NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,480
    • กระทู้ 2,481
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    NCSA_THAICERT

    @NCSA_THAICERT

    1
    ชื่อเสียง
    57
    ดูข้อมูลส่วนตัว
    2.5k
    กระทู้
    3
    คนติดตาม
    0
    ติดตาม
    เข้าร่วม ออนไลน์ล่าสุด
    เว็บไซต์ www.ncsa.or.th/?fbclid=IwAR0BqJEC-CJzBs98rlBxUbZkNBgp1g814xdDNNaKnHTrxfqZhPD--ksY68I

    NCSA_THAICERT เลิกติดตาม ติดตาม
    Global Moderator administrators

    Latest posts made by NCSA_THAICERT

    • พบ PATCHCORD Backdoor ใช้ Google Sheets เป็น C2 ในแคมเปญจารกรรมไซเบอร์

      พบ PATCHCORD Backdoor ใช้ Google Sheets เป็น C2 ในแคมเปญจารกรรมไซ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 52006770-2e01-4b9c-bc00-3b00fbacad76-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • DDoS Attack ขนาดใหญ่ทำให้บริการ Threema ขัดข้องเป็นวงกว้าง

      DDoS Attack ขนาดใหญ่ทำให้บริการ Threema ขัดข้องเป็นวง.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 062c6cd5-ce37-4fb6-a228-403517734e65-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • องค์กรระดับ Fortune 500 ตกเป็นเหยื่อของแคมเปญขโมยข้อมูล Azure

      องค์กรระดับ Fortune 500 ตกเป็นเหยื่อของแคมเปญขโม.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 336e96c9-b2cd-4421-9e75-10deb4bbb2dd-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 17 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand a865c16d-98b2-4831-a134-de1fbb77e3b3-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 18 August 2026

      Government/Law/Policy

      • ETSI Launches Approval Process For 17 European Standards Supporting The Cyber Resilience Act
        "ETSI is pleased to announce the availability of the 17 vertical final draft standards developed in the framework of the EU Cyber Resilience Act (CRA) and currently under Public Enquiry. These standards aim to become Harmonised Standards, giving manufacturers a recognised way to demonstrate compliance with the legislation, the so-called “presumption of conformity”. The ETSI EN 304 xxx series standards on cybersecurity requirements have been submitted this summer to 41 member organisations across Europe, including the national standardisation bodies of the European Economic Area. They will be able to provide comments as part of the first phase of the approval procedure. ETSI’s societal partners ANEC (the European consumer voice in standardisation), ECOS (the European Environmental Citizens’ Organisation for Standardisation), ETUC (the European Trade Union Confederation), and SBS (Small Business Standards), collectively known as the Annex III Organisations, will also be able to comment on these standards."
        https://www.etsi.org/newsroom/press-releases/etsi-launches-approval-process-for-17-european-standards-supporting-the-cyber-resilience-act/
        https://www.infosecurity-magazine.com/news/etsi-proposes-17-cybersecurity/

      New Tooling

      • Hazmat: Open-Source Containment For AI Agents
        "Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud credentials, and the pile of configuration in your home directory that has accumulated over years. Hazmat gives the agent a home of its own and shares only the project directory you point it at. Your keys and credential folders sit outside what the session can reach."
        https://www.helpnetsecurity.com/2026/08/17/hazmat-open-source-ai-coding-agent-containment/
        https://github.com/dredozubov/hazmat

      Vulnerabilities

      • 40,000 WordPress Sites Affected By Authentication Bypass Vulnerability In User Profile Builder WordPress Plugin
        "On July 14th, 2026, we received a submission for an Authentication Bypass vulnerability in User Profile Builder, a WordPress plugin with more than 40,000 active installations. This vulnerability makes it possible for unauthenticated attackers to log in as the user with ID 1, which is typically the site administrator, resulting in full administrative takeover of the site. The vulnerability is only exploitable on sites where the plugin’s Automatically Log In setting is enabled. Props to Supakiad S. (m3ez) who discovered and responsibly reported this vulnerability through the Wordfence Bug Bounty Program. This researcher earned a bounty of $975.00 for this discovery."
        https://www.wordfence.com/blog/2026/08/40000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-user-profile-builder-wordpress-plugin/
        https://www.infosecurity-magazine.com/news/wordpress-plugin-flaw-40000-sites/
      • 600,000 WordPress Sites Affected By Arbitrary File Upload Vulnerability In Forminator Forms WordPress Plugin
        "On July 14th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Forminator Forms, a WordPress plugin with more than 600,000 active installations. This vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site compromise. The vulnerability is only exploitable on sites that have a form containing both a File Upload field and a Select field."
        https://www.wordfence.com/blog/2026/08/600000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-forminator-forms-wordpress-plugin/
        https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html
      • Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
        "GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on August 17, 2026, the critical patch release arrived outside the company's usual schedule of twice-monthly updates on the second and fourth Wednesdays, five days after a routine patch release that carried no critical-rated issues."
        https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html
      • Microsoft Working On Defender Patch For ShieldBreak Zero-Day
        "On Friday, Microsoft confirmed it has begun working on a security patch for a Defender zero-day vulnerability named "ShieldBreak." A security researcher who uses the "Nightmare Eclipse" handle disclosed this privilege escalation vulnerability after Microsoft released the August 2026 Patch Tuesday security updates. ​"Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims," a Microsoft spokesperson told BleepingComputer when asked for a statement regarding the new ShieldBreak zero-day."
        https://www.bleepingcomputer.com/news/security/microsoft-working-on-defender-patch-for-shieldbreak-zero-day/
        https://www.bankinfosecurity.com/microsoft-faces-fresh-nightmare-eclipse-zero-day-a-32573
        https://www.malwarebytes.com/blog/bugs/2026/08/shieldbreak-bypasses-microsofts-patch-for-earlier-defender-flaw
      • Windows 11’s Strongest Security Defenses Can Be Bypassed Without a Screwdriver
        "Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already gained privileged access to the system. The attack, named “Download More RAM,” targets a small configuration chip found on Dual In-line Memory Modules (DIMMs), the RAM sticks inside most desktops and laptops. That chip stores information about the memory module, including its capacity and configuration. On several consumer memory modules, nothing stops software from rewriting critical parts of it."
        https://www.helpnetsecurity.com/2026/08/17/windows-11-security-bypass-research/
        https://www.usenix.org/system/files/usenixsecurity26-collins.pdf
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog
      • UNISOC T612 LPE
        "UNISOC (Shanghai) Technologies Co., Ltd. is a top-three global fabless semiconductor company headquartered in Shanghai, specializing in 2G/3G/4G/5G mobile communication, IoT, and smart device chipsets. Formerly Spreadtrum, it serves major brands like Honor, realme, vivo, Samsung, and Motorola, with products in over 140 countries. A critical vulnerability has been identified in the Unisoc modem firmware that allows arbitrary code execution with kernel privileges from the modem context."
        https://ssd-disclosure.com/unisoc-t612-lpe/
        https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html
        https://www.darkreading.com/mobile-security/video-call-exploit-chains-two-flaws-unisoc-modems
        https://www.infosecurity-magazine.com/news/unisoc-modem-flaw-rce-calls/
      • Wiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Through a Flaw In a GitHub Copilot–Assisted PR
        "As part of ongoing security research conducted through Snowflake’s HackerOne vulnerability disclosure program, Wiz Research’s "Red Agent"—an autonomous, AI-powered security research tool—identified a critical GitHub Actions workflow vulnerability in one of Snowflake’s public repositories. This incident highlights a new reality in software development: Critical vulnerabilities can still be introduced and approved within workflows involving AI coding agents, while autonomous AI security agents can rapidly discover and exploit them in the wild."
        https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug
        https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets_0330881554.html
        https://www.theregister.com/security/2026/08/17/an-ai-failed-to-detect-a-bug-in-snowflakes-code-then-another-ai-agent-exploited-it/5288666

      Malware

      • C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
        "In July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbitrary commands, performing reconnaissance, and deploying second-stage payloads. In this blog post, ThreatLabz provides a technical analysis of the identified C2Looper variants, including their network communication protocols and capabilities."
        https://www.zscaler.com/blogs/security-research/c2looper-new-backdoor-likely-tied-ransomware-github-c2
      • Global Exploitation Of CVE-2026–59310 By Suspected Chinese-Nexus APT & Related CVE-2026–59309 Activity
        "QUIRSO’s Incident Response team recently investigated a VMware vCenter compromise that uncovered a coordinated, global exploitation campaign targeting CVE-2026–59310 as well as exploitation of CVE-2026–59309 by a possible different actor. Our investigation enabled us to map affected systems across numerous countries and identify evidence pointing to a Chinese-nexus advanced persistent threat. We continue to track the campaign as it develops. This article presents our current findings on its scale, victimology, infrastructure, tooling and attribution, while acknowledging that the assessment may evolve as new evidence emerges."
        https://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d
        https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html
      • The Gentlemen Ransomware: Inside One Of The Fastest-Growing Extortion Operations
        "The Gentlemen is a financially motivated ransomware-as-a-service (RaaS) double-extortion operation. Originally appearing as affiliate activity under other ransomware programs, the core operators established The Gentlemen as an independent brand in mid-2025 and began recruiting experienced affiliates with a 90% share of ransom proceeds. This generous affiliate share is one of several reasons why the group has been able to expand so quickly. As of this writing, The Gentlemen has claimed more than 750 victims worldwide, and it continues to add new victims at a steady pace. Multiple reporting sources now rank the group alongside Qilin as the most active ransomware groups by victim volume this year."
        https://blog.barracuda.com/2026/08/17/the-gentlemen-ransomware--inside-one-of-the-fastest-growing-rans

      Breaches/Hacks/Leaks

      • Massive Azure Exfiltration Campaign Exposes Millions Of Enterprise Records Via Compromised Credentials (Mcdonald’s, Vodafone, Kyndryl & Others)
        "A significant Azure exfiltration campaign is currently underway, driven by a threat actor actively selling massive enterprise employee databases. These extensive directories were reportedly downloaded directly from the organizations’ Azure/Entra portals utilizing compromised credentials. Over the past week, a threat actor operating under the moniker “TheHatman” has flooded cybercrime forums with massive internal employee directories belonging to several Fortune 500 companies. The actor claims these dumps were extracted directly from the organizations’ Azure Tenants."
        https://www.infostealers.com/article/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others/
        https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/
        https://www.securityweek.com/fortune-500-companies-hit-in-azure-data-theft-campaign/
        https://securityaffairs.com/197322/cyber-crime/mcdonalds-employee-data-appears-in-leak-seller-claims-1-7m-records-stolen.html
        https://www.bankinfosecurity.com/azure-breach-campaign-claims-mcdonalds-vodafone-as-victims-a-32578
        https://www.theregister.com/security/2026/08/17/crook-hawks-millions-of-records-allegedly-plundered-from-corporate-azure-tenants/5288305
      • Pokémon Center Data Breach Exposes Customer Info, Cancels Some Orders
        "Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. While CEVA's systems were compromised in the cyberattack, the exposed records belonged to Pokémon Center customers who submitted orders on the site. The company then shared this information with the logistics provider to fulfill and ship PokemonCenter.com orders."
        https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/
      • Philips And GE Investigating Clop Ransomware Data Theft Claims
        "Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. While a GE spokesperson said the company is aware of the claim and is "working to assess the potential issue," a Philips spokesperson confirmed its systems were breached but said the incident has been contained and didn't affect customers. "Philips has identified ​and contained an attempted cybersecurity compromise of a specific enterprise server related to ⁠internal data," Philips said in a statement shared with Reuters. "This has no impact on customer environments.""
        https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/
        https://www.bankinfosecurity.com/clop-claims-data-theft-from-more-than-40-companies-a-32581
      • Hack On Med Software Firm Hits Half Of Poland's Population
        "A hack into IT systems of MyDr, a Polish provider of electronic medical documentation software, has affected more than 12,000 healthcare facilities and nearly 19 million people in Poland, about half the country's population. Government authorities said they launched an investigation Aug. 12 into the alleged 2.5 terabyte data theft incident, in which cybercriminals appeared to have gained access into MyDr's IT environment no later than Aug. 6."
        https://www.bankinfosecurity.com/hack-on-med-software-firm-hits-half-polands-population-a-32580
        https://therecord.media/poland-probes-mydr-healthcare-software-breach
      • The LiteLLM Supply-Chain Attack — TeamPCP “SANDCLOCK” CI/CD Credential-Harvesting Campaign Via a Backdoored Trivy GitHub Action
        "Resecurity has acquired 152.5 GiB of data following a supply-chain security breach involving LiteLLM, exposing stolen corporate credentials and configuration data linked to thousands of domains. Analysis of the attacker's victim archive from the March 2026 LiteLLM supply-chain compromise (TeamPCP / “SANDCLOCK” stealer): 415,427 on-host secret-capture files harvested from GitHub Actions / CI-CD runners across 898 owners and 2,038 repositories — with the Trivy→LiteLLM attack chain, captured-secret composition, real masked evidence, and named victims."
        https://www.resecurity.com/blog/article/the-litellm-supply-chain-attack-teampcp-sandclock-cicd-credential-harvesting-campaign-via-a-backdoored-trivy-github-action
        https://securityaffairs.com/197377/hacking/litellm-supply-chain-attack-technology-banking-and-healthcare-the-most-affected.html
      • Irregular Details How a Naming Error Let AI Models Attack a Real Company
        "AI safety testing firm Irregular has published its account of an incident in which models being evaluated inside one of its testing environments took offensive security actions against real systems rather than the simulated targets they were meant to attack. The Israeli company, which last year raised $80 million in funding, has been in the news in recent weeks after it came to light that AI models it tested on behalf of OpenAI, Anthropic, and Meta escaped their test environments and carried out real-world attacks. Irregular’s core business involves partnering with major AI labs to stress-test models before they are released to the public, running controlled simulations designed to measure a model’s capabilities in vulnerability research and offensive cyber tasks."
        https://www.securityweek.com/irregular-details-how-a-naming-error-let-ai-models-attack-a-real-company/
        https://www.irregular.com/research/addressing-recent-incidents-ongoing-findings-and-path-forward
        https://therecord.media/irregular-ai-hacking-model-blog
        https://cyberscoop.com/irregular-ai-sandbox-escape-human-oversight/
      • Nearly 750k Had Financial Info, SSNs Leaked In South Carolina Loan Company Breach
        "Cybercriminals breached the cloud system of a debt consolidation loan company in May, stealing troves of sensitive financial information and personal data on about 750,000 customers. The company, Heights Finance, published a warning to customers last week about the data breach and told regulators in Texas on Friday that 734,828 people were affected. Heights Finance operates dozens of personal loan companies across Alabama, Tennessee, Georgia, Texas and South Carolina."
        https://therecord.media/financial-info-leak-debt-consolidator

      General News

      • When Companies Get Specific About AI, Revenue Growth Looks Different
        "Companies that provide specific evidence of how they use AI tend to record stronger revenue growth. Researchers at Carnegie Mellon University and Larridin examined a study universe of 564 companies across 12 industry sectors. Individual analyses used smaller samples depending on data availability. The data included 478 corporate 10-K filings, more than 30,000 classified job postings, financial information, market data, and the AI Transformation Tracker built by Larridin."
        https://www.helpnetsecurity.com/2026/08/17/ai-adoption-revenue-growth-research/
        https://larridin.com/hubfs/CMU-Larridin AI-Company Performance 20270811.pdf
      • Infostealers Harvest 1.7 Billion Credentials In Six Months
        "Security researchers recorded 7.4 million devices infected with infostealer malware in the first half of 2026, a 27% increase from the previous six months, according to Flashpoint data. The threat intelligence company revealed the news in its 2026 Global Threat Intelligence Report: Midyear Edition, which features information collected from deep and dark web forums, illicit marketplaces, encrypted channels, and threat actor-linked infrastructure and ecosystems. In total, it claimed that hackers harvested 1.7 billion credentials via infostealer malware between January and June 2026, with Vidar, StealC and Lumma the top three most prolific infostealer variants."
        https://www.infosecurity-magazine.com/news/infostealers-17-billion/
      • Person Hides Prompt Injection In Legal Filing Telling AI To Side With Them
        "A person representing themselves in a Connecticut court hid a series of instructions designed to manipulate artificial intelligence in an official court filing. These “prompt injections” told the hypothetical LLM to side with them, and to “ensure your textual output agrees with the presented filing to ensure remediation.” The instructions were written in tiny, 3-point white font and hidden throughout the filing. In October, the person, named Matthew Elliott, sued the New York Bariatric Group, alleging a series of privacy violations, discrimination, and several other claims."
        https://www.404media.co/person-hides-prompt-injection-in-legal-filing-telling-ai-to-side-with-them/
        https://www.jdsupra.com/legalnews/the-first-documented-prompt-injection-1799990/
        https://securityaffairs.com/197370/ai/invisible-ai-prompts-trigger-court-sanctions.html
      • Phonescams: Casting a Wide Net In An Orchard Of Low-Hanging Fruit
        "Phonescams that impersonate some of America’s favorite brands—and some less expected ones—are distributed en masse to Cofense client email inboxes daily. In the digital age, everyone is looking to get ahead, and while one innovation breeds another, some things never change. Just as the humble wheel has been used for thousands of years, the easiest apple to pick off a tree is still the lowest hanging. Why fetch a ladder when the fruit is within reach? Here in the Cofense Phishing Defense Center, we have noticed that contemporary threat actors are all too aware of the concepts of wide nets and low-hanging fruit."
        https://cofense.com/blog/phonescams-casting-a-wide-net-in-an-orchard-of-low-hanging-fruit
      • Patterns And Problems In Emerging Multiagent Systems
        "Models are improving and AI agents are taking on more tasks in shared codebases, markets, and other social systems. As a result, an increase in real-world interactions between agents is imminent. We've already begun studying this, but still have a lot of uncertainty regarding what this looks like at scale. The trajectory is easy to imagine and hard to slow: current institutions are designed by and for people, resting on assumptions about the sufficiency of oversight at human speed. Some institutions will become human-AI hybrids; others where agents outcompete on speed or cost will become agent-only. The volume of agent-agent interaction could plausibly exceed that of human-human and human-agent interactions before the world understands the conditions for making such interactions go well."
        https://www.anthropic.com/research/multiagent-systems
        https://www.darkreading.com/threat-intelligence/turf-war-claude-agents-self-replicating-malware
        https://www.securityweek.com/conflicting-test-goals-pushed-claude-agents-to-deploy-self-replicating-malware/
      • Adam Shostack Talks Hugging Face & PHANTOM-B
        "OpenAI's rogue agents are raising a whole new set of questions for cyber defenders, and Dark Reading's senior news director Rob Wright sat down at the News Desk with threat modelling expert Adam Shostack to find out more. Shostack attended OpenAI's recent presentation on its findings in the wake of their AI agents going rogue, and he posed fundamental questions the industry will have to reckon with: namely, who is held liable when AI agents do real damage?"
        https://www.darkreading.com/vulnerabilities-threats/adam-shostack-talks-hugging-face-phantom-b

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 7e726480-ef24-4b7b-b7b6-b76eab99d0ab-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 17 August 2026

      Vulnerabilities

      • Chinese Loongson Processors Have Leaky Caches, Researchers Find
        "Researchers from Germany’s Helmholtz Center for Information Security have found processors made by China’s Loongson have leaky caches that attackers could use to seek specific data. Loongson has developed its own LoongArch instruction set architecture (ISA) that blends approaches used by MIPS and RISC-V. On a site called LoongLeakAttack.com, the researchers explain that they found the leaky cache using a fuzzer, then noticed that the LoongArch ISA manual mentions an instruction that leaves 32 bits of a memory register in an “uncertain” state."
        https://www.theregister.com/security/2026/08/13/chinese-loongson-processors-have-leaky-caches-researchers-find/5287137
        https://loongleakattack.com/
      • Unpatched GeoServer Zero-Day Targeted In Active Exploitation Attempts, Can Lead To RCE
        "A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remains unpatched. It was first disclosed on August 12, 2026, at 10:46 UTC, by a researcher named @q1uf3ng on X. "GeoServer jsonArrayContains unauthorized SQL injection, and in the case of the sa [system administrator] database, it's naturally possible to achieve RCE," the researcher said."
        https://thehackernews.com/2026/08/unpatched-geoserver-zero-day-targeted.html
        https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/
        https://securityaffairs.com/197216/hacking/geoserver-zero-day-is-already-being-probed-thats-the-problem.html

      Malware

      • Hackers Exploit MacOS Screen Sharing Flaw To Deploy Monero Miner
        "The Netherlands’ National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. The security issue lies in macOS Screen Sharing, a built-in remote desktop feature that allows remote desktop control over a network, using the VNC protocol over TCP port 5900. Apple fixed CVE-2026-65400 on August 6 in macOS Tahoe 26.6.1 and earlier releases. The flaw allows network-based attackers to gain access without valid credentials."
        https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/
        https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html
        https://securityaffairs.com/197234/uncategorized/macos-screen-sharing-flaw-exploited-to-deploy-monero-miners.html
      • Max Severity SAP Commerce Cloud Flaw Now Targeted In Attacks
        "A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. Commerce Cloud (formerly known as SAP Hybris) is a cloud-based e-commerce platform used by online stores owned by high-profile global brands and large retailers. Tracked as CVE-2026-58231, this critical flaw stems from an improper authorization weakness in the core Data Hub Adapter extension for Commerce Cloud that threat actors without privileges can exploit in low-complexity attacks to execute arbitrary code."
        https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/
        https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html
        https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html
      • ExfilSquad: New Data Extortion Group Leaks Microsoft D365 Data, Likely Linked To Misconfigured Power Pages
        "Fortra Intelligence and Research Experts (FIRE) have developed specialist tooling to support certain customers when faced with ransomware and data extortion claims. We monitor for new disclosures, including public and dark web sources, to provide early alerting to customers and support investigations. As part of this process, we also see activity that is not directly related to customers. When there is a significant interest, and we have new intelligence to share, we aim to share information with the security community to aid understanding of ransomware and extortion actors and campaigns."
        https://www.fortra.com/blog/exfilsquad-data-extortion-group-ransoming-microsoft-d365-data
        https://www.infosecurity-magazine.com/news/exfilsquads-13-organizations/
      • AmnesiaStealer: a Multi-Stage Rust-Based MacOS Infostealer That Hijacks Chromium Browsers
        "Jamf Threat Labs discovers and investigates AmnesiaStealer, a multi-stage Rust-based macOS infostealer spread through a counterfeit GitHub download page that captures the login password, reaches for macOS bypasses Apple has already patched, and can hand the operator live, hidden control of the victim's Chromium browser to steal authenticated sessions."
        https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/
        https://thehackernews.com/2026/08/amnesiastealer-hijacks-chromium.html
        https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/
        https://www.infosecurity-magazine.com/news/macos-infostealer-spread-clickfix/
        https://www.securityweek.com/amnesiastealer-macos-malware-steals-data-controls-browser-sessions/
        https://securityaffairs.com/197190/malware/amnesiastealer-gives-attackers-live-control-of-victims-macos-browsers.html
      • APT Group HoneyMyte Upgrades CoolClient: The Backdoor Gets a Kernel-Level Windows Rootkit
        "CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia. It supports such capabilities as keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and plugin-based extensions. Since its first public disclosure by Sophos in 2022 and subsequent analysis by Trend Micro in 2023, CoolClient has continued to evolve. In 2025, we analyzed a newer variant that introduced clipboard theft and HTTP traffic interception for credential harvesting."
        https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
        https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html
        https://securityaffairs.com/197274/apt/mustang-panda-upgrades-coolclient-with-a-kernel-rootkit.html
      • Return Of The Cookie Monster
        "In Dough No! Revisiting Cookie Theft, we looked at how Chromium’s Application Bound Encryption (ABE) in Windows made cookie theft significantly harder. For operators, this meant they needed to inject into a browser process, utilize remote debugging, or install an extension to steal cookies. This blog post dives deeper how to enable the remote debugging protocol without having to launch it via the --remote-debugger-port argument. With the release of Chrome 136+, Google announced additional protections against stealing cookies via remote debugging. To enable the Chrome DevTools Protocol (CDP) an alternate --user-data-dir needed to be supplied with --remote-debugger-port causing the existing cookies to be abandoned as a new data directory would be used. These changes forced operators to think more carefully about their process context before stealing cookies."
        https://specterops.io/blog/2026/08/13/chrome-devtools-protocol-cookie-theft/
        https://thehackernews.com/2026/08/chrome-devtools-technique-enables.html
      • Fake Zoom Installer Uses .NET Downloader To Deliver Overlord RAT On MacOS
        "Jamf Threat Labs recently identified a campaign using a fake Zoom installer to deliver a configured build of Overlord, an open-source remote access framework, hosted on attacker-controlled infrastructure. The downloader is a macOS ARM64 Mach-O binary named ZoomMeetings, built as a self-contained .NET 10 single-file application with the .NET runtime bundled inside. Rather than the Go or Rust we typically see in macOS malware, this downloader uses .NET, whose cross-platform support means the same codebase also targets Windows. Building macOS malware using the .NET framework is fairly uncommon, so naturally this caught our attention. Our curiosity led to a number of interesting finds that we'll share in this blog post."
        https://www.jamf.com/blog/fake-zoom-installer-delivers-overlord-rat-macos/
      • Large-Scale DDoS Attacks Disrupted Threema Secure Messaging Service
        "Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. ​Organizations using Threema On-Prem did not experience any issues because they rely on their own infrastructure. In a post-mortem report on Friday, the end-to-end encrypted instant messaging service said that the attacks were difficult to defend against because the threat actor constantly changed patterns."
        https://www.bleepingcomputer.com/news/security/large-scale-ddos-attacks-disrupted-threema-secure-messaging-service/
        https://securityaffairs.com/197353/hacking/ddos-attacks-cause-major-threema-outages.html
      • PATCHCORD: New Malware Cluster Targets Afghan Telecom And South Asian Critical Infrastructure
        "Acronis Threat Research Unit (TRU) has identified an ongoing campaign delivering a previously undocumented custom backdoor against Afghan telecom providers and South Asian critical infrastructure organizations. The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools. Infrastructure pivoting uncovered SHEETCORD, a Go-based implant that builds on PATCHCORD's capabilities while abusing Google Sheets for C2 communication. The malware was actively distributed through a domain impersonating India's National Informatics Centre (NIC)."
        https://www.acronis.com/en/tru/posts/patchcord-new-malware-cluster-targets-afghan-telecom-and-south-asian-critical-infrastructure/
        https://securityaffairs.com/197266/intelligence/apt36-suspected-in-patchcord-espionage-campaign-using-google-sheets-c2.html

      Breaches/Hacks/Leaks

      • Shell Investigates 'potential Incident' After Clop Data Theft Claims
        "Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. Shell is a British multinational energy conglomerate and one of the world's top three oil and gas companies, after Chevron and ExxonMobil. It has 85,000 employees in more than 70 countries and operates a massive network of tens of thousands of service and recharge stations that serve over 20 million customers daily. According to a recent post on Clop's dark web data leak site, the allegedly stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans."
        https://www.bleepingcomputer.com/news/security/shell-investigates-potential-incident-after-clop-data-theft-claims/
      • RingCentral Data Breach Exposed Info Of 1.6 Million Accounts
        "The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned. RingCentral is a cloud-based collaboration and communication platform used by over 600,000 businesses for services such as calling, messaging, and voicemail. The company disclosed the incident on July 28, revealing that its systems were compromised following what it described as a "sophisticated social engineering campaign.""
        https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/
        https://haveibeenpwned.com/Breach/RingCentral
        https://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/
      • Scottish Govt Suffers Potentially Widening Data Breach At Prosecutor's Office
        "A contractor has leaked Scottish government employees' personal information, and the full scope of the breach may be far greater than what is currently being reported. On Aug. 13, Scotland's Crown Office and Procurator Fiscal Service (COPFS) — the government's public prosecution service and death investigation authority — disclosed that an unidentified external supplier had experienced a data breach. The breach affected some of its employees' personally identifying information (PII)."
        https://www.darkreading.com/cyberattacks-data-breaches/scottish-govt-data-breach-prosecutors-office
      • 7.3M Chess.com Records Leaked, And The Data Is Real
        "A 15.5 GB file containing 7,337,395 chess.com user records is being handed out free on two data-leak forums. It carries email addresses, usernames, real names, countries, ratings, subscription tiers and internal advertising-audience tags. Ransomnews verified the data against the file itself. It is genuine chess.com data, and it is days old, not a recycled dump. What it is not, on the evidence, is a break-in: every structural signal points to large-scale scraping of a non-public interface rather than a compromise of chess.com’s systems."
        https://ransomnews.com/chess-com-leak-7-million-2026/
        https://securityaffairs.com/197174/breaking-news/chess-com-leak-exposes-7-3-million-users-evidence-points-to-scraping.html
      • LiteLLM Supply Chain Attack: Inside The AI Breach That Exposed 2,500+ Companies
        "New analysis published in August 2026 has overturned the original timeline of the LiteLLM supply chain attack. The well-known 40-minute PyPI window was not the beginning of the exposure. It was the final stage of a five-day collection run that started with the compromise of the Trivy scanner. Record-level data now maps exposure across more than 2,500 organizations and roughly 434,000 captured CI/CD files. SOCRadar’s analysis found that 95% of affected organizations appeared in the dataset before the malicious LiteLLM packages were published on March 24."
        https://socradar.io/blog/litellm-supply-chain-attack/
        https://www.securityweek.com/trivy-not-litellm-behind-the-2500-org-compromise/
      • France Investigates Tax Authority Breach After Hacker Claims 600,000 Victims
        "France’s tax authority has confirmed that hackers breached its information systems and extracted data on individuals and businesses. France’s Economy Ministry said late Thursday that an attacker gained unauthorized access to systems at the Directorate General of Public Finances, or DGFiP, in late June after stealing or misusing someone’s identity. The intrusion allowed the attacker “to view and extract data belonging to individuals and businesses,” according to the ministry."
        https://therecord.media/french-tax-authority-dgfip-confirms-data-breach
        https://securityaffairs.com/197287/cyber-crime/sophisticated-cyberattack-exposes-data-of-678000-french-taxpayers.html
      • Uber Freight Keeps On Trucking After Extortion Crew Breaks In
        "Uber Freight says it is investigating a "data security incident" days after the Helix extortion group listed the company on its data leak site on August 6. Helix claims to have stolen nearly 1 million files from mailboxes, OneDrive accounts, the accounts receivable department, and other repositories. An Uber Freight spokesperson told The Register that the incident was under investigation but had not disrupted the company's daily operations."
        https://www.theregister.com/security/2026/08/12/uber-freight-keeps-on-trucking-after-extortion-crew-breaks-in/5286782
      • SafePal Data Breach Impacts 39,798 Customers, Stolen Info For Sale
        "Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. SafePal says the breach impacts customers who placed orders between March 2, 2025, and April 11, 2026, exposing their names, email addresses, shipping addresses, phone numbers, and purchase information."
        https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-39-798-customers-stolen-info-for-sale/

      General News

      • Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw
        "Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers’ bank accounts. The theft, investigated by the Brazilian and German federal police agencies, occurred over four days in November 2023 and caused losses of around €30 million ($34.6 million). While neither the Brazilian Federal Police nor Germany's BKA named the affected German financial institution, Brazilian media identified it as Commerzbank, a major European financial institution that generates more than €11.1 billion ($12.8 billion) in annual revenue."
        https://www.bleepingcomputer.com/news/security/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw/
        https://therecord.media/investigation-into-banking-hack-leads-to-arrests-germany-brazil
      • Data Analyst Sent To Prison For Stealing Data, Extorting Employer
        "A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. Brightly is a Software-as-a-Service (SaaS) company formerly known as SchoolDude, which was acquired by Siemens in August 2022. Brightly employs over 700 people and provides asset management and maintenance software to more than 12,000 clients worldwide. 27-year-old North Carolina man Cameron Curry (also known as "Loot") was found guilty in March of orchestrating an "extensive cyber extortion scheme" targeting his employer."
        https://www.bleepingcomputer.com/news/security/data-analyst-sent-to-prison-for-stealing-data-extorting-employer/
      • Ransomware Threats In The Americas H1 2026: Dissecting The Regional Attack Patterns And Dominant Actors
        "The Americas carried the heaviest ransomware burden of any region on the planet in the first half of 2026. According to Cyble Research and Intelligence Labs (CRIL), North and South America combined experienced 2,188 documented ransomware attacks between January and June 2026. That single figure — 2,188 attacks — represents more than 57% of the 3,836 ransomware incidents CRIL tracked worldwide, making the Americas the undisputed center of gravity for global ransomware operations."
        https://cyble.com/blog/ransomware-threats-in-america-h1-2026/
      • What Boards Need To Know About Tech Risk
        "Most boardrooms are built to evaluate opportunity, growth initiatives, tech acquisitions, and operational improvements. The discussion centers on a familiar equation: investing in X to generate Y return. That mindset is essential for scaling a business. But it often creates dangerous blind spots in digital infrastructure. Unlike revenue-generating projects, many of the most important technology investments don't produce visible upsides."
        https://www.darkreading.com/cyber-risk/what-boards-must-know-tech-risk
      • The Hardest Part Of Agentic AI May Be Rebuilding The Business
        "Organizations expect AI agents to change how work gets done, driving productivity and growth while allowing employees to focus on higher-value tasks. Few, however, have the processes and workflows needed to realize those benefits, according to Deloitte’s latest research. About half of surveyed leaders say they understand how AI agents will affect their future operating model. Three main challenges limit wider adoption: the lack of a unified and accessible data foundation, limited trust in and governance of AI agents, and the cost and complexity of integration."
        https://www.helpnetsecurity.com/2026/08/14/deloitte-agentic-ai-readiness-gap-report/
      • Weak IAM Affects Up To 98% Of Cloud Environments
        "Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing encryption, exposed services, and logging gaps. CISA now mandates baseline cloud configuration practices for US federal agencies. More than two-thirds of midmarket organizations use multiple cloud providers, each with its own security model, terminology, and configuration settings. The same security issue can manifest differently across AWS, Azure, and Google Cloud, often requiring a different approach to identify and remediate, according to Intruder’s 2026 Cloud Security Index report."
        https://www.helpnetsecurity.com/2026/08/14/intruder-cloud-misconfiguration-trends-report/
      • Black Hat USA 2026: Will Vulnerability Discovery Eventually Decline In The AI Era?
        "The accelerated discovery of previously unknown software vulnerabilities has been making headlines for months. It’s an issue that has even led the US government to create a vulnerability clearing house named Gold Eagle to coordinate research efforts in vulnerability discovery, mitigation and fixes. An indication of the broader pressure facing cyber-defenders can be drawn from the sheer number of patches being delivered in Microsoft’s Patch Tuesday through the last four months: 169 CVEs in April, 118 CVEs in May, 571 CVEs overall in June (including 208 direct Microsoft CVEs) and another 622 vulnerabilities in July that included zero-days under active exploitation."
        https://www.welivesecurity.com/en/business-security/black-hat-usa-2026-vulnerability-discovery-decline-ai-era/
      • North Korean Remote Workers Are Infiltrating Government And Businesses: How To Expose Them Before Hiring
        "Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems companies spend millions trying to protect. That risk is no longer theoretical. The FBI is now investigating a North Korean remote IT worker who reportedly worked for a U.S. federal agency. For CISOs, the priority is clear: spot the warning signs before a fraudulent hire becomes trusted access."
        https://thehackernews.com/2026/08/north-korean-remote-workers-are.html
      • AI Can Find Bugs, But Human Knowledge Still Proves Them
        "Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, explain unfamiliar APIs, and run repetitive testing workflows at impressive speed. That is a real advantage for security teams. It also creates a new kind of pressure, because the industry can now produce more vulnerability-looking output than ever before."
        https://www.sans.org/blog/ai-can-find-bugs-but-human-knowledge-still-proves-them
      • Drop Something? Don’t Worry, Someone Caught It
        "Every day, tens of thousands of domain names expire and become available for registration. Some fade away and are never seen again. Others get a second chance. We refer to these as dropcatch domains: the domain was dropped, became available again, and someone caught it. This isn’t just our name; it’s widely used. There’s even an auction service called DropCatch[.]com. During the first half of 2026, we observed over 50k dropcatch domains a day in the gTLDs alone—when we add in various ccTLDs that number rises to around 65k. That’s an astounding number when you put it next to the total of new registrations every day. For the gTLDs, nearly 20% of all observed registrations are dropcatch. In other words, one of every five newly registered domains had a prior life, sometimes several."
        https://www.infoblox.com/blog/threat-intelligence/drop-something-dont-worry-someone-caught-it/
        https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html
        https://securityaffairs.com/197251/uncategorized/crooks-are-buying-your-expired-domains-and-using-them-to-deliver-malware.html
      • AI Won't Solve Cybersecurity Burnout. Better Leadership Might
        "Cybersecurity has spent years talking about workforce shortages. More recently, AI has entered the conversation as a possible solution. It can help teams analyze alerts, identify threats, automate investigations, and complete routine tasks faster than ever. That shift is already underway. According to SANS workforce research, 74% of cybersecurity teams are changing structures and role assignments because of AI, with entry-level SOC and security analyst roles among the most affected. Yet workloads, complexity and stress continue to rise. The latest ISSA workforce study found that 68% of professionals believe their jobs have become harder over the past two years, and nearly half have considered leaving their current role."
        https://blog.barracuda.com/2026/08/14/ai-won-t-solve-cybersecurity-burnout--better-leadership-might

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 7b745a34-7080-45b9-8405-28899a9c7f37-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบความพยายามใช้ประโยชน์จากช่องโหว่ SAP Commerce Cloud เสี่ยงรันโค้ดบนระบบ

      พบความพยายามใช้ประโยชน์จากช่องโหว่ SAP Commerce Clo.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 35acf675-b145-44b4-ab65-8d41d42e0cc2-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CTM360 พบแคมเปญ Phishing สมัครงานกว่า 3,000 URL ใช้เทคนิค Browser-in-the-Browser ขโมย Credential

      CTM360 พบแคมเปญ Phishing สมัครงานกว่า 3,000 URL ใช้เทคนิค Bro.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 9548d032-b9a5-41df-b758-4162bdc6eebc-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบกลุ่มผู้ไม่หวังดีกว้านซื้อโดเมนที่หมดอายุแล้ว เพื่อใช้เป็นฐานในการโจมตีทางไซเบอร์และแพร่มัลแวร์

      พบกลุ่มผู้ไม่หวังดีกว้านซื้อโดเมนที่หมด.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand df49e788-349b-46f2-ad92-23c2e992b1aa-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 15 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 15 รายการ เมื่อวันที่ 13 สิงหาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-225-01 AVEVA Enterprise SCADA
      • ICSA-26-225-02 Haiwell IoT Cloud HMI Gateway
      • ICSA-26-225-03 Johnson Controls Inc. Airwall
      • ICSA-26-225-04 Hitachi Energy APM Edge Product
      • ICSA-26-225-05 ANDRITZ HIPASE-250 and 250 SCALA
      • ICSA-26-225-06 Siemens RUGGEDCOM APE1808
      • ICSA-26-225-07 Siemens License Server (SLS)
      • ICSA-26-225-08 Siemens Desigo DXR and PXC Controllers
      • ICSA-26-225-09 Siemens Siveillance Video
      • ICSA-26-225-10 Siemens Parasolid
      • ICSA-26-225-11 Siemens Simcenter Femap
      • ICSA-26-225-12 Siemens Solid Edge
      • ICSA-26-225-13 Siemens LOGO! Soft Comfort
      • ICSA-26-225-14 Johnson Controls Metasys
      • ICSMA-26-225-01 Flow Neuroscience FL-100

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5659c9e0-8038-44d2-9544-47a194eab180-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT