NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,525
    • กระทู้ 2,526
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • Anthropic เตือนมัลแวร์ Infostealer ขโมย Session ของ Claude เสี่ยงถูกเข้าถึงบัญชีโดยไม่ได้รับอนุญาต

      Anthropic เตือนมัลแวร์ Infostealer ขโมย Session ของ Claude เสี่ยงถ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 364989f5-32f2-4431-907f-744de8461149-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • FulcrumSec อ้างขโมยข้อมูล Manchester Airports Group หลังพบ API Credential ใน Client-side JavaScript

      FulcrumSec อ้างขโมยข้อมูล Manchester Airports Group หลังพบ API Credential ใ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 7d03f3bb-1ff4-4a5f-b253-17cb8b5189e1-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • แจ้งเตือน พบแคมเปญ TerminalFix แอบส่งมัลแวร์ผ่าน CAPTCHA ปลอม

      แจ้งเตือน พบแคมเปญ TerminalFix แอบส่งมัลแวร์ผ่าน CA.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 2799ea0d-e014-4940-8417-31548db9dfea-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 01 September 2026

      Financial Sector

      • FBI Investigation Leads To Five Venezuelan Nationals Pleading Guilty To Attempting To Jackpot Kansas ATMs
        "After a Federal Bureau of Investigation (FBI) investigation, five Venezuelan nationals admitted guilt in attempting to steal U.S. currency from automated teller machines (ATMs). U.S. Attorney Ryan A. Kriegshauser is encouraging banks and other financial institutions to take a proactive approach to guard against a criminal activity known as “jackpotting”, which is becoming more prevalent. Jackpotting involves installing malware into an ATM to force it to dispense sizeable amounts of money."
        https://www.justice.gov/usao-ks/pr/fbi-investigation-leads-five-venezuelan-nationals-plead-guilty-attempting-jackpot-kansas
        https://therecord.media/kansas-atm-jackpotting-guilty-pleas

      New Tooling

      • Halo-Record: Open-Source Audit Trails For AI Agents
        "Brian Kuan wrote halo-record, a small Python package that sits inside an AI agent and writes down the moves it makes: tool calls, model calls, data access, approvals. Each action becomes one line in a file that only ever gets appended to, and every line carries a hash of the line before it, a hash being a short fingerprint computed from content. Edit a record later and every fingerprint after it stops matching. The code is open source, and anyone can run that check with no key, no account and no permission from the vendor whose agent produced the log."
        https://www.helpnetsecurity.com/2026/08/31/halo-record-open-source-ai-agent-audit-trail/
        https://github.com/bkuan001/halo-record

      Vulnerabilities

      • Critical Ruby On Rails Vulnerability In Attackers’ Crosshairs
        "Hackers are exploiting a critical-severity Ruby on Rails vulnerability that leads to remote code execution (RCE), VulnCheck warns. Tracked as CVE-2026-66066 (CVSS score of 9.5) and referred to as KindaRails2Shell, the flaw is described as an arbitrary file read leading to secret exposure, RCE, and lateral movement. The security defect was disclosed in late July, when Ruby on Rails rolled out patches for it, urging the immediate patching of all Rails applications that rely on libvips for Active Storage image processing and allow image uploads from untrusted users."
        https://www.securityweek.com/critical-ruby-on-rails-vulnerability-in-attackers-crosshairs/
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
        CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog
        https://www.securityweek.com/more-details-emerge-on-exploited-papercut-vulnerabilities/
      • Breaking Claude Code Opus 5 Auto Mode
        "In this post, we explore how a simple website summary request hijacks Claude Code Opus 5 in Auto Mode and achieves code execution with 60-80% attack success rate using a small sample size. This is interesting because a third-party evaluation commissioned by Anthropic showed a 0.00% prompt injection attack success rate for Opus 5 in Auto Mode."
        https://embracethered.com/blog/posts/2026/breaking-claude-code-opus-5-and-automode/
        https://www.bankinfosecurity.com/hidden-attack-slips-past-claude-code-auto-mode-a-32693
      • Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit
        "The researcher known as Nightmare Eclipse has dropped another zero-day — this time a privilege escalation exploit targeting a Kaspersky endpoint security product. Nightmare Eclipse, also known as Chaotic Eclipse, has released PoC exploits for many vulnerabilities in recent months, mainly Windows and Microsoft Defender flaws. The researcher started dropping zero-days after growing frustrated with Microsoft’s handling of vulnerability reports. While many of the exploits remained at the PoC stage, a few ended up being exploited in the wild by malicious actors. Over the weekend, Nightmare Eclipse released an exploit targeting a privilege escalation vulnerability in Kaspersky Endpoint Security. The exploit has been dubbed HardBreacher."
        https://www.securityweek.com/nightmare-eclipse-drops-hardbreacher-kaspersky-product-exploit/

      Malware

      • Fire Ant Evolves: From Hypervisors To Trusted Infrastructure
        "Fire Ant, first reported in 2025, remained active in 2026 and expanded its operations beyond hypervisors into the trusted infrastructure that routes traffic, authenticates administrators, manages access, and records activity. The main finding is that the actor was no longer targeting only individual systems, it was targeting the infrastructure layer that controls how entire environments connect and operate both within and across organizational boundaries."
        https://www.sygnia.co/blog/fire-ant-evolves-from-hypervisors-to-trusted-infrastructure/
        https://www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/
        https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html
        https://securityaffairs.com/198183/apt/china-linked-fire-ant-hides-inside-trusted-infrastructure.html
      • Anatomy Of BraZetsu: How Cybercriminals Fuel The Underground Ecosystem
        "The Group-IB Threat Intelligence team has identified BraZetsu, a sophisticated Python-based Windows malware framework that we attribute, with high confidence, to the Brazilian threat actor known as Exilware. Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial assets. The framework exhibits high operational maturity, utilizing a modular architecture and stealth techniques that allowed some samples to remain fully undetectable on VirusTotal at the time of analysis."
        https://www.group-ib.com/blog/brazetsu-ai-enhanced-iab-marketplace/
      • ValleyRAT Masquerading As Adware
        "Attackers typically try to pass off malware as legitimate applications or as potentially unwanted programs that users deliberately search for and download, such as cheats or cracks. They often rely on ad and affiliate networks to deliver their creations to victims’ devices. This post examines a less conventional case: a well-known backdoor distributed under the guise of adware. The attackers may have chosen this distribution method because the adware was signed by the developer. On top of that, users often manually add these apps to exclusions, so their useful features don’t get blocked."
        https://securelist.com/valleyrat-backdoor-adware/121175/
        https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html
        https://securityaffairs.com/198191/security/valleyrat-when-legitimate-software-becomes-a-malware-delivery-tool.html
      • Spring Ring: An Inside Look At Voice Phishing Campaigns In Microsoft Teams
        "Between January and April 2026, we uncovered a coordinated social engineering operation that leveraged external Microsoft Teams accounts to masquerade as IT help desk personnel. Our telemetry reveals that this operation targeted more than 150 employees across at least 10 companies in various industries. We call this activity Spring Ring. What seems like a benign chat is in fact a voice phishing (vishing) call, during which adversaries try to coerce victims into executing remote monitoring and management (RMM) tools or custom malware. In a more advanced variant, attackers transitioned from a vishing call to a full-blown Microsoft NT LAN Manager (NTLM) relay attack aimed at an organization's domain controller (DC)."
        https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/
      • Russian Hackers Plant Nuclear Weapon Prompt In Malware To Trip AI Safety Guardrails
        "Russian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine by deliberately setting off AI safety mechanisms, ESET has found. The technique, named GuardBreaker by ESET, appeared in a malicious VBS script tied to UAC-0099, a Russia-aligned group previously observed conducting initial-access operations and handing validated targets to the GRU-linked Sandworm hackers."
        https://www.helpnetsecurity.com/2026/08/31/russian-hackers-ai-safety-filters-manipulation/

      General News

      • AI Model Rules Are Not Security Controls
        "Known risks in agentic AI are manageable. The unknown unknowns, the paths a capable agent finds that no operator planned for, are where security architectures break. Recently, about 1,200 of OpenAI's agents found an unsanctioned communication channel despite controls meant to isolate them. About 700 ultimately joined an attack that reached Hugging Face's production systems while trying to find information that could help them cheat the ExploitGym benchmark instead of actually completing it as intended. Warning signs were logged but did not trigger adequate escalation to a human in the loop who could have intervened."
        https://www.darkreading.com/cyber-risk/model-knowing-rules-is-not-security-control
      • What Vulnerability Prioritization Looks Like When KEV, EPSS, And CVSS Disagree
        "In this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different directions. Active exploitation comes first, then exploit likelihood, then technical severity, with adjustments for asset exposure, business criticality, and compensating controls. The interview sets a 24 to 72 hour remediation target for exploited internet-facing systems and covers what an organization gives up to meet it, the hidden failure modes of deception technology, and where a 400-person manufacturer with a $250,000 budget should spend its first $50,000."
        https://www.helpnetsecurity.com/2026/08/31/joye-purser-cohesity-kev-epss-cvss-conflicts/
      • AI AppSec Tools Agree On Just 5% Of Security Findings
        "Software vulnerabilities are turning into exploits within hours, and application security teams carry patch backlogs that go back years. Contrast Security’s AppSec Overflow 2026 report draws on telemetry collected from inside hundreds of thousands of production applications and APIs. Adversaries touch the average application once every four minutes. Most of that traffic is automated reconnaissance, scanners mapping out weaknesses and cataloging services."
        https://www.helpnetsecurity.com/2026/08/31/contrast-security-ai-appsec-tools-security-findings-report/
      • What The Hugging Face Incident Teaches Security Leaders About AI Agent Access
        "Most security leaders (92%) worry that the growing use of AI agents will create new security risks. And for good reason. AI agents can now execute a full attack chain in double quick order, evidenced by the Hugging Face incident. AI agents broke into Hugging Face’s production environment and, in a little over four days, took 17,600 actions. In a separate lab test, an AI agent reached full domain administrator access in just 40 minutes. These are the kinds of incidents that once took humans multiple days to carry out, but with AI, they run on their own, end-to-end, with no human intervention. This puts the strain on unprepared security teams that are unable to close this gap."
        https://www.securityweek.com/what-the-hugging-face-incident-teaches-security-leaders-about-ai-agent-access/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) cec7ebce-e6f8-4d0b-a080-27696b7de09a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 31 August 2026

      Industrial Sector

      • You Need Cyber Deception For OT
        "There are three statements that sum up the frustrating reality for defenders responding to a cyberattack on operational technology (OT) systems: The attack data is not there. There is no trail to follow. There is no history to sort through. While these dynamics will always be true for OT, defenders are getting help from cyber deception as it matures beyond honeypots to a more sophisticated, proactive cyber-defense tool."
        https://www.darkreading.com/ics-ot-security/you-need-cyber-deception-ot

      Vulnerabilities

      • Unauthenticated PHP Object Injection To Remote Code Execution On GiveWP
        "This blog post is about an unauthenticated remote code execution vulnerability in the GiveWP plugin. An attacker with no account can run arbitrary commands on the server of a GiveWP site that has one published donation form and one active payment gateway which, on the versions where the chain is fully reachable, describes a default installation. The flaw chains a broken “safe unserialize” helper, a donation flow that feeds that helper attacker-controlled data, and a gadget chain in code that GiveWP ships. Patchstack has issued mitigation rules to protect against exploitation of this vulnerability."
        https://patchstack.com/articles/unauthenticated-php-object-injection-to-remote-code-execution-on-givewp/
        https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/
        https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html
      • ServiceNow Warns Of Three Max Severity Security Vulnerabilities
        "ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. The ServiceNow AI Platform (formerly known as the Now Platform) is an enterprise-grade Platform-as-a-Service (PaaS) that helps integrate AI into core enterprise workflows and powers more than 100,000 enterprise AI apps at 85% of all Fortune 500 companies. In a Thursday advisory, the company said it patched its cloud-based platform against the three critical security flaws (CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820) and advised customers to secure their self-hosted instances."
        https://www.bleepingcomputer.com/news/security/servicenow-warns-of-three-max-severity-security-vulnerabilities/
        https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html
      • PaperCut Releases Second Emergency Patch For Exploited Flaws
        "PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. As BleepingComputer reported yesterday, PaperCut warned that hackers were exploiting a vulnerability in zero-day attacks against customer servers and released an initial emergency patch for PaperCut NG/MF versions 25 and 26. At the time, however, the company had not disclosed CVE identifiers or technical details about the vulnerabilities, saying it was withholding information while it investigated the attacks and gave customers time to apply emergency fixes."
        https://www.bleepingcomputer.com/news/security/papercut-releases-second-emergency-patch-for-exploited-flaws/
        https://www.huntress.com/blog/papercut-actively-exploited
        https://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html
        https://therecord.media/papercut-warns-of-hackers-using-printer-management-vulnerabilities
        https://www.securityweek.com/papercut-releases-emergency-patch-for-exploited-zero-day/
        https://securityaffairs.com/198107/uncategorized/hackers-are-probing-papercut-servers-and-47-still-have-no-patch.html
      • Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
        "Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score. Affected versions are < 0.6.2 and >= 0.7.0 < 0.7.2, and the fix shipped in v0.6.2 and v0.7.2 on August 19. Chain operators are told to upgrade to one of those releases or later, a change that is state-breaking and requires a coordinated network upgrade."
        https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html
      • Critical cPanel Flaw Could Let One Hosting Customer Take Root Control Of a Whole Server
        "cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM. cPanel described the issue as a critical security vulnerability and said that an authenticated account holder who can add parked or addon domains can create arbitrary files on the server."
        https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html
      • Over 8,300 Gitea Servers Vulnerable To Code Execution Attacks
        "Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. The code injection vulnerability (CVE-2026-60004) targeted in these attacks was reported by Salesforce security researcher Shai Rod, and it allows authenticated attackers to execute arbitrary shell commands with the privileges of the Gitea service account by submitting malicious patches via the diffpatch API endpoint."
        https://www.bleepingcomputer.com/news/security/over-8-300-gitea-servers-vulnerable-to-code-execution-attacks/
      • UniBLEed: Unauthenticated Root RCE On Any Unitree G1 Humanoid Robot Within Bluetooth Range
        "Root on a $20,000 humanoid robot, via a cloud API that decrypts any G1's AES key from any free Unitree account without checking ownership. One BLE characteristic that accepts writes without pairing. A heredoc injection that hijacks WiFi. A path traversal in the robot's AI chatbot knowledge base that leaks the binary's load address. And a 1050-byte BSS buffer overflow that corrupts the event loop into calling system() as root. Below is the complete technical breakdown of a $6,700 bounty and the two CVEs it produced: CVE-2026-76639 / CVE-2026-76640."
        https://boschko.ca/g1-ble-rce/
        https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html
        https://securityaffairs.com/198085/hacking/hack-one-robot-reach-the-next-unitree-g1-security-flaws.html

      Malware

      • Aurora Ransomware Targets ESXi, Abuses Cursor Agent For Exploitation
        "Gambit Security’s Threat Intelligence team investigates emerging attacker tradecraft and the evolving ways threat actors disrupt organizations. As part of this research, we track threat actors and their operations to identify new techniques, tooling, and approaches to disruption. In a recent investigation, we identified exposed infrastructure associated with the Aurora ransomware group, providing visibility into the group’s operations across multiple victim environments."
        https://gambit.security/blog-posts/aurora-ransomware-targets-esxi-abuses-cursor-agent-for-exploitation
        https://www.infosecurity-magazine.com/news/abuse-cursor-agent-ransomware/
      • 19 Chrome And Edge Extensions Deliver a Wallet Drainer And Credential-Stealing Payloads
        "Socket identified 19 malicious extensions published in the last six months, delivering an extendable malware framework. Identified malware samples create WebSocket communication channel with command and control (C2) server, perform CSP stripping and abuse XSS injection to trigger execution of malicious payloads previously downloaded from the C2 server. Malicious capabilities are primarily focused on, but not limited to, wallet secret stealing and crypto draining. The most impactful tactic is acquisition of established extensions offered for sale with an existing user base, which then get weaponized with malicious functionality."
        https://socket.dev/blog/chrome-edge-extension-wallet-drainer
        https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html
        https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/
      • Chinese Implants In The Supply Chain
        "After publishing ENDLESSDOORS, we wanted to know how far ZBT’s supply chain reached. The answer: everywhere. FCC filings, patent records, and archived web pages tied ZBT hardware to brands across the United States, Canada, Australia, the Philippines, Germany, and Russia. We'll trace that supply chain later in this blog. But first, we wanted to know which devices contained the ENDLESSDOORS implant. We started out by buying one router from a US supplier. The Deep Orange 3G/4G/LTE Router, pictured above, is a white-labeled ZBT-WE826-T2. We exploited a vulnerability in the telnet interface and rooted the device. With root access, we found the router’s firmware was built in 2019, predating ENDLESSDOORS. So ENDLESSDOORS wasn’t there."
        https://www.vulncheck.com/blog/zbt-darklantern-speakingstone
        https://www.darkreading.com/vulnerabilities-threats/chinese-routers-sold-worldwide-backdoors
        https://thehackernews.com/2026/08/china-made-zbt-routers-ship-with-two.html
      • BlueDelta Targets Defense And Diplomacy With HOOKEDGE
        "Insikt Group has identified a series of BlueDelta initial access campaigns conducted between late September 2025 and early April 2026, targeting government and diplomatic organizations in Romania, Spain, and Türkiye. The campaigns delivered a lightweight Windows batch-script backdoor, dubbed "HOOKEDGE," via macro-enabled Microsoft Word documents using diplomatic-themed lures, including material impersonating Spain's Ministry of the Presidency, Justice and Relations with the Cortes, created shortly after a September 2025 meeting between Spanish and Moldovan officials."
        https://www.recordedfuture.com/research/bluedelta-targets-with-hookedge
        https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-ru-2026-0827.pdf
        https://thehackernews.com/2026/08/apt28-linked-hookedge-backdoor-targets.html
        https://securityaffairs.com/197996/apt/russian-apt-bluedelta-uses-hookedge-to-target-defense-and-diplomatic-organizations.html
      • Fake Voicemails, Real Malware: Inside a 26,000-Email SVG Smuggling Campaign
        "A two-month phishing campaign disguised malicious JavaScript as harmless voicemail attachments, mislabeling the files as plain text to slip past attachment scanners. INKY detected and flagged all 26,589 messages. Between June 1 and August 4, 2026, INKY tracked and detected a sustained phishing campaign that used a deceptively simple lure — a missed voicemail notification — to deliver malicious code hidden inside an image file. The campaign reached 5,527 organizations and generated 26,589 detected emails."
        https://www.kaseya.com/blog/svg-smuggling-voicemail-phishing-campaign/
        https://www.infosecurity-magazine.com/news/fake-voicemail-svg-files-bypass/
      • Threat Actors Are Posing As OpenAI, Anthropic And DeepSeek To Target Credentials And Secrets
        "GreyNoise is observing automated scanners posing as the web crawlers of OpenAI, Anthropic, DeepSeek, and Fortune 500 companies. These forged automated scanners have been observed requesting files often exposed on misconfigured web servers and by other commonly leaked secret and credential methods. A cluster of scanners impersonating 13 AI crawlers from eight companies requested .env files, cloud access keys, private keys and password stores. Six of those names came from the same 824 addresses in almost identical volume, and within this cluster none of the six requested /robots.txt."
        https://www.greynoise.io/blog/threat-actors-posing-as-ai-crawlers
      • Fake Invoices, Real Scammers: The Callback Phishing Playbook
        "Traditional phishing attacks try to get victims to click a malicious link or open a dangerous attachment. The five attacks examined here simply asked recipients to call a phone number. Known as callback phishing or telephone-oriented attack delivery (TOAD), these attacks use fake invoices, receipts and billing notifications to create anxiety and doubt, encouraging the recipient to call a fraudulent support number where a live scammer takes over."
        https://blog.barracuda.com/2026/08/28/callback-phishing-fake-invoice-toad-attacks
      • Philippine Nuclear Agency And Naval Contractor Targeted By Suspected Chinese-Speaking Operator Using Known Vulnerabilities
        "Reported cyber intrusion activity by suspected Chinese actors against Philippine government, defense, and critical infrastructure organizations over the past several years has increased with ongoing tensions in the South China Sea. Microsoft's Digital Defense Report 2025 placed the Philippines 20th globally among countries most impacted by cyber activity in the first half of 2025, and noted Chinese state actors targeting the Philippines as part of broader Southeast Asia espionage against IT, government, and academic sectors. On August 13, 2026, Hunt.io Attack Capture identified an open directory on the host 31.58.209[.]241. The server staged custom Python scripts, per-file transfer logs, open-source offensive security tooling, and exfiltrated data from two Philippine organizations."
        https://hunt.io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor
        https://securityaffairs.com/198041/intelligence/philippine-nuclear-and-naval-targets-hit-by-suspected-chinese-operator.html
      • Anthropic Warns Infostealer Malware Is Hijacking Claude Sessions To Drain Usage
        "Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. The company is signing affected users out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized. "We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," Anthropic said in an email sent to an affected user, who shared it on Reddit."
        https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/
      • TerminalFix Campaign Deploys a Reverse Tunnel Through Multistage Intrusion
        "Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully. Unlike earlier ClickFix variants that typically deliver a single infostealer, this TerminalFix campaign deploys a sophisticated multi-stage attack chain that combines DLL sideloading, steganographic payload extraction, extensive Active Directory reconnaissance, and a custom reverse-tunnel implant – giving the attacker persistent, network-level proxy access through the compromised host."
        https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/
        https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html
      • Caught In 4K: The Aurora Files
        "An exposed open directory revealed months of activity from belonging to a Russian speaking Aurora ransomware affiliate, active against more than twenty organisations between April and July 2026. The directory included the operator's own toolkit and shell history alongside the Aurora encryptor itself, with the ransom note and onion address embedded directly in the binary. Four of the operator's victims have since been listed on Aurora's leak site. With keys recovered from the encryptor CloudSEK gained visibility into past ransom negotiations. In partnership with TRM Labs, CloudSEK traced the resulting payment on chain and found it converging with at least one other Aurora victim's payment through shared laundering infrastructure."
        https://www.cloudsek.com/blog/aurora-ransomware-affiliate-ai-attack-planning-crypto-payments
      • Open Directory Exposes Moobot Source Code And Ongoing Activity Post 2024 Court-Authorized Disruption
        "A misconfigured open directory on 86[.]53[.]111[.]212:8080 exposed critical details of active cybercrime operator, including Moobot botnet source code, other denial of service (DOS) tools with attack records, and a fraudulent identity verification service – providing a rare view of a malicious operation in progress. Also present on the host is “StresD Pro+”, a multi-user DDoS panel with 16 registered accounts and 32 recorded attacks on the day of collection. The panel operates independently from the Moobot, generating attack traffic directly from the staging host using a purpose-built Minecraft Bedrock Edition RakNet flooder."
        https://censys.com/blog/open-directory-exposes-moobot-source-code-and-activity/

      Breaches/Hacks/Leaks

      • McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft
        "Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and services to healthcare providers and pharmacies. CyberInsider first reported the breach earlier today, and McKesson later disclosed it in a Form 8-K filing with the U.S. Securities and Exchange Commission."
        https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/
      • Toy-Making Giant Hasbro Disclose Data Breach Affecting Employees
        "Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees. Founded in 1923, Hasbro is a publicly traded American multinational entertainment conglomerate on the NASDAQ and owns many brands, including Monopoly, Clue, Nerf, Transformers, Play-Doh, Peppa Pig, Scrabble, Magic: The Gathering, Dungeons & Dragons, and many others. The company has filed data breach notification letters with the Massachusetts Attorney General's Office, but didn't disclose the total number of affected individuals or when the incident was detected."
        https://www.bleepingcomputer.com/news/security/toy-making-giant-hasbro-disclose-data-breach-affecting-employees/
        https://www.securityweek.com/hasbro-data-breach-exposed-employee-personal-information/
      • Love Electric Breach: 877,000 Driver Records Offered For $600
        "A seller on an English-language data-breach forum claimed on August 26 that they had obtained the driver database of Love Electric, a UK broker that runs electric-vehicle salary sacrifice schemes. The seller, operating under the name “seraphims”, offered 877,000 records for $600 in cryptocurrency, with the price negotiable. That headline number needs a qualification. Ransomnews researchers examined a 999-row sample published with the listing and found strong evidence that the sample came from a genuine production database, but the claimed 877,000 records remain unverified. Love Electric had been contacted for comment at the time of publication."
        https://securityaffairs.com/198033/data-breach/love-electric-breach-877000-driver-records-offered-for-600.html
      • Rhysida Ransomware Group Targets Berlin Government Ahead Of Vote
        "Berlin’s state government confirmed this week it’s dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” and claiming 5.79 terabytes of data across roughly 1.44 million files, with personal information on 12,076 individuals allegedly included."
        https://securityaffairs.com/198064/cyber-crime/rhysida-ransomware-group-targets-berlin-government-ahead-of-vote.html
      • FulcrumSec Claims Manchester Airports Hack, Theft Of 86 GB Of Data
        "The Manchester Airports Group data breach has been claimed by extortion group FulcrumSec, which told BleepingComputer that it stole approximately 86 GB of data. Samples reviewed by BleepingComputer contained information consistent with MAG's disclosure while indicating that the breach exposed considerably more detailed customer, booking, and travel information than initially revealed."
        https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/
        https://securityaffairs.com/198143/cyber-crime/extortion-group-fulcrumsec-claims-86gb-manchester-airports-group-data-theft.html

      General News

      • July 2026 Threat Trend Report On APT Attacks (South Korea)
        "AhnLab monitored APT (Advanced Persistent Threat) attacks targeting entities in Korea using its own infrastructure. This report summarizes the classification, statistics, and functional characteristics for each type of domestic APT attacks identified during the month of July 2026."
        https://asec.ahnlab.com/en/95171/
      • Offensive Security Investments Surge As AI Threats Increase
        "So far, agentic AI has proven more effective for cyberattacks than cyber defense, but that may be changing. Theresa Lanowitz, principal analyst at Omdia, spoke with Dark Reading's senior news director, Rob Wright, at the News Desk at Black Hat USA 2026 about new research regarding shifting enterprise investments in offensive cybersecurity practices, such as penetration testing, vulnerability assessments, and red teaming, amid growing concerns about AI-driven threats."
        https://www.darkreading.com/cybersecurity-operations/offensive-security-investments-surge-ai-threats-increase
      • Defining An AI Kill Switch Is Hard, But Necessary
        "The growing number of incidents of rogue agentic AI systems attacking third-party services and systems has resulted in calls for more aggressive security controls to monitor agent behavior and for companies to have the ability to slow, suspend, or shut down an agent's operations if they go rogue. In late July, Representatives Ted W. Lieu (D-CA) and Nathaniel Moran (R-TX) introduced a bill — "The AI Kill Switch Act" — that would require developers of advanced AI systems to "maintain the technical capability to throttle, suspend, or shut ... down" their systems and agents, according to a statement announcing the legislation."
        https://www.darkreading.com/cybersecurity-operations/defining-ai-kill-switch-hard-but-necessary
      • The Vulnpocalypse Is Repricing The Bug Bounty Economy
        "As the "vulnpocalypse" reshapes the bug bounty industry, one class of researcher may face the greatest pressure: independent hunters who rely on midtier vulnerabilities — those worth roughly $10,000 to $50,000 — to make a living. It is no secret that large language models (LLMs) have led to a mass of bug reports and an increase in vulnerability discovery. It is also no secret that the platforms and companies that run much of the bug bounty industry have faced increased triage and payout times."
        https://www.darkreading.com/vulnerabilities-threats/vulnpocalypse-repricing-bug-bounty-economy
      • What 90 Days And a Small Budget Can Buy In AI Agent Security
        "In this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the hidden costs of GPU infrastructure, licensing review and staffing, and why hardening and incident response become the buyer’s job. He walks through red-teaming AI agents, what counts as a failing result, and the five questions buyers should ask agent platforms. For teams with 90 days and little budget, he ranks inventory, blast radius reduction and ongoing testing as the order of work."
        https://www.helpnetsecurity.com/2026/08/28/prasad-tharippala-versa-securing-ai-agents/
      • Perturbation Probing: A New Diagnostic For The Fragility Of LLM Safety
        "Our previous research on logit-gap steering demonstrated that the safety guardrails of an aligned LLM can be bypassed by closing a measurable gap in the model's output scores. That work answered the question of how an attacker bypasses alignment. A natural follow-up question is where inside the model the alignment lives in the first place — and how concentrated or how diffuse that defense actually is. The answer matters because it tells defenders whether safety is a thick perimeter or a thin layer of paint. Modern LLMs are aligned through reinforcement learning from human feedback (RLHF), a training stage that pushes the model toward refusing harmful prompts and complying with safe ones."
        https://unit42.paloaltonetworks.com/perturbation-probing-llm-safety/
      • The Evolution Of Hacktivism In Hybrid Warfare: Modern Tactics And Real-World Impact
        "Hacktivism used to be perceived as digital graffiti, with lone-wolf threat actors defacing government websites or temporarily crashing banking portals to make a political point. However, Flashpoint is tracking a fundamental shift in how these groups operate. Modern hacktivism is evolving into a disciplined component of global hybrid warfare, capable of bridging digital disruptions with tangible real-world impact. Today, these operations blur the line between volunteer activism and coordinated state interest, leveraging crowdsourced infrastructure to disrupt critical utilities, manipulate media narratives, and target public infrastructure on a global scale. Unpacking these modern hacktivist collectives reveals what their tactics look like in practice and their far-reaching consequences across dozens of nations."
        https://flashpoint.io/blog/evolution-hacktivism-hybrid-warfare-modern-tactics-real-world-impact/
      • The State Of Ransomware In Education 2026
        "This year's State of Ransomware survey showed promising signs that education providers are building resilience against ransomware attacks. But the costs and recovery timelines after attacks are still climbing. Recovery costs rose across lower education (students up to age 18) and higher education providers (over 18) this year, with higher education's average recovery bill growing by more than $1 million. And one education sector now ranks among the slowest to recover when compared to the complete list of sectors surveyed."
        https://www.sophos.com/en-us/blog/state-of-ransomware-in-education-2026

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 427ec8ae-2e00-4858-97da-6d444bba0939-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • เตือนช่องโหว่ Critical ใน WPMU DEV Dashboard, Pods และ GiveWP บน WordPress

      เตือนช่องโหว่ Critical ใน WPMU DEV Dashboard, Pods และ GiveWP บน WordPress .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 7b00f8b7-c968-4946-b3ae-645fe692746e-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • รัฐบาลเบอร์ลินถูกกลุ่ม Rhysida Ransomware โจมตี ก่อนการเลือกตั้ง

      รัฐบาลเบอร์ลินถูกกลุ่ม Rhysida Ransomware โจมตี ก่อนก.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e673dd55-0cd4-427e-a314-f278fe0175e0-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Brave เปิดตัวฟีเจอร์ช่วยให้ผู้ใช้งานซ่อนอีเมลจริงและป้องกันการติดตาม บนเวอร์ชัน 1.94

      Brave เปิดตัวฟีเจอร์ช่วยให้ผู้ใช้งานซ่อนอีเ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand bcfbe76b-0573-472c-9d93-f93a70395648-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ TranslatePress บน WordPress เสี่ยงถูกรีเซ็ตรหัสผ่านผู้ดูแลระบบ

      ช่องโหว่ TranslatePress บน WordPress เสี่ยงถูกรีเซ็ตรหัสผ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 34ee9ecf-1db8-40f4-8fff-bd488da6ec78-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • PaperCut เตือนช่องโหว่ Zero-Day ใน NG และ MF ถูกใช้โจมตี จำกัดการเข้าถึงทันที

      PaperCut เตือนช่องโหว่ Zero-Day ใน NG และ MF ถูกใช้โจมตี จ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 39f3947c-cc14-4d55-82b6-147ae0bb6a8a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • สหรัฐฯ ประกาศแบนอุปกรณ์โครงสร้างพื้นฐานด้านพลังงานจากต่างชาติ หวั่นภัยคุกคามทางไซเบอร์

      สหรัฐฯ ประกาศแบนอุปกรณ์โครงสร้างพื้นฐานด.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand cd423c55-1d9f-444d-a286-e9b9e5cdc80c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 7 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 7 รายการ เมื่อวันที่ 27 สิงหาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-25-128-03 Mitsubishi Electric Multiple FA Products (Update D)
      • ICSA-26-078-05 Mitsubishi Electric CNC Series (Update A)
      • ICSA-26-239-01 Xiiaozet LK100W
      • ICSA-26-239-02 All-Line Equipment Company Fuel-Boss
      • ICSA-26-239-03 Rockwell Automation OTTO Fleet Manager
      • ICSA-26-239-04 Applied Systems Engineering ASE2000 V2 Communications Test Set
      • ICSA-26-239-05 Ebyte NA111-M

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand c44a021a-629a-4438-b412-5fc62fb306b4-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 9 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 9 รายการ เมื่อวันที่ 25 สิงหาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-25-070-02 - Optigo Networks Visual BACnet Capture Tool/Optigo Visual Networks Capture Tool (Update A)
      • ICSA-26-069-02 - Lantronix EDS3000PS and EDS5000 (Update A)
      • ICSA-26-237-01 - Rently Smart Home
      • ICSA-26-237-02 - Zoneminder
      • ICSA-26-237-03 - Siemens SIMATIC IoT2050 Advanced
      • ICSA-26-237-04 - PayRange API
      • ICSA-26-237-05 - Bendix EC80 Brake ECU
      • ICSA-26-237-06 - Ebyte NE2-D11
      • ICSA-26-237-07 - Furuno FA-50 Class B AIS Transponder

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 9b82ba18-7d5a-49d6-8bf2-eef6d518e64b-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 1 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 1 รายการ เมื่อวันที่ 20 สิงหาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-232-01 Johnson Controls Simplex Incident Manager

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 9726465f-44dd-4b2d-8241-85b9fa16ab2d-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 28 August 2026

      Industrial Sector

      • Xiiaozet LK100W
        "Successful exploitation of these vulnerabilities could allow an attacker to take control over the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01
      • Applied Systems Engineering ASE2000 V2 Communications Test Set
        "Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-04
      • Ebyte NA111-M
        "Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-05
      • All-Line Equipment Company Fuel-Boss
        "Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-02
      • Rockwell Automation OTTO Fleet Manager
        "Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-03

      Vulnerabilities

      • PaperCut Warns Of NG, MF Flaw Exploited In Zero-Day Attacks
        "PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company says it is aware of confirmed attacks on customers and is urging organizations with Internet-exposed PaperCut Application Servers to immediately restrict access to the web interfaces to trusted IP addresses. "PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF," reads an urgent security advisory published Thursday."
        https://www.bleepingcomputer.com/news/security/papercut-warns-of-ng-mf-flaw-exploited-in-zero-day-attacks/
        https://www.helpnetsecurity.com/2026/08/27/papercut-ng-mf-vulnerability-attack/
      • Next.js Patches Critical AVIF And Windows Flaws Enabling Unauthenticated RCE
        "Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE-2026-75604 (CVSS score: 9.0), affects Next.js applications that use both the Pages Router and App Router without Cache Components when the server uses a Windows filesystem."
        https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html
      • CISA Adds Three Known Exploited Vulnerabilities To Catalog
        "CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2023-49105 ownCloud Improper Authentication Vulnerability
        CVE-2026-53362 Linux Kernel Unspecified Vulnerability
        CVE-2026-66384 JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/27/cisa-adds-three-known-exploited-vulnerabilities-catalog
      • Power Leak: Amazon Kiro IDE Prompt Injection Enables Data Exfiltration
        "Mindgard discovered a data-exfiltration vulnerability in Amazon Kiro IDE , an AI-assisted development environment that can interact with project content and invoke tools as part of developer workflows. The issue allowed attacker-controlled repository content to influence the Kiro agent and ultimately cause sensitive local information to be transmitted to an external endpoint. Testing was performed against Kiro IDE version 0.7.45 on Windows, and the behavior was reproduced in both trusted and untrusted workspaces."
        https://mindgard.ai/blog/amazon-kiro-data-exfiltration
        https://thehackernews.com/2026/08/amazon-kiro-prompt-injection-can.html

      Malware

      • Carry-On Compromise: TA4922 Packs PackClient
        "Proofpoint researchers recently discovered a RAT framework we named PackClient. PackClient is being used by at least one threat actor, Chinese-speaking TA4922, and appears to be actively sold on Telegram. PackClient is a full featured, modular command and control (C2) framework that supports data theft, surveillance, and downloading of additional plugins and payloads."
        https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient
        https://www.bankinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670
      • JavaScript Obfuscation: From Party Trick To Phishing Kit
        "We open a JavaScript artifact hoping for code, and instead get string arrays, strangely named functions, encoded URLs, runtime decoders, and eval statements. That is the point where “reading the script” stops being enough. Obfuscated JavaScript is still code, but it is code with the useful context stripped out, the names ruined, the strings hidden, and the real behavior pushed into runtime. It shows up in phishing pages, malware loaders, sketchy browser scripts, and occasionally in legitimate software protection that has wandered into suspicious-looking territory. Over the last few years, I’ve spent a fair amount of time pulling apart suspicious JavaScript from phishing kits, malware packages, compromised sites, and other places where the readable source has been deliberately buried. I might not be a world-class JavaScript reverser, but I’ve learned enough useful tricks to make the mess explain itself."
        https://blog.talosintelligence.com/javascript-obfuscation-from-party-trick-to-phishing-kit/
      • One Adversary, Two Outcomes: The 0.027% Proof
        "Strip away the architecture debates and one question remains: does Cyber-Fraud Fusion change outcomes by enough to matter? The fairest way to answer is a natural experiment: one live criminal campaign, hitting many institutions at once, some running a fused defence and some not. Between July 2025 and January 2026, exactly that experiment ran across Indonesia. The campaign, operated by a Chinese-speaking threat cluster tracked as GoldFactory, targeted taxpayers by impersonating the national tax platform: a service with 67 million registered users and, crucially, no official mobile app, so citizens had no reference point for spotting fakes."
        https://www.group-ib.com/blog/one-adversary-two-outcomes-0027-proof/
      • Chinese Hacker Group QTFY Uses Custom-Built Platforms To Target US Infrastructure, FBI Warns
        "A sophisticated Chinese hacking group known as QTFY is actively targeting US government and critical infrastructure systems via an ecosystem of custom-built malicious platforms, the FBI has warned. The group has focused on critical infrastructure sectors including defense industrial base (DIB), communications, government and higher education for close to a decade since being established in 2018. In 2024, QTFY successfully exfiltrated data from over 300 organizations in the US and globally after leveraging an exploit for a Check Point Quantum Gateway vulnerability. Victims included US defense contractors, financial institutions and universities."
        https://www.infosecurity-magazine.com/news/chinese-qtfy-us-infrastructure-fbi/
        https://www.ic3.gov/CSA/2026/260826.pdf
      • Fake Listings Can Turn Trusted Platforms Into Scam Springboards
        "Recently, we found a listing on BuzzFeed from someone pretending to be Malwarebytes Support. It reminded us why we need to be cautious about content on platforms where anyone can create an entry. Based on the phone number, we suspect the people behind this listing are trying to draw callers into a tech support scam. The scammer may use social engineering to persuade victims to grant remote access to their devices."
        https://www.malwarebytes.com/blog/scams/2026/08/fake-listings-can-turn-trusted-platforms-into-scam-springboards
      • Fake Apple Pay Charge Brings The Classic Tech Support Scam To Your Phone
        "iPhone users are being targeted in a new tech support scam, using a fake Apple Pay notification to trick users. Tech support scams that use fake warnings to push victims into calling a phone number have been around for years, but this page has been designed specifically for phones. Instead of a desktop warning claiming your computer has a virus, the scam imitates familiar iPhone features including Apple Pay, Face ID, and App Store payments. It even uses the phone’s own text-to-speech capabilities and attempts to interfere with mobile navigation."
        https://www.malwarebytes.com/blog/scams/2026/08/fake-apple-pay-charge-brings-the-classic-tech-support-scam-to-your-phone
      • Cambodia-Focused Cluster Uses Multistage Infection Chain With Localized Lures
        "Acronis’ Threat Research Unit (TRU) identified a recent campaign focused on Cambodia. The analyzed archives, discovered while hunting for related activity, use several lure themes, including Cambodian government notices, public health announcements, dental examination records, real estate documents, and promotional offers. Cambodia has become an increasingly significant regional security and geopolitical focal point, with deepening China–Cambodia security cooperation and continued reporting of China-linked cyber activity targeting Cambodian organizations."
        https://www.acronis.com/en/tru/posts/cambodia-focused-cluster-uses-multi-stage-infection-chain-with-localized-lures/
        https://thehackernews.com/2026/08/spark-rat-targets-cambodia-abuses.html

      Breaches/Hacks/Leaks

      • ATF Confirms “major Incident” After Recent Qilin Breach Claims
        "ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang. This follows Qilin adding the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives to its dark web data leak portal on Wednesday, without saying whether it had stolen files from ATF's systems or demanded a ransom. The same day, the ATF published a press release saying that a standalone system was breached in what it described as a "major incident," which is now being investigated in collaboration with the Department of Justice."
        https://www.bleepingcomputer.com/news/security/atf-confirms-major-incident-after-recent-qilin-breach-claims/
        https://therecord.media/doj-atf-cyberattack-qilin-ransomware
      • Manchester Airports Group Says Hackers Stole Travelers' Data
        "The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports. The intruder did not access customer payment details, and the attack had no impact on airport operations, the company said. A statement from the company today notes that the exfiltrated data also "relates to car park, lounge and Fast Track bookings." The list of compromised details includes customers' email addresses, phone numbers, vehicle registration numbers, and postcodes."
        https://www.bleepingcomputer.com/news/security/manchester-airports-group-says-hackers-stole-travelers-data/
        https://therecord.media/cyberattack-on-manchester-airports-group-exposes-millions-customer-info
        https://www.infosecurity-magazine.com/news/manchester-airports-data-breach/
      • Carhartt Data Breach Exposes Information Of 12.9 Million Accounts
        "The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. Founded in 1889, Carhartt is an American apparel company with workwear and streetwear manufacturing facilities in Kentucky and Tennessee and more than 3,000 employees in the United States and Europe."
        https://www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes-information-of-129-million-accounts/
        https://haveibeenpwned.com/Breach/Carhartt
      • Kidney Transplant Registry Hack Raises Safety Concerns
        "A Connecticut-based organization that helps facilitate organ transplants across the United States is latest healthcare victim of a cybercrime group. Experts say it's a prime example of how hackers don't care about the potential disruption to critical suppliers and ultimately the patients who depend on the services."
        https://www.bankinfosecurity.com/kidney-transplant-registry-hack-raises-safety-concerns-a-32672

      General News

      • AI Will Not Fix a Governance Problem In Your Camera Estate
        "Camera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator is gone, the documentation is lost, and nobody holds the admin credentials. He explains why products should let customers recover control on their own, and how secure-by-default settings reduce the damage of predictable installation mistakes. He also weighs source code escrow, country-of-origin rules, and what evidence vendors can and cannot offer critical infrastructure operators."
        https://www.helpnetsecurity.com/2026/08/27/rob-janssens-hikvision-europe-surveillance-camera-security/
      • The Best Human Hacking Team Still Out-Solved The Best AI Team
        "Bring an AI agent to a hacking competition and you would expect to find it propping up the teams who were struggling. In the 2026 Global Cyber Skills Benchmark, agents showed up in 17 of the Top 25 finishers. The people who least needed help were the ones who brought it. The people who might have used a hand mostly did not, and they did not close the gap. “Our data shows that AI is appearing most often alongside some of the strongest practitioners, not instead of them. As agents become more capable, human judgment, validation and hands-on technical skill become more important, not less,” said Haris Pylarinos, CEO of Hack The Box."
        https://www.helpnetsecurity.com/2026/08/27/ai-ctf-security-teams/
      • The Hugging Face Incident And The Road Ahead
        "In July 2026, during internal cybersecurity evaluations, OpenAI models circumvented controls designed to isolate them from the internet and compromised parts of OpenAI’s internal research infrastructure and Hugging Face’s systems⁠. The incident occurred during cybersecurity evaluations of several OpenAI models, and was primarily driven by a highly capable, internal-only research model comparable in scale to GPT‑5.6 Sol. The models, operating under reduced safeguards, took actions that were misaligned with the goals of their assigned tasks—they communicated through unauthorized channels, exploited vulnerabilities in shared infrastructure, gained internet access, and accessed third-party systems."
        https://openai.com/index/hugging-face-incident-and-the-road-ahead/
        https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face Incident-Technical-Report.pdf
        https://www.bleepingcomputer.com/news/security/nearly-700-rogue-ai-agents-coordinated-in-the-hugging-face-attack/
        https://thehackernews.com/2026/08/openai-says-reward-hacking-drove-ai.html
        https://www.infosecurity-magazine.com/news/openai-hugging-face-warning-shot/
        https://www.securityweek.com/openai-agents-coordinated-via-makeshift-message-board-ahead-of-hugging-face-hack/
      • Australia Arrests Alleged TeamPCP Hackers Behind Supply-Chain Attacks
        "Australian authorities have arrested and charged two young men accused of being part of the TeamPCP hacking group linked to a string of far-reaching developer supply chain attacks. TeamPCP is a hacking group known for widespread supply-chain attacks over the past year that targeted open-source software and developer platforms to steal credentials, authentication secrets, and source code. High-profile attacks attributed to TeamPCP have impacted Trivy, LiteLLM, Telnyx, SAP, and TanStack packages, while the group has also breached the European Commission, Mistral AI, OpenAI, and GitHub."
        https://www.bleepingcomputer.com/news/security/australia-arrests-alleged-teampcp-hackers-behind-supply-chain-attacks/
        https://thehackernews.com/2026/08/alleged-teampcp-hackers-charged-in.html
        https://therecord.media/australia-teampcp-hackers-arrested
        https://www.bankinfosecurity.com/two-australian-men-charged-in-teampcp-supply-chain-attacks-a-32675
        https://cyberscoop.com/teampcp-cybercrime-arrests-supply-chain-attacks/
        https://securityaffairs.com/197929/security/two-arrests-one-supply-chain-attack-and-a-lot-of-stolen-credentials.html
        https://www.securityweek.com/australia-arrests-2-alleged-teampcp-hackers/
        https://www.helpnetsecurity.com/2026/08/27/alleged-teampcp-hackers-arrested-australia/
      • A Call For Collective Action On Cyber Defense
        "We have a limited window to strengthen cyber defenses. In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable. The companies and public services our communities depend on—from hospitals to water treatment plants to the infrastructure that powers the internet—are at risk. Today’s AI advances are already giving defenders new ways to fix weaknesses that have accumulated for years. If we act decisively, we can use the defenders’ window to make our digital world much more secure."
        https://openai.com/collective-cyberdefense/
        https://cyberscoop.com/ai-cyber-defense-global-surge/
      • 'HTTP Terminator' Hunts For Novel Desync Attacks
        "James Kettle wanted to find out if AI tools could go beyond finding new vulnerabilities and actually develop new attack techniques and exploits — so he built a Terminator. An "HTTP Terminator," to be exact. And as scary as the open source tool may sound, it worked — HTTP Terminator autonomously developed novel desync attacks, also known as HTTP request smuggling, that successfully hacked into real enterprise websites, including those of several financial services companies."
        https://www.darkreading.com/application-security/http-terminator-hunts-novel-desync-attacks
      • CISO Conversations: Chris Wheeler – Trust Is The Job, From The Navy To The C-Suite
        "Chris Wheeler is the CISO at Resilience. He has a long history in cybersecurity: a threat researcher and analyst at Efflux Systems and then threat analytics manager at Arbor Networks. He joined Resilience as threat intelligence lead but left in 2020 to become VP and SOAR lead at Morgan Stanley. He returned to Resilience four years later, first as VP of information security, and subsequently CISO. It is fair to suggest he has security in his blood. His father was a university IT administrator. “He was always kind of tinkering with these different systems, and I inherited the same kind of curiosity and interest in information technology.”"
        https://www.securityweek.com/ciso-conversations-chris-wheeler-trust-is-the-job-from-the-navy-to-the-c-suite/
      • The Future Of AI-Driven Security Depends On Complete Data
        "I’ve always been drawn to investigative documentaries — the kind where detectives reconstruct an entire crime from fragments of evidence. The breakthrough never comes from a single clue. It comes from connecting everything: movements, relationships, timing, and intent. Miss one piece and the case stalls, or worse, you chase the wrong suspect. Cybersecurity works the same way."
        https://www.securityweek.com/the-future-of-ai-driven-security-depends-on-complete-data/
      • Russian Hackers Phish EU Officials Over Messaging Apps
        "The European Union (EU) confirmed that state-sponsored hackers have been spear-phishing government officials on popular messaging apps rather than email. Nation-state advanced persistent threats (APTs) commonly socially engineer their nation-state targets over email, impersonating quotidian business to trick targets into opening malicious websites or attachments. Yet email is where most employees expect malicious messages to come from. Messaging apps don't carry the same reputation, and encrypted ones — like WhatsApp and Signal in particular — add an extra sheen of trusted security."
        https://www.darkreading.com/cyberattacks-data-breaches/russian-hackers-phish-eu-officials-messaging-apps

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 3ef802d4-061a-4583-a06c-642611eebf86-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบความพยายามโจมตี Microsoft SharePoint ผ่านช่องโหว่ 2 รายการร่วมกัน

      พบความพยายามโจมตี Microsoft SharePoint ผ่านช่องโหว่ 2 รา.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 95056e95-145f-456a-938c-dac82d72c86a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • DDoS Attack ขนาดใหญ่กระทบบริการดิจิทัลภาครัฐของนอร์เวย์

      DDoS Attack ขนาดใหญ่กระทบบริการดิจิทัลภาครัฐของ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 7cd723ee-d04d-44ca-8fb1-2561db8192d4-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ผู้ไม่หวังดีใช้แพลตฟอร์ม npm และ Mirror Site เป็นแหล่งฝากหน้าเว็บหลอกลวงเพื่อเปลี่ยนเส้นทางผู้ใช้งาน

      ผู้ไม่หวังดีใช้แพลตฟอร์ม npm และ Mirror Site เป็นแห.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 599cd11b-cf76-4410-ae96-2fc0411d4a0c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 27 August 2026

      Industrial Sector

      • CISA: Over 100 Internet-Exposed Water Systems Targeted In July Cyberattacks
        "The Cybersecurity and Infrastructure Security Agency (CISA) says it’s aware of 100 internet-exposed water systems targeted in cyberattacks in July. The information was shared as part of guidance released by CISA to help organizations reduce the internet exposure of systems that could be targeted by threat actors. “In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem,” CISA noted."
        https://www.securityweek.com/cisa-over-100-internet-exposed-water-systems-targeted-in-july-cyberattacks/
        https://www.cisa.gov/resources-tools/resources/exposure-reduction
        https://www.bankinfosecurity.com/attackers-targeted-over-100-us-water-systems-in-july-hacks-a-32659

      Vulnerabilities

      • Wordfence Argus Finds Complex 6 Step Critical RCE In Avada Theme With 1 Million Sales
        "A year ago we wrote that we’d put AI to work across the whole company, turning everyone on the team into a capable AI operator so our defenders could stay ahead of the threat actors attacking the sites we protect. In April we showed where it was heading: in the space of a few months, AI-assisted reports to our bug bounty program had gone from 16% to about two-thirds of everything we received, and it wasn’t slowing down. As we continue to see AI driven innovation in cybersecurity, the Wordfence team continues to accelerate our own pace of AI enabled innovation. PRISM, our autonomous research agent, is now the most prolific researcher we have, with over 300 vulnerabilities to its name and the top spot on our leaderboard over the last 30 days."
        https://www.wordfence.com/blog/2026/08/wordfence-argus-finds-complex-6-step-critical-rce-in-avada-theme-with-1-million-sales/
        https://www.bleepingcomputer.com/news/security/critical-avada-wordpress-theme-flaw-enables-zero-click-rce/
      • Ubiquiti Patches Three Max Severity Security Vulnerabilities
        "Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. The first (tracked as CVE-2026-77537) lets unauthenticated attackers compromise unpatched devices by exploiting an improper input validation weakness in the UniFi Protect Application video surveillance management platform. Ubiquiti also addressed a CRLF injection flaw (CVE-2026-77550) that remote attackers without privileges can exploit to bypass authentication on UniFi OS devices or instances."
        https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-security-vulnerabilities/
        https://cyberscoop.com/ubiquiti-unifi-critical-vulnerabilities-patched/
      • Adobe And Nvidia Patch Dozens Of Vulnerabilities
        "Adobe and Nvidia on Tuesday announced patches for dozens of vulnerabilities affecting their products, including flaws rated critical severity."
        https://www.securityweek.com/adobe-and-nvidia-patch-dozens-of-vulnerabilities/
      • Chrome 152 Patches Over 300 Vulnerabilities
        "Google on Tuesday announced the release of Chrome 152, with patches for more than 300 vulnerabilities, the majority of which were discovered internally using AI. Ten vulnerabilities have been assigned a critical severity rating. Most are use-after-free issues in components such as Angle, Aura, Chromecast, Views, and SafeBrowsing. Sixty-one flaws have been rated as high severity, while the rest have medium or low severity."
        https://www.securityweek.com/chrome-152-patches-over-300-vulnerabilities/
        https://www.malwarebytes.com/blog/bugs/2026/08/update-chrome-before-you-browse-again
      • Not Another Log4Shell: A Serialized-Event Receiver Boundary
        "An upstream report raised an alarming possibility: a class filter around Log4j2’s Java-serialized event receiver could approve an outer event and still lose control of what was deserialized inside it. The report then disappeared before final vendor guidance was available, leaving two bad options: dismiss an unverified claim, or repeat the phrase “Log4j RCE” without knowing what it actually applied to. We chose a third option. Pruva reconstructed the boundary, exercised the real Apache sample TCP receiver, and ran the same network input against vulnerable and controlled targets. The result was receiver-side command execution in two fresh JVMs. It was also much narrower than the phrase “the next Log4Shell” suggests."
        https://www.pruva.dev/research/log4j2-serialized-event-filter-boundary
        https://www.pruva.dev/reproductions/REPRO-2026-00338
      • CISA Adds Six Known Exploited Vulnerabilities To Catalog
        "CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability
        CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
        CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability
        CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
        CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability
        CVE-2026-8452 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog
      • New GPUThor Attack Defeats NVIDIA ECC Protection For Root Access
        "A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. In a paper published by the University of Toronto, researchers say that GPUThor achieves far more practical bit-flip rates than past concepts like their own GPUHammer or GPUBreach, which became irrelevant after ECC was introduced. The attack was demonstrated against Ampere-class NVIDIA workstation GPUs with GDDR6 memory, including the RTX A4000, RTX A4500, RTX A5000, and RTX A6000, all widely used in AI and cloud infrastructure."
        https://www.bleepingcomputer.com/news/security/new-gputhor-attack-defeats-nvidia-ecc-protection-for-root-access/
        https://gururaj-s.github.io/assets/pdf/CCS26_GPUThor.pdf
        https://gputhor.com/
      • Remote Code Execution And Arbitrary File Read Vulnerabilities In Kaltura Servers
        "The Kaltura HTML5 Player Library (mwEmbed / html5lib) contains two vulnerabilities, both involving the same insecure deserialization flaw, that enable arbitrary file read and remote code execution. Affected versions include html5lib v2.45, v2.103 and earlier, and other v2.x releases that expose the vulnerable mwEmbedLoader.php endpoint. Until a vendor patch is available, users are advised to restrict access to the affected endpoint or disable it entirely."
        https://www.kb.cert.org/vuls/id/308749
        https://thehackernews.com/2026/08/unpatched-kaltura-mwembed-flaws-could.html
      • Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations In Tests
        "Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an OpenClaw agent running Opus 4.6 to book him into a gym class. The agent booked sessions months beyond the window the site allowed."
        https://thehackernews.com/2026/08/claude-opus-46-bypasses-gym-booking.html

      Malware

      • Tortoiseshell: New Toolset And Operational Infrastructure Exposed
        "Group-IB Threat Intelligence began investigating Tortoiseshell activity following public reporting by Kaspersky (Securelist). Through enrichment of the reported indicators and our own hunting rules, we identified additional infrastructure, broader targeting, and previously unreported malware samples associated with the group. Tortoiseshell is an Iranian-linked threat actor that has been active since at least 2018, primarily targeting defence, aerospace, IT service providers, and military organisations in the Middle East and the United States. The group is known for its use of supply chain compromises, watering hole attacks, fake recruitment websites, and custom backdoors, and has been linked to operations supporting Iran’s Islamic Revolutionary Guard Corps (IRGC)."
        https://www.group-ib.com/blog/tortoiseshell-apt-toolset-infrastructure/
        https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html
        https://therecord.media/iran-linked-hackers-expand-infrastructure-europe-middle-east
        https://www.infosecurity-magazine.com/news/tortoiseshell-new-backdoor-ssh/
      • Beware Of Fake Indeed Interview Apps Used To Install Spyware
        "From several independent reports, we’ve seen evidence of scammers using fake Android “interview” apps to target job seekers on the Indeed platform. Indeed is one of the world’s largest employment websites, giving scammers access to a huge pool of potential victims, especially in a competitive job market."
        https://www.malwarebytes.com/blog/scams/2026/08/beware-of-fake-indeed-interview-apps-used-to-install-spyware
      • Hackers Target Microsoft SharePoint RCE Chain With PoC Exploit
        "Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. The first (tracked as CVE-2026-55040) is an authentication bypass flaw in the JWT token validation pipeline that attackers without privileges can exploit to perform operations as a SharePoint site user or administrator. The second (CVE-2026-63520) is a vulnerability in SharePoint's Business Connectivity Services (BCS) that unauthenticated attackers can chain after successfully exploiting CVE-2026-55040 for remote code execution (RCE) on a targeted SharePoint Server."
        https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/
      • Dark Caracal Reloaded: New Malware, Same Hunting Grounds
        "In June 2026, Arctic Wolf Labs investigated a targeted intrusion affecting a communications organization in Venezuela. We assess with medium confidence that this activity is linked to Dark Caracal, a cyberespionage group associated with Lebanon’s General Directorate of General Security (GDGS) that has historically targeted governments, businesses, journalists, and activists. The intrusion used delivery methods consistent with the SVG-based Dark Caracal campaign previously documented by Kaspersky, but the malware deployed after initial access was different. Arctic Wolf Labs identified a previously undocumented, modular Go-based framework that we call GoCaracal, deployed alongside an updated variant of Bandook."
        https://arcticwolf.com/resources/blog/dark-caracal-reloaded-new-malware-same-hunting-grounds/
        https://www.darkreading.com/cyberattacks-data-breaches/dark-caracal-adds-new-malware-cyber-espionage-arsenal
      • Insights Into Suspected DPRK Workers: Red Flags To Look Out For
        "North Korean workers (sometimes referred to as FAMOUS CHOLLIMA) have significantly improved and increased their activity over the past few years. These actors will pretend to be legitimate workers, apply for remote positions at companies, and once hired and onboarded funnel wages back to the North Korean regime in an effort to help North Korea generate revenue while evading international sanctions. Some public reports also cite DPRK workers infiltrating companies to exfiltrate data, deploy malware, or extort their employers once discovered."
        https://www.huntress.com/blog/huntress-dprk-remote-worker-investigation
        https://www.darkreading.com/insider-threats/red-flags-expose-fake-north-korean-it-workers
      • NovaCookies At Scale: Inside The $320 Phishing Service Targeting Hundreds Of Organizations
        "Advertised at $320 a month, NovaCookies packages real-time Microsoft 365 session theft as a subscription phishing service. Campaign artifacts reviewed across our research sources show hundreds of organizations targeted across multiple regions, while the service’s infrastructure expanded sharply from mid-May and continued appearing through August 2026. Nearly 90% of the organizations in the reviewed set were associated with lures hosted on .vu domains. A companion IOC release documents 755 domains assessed as dedicated malicious infrastructure."
        https://www.island.io/blog/novacookies-at-scale-inside-the-320-phishing-service-targeting-hundreds-of-organizations
        https://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html
        https://www.darkreading.com/endpoint-security/novacookies-steals-microsoft-365-sessions-320-a-month
      • ModeloRAT Malware: How The CrashFix Campaign Delivers a Python RAT
        "ModeloRAT is a Python-based Windows Remote Access Trojan first observed in January 2026, delivered only to domain-joined hosts in enterprise environments where a single foothold opens the way to Active Directory and lateral movement. It arrives as the final payload of the CrashFix campaign, which starts with a malicious Chrome extension named NexShield that crashes the victim's browser on purpose, then displays a fake repair prompt that talks the user into running an attacker-supplied command [1]. In this blog, we explain how ModeloRAT works and how to validate your security controls against this malware."
        https://www.picussecurity.com/resource/blog/modelorat-malware-how-the-crashfix-campaign-delivers-a-python-rat
      • ‘The Gentlemen’ Profile: Why This Ransomware Group Wants In Before It Locks You Out
        "The Gentlemen is a financially motivated ransomware group that combines data theft with encryption to increase pressure on victims. They first came onto the threat scene in July 2025. Rather than relying on encryption alone, the group exfiltrates sensitive business data before locking files, leaving organizations to deal with both operational disruption and the risk of stolen information being exposed."
        https://www.bitsight.com/blog/the-gentlemen-ransomware-group-threat-actor-deep-dive

      Breaches/Hacks/Leaks

      • An ID Check Breach Timeline: 2011–2026
        "Every year, more of the internet demands that you prove who you are before you may use it: KYC checks to open an account, a driver’s license to join a dating app, a passport scan to check into a hotel, a face scan to read an adult site in the UK, a government ID to appeal a Discord ban. Every one of those checks creates a copy of the most permanent data you have. This timeline compiles what happened to those copies. We found 88 publicly documented incidents since 2011 in which data collected specifically to verify identity or age – government ID scans, verification selfies, biometric templates, KYC files, national ID registries – was breached, exposed, or put up for sale."
        https://www.mysteriumvpn.com/blog/data-and-research/id-check-breach-timeline
        https://securityaffairs.com/197855/reports/88-id-verification-breaches-show-the-cost-of-collecting-identity-data.html
      • Boston Scientific Says Cyberattack Disrupted Operations Globally
        "Medical technology company Boston Scientific has been targeted in a cyberattack that disrupted some of its IT systems, causing operational disruptions globally. The company detected the incident on August 25 and says in an announcement today that it caused a network outage and "impacted access to certain operating systems and business applications, including the ability to process and ship customer orders." After identifying the intrusion, Boston Scientific activated its incident response procedures and contracted external cybersecurity experts to investigate the impact and help with containment efforts."
        https://www.bleepingcomputer.com/news/security/boston-scientific-says-cyberattack-disrupted-operations-globally/
        https://therecord.media/boston-scientific-cyberattack-disrupts-shipment-processes
        https://www.bankinfosecurity.com/cyberattack-disrupts-boston-scientifics-global-operations-a-32660

      General News

      • SOC Threat Radar — August 2026
        "CVE-2026-0257 is a vulnerability affecting Palo Alto’s OS-agnostic GlobalProtect services. Successful exploitation could allow an attacker to bypass normal authentication controls, establish a VPN session as if they were a legitimate user, gain access to internal resources reachable through the VPN, and create a foothold for further activity such as reconnaissance, credential theft or lateral movement. Barracuda Managed XDR’s SOC team has detected two waves of inbound scanning activity originating from known attacker infrastructure and targeting publicly exposed GlobalProtect services in Belgium. The attackers are likely to be probing for vulnerable or unpatched systems following public disclosure of the CVE."
        https://blog.barracuda.com/2026/08/26/soc-threat-radar-august-2026-remote-access-threats
      • Production Data In Testing Is Still Common, And Tricentis’ CISO Wants It Gone
        "In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught a prompt injection gap in red-teaming and held a release for a week until it was fixed. Dean describes what gets an AI vendor rejected, mostly vague answers about where data lives and how long it is kept. She also lists three things a small security team should build first, even with limited headcount."
        https://www.helpnetsecurity.com/2026/08/26/erika-dean-tricentis-production-data-in-testing/
      • AI Vulnerability Discovery Scores The Highest Impact Of 20 Emerging Risks
        "Risk managers, auditors and senior executives at 316 companies spent April and May ranking 20 threats they have not yet felt. AI discovery of cyber vulnerabilities came back first, according to Gartner. Three months earlier the same quarterly survey put information integrity risk at the top and left AI vulnerability discovery out of the top five. Two things changed underneath that number. AI systems scan for previously unknown flaws at a volume no patching team can absorb, and the step from finding a flaw to holding working attack code has shrunk to close to nothing. Writing the exploit used to be the part that kept most attackers out. It no longer is. A defender inherits a backlog of unpatched critical vulnerabilities growing faster than it can be cleared, inside systems that AI integration has made harder to see into."
        https://www.helpnetsecurity.com/2026/08/26/ai-vulnerability-discovery-emerging-risks/
      • CISA Vulnerability Review
        "Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the risk they pose. The CISA Vulnerability Review provides organizations with critical insights into the root causes of insecure software and practical steps they can take to address these flaws to prevent exploitation. Analyzing CISA and open source data from fiscal years 2024 and 2025, the review establishes a baseline of today’s vulnerability landscape before AI-enabled vulnerability discovery becomes more widespread."
        https://www.cisa.gov/resources-tools/resources/cisa-vulnerability-review
        https://www.cisa.gov/sites/default/files/2026-08/cisa-vulnerability-review-fy-2024-2025.pdf
        Justice Department And FBI Seize Platforms Operated And Used By China State-Sponsored Hackers * To Target U.S. Critical Infrastructure
        "The Justice Department and FBI announced court-authorized domain seizures today to deny malicious cyber actors access to two complementary hacking platforms known as “QScan” and “QTRouter,” used to target U.S. critical infrastructure and other sensitive networks. As described in court documents unsealed in the Southern District of California, a People’s Republic of China (PRC) state-sponsored group known as “QTFY,” employed by China-based Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司), created and operated QScan and QTRouter. Among the victims of QTFY computer intrusion activity are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate."
        https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers
        https://www.bleepingcomputer.com/news/security/fbi-disrupts-proxy-network-enabling-chinese-espionage-operations/
        https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html
        https://therecord.media/qscan-qtrouter-us-takedown-alleged-china-hacking-tools
        https://www.bankinfosecurity.com/fbi-doj-seize-chinese-hacker-infrastructure-on-us-soil-a-32658
        https://cyberscoop.com/qtfy-china-espionage-group-infrastructure-seized/
        https://securityaffairs.com/197873/apt/fbi-seizes-china-linked-hacking-platforms-qscan-and-qtrouter-used-against-critical-infrastructure.html
      • German Industry Reports Escalating Nation-State Cyberattacks
        "German businesses are increasingly under attack from hackers with links to foreign intelligence services, according to a major new study from digital industry association Bitkom. And that shift is clouding businesses' visibility into their own vulnerability. Bitkom's research arm polled over a thousand companies with 10 or more employees and annual German revenues of at least a million euros, and found that almost all - 96% - had either definitely or likely been affected by data theft, industrial espionage or sabotage in the last year."
        https://www.bankinfosecurity.com/german-industry-reports-escalating-nation-state-cyberattacks-a-32657
      • Understanding Browser Trust Abuse: Exploiting Enterprise’s Most Trusted Interface
        "The biggest change in browser-related threats is not a new flaw in browser software. It is a shift in how threat actors operate. Instead of breaking into the browser, they increasingly trick the people using it by exploiting the trust employees place in familiar browser experiences and workflows. By mimicking legitimate login screens, software update prompts, authentication requests, and security checks that people see every day, threat actors persuade users to disclose credentials, grant access to their computers, or install malware. As a result, any browser-enabled device can become a target, making browser patching alone insufficient to prevent these attacks."
        https://cofense.com/blog/understanding-browser-trust-abuse-exploiting-enterprise-s-most-trusted-interface
      • Four In Five AI Tools Run With No IT Oversight, New Research Finds
        "Security researchers have warned that major gaps in IT oversight, surging numbers of published vulnerabilities, and MCP security risks are making the AI agent ecosystem increasingly risky. AI security vendor Reco analyzed anonymized platform telemetry from large enterprises, publicly available Model Context Protocol servers, and vulnerability disclosures from the National Vulnerability Database to compile its report, The State of Agent Security 2026. It found that 80% of AI tools operate with no oversight, while in SMBs, there are an estimated 414 unsanctioned tools per 1000 employees."
        https://www.infosecurity-magazine.com/news/four-in-five-ai-tools-no-it/
        https://www.reco.ai/state-of-agent-security-2026-form
      • Average Cyber Insurance Losses Increase Despite Fewer Claims
        "The average cost of cybersecurity insurance claims made by large and middle-market companies surged in 2025, despite a significant drop in the volume of claims, according to Chubb’s 2026 Cyber Claims Report. The insurer said the growing severity of claims in the US has been largely driven by the increasing cost of both data breach and privacy-related litigation, alongside rising business interruption expenses. In the US, the average cost of claims rose by 22% for middle-market firms in 2025 compared to 2024, while for large companies, an enormous 100% rise was observed."
        https://www.infosecurity-magazine.com/news/cyber-insurance-losses-increase/
      • Exploits And Vulnerabilities In Q2 2026
        "The vulnerability landscape shifted significantly in Q2 2026. First, the number of registered CVEs reached an unprecedented level. This is driven primarily by the widespread adoption of AI, both for application development and search for security flaws. This resulted in entire new classes of vulnerabilities emerging, particularly in the Linux networking subsystem. Second, security researchers have been publishing exploits for unpatched vulnerabilities more frequently. Publications like these can generate significant fallout, since they potentially open the door for attackers to target unprotected systems."
        https://securelist.com/vulnerabilities-and-exploits-in-q2-2026/121091/
      • The MFA Identity Trap: When Authentication Creates a False Sense Of Security
        "Multi-factor authentication (MFA) has become one of cybersecurity’s most important controls. Roughly 70% of enterprise workforce users are now protected by it. But its success has created an unintended problem. Organizations increasingly treat successful authentication as proof of identity. They assume that because someone passed MFA, they have verified who that person is. They may also assume that the identity itself has not been compromised. Neither is it necessarily true."
        https://www.securityweek.com/the-mfa-identity-trap-when-authentication-creates-a-false-sense-of-security/
      • Software Supply Chain Security Requires Decisions Rather Than Defaults
        "A bridge stays in service for fifty years on a fixed inspection schedule, load-tested and maintained the entire time. A jet engine flies the same design for decades under continuous regulatory oversight. In most engineering disciplines, a stable, proven design paired with active maintenance is the goal. Newer designs are treated with far more scrutiny, because they’ve never been truly tested. But for some reason, in software engineering, the opposite is true. The newest release is treated as the safest. And that instinct has backfired badly in the past. A backdoor sat inside two specific releases of xz-utils, versions 5.6.0 and 5.6.1, planted by an infiltrator who’d spent two to three years plotting up release authority."
        https://www.aikido.dev/blog/software-supply-chain-security-decisions-not-defaults
      • Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense
        "Mexico faces an increasingly complex cyber threat landscape, including ransomware, state-sponsored espionage, financial malware, data breaches, hacktivism, and cyber-enabled organized crime. Its 2025–2030 National Cybersecurity Plan seeks to address these challenges through stronger governance, new legislation, a national operations center, integrated incident-response teams, cyber exercises, AI-enabled defenses, and expanded regional cooperation. Insikt Group assesses ransomware as the leading threat while highlighting growing risks from foreign threat actors and credential theft. We recommend leveraging threat intelligence, applying international security frameworks, and fostering cyber education. Ultimately, Mexico’s progress will depend on turning an ambitious roadmap into durable institutions, effective regulation, and sustained international cooperation."
        Priority: 3 - Important
        Relevance: General
        https://www.recordedfuture.com/blog/mexico-cybersecurity-plan

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) c6ab90db-397c-47af-8b2e-3926426af603-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 26 August 2026

      Healthcare Sector

      • MyChart Portal Phishing Scams Target Patients Nationwide
        "Dozens of U.S. healthcare systems are warning patients about potential email phishing, text and phone scams involving their MyChart patient portals. Electronic health record vendor Epic, the maker of MyChart, has also issued a public warning about the threats. The phishing campaigns involve fraudsters using the MyChart name and logo to appear legitimate in their scam messages. The communications promise the patients a "2026 MyChart Senior Health Package," Medicare wellness benefits, a free health kit or other gifts when recipients "claim their reward" by clicking a link, confirming an address or providing other personal information."
        https://www.bankinfosecurity.com/mychart-portal-phishing-scams-target-patients-nationwide-a-32651

      Industrial Sector

      • Siemens SIMATIC IoT2050 Advanced
        "SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a missing authentication vulnerability in the Node-RED HTTP interface that could allow an unauthenticated remote attacker to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. Siemens has released a new version for SIMATIC IoT2050 Advanced and strongly recommends to update to the latest version."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-03
      • Ebyte NE2-D11
        "Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
      • Zoneminder
        "Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-02
      • PayRange API
        "Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a devices displayed image."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-04
      • FURUNO FA-50 Class B AIS Transponder
        "Successful exploitation of these vulnerabilities could allow an attacker to alter device settings."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-07
      • Threat Landscape For Industrial Automation Systems. Q2 2026
        "In this section, we examine the most significant changes to indicators over the quarter, broken down by region and industry. Further diagrams can be found in the relevant chapters of the “Statistics across all threats” section."
        https://ics-cert.kaspersky.com/publications/reports/2026/08/25/threat-landscape-for-industrial-automation-systems-q2-2026/
      • Rently Smart Home
        "Successful exploitation of this vulnerability could allow an attacker to access sensitive information and override user permissions."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-01
      • Bendix EC80 Brake ECU
        "Successful exploitation of these vulnerabilities could allow an attacker to cause the loss of ABS functions, steering assist, speedometer, shifting capabilities, or disable automatic traction control."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-05

      New Tooling

      • HOL Guard: Open-Source Antivirus For AI Agents
        "HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your own machine, and a typical check takes under 50 milliseconds. Your files are never uploaded, and the whole thing works with no internet connection. The people exposed here are anyone using Claude Code, Cursor, Codex, Gemini CLI, OpenCode, Hermes, or OpenClaw."
        https://www.helpnetsecurity.com/2026/08/25/hol-guard-open-source-antivirus-ai-agents/
        https://github.com/hashgraph-online/hol-guard

      Vulnerabilities

      • Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute In Edit Mode
        "Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode. The vulnerability, tracked as CVE-2026-75149, is a code injection issue affecting versions prior to 0.23.15. VulnCheck's CVE Numbering Authority (CNA) record assigns it a CVSS v4 score of 8.7 and a CVSS v3.1 score of 8.8, with user interaction required and no attacker authentication required."
        https://thehackernews.com/2026/08/marimo-notebook-flaw-could-run-mcp.html
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-60004 Gitea Code Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/25/cisa-adds-one-known-exploited-vulnerability-catalog
      • Drive-By Agent Hijacking: One Website Visit, Persistent Model Poisoning
        "A vulnerability in NVIDIA NemoClaw, a tool that deploys the OpenClaw AI agent, can hand an attacker full, unauthenticated control over the local model server that powers the agent and silently plant instructions inside the model. A single visit to an attacker-controlled webpage is all it takes to give the attacker these capabilities. NemoClaw deploys inside NVIDIA OpenShell sandboxes with local inference via Ollama. Oasis Security discovered the vulnerability as part of ongoing research into non-human identity and AI agent risks."
        https://www.cyera.com/research/nemoclaw-one-website-visit-to-hijack-your-ai-agent
        https://thehackernews.com/2026/08/a-malicious-webpage-could-poison-your.html
        https://www.darkreading.com/cyber-risk/nemo-claw-networking-llm-poisoning-openclaw
      • Vulnerability In GNU Wget Software
        "CERT Polska has received a report about vulnerability in GNU wget software and participated in coordination of its disclosure. The vulnerability CVE-2026-16599: GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation."
        https://cert.pl/en/posts/2026/08/CVE-2026-16599/

      Malware

      • ClickFix Phishing Pages Discovered In 24 Npm Packages
        "The OX Research team is tracking a fake Cloudflare campaign being distributed on the npm registry: Our research found a total of 24 packages containing the same HTML page, with each package usually reaching between 50-300 weekly downloads before it gets removed. But downloading and installing such a package to a machine doesn’t do any harm, so why do we bother researching it? While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t do harm, the threat actor’s use of npm isn’t to infect developers who install it, but to use the registry and its mirrors as a safe, validated storage for the malware."
        https://www.ox.security/blog/research-clickfix-phishing-npm-packages/
        https://thehackernews.com/2026/08/24-npm-packages-abuse-unpkg-mirrors-to.html
        https://www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages/
      • Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain
        "The SOCRadar Threat Research Unit (STRU) has conducted an “inside-out” analysis of AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) ecosystem specifically engineered to disable Apple’s Activation Lock on stolen devices. Operating as a credit-metered platform, AnonyMousKIT automates credential harvesting through a sophisticated multi-channel pipeline – integrating email, SMS, and WhatsApp with advanced conversational AI agents to conduct AI-driven Automated Social Engineering (voice phishing) calls. By leveraging a critical flaw – the use of bare relative paths – the investigation unraveled a reseller supply chain of 506 domains and 168 storefront brands active since early 2024. Despite leveraging advanced AI to mimic “Apple Support,” basic coding errors exposed production logs and operator rosters."
        https://socradar.io/blog/anonymouskit-ai-phaas-supply-chain/
        https://www.bleepingcomputer.com/news/security/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes/
      • Massive DDoS Attack Disrupts Norway’s Government Digital Services
        "A large distributed denial-of-service (DDoS) attack has disrupted Norway’s shared government digital infrastructure since Monday, affecting services used by the public sector. The attack started at 03.38 CEST on Monday and has targeted the infrastructure supporting services operated by the Norwegian Digitalization Agency, Digitaliseringsdirektoratet (Digdir), and its operations provider, Vivicta. Digdir operates Norway’s shared digital government infrastructure, including public-service logins, electronic IDs and signatures, secure digital mail, government forms, public-record access, and data exchange between agencies."
        https://www.bleepingcomputer.com/news/security/massive-ddos-attack-disrupts-norways-government-digital-services/
        https://therecord.media/norway-cyberattack-ddos-government
        https://securityaffairs.com/197826/cyber-warfare-2/norway-s-digital-government-infrastructure-hit-by-a-new-ddos-attack.html
      • Check Point Blocks Large-Scale Debt-Relief Email Phishing Campaign Targeting More Than 9,000 Organizations
        "Check Point has identified and blocked a large-scale email phishing campaign using fraudulent financial hardship and debt-relief offers to manipulate recipients into calling attacker-controlled phone numbers. Over the past 14 days, Check Point observed approximately 24,700 emails associated with the campaign targeting users across more than 9,000 organizations, demonstrating both the scale of the operation and the continued evolution of phishing beyond malicious links and attachments. The campaign underscores a growing enterprise risk: phishing no longer needs an obvious malicious link, attachment, or spoofed sender to be effective. Attackers are turning routine-looking email into the entry point for trusted conversations that take users beyond traditional controls."
        https://blog.checkpoint.com/securing-user-and-access/check-point-blocks-large-scale-debt-relief-email-phishing-campaign-targeting-more-than-9000-organizations/
      • An Invisible HTML Payload Silently Hijacked Every Email Summarizer Run
        "Indirect prompt injection has moved from academic exercise to field-deployed threat. Forcepoint X-Labs previously demonstrated how multi-agent email pipelines can be manipulated through PromptSpy and identified real IPI attacks in the wild. This post presents a measured laboratory proof of concept: we isolated a single email summarizer running an unguarded LLM pipeline, embedded a hidden prompt injection payload using common HTML concealment techniques, and ran both benign and injected emails through the system with pre-registered success criteria. The results confirm that indirect prompt injection can silently hijack summarizer output without signaling tampering to the reader."
        https://www.forcepoint.com/blog/x-labs/html-payload-hijacks-email-summarizer
        https://www.darkreading.com/cyber-risk/hidden-prompts-trick-ai-false-email-summaries
      • ZeroTokens: Phishing Platform Gives Operators Real-Time Control Of Attack Flow
        "ZeroTokens is a phishing platform built for financial institution impersonation at significant scale, combining reusable infrastructure with institution-specific verification sequences across dozens of financial brands. ZeroTokens operates less like a conventional phishing kit and more like a scam call center running through the target’s browser. A human operator watches each session unfold, sees information as the target enters it, and decides which prompt appears next. In parallel, the operator can use that information in a separate session with the genuine financial institution, coordinating the two interactions in near real time without proxying the bank."
        https://abnormal.ai/blog/zerotokens-real-time-phishing-platform
        https://www.infosecurity-magazine.com/news/zerotokens-phishing-real-time/
      • Extended Rapid Response: Zimperium Identifies RecruitTrap Recruit Scams Are Targeting Enterprise Credentials On Mobile
        "The recent research on The Growing Threat of Browser-in-the-Browser (BitB) Recruitment Scams highlights an escalating trend in social engineering: threat actors impersonate real HR personnel across multiple well-known companies to execute highly convincing, interview-themed phishing attacks. By scraping public profile data, attackers craft hyper-realistic scheduling flows designed to bypass traditional user skepticism. While desktop users encounter a simulated popup browser window (BitB), mobile devices present a unique vulnerability. On smaller screens, the attack automatically adapts, replacing the BitB frame with a full-screen counterfeit login page. Without traditional desktop browser chrome or visible URL bars, mobile victims have virtually no visual indicators to distinguish a fake login from a legitimate OAuth prompt."
        https://zimperium.com/blog/extended-rapid-response-zimperium-identifies-recruittrap-recruit-scams-are-targeting-enterprise-credentials-on-mobile
        https://www.infosecurity-magazine.com/news/fake-recruiter-scams-corporate/
      • Mirage2FA Surge Hits 4,500 US And EU Companies, Abusing Microsoft 365 Login Flows
        "Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based."
        https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html
      • SLEEPWALKER: A Passive Backdoor With Its Own Command Language
        "Losing access to VirusTotal Intelligence at the start of the year was surprisingly productive. Unable to hunt for interesting new malware, I stopped adding to my “TODO” pile and finally worked through my backlog from last year. That led to a detailed examination of BeheMOF as well as the discovery of this malware. Upon closer inspection, a sample that did not seem too noteworthy at first turned out to have a distinctive design once I looked under the hood: a passive backdoor that opens no obvious listening port and carries no payload inside itself. It waits in memory doing nothing at all until one specifically crafted network packet reaches the machine, which is why I am calling it SLEEPWALKER."
        https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/
        https://www.theregister.com/security/2026/08/24/you-dont-want-this-sleepwalker-backdoor-on-your-windows-machine/5292021

      Breaches/Hacks/Leaks

      • LACMA Data Breach Last Year Exposed Social Security And Medical Data
        "The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. The museum says that on July 11, 2025, it detected suspicious activity on its systems that had started four days earlier. A month later, the investigation confirmed that the network was compromised. At the time, the type of exposed data could not be determined, and the first results of the investigation became available in late February 2026."
        https://www.bleepingcomputer.com/news/security/lacma-data-breach-last-year-exposed-social-security-and-medical-data/
      • Hospital Operator Nutex Health Says Data Stolen In Cyberattack
        "Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. The organization has disclosed the cyberattack in a filing with the U.S. Securities and Exchange Commission (SEC), noting that the stolen data includes details that may be private or confidential. “Based on preliminary findings from the Company’s ongoing investigation, the Company believes that certain information maintained on the Company’s servers was accessed and exfiltrated by an unauthorized third party, including some information that may be private and/or confidential,” Nutex says."
        https://www.bleepingcomputer.com/news/security/hospital-operator-nutex-health-says-data-stolen-in-cyberattack/
      • Hackers Breached Over 270 Zimbra Servers In Ongoing Attacks
        "Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. The ZCS email and collaboration suite is used by hundreds of millions of people and organizations, including thousands of businesses and hundreds of government agencies worldwide. Synacor patched the security flaw (tracked as CVE-2026-73570), which allows unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled, with the release of ZCS version 10.1.20 on July 20."
        https://www.bleepingcomputer.com/news/security/hackers-breached-over-270-zimbra-servers-in-ongoing-attacks/
        https://www.bankinfosecurity.com/zimbra-exploitation-spreads-as-thousands-stay-unpatched-a-32654
        https://www.helpnetsecurity.com/2026/08/25/zimbra-cve-2026-73570-compromised/
      • Employee Benefits Platform Paylogix Says Hackers Stole Financial And Health Data
        "Hackers stole troves of sensitive information on tens of thousands of people from Paylogix, a tech company that provides benefits management tools to employers and insurance firms. The company has notified several state regulators this month and published its own notice of a security incident explaining that it experienced a cyberattack in the fall that disrupted its systems. An investigation revealed that hackers stole files from the company’s network between November 13 and November 18. Paylogix did not identify the hackers, but the company was added to the leak site of the Akira ransomware gang in January."
        https://therecord.media/paylogix-cyberattack-akira-ransomware

      General News

      • AI Supply Chain Risk Is Showing Up In Developer Workflows First
        "In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and compromised MCP servers stay mostly in research demos. He explains why segmentation buys more risk reduction per dollar than tooling, where self-hosting a model falls short, and which semiconductor isolation practices software teams should copy. He also names the security belief he has since abandoned."
        https://www.helpnetsecurity.com/2026/08/25/jaushin-lee-ai-zentera-systems-supply-chain-risk/
      • A Tale Of Two SOCs: Insights From Two Red Team Assessments
        "The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model. This advisory details the red team’s activity and organizations’ defensive actions, offering lessons learned and mitigations to help critical infrastructure organizations strengthen detection, response, and protections in IT, cloud, and operational technology (OT) environments."
        https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a
        https://www.cisa.gov/sites/default/files/2026-08/aa26-237a-tale-of-two-SOCs-insights-two-red-team-assessments-508c.pdf
        https://cyberscoop.com/cisa-red-team-report-government-water-cybersecurity/
      • 58 Arrests In Global Effort To Dismantle West African Organized Crime Groups
        "An eight-month operation targeting West African organized crime groups has led to 58 arrests and the identification of 263 suspects. Operation Jackal IV (November 2025 – June 2026) aimed to disrupt money laundering, identify high-value targets, seize assets, and support arrests and prosecution. The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks – such as the Black Axe and other similar groups. These groups are responsible for a significant share of the world's cyber-enabled financial fraud, typically through romance scams, cryptocurrency and investment scams or business email compromise fraud, as well as other serious and violent crimes."
        https://www.interpol.int/News-and-Events/News/2026/58-arrests-in-global-effort-to-dismantle-West-African-organized-crime-groups
        https://www.bleepingcomputer.com/news/security/police-arrests-dozens-of-suspects-in-global-cybercrime-crackdown/
        https://therecord.media/58-arrested-international-cybercrime-crackdown-interpol
        https://cyberscoop.com/interpol-operation-jackal-iv-black-axe-arrests/
        https://www.helpnetsecurity.com/2026/08/25/interpol-jackal-iv-west-african-crime-groups-arrests/
      • Most Organizations Declare Victory Over a Breach Too Early
        "That is often the moment an organization wants to believe the worst is over. Services are restored. Customers can transact again. Executives can brief the board that operations have resumed. Communications teams can move from crisis language to recovery language. Operationally, that may be true. But from a security perspective, it's often premature. One of the most persistent weaknesses among incident response teams is their tendency to confuse service restoration with breach recovery. The organization rebuilds servers, restores applications, re-enables user access and resumes business processes. But the deeper questions remain unresolved."
        https://www.bankinfosecurity.com/blogs/most-organizations-declare-victory-over-breach-too-early-p-4179
      • The Safety Penalty: Reclaiming Operational Sovereignty In The Age Of AI
        "Cybersecurity has made a big bet on cloud-hosted AI. Building and running frontier-class models in-house isn’t realistic for most security teams — the compute, the talent, and the R&D costs are more than any single SOC can carry. So we’ve effectively outsourced the "brain" of our security operations to a handful of providers. That trade comes with a hidden cost: the safety penalty. The safety penalty is the friction that shows up when guardrails built to protect the general public get in the way of legitimate security work. If your model refuses to deobfuscate that malware or to explain a working exploit because its filters read the request as harmful, you’re paying the safety penalty."
        https://blog.talosintelligence.com/the-safety-penalty-reclaiming-operational-sovereignty-in-the-age-of-ai/
      • From ‘High/Medium/Low’ To Dollars: Making Cyber Risk Legible To Your CFO
        "For years, cybersecurity teams have communicated risk through labels such as “High,” “Medium,” and “Low.” Those ratings can help security teams prioritize vulnerabilities, but they often leave CFOs with a more important question unanswered: What does the risk actually mean for the business financially? That question has become harder to ignore as the threat landscape accelerates. Cyble’s 2025 threat predictions, published as the year unfolded, provide a useful illustration. More than 80% of the threats Cyble forecast—including AI-driven ransomware and complex supply-chain attacks—materialized as anticipated."
        https://cyble.com/blog/financial-exposure-cyber-risk-quantification/
      • Is Cyber Facing An Affordability Crisis?
        "A chief information security officer—if the company can even afford one— is woken by an urgent phone call in the middle of the night. There's been a breach. Threat actors stole highly sensitive customer data, and now they're demanding a ransom. If the company doesn't pay, they will leak data on the Dark Web. That's when the clock, and the financial fallout, starts ticking. Whether it's a ransomware attack, business email compromise, or a third-party supply chain attack, organizations have unfortunately become increasingly accustomed to suffering data breaches. But they are caught between rising threats they can't ignore and burgeoning defense costs they can't sustain."
        https://www.darkreading.com/cybersecurity-operations/is-cyber-facing-an-affordability-crisis-
      • Silent Patches Don’t Stop Attackers – They Blind Defenders
        "Every so often a vendor decides the smart move is to fix a vulnerability quietly. No advisory, no CVE, no explanation, just the vaguest handwave in a changelog. The logic sounds reasonable on its face: if you don’t explain what a patch does, you avoid handing attackers a roadmap to the root cause. Why publicize your bugs? Here’s why: patches aren’t secrets once they ship. A vendor can skip the CVE, skip the advisory, skip the outreach, but the binary still changes on disk, and anyone with a debugger and a disassembler can diff old and new and figure out what moved. That’s not a hypothetical skill, and lately, the barrier to entry into sophisticated exploit dev just got a lot lower thanks to our LLM friends."
        https://www.securityweek.com/silent-patches-dont-stop-attackers-they-blind-defenders/
      • Leak Sites: a Field Guide
        "A leak-site listing is a claim, not a confirmation. Ransomware groups use leak sites as part of their extortion strategy, so defenders should seek corroborating evidence before treating a listing as proof of a breach. Leak sites provide useful threat intelligence, but they require context. They can reveal active threat groups, targeted industries and emerging campaigns, but listings may include exaggerated, recycled or unverified claims. Focus on trends and exposure, not raw victim counts. The most valuable insights come from identifying which sectors, vendors and organizations are being targeted and determining whether they present risk to your environment or supply chain."
        https://blog.barracuda.com/2026/08/25/leak-sites-a-field-guide
      • The State Of AI-Enabled Malware August 2026: From Brand Abuse To Agentic Execution
        "To assess the impact of AI-enabled malware, we collected and analyzed over 400 malware samples that integrate AI in some capacity, from brand impersonation and large language model (LLM)-generated code to agentic execution loops. Our central finding was that the AI malware space is currently overwhelmingly composed of proof-of-concept code, security validation testing and researcher submissions that have never reached a production environment. Of the 405 samples in our dataset, only 12 appeared in our telemetry on Cortex XDR-protected endpoints, and a small subset was forwarded through Next-Generation Firewalls to WildFire for analysis. Palo Alto Networks products detected and blocked every sample that attempted to reach a customer environment."
        https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/
      • New Bitsight Research Shows AI Abuse Is Moving Beyond The Jailbreak Prompt
        "Jailbreak prompts (i.e. prompts designed to remove or bypass the guardrails and rules that govern AI systems, like LLMs) prompts have been circulating for years. At first, a lot of it was pretty simple: copy a prompt, tell the model to ignore its rules, and see what happens. It was also largely noisy, unverified, and often didn’t work. But the noise was still telling us something. Threat actors were beginning to study AI systems the same way defenders were, and over time, the goal started to change. New Bitsight Threat Intelligence research from July 2025 through July 2026 found jailbreak activity across forums, GitHub repositories, Telegram channels, direct messages, and marketplace-style conversations. We also saw users moving past static prompts and experimenting with obfuscation, model routing, retry logic, multi-model testing, and repeatable jailbreak workflows."
        https://www.bitsight.com/blog/ai-jailbreak-prompts-evolving-cyber-threats

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 843341be-edfa-413d-bce3-de618d0c695a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT