSA-26-279-06 Hitachi Energy RTU500 series CMU Firmware
      • ICSA-26-281-01 Red Lion Controls N-Tron 700 Series
      • ICSA-26-281-02 Grid Protection Alliance openPDC and openHistorian
      • ICSA-26-281-03 Satel Netco Design
      • ICSA-26-069-02 Lantronix EDS3000PS and EDS5000 (Update B)
      • ICSMA-26-223-02 Pulsetto Vagus Nerve Stimulator (Update A)
      • ICSA-25-259-02 Hitachi Energy RTU500 series (Update A)

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 40159308-883f-424e-bd55-0b7aff18a992-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 4 รายการลงในแคตตาล็อก

      เมื่อวันที่ 1-4 ตุลาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 4 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability
      • CVE-2026-102489 Zammad GmbH Zammad Session Fixation Vulnerability
      • CVE-2026-102490 Zammad GmbH Zammad Improper Privilege Management Vulnerability
      • CVE-2026-88779 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog
      https://www.cisa.gov/news-events/alerts/2026/10/02/cisa-adds-two-known-exploited-vulnerabilities-catalog
      https://www.cisa.gov/news-events/alerts/2026/10/04/cisa-adds-one-known-exploited-vulnerability-catalog

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 6 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 6 รายการ เมื่อวันที่ 1 ตุลาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      ICSA-26-274-01 Armatura LLC Armatura One
      ICSA-26-274-02 Monta monta.app
      ICSA-26-274-03 ABB Protection and Control IED Manager PCM600
      ICSA-26-274-04 Johnson Controls EasyIO Neo Series EC and CW Controllers
      ICSA-26-274-05 Johnson Controls EasyIO Neo Series EC and CW Controllers
      ICSA-26-274-06 Meari IoT Cloud Platform OpenAPI Service

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ea8c3e7b-9f7a-437b-8bca-9905bc860759-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 2 รายการลงในแคตตาล็อก

      เมื่อวันที่ 29-30 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 2 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-86950 Apple Multiple Products Out-of-Bounds Write Vulnerability
      • CVE-2026-76504 Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/29/cisa-adds-one-known-exploited-vulnerability-catalog
      https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 429480fb-87b7-4949-aa16-b9d58755d6b7-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 7 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 7 รายการ เมื่อวันที่ 29 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-272-01 Lantronix G520 Series Cellular Gateway
      • ICSA-26-272-02 Toptech TMS7 and TopHAT
      • ICSA-26-272-03 VIVOTEK Camera Firmware
      • ICSA-26-272-04 Baicells Nova 430H
      • ICSA-26-272-05 Anjvision YSSD-RTMP-H5
      • ICSA-26-272-06 MikroTik RouterOS
      • ICSA-26-272-07 Viidure Dashcam Android Application

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 33e7cb7d-c1c2-49fb-9988-90c294557326-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 09 October 2026

      Vulnerabilities

      • Cisco Warns Of Critical Flaws Allowing Nexus Switch Takeover
        "Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches. If remote code execution cannot be achieved, an attacker could exploit the vulnerabilities to crash processes and force the vulnerable device to reload, resulting in a denial-of-service condition. The issues affect the NX-API, Next Generation OAM (NGOAM), and MPLS OAM features in Nexus 3000 and Nexus 9000 Series switches."
        https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-flaws-allowing-nexus-switch-takeover/
        https://www.securityweek.com/cisco-patches-a-dozen-critical-vulnerabilities/
      • SonicWall And Splunk Patch Critical Vulnerabilities
        "Splunk and SonicWall on Wednesday announced patches for multiple critical- and high-severity vulnerabilities in their products, including flaws that could lead to arbitrary code execution. SonicWall rolled out fixes for four vulnerabilities in its SMA1000 appliances, urging users to update to versions 12.5.0-03082 and 12.4.3-03670 as soon as possible. The most severe of the issues, tracked as CVE-2026-102255 (CVSS score of 10), is a pre-authenticated SSRF bug that exists due to an unintended alternate access path. “By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations,” the company warned."
        https://www.securityweek.com/sonicwall-and-splunk-patch-critical-vulnerabilities/
      • High-Severity Nvidia Bug Could Crash GPU Monitoring On Exposed Servers
        "Researchers found thousands of GPU servers exposing Nvidia's DCGM Exporter to the internet, with hundreds potentially vulnerable to a high-severity flaw that could let unauthenticated attackers crash the GPU monitoring service and disrupt AI workloads. DCGM Exporters read telemetry from the GPUs on a host, including its hardware, utilization, memory usage, power consumption, and error events. Each GPU has its own unique ID, or UUID, and all of these metrics are exposed in plaintext over HTTP."
        https://www.theregister.com/security/2026/10/08/high-severity-nvidia-bug-could-crash-gpu-monitoring-on-exposed-servers/5302077
      • AgentCorruption' Puts AWS Environments At Risk With Single Prompt
        "If one thing has become apparent over the past year, it's that AI and cloud computing don't mix well. That's according to Tamir Ishay Sharbat, director of security research at AI security vendor Zenity Labs, who detailed a now-patched flaw in AWS Bedrock AgentCore during a session at SecTor 2026 on Wednesday. Bedrock AgentCore, which launched last year, is AWS's managed platform for deploying and operating agents. But Sharbat and Zenity's research team tested the platform and found that agents deployed through Bedrock AgentCore could access the organization's Instance Metadata Services (IMDS), which contains sensitive data such as temporary credentials, instance IDs, and configurations. With a single prompt to a public facing chatbot, Sharbat discovered he could not only gain control over that specific agent but take over all agents on in the same AWS account and region."
        https://www.darkreading.com/cloud-security/agentcorruption-aws-environments-at-risk-single-prompt

      Malware

      • RMM Tools Currently Being Distributed Through Phishing Attacks (ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, N-Able)
        "In January 2026, the AhnLab SEcurity intelligence Center (ASEC) reported on attack cases that distributed RMM (Remote Monitoring and Management) tools through video files or attachments in phishing emails. [1] [2] In these attack cases, tools such as Syncro, ConnectWise ScreenConnect, NinjaOne, and SuperOps were exploited."
        https://asec.ahnlab.com/en/95751/
      • The Phone Was Compromised Before The User Turned It On: The Rise Of Midnight Mimosa
        "Bitdefender's security researchers have identified a malware campaign (dubbed Midnight Mimosa) running on low-cost, multi-brand Android devices built on MediaTek platforms. The malware ships preinstalled in the device firmware, and we found multiple system packages involved, depending on the device. It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled. The malware runs with system-level privileges that allow it to silently install and remove apps, grant permissions, and load arbitrary code supplied remotely. This essentially means its operators could install and delete apps at will, tuning each device to their needs, including making them part of large botnets."
        https://www.bitdefender.com/en-us/blog/labs/midnight-mimosa-malware
        https://www.bleepingcomputer.com/news/security/low-cost-android-phones-ship-with-residential-proxy-malware/
        https://therecord.media/cheap-androids-shipped-with-ad-fraud-malware
      • Never Deleted, Only Re-Pointed: Inside The 17,600-Repo FakeGit Fleet That Re-Arms Overnight
        "Around 06:30 UTC on October 4, a script started editing READMEs across FakeGit, the network of fake GitHub repos that delivers the SmartLoader malware loader. Over the next thirty-four hours, more than thirteen thousand GitHub repositories were pushed in coordinated bursts, at up to 2,999 an hour. In the commits we sampled, 97% touched only the README, and 88% pointed its “Download” button at a ZIP that installs SmartLoader. Nobody had to create a single new repo. The fleet was already there. It just got re-aimed. We call this RePointing: keep a trusted, long-lived repo, and swap only where its download button points."
        https://apiiro.com/blog/never-deleted-only-re-pointed
        https://www.bleepingcomputer.com/news/security/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos/
      • MATCHBOIL: New Tricks, Same Old Evil Intentions
        "ESET researchers have documented the evolution of the MATCHBOIL malware, a custom C# downloader wielded by the Russia-aligned UAC-0099 APT group. The malware is used to download a payload from the group’s C&C server, install it, and establish its persistence. Although MATCHBOIL was first documented by CERT-UA in August 2025, our research indicates that it has been in development since at least 2024. The earliest versions of the malware that we analyzed are from April 2024 and the latest from April 2026. This blogpost goes over these versions chronologically and describes the malware’s changes. Each new iteration of the downloader was more sophisticated than the last, showing that MATCHBOIL is an important part of UAC-0099’s toolkit."
        https://www.welivesecurity.com/en/eset-research/matchboil-new-tricks-same-old-evil-intentions/
        https://www.darkreading.com/cyberattacks-data-breaches/russian-spies-matchboil-malware-facelift
        https://therecord.media/russia-ukraine-malware-transportation
        https://www.bankinfosecurity.com/sandworm-linked-group-sharpens-matchboil-downloader-a-33037
        https://www.infosecurity-magazine.com/news/russia-aligned-uac-0099-evolves/
        https://www.helpnetsecurity.com/2026/10/08/matchboil-malware-uac-0099/
      • Chasing AMMYY At Splunk .conf
        "We’ve run the Encrypted Visibility Engine (EVE) in Firewall Threat Defense (FTD) at enough conferences to develop a ‘usual suspects’ list of malware detections. Endpoint connections related to Upatre, Xpiro, and Quasar malware are among the most consistent malware related detections in EVE from conference to conference. The Splunk .conf network brought a new detection that we hadn’t seen before: Flawed AMMYY. AMMYY is a remote access tool that is often misused in scams to gain access to victim computers. There is also a Remote Access Tool (RAT) called Flawed AMMYY that was developed from leaked AMMYY source code, and is directly used as malware. See the MITRE advisory here."
        https://blogs.cisco.com/security/conf26-agentic-soc-chasing-ammyy
      • UAT-11985: AI-Assisted Event Lures Delivering Real-Time Google AitM Phishing
        "Cisco Talos identified an advanced persistent threat (APT) spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions to establish credibility. The phishing emails exhibited highly consistent structure, rhetoric, and personalization patterns, suggesting the threat actor likely used AI-assisted content generation to rapidly customize invitation lures for different targets while maintaining a common social engineering framework."
        https://blog.talosintelligence.com/uat-11985/
      • Ignore All Instructions And Read This Blog: The State Of AI-Analysis Evasion In Malware
        "Just as attackers are adding new capabilities into their toolkits with AI, they are consciously trying to evade the novel AI capabilities levied on them by defenders. In Cisco Talos' findings with CAIRN, we classify this archetype of malware as “A3: AI-Analysis Evasion” — that is, malware that embeds natural-language instructions to influence automated analysis. In line with the CAIRN philosophy, we treat this embedded language as a signal and actively seek it out to track and measure the progression of adversary techniques on this front."
        https://blog.talosintelligence.com/ignore-all-instructions-and-read-this-blog-the-state-of-ai-analysis-evasion-in-malware/
      • Inside a Brand Deal Scam Targeting YouTube Creators
        "For a YouTuber, the approach may look like routine business: a personalized sponsorship email from a global brand and a brief negotiation over rates, followed by an invitation to visit a slick collaboration platform. In some cases, however, the sequence can mask a scam that could part social media content creators from their Google accounts. One such recent campaign impersonates Hollyland, a legitimate manufacturer of wireless transmission and audiovisual equipment. We’ve traced the scheme from the first contact and the negotiations of a supposed partnership through to the login request. We’ve also spotted several variants where fraudsters repackage the campaign using different brand identities and domains."
        https://www.welivesecurity.com/en/social-media/brand-deal-scam-targeting-youtube-creators/
        https://www.helpnetsecurity.com/2026/10/08/scams-targeting-youtube-creators-sponsorship/
        Suspected TraderTraitor Group Uses Trojanized Terraform Provider To Deliver Cross-Platform Malware
        "In July 2026, Zscaler ThreatLabz uncovered a campaign linked to TraderTraitor (also tracked as Jade Sleet, UNC4899, Pressure Chollima, and Slow Pisces), an advanced persistent threat actor backed by the North Korean government that has targeted the cryptocurrency industry for years. This campaign also significantly overlaps with the previously reported KelpDAO incident, the analysis of which discussed both FLATROOF and ROOFDECK, two malware families also observed in this campaign. The attackers utilized a trojanized Terraform provider to deliver a Bash loader that selects and downloads malware tailored to the victim's operating system. The FLATROOF malware deployed Python scripts to steal sensitive data from the victim before ultimately dropping the ROOFDECK backdoor to gain full remote control."
        https://www.zscaler.com/blogs/security-research/suspected-tradertraitor-group-uses-trojanized-terraform-provider-deliver
      • FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access To Stolen Emails
        "Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8. The company, Integrity Technology Group, has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using a tool containing more than 1,300 scripts, guessed passwords for Microsoft 365 and Exchange accounts, and copied mailboxes using tools designed to collect mail."
        https://thehackernews.com/2026/10/fbi-says-china-linked-hackers-ran.html
        https://www.ic3.gov/CSA/2026/261008.pdf
      • Earth Sirrush: A Russia-Aligned Intrusion Set With 4 Years Of Evolving Espionage Tooling
        "Since at least 2022, the Russia-aligned intrusion set tracked by TrendAI™ Research as Earth Sirrush — previously tracked as SHADOW-EARTH-065, overlapping with the UAC-0099 designation by the Computer Emergency Response Team of Ukraine (CERT-UA) — has conducted sustained spear-phishing campaigns against Ukrainian government agencies, defense organizations, border guard units, and logistics operators. Our new report traces the group’s operations from 2022 through July 2026, revealing a threat actor who continually replaces its malware while retaining recognizable development, delivery, and infrastructure patterns."
        https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/earth-sirrush-russia-aligned-intrusion-set-4-years-evolving-espionage-tooling
        https://cdn.sanity.io/files/ch6z6vqj/production/6841312eb734e41b43e14eeb5a9474df8a6c77d0.pdf
        https://thehackernews.com/2026/10/uac-0099-targets-ukrainian-government.html
      • Wazza Phishkit Targets Banking, Government, And Manufacturing Across The US, EU, And Australia
        "Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself. ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia. The campaign uses a multi-stage routing chain to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page."
        https://thehackernews.com/2026/10/wazza-phishkit-targets-banking.html
      • 16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
        "Socket Threat Research identified a coordinated campaign of 16 Firefox extensions targeting cryptocurrency wallet users. The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to attacker-controlled Cloudflare Workers."
        https://socket.dev/blog/firefox-crypto-wallet-stealers
        https://thehackernews.com/2026/10/16-malicious-firefox-extensions-pose-as.html
      • TensorLake Npm SDK Compromised In ChainDrop Shai-Hulud Credential-Stealing Attack
        "Socket detected a compromised release of tensorlake, the npm SDK for Tensorlake’s AI agent infrastructure, in a ChainDrop / Shai-Hulud supply chain attack. Version 0.5.144 contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code. The package receives approximately 12K weekly downloads and has over 1k stars on GitHub. Tensorlake provides isolated sandboxes for running untrusted, LLM-generated code, with checkpointing, suspend, and resume capabilities. Its npm SDK lets developers create and manage those environments from TypeScript applications. A compromised SDK creates exposure on the machine installing it, before generated code reaches a sandbox."
        https://socket.dev/blog/tensorlake-compromise
        https://thehackernews.com/2026/10/tensorlake-npm-package-compromised-to.html
        https://www.theregister.com/security/2026/10/08/shai-hulud-worm-makes-jump-to-ai-infrastructure-with-tensorlake-compromise/5302054
      • Leaked Chats Show Russian Extortion Gang Sending ‘agents’ Into US Law Firms
        "Members of a Russia-based cyberextortion gang plotted to send operatives into U.S. law firms, kidnap business executives and even recruit military personnel to spy on submarine-based nuclear forces, according to leaked chats reviewed by Recorded Future News. The archive, posted to a bespoke .onion site in early October by an unidentified source who did not state a motive, contains thousands of messages from August 2025 to September 2026. In those messages, members track dozens of victims, haggle over multimillion-dollar payments and direct operatives based in the United States whom they call “agents.” Some of the named organizations have not publicly acknowledged a breach."
        https://therecord.media/leaked-chats-show-russian-extortion-gang-sending-agents-to-law-firms
      • CastleStealer: An Emerging Infostealer Growing More Sophisticated
        "First discovered in April 2026, CastleStealer is a C#-based information-stealing malware that has continued to add new capabilities since its emergence. Newer samples analyzed by Flashpoint can bypass app-bound encryption in Chromium-based browsers, execute commands remotely, and exfiltrate stolen information in small encrypted transmissions rather than a single large archive. While Flashpoint has not yet identified a large influx of threat actors using CastleStealer, its continued development makes it an emerging threat worth watching."
        https://flashpoint.io/blog/castlestealer-an-emerging-infostealer-growing-more-sophisticated/
      • FortiBleed Is Still Active, Locking Organizations Out
        "On October 6, 2026, the FBI and the U.S. Secret Service published a joint Cybersecurity Advisory on FortiBleed, the active global credential compromise campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. If you defend or triage Fortinet exposure, this is the document to read in full; it adds field-response detail that changes how you should scope, hunt and remediate. Below is what is operationally relevant right now: what has changed since the earlier reporting, the indicators to hunt on today, and the actions that actually close the gap. SOCRadar’s Threat Research Unit first documented FortiBleed in June, and we have folded the relevant background in where it helps you act."
        https://socradar.io/blog/fortibleed-still-active-locking-organizations-out/
        https://securityaffairs.com/200558/cyber-crime/fortibleed-hit-86000-firewalls-by-exploiting-something-nobody-can-patch-away.html
        https://www.securityweek.com/fortibleed-attackers-locking-victims-out-of-fortinet-devices/
      • Brazilian Access Broker Targeting Latin America: Mapping BraZetsu Infrastructure Via TLS Certificates
        "On 31 August 2026 Group-IB described BraZetsu, a Python framework for Windows compiled with Nuitka, and attributed it with high confidence to the Brazilian actor Exilware. The same paper ties the binary to the Infected Marketplace (Banco de Infects), a shop that inventories compromised Windows hosts and sells the access after a deposit of about $5.80 (BRL 30), settled through NowPayments. The published network indicators are three Pastebin raw URLs, the hostnames c2.installscenter.com, infect.online and infectonline.store, and one IPv4 address: 38.242.246[.]176, a Contabo VPS already seen in the AgenteV2 lineage."
        https://hunt.io/blog/brazetsu-access-broker-infrastructure
        https://securityaffairs.com/200634/cyber-crime/hunt-io-finds-new-brazetsu-infrastructure-months-before-disclosure.html
      • Spike In Attacks Targeting Digital Video Recorders In Ukraine
        "GreyNoise identified an increase in scanning and exploitation attempts targeting Digital Video Recorders (DVR) in Ukraine between 21 September and 1 October 2026. The activity coincides with an escalation in Russian strikes across the country. There are a myriad of malicious use cases for compromising DVRs; one involves gaining the ability to physically survey an area to gain battlespace awareness before, during, and after kinetic strikes."
        https://www.greynoise.io/blog/hikvision-camera-exploitation-attempts-ukraine
      • How BlueMoon Exploits Chrome CVE-2026-85046 And CVE-2026-87491
        "BlueMoon Exploit Kit is a malware delivery kit first observed on August 28, 2026. Campaigns targeted the US and Southeast Asia, including Vietnam, Indonesia, and Singapore, across nonprofit, mining, commodity trading, aerospace, manufacturing, government, consulting, and financial sectors [1]. It chains V8 type confusion and sandbox escape with a Windows kernel exploit. After checking the host, it raises the renderer’s privileges and injects code into the browser’s parent broker process to download and run a payload outside the renderer sandbox. In this blog, we will explain how BlueMoon Exploit Kit works and show how Picus helps you test your security controls against this threat."
        https://www.picussecurity.com/resource/blog/how-bluemoon-exploits-chrome-cve-2026-85046-and-cve-2026-87491
      • Phishing Campaign Abuses Microsoft Power BI To Deploy Rogue RMMs
        "In September, Huntress observed a phishing campaign where threat actors abused legitimate Power BI domains to make their attack more convincing and evade security controls that trust the service. These emails led victims to a fake reference document on the Power BI domains, which prompted targets to "Download Reference". When they attempted to do so, a new tab opened to an attacker-controlled website, which would fingerprint victims before triggering a rogue ScreenConnect installer download. Notably, these webpages delayed the payload's automatic download. After a few seconds, a script programmatically activated a hidden download link that led to the installer."
        https://www.huntress.com/blog/screenconnect-power-bi
      • DarkSword/Coruna Open Directory Finding Report
        "Open directories on five hosts exposed the full DarkSword/Coruna iOS exploit-and-harvest platform, from the C2 delivery server to the per-wallet theft modules. The infrastructure was still in use at triage time. The platform runs a commercial exploitation-as-a-service operation. A copy of the production server recovered 11 victim recovery phrases, 179 device loot directories, and a 75-account control-plane roster. A separate China-based operator is running the same kit in the wild against its own C2, distinct from every other tracked DarkSword actor."
        https://censys.com/blog/darksword-coruna-open-directory-finding-report/

      Breaches/Hacks/Leaks

      • Ransomware Attack Disrupts Japan's IDCF Cloud Used By Govt Clients
        "IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country. The company says that the attack started on October 7 at 3:40 AM local time, forcing a shutdown of the network and system. “Our investigation has determined that a disruption in East Japan Region 1 was caused by a ransomware attack by a third party,” reads IDFC Cloud’s announcement."
        https://www.bleepingcomputer.com/news/security/ransomware-attack-disrupts-japans-idcf-cloud-used-by-govt-clients/
      • ASOS: Hackers Tricked Way Into Employee Account Before Sending Rogue Push Notification
        "British online fashion retailer ASOS said Thursday that hackers gained access to an employee’s account by “impersonating a trusted contact,” allowing them to send an unauthorized push notification to customers. The company said its investigation, carried out with external experts, found the attackers had accessed “some personal information, including names and contact details, and certain non-personal account related information.” ASOS did not say how many customers were affected nor whether it believed data had been copied out of its systems."
        https://therecord.media/asos-says-hackers-tricked-employee-access-push-notification
        https://www.bleepingcomputer.com/news/security/asos-links-data-breach-to-social-engineering-attack-credential-theft/
        https://www.infosecurity-magazine.com/news/asos-data-breach-stolen-employee/
      • Hackers Target Two South Korean Megachurches, Potentially Exposing Congregant Data
        "Two of South Korea's largest Protestant churches are investigating cyberattacks that may have exposed sensitive information about hundreds of thousands of members, including personal details, financial records and internal documents. Seoul-based Yoido Full Gospel Church and SaRang Church acknowledged the suspected breaches after South Korean cybersecurity firm Oasis Security published research this week analyzing data recovered from a server used by the attackers. In a statement to local media on Wednesday, Yoido Full Gospel Church said it had identified one dataset containing personal information associated with approximately 850,000 members."
        https://therecord.media/south-korea-hackers-megachurches

      General News
      Justice Department And FBI Seize Vulnerability Scanning And Spear Phishing Tools Operated And Used By China-State Sponsored Hackers
      "Today the Justice Department and FBI announced court-authorized seizures to deny malicious cyber actors access to two hacking tools, “Microscan” and “FishHub,” used to scan and, in some cases, hack, U.S. and foreign critical infrastructure systems and other networks. As alleged in court documents unsealed in the Western District of Pennsylvania, malicious cyber actors working for Integrity Technology Group (Integrity Tech), a company based in the People’s Republic of China (PRC), operated and used the tools. Integrity Tech has contracts with the PRC government."
      https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-vulnerability-scanning-and-spear-phishing-tools-operated
      https://www.bleepingcomputer.com/news/security/fbi-disrupts-chinese-hacking-tools-used-to-breach-critical-infrastructure/
      https://therecord.media/flax-typhoon-china-tools-integrity-tech-international-takedown
      https://www.bankinfosecurity.com/fbi-seizes-domains-used-in-flax-typhoon-attacks-a-33049
      https://cyberscoop.com/doj-fbi-seize-flax-typhoon-hacking-tools-microscan-fishhub/
      https://www.theregister.com/security/2026/10/08/us-disrupts-chinese-hacking-tools-as-7-govts-warn-of-prc-spies-stealing-sensitive-data-worldwide/5302107

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) a012c433-13c4-44a3-8488-b1ed017182e5-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ XSS ใน Ninja Forms และ WPC Product Bundles ถูกใช้โจมตีเว็บไซต์ WordPress

      ช่องโหว่ XSS ใน Ninja Forms และ WPC Product Bundles ถูกใช้โจมตีเว.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 3769a731-294c-4f30-92d9-0277273f3878-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT