NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,441
    • กระทู้ 2,442
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    NCSA_THAICERT

    @NCSA_THAICERT

    1
    ชื่อเสียง
    56
    ดูข้อมูลส่วนตัว
    2.4k
    กระทู้
    3
    คนติดตาม
    0
    ติดตาม
    เข้าร่วม ออนไลน์ล่าสุด
    เว็บไซต์ www.ncsa.or.th/?fbclid=IwAR0BqJEC-CJzBs98rlBxUbZkNBgp1g814xdDNNaKnHTrxfqZhPD--ksY68I

    NCSA_THAICERT เลิกติดตาม ติดตาม
    Global Moderator administrators

    Latest posts made by NCSA_THAICERT

    • Thermo Fisher ออกแก้ช่องโหว่ซอฟต์แวร์วิเคราะห์ DNA เสี่ยงกระทบความถูกต้องของข้อมูล

      Thermo Fisher ออกแก้ช่องโหว่ซอฟต์แวร์วิเคราะห์ DNA เ_.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 7044e34d-f95f-4124-91db-952e1a575eaf-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • PNLD ยืนยันเหตุข้อมูลรั่วไหล กระทบเจ้าหน้าที่ตำ

      PNLD ยืนยันเหตุข้อมูลรั่วไหล กระทบเจ้าหน้าท_0.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 7ef974d4-b620-4c69-8d67-e72be4e7c961-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการโจมตี Pass-ta-key มัลแวร์บน Windows สามารถขโมยข้อมูล Passkey จาก Google Password Manager ได้

      พบการโจมตี Pass-ta-key มัลแวร์บน Windows สามารถขโมยข้อ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand f1436953-62dd-4b59-b3b3-5d0fcd232626-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 2 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 2 รายการ เมื่อวันที่ 4 สิงหาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-216-01 Acrisure Karr Anti-theft
      • ICSMA-26-216-01 Thermo Fisher Applied Biosystems 3100 and 3500 Series Genetic Analyzers

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง

      https://www.cisa.gov/news-events/ics-advisories

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 1e8b4b59-8607-44de-b280-03dc4d81573f-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 3 รายการลงในแคตตาล็อก

      เมื่อวันที่ 4 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 3 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-9198 IBM Langflow Code Injection Vulnerability
      • CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
      • CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ddcf667c-65ab-4c7e-93bd-95a301ec5c9c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 05 August 2026

      Healthcare Sector

      • Thermo Fisher Applied Biosystems Genetic Analyzers
        "Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results."
        https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-216-01

      Industrial Sector

      • Acrisure KARR BT And DR-100
        "Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-216-01

      New Tooling

      • OWASP’s Subtractive Security Project Measures The Attack Paths You Erased
        "An attacker who talks a user into opening an attachment gets whatever that machine still permits: a service account with rights across the domain, an outbound route to anywhere, a scripting engine sitting there for the taking. Christopher Frenz wants those capabilities deleted before anyone writes a detection rule for them. Frenz leads the OWASP Subtractive Security Top 10, a set of nine lists published alongside an engineering standard called Path Erasure Rate. Organizations that answered the last decade by stacking EDR, SIEM, and NDR now pay for alerts on paths they could have removed. The lists name which paths to remove, by platform."
        https://www.helpnetsecurity.com/2026/08/04/owasp-subtractive-security/
        https://github.com/OWASP/OWASP-Subtractive-Hardening-Top-10

      Vulnerabilities

      • New cPanel Critical Flaw Could Let Hosting Customers Run SQL As Database Root
        "cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The database bug is tracked as CVE-2026-58048 (CVSS 4.0 score: 9.4) and affects all supported versions of cPanel & WHM, along with WP Squared. Reaching it requires a valid cPanel account and access to the MySQL/MariaDB feature. From there, the vendor says the account holder could execute arbitrary database commands with full administrative privileges."
        https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html
        https://securityaffairs.com/196595/security/cve-2026-58048-cpanel-bug-enables-full-database-administrator-access.html
      • CISA Adds Three Known Exploited Vulnerabilities To Catalog
        "CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-9198 IBM Langflow Code Injection Vulnerability
        CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
        CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog
      • New TP-Link Router Vulnerabilities: Exploiting Zero Touch Provisioning
        "For more than three years, Forescout Research – Vedere Labs has reported on the increasing exploitation of network infrastructure devices, such as routers and firewalls. Previous research, including Sierra:21 and Dray:Break, and observed threat actor activity by the larger research community targeting these devices, focused on individual vulnerabilities that enable remote code execution. However, the growing use of Zero-Touch Provisioning (ZTP) by IT teams creates opportunities for attacks at a much larger scale. Network vendors offer ZTP ecosystems in which provisioning servers push configurations and updates to client devices, including routers, switches, gateways, and wireless access points. This enables devices to be configured with little or no manual intervention."
        https://www.forescout.com/blog/new-tp-link-router-vulnerabilities-exploiting-zero-touch-provisioning/
        https://support.omadanetworks.com/us/document/130627/
        https://www.bleepingcomputer.com/news/security/tp-link-patches-omada-ztp-flaws-allowing-hackers-to-breach-networks/
        https://www.securityweek.com/tp-link-omada-ztp-vulnerabilities-chain-into-full-network-takeover/
      • Tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
        "tl;dv (Too Long; Didn't View) is an AI meeting recording platform. It drops a bot into your Google Meet, Zoom, or Teams call, records everything, transcribes it, and generates summaries with AI. Over 2 million users. Backed by investors. Endorsed by half of LinkedIn's sales influencer community. They store your sales calls, job interviews, performance reviews, internal strategy sessions. The kind of content where someone says "this call is being recorded" and everyone nervously laughs and then shares trade secrets for 45 minutes."
        https://bobdahacker.com/blog/tldv-hack
        https://www.darkreading.com/application-security/ai-notetaker-spy-government-corporate-video-calls
      • I'll Just Call You: Agent-To-Agent Privilege Boundary Failures In CI/CD On Google's ADK Repository
        "Pillar Security researchers have identified the first practical, real-world case of agent-to-agent exploitation in a multi-agent system in a real production environment, a class of attack not seen in real production systems until now. A case where one AI agent can be used to attack another, turning a benign automation into a path that ends in a potential software supply chain compromise. We found the exploit in google/adk-python, the repository behind Google's Agent Development Kit for Python, an SDK many teams use to build their own agents."
        https://www.pillar.security/blog/ill-just-call-you-agent-to-agent-privilege-boundary-failures-in-ci-cd-on-googles-adk-repository
        https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html
        https://www.securityweek.com/gemini-agent-to-agent-attack-exposed-secrets-enabled-pull-request-tampering/
        https://www.theregister.com/security/2026/08/03/google-dev-kit-spurs-first-ever-agent-on-agent-violence/5282496

      Malware

      • Inside Greatness: Telegram-Distributed M365 AiTM PhaaS
        "ZeroBEC threat research on the Greatness phishing-as-a-service (PhaaS) platform, a commercially distributed kit sold via Telegram that combines adversary-in-the-middle (AiTM) credential and token theft with device code phishing in a single operator product. This investigation began with a live campaign that exploited spoofed RingCentral emails and customer-side safe sender exclusions to bypass email gateway controls and deliver phishing lures targeting Microsoft 365 accounts. Panel access, infrastructure testing, and cross-domain analysis revealed the full operator ecosystem, shared backend, and post-compromise tradecraft."
        https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing
        https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/
        https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html
      • 77 "evil Twin" Open VSX Extensions: 19 Copy Private Repo And CI Data To a New Domain
        "Between July 26 and August 1, 2026, our monitoring systems identified 77 Open VSX extensions that beacon to the same newly registered domain. Each one republishes the name, namespace and description of a real, unrelated extension at a low version number, almost always 0.0.1, under an account that does not own the namespace and does not belong to the original author [example 1, example 2, example 3]. The bundled extension.js is swapped for a beacon. In most of the packages it sends little more than the machine's hostname. In nineteen of them it sends a detailed description of the machine, the repository open in the editor, and the CI system the editor is running inside. The Open VSX listings described this under a section headed “Telemetry.”"
        https://www.manifold.security/blog/open-vsx-evil-twin-extensions
        https://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/
      • Keyv And Friends Compromised In Active Shai-Hulud Supply Chain Attack
        "On August 4, 2026, attackers compromised the GitHub account of the maintainer behind keyv, a key-value storage library with roughly 127 million weekly npm downloads, and used that access to inject a credential-stealing worm across the entire package family. The same maintainer owns cacheable (29M downloads/month), flat-cache (565M downloads/month), file-entry-cache (557M downloads/month), and several other widely-used caching utilities, all of which were swept up in the same attack. The compromise was carried out by pushing malicious files directly to the main branch and then immediately cutting a new release, meaning the poisoned versions were published to npm with valid provenance signed by GitHub Actions."
        https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack
        https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack
        https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/
        https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html
        https://www.bankinfosecurity.com/worm-targets-more-than-2000-npm-package-versions-a-32412
        https://cyberscoop.com/supply-chain-attack-malware-mini-shai-hulud-teampcp/
        https://hackread.com/shai-hulud-npm-worm-poisoning-1280-packages/
      • “Keep Going, Bro. You’ve Got This!” A Data-Driven Look At How Adversaries Are Weaponizing AI
        "Artificial intelligence (AI) and associated language models are now ubiquitous and heavily used in both personal and professional contexts to streamline tasks and expand capabilities. With AI being used everywhere and by almost everyone, one of the biggest questions is how malicious actors are taking advantage. Fortunately, actors make mistakes and chatbots leave artifacts. Leveraging cloud-based AI models leaves behind a variety of artifacts, most notably a prompt log. These logs can take on a variety of shapes and sizes, but they are left on endpoints that are running various applications, such as Claude Code, CodeX, Cursor, or Gemini."
        https://blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/
        https://www.infosecurity-magazine.com/news/talos-attackers-split-tasks-evade/
        https://www.theregister.com/security/2026/08/04/bypassing-ai-guardrails-is-so-easy-a-script-kiddie-can-do-it/5282973
      • Incident Report: Unsanctioned Agent Behaviour During Cyber Testing
        "AISI’s role is to evaluate and understand the capabilities of frontier AI models, surfacing potential risks before they reach the public. To assess what these models can do, including whether they could be misused for cyberattacks, we test them under deliberately permissive conditions: with access to the open internet, and with some safety filters disabled. On 28th July 2026, AISI's Security Team detected unusual data transfers leaving our research systems during a routine cyber evaluation. On investigation, we found that some of the agents being tested had engaged in sustained, potentially harmful activity directed at real people and organisations. We declared a security incident and, within roughly one hour of discovery, had contained it and begun a full investigation."
        https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing
        https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security Incident INC-2026-07-28-01.pdf
        https://cyberscoop.com/aisi-openai-report-unsanctioned-ai-model-hacks/
      • Analyzing SMOKE#SCREEN: ScreenConnect RMM Abuse, Cloudflare Tunnels, And Trusted Software Lures
        "Securonix Threat Research has been tracking an active, multi-wave campaign we are calling SMOKE#SCREEN, in which threat actors use a rotating collection of social engineering lures themed around Zoom software updates, business document reviews, and system maintenance utilities to deliver silent ScreenConnect Remote Monitoring and Management (RMM) agent installations. The campaign relies on a toolkit of VBScript droppers, batch file loaders, compiled .NET executables and a HTML phishing page, all ultimately pointing to a live WsgiDAV-based staging server at 207.174.0.143:8080. Victims who execute any of the initial access files end up with a fully functional ScreenConnect agent silently installed and beaconing to one of three attacker-controlled relay servers, providing the threat actor with persistent, legitimate-looking remote access to compromised hosts."
        https://www.securonix.com/blog/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels/
        https://www.darkreading.com/cyberattacks-data-breaches/latest-rmm-fueled-phishing-attack-exposes-threat-actor-playbook
        https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html
      • QuickFox Supply Chain Attack Used To Deploy FDMTP Implant
        "FortiGuard Labs is tracking a campaign associated with a long-standing supply chain attack on the QuickFox application. QuickFox is a VPN proxy and game accelerator typically employed by Chinese users to speed up access to Chinese-based resources, often to improve video game user experience. Active since at least August 2025, the supply chain attack involves a trojanized version of the QuickFox application. The attack is delivered via a modified Electron renderer HTML file used to download and execute a JavaScript-based loader. Upon execution, the JavaScript loader fingerprints the victim endpoint to determine if it’s a valid target before downloading and installing an FDMTP implant. Analysis of infrastructure related to this campaign indicates active development, and infrastructure continues to be active at the time of publishing."
        https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant
      • Consumer Protection Tuesday: A Fake IRS "Digital Asset Compliance Portal" Letter Is Targeting Crypto Holders
        "Scammers are mailing physical letters in subtle, unmarked envelopes that look like they come from the IRS, telling crypto holders they must "enroll" in a so-called Digital Asset Compliance Portal (DACP) before a deadline. The letter includes a QR code that leads to a convincing fake IRS website."
        https://www.coinbase.com/en-gb/blog/consumer-protection-tuesday-fake-irs-scam
        https://www.helpnetsecurity.com/2026/08/04/fake-irs-crypto-letters-compliance-portal-scam/
      • WhatsApp Account Takeover Scam Asks You To “vote For My Friend”
        "A scam is spreading through WhatsApp with the goal of taking over victims’ accounts entirely. It starts with a message that feels harmless and familiar. Someone—often a contact whose account has already been compromised—asks you to support a friend or relative of theirs by voting in an online contest. The theme varies: a ballet performance, a dog competition, a school event. The wording is casual, sometimes urgent, and designed to get a quick click."
        https://www.malwarebytes.com/blog/scams/2026/08/whatsapp-account-takeover-scam-asks-you-to-vote-for-my-friend
        https://www.infosecurity-magazine.com/news/whatsapp-voting-scam-linked/
      • How Legitimate Cloud Platforms Enable Phishers To Bypass MFA
        "Threat actors are increasingly exploiting legitimate cloud services to evade detection and streamline the deployment of their scam infrastructure. Cloud hosting services and decentralized networks have become primary platforms for hosting phishing pages and sites. Throughout 2025 and 2026, we have observed phishing operators steadily migrate toward platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS. This post analyzes the mechanics of a real-life adversary-in-the-middle (AitM) attack in a cloud environment and presents detailed statistics on the platforms and domains phishers abuse most frequently."
        https://securelist.com/cloud-platforms-in-phishing/120832/
      • AI-Enabled Email Accounts Could Become The Ultimate Insider Threat
        "In June, Barracuda’s Red Team detailed a multilayered controlled attack that showed how attackers gain access to a victim’s account. Once an attacker has access, the next steps depend on their objectives. In most cases, however, attackers first seek to establish persistence, escalate privileges and extend their access within the environment. Attackers increasingly try to achieve this by abusing legitimate tools already present in the environment, a technique known as “living off the land.” This commonly takes the form of PowerShell scripts or the misuse of remote access software. Our controlled attack focused instead on the growing threat of attackers leveraging the victim’s AI assistant to perform reconnaissance, identify targets and accelerate attack progression."
        https://blog.barracuda.com/2026/08/04/ai-enabled-email-accounts-insider-threat
        https://www.securityweek.com/weaponized-email-ai-assistants-could-help-attackers-hijack-accounts/
      • Almost Half Of Malware Samples Communicate Direct To IP
        "Malware samples often bypass DNS entirely, communicating directly to IP addresses instead. Our analysis of 4 million dynamic analysis reports indicates that almost half (45.32%) of malware samples with any command-and-control (C2) activity made at least one direct-to-IP (D2IP) address connection. Measured as a fraction of all C2 connection attempts, D2IP traffic accounts for 23.17% of the total. A wide variety of threats — including ransomware droppers, peer-to-peer (P2P) botnets and supply chain risks — communicate directly with hard-coded IP addresses, bypassing DNS entirely and evading DNS-based defenses altogether."
        https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/
      • Developers In The Crosshairs: Fake AI Tools Deliver Infostealer
        "In April 2026, Netskope Threat Labs exposed a Malware-as-a-Service (MaaS) NodeJS infostealer delivered through the ClickFix social engineering technique. As we tracked this infostealer, we uncovered ongoing campaigns in which attackers shifted delivery vectors, cloning and impersonating known GitHub repositories and redirecting download links at their payloads. These GitHub repositories are part of the broader campaign previously tracked as TroyDen’s lure factory.The campaign’s target victims were mainly in North America, Asia, and Southern Europe, across different segments, with the financial services, banking, and technology sectors leading."
        https://www.netskope.com/blog/developers-in-the-crosshairs-fake-ai-tools-deliver-infostealer
        https://www.helpnetsecurity.com/2026/08/04/developers-github-fake-ai-tools-infostealer/
      • Npm Stealer Reads Its C2 From An Ethereum Contract
        "Netskope Threat Labs identified and analyzed 28 malicious npm package versions published across four unrelated enterprise namespaces (@servicetitan, @or-sdk, @onereach, and @umacloud) on 2026-08-04. The packages arrived in two rapid bursts: the @or-sdk and @onereach packages at 10:39 UTC, the @servicetitan packages two minutes later at 10:41 UTC, and @umacloud/knowledge nearly three hours after that at 13:18 UTC. All 28 carry an identical or functionally equivalent payload, confirmed by hash match for @umacloud/[email protected], the one tarball still live when we retrieved it. The operator behind the campaign calls it Shai-Hulud, consistent naming with similar attacks we have tracked over the past year [1], [2], [3]. At install time, the packages fetch a signed Bun runtime release from GitHub, execute an obfuscated JavaScript stealer under it, and delete the runtime."
        https://www.netskope.com/blog/npm-stealer-reads-its-c2-from-an-ethereum-contract
      • Malware Signing: When Trust Becomes An Attack Surface
        "Digital code-signing certificates play a critical role in the software ecosystem. When a software publisher signs an application, the certificate serves two important purposes: It identifies the publisher and verifies that the software has not been modified since it was signed. Operating systems, browsers, endpoint protection tools, and users all rely on these signals to determine whether software should be trusted. This trust model benefits everyone. Developers can prove that their software is authentic, users can install applications with greater confidence and security tools can use certificate information as one factor when evaluating risk. In a world where millions of software packages are downloaded every day, digital signatures help establish a foundation of trust. Unfortunately, attackers have learned how to exploit that foundation."
        https://blog.barracuda.com/2026/08/04/malware-signing--when-trust-becomes-an-attack-surface

      Breaches/Hacks/Leaks

      • 150,000 Impacted By Madera Community Hospital Data Breach
        "Madera Community Hospital in California is notifying just over 150,000 individuals that their personal, financial, and medical information was compromised in a data breach. A not-for-profit community healthcare provider serving Madera County and surrounding areas, Madera Community Hospital provides emergency services, surgical services, acute care, diagnostic imaging, and specialized medical programs. The incident, the hospital says in an incident notice, occurred in May 2025, when hackers accessed its network for two days and likely exfiltrated certain files."
        https://www.securityweek.com/150000-impacted-by-madera-community-hospital-data-breach/
      • Swiss IT Agency Hacked, 200 Accounts Compromised, SharePoint Vulns Suspected
        "Switzerland’s Federal Office for Information Technology and Communications (BIT) disclosed Tuesday that hackers had compromised approximately 200 accounts on its on-premises SharePoint servers. The agency made the announcement a week after security specialists first detected anomalies on the on-premises Microsoft servers. It did not confirm how the hackers got in but acknowledged several vulnerabilities affecting SharePoint had been identified in July’s Patch Tuesday release. “The cyberattack was carried out by previously unknown actors, presumably by exploiting these vulnerabilities in the SharePoint software,” the Swiss agency said."
        https://therecord.media/swiss-bit-foitt-hacked-possibly-sharepoint-vulnerabilities
        https://securityaffairs.com/196625/hacking/sharepoint-flaws-used-to-hack-switzerlands-federal-it-agency.html

      General News

      • Third-Party Cyber Evaluations Involving OpenAI Models
        "Independent testing plays an important role in helping us validate and further understand risks before deployment. Some cyber evaluations intentionally use custom configurations, including lowered safeguards to measure underlying capability—not how models ordinarily behave in publicly available deployments. During recent evaluations, two external testing partners identified incidents in which testing configurations and controls combined with the advancing capabilities of the recent models allowed for model activity to extend beyond their intended testing boundaries."
        https://openai.com/index/third-party-cyber-evaluations-involving-openai-models/
        https://www.bleepingcomputer.com/news/security/openai-anthropic-ai-agents-targeted-real-people-and-systems-in-cyber-tests/
      • When Data Becomes Instructions: AI Agents Need a Chain Of Custody For Context
        "A few weeks ago, an AI cyber evaluation produced an unexpectedly efficient strategy for solving a benchmark: the agents went looking for the answers. According to OpenAI’s preliminary disclosure, models being tested for advanced cyber capabilities found ways to obtain secret information that could help them complete a benchmark. They chained vulnerabilities, stolen credentials, internet access, and inferences about where benchmark material might be hosted. The route eventually reached Hugging Face infrastructure, where the activity was detected and contained."
        https://blog.checkpoint.com/ai-security/ai-agent-context-chain-of-custody/
      • How Companies Could Share Cyber Risks Without Exposing Their Secrets
        "Zero-knowledge proofs could let infrastructure operators answer key security questions without handing over the sensitive data behind their answers. Imagine a major software flaw is discovered in equipment used across pipelines, power plants and telecom networks. The government needs to know as fast as possible which companies are exposed. But answering that question may require firms to share software inventories, network diagrams and vulnerability scans, which could become attack roadmaps for attackers if compromised. A lesser-known cryptographic concept could help solve this problem. The method, known as zero-knowledge proofs, allows companies prove a vulnerability exists without disclosing how their systems work or other proprietary information."
        https://cyberscoop.com/zero-knowledge-proofs-cyber-risk-sharing-op-ed/
      • Digital Executive Protection Is a Strategic Imperative For CEOs
        "In this interview with Help Net Security, Brian Hill, Field CISO, Client Advisory for BlackCloak, explains how attackers reach companies through the personal lives of executives. He describes a case where a draft report sat in an executive’s personal email with no multifactor authentication, and traders acted on it before the news went public. He also covers a home network left open after an AV technician swapped cables, malware planted through hotel Wi-Fi, and why he thinks deepfake defense should verify the person, not the message. Companies lack the tools to close this gap."
        https://www.helpnetsecurity.com/2026/08/04/brian-hill-blackcloak-digital-executive-protection/
      • Why Trust Is The New Attack Surface: Darktrace’s Mid-Year Threat Update 2026
        "Darktrace’s analysis of the first half of 2026 shows attackers increasingly exploiting trust rather than bypassing security controls. Identity compromise, supply-chain attacks, SaaS abuse, AI-enabled operations, and state-aligned activity demonstrate how trusted users, services, and infrastructure have become key attack paths. For defenders, context and behavioral analysis remain essential foundations of security."
        https://www.darktrace.com/blog/why-trust-is-the-new-attack-surface-darktraces-mid-year-threat-update-2026
        https://www.infosecurity-magazine.com/news/cloud-saas-targets-attackers/
      • AI Accounts For Over Half Of Cybercrime In Africa, Says Interpol
        "AI-driven cybercrime now accounts for 55% of all reported digital crime in Africa, Interpol has warned. The policing group made the claim in a new African Cyberthreat Assessment Report 2026, which draws on data provided by its 36 member countries on the continent. AI-powered scams, social engineering and credential harvesting have helped to drive cybercrime losses from $192m in 2024 to $484m last year, the report claimed."
        https://www.infosecurity-magazine.com/news/ai-accounts-over-half-cybercrime/
      • CISO Conversations: Russ Kirby – Passion Is The Antidote To Burnout
        "Passion for the job is the secret of a successful career. Russ Kirby has been CISO at Ping Identity since the summer of 2023. Before then he was CISO at Creditsafe, and then CISO at ForgeRock. Prior to that he had been global head and director of enterprise services information security directorate at Hewlett Packard."
        https://www.securityweek.com/ciso-conversation-russ-kirby-passion-is-the-antidote-to-burnout/
      • SQLite Critical CVEs Or LLM Slop?
        "Over the past few days, a newly created GitHub repo (programmervuln/cveadvisory-) published a batch of SQLite vulnerability advisories (as part of other 50+ CVEs which we believe are also LLM slop except from one). NVD quickly flagged these as critical, and CISA's ADP agreed. But when JFrog security researchers dug in to verify, the claims fell apart:

      The cited code didn't even exist in those versions or referenced unrelated logic.
      When testing the PoC payloads they didn’t work (not triggering any crash).
      None of these CVEs are listed on SQLite’s official advisory page (which is a gold standard for tracking actual vulnerabilities).
      All advisories in this repo seem AI generated when testing them with Gptzero
      "
      https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/
      https://www.theregister.com/security/2026/08/03/ai-slop-pollutes-the-cve-pipeline-with-fake-vulns/5282462

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 397c3606-e2f9-451d-94f3-7799fea61b5f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Google เตรียมบล็อกส่วนขยาย Chrome ที่เปลี่ยนหน้า New Tab โดยไม่ได้รับอนุญาต

      Google เตรียมบล็อกส่วนขยาย Chrome ที่เปลี่ยนหน้า New .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 95a06120-b5c0-4cbb-9a1d-e66f78fa5e04-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CareCloud แจ้งเหตุข้อมูลรั่วไหล กระทบประชาชน 345,000 ราย หลังระบบบน AWS ถูกโจมตี

      CareCloud แจ้งเหตุข้อมูลรั่วไหล กระทบประชาชน 345,000 .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand c7ee4327-cd99-4f29-af50-d2e7d8947430-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CrowdStrike เผย AI กลายเป็นทั้ง อาวุธ และ เป้าหมาย ในการโจมตีไซเบอร์ยุคใหม่

      CrowdStrike เผย AI กลายเป็นทั้ง อาวุธ และ เป้าหมาย ใน.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 709f79d1-962a-45ad-9549-23efc717402c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 3 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 22ed4d9d-ad60-4a77-9987-6c69d62805ea-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT