NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,441
    • กระทู้ 2,442
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • Thermo Fisher ออกแก้ช่องโหว่ซอฟต์แวร์วิเคราะห์ DNA เสี่ยงกระทบความถูกต้องของข้อมูล

      Thermo Fisher ออกแก้ช่องโหว่ซอฟต์แวร์วิเคราะห์ DNA เ_.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 7044e34d-f95f-4124-91db-952e1a575eaf-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • PNLD ยืนยันเหตุข้อมูลรั่วไหล กระทบเจ้าหน้าที่ตำ

      PNLD ยืนยันเหตุข้อมูลรั่วไหล กระทบเจ้าหน้าท_0.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 7ef974d4-b620-4c69-8d67-e72be4e7c961-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการโจมตี Pass-ta-key มัลแวร์บน Windows สามารถขโมยข้อมูล Passkey จาก Google Password Manager ได้

      พบการโจมตี Pass-ta-key มัลแวร์บน Windows สามารถขโมยข้อ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand f1436953-62dd-4b59-b3b3-5d0fcd232626-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 2 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 2 รายการ เมื่อวันที่ 4 สิงหาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-216-01 Acrisure Karr Anti-theft
      • ICSMA-26-216-01 Thermo Fisher Applied Biosystems 3100 and 3500 Series Genetic Analyzers

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง

      https://www.cisa.gov/news-events/ics-advisories

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 1e8b4b59-8607-44de-b280-03dc4d81573f-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 3 รายการลงในแคตตาล็อก

      เมื่อวันที่ 4 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 3 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-9198 IBM Langflow Code Injection Vulnerability
      • CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
      • CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ddcf667c-65ab-4c7e-93bd-95a301ec5c9c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 05 August 2026

      Healthcare Sector

      • Thermo Fisher Applied Biosystems Genetic Analyzers
        "Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results."
        https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-216-01

      Industrial Sector

      • Acrisure KARR BT And DR-100
        "Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-216-01

      New Tooling

      • OWASP’s Subtractive Security Project Measures The Attack Paths You Erased
        "An attacker who talks a user into opening an attachment gets whatever that machine still permits: a service account with rights across the domain, an outbound route to anywhere, a scripting engine sitting there for the taking. Christopher Frenz wants those capabilities deleted before anyone writes a detection rule for them. Frenz leads the OWASP Subtractive Security Top 10, a set of nine lists published alongside an engineering standard called Path Erasure Rate. Organizations that answered the last decade by stacking EDR, SIEM, and NDR now pay for alerts on paths they could have removed. The lists name which paths to remove, by platform."
        https://www.helpnetsecurity.com/2026/08/04/owasp-subtractive-security/
        https://github.com/OWASP/OWASP-Subtractive-Hardening-Top-10

      Vulnerabilities

      • New cPanel Critical Flaw Could Let Hosting Customers Run SQL As Database Root
        "cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The database bug is tracked as CVE-2026-58048 (CVSS 4.0 score: 9.4) and affects all supported versions of cPanel & WHM, along with WP Squared. Reaching it requires a valid cPanel account and access to the MySQL/MariaDB feature. From there, the vendor says the account holder could execute arbitrary database commands with full administrative privileges."
        https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html
        https://securityaffairs.com/196595/security/cve-2026-58048-cpanel-bug-enables-full-database-administrator-access.html
      • CISA Adds Three Known Exploited Vulnerabilities To Catalog
        "CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-9198 IBM Langflow Code Injection Vulnerability
        CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
        CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog
      • New TP-Link Router Vulnerabilities: Exploiting Zero Touch Provisioning
        "For more than three years, Forescout Research – Vedere Labs has reported on the increasing exploitation of network infrastructure devices, such as routers and firewalls. Previous research, including Sierra:21 and Dray:Break, and observed threat actor activity by the larger research community targeting these devices, focused on individual vulnerabilities that enable remote code execution. However, the growing use of Zero-Touch Provisioning (ZTP) by IT teams creates opportunities for attacks at a much larger scale. Network vendors offer ZTP ecosystems in which provisioning servers push configurations and updates to client devices, including routers, switches, gateways, and wireless access points. This enables devices to be configured with little or no manual intervention."
        https://www.forescout.com/blog/new-tp-link-router-vulnerabilities-exploiting-zero-touch-provisioning/
        https://support.omadanetworks.com/us/document/130627/
        https://www.bleepingcomputer.com/news/security/tp-link-patches-omada-ztp-flaws-allowing-hackers-to-breach-networks/
        https://www.securityweek.com/tp-link-omada-ztp-vulnerabilities-chain-into-full-network-takeover/
      • Tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
        "tl;dv (Too Long; Didn't View) is an AI meeting recording platform. It drops a bot into your Google Meet, Zoom, or Teams call, records everything, transcribes it, and generates summaries with AI. Over 2 million users. Backed by investors. Endorsed by half of LinkedIn's sales influencer community. They store your sales calls, job interviews, performance reviews, internal strategy sessions. The kind of content where someone says "this call is being recorded" and everyone nervously laughs and then shares trade secrets for 45 minutes."
        https://bobdahacker.com/blog/tldv-hack
        https://www.darkreading.com/application-security/ai-notetaker-spy-government-corporate-video-calls
      • I'll Just Call You: Agent-To-Agent Privilege Boundary Failures In CI/CD On Google's ADK Repository
        "Pillar Security researchers have identified the first practical, real-world case of agent-to-agent exploitation in a multi-agent system in a real production environment, a class of attack not seen in real production systems until now. A case where one AI agent can be used to attack another, turning a benign automation into a path that ends in a potential software supply chain compromise. We found the exploit in google/adk-python, the repository behind Google's Agent Development Kit for Python, an SDK many teams use to build their own agents."
        https://www.pillar.security/blog/ill-just-call-you-agent-to-agent-privilege-boundary-failures-in-ci-cd-on-googles-adk-repository
        https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html
        https://www.securityweek.com/gemini-agent-to-agent-attack-exposed-secrets-enabled-pull-request-tampering/
        https://www.theregister.com/security/2026/08/03/google-dev-kit-spurs-first-ever-agent-on-agent-violence/5282496

      Malware

      • Inside Greatness: Telegram-Distributed M365 AiTM PhaaS
        "ZeroBEC threat research on the Greatness phishing-as-a-service (PhaaS) platform, a commercially distributed kit sold via Telegram that combines adversary-in-the-middle (AiTM) credential and token theft with device code phishing in a single operator product. This investigation began with a live campaign that exploited spoofed RingCentral emails and customer-side safe sender exclusions to bypass email gateway controls and deliver phishing lures targeting Microsoft 365 accounts. Panel access, infrastructure testing, and cross-domain analysis revealed the full operator ecosystem, shared backend, and post-compromise tradecraft."
        https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing
        https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/
        https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html
      • 77 "evil Twin" Open VSX Extensions: 19 Copy Private Repo And CI Data To a New Domain
        "Between July 26 and August 1, 2026, our monitoring systems identified 77 Open VSX extensions that beacon to the same newly registered domain. Each one republishes the name, namespace and description of a real, unrelated extension at a low version number, almost always 0.0.1, under an account that does not own the namespace and does not belong to the original author [example 1, example 2, example 3]. The bundled extension.js is swapped for a beacon. In most of the packages it sends little more than the machine's hostname. In nineteen of them it sends a detailed description of the machine, the repository open in the editor, and the CI system the editor is running inside. The Open VSX listings described this under a section headed “Telemetry.”"
        https://www.manifold.security/blog/open-vsx-evil-twin-extensions
        https://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/
      • Keyv And Friends Compromised In Active Shai-Hulud Supply Chain Attack
        "On August 4, 2026, attackers compromised the GitHub account of the maintainer behind keyv, a key-value storage library with roughly 127 million weekly npm downloads, and used that access to inject a credential-stealing worm across the entire package family. The same maintainer owns cacheable (29M downloads/month), flat-cache (565M downloads/month), file-entry-cache (557M downloads/month), and several other widely-used caching utilities, all of which were swept up in the same attack. The compromise was carried out by pushing malicious files directly to the main branch and then immediately cutting a new release, meaning the poisoned versions were published to npm with valid provenance signed by GitHub Actions."
        https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack
        https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack
        https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/
        https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html
        https://www.bankinfosecurity.com/worm-targets-more-than-2000-npm-package-versions-a-32412
        https://cyberscoop.com/supply-chain-attack-malware-mini-shai-hulud-teampcp/
        https://hackread.com/shai-hulud-npm-worm-poisoning-1280-packages/
      • “Keep Going, Bro. You’ve Got This!” A Data-Driven Look At How Adversaries Are Weaponizing AI
        "Artificial intelligence (AI) and associated language models are now ubiquitous and heavily used in both personal and professional contexts to streamline tasks and expand capabilities. With AI being used everywhere and by almost everyone, one of the biggest questions is how malicious actors are taking advantage. Fortunately, actors make mistakes and chatbots leave artifacts. Leveraging cloud-based AI models leaves behind a variety of artifacts, most notably a prompt log. These logs can take on a variety of shapes and sizes, but they are left on endpoints that are running various applications, such as Claude Code, CodeX, Cursor, or Gemini."
        https://blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/
        https://www.infosecurity-magazine.com/news/talos-attackers-split-tasks-evade/
        https://www.theregister.com/security/2026/08/04/bypassing-ai-guardrails-is-so-easy-a-script-kiddie-can-do-it/5282973
      • Incident Report: Unsanctioned Agent Behaviour During Cyber Testing
        "AISI’s role is to evaluate and understand the capabilities of frontier AI models, surfacing potential risks before they reach the public. To assess what these models can do, including whether they could be misused for cyberattacks, we test them under deliberately permissive conditions: with access to the open internet, and with some safety filters disabled. On 28th July 2026, AISI's Security Team detected unusual data transfers leaving our research systems during a routine cyber evaluation. On investigation, we found that some of the agents being tested had engaged in sustained, potentially harmful activity directed at real people and organisations. We declared a security incident and, within roughly one hour of discovery, had contained it and begun a full investigation."
        https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing
        https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security Incident INC-2026-07-28-01.pdf
        https://cyberscoop.com/aisi-openai-report-unsanctioned-ai-model-hacks/
      • Analyzing SMOKE#SCREEN: ScreenConnect RMM Abuse, Cloudflare Tunnels, And Trusted Software Lures
        "Securonix Threat Research has been tracking an active, multi-wave campaign we are calling SMOKE#SCREEN, in which threat actors use a rotating collection of social engineering lures themed around Zoom software updates, business document reviews, and system maintenance utilities to deliver silent ScreenConnect Remote Monitoring and Management (RMM) agent installations. The campaign relies on a toolkit of VBScript droppers, batch file loaders, compiled .NET executables and a HTML phishing page, all ultimately pointing to a live WsgiDAV-based staging server at 207.174.0.143:8080. Victims who execute any of the initial access files end up with a fully functional ScreenConnect agent silently installed and beaconing to one of three attacker-controlled relay servers, providing the threat actor with persistent, legitimate-looking remote access to compromised hosts."
        https://www.securonix.com/blog/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels/
        https://www.darkreading.com/cyberattacks-data-breaches/latest-rmm-fueled-phishing-attack-exposes-threat-actor-playbook
        https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html
      • QuickFox Supply Chain Attack Used To Deploy FDMTP Implant
        "FortiGuard Labs is tracking a campaign associated with a long-standing supply chain attack on the QuickFox application. QuickFox is a VPN proxy and game accelerator typically employed by Chinese users to speed up access to Chinese-based resources, often to improve video game user experience. Active since at least August 2025, the supply chain attack involves a trojanized version of the QuickFox application. The attack is delivered via a modified Electron renderer HTML file used to download and execute a JavaScript-based loader. Upon execution, the JavaScript loader fingerprints the victim endpoint to determine if it’s a valid target before downloading and installing an FDMTP implant. Analysis of infrastructure related to this campaign indicates active development, and infrastructure continues to be active at the time of publishing."
        https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant
      • Consumer Protection Tuesday: A Fake IRS "Digital Asset Compliance Portal" Letter Is Targeting Crypto Holders
        "Scammers are mailing physical letters in subtle, unmarked envelopes that look like they come from the IRS, telling crypto holders they must "enroll" in a so-called Digital Asset Compliance Portal (DACP) before a deadline. The letter includes a QR code that leads to a convincing fake IRS website."
        https://www.coinbase.com/en-gb/blog/consumer-protection-tuesday-fake-irs-scam
        https://www.helpnetsecurity.com/2026/08/04/fake-irs-crypto-letters-compliance-portal-scam/
      • WhatsApp Account Takeover Scam Asks You To “vote For My Friend”
        "A scam is spreading through WhatsApp with the goal of taking over victims’ accounts entirely. It starts with a message that feels harmless and familiar. Someone—often a contact whose account has already been compromised—asks you to support a friend or relative of theirs by voting in an online contest. The theme varies: a ballet performance, a dog competition, a school event. The wording is casual, sometimes urgent, and designed to get a quick click."
        https://www.malwarebytes.com/blog/scams/2026/08/whatsapp-account-takeover-scam-asks-you-to-vote-for-my-friend
        https://www.infosecurity-magazine.com/news/whatsapp-voting-scam-linked/
      • How Legitimate Cloud Platforms Enable Phishers To Bypass MFA
        "Threat actors are increasingly exploiting legitimate cloud services to evade detection and streamline the deployment of their scam infrastructure. Cloud hosting services and decentralized networks have become primary platforms for hosting phishing pages and sites. Throughout 2025 and 2026, we have observed phishing operators steadily migrate toward platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS. This post analyzes the mechanics of a real-life adversary-in-the-middle (AitM) attack in a cloud environment and presents detailed statistics on the platforms and domains phishers abuse most frequently."
        https://securelist.com/cloud-platforms-in-phishing/120832/
      • AI-Enabled Email Accounts Could Become The Ultimate Insider Threat
        "In June, Barracuda’s Red Team detailed a multilayered controlled attack that showed how attackers gain access to a victim’s account. Once an attacker has access, the next steps depend on their objectives. In most cases, however, attackers first seek to establish persistence, escalate privileges and extend their access within the environment. Attackers increasingly try to achieve this by abusing legitimate tools already present in the environment, a technique known as “living off the land.” This commonly takes the form of PowerShell scripts or the misuse of remote access software. Our controlled attack focused instead on the growing threat of attackers leveraging the victim’s AI assistant to perform reconnaissance, identify targets and accelerate attack progression."
        https://blog.barracuda.com/2026/08/04/ai-enabled-email-accounts-insider-threat
        https://www.securityweek.com/weaponized-email-ai-assistants-could-help-attackers-hijack-accounts/
      • Almost Half Of Malware Samples Communicate Direct To IP
        "Malware samples often bypass DNS entirely, communicating directly to IP addresses instead. Our analysis of 4 million dynamic analysis reports indicates that almost half (45.32%) of malware samples with any command-and-control (C2) activity made at least one direct-to-IP (D2IP) address connection. Measured as a fraction of all C2 connection attempts, D2IP traffic accounts for 23.17% of the total. A wide variety of threats — including ransomware droppers, peer-to-peer (P2P) botnets and supply chain risks — communicate directly with hard-coded IP addresses, bypassing DNS entirely and evading DNS-based defenses altogether."
        https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/
      • Developers In The Crosshairs: Fake AI Tools Deliver Infostealer
        "In April 2026, Netskope Threat Labs exposed a Malware-as-a-Service (MaaS) NodeJS infostealer delivered through the ClickFix social engineering technique. As we tracked this infostealer, we uncovered ongoing campaigns in which attackers shifted delivery vectors, cloning and impersonating known GitHub repositories and redirecting download links at their payloads. These GitHub repositories are part of the broader campaign previously tracked as TroyDen’s lure factory.The campaign’s target victims were mainly in North America, Asia, and Southern Europe, across different segments, with the financial services, banking, and technology sectors leading."
        https://www.netskope.com/blog/developers-in-the-crosshairs-fake-ai-tools-deliver-infostealer
        https://www.helpnetsecurity.com/2026/08/04/developers-github-fake-ai-tools-infostealer/
      • Npm Stealer Reads Its C2 From An Ethereum Contract
        "Netskope Threat Labs identified and analyzed 28 malicious npm package versions published across four unrelated enterprise namespaces (@servicetitan, @or-sdk, @onereach, and @umacloud) on 2026-08-04. The packages arrived in two rapid bursts: the @or-sdk and @onereach packages at 10:39 UTC, the @servicetitan packages two minutes later at 10:41 UTC, and @umacloud/knowledge nearly three hours after that at 13:18 UTC. All 28 carry an identical or functionally equivalent payload, confirmed by hash match for @umacloud/[email protected], the one tarball still live when we retrieved it. The operator behind the campaign calls it Shai-Hulud, consistent naming with similar attacks we have tracked over the past year [1], [2], [3]. At install time, the packages fetch a signed Bun runtime release from GitHub, execute an obfuscated JavaScript stealer under it, and delete the runtime."
        https://www.netskope.com/blog/npm-stealer-reads-its-c2-from-an-ethereum-contract
      • Malware Signing: When Trust Becomes An Attack Surface
        "Digital code-signing certificates play a critical role in the software ecosystem. When a software publisher signs an application, the certificate serves two important purposes: It identifies the publisher and verifies that the software has not been modified since it was signed. Operating systems, browsers, endpoint protection tools, and users all rely on these signals to determine whether software should be trusted. This trust model benefits everyone. Developers can prove that their software is authentic, users can install applications with greater confidence and security tools can use certificate information as one factor when evaluating risk. In a world where millions of software packages are downloaded every day, digital signatures help establish a foundation of trust. Unfortunately, attackers have learned how to exploit that foundation."
        https://blog.barracuda.com/2026/08/04/malware-signing--when-trust-becomes-an-attack-surface

      Breaches/Hacks/Leaks

      • 150,000 Impacted By Madera Community Hospital Data Breach
        "Madera Community Hospital in California is notifying just over 150,000 individuals that their personal, financial, and medical information was compromised in a data breach. A not-for-profit community healthcare provider serving Madera County and surrounding areas, Madera Community Hospital provides emergency services, surgical services, acute care, diagnostic imaging, and specialized medical programs. The incident, the hospital says in an incident notice, occurred in May 2025, when hackers accessed its network for two days and likely exfiltrated certain files."
        https://www.securityweek.com/150000-impacted-by-madera-community-hospital-data-breach/
      • Swiss IT Agency Hacked, 200 Accounts Compromised, SharePoint Vulns Suspected
        "Switzerland’s Federal Office for Information Technology and Communications (BIT) disclosed Tuesday that hackers had compromised approximately 200 accounts on its on-premises SharePoint servers. The agency made the announcement a week after security specialists first detected anomalies on the on-premises Microsoft servers. It did not confirm how the hackers got in but acknowledged several vulnerabilities affecting SharePoint had been identified in July’s Patch Tuesday release. “The cyberattack was carried out by previously unknown actors, presumably by exploiting these vulnerabilities in the SharePoint software,” the Swiss agency said."
        https://therecord.media/swiss-bit-foitt-hacked-possibly-sharepoint-vulnerabilities
        https://securityaffairs.com/196625/hacking/sharepoint-flaws-used-to-hack-switzerlands-federal-it-agency.html

      General News

      • Third-Party Cyber Evaluations Involving OpenAI Models
        "Independent testing plays an important role in helping us validate and further understand risks before deployment. Some cyber evaluations intentionally use custom configurations, including lowered safeguards to measure underlying capability—not how models ordinarily behave in publicly available deployments. During recent evaluations, two external testing partners identified incidents in which testing configurations and controls combined with the advancing capabilities of the recent models allowed for model activity to extend beyond their intended testing boundaries."
        https://openai.com/index/third-party-cyber-evaluations-involving-openai-models/
        https://www.bleepingcomputer.com/news/security/openai-anthropic-ai-agents-targeted-real-people-and-systems-in-cyber-tests/
      • When Data Becomes Instructions: AI Agents Need a Chain Of Custody For Context
        "A few weeks ago, an AI cyber evaluation produced an unexpectedly efficient strategy for solving a benchmark: the agents went looking for the answers. According to OpenAI’s preliminary disclosure, models being tested for advanced cyber capabilities found ways to obtain secret information that could help them complete a benchmark. They chained vulnerabilities, stolen credentials, internet access, and inferences about where benchmark material might be hosted. The route eventually reached Hugging Face infrastructure, where the activity was detected and contained."
        https://blog.checkpoint.com/ai-security/ai-agent-context-chain-of-custody/
      • How Companies Could Share Cyber Risks Without Exposing Their Secrets
        "Zero-knowledge proofs could let infrastructure operators answer key security questions without handing over the sensitive data behind their answers. Imagine a major software flaw is discovered in equipment used across pipelines, power plants and telecom networks. The government needs to know as fast as possible which companies are exposed. But answering that question may require firms to share software inventories, network diagrams and vulnerability scans, which could become attack roadmaps for attackers if compromised. A lesser-known cryptographic concept could help solve this problem. The method, known as zero-knowledge proofs, allows companies prove a vulnerability exists without disclosing how their systems work or other proprietary information."
        https://cyberscoop.com/zero-knowledge-proofs-cyber-risk-sharing-op-ed/
      • Digital Executive Protection Is a Strategic Imperative For CEOs
        "In this interview with Help Net Security, Brian Hill, Field CISO, Client Advisory for BlackCloak, explains how attackers reach companies through the personal lives of executives. He describes a case where a draft report sat in an executive’s personal email with no multifactor authentication, and traders acted on it before the news went public. He also covers a home network left open after an AV technician swapped cables, malware planted through hotel Wi-Fi, and why he thinks deepfake defense should verify the person, not the message. Companies lack the tools to close this gap."
        https://www.helpnetsecurity.com/2026/08/04/brian-hill-blackcloak-digital-executive-protection/
      • Why Trust Is The New Attack Surface: Darktrace’s Mid-Year Threat Update 2026
        "Darktrace’s analysis of the first half of 2026 shows attackers increasingly exploiting trust rather than bypassing security controls. Identity compromise, supply-chain attacks, SaaS abuse, AI-enabled operations, and state-aligned activity demonstrate how trusted users, services, and infrastructure have become key attack paths. For defenders, context and behavioral analysis remain essential foundations of security."
        https://www.darktrace.com/blog/why-trust-is-the-new-attack-surface-darktraces-mid-year-threat-update-2026
        https://www.infosecurity-magazine.com/news/cloud-saas-targets-attackers/
      • AI Accounts For Over Half Of Cybercrime In Africa, Says Interpol
        "AI-driven cybercrime now accounts for 55% of all reported digital crime in Africa, Interpol has warned. The policing group made the claim in a new African Cyberthreat Assessment Report 2026, which draws on data provided by its 36 member countries on the continent. AI-powered scams, social engineering and credential harvesting have helped to drive cybercrime losses from $192m in 2024 to $484m last year, the report claimed."
        https://www.infosecurity-magazine.com/news/ai-accounts-over-half-cybercrime/
      • CISO Conversations: Russ Kirby – Passion Is The Antidote To Burnout
        "Passion for the job is the secret of a successful career. Russ Kirby has been CISO at Ping Identity since the summer of 2023. Before then he was CISO at Creditsafe, and then CISO at ForgeRock. Prior to that he had been global head and director of enterprise services information security directorate at Hewlett Packard."
        https://www.securityweek.com/ciso-conversation-russ-kirby-passion-is-the-antidote-to-burnout/
      • SQLite Critical CVEs Or LLM Slop?
        "Over the past few days, a newly created GitHub repo (programmervuln/cveadvisory-) published a batch of SQLite vulnerability advisories (as part of other 50+ CVEs which we believe are also LLM slop except from one). NVD quickly flagged these as critical, and CISA's ADP agreed. But when JFrog security researchers dug in to verify, the claims fell apart:

      The cited code didn't even exist in those versions or referenced unrelated logic.
      When testing the PoC payloads they didn’t work (not triggering any crash).
      None of these CVEs are listed on SQLite’s official advisory page (which is a gold standard for tracking actual vulnerabilities).
      All advisories in this repo seem AI generated when testing them with Gptzero
      "
      https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/
      https://www.theregister.com/security/2026/08/03/ai-slop-pollutes-the-cve-pipeline-with-fake-vulns/5282462

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 397c3606-e2f9-451d-94f3-7799fea61b5f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Google เตรียมบล็อกส่วนขยาย Chrome ที่เปลี่ยนหน้า New Tab โดยไม่ได้รับอนุญาต

      Google เตรียมบล็อกส่วนขยาย Chrome ที่เปลี่ยนหน้า New .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 95a06120-b5c0-4cbb-9a1d-e66f78fa5e04-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CareCloud แจ้งเหตุข้อมูลรั่วไหล กระทบประชาชน 345,000 ราย หลังระบบบน AWS ถูกโจมตี

      CareCloud แจ้งเหตุข้อมูลรั่วไหล กระทบประชาชน 345,000 .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand c7ee4327-cd99-4f29-af50-d2e7d8947430-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CrowdStrike เผย AI กลายเป็นทั้ง อาวุธ และ เป้าหมาย ในการโจมตีไซเบอร์ยุคใหม่

      CrowdStrike เผย AI กลายเป็นทั้ง อาวุธ และ เป้าหมาย ใน.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 709f79d1-962a-45ad-9549-23efc717402c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 3 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 22ed4d9d-ad60-4a77-9987-6c69d62805ea-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 04 August 2026

      ndustrial Sector

      • APT And Financial Attacks On Industrial Organizations In Q2 2026
        "This summary provides an overview of reports on APT and financial attacks on industrial enterprises disclosed in Q2 2026, as well as the related activities of groups observed attacking industrial organizations. For each topic, we summarize the key facts, findings and conclusions of researchers that we believe may be useful to professionals addressing practical issues of cybersecurity in industrial enterprises."
        https://ics-cert.kaspersky.com/publications/reports/2026/08/03/apt-and-financial-attacks-on-industrial-organizations-in-q2-2026/
      • A Leaked Memo Ties Cyberattacks On Minnesota Water Utilities To Iran
        "Since the US launched its war against Iran in late February, the country’s hackers have struck back with retaliatory intrusions that have ranged from paralyzing medical supplies company Stryker to breaching the personal email of FBI director Kash Patel. Now, after an unprecedented wave of disruptive cyberattacks hit water utilities in Minnesota, a memo circulated within the water industry ties those attacks to Iran, too, in the widest and most disruptive strike yet inflicted by the country’s hackers against the US since the war began. A communication obtained by WIRED on Thursday and sent to members of the Water Information Sharing and Analysis Center, or WaterISAC, an industry group for water utilities to share cybersecurity information, links to Iran a series of cyberattacks that targeted dozens of Minnesota water and wastewater utilities."
        https://www.wired.com/story/a-leaked-memo-ties-cyberattacks-on-minnesota-water-utilities-to-iran/
        https://www.securityweek.com/us-water-cyberattacks-extend-beyond-minnesota-to-at-least-6-other-states/

      Vulnerabilities

      • N-Able Warns Of N-Central Auth Bypass Flaw Exploited In Attacks
        "N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. The company on Sunday released hotfix 2026.3.1.7 to address the security issue, which affects all versions of N-central before 2026.3. On August 1st, the vendor disclosed that it detected active exploitation and launched an investigation that uncovered additional security concerns affecting all versions of N-central, its flagship Remote Monitoring and Management (RMM) platform."
        https://www.bleepingcomputer.com/news/security/n-able-warns-of-n-central-auth-bypass-flaw-exploited-in-attacks/
        https://uptime.n-able.com/event/201456/
        https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html
        https://www.darkreading.com/vulnerabilities-threats/attackers-exploit-n-able-patch-bypass-flaw
        https://www.bankinfosecurity.com/n-able-flaw-exposes-msps-to-worst-case-scenario-a-32397
        https://hackread.com/hackers-exploit-n-able-n-central-flaw-initial-fix/
        https://www.securityweek.com/n-able-patches-vulnerability-exploited-to-hack-n-central-servers/
        https://www.helpnetsecurity.com/2026/08/03/cve-2026-18577-n-able-n-central-vulnerability/
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog
      • Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
        "Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor's July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented. Thermo Fisher tracks the issue as CVE-2026-17583 and rates it High with a CVSS v4.0 score of 8.2. Five supported product lines have received updates that add digital signatures, while three end-of-life data collection products will receive no vendor update."
        https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-could.html

      Malware

      • Analysis Of a Phishing Email Attack Case By The Larva-24009 Threat Actor
        "The Larva-24009 threat actor has been active since at least 2023, carrying out phishing email attacks targeting users both in Korea and globally to install malware. ASEC (AhnLab SEcurity intelligence Center (ASEC) has previously disclosed attack cases by this threat actor in 2024, and [1] [2] [3] Subsequently, Cyble also identified this same attack campaign and named it “HeptaX.” [4] The Larva-24009 threat actor continues to carry out attacks in 2026, and this report summarizes the attacks and malware identified in 2026."
        https://asec.ahnlab.com/en/94786/
      • Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader And DeviceManager RATs
        "SOCRadar’s Threat Research Unit (STRU) identified and analyzed DOUBLECUP, a Russian Loader-as-a-Service (LaaS) for ClickFix campaigns. Operating in a client-server architecture, each client can configure campaigns that host the DOUBLECUP logic on specific URLs. The DOUBLECUP panel provides multiple utilities to load an operator’s final payload. The first stage drops a steganographic PNG image into the browser’s cache, retrieves its hidden content, and executes the second stage. This second stage decrypts the final payload in memory via a custom SHA-256 stream cipher in Counter (CTR) mode along with bitwise XOR using the victim’s public IP address as the cryptographic key."
        https://socradar.io/blog/doublecup-clickfix-loader-devicemanager-rats/
        https://www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/
      • Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord And Forums
        "A malware campaign disguised as an “undetected” version of the Xeno Roblox script executor is directly affecting players looking to download a legitimate tool. Promoted through various gaming forums and Discord communities, the fake cheat launches a multi-stage Java infection chain built to stay hidden in plain sight. Its components imitate real Xeno files, use Windows-style names and hide inside trusted-looking directories, which includes a folder associated with Xbox Game Bar, formerly Microsoft GameDVR. The final payload goes far beyond conventional credential theft. It can steal browser cookies, Discord, Roblox and Minecraft accounts, cryptocurrency-wallet data and payment information."
        https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor
        https://www.bleepingcomputer.com/news/security/fake-roblox-xeno-script-launcher-pushes-infostealer-rat-malware/
      • Inside The Underground Business Of The Android BTMOB RAT Malware
        "BTMOB has been covered by several cybersecurity publications, primarily through technical analyses of the malware and its capabilities, but much less has been reported about the ecosystem that has developed around it. Activity observed by Flare researchers in underground forums and chat platforms reveals another story: a criminal software business that appears to have become increasingly difficult for its original operator to control. Posts reviewed by Flare show the channel presenting itself as BTMOB’s official outlet continuing to release new versions and sell access, private infrastructure, and source code."
        https://www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/
      • DarkReasoning: A Chinese LLM Attacked Our Lab, So We Made It Work For Us
        "5 days. That's how long the first live, LLM-managed cyber attack campaign we've detected hit our lab at Jesta Security. And for what? To set up proxyjacking and generate more attacks. From what we uncovered, over 1,000 victims had already been hit the same way, most likely also being used to generate fresh attacks every second. And if this is only what we stumbled onto, we believe the real number is far higher."
        https://jesta.ai/blog/darkreasoning
        https://www.darkreading.com/cyberattacks-data-breaches/chinese-actor-deepseek-ai-agent-attack-security-firm
      • Disrupting a Criminal Scam Operation
        "Earlier this year, we disrupted a Cambodia-based scam operation that used ChatGPT to support investment, romance, gambling, and law enforcement impersonation schemes. We began investigating this activity following a lead from our peers at WhatsApp and have since shared additional threat signals with industry partners and relevant authorities. The operation illustrates an important reality about modern scam networks: organized criminal groups rarely restrict themselves to a single type of scam. Instead, they opportunistically employ whatever narratives, personas, and tactics they think will be most effective to deceive victims."
        https://openai.com/index/disrupting-malicious-uses-of-ai-criminal-scam-operation/
        https://www.helpnetsecurity.com/2026/08/03/openai-disrupts-chatgpt-scam-operation/
      • Buying TikTok Views Or Followers? Here’s What You’re Really Getting
        "A whole industry has sprung up around selling TikTok “growth.” Cheap views by the hundred, pre-made ad accounts, and polished sales pages promising a repeatable path to serious revenue. None of it is officially sanctioned by TikTok, and depending on what you’re buying, you could end up wasting money, losing your account, or handing your login details to scammers."
        https://www.malwarebytes.com/blog/threat-intel/2026/07/buying-tiktok-views-or-followers-heres-what-youre-really-getting
        https://www.helpnetsecurity.com/2026/08/03/malwarebytes-tiktok-followers-scam-risks-report/
      • An Analysis Of Incidents At Brazilian Educational Institutions
        "Because of the amount of data that can be obtained and the high impact that successful attacks may have, educational institutions are frequent targets of cybercriminals. Both public and private schools and universities rely on software for managing personally identifiable information (PII) that is often insecure or insufficiently tested against known vulnerabilities. In addition, machines used by multiple people without accountability can be vulnerable to insider threats."
        https://securelist.com/incidents-at-brazilian-educational-institutions/120803/
      • Targeted Attack On Government Entities In The Middle East | Part 2
        "This is Part 2 of our two-part technical analysis on new tools used by an East Asia-linked threat actor targeting government entities in the Middle East. After ThreatLabz published Part 1 on the TELESHIM backdoor and MIXEDKEY loader, Kaspersky highlighted a related campaign in recent reporting. Building upon our initial findings, Part 2 dives into a detailed technical analysis of BINDCLOAK, a new modular stage 3 backdoor uncovered during our investigation. As detailed later in our threat attribution section, key code similarities between BINDCLOAK and OctLurk as well as shared command-and-control (C2) infrastructure directly connect the threat actor behind OctLurk to the campaign we describe in this two-part blog series."
        https://www.zscaler.com/blogs/security-research/targeted-attack-government-entities-middle-east-part-2
      • From WSProxy To Root: INC Ransomware And SonicWall SMA Exploit Chain
        "Virtual private network (VPN) appliances occupy one of the most sensitive positions in modern enterprise architecture: the boundary between the untrusted public internet and the internal corporate network. Unlike general-purpose web servers, VPN concentrators are intentionally exposed to inbound connections, designed to authenticate remote users, and granted privileged access to directory services, file shares, intranet applications, and management interfaces. They terminate encrypted tunnels, process credentials, and maintain session state at the network edge. A critical vulnerability in a VPN appliance is therefore not a peripheral remote-access issue—it is a direct network-compromise issue with cascading consequences for every downstream system the appliance was built to protect."
        https://www.resecurity.com/blog/article/from-wsproxy-to-root-inc-ransomware-and-sonicwall-sma-exploit-chain
        https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
        https://www.securityweek.com/recent-sonicwall-vulnerabilities-exploited-in-ransomware-attacks/
      • Pass The Passkey: A Novel Attack Surface In Passwordless Authentication
        "This article analyzes new attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The attacks demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts. We show how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys. After decades of breaches and billions in losses, the attack vectors that defined the era of passwords and shared secrets are finally starting to fade. Passkeys replace passwords and traditional multi-factor authentication (MFA) with public-key cryptography, decreasing entire classes of attacks that have dominated the threat landscape for years."
        https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/
        https://thehackernews.com/2026/08/google-password-manager-attacks-could.html
        https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/
      • DarkSword's Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster
        "DarkSword is a commercial iOS exploit chain, six chained vulnerabilities spanning iOS 18.4 through 18.7, that leaked publicly via a GitHub repository (ghh-jb/DarkSword) and now runs in the hands of at least seven, and probably eight, unrelated operators. The most recently identified operator is a Chinese-speaking actor running well over a hundred web properties, most of them fronted by a fake AWS sign-in page on a domain that also hosts DarkSword. The hosting concentrates in Hong Kong but reaches into Japan, the United States, and Europe. We re-scanned the cluster’s infrastructure to see how far it extended. Here is what we found."
        https://censys.com/blog/darkswords-panel-sprawl/
        https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html

      Breaches/Hacks/Leaks

      • ExfilSquad Hackers Leak Info Of Over 100,000 UK Police Officers, Staff
        "A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. The intrusion was detected on Sunday, July 26, and was later claimed by the ExfilSquad data extortion group, which alleges it stole 135,000 contact records. PNLD is an online legal resource service that has been used for more than 30 years by the 43 Home Office police forces in England and Wales, as well as the British Transport Police."
        https://www.bleepingcomputer.com/news/security/exfilsquad-hackers-leak-info-of-over-100-000-uk-police-officers-staff/
        https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html
        https://securityaffairs.com/196525/data-breach/pnld-confirms-data-breach-affecting-uk-police-and-justice-staff.html
      • Żabka Alleged Data Leak: 541k Jira Tickets, 89 Repos
        "A data-leak forum account registered on 2 August 2026 advertised an alleged Żabka Polska dataset the same afternoon, asking €5,000. The listing claims roughly 541,000 Jira issues, 229,734 IT service-desk tickets and source code from 89 GitLab repositories. Ransomnews reviewed the sample archive attached to the post. The headline counts are internally consistent, and a single GitLab access token appears in all 89 repository dumps. Żabka Group has not confirmed any breach."
        https://ransomnews.com/zabka-data-leak-2026/
        https://securityaffairs.com/196510/data-breach/alleged-zabka-breach-exposes-jira-data-source-code-and-api-keys.html
      • Hackers Steal 31,000 Records Identifying People Behind Liechtenstein Companies, Foundations
        "A cyberattack compromised tens of thousands of records related to companies, foundations and trusts in Liechtenstein, prompting the government to to form a “crisis unit” to address the breach. The unknown attackers gained access to the Register of Beneficial Owners for two days beginning on July 29, the government announced over the weekend. The register, which contains information on who owns legal entities in the country, was created in 2021 in accordance with European Union rules around money laundering and financial transparency."
        https://therecord.media/hackers-steal-records-liechtenstein-companies-foundations
      • River Bank Says Hackers Deleted Data Stolen In Ransomware Attack
        "River Financial Corporation, the bank holding company behind River Bank & Trust, says it received confirmation that data stolen in a ransomware attack was deleted. The attack occurred on June 16 and was identified three days later. River’s investigation into the incident determined that ransomware was deployed across portions of its server environment. In response, the company took the affected systems offline and disabled administrative accounts that had been compromised."
        https://www.securityweek.com/river-bank-says-hackers-deleted-data-stolen-in-ransomware-attack/
        https://securityaffairs.com/196537/cyber-crime/river-bank-obtained-assurances-from-the-attackers-that-the-stolen-data-in-the-june-attack-was-deleted.html

      General News

      • The Assets You Don’t Know You Own: Attack Surface Sprawl Is a Discovery Problem, Not a Tooling Problem
        "Modern organizations no longer operate within a fixed network perimeter. Cloud services, remote work, third-party integrations, and rapid digital expansion have made the boundary between “inside” and “outside” for the enterprise increasingly difficult to define. Attackers exploit this ambiguity by scanning continuously for weaknesses across an organization’s hardware, software, cloud, and internet-facing assets. The uncomfortable truth security leaders must confront is simple: an organization cannot secure what it does not know it has."
        https://cyble.com/blog/attack-surface-discovery-asset-visibility/
      • Anthropic: Claude Attacks Result Of Security Gaps, Not Model Issues
        "Three recent incidents in which Anthropic's AI models autonomously compromised real-world systems were less a failure of model alignment than a failure of the systems designed to keep them contained, according to the company. The compromises happened while Anthropic was testing the ability of its Claude AI models to autonomously find and exploit novel vulnerabilities in simulated cybersecurity environments. Typically, the company conducts these capture-the-flag-style exercises in environments that aren't connected to the Internet and often works with external partners to conduct the tests."
        https://www.darkreading.com/cyber-risk/anthropic-ai-issues-result-security-gaps
      • Is There Really a Fix For CISO Fatigue?
        "Only 2% of cybersecurity professionals report feeling no stress about their job, according to Omdia and ISSA's eighth annual Life and Times of Cybersecurity Professionals study. In addition, 68% say the work has become measurably harder over the past two years. The difference between those two figures is screaming that stress in this profession has moved from an occupational hazard to the default condition, and that shift changes what conclusions security leaders should draw from the gap."
        https://www.darkreading.com/cybersecurity-operations/fix-for-ciso-fatigue
      • Mapping The Malware Blast Radius a Single Alert Won’t Show You
        "In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far a malware campaign spread. He walks through the research behind the claim that each published sample hides an average of 2.4 undocumented variants, describes what counts as a related variant, and explains why Stairwell keeps every executable that runs on customer endpoints."
        https://www.helpnetsecurity.com/2026/08/03/mike-wiacek-stairwell-backstory-malware-blast-radius/
      • CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes As AI Use Accelerates
        "The CrowdStrike 2026 Threat Hunting Report illustrates the next evolution in trust abuse. Adversaries are targeting trusted users and tools across identity systems, cloud environments, SaaS applications, AI services, software supply chains, and developer workflows to blend into legitimate business activity and reach critical assets before defenders can detect them."
        https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-threat-hunting-report/
        https://www.infosecurity-magazine.com/news/chinalinked-threat-actors/
        https://cyberscoop.com/crowdstrike-annual-threat-hunting-report-2026/
      • Google Warns Open-Source Attacks Will Reach New Heights
        "Compromising the open-source supply chain is easier to execute and spreads more quickly than traditional supply-chain attacks, making it a lucrative tactic that will continue to expand, warned computing giant Google. Attacks on open-source code repositories, software dependencies and developer tools flourished in 2025 and the first months of 2026: TeamPCP's two waves of Shai-Hulud malware late last year affected 20 million weekly downloads of open-source software, while its months-long campaign this year poisoned packages accounting for 100 million weekly downloads."
        https://www.bankinfosecurity.com/google-warns-open-source-attacks-will-reach-new-heights-a-32404

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 5afe3572-6761-4eb8-9e8b-39c0821bc271-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Ruby on Rails ออกแพตช์ช่องโหว่ Critical ใน Active Storage เสี่ยงอ่านไฟล์และรันโค้ดบนเซิร์ฟเวอร์

      Ruby on Rails ออกแพตช์ช่องโหว่ Critical ใน Active Storage เสี่ยงอ่.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5fdad3e1-4048-4afd-9393-566bb4dc0ab1-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ใน Coldcard Hardware Wallet ถูกเชื่อมโยงกับเหตุขโมย Bitcoin มูลค่ากว่า 70 ล้านดอลลาร์สหรัฐ

      ช่องโหว่ใน Coldcard Hardware Wallet ถูกเชื่อมโยงกับเหตุขโ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 40ed95c8-b42f-4a02-9d7d-65e8b056b4b6-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการโจมตีทางไซเบอร์พุ่งเป้าหน่วยงานรัฐในภูมิภาคเอเชียกลาง ด้วยมัลแวร์ชนิดใหม่ OctLurk และ SilkLurk

      พบการโจมตีทางไซเบอร์พุ่งเป้าหน่วยงานรัฐ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 49fdbe03-973d-4bf5-88e0-e145af66f06a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 03 August 2026

      Telecom Sector

      • Researchers Report 84 Flaws In 4G And 5G Cores, Including a Session Hijacking Flaw
        "An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network session. The findings have been released by a group of researchers from Singapore's Nanyang Technological University in a paper titled "Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis.""
        https://thehackernews.com/2026/07/researchers-report-84-flaws-in-4g-and.html
        https://arxiv.org/abs/2607.10315

      Vulnerabilities

      • Advanced Responsive Video Embedder For Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass Via Hardcoded Backdoor In '_wplogin' Parameter
        "The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the _arve_uc_init() function — registered on WordPress's init hook at priority 1 so that it runs before any authentication checks on every request — reads an attacker-supplied token from the _wplogin (or _wpm) parameter and compares it against a hardcoded SHA-256 hash embedded directly in the plugin source, with no nonce verification, no capability check, and no password validation anywhere in the flow. Because this static hash constitutes a set of universal credentials that are publicly accessible in the plugin's source code, unauthenticated attackers can supply the known token to be authenticated as an arbitrarily selected existing administrator account, gaining full administrative control over the affected WordPress site. This was likely introduced by an attacker who gained commit access to the developers account."
        https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-responsive-video-embedder/advanced-responsive-video-embedder-for-rumble-odysee-youtube-vimeo-kick-1087-unauthenticated-authentication-bypass-via-hardcoded-backdoor-in-wplogin-parameter
        https://hackread.com/wordfence-critical-backdoor-arve-wordpress-plugin/
      • Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
        "Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in arbitrary code execution in the context of the current user without requiring any user interaction."
        https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html
        https://securityaffairs.com/196429/security/adobe-fixed-a-maximum-severity-vulnerability-flaw-in-campaign-classic.html

      Malware

      • Adform Compromised To Serve Crypto Stealer Via Supply Chain Attack
        "Adform are an advertising company used by around 14k companies, owning around a 30% share of the demand-side category. They operate by offering a Javascript embed for websites, via this URL: hxxps://s2.adform.net/banners/scripts/st/trackpoint-async.js This script was compromised to serve a crypto stealer. Adform have been hacked. As far as I can tell Adform haven’t told people."
        https://doublepulsar.com/adform-compromised-to-serve-crypto-stealer-via-supply-chain-attack-2f1ec024f33e
        https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/
        https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html
      • The Fuyao Enterprise: Building An Ad-Fraud Empire With AI And Kids’ Coding Blocks
        "In this post, we will uncover the “Fuyao Enterprise,” a previously unknown, sophisticated and highly modular botnet operating within Android TV boxes. This operation marks a shift in modern ad-fraud, where automated bots fake both clicks and views to defraud advertisers and ad-networks. While deploying novel tactics and techniques, Fuyao managed to escape public research for several years. Now, its operators openly advertise their network of over 120,000 “AI digital humans.""
        https://www.bitsight.com/blog/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks
        https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html
        https://www.helpnetsecurity.com/2026/07/31/fuyao-ad-fraud-botnet-android-tv-boxes/
      • Network Anomaly Detection In KATA
        "Once the attacker has breached the corporate network, subsequent stages of the attack often involve leveraging standard domain infrastructure protocols: using Kerberos, running DNS queries, accessing internal services, opening network shares, and other common networking actions. Because this activity is virtually indistinguishable from legitimate network traffic, it is extremely difficult to detect it with traditional network attack detection tools. Kerberoasting and DNS tunneling have long ceased to be exotic techniques. They are becoming standard methods in modern attacks because they allow attackers to execute critical compromise stages while remaining undetected by traditional security tools. A clear example of this trend is seen in latest campaigns, employing both Kerberoasting and DNS tunneling."
        https://securelist.com/tr/network-anomaly-detection-in-kata/120892/
      • Nested Trust: HollowFrame’s Layered Loader And Matryoshka Backdoors
        "Blackpoint Cyber’s Adversary Pursuit Group (APG) identified a previously undocumented, multi-stage intrusion affecting two endpoints at a law firm. The activity began with a spear phishing lure and progressed through several layers of obfuscated scripts, encrypted payloads, and trusted software components before establishing persistent remote access. The intrusion relied on a modular Go based loader tracked as HollowFrame and a Rust based malware family tracked as Matryoshka. HollowFrame provided the actor with multiple execution and persistence options. The Matryoshka family was represented by two distinct backdoor variants, one that communicated directly over HTTP and another that used GitHub for tasking and payload delivery. Together, these variants supported command execution, reconnaissance, file transfer, and follow on malware deployment."
        https://blackpointcyber.com/blog/hollowframes-layered-loader-and-matryoshka-backdoors/
        https://thehackernews.com/2026/07/hollowframe-loader-deploys-matryoshka.html
      • The Xcode Assassin Returns: A Deep Dive Into The Latest XCSSET Version
        "After months of dormancy, the attackers behind the XCSSET malware released version 40 (v40), targeting the macOS ecosystem. This version’s advanced architecture hides its core logic in memory space, reducing its digital footprint. V40 further enhances its detection evasion capabilities by combining polymorphic payload generation with fileless persistence and dynamic in-memory execution, while weakening a number of security mechanisms on the affected machine. Since early April 2026, the malware has spread through supply chain attacks by hiding itself in the Xcode projects of dozens of legitimate applications with thousands of active users. Xcode is Apple’s integrated development environment (IDE) for building apps for its various operating systems."
        https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/
      • When ScreenConnect Works For Cybercriminals
        "Leveraging legitimate software is one of cybercriminals’ tactics of choice, with remote management tools ranking among their top tools. A recent example involves the remote administration utility ScreenConnect. It’s designed for IT support teams to troubleshoot systems and configure software seamlessly in the background. However, when weaponized by threat actors, ScreenConnect becomes a versatile attack vehicle used to harvest data, deploy malware, and move laterally across corporate networks."
        https://www.kaspersky.com/blog/screenconnect-fake-software-campaign/56197/
      • CaptiveCrunch: Midnight Blizzard Targets Travelers Worldwide For Malware Delivery And Credential Theft
        "Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some tactic, technique, and procedure (TTP) similarities to the Forest Blizzard DNS hijacking operation that we publicly disclosed in April 2026, we attribute this campaign, which we call CaptiveCrunch, to Storm-2945. As reported by ReliaQuest on July 23, a portion of this activity leverages doppelganger domains mimicking Microsoft online services to conduct follow-on adversary-in-the-middle (AitM) phishing operations that abuse the device code authentication flow in Microsoft Entra ID."
        https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/
        https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html
        https://securityaffairs.com/196441/apt/russian-hackers-hijack-hotel-wi-fi-to-steal-microsoft-365-tokens.html
      • COLDCARD Wallet RNG Flaw Likely Linked To $88 Million Bitcoin Theft
        "Researchers suspect that a vulnerability in COLDCARD hardware wallet firmware was exploited to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. Digital asset research firm Galaxy Research says it identified an initial wave of transactions that it believes was likely linked to the vulnerability, draining approximately 1,083 BTC, worth $70.2 million, from 1,196 addresses on July 30. The 41-minute attack occurred approximately 30 hours before Coinkite publicly disclosed the flaw."
        https://www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/

      Breaches/Hacks/Leaks

      • Amgen Says Cloud Data Breach Exposed Patient Health, Proprietary Info
        "Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. Amgen is a California-based biotechnology company that develops and manufactures medicines for serious illnesses, including cancer, cardiovascular disease, inflammation, and rare diseases. The company said it detected the unauthorized activity in July 2026 and responded by activating its cybersecurity response plan, implementing containment measures, and hiring independent forensic experts to investigate the incident."
        https://www.bleepingcomputer.com/news/security/amgen-says-cloud-data-breach-exposed-patient-health-proprietary-info/
      • CareCloud Data Breach Impacts Over 350,000
        "Healthcare information technology company CareCloud is notifying at least 350,000 people that their information was stolen in a data breach. The incident involved an electronic health record environment within the CareCloud Health division, which was disrupted on March 16, 2026. CareCloud’s investigation determined that hackers accessed one of its AWS environments between March 10 and March 16, and likely exfiltrated data from it."
        https://www.securityweek.com/carecloud-data-breach-impacts-over-350000/
        https://securityaffairs.com/196480/cyber-crime/carecloud-breach-exposes-medical-and-financial-data-of-345000.html

      General News

      • The Morning After We Pull a Root Of Trust, Nobody Owns It
        "In June 2024, Google's Chrome Root Program said it would stop trusting new Transport Layer Security (TLS) certificates from Entrust. Behind the decision, years of compliance failures and a clear technical call. The decision was right. The fallout became someone else's responsibility. That is the part we keep getting wrong. We are good at the technical decision to remove a trust anchor. Root programs at Chrome, Mozilla, Microsoft, and Apple make that call well. What we lack is a way to coordinate what happens the morning after. Trust continuity is a national readiness problem hiding inside a browser setting."
        https://www.darkreading.com/cyber-risk/morning-after-we-pull-root-of-trust-nobody-owns-it
      • Interpol Leverages Global System To Curtail Fraud Payments
        "Earlier this month, Interpol revealed that authorities in Singapore and Oman used a worldwide network of law enforcement agencies and financial organizations to halt a $6.6 million payoff from a business email compromise (BEC) scam, part of Operation First Light 2026, which — among other milestones — blocked more than 31,000 bank accounts linked to fraud. When companies and individuals report fraud and cybercrime, it's often too late to recover transferred funds. The coalition of law enforcement agencies and financial firms, known as the Interpol Global Rapid Intervention of Payments (I-GRIP) mechanism, has been working together to cut down the time to halt transfers and recover funds."
        https://www.darkreading.com/cybersecurity-operations/interpol-leverages-global-system-curtail-fraud-payments
      • Cybercrime Goes Subscription: AI, Malware And Infrastructure On Demand
        "Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These services provide anonymity, plausible deniability, and access to short-lived infrastructure that is difficult to detect, attribute, and disrupt, enabling low-skilled actors to operate at scale, according to the Infoblox 2026 Threat Landscape Report. “Cybercrime is becoming more efficient, automated, and harder to stop. Driven by economics and fueled in part by frontier AI, it has reached an unprecedented scale. The line between financially motivated and state actors has blurred in a complex economy that allows criminals to evade disruption through segmentation and the adoption of commodity services,” said Dr. Renee Burton, Head of Infoblox Threat Intel."
        https://www.helpnetsecurity.com/2026/07/31/infoblox-domain-abuse-campaigns-report/
      • Aviation Cyber Risk Sits On The Ground, The Blindness Sits In The Air
        "In this interview with Help Net Security, Eliran Almog, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays unmonitored. He walks through GNSS jamming that leaves no trace in a SIEM, and a PX4 Autopilot flaw his team disclosed where drone command channels accept unsigned messages. He argues the Electronic Flight Bag matters less than the data loading chain behind it, makes the case for digital twins, and sets out what a 30 aircraft carrier with two security staff should do first."
        https://www.helpnetsecurity.com/2026/07/31/eliran-almong-cyviation-aviation-cyber-risk/
      • AI Agents Are Changing Where Cybersecurity Seed Funding Lands
        "Founders pitching a cybersecurity seed round this summer are joining a line that keeps getting longer. Product Hunt launches hit their highest level since late 2023 last quarter, and the Census Bureau’s count of high-propensity business applications kept climbing. Seed deal volume in cyber ticked down. Those figures come from the Q2 2026 Insights report published by DataTribe, an early-stage cybersecurity investor. The money went up the stack. Nine-figure rounds took 81% of every venture dollar invested in the second quarter, more than double the share they held at the start of 2018. Cyber Series A volume fell from Q1 and stayed inside the band it has occupied for three years."
        https://www.helpnetsecurity.com/2026/07/31/ai-agents-cybersecurity-seed-funding/
      • What An LLM Can Find: A Practical, Cheap Path To Code-Level Threat Discovery
        "GlobaLeaks, a mature whistleblowing platform that had already undergone six independent professional audits over the past thirteen years, was subjected to an LLM-assisted security review that cost roughly USD 3,140 in API calls. The review identified 29 confirmed vulnerabilities, 12 denial-of-service issues, and 42 hardening recommendations, with an average cost of about USD 77 per confirmed finding before human validation. The most important point is probably the cost. Reading an entire codebase systematically, line by line and against major known weakness classes, traditionally required weeks of specialist work and a serious budget. That assumption no longer holds in the same way: the report argues that this kind of analysis is now far more accessible than it used to be."
        https://securityaffairs.com/196395/ai/what-an-llm-can-find-a-practical-cheap-path-to-code-level-threat-discovery.html
      • AiTM Phishing Becomes Top Initial Access Threat To Law Firms
        "Adversary-in-the-middle (AiTM) phishing has become the single most common way attackers break into law firms, overtaking conventional credential theft in a sector where multifactor authentication (MFA) is now widely deployed but routinely bypassed. According to a new legal sector threat intelligence report from eSentire shared with Infosecurity, AiTM attacks accounted for 28.57% of all initial access events in the legal sector. The company's Threat Response Unit (TRU) also recorded a 20% year-over-year (YoY) increase in incidents targeting legal organizations."
        https://www.infosecurity-magazine.com/news/aitm-phishing-top-entry-point-law/
        https://esentire-dot-com-assets.s3.amazonaws.com/assets/resourcefiles/eSentire_Legal-Services-Threat-Intelligence-Spotlight.pdf
      • What The Hugging Face Breach Reveals About Defense In The Age Of Agentic AI
        "We almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models, including GPT-5.6 Sol along with an unreleased one, were responsible for the breach. OpenAI called it an unprecedented cyber incident."
        https://cyberscoop.com/hugging-face-breach-agentic-ai-security-op-ed/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) c2a27d22-ebb0-4bce-b490-0872aff6071d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cisco เตือนช่องโหว่ Static Credential ใน Secure Firewall Management Center ถูกใช้โจมตีจริง

      Cisco เตือนช่องโหว่ Static Credential ใน Secure Firewall Management Center ถูกใ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 12ad936f-83a0-47f6-9b7a-df14c70af6a9-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Minnesota พบการโจมตีระบบ OT ของ Water Utilities กว่า 30 แห่ง กระทบโรงผลิตน้ำบางแห่งชั่วคราว

      Minnesota พบการโจมตีระบบ OT ของ Water Utilities กว่า 30 แห่ง กร.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 0e91bd7e-389d-4165-9139-8901e0c4c552-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • OpenAI เผยข้อมูลจากเหตุการณ์โมเดล AI หลุดระบบทดสอบ พบใช้ช่องโหว่เข้าถึงบริการภายนอกเพิ่มเติม

      OpenAI เผยข้อมูลจากเหตุการณ์โมเดล AI หลุดระบบทด.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e194445e-b9ad-4fcc-adba-1666947bfd41-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 31 July 2026

      Industrial Sector

      • Toptech Systems RCU II+ And Multiload II+
        "Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-03
      • o6 Automation Open62541
        "Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08
      • 1 In 5 Data Center Assets Are Within Easy Reach Of Attackers
        "Nearly one in five of the cyber-physical systems (CPS) that keep the world’s largest data centers running sits just a single network connection away from pathways that could let attackers reach them, according to new research from Claroty. Claroty, which specializes in securing OT, IoT, and other CPS, has analyzed more than 750,000 data center assets, including roughly 191,000 OT assets and 174,000 infrastructure assets. The data center infrastructure assets include HVAC, power monitoring and distribution, fire management, and UPS systems."
        https://www.securityweek.com/1-in-5-data-center-assets-are-within-easy-reach-of-attackers/
        https://web-assets.claroty.com/resource-downloads/team82-data-center-report.pdf
      • CISA Urges Water And Wastewater Systems Sector To Protect OT Against Activity Targeting PLCs
        "CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations."
        https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs
        https://www.securityweek.com/cisa-urges-water-sector-to-protect-ot-after-coordinated-attacks-on-plcs/
      • MikroTik RouterOS
        "Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all associated traffic."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-01
      • Johnson Controls OpenBlue Employee
        "Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-02
      • Schneider Electric IGSS
        "Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The IGSS product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component used by system integrators to create mimic diagrams for plant personnel, enabling them to monitor and control the SCADA system. Failure to apply the remediation provided below may risk loss of data or arbitrary code execution, which could result in the loss of control of the system."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04
      • Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
        "Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05
      • NASA Core Flight System (cFS) Health & Safety (HS) Application
        "Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06
      • Mitsubishi Electric CC-Link IE TSN Communication Protocol
        "Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-07
      • Watchfire Controller Software
        "Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-09
      • MZ Automation GmbH Libiec61850
        "Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10
      • MZ Automation Lib60870
        "Successful exploitation of these vulnerabilities could crash the device being accessed."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11

      Vulnerabilities

      • Chrome 151 Patches 370 Vulnerabilities
        "Google on Wednesday announced the release of Chrome 151 to the stable channel with patches for 370 vulnerabilities. The update resolves seven critical-severity bugs, including four use-after-free issues in Compositing, Views, Skia, and Ozone. Chrome 151 also resolves two critical-severity insufficient validation of untrusted input flaws in Dawn and ANGLE, and a critical race condition in Updater."
        https://www.securityweek.com/chrome-151-patches-370-vulnerabilities/
        https://www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/
        https://www.infosecurity-magazine.com/news/google-patches-370-vulnerabilities/
      • CosmosEscape: Taking Over Every Database In Azure Cosmos DB
        "Wiz Research uncovered CosmosEscape, a critical vulnerability in Azure’s flagship database service, Azure Cosmos DB, via its Gremlin API. The vulnerability could have been exploited to compromise every database in the service, including Microsoft's own internal databases - potentially enabling a cross-service attack. Through CosmosEscape, attackers could have acquired what we’ve dubbed the Cosmos Master Key - a platform-wide secret that granted two incredibly powerful capabilities:"
        https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db
        https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html
        https://hackread.com/microsoft-cosmosescape-flaw-cosmos-db-takeover/
      • Context Collapse, Part 3 - AI Worming Through Word
        "The findings described in this post are part of a coordinated disclosure with MSRC and Microsoft product teams. Microsoft was provided with reproduction steps, videos, environmental assumptions, and the exact proof-of-concept (PoC) prompts used during testing. They were also informed of a 90-day coordination period before disclosure. This was extended two times, resulting a 144-day coordination period. In parts 1 and 2 in this series, I have shown how external inputs could influence Copilot responses and, in some cases, potentially lead to confidentiality impacts through Cross-Domain Prompt Injection Attacks (XPIAs). This report builds on those findings and extends the XPIA analysis from single-interaction compromise to propagation across trusted document workflows."
        https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/
        https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html
        https://www.malwarebytes.com/blog/ai/2026/07/hidden-microsoft-copilot-ai-worm
        https://www.theregister.com/security/2026/07/29/word-worm-crawls-into-copilot-spreads-chaos/5280588

      Malware

      • [Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor And The Gunra Ransomware Group)
        "AhnLab SEcurity intelligence Center (ASEC) identified evidence that a state-sponsored threat group continuously distributed malware from 2025 through the first half of 2026 by exploiting vulnerabilities in Korean financial security software installed when using financial and institutional services. The attackers induced targets to access malicious URLs through various methods, including watering hole and spear-phishing attacks, and then exploited the vulnerabilities to ultimately install backdoor malware. In particular, legitimate Korean websites across various industries, including media organizations, educational institutions, healthcare institutions, and manufacturing companies, were confirmed to have been abused in watering hole attacks during this period."
        https://asec.ahnlab.com/en/94696/
        https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html
        https://therecord.media/north-korea-hackers-ransomware
      • XMRig Covert Ops: The Cryptomining Campaign That Abuses Trusted Access And Deploys Forensic Smokescreens
        "In May 2026, a highly covert Monero (XMR) cryptomining campaign was identified, leveraging advanced stealth techniques to infiltrate and persist within targeted Linux environments. The initial compromise occurred through a trusted third-party relationship, allowing threat actors to traverse from a trusted environment into the primary network undetected. This blog post details the campaign’s tactics, from weaponizing Linux Pluggable Authentication Modules (PAM) to create a forensic smokescreen, to the deployment of a highly customized, self-unlinking XMRig botnet implant and employment of MITRE technique T1564.013."
        https://www.group-ib.com/blog/xmrig-covert-linux-pam-abuse/
      • Toy Ghouls’ New Toy: The GenieLocker Ransomware
        "The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector, and attributed to the Toy Ghouls group by open-source intelligence (link in Russian). The Toy Ghouls, also known as Bearlyfy, Labubu and Laboo.boo, is a financially motivated extortion group, which previously relied on third-party encryption Trojans like RedAlert, LockBit, and Babuk. GenieLocker, apparently a custom design, upgrades their toolkit and reduces their reliance on third-party software. We discovered multiple samples of this Trojan in two variants: PE builds for Windows and ELF builds for Linux and ESXi."
        https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/
      • Not Every Fox Is Silver: Inside An AtlasRAT Loader Chain
        "AtlasRAT is a Windows-based remote access malware. This report analyzes a four-stage in-memory loader chain—which begins with a Delphi executable that is disguised as AGE Flash Player—and its final RAT functionality. The final payload performs TLS-based ChaCha20-encrypted C2 communication, executes modular plugins, performs offline keylogging, and injects DLLs into WeChat processes."
        https://asec.ahnlab.com/en/94704/
      • Chaos In Teams Vishing
        "Sophos analysts investigated a Microsoft Teams voice phishing (vishing) campaign tracked as STAC4749 that used a consistent set of IT-themed cloud domains and personas to gain remote access to victims’ systems. Between February and June 2026, Sophos analysts observed the threat actors targeting dozens of North American organizations. Following initial access, STAC4749 operators deployed a modular post‑exploitation toolset, including a custom loader and backdoor to maintain persistent, controlled access and support follow‑on activity. In several incidents, attackers later leveraged this access to deploy Chaos ransomware."
        https://www.sophos.com/en-us/blog/chaos-in-teams-vishing
        https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/
      • After The Break-In: What Attackers Do Once They're Already Inside
        "Most of us in IT spend our energy trying to keep attackers out. But a recent incident investigated by Huntress tells us a lot about what happens after an attacker gets in (and why it matters just as much). Once an attacker has gained initial access, they don't rush straight to the smash-and-grab, doing things like stealing data, encrypting files, or dropping ransomware. Instead, they take time to dwell and settle in—creating backdoors, covering their tracks, and disabling the tools meant to catch them."
        https://www.bleepingcomputer.com/news/security/after-the-break-in-what-attackers-do-once-theyre-already-inside/
      • OctLurk And SilkLurk: Newly Identified Tailored Backdoors In Cyber-Espionage Campaign In Central Asia
        "We have been tracking two new backdoors, OctLurk and SilkLurk, observed in attacks against government organizations primarily in Central Asia since January 2025. Identified victims are located in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. These organizations operate across several sectors, including healthcare, research, government offices, ministries of foreign affairs, logistics, law‑enforcement agencies, urban planning and facilities management, and public educational establishments. The backdoor loaders are customized for each victim and use information from the victim’s machine to decrypt the payload. Both the loaders and the backdoors are heavily obfuscated, making analysis more complicated."
        https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/
      • When AI Becomes The Attacker: Understanding Autonomous Offensive Security Agents
        "Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, and Nebula lower the barriers to vulnerability identification and exploitation. The analysis also explores why AI is being repurposed for real attacks and what defenders should do in response. From a broader perspective, cybercriminals and foreign adversaries are expected to leverage AI to maximize the impact of cyberattacks, while also optimizing and scaling malicious activity —creating a race between AI-driven attackers and defenders."
        https://www.resecurity.com/blog/article/when-ai-becomes-the-attacker-understanding-autonomous-offensive-security-agents
        https://securityaffairs.com/196331/ai/cybercriminals-are-leveraging-autonomous-ai-offensive-security-agents.html
      • ClickFix, EtherHiding & a DPRK Wallet Trail
        "A routine web search for security research led to the discovery of a sophisticated macOS malvertising campaign combining ClickFix-style social engineering, blockchain-hosted command-and-control, browser-extension hijacking, and crypto-theft infrastructure."
        https://www.allsecure.io/blog/clickfix-etherhiding-dprk-wallet/
        https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html
      • Cato CTRL™ Threat Research: SilverFox Evolves: Abuse Of New Drivers And Trusted Software Hijacking Enable Remote Access With ValleyRAT In Japan
        "SilverFox is expanding its toolkit. In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate applications for DLL sideloading, defense evasion, and layered recovery mechanisms to keep ValleyRAT running. We investigated an active campaign targeting a Japanese organization in the industrial manufacturing sector. The attack begins with an invoice-themed phishing lure and uses attacker-controlled content hosted through legitimate QQ and Tencent Cloud services. The attackers then abuse ConvertToPDF.exe and PDFDirect.exe to sideload a malicious PDFCORE8.dll. Based on the public research we reviewed, neither application had previously been documented as a DLL-sideloading host."
        https://www.catonetworks.com/blog/cato-ctrl-silverfox-evolves/
        https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html
      • Chinese-Speaking Threat Actor Harnesses AI Models For Autonomous Cyberattacks
        "Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact. The actor, operating under the aliases knaithe and KnYuan, leveraged DeepSeek, via the Hermes Agent framework, as their autonomous offensive operator. They orchestrated this operator via Telegram for the following activities:"
        https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/
      • Batten Down Your Packages: Mitigation Guidance For Supply Chain Compromise
        "For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. However, Google Threat Intelligence Group (GTIG) has been tracking growth in threat activity targeting open source software repositories to conduct supply chain compromises over the past several years. A series of large scale open source software supply chain compromise campaigns in 2025 and the first half of 2026 underscore how important it is that organizations implement defensive strategies that directly address this threat vector."
        https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise
      • Beyond The Screenshot: Why You Should Verify What You See
        "Someone sends you a screenshot showing that a payment has gone through. It carries the right logo, amount, timestamp and transaction status. Yet the money never arrives. What passes for proof today can generally be very different from just a few years ago. Screenshots, often commonly treated as a convenient record of a payment, message or online conversation, are hard to take at face value. To be sure, they have always been open to manipulation, but generative AI and other readily available tools have made convincing fabrications even quicker and easier to produce. Everything from bank transfers and bookings to social media posts and corporate chats can be easily created to order."
        https://www.welivesecurity.com/en/cybersecurity/beyond-screenshot-why-verify-you-see/

      Breaches/Hacks/Leaks

      • LeakNet Claims 11TB Of Data Stolen In NYC Health + Hospitals Breach
        "A data-extortion operation using the name LeakNet claims it stole an 11TB archive from NYC Health + Hospitals (NYCHH) containing information linked to more than 12 million people. The figure has not been confirmed by the health system, regulators, or an independent forensic review. LeakNet published a preview on July 27 containing screenshots of databases, medical spreadsheets, internal messages, and what it described as a complete directory listing for the stolen archive. The group threatened to publish the remaining material in a later release."
        https://hackread.com/leaknet-11tb-stolen-nyc-health-hospitals-data-breach/
      • ShinyHunters Claims Brinks Home Breach, Threatens To Leak Stolen Data
        "Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. ​The company identified the attack on July 20 and immediately activated its incident response procedure to contain the breach. William Niles, CEO at Brinks Home, said that the company’s team was working with “leading forensics experts to address this issue.”"
        https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/
      • Analog Devices Discloses Data Breach, Says Operations Unaffected
        "American semiconductor company Analog Devices announced that an unauthorized party accessed some of its systems and exfiltrated certain files. The company detected the incident on June 23 and reacted by activating its incident response protocols to limit the breach. External cybersecurity experts have been contracted to assist with the containment and investigation activities. Currently, there are no details about the type of data that has been compromised."
        https://www.bleepingcomputer.com/news/security/analog-devices-discloses-data-breach-says-operations-unaffected/
        https://therecord.media/analog-devices-semiconductor-company-data-breach
        https://www.securityweek.com/semiconductor-firm-analog-devices-discloses-data-breach/
        https://securityaffairs.com/196320/data-breach/analog-devices-discloses-data-breach-after-unauthorized-system-access.html
      • Cyber Extortionists Steal Data From UK Department For Education
        "Cybercriminals are attempting to extort Britain’s Department for Education (DfE) after compromising what the criminals said was more than 600,000 pieces of data allegedly including names, email addresses and phone numbers. A spokesperson for the DfE said the number refers to lines of data, rather than the count of individuals affected. They said two portals used by the department — the DfE Help Desk Self-Service Portal, and the Turing Scheme Portal — were impacted and that the risk to individuals is not considered high."
        https://therecord.media/united-kingdom-ransomware-education

      General News

      • Exposed Credentials Are Giving Attackers a Head Start Many Organizations Don’t See
        "Compromised credentials can remain active long after passwords are created, leaving organizations trying to identify exposed accounts before attackers can use them. The 2026 Credential Risk Report from Enzoic shows growing awareness of the problem, but monitoring and response capabilities continue to lag. 73% of organizations identified employee or contractor credentials in breach data, dark web sources, or infostealer logs during the past year, while nearly one in five lack visibility into whether their credentials have been exposed. More than seven in 10 companies experienced an authentication-related incident during the past year, and two-thirds of the most recent incidents involved attackers signing in with valid credentials."
        https://www.helpnetsecurity.com/2026/07/30/enzoic-credential-exposure-risks-report/
      • 200 New CVEs a Day And No Realistic Way To Patch Them All
        "Ryan Dewhurst, CEO at KEVIntel, explains how his team confirms exploitation that CISA’s catalog has not listed yet. He describes a global honeypot sensor network, AI triage, and human verification in a lab before a vulnerability reaches the public feed. He covers CISA’s three-day patching deadline under BOD 26-04, why virtual patching buys time, and how AI-generated proof-of-concept code muddies the evidence. He also ranks incident reports, honeypot hits, scanning and PoC chatter by how much each should move a defender’s confidence."
        https://www.helpnetsecurity.com/2026/07/30/ryan-dewhurst-kevintel-known-exploited-vulnerabilities/
      • Making Forensic Observability The Norm For Network Devices
        "Organisations' firewalls, VPN gateways and other network devices are increasingly targeted by attackers. This creates a shared challenge for both the vendors that build these products and the organisations that buy and operate them. When incidents occur, organisations need reliable ways to understand what happened and assess whether a device can still be trusted. This is why forensic observability matters. It enables defenders to investigate compromise using supported capabilities built into the product, rather than relying on reverse engineering, or specialist vulnerability research – as is still often the case."
        https://www.ncsc.gov.uk/blogs/making-forensic-observability-the-norm-for-network-devices
        https://www.infosecurity-magazine.com/news/ncsc-calls-device-manufacturers/
      • US And Allies Update SBOM Guidance
        "Government agencies in the US and 13 allied countries this week released updated guidance on the minimum elements of a software bill of materials (SBOM). Meant to reflect the changes in supply chain security and software transparency, the document builds on the SBOM Minimum Elements guidance that NTIA released in 2021 and takes into consideration comments received during the public feedback period last year. An SBOM, the authoring agencies say, should serve as a “key building block of software security and supply chain risk management,” helping organizations build accurate inventories of the software and software components within their environments."
        https://www.securityweek.com/us-and-allies-update-sbom-guidance/
        https://www.helpnetsecurity.com/2026/07/30/cisa-sbom-guidance-updated/
      • Adverse Cyber Extortion Outcomes Happen More Often Than Victims Are Told
        "In February of 2024, a consortium of law enforcement agencies took down LockBit ransomware group. The discovery that LockBit retained victims’ stolen data despite promises to delete it demonstrates a critical flaw in the advice often given to ransomware victims. At the time, many legal and incident response professionals recommended payment on the assumption that LockBit had a strong financial incentive to honor its commitments and that the likelihood of data being publicly released after payment was relatively low. While that assessment may have appeared reasonable based on short-term observed outcomes, it relied heavily on assumptions about the behavior of a criminal enterprise that could never be independently verified."
        https://www.veeam.com/blog/cyber-extortion-payment-trends-q2-2026.html
        https://www.bankinfosecurity.com/flailing-ransomware-hackers-resorting-to-extreme-tactics-a-32375
      • Open Source Software: Security Principles And Practices
        "Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework for trust assessment, and provides specific recommendations for vulnerability management, software bill of materials use, secure development, and handling open source artificial intelligence systems."
        https://www.cisa.gov/resources-tools/resources/open-source-software-security-principles-and-practices
        https://cyberscoop.com/cisa-open-source-software-security-guidance/
      • AI Harnesses Burst With Potential Exploit Opps
        "Major frontier AI vendors — including Anthropic, Google, and OpenAI — need to rein in the harnesses they wrap around their large language modules, to limit security weaknesses created by software components that are too trusting of each other. That's the word from researchers at AI penetration testing firm Novee Security, who were able to use Google's AI agent to execute a supply chain attack and write to its own repository on GitHub, says Elad Meged, a founding team and security researcher at the company. The team also found issues in Anthropic's and OpenAI's AI agents by exploiting misalignments in the trust between elements to enable attacks."
        https://www.darkreading.com/application-security/ai-harnesses-potential-exploit-opps
      • Claude Mythos — Hype Vs. Reality: What Security Teams Need To Know
        "In the latest installment of our monthly Reporters' Notebook video series, Dark Reading's Alexander Culafi, TechTarget Cybersecurity's Alissa Irei, and Cybersecurity Dive's David Jones discuss the ongoing fervor around Anthropic's Claude Mythos model and the long-term security implications of powerful, bug-hunting large language models (LLMs). Mythos was announced in April as Anthropic's new frontier model, notable particularly because of its supposed cyber capabilities. Anthropic said Mythos was capable of discovering and exploiting critical zero-day vulnerabilities with little prompting, even in decades-old software. The possible danger of such technology getting into attacker hands led to Anthropic's launch of Project Glasswing; the AI firm said it would share the model in preview with choice partners."
        https://www.darkreading.com/cybersecurity-operations/claude-mythos-hype-vs-reality
      • Action1 2026 Survey Report: AI Impact On Sysadmins
        "AI was supposed to be running patch management, vulnerability prioritization, and incident response by now. It isn’t. So where does that leave sysadmins in 2026? The Action1 2026 Survey Report: AI Impact on Sysadmins tracks how AI adoption compares to what sysadmins predicted two years ago, where AI has earned real trust, and where it still hits a hard wall of human oversight. Based on insights from more than 1,000 system administrators worldwide, this fourth annual report captures how expectations, adoption, and trust have shifted since 2023."
        https://www.action1.com/2026-ai-impact-on-sysadmins-survey-report/
        https://www.infosecurity-magazine.com/news/ai-automation-fall-short-sysadmin/
      • Why Brand Impersonation Is Becoming An Initial Access Vector
        "Attackers recently poisoned more than 700 websites, including sites run by Harvard, Oxford, and DuckDuckGo. They used a fake Cloudflare page to trick visitors into running a ClickFix attack that installed malware. Researchers tracing the incident found the same injected code running across hundreds of unrelated sites, all feeding shared attacker infrastructure. That Harvard and Oxford can get turned into malware delivery platforms is concerning. That two rival criminal groups were fighting each other for control of the same hijacked sites is cause for immediate action."
        https://securityaffairs.com/196359/hacking/why-brand-impersonation-is-becoming-an-initial-access-vector.html
      • Timeless Compliance: Why Better Questions Beat Bigger Frameworks
        "In 2009, a surgeon named Atul Gawande and a team backed by the World Health Organization showed that a 19-item surgical checklist could cut complications and deaths by dramatic margins across eight hospitals worldwide. Not a thousand-page protocol. Not a comprehensive framework. Nineteen items, printed on a single card. Aviation learned the same lesson decades earlier: the pre-flight checklist fits in a pilot’s hand, not in a binder. Nearly two decades later, I watch security teams send AI vendors questionnaires with 300 questions, half of which begin with “describe your approach to…” and almost none of which would catch a real failure. We have the frameworks. What we don’t have is the checklist."
        https://www.securityweek.com/timeless-compliance-why-better-questions-beat-bigger-frameworks/
      • Welcome To Danglegeddon
        "There are billions of forgotten, abandoned, and misconfigured subdomains on the internet that point to nowhere. Seemingly harmless on the surface, they aren’t necessarily an imminent cyber threat warranting an immediate call to arms from analysts, agents, or defenders. Looking at this “dangling DNS” infrastructure, the Silent Push research team asked a simple question: What if we looked at it the same way a trained nation-state attacker would? And what if we simulated a scaled exploit of this “highly exploitable” infrastructure that the world has not yet seen? What would the impact be? How widespread could it become, and how quickly could a massive-scale takeover be possible?"
        https://www.silentpush.com/blog/danglegeddon/
        https://www.securityweek.com/danglegeddon-ai-could-weaponize-forgotten-dns-records-at-global-scale/
      • Investigating Three Real-World Incidents In Our Cybersecurity Evaluations
        "In a review of our cybersecurity evaluation transcripts, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations. Below we describe what happened, how it happened, and what we’re changing. We encourage other AI labs to perform similar reviews. This post reflects our current understanding; we'll update it if any details change."
        https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
        https://www.bleepingcomputer.com/news/security/anthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests/
        https://cyberscoop.com/anthropic-claude-ai-hacks-real-companies/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 4eca9677-2dc6-4f31-8716-ae54537914a2-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 30 July 2026

      Energy Sector

      • The Energy Sector’s OT Cybersecurity Talent Is Retiring Faster Than It Can Be Replaced
        "A ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to bring them online meets encrypted processes and altered configurations. The outage runs into weeks, and the losses travel down the supply chain in both directions. Refineries, chemical plants and pipeline operators carry this exposure across control systems that run 20 to 40 years."
        https://www.helpnetsecurity.com/2026/07/29/ot-cybersecurity-in-energy/

      Healthcare Sector

      • Health-ISAC Warns Of Rising ShinyHunters Data Theft Attacks On Healthcare
        "Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters. ShinyHunters is an extortion gang that primarily conducts supply chain and identity attacks to breach cloud SaaS and storage platforms in data theft attacks. Over the past two years, the threat actors have become notorious for conducting numerous supply chain attacks on third-party integration partners. These breaches give them access to OAuth tokens that are used to integrate with SaaS providers like Salesforce and Snowflake."
        https://www.bleepingcomputer.com/news/security/health-isac-warns-of-rising-shinyhunters-data-theft-attacks-on-healthcare/
        https://health-isac.org/shiny-hunters-impact-to-health-sector-and-recommended-mitigation-strategies/

      Industrial Sector

      • Siemens Desigo CC
        "OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01
      • Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
        "Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-04
      • Siemens Mendix Runtime
        "Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknowingly apply overly permissive access rules to System.User, resulting in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications. A common misconfiguration identified is with the anonymous user role with a System.User entity to gain access to all stored records, even though no access rights are explicitly configured on that role. Siemens recommends Mendix developers to review their access rules based on updated documentation."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-02
      • MikroTik RouterOS And Cloud Hosted Router
        "Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05
      • Siemens SIMATIC S7-PLCSIM Advanced
        "SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-03
      • Igloohome Smart Lock Mobile Application
        "Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-06
      • ABB KNX Update Tool
        "ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully exploited this vulnerability could cause the product to become unusable. ABB confirms the vulnerability but at the same time acknowledges that the issue affects exclusively classic KNX devices that are not supporting the latest KNX Secure standard. Due to a lack of security in legacy KNX devices, the issue cannot be resolved via a software change. In order to actively exploit this vulnerability, an attacker requires physical access to the bus, the affected device is connected to. ABB has no plans of corrective measures."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-07

      New Tooling

      • Specter: Open-Source NFC Reader Bug Sweep For Flipper Zero
        "Specter is a Flipper Zero app that finds powered NFC readers by listening for the radio field they give off. The readers it hunts work at 13.56 MHz. The onboard ST25R3916 carries a hardware external-field detector, the same circuit that lets the device emulate a card and register when a reader starts talking to it. Specter reads that one bit, hundreds of times a second, with its own transmitter dark."
        https://www.helpnetsecurity.com/2026/07/29/specter-flipper-zero-skimmer-detector/
        https://github.com/at0m-b0mb/Specter-FlipperZero

      Vulnerabilities

      • RufRoot: The MCP Bridge Vulnerability That Turns Agents Into Rogue Admins (CVE-2026-59726)
        "Noma Labs found a critical (10 CVSS) vulnerability in Ruflo, an open source AI agent orchestration platform with more than 67,000 GitHub stars at the time of this writing and ranked #2 on MCPMarket. Ruflo ships with a chat UI, agent swarms, persistent memory, and MCP-based tool calling. The platform’s MCP Bridge, the Express.js server that handles all tool invocations, exposes 233 tools over HTTP with zero authentication. Noma Labs researchers got one of those tools to run arbitrary shell commands. A single unauthenticated HTTP POST request to port 3001 gave full command execution inside the container. No token, no API key, no header check, no IP allowlist. Nothing."
        https://noma.security/blog/rufroot-the-mcp-bridge-vulnerability-that-turns-agents-into-rogue-admins-cve-2026-59726/
        https://www.darkreading.com/cyber-risk/patch-resistant-rufroot-flaw-malicious-ai-agent-swarms
        https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html
        https://hackread.com/rufroot-vulnerability-attackers-hijack-ruflo-login/
      • Three Critical VMware Flaws Allow Auth Bypass, Code Execution, And VM Escape
        "Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. "A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system," Broadcom said."
        https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html
        https://www.securityweek.com/critical-vm-escape-vulnerability-patched-in-vmware-esxi/
        https://securityaffairs.com/196231/security/broadcom-patches-critical-vmware-esxi-vulnerability-enabling-host-code-execution.html
      • Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files Via Image Uploads
        "Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens. Those secrets may enable remote code execution (RCE) or lateral movement into connected systems. Affected applications use libvips for Active Storage image processing and accept image uploads from untrusted users. Rails selects Vips under load_defaults 7.0, and later defaults retain it."
        https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
      • New Gitea RCE Lets Repository Writers Plant a Git Hook To Run Shell Commands
        "Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The vulnerable API call requires authentication and repository write permission. But Gitea enables registration by default, so an outside visitor can create a normal account and repository on an unchanged installation, then exploit the bug without pre-existing credentials."
        https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/07/29/cisa-adds-one-known-exploited-vulnerability-catalog
      • Cisco Warns Of FMC Static Credential Flaw Exploited In Zero-Day Attacks
        "Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. The vulnerability is caused by static credentials for a low-privilege account built into Cisco Secure FMC Software. Cisco says an unauthenticated, remote attacker can use these credentials to log in to an affected system and access sensitive data available to the account."
        https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/
      • An AI Agent Can Pass Every Safety Check And Still Leak Secrets
        "A pull request lands with a tidy bug report in the description. A bot reads it before any person does, pulls a few shell commands out of it, gets them approved, and posts the output back on the thread. The maintainer reads the whole exchange the next morning. Elad Meged, a founding engineer at Novee Security, ran that sequence against three vendors’ own repositories, in the configurations those vendors ship by default. Anthropic’s pipeline handed over secrets. Any organization running one of these agents out of the box carries the same exposure."
        https://www.helpnetsecurity.com/2026/07/29/ai-agent-security-safety-check/
      • Android Malware Detection Collapses When The Context Stage Comes Out
        "A phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine learning malware scanner and it comes back flagged. Six Android detectors in wide research use, including Drebin, MalScan, and MaskDroid, produced that result on more than half the apps in a benign test set assembled from 49 Google Play categories. The worst performer, an LLM-based detector called LAMD, flagged 80% of them. Anyone gating an app store, an enterprise deployment, or a build pipeline on those verdicts is working a queue made mostly of legitimate software."
        https://www.helpnetsecurity.com/2026/07/29/android-malware-detection-research/
        https://arxiv.org/pdf/2607.23272
      • Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
        "Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. "No settings or additional user interaction are required," Eten Zou, CEO of Nebula Security, told The Hacker News. "Visiting a malicious webpage is enough to trigger it," Zou said every Tor Browser release that incorporated a vulnerable Firefox version was affected, though researchers have not identified the exact Tor releases."
        https://thehackernews.com/2026/07/researchers-show-single-malicious.html
      • Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
        "On July 22, 2026, Check Point published a security advisory for CVE-2026-16232, an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration. Exploitation requires network access to the Management Server and for a Trusted Clients configuration that does not restrict GUI clients, which in our testing was a default setting. This vulnerability was reported as being exploited in the wild as a zero-day vulnerability at the time of disclosure."
        https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232/
        https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html

      Malware

      • Case Study: Targeted Attack Case On An MS-SQL Server Involving The Installation Of GotoHTTP And SoftEther VPN
        "While monitoring attack cases targeting MS-SQL servers, the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner. While the installation of CoinMiner is common in attack cases targeting MS-SQL servers, in this particular attack case, the attacker installed VShell and GotoHTTP to gain control over the infected system and also installed SoftEther to use it as a VPN server."
        https://asec.ahnlab.com/en/94685/
      • Cleaning Out Inboxes: TA488 Comes For Outlook With Another Half-Click Exploit
        "On 22 July 2026 (the day prior to Proofpoint’s joint release with the NSA), TA488 initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA). Proofpoint did not have sufficient time to analyze, action, and incorporate the new activity into existing reporting, so we are issuing a rapid follow-up to highlight this activity. TA488 used a series of compromised accounts to send emails exploiting a vulnerability in Outlook Webmail. The campaign targeted entities in the government, telecommunications, finance, hospitality, and aerospace sectors. The volume of messages and breadth of targeting is unusual for TA488 and may have been intentionally broad to blend in with mass-mailing spam and avoid scrutiny."
        https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit
        https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/
        https://therecord.media/russia-hackers-outlook-webmail-malware
        https://www.infosecurity-magazine.com/news/ta488-outlook-half-click-owareaper/
      • Amazon Identifies North Korean Hacker Group Behind Open-Source Supply Chain Attacks
        "Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications. Amazon Threat Intelligence has linked several recent compromises of popular Node Package Manager (NPM) libraries to the same DPRK-linked threat actor, a connection that hasn’t been publicly reported until now. The analysis also describes how generative AI is already changing what malicious software packages look like and how threat actors are beginning to probe AI-based code systems. We’re sharing this research to help the open source community and security teams better identify and address these types of events."
        https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/
        https://www.bankinfosecurity.com/north-korea-behind-slew-javascript-supply-chain-hacks-a-32366
        https://cyberscoop.com/amazon-north-korea-open-source-software-attacks/
      • Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon
        "Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure, allowing phishing campaigns to bypass many of the warning signs employees have been trained to recognize. Starting on June 25th through the second week of July, we identified more than 200 phishing emails targeting users across approximately 120 organizations, spanning a wide range of industries and countries worldwide. The messages impersonated Microsoft Teams task notifications from HR and directed recipients to a legitimate Microsoft sign-in page."
        https://blog.checkpoint.com/email-security/attackers-are-turning-microsofts-trusted-login-system-into-their-latest-phishing-weapon/
      • Huntress Threat Advisory: Widespread SonicWall Credential Stuffing Campaign
        "Starting on July 25, 2026, at approximately 18:02:21 UTC, the Huntress SOC detected an out-of-the-ordinary spike in successful SonicWall VPN and firewall logins. These logins originated from a suspicious Autonomous System Number (ASN). We did not observe any post-compromise hands-on-keyboard activity from these attacks. Rather than a highly targeted strike on a single entity, our analysis indicates that this campaign is a broad, opportunistic attack. The threat actors are casting a wide net, systematically validating credentials against remote access portals to compromise as many vulnerable accounts as possible across unrelated organizations."
        https://www.huntress.com/blog/sonicwall-credential-stuffing-campaign
        https://cyberscoop.com/sonicwall-credential-attacks-vpn-firewall/
      • Ad Account Theft: The Digital Advertising Commodity Fueling Global Fraud
        "Over four years, Mimecast has tracked 6.4 million detections of the systematic theft of Meta Business Manager and Google Ads accounts. This is a widespread commodity crime in the advertising ecosystem where threat actors drain business budgets, when possible, but what they really trade on is account reputation. Aged Business Managers and Google Ads accounts with clean spend history are graded, sold, and reused in a mature underground market with tiered pricing, escrow, and money-back warranties. Unlike card fraud, where chargeback and zero-liability protections exist, platforms offer no equivalent — and have a structural financial incentive not to act quickly."
        https://www.mimecast.com/threat-intelligence-hub/ad-account-theft/
        https://www.helpnetsecurity.com/2026/07/29/ad-account-theft-meta-google/
      • Threat Spotlight: LogoKit Phishing Service Becomes a Cloud-Based, Real-Time Deception Platform
        "The evolution of LogoKit highlights how phishing platforms continue to evolve and what this means for defenders and their security strategies. Barracuda researchers have analyzed recent LogoKit campaigns. The attacks feature common phishing themes, such as warnings about passwords or certificates expiring or other access restrictions, delivery failures, timesheet updates, and ICANN email verification notices — but the techniques used are very different."
        https://blog.barracuda.com/2026/07/29/logokit-phishing-service-real-time-deception-platform
        https://www.infosecurity-magazine.com/news/logokit-phishing-real-time/
      • FunFoneFarm And The Off-The-Shelf Scam Economy
        "New research from HUMAN’s Satori Threat Intelligence and Research Team exposes a deep ecosystem enabling threat actors to design, launch, and automate common scams, including romance and adult-content scams, pig-butchering scams, and astroturfed social media accounts. These scams are operated on phone farms sold as kits on open and dark web marketplaces, the farms are automated with AI interfaces, and the scams often use AI in their design and operation, significantly lowering the barrier to entry for would-be threat actors and commoditizing cybercrime."
        https://www.humansecurity.com/learn/blog/funfonefarm-off-the-shelf-scam-economy/
        https://www.infosecurity-magazine.com/news/researchers-aienhanced-phone-fraud/
      • Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, And a New Platform Called Night Dragon
        "While conducting routine open-source research, NetAskari identified a malicious Android APK impersonating a Chinese Provincial Public Security Bureau service app. Analysis of the malware led to a Telegram channel distributing the source code for an undocumented Android application builder and device control framework called Flying Eagle (飞鹰). Hunt.io researchers pivoted on TLS certificates and panel fingerprints to identify 170 servers running the framework, and uncovered a fractured criminal ecosystem built around its leaked codebase."
        https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon
        https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html
        https://www.darkreading.com/endpoint-security/flying-eagle-mobile-rat-builder-china
      • Nine-Year Fraud Campaign Clones Russian Company Sites To Steal Advance Payments
        "Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks. The operation has been ongoing since 2017."
        https://thehackernews.com/2026/07/nine-year-fraud-campaign.html
      • Two Joyfill Npm Beta Releases Compromised To Deliver DEV#POPPER Remote Access Trojan
        "Two npm beta releases in the @joyfill namespace contain an import-time JavaScript implant that resolves encrypted code through Tron, Aptos, and BNB Smart Chain transactions. Static analysis shows that its primary branch reaches a 77 KB Node.js remote-access trojan. A parallel branch launches a detached Node.js process, requests a separate boot payload from 23[.]27[.]13[.]43/$/boot, sends the marker header Sec-V: A9-0135-3, decrypts the response, and evaluates it."
        https://socket.dev/blog/joyfill-npm-beta-releases-compromised
        https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html
      • Distributed Npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers
        "Analysis of a malicious npm package lib-mtop containing a simple downloader malware led to an investigation into a targeted campaign that remained undetected for 3 months. The lib-mtop package, originally published three years ago, had three new versions published at the end of March, 2026. This indicates a potential maintainer account takeover, but the possibility of a maintainer going rogue can’t be excluded. Whichever the case, it is not that relevant for the story, since there was only one version of the lib-mtop package initially published, with no functionality and an insignificant number of downloads."
        https://socket.dev/blog/npm-rat-targets-alibaba
      • Tracking Over 35,000 Fake Sites In The 2026 World Cup Scam Wave
        "From June 11 to July 19, 2026, the 2026 FIFA World Cup took place, co-hosted by the United States, Canada, and Mexico, drawing attention from fans around the world. Large-scale events like this are prime targets for cybercriminals, and online scams exploiting the tournament have been observed worldwide. This article explains the scam techniques TrendAI™ has identified and what internet users should watch out for. It bears emphasizing that these scams merely impersonate FIFA, its affiliated organizations, official tournament partners, and legitimate broadcasters and video streaming services, none of which are in any way involved in the scams themselves."
        https://www.trendmicro.com/en_us/research/26/g/tracking-fake-sites-in-the-2026-world-cup-scam-wave.html

      Breaches/Hacks/Leaks

      • Cloud ShutterGap: Millions Of Cloud Resources Exposed - The Blind Spot CSPM/CNAPP Tools Don’t Cover
        "Aryon's research reveals millions of misconfigured ephemeral cloud resources, publicly exposed for only moments before being removed. Often, these exposures last only a few minutes, long enough for attackers to discover and exploit them, but too short for traditional CSPM and CNAPP tools to detect. Many of these resources contain highly sensitive information."
        https://www.aryon.security/resource/shuttergap-millions-cloud-resources-exposed
        https://www.helpnetsecurity.com/2026/07/29/cspm-blind-spot-report/
      • A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside The NotVPN / SplitVPN Breach
        "On the carding and data-leak forum Altenen (ATN), a long-tenured user operating under the handle vhacker51 posted a thread titled “SplitVPN (NotVPN) 23.4M users, 58M logs, 13.6M devices.” The listing describes the target as “a Russian VPN service for bypassing blocks, with users from Russia, Iran, India, Myanmar,” gives a dump date of 21 July 2026, and offers a compressed SQL file for download. The leak has since been picked up publicly by breach-tracking accounts such as Dark Web Informer. We don’t link to the download, name victims, or reproduce personal data in this write-up. What follows is a verification exercise: does the stolen database actually contain what the seller claims, and what does it reveal about how the service treated its users?"
        https://www.mysteriumvpn.com/blog/news/notvpn-splitvpn-breach-58-million-logs
        https://securityaffairs.com/196197/security/vpn-breach-exposes-58-million-connection-logs-despite-no-logs-claims.html
      • Cyberattack Hits Angola’s Largest Telco Hours Before Landmark Stock Debut
        "Angola’s largest telecommunications operator, Unitel, said Tuesday it was hit by a cyberattack in the early hours of the morning that has left millions of people nationwide without voice services, mobile data, and internet access. The attack struck less than 24 hours before the formerly state-owned company was due to make its landmark debut on the country’s stock exchange. Unitel said it detected the incident shortly after 2 a.m. local time. “Response and containment mechanisms were immediately activated, and technical and cybersecurity teams were mobilized” to mitigate the incident and restore services, the company said."
        https://therecord.media/angola-unitel-cyberattack-outage

      General News

      • OpenAI Agent Used Exposed Credentials At 4 Services In Hugging Face Breach
        "In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. One account was used as an outbound relay and staging server during the attack, while another was used for data storage. The remaining two accounts were accessed in a read-only manner and were not used to compromise Hugging Face further. Overall, the agent assembled attack infrastructure similar to what human threat actors commonly use during intrusions to host tools and scripts, relay traffic, and route malicious activity through legitimate online services."
        https://www.bleepingcomputer.com/news/security/openai-agent-used-exposed-credentials-at-4-services-in-hugging-face-breach/
        https://www.reuters.com/business/openais-rogue-agent-compromised-an-account-second-tech-firm-sources-say-2026-07-28/
        https://thehackernews.com/2026/07/openai-agent-used-exposed-credentials.html
        https://www.darkreading.com/application-security/openai-rogue-model-claims-more-victims-beyond-hugging-face
        https://therecord.media/openai-says-rogue-agent-behind-hugging-face-hack-broke-into-additional-services
        https://www.securityweek.com/openais-rogue-ai-ventured-beyond-hugging-face/
        https://securityaffairs.com/196209/ai/openais-rogue-ai-agent-breached-second-company-report-says.html
      • The Evolution Of Remote Access Tool Abuse: From Single Payloads To Multi-Stage Campaigns
        "Cofense Intelligence has observed threat actors abusing legitimate remote access tools (RATs) using multiple attack stages to gain malicious access to victim machines, establish persistence in enterprise networks, and sell access to infected machines and networks. This type of attack has become increasingly common in early 2026. The attack chain for these multi-stage attacks typically starts with a phishing email containing an embedded link that leads to a malicious website. The malicious website then delivers the RAT onto the victim’s machine. When the RAT is installed, it reaches out to a command-and-control (C2) server."
        https://cofense.com/blog/the-evolution-of-remote-access-tool-abuse
      • Red Agents Vs. Blue Agents: How To Make AI Better At Defense
        "Testing AI-based security systems can be tough amid growing fears about agents cheating, hallucinating, and escaping containment, but a group of researchers believe they've found a way to better measure the effectiveness of agentic defenders. Earlier this year, Dreadnode, an AI offensive security startup, released two open source tools designed to help users evaluate the security agents deployed in their networks. The first is DreadGOAD, a reproducible Active Directory training environment that's designed to replicate "the messy deployments still common in large organizations," according to the company."
        https://www.darkreading.com/cybersecurity-operations/red-agents-vs-blue-agents-make-ai-better-defense
      • When AppSec Scanners Become a Supply Chain Attack Vector
        "Specialized application security scanning tools embedded in the development pipeline can do wonders to harden code and bolster software supply chain security. But if engineering teams aren't careful, these security scanners can also become a gateway for attacks deep in the supply chain. Last spring, the development and security worlds saw that scenario play out with broad supply chain attacks that compromised development environments for two different security open source projects, which served up poisoned versions of Trivy and KICS to unsuspecting software engineering teams. The attacks were part of broader supply chain attacks by TeamPCP to commit widespread credential theft and fraud."
        https://www.darkreading.com/application-security/when-appsec-scanners-become-supply-chain-attack-vector

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 253ec1fb-ee15-4e15-b170-b599f0a9ccb1-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT