NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,623
    • กระทู้ 2,624
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 5 รายการลงในแคตตาล็อก

      เมื่อวันที่ 24-25 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 5 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability
      • CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability
      • CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability
      • CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
      • CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalog
      https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalog
      https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ec918105-23fc-4085-ab86-750f02fa84ab-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 4 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 4 รายการ เมื่อวันที่ 24 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-267-01 Botslab G980H Dashcams
      • ICSA-26-267-02 Eufy Omni C20, Omni X10 Pro
      • ICSA-26-258-02 Wärtsilä FOS-Onboard (Update A)
      • ICSA-26-209-02 Siemens Mendix Runtime (Update A)

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 6bc07576-215d-45c1-a498-4cff5d651cc8-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 4 รายการลงในแคตตาล็อก

      เมื่อวันที่ 22 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 4 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability
      • CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability
      • CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
      • CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fcf6c52f-7679-4063-8e28-e01df193dbc0-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ เมื่อวันที่ 22 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-265-01 lwIP TCP/IP Stack MQTT Client Application
      • ICSA-26-265-02 lwIP (Lightweight IP)
      • ICSA-26-265-03 Siemens Siveillance Control
      • ICSA-26-265-04 Siemens SIPLUS and SIMATIC Products
      • ICSA-26-265-05 Siemens Desigo CC family
      • ICSA-26-265-06 Siemens Industrial Edge Management
      • ICSA-26-265-07 Siemens SIMOVE Fleetmanager and SIPLANT
      • ICSA-26-265-08 Siemens WTV676 and WTV776
      • ICSA-26-265-09 OpenPLC Runtime v3

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand d8295e0c-f186-4c5d-a589-bd1f6daea8e1-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 29 September 2026

      Financial Sector

      • Security Issues In The Korean & Global Financial Sector In August 2026
        "In Attack Stage 1, phishing was the highest at 2.1, Up from 1.8 The previous month. In Attack Stage 2, dropper/downloader was the highest at 1.1, Down from 3.2 The previous month. In Stage 3 of the attack, Infostealers were the most prevalent at 0.3, Down from 0.4 The previous month. WebShells, Backdoors, HackTools, Ransomware, and CoinMiners remained at low levels."
        https://asec.ahnlab.com/en/95589/

      Industrial Sector

      • One Packet Can Crash OT Servers In Industrial Sectors
        "A newly disclosed flaw in an open source database used in industrial and Internet of Things (IoT) environments could let unauthenticated attackers crash vulnerable servers with a single specially crafted network packet. The zero-day vulnerability, tracked as CVE-2026-42542 affects TDengine, a time-series database that organizations in sectors like manufacturing, energy, automotive, and IoT use to store and analyze large volumes of data collected over time. Examples of such data include readings from sensors and industrial equipment, as well as application- and infrastructure-related performance metrics."
        https://www.darkreading.com/ics-ot-security/one-packet-crash-servers-tdengine

      New Tooling

      • Authorizer: Open-Source Authentication And Authorization For Your Apps
        "Authorizer is an open-source server for sign-in and access control in web and mobile apps. Teams run it on their own infrastructure and keep user accounts in a database they choose. Its maintainers have built a permissions engine and an interface for AI agents into the same Go program that logs users in, so a chatbot can ask whether a user may see a document before it fetches that document. This affects any team that connects an AI assistant to company files. A vector search, which is the lookup that finds text similar to a question, returns close matches without checking who asked. Authorizer gives the search a list of documents the user is allowed to see, and everything else is dropped before it is scored."
        https://www.helpnetsecurity.com/2026/09/28/authorizer-open-source-authentication-server/
        https://github.com/authorizerdev/authorizer

      Vulnerabilities

      • How I Could've Accessed 17 Trillion Microsoft Records
        "An estimated 17.3 trillion stored rows across a wide range of Microsoft datasets were reachable through a single internal analytics service, all because it never checked the signature on a login token. That flaw let me claim an administrator’s identity and submit unauthorized SQL queries without any real credentials. I used only table descriptions, metadata, and bounded sample rows to understand the potential scope."
        https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records
        https://www.helpnetsecurity.com/2026/09/28/microsoft-titan-jwt-signature-flaw/
      • “Drunk” AI Is Terrible At Keeping Secrets
        "AI models taught to write like drunk people became easier to jailbreak and more likely to leak secrets shared in confidence. That is the finding of UNSW Sydney researchers Anudeex Shetty, Aditya Joshi and Salil Kanhere, published in their paper “In Vino Veritas and Vulnerabilities.” “The key research question from the natural language processing (NLP) side for me was, how do we get LLMs drunk?” said Aditya Joshi, a senior lecturer at the UNSW School of Computer Science and Engineering. “And the cyber security question was, how do we measure their vulnerabilities once they are drunk?”"
        https://www.helpnetsecurity.com/2026/09/28/drunk-ai-models-jailbreak-research/
      • Apple Patches CoreGraphics Flaw Possibly Exploited In Targeted Attacks
        "Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the issue was addressed with improved bounds checking. It credited Meta Product Security with discovering and reporting the issue."
        https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html

      Malware

      • Vulnerability Attack Case: Installation Of a Web Shell And Execution Of a Scanner By Exploiting a Telerik UI Vulnerability
        "The AhnLab SEcurity intelligence Center (ASEC) has identified two vulnerability attack cases that exploited a remote code execution vulnerability (CVE-2019-18935) targeting unpatched Telerik UI for ASP.NET AJAX servers. In the first incident, after exploiting the vulnerability, the attacker executed a reverse shell, attempted to perform privilege escalation, and installed a web shell; in the second incident, the attacker ran a scanner tool to search for additional Attack Targets."
        https://asec.ahnlab.com/en/95561/
      • Storm-3168: Agentic-Driven Cloud Attacks Using Compromised Service Principals
        "Microsoft Security Research has identified malicious cloud activity associated with JADEPUFFER, a threat actor discovered by Sysdig in July 2026 and reported to be the first documented agentic ransomware operation. Our investigation found an extensive Azure-focused resource destruction activity using compromised service principals and cloud credential collection that could be used to facilitate future exfiltration."
        https://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/
        https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html
        https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/
        https://www.darkreading.com/cloud-security/jadepuffer-ai-actor-azure-tenant-destructive-cloud-attack
        https://securityaffairs.com/199905/cyber-crime/storm-3168-linked-to-jadepuffer-abused-stolen-azure-identities.html
      • Chrome Store Hosts 'Poper Blocker' Spyware Downloaded By Millions
        "Millions of people have downloaded infostealers disguised as legitimate ad-blocking browser extensions, in part because Google has provided them with seals of approval on the Chrome Web Store. That's the word from Bay Area Labs, which uncovered one such app, "Poper Blocker," lurking in the Chrome Web Store. Poper Blocker has every trapping of a legitimate, mainstream app: It sports a big, green "Featured" badge, and its developer has earned a trustworthy "Established Publisher" status with Google. It enjoys a 4.8 out of 5 star rating from more than 81,000 reviewers. It claims more than 2 million active users. In short, no user could spot anything untoward about this program were they to come across it while shopping for an ad blocker."
        https://www.darkreading.com/application-security/chrome-store-poper-blocker-spyware-downloaded-millions
      • NeedyMantis: Unpacking a Post-Compromise Malware Family Used In Targeted Operations
        "Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Based on observed activity, NeedyMantis is typically deployed after a threat actor has already established access to a target environment, indicating that the malware is used to maintain long-term access and support follow-on operations."
        https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/
        https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html
      • RatHat Android Malware Console Uses Gemini To Identify Higher-Value Victims
        "RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone, including text messages and passwords entered into fake login screens overlaid on banking apps. Its latest version asks Google's Gemini AI model to estimate each victim's bank balance from those messages and sorts the phones into high-value and mid-value groups."
        https://thehackernews.com/2026/09/rathat-android-malware-console-uses.html
      • The Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, And AI Environments
        "Identity has long been the primary attack surface of the cloud. Infostealer malware, distributed through an industrialized cybercrime economy, is a leading initial access vector for compromising enterprise cloud, code, and AI environments. By targeting unsecured endpoints of developers through social engineering and supply chain attacks, threat actors steal credentials, API keys, and active session tokens, thereby bypassing the stronger defenses protecting most cloud environments from more direct attacks. Stolen credentials are widely recognized as one of the most common initial infection vectors - Microsoft, Recorded Future, and Verizon’s DBIR all point to infostealers as a cause of major concern. These attacks begin with a simple malware infection on a personal device, and end with attackers gaining privileged access to your AWS, Azure, or GCP estate, and more recently to the code platforms used by your organization, such as GitHub or GitLab."
        https://www.wiz.io/blog/infostealer-incursion-cloud-ai-credentials
      • A Fake Security Locker, Delivered By Google Ads
        "Netskope Threat Labs has been tracking a cloud-hosted tech-support-scam (TSS) kit that hijacks a victim’s browser with a fake security alert and pressures them into calling a bogus support line, where the goal is to either extract payment for fake “support,” gain remote access, or collect personal and financial details. Victims arrive by clicking a Google ad and land on a loading spinner webpage then into what looks like an ordinary online store, with nothing that reads as malicious."
        https://www.netskope.com/blog/a-fake-security-locker-delivered-by-google-ads

      Breaches/Hacks/Leaks

      • Japan's Keio Confirms Ransomware Attack Disrupted Business Systems
        "Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. Following a system failure in the early hours of Saturday, the company confirmed the attack and shut down its network to prevent additional damage. The company said it is investigating the extent of the impact and whether the attackers accessed any customer or business partner information."
        https://www.bleepingcomputer.com/news/security/japans-keio-confirms-ransomware-attack-disrupted-business-systems/
      • Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
        "Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. The company announced the incident on September 25, saying that a third party had accessed its systems at the beginning of the month. Times Car took action to block the unauthorized access on September 26. At the time, the company said it was investigating whether the attackers accessed members' personal information, but confirmed the data theft in an update earlier today."
        https://www.bleepingcomputer.com/news/security/times-car-confirms-data-breach-affecting-66-million-user-accounts/
      • Everything Everywhere: Systemic Data Exposure In Supabase Apps
        "Since 2025, the database service Supabase has been known to leak data through a variety of configuration issues. Despite improvements to Supabase product security, those issues continue to exist; multiplied by Supabase’s growth as a favorite tool for Claude Code, there are now thousands of Supabase instances exposing personal information and other data. In the largest study of its kind, UpGuard Research shows how Supabase misconfigurations expose personal data for people all over the world."
        https://www.upguard.com/blog/everything-everywhere-systemic-data-exposure-in-supabase-apps
        https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/
      • FBI Job Portals Remain Offline After ShinyHunters Claims Breach Via PeopleSoft Zero-Day
        "The FBI’s online portals for job applicants (at apply.fbijobs.gov) and special agent applicants (at fbijobs.gov/special-agents) are still unavailable, following what appears to be successful compromises by the ShinyHunters cyber extortion group. Last week, the United States’ domestic intelligence and security service confirmed it was investigating ShinyHunters’ claim of having compromised personal information of FBI employees. ShinyHunters told The Register they leveraged a currently unspecified and unconfirmed Oracle PeopleSoft zero-day vulnerability to breach the portals."
        https://www.helpnetsecurity.com/2026/09/28/fbi-job-portals-offline-shinyhunters-breach/
        https://cyberscoop.com/fbi-data-breach-shinyhunters-agent-safety-risk/
        https://www.malwarebytes.com/blog/data-breaches/2026/09/fbi-agents-blood-tests-and-doctors-notes-surface-after-breach
      • Bitget Says Attacker Exploited Third-Party Security Product Flaw To Steal $388M
        "The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most customer funds in offline cold wallets and use hot and warm wallets to process withdrawals. Transfers from those wallets must still be approved before they are signed. The stolen funds came from part of Bitget's hot and warm wallets, and its cold wallets were not affected."
        https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html
        https://www.bleepingcomputer.com/news/security/bitget-resumes-bitcoin-withdrawals-after-3875-million-crypto-heist/
        https://www.infosecurity-magazine.com/news/bitget-restarts-withdrawals-387-5m/
      • Cyberattack On Polish Medical Software Provider Exposes Patient Data
        "Hackers stole personal data from a Polish healthcare software provider in the latest cyberattack to hit the country’s medical sector in recent months. Qbusoft, which develops the Medyc medical records and practice management platform, was breached after an attacker exploited an SQL injection vulnerability in August, according to a notification issued last week by one of the healthcare providers affected by the incident. SQL injection is a security flaw that allows hackers to trick a website into giving them access to information stored in its database."
        https://therecord.media/poland-cyberattack-medical-medyc
      • DC Health Agency Exposes 400,000 Beneficiary Records
        "The District of Columbia Department of Health Care Finance (DHCF) is notifying nearly 400,000 people that their personal information was potentially compromised in a data breach. According to the agency, the incident impacts Medicaid and the DC Healthcare Alliance beneficiaries who enrolled between 2023 and 2026. The data breach was not the result of hacking. Instead, DHCF discovered in July that two reports on its website contained hidden personal information accessible to unauthorized individuals."
        https://www.securityweek.com/dc-health-agency-exposes-400000-beneficiary-records/
        https://securityaffairs.com/199926/data-breach/nearly-400000-medicaid-beneficiaries-caught-in-medicaid-and-dc-healthcare-alliance-data-exposure.html

      General News

      • August 2026 Threat Trend Report On Ransomware
        "This report summarizes statistics on new ransomware samples, affected systems, and statistics on targeted businesses collected during the month of August 2026, as well as major Korean & Global ransomware issues. Statistics on targeted businesses were compiled based on the time when publicly available information from ransomware groups’ DLS (Dedicated Leak Sites, i.E., Ransomware PR sites or PR pages) was collected via the ATIP (AhnLab TIP, Threat Intelligence Platform) infrastructure."
        https://asec.ahnlab.com/en/95567/
      • Dutch Police Arrest ‘Reformed’ Hacker In Shiny Hunters Investigation
        "Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p."
        https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/
        https://databreaches.net/2026/09/28/still-on-probation-from-previous-arrest-for-hacking-and-extortion-dutch-national-is-arrested-again/
        https://www.bleepingcomputer.com/news/security/dutch-police-confirm-arrest-in-shinyhunters-hacking-investigation/
      • AI Agents Are Privileged Users; Who Is Auditing Their Access?
        "Enterprises spend heavily protecting the human perimeter. Security teams deploy phishing-resistant multifactor authentication (MFA), enforce rigid conditional access policies, and scrutinize every login from an unexpected IP address. Yet while we closely monitor the human employee, engineering teams are quietly granting broad production access to autonomous AI agents, which often operate as non-human identities (NHIs) backed by service accounts, API tokens, or delegated cloud permissions."
        https://www.darkreading.com/vulnerabilities-threats/ai-agents-are-privileged-users-who-is-auditing-their-access
      • If You Do One Security Check This Quarter, Make It Agent Memory
        "In this interview with Help Net Security, Chris Latimer, CEO of Vectorize, talks about the security risks hiding in AI agent memory. He found coding agents storing API keys, credentials, and sensitive documents in plain text on developer machines and in cloud services. Latimer explains how attackers could plant poisoned memories through plugins, skills, and MCP integrations, often aimed at new coders who trust too easily. He covers why access control for agent memory lags behind other areas, what to track after an incident, and the one audit he thinks every CISO should run this quarter."
        https://www.helpnetsecurity.com/2026/09/28/chris-latimer-vectorize-agent-memory-security/
      • AI Tests The Limits Of Enterprise Security Governance
        "AI agents are forcing enterprises to rethink security governance, human accountability and oversight as deployments scale. AWS’s Reimagine 2026 argues that organizations need to build governance into their systems and keep humans accountable for outcomes. The findings come from confidential interviews of 45 to 60 minutes with 154 executives at 128 organizations in 23 industries, conducted over nine months. A number of the organizations interviewed still apply review processes designed for six-month IT programs to work that takes days. If a two-week experiment waits a month for approval, some teams stop asking for permission. Policy in that situation is “pushing it underground,” the authors write."
        https://www.helpnetsecurity.com/2026/09/28/ai-agent-security-governance-aws-report/
      • Quantum Random Numbers Can Pass The Tests And Still Leak Clues To Attackers
        "The European Telecommunications Standards Institute’s (ETSI) technical report, ETSI TR 104 171, offers guidance on building and evaluating quantum random number generators (QRNGs). It focuses on weaknesses in the devices and their supporting systems that could make the numbers they produce less secure. A QRNG measures a quantum process and turns the raw results into usable random numbers. Cryptographic systems rely on unpredictable numbers to generate keys and perform other security functions. If an attacker can predict those numbers, the protection those systems provide may be weakened."
        https://www.helpnetsecurity.com/2026/09/28/quantum-random-number-generator-qrng-guidance/
      • Deepfakes Are Becoming a Costly Reality For Businesses, Report Warns
        "Three quarters of cybersecurity leaders say their organization has faced a suspected deepfake incident during the last year and a quarter of those hit by one say it cost the business over $1m in total, a new report has warned. The 2026 Pindrop Deepfake Readiness Index, published on 28 September, warned there is a significant gap between the threat of deepfake attacks and enterprise readiness to defend against them. Deepfakes are AI generated audio and videos of people. The technology has become increasingly sophisticated, making it difficult for anyone watching or listening to the deepfake to tell that it isn’t footage of a real person."
        https://www.infosecurity-magazine.com/news/deepfakes-costly-reality-for/
      • MCP Is Creating Major Governance Gaps, Researchers Warn
        "Model Context Protocol (MCP) servers are creating a silent enterprise governance gap which threatens to undermine cybersecurity efforts as AI deployments proliferate, according to new research from Ox Security. MCP connects AI applications to external tools and data in a standardized manner, so that developers don’t have to write custom code each time they want to connect AI to an API or database."
        https://www.infosecurity-magazine.com/news/mcp-creating-major-governance-gaps/
      • AI Accounts Are Becoming The New Target For Infostealers
        "SOCRadar analyzed stealer log data from the last 90 days and found 482 companies with exposed AI accounts and credentials. Of those, 295 appeared in active logs during that period, suggesting the exposure is recent rather than the result of historical cleanup. Together, these companies account for 5,434 stealer log records linked to 1,500 distinct corporate email addresses. The number that really stands out is the ChatGPT figure. A captured ChatGPT or OpenAI session appeared at 358 of the 482 companies, accounting for roughly 90% of all records in the study. Other platforms, including Zapier, Notion, Hugging Face, Replit, Lovable and ElevenLabs, were far behind."
        https://securityaffairs.com/199933/ai/ai-accounts-are-becoming-the-new-target-for-infostealers.html
        https://socradar.io/resources/report/ai-identity-exposure-report-2026.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) e6cb8319-d61a-4b1c-bbae-4272190ddf47-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบ x47.c บอตเน็ต Windows ใช้ Grok ช่วยคงอยู่ในระบบ พร้อมความสามารถ AI API Drain

      พบ x47.c บอตเน็ต Windows ใช้ Grok ช่วยคงอยู่ในระบบ พร้อ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand c972b94c-f61a-4e91-91f1-816fcf59ced2-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • OpenAI เผยเหตุ AI Agents อัปโหลดรูปภาพผู้ใช้ไปยังเว็บไซต์ภายนอกโดยไม่ได้ตั้งใจ

      OpenAI เผยเหตุ AI Agents อัปโหลดรูปภาพผู้ใช้ไปยังเว.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand c0e14281-2ecd-490e-bccd-c82ac481e268-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบมัลแวร์ Lunex อาศัยช่องโหว่ไดรเวอร์ AMD ข้ามผ่านระบบรักษาความปลอดภัยเพื่อขโมยข้อมูลผู้ใช้งาน

      พบมัลแวร์ Lunex อาศัยช่องโหว่ไดรเวอร์ AMD ข้ามผ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 76e79886-d0a3-48b9-8c14-eb1a5414c1c7-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 28 September 2026

      Industrial Sector

      • Considerations For Critical Infrastructure Operators Working With Third-Party ICS Integrators
        "The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—hereafter referred to as the “authoring agencies”—have published this fact sheet to highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control system (ICS) integrators. ICS is an umbrella term referring to integrated networks of hardware and software designed to monitor and automate physical processes, encompassing specialized control systems and devices, such as supervisory control and data acquisition (SCADA) systems and programmable logic controllers. Third-party integrators provide varying types of services for ICS, such as control system design, installation, operational data analysis, device support and service, and daily operational control."
        https://www.cisa.gov/resources-tools/resources/considerations-critical-infrastructure-operators-working-third-party-ics-integrators
        https://www.bankinfosecurity.com/cisa-fbi-warn-ot-operators-about-third-party-hacking-a-32942

      Telecom Sector

      • Inside The Telecom Attack Surface: SS7, BGP Hijacking, And The Technical Reality Of Nation-State Intrusions
        "Nation-state operators rarely need a zero-day to get inside a carrier. Much of the telecom stack still runs protocols designed when every participant was a known, trusted operator. SS7 assumes that the node sending a request has a legitimate reason to send it. BGP assumes a network announcing a route actually owns it. Attackers who understand those assumptions can operate inside a carrier for years without triggering a single alert. For telecom CISOs and SOC teams, defending this environment starts with understanding how these attacks actually work."
        https://cyble.com/blog/ss7-bgp-nation-state-intrusions/

      Vulnerabilities

      • Citrix Confirms Two NetScaler RCE Zero-Days Exploited In Attacks
        "Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws. The vulnerabilities are the same zero-days that cybersecurity researchers, IT providers, and national cybersecurity agencies began privately warning organizations about over the weekend. NetScaler appliances are particularly valuable targets because organizations commonly deploy them as Internet-facing edge devices that provide remote access and application delivery services for internal corporate networks."
        https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
        https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
        https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html
        https://securityaffairs.com/199873/security/citrix-confirmed-two-new-netscaler-flaws-exploited-as-zero-day.html
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability
        CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalog
        https://thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html
        https://securityaffairs.com/199777/hacking/u-s-cisa-adds-microsoft-sharepoint-and-mikrotik-routeros-flaws-to-its-known-exploited-vulnerabilities-catalog.html
        https://www.securityweek.com/microsoft-sharepoint-flaw-cve-2026-65660-now-exploited-in-attacks/
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-one-known-exploited-vulnerability-catalog
        https://securityaffairs.com/199790/security/u-s-cisa-adds-wordpress-flaw-to-its-known-exploited-vulnerabilities-catalog.html
      • Kiteworks Urges 6-Hour Server Shutdown Over Potential Zero-Day Attacks
        "Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack. According to German technology publication Heise, Kiteworks CISO Frank Balonis emailed customers warning that the company had received "credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend.""
        https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/
        https://therecord.media/kiteworks-urges-customers-to-stop-using-systems-incident
        https://thehackernews.com/2026/09/kiteworks-urges-customers-to-shut-down.html
      • Cross-Site Request Forgery In Elementor Plugin Affecting 2 Million+ Sites
        "This blog post is about a Cross-Site Request Forgery vulnerability in the Elementor Website Builder plugin. One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perform. On a stock installation, an administrator clicking the link creates a second administrator account for the attacker. The link needs no JavaScript, no form, and no page under the attacker’s control. It works as a plain anchor in an email, a chat message, or a comment. Patchstack has issued mitigation rules to protect against exploitation of this vulnerability."
        https://patchstack.com/articles/cross-site-request-forgery-in-elementor-plugin-affecting-2-million-sites/
        https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/
        https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html
      • SalesBleed: Indirect Prompt Injection And 0-Click Data Exfiltration On Agentforce
        "We found a way to pull sensitive account data out of Salesforce Agentforce without ever logging in, or requiring the victim to click anything. The entry point was a public Web-to-Lead form, the exit was a DNS query. We call it SalesBleed. In between, sat a few guardrails and Salesforce's Trusted URLs mechanism, which is a redaction layer built to strip untrusted URLs out of agent responses before a user ever sees them. We were eventually able to fully bypass all these mechanisms and exfiltrate data."
        https://labs.zenity.io/post/salesbleed-0-click-data-exfiltration-on-agentforce
        https://www.infosecurity-magazine.com/news/vulnerabilities-salesforce-ai/
        https://www.securityweek.com/salesbleed-flaws-in-salesforce-agentforce-enabled-zero-click-data-exfiltration/
      • How Cloudflare Addressed a Cross-Tenant Data Exposure Vulnerability In Containers
        "On September 4, 2026, Oren Yomtov, a security researcher from Accomplish, responsibly reported a vulnerability affecting Cloudflare Containers and Cloudflare Sandboxes (which is built on Containers), through Cloudflare’s bug bounty program. Cloudflare has fully remediated the vulnerability, and we have no evidence that customer data has been compromised. This post was prepared in collaboration with Oren Yomtov and the Accomplish security research team, whose detailed report and controlled testing helped us validate the issue and respond quickly."
        https://blog.cloudflare.com/containers-cross-tenant-vulnerability/
        https://thehackernews.com/2026/09/cloudflare-fixes-flaw-that-let-one.html
        https://www.bleepingcomputer.com/news/security/cloudflare-fixes-containers-cross-tenant-flaw-exposing-customer-data/
      • File Notification Attacks
        "File-notification systems tell applications when files change, e.g., opened, closed, written, deleted. With only read permission on a file or directory, an attacker can watch these notifications and reconstruct user behavior. We find generic issues similar on each of Linux, Android, Windows, and macOS. However, there are three issues that are severe and unique to their platform: 1. On Linux, watching a readable directory reports every event on a file inside it, even one the attacker cannot read directly. The most severe case of this is with /dev/input, discussed in Inter-Keystroke Timing below. 2. On Android, FileObserver bypasses the FUSE layer's per-app storage view, letting an unprivileged app watch another app's private folder. We show this against WhatsApp, revealing exactly when photos, videos, and files arrive or get deleted, detailed in Revealing Private Communication below."
        https://inoti.fyi/
        https://www.securityweek.com/windows-linux-android-file-notification-systems-leak-user-activity/
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-88771 Citrix NetScaler Improper Input Validation Vulnerability
        CVE-2026-88772 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog

      Malware

      • The Brand Was Real. The Desktop App Wasn’t.
        "Someone is impersonating major HR and payroll platforms with “native desktop apps” that do not exist. The download is real and what it installs is real, but it is not what the victim is expecting. The file is a copy of ConnectWise ScreenConnect, a legitimate remote monitoring and management (RMM) tool of the kind IT teams use to administer machines remotely, configured here for silent unattended access and pinned to the attacker’s server. The lure pages were generated with an AI app builder and hosted on Vercel, the payload was served from GitHub Releases, and a single operator ran at least three brand lookalikes at once."
        https://alluresecurity.com/blog/signal-noise-brand-was-real-app-wasnt
        https://www.helpnetsecurity.com/2026/09/25/fake-payroll-desktop-apps-screenconnect/
        https://www.theregister.com/security/2026/09/25/crooks-use-fake-desktop-apps-to-fool-hr-staff-into-giving-them-remote-access/5299226
      • AliExpress Phishing Campaign: What EfficientIP Research Labs Uncovered
        "EfficientIP Research Labs uncovered an AliExpress phishing campaign designed to lure people to a convincing fake shopping site. On June 9, researchers identified ten potential web addresses before they were registered and added them to DNS Threat Pulse. On July 2, the addresses became active, and their shared naming patterns and infrastructure linked them to the same campaign. The campaign directed visitors through a series of links to a fake AliExpress-themed site. It used familiar branding, a lookalike name and an “Add to Browser” prompt encouraging visitors to install a shopping-assistant extension. Several independent security services classified the destination as malicious or unsafe."
        https://efficientip.com/blog/aliexpress-phishing-campaign-dns/
        https://www.infosecurity-magazine.com/news/aliexpress-phishing-flagged-early/
      • Kothamine Malware Uses Tailscale’s Tailcat To Evade Network Detection
        "We discovered an undocumented remote-access Trojan (RAT) called Kothamine Agent. It supports more than 30 commands and it gives attackers control of an infected Windows computer: they can run commands, read and change files, and add new capabilities. Some versions can also steal browser data and record through the camera and microphone. We found Kothamine linked to malicious npm packages, which could put users and developers who install those packages at risk. In recent versions, the malware uses tailcat, an open-source tool from Tailscale, to receive commands over an encrypted connection. That makes its communications harder to inspect and gives defenders no conventional command-and-control (C2) domain to block."
        https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection
      • Threat Actors Use Google Ads To Target Ledger Users
        "In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake device-verification process prompted users to enter their secret recovery phrases, which attackers could use to access their wallets without the physical devices. In this blog post, ThreatLabz examines the campaign’s infrastructure and the steps used to trick users into submitting their recovery phrases."
        https://www.zscaler.com/blogs/security-research/threat-actors-use-google-ads-target-ledger-users
      • Re-Enabled GitHub Actions Expose Thousands Of Repositories To Mini Shai-Hulud
        "The GitHub Actions actions-cool/issues-helper and actions-cool/maintain-one-comment were compromised in the May 2026 Mini Shai-Hulud campaign. GitHub security team disabled both repositories on May 19, 2026, one day after the malicious content was introduced. Disabling the repositories stopped the attack: downstream workflows could no longer download either action, so they failed before any action code ran. On September 16, 2026, both repositories became accessible again. Their release tags were not cleaned up first. They still point to the malicious content introduced on May 18, so any workflow that references either action by a version tag resumed downloading and executing the payload on its next run."
        https://socket.dev/blog/mini-shai-hulud-actions
        https://thehackernews.com/2026/09/compromised-github-actions-came-back.html
        https://www.bleepingcomputer.com/news/security/github-actions-re-enabled-with-mini-shai-hulud-payload-still-active/
      • PamStealer Adapts Again: a Move To Swift With a Server-Side Decryption Chain
        "Following our July 2026 publication of PamStealer, Jamf Threat Labs has continued to monitor and identify additional variants. While our earliest publication documented a compiled JXA dropper distributed as a fake Maccy clipboard manager, the sample analyzed here uses the same compiled JXA outer format but shifts the lure and rebuilds the delivery chain entirely. What distinguishes this variant from its earlier ones is not what it collects but how it is delivered. Where earlier variants embedded their payload key material directly in the JXA source, it now fetches a purpose-built decryption utility and completes a key exchange with the server before the payload can be unwrapped. Without the server's cooperation, the payload cannot be recovered statically. The second stage has also been rewritten, moving from Rust to Swift, while carrying forward the PAM-based credential validation that gave this family its name."
        https://www.jamf.com/blog/pamstealer-wavel-macos-infostealer/
        https://thehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html
      • Been Told To Pay At a Bitcoin ATM? Read This First
        "Many of us still view cryptocurrency as a niche asset. Yet some estimates claim that nearly one in 10 people globally own some. That’s why you may have noticed Bitcoin or crypto ATMs springing up in retail stores, transport hubs, and gas stations over recent years. Today there are tens of thousands in the US alone. Their job is simple: allow you to buy or sell crypto using cash or card. But scammers also have them in their sights. If you ever receive an unsolicited call urging you to deposit money into a crypto ATM, hang up immediately, no matter how serious the allegations. No real government agency, bank, or company will ever tell you to pay them via a Bitcoin ATM."
        https://www.welivesecurity.com/en/scams/been-told-pay-bitcoin-atm-read-first/
      • Threat Actor Profile: Blue Locker Ransomware
        "Blue Locker Ransomware, first detected in late 2021, the group stayed low-profile for years before making global headlines in August 2025 with a targeted attack on Pakistan Petroleum Limited (PPL), the country’s second-largest oil and gas producer. The attack encrypted servers, wiped backups, and brought financial operations to a standstill for two days, prompting Pakistan’s National CERT to issue an emergency advisory to 39 government ministries and institutions. However, attribution remains vague due to competing analyses linking the malware to the Iranian-associated Proton ransomware family on one hand and to an open-source project called MemeCryptor on the other."
        https://socradar.io/blog/dark-web-profile-blue-locker-ransomware/
      • File Acquisition May Be Recorded As “FileAccessed” In Microsoft 365 (“M365”)
        "A recent trend has emerged where threat actor groups (e.g., ShinyHunters, PEAR, HELIX, etc.) have been leveraging phishing and vishing techniques to gain access to M365 email accounts. Through identity and token abuse, these actors have then automated large-scale file exfiltration and extortion campaigns targeting SharePoint, OneDrive, Microsoft Entra ID (formerly Azure AD), and email data through abuse of the Microsoft Graph API. Variations of this playbook have also included leveraging SSO-connected access to third-party platforms (e.g., Salesforce, Jira, etc.) to exfiltrate additional data. Threat actors may also leverage the My Apps page within Microsoft 365, which provides a centralized view of applications available to the user and is frequently used by threat actors to access connected services and applications."
        https://www.levelblue.com/blogs/spiderlabs-blog/file-acquisition-may-be-recorded-as-fileaccessed-in-microsoft-365
      • Beyond The Ransomware: Tracking Storm-2570’s Consistent Tradecraft Across Deployments
        "Activity associated with Storm-2570, a ransomware affiliate linked to multiple ransomware payloads, illustrates how tracking and responding to ransomware attacks by payload alone can obscure the affiliates carrying out intrusions and the recurring behaviors that defenders can use to detect and disrupt them. Microsoft Threat Intelligence has observed Storm-2570 using consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware. Across multiple investigations, Storm-2570 has maintained largely uniform tradecraft, infrastructure overlaps, and repeated use of the same remote access and cloud exfiltration tooling despite operating across multiple ransomware ecosystems."
        https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/
      • The Not So Silent Miner: Threat Actor Compiles Cryptominer On The Endpoint
        "Huntress researchers recently came across a unique incident where, after gaining initial access via exploiting a known Samsung MagicINFO vulnerability and installing a rogue AnyDesk instance on the endpoint, among other things, the threat actor aimed to deploy a cryptominer. Cryptominers in incidents aren't uncommon, but what raised our eyebrows was that the actor in this incident compiled the cryptominer directly on the endpoint. They ran commands via Silent XMR Miner Builder.exe (a Windows builder for deploying a Monero, or XMR, cryptominer, commonly associated with the open-source SilentXMRMiner project) that executed several .NET Framework utilities and an array of C compilers."
        https://www.huntress.com/blog/threat-actor-compiles-cryptominer
      • ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
        "As an update to the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), along with expanded global targeting across multiple sectors. In June, the threat actor exploited this vulnerability as a zero-day predominantly against academic institutions. This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint."
        https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft
        https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/
        https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html
      • Lunex Unmasked: A New Information Stealer Deployed Through BYOVD
        "The Ontinue Cyber Defence Centre has identified and reverse-engineered a four-stage attack chain associated with the Lunex Malware-as-a-Service platform, targeting Ukrainian-speaking users. The analysed stealer binary was compiled on 12 September 2026, with its supporting infrastructure provisioned shortly beforehand, indicating active development. The attack chain begins with a fake CAPTCHA page and culminates in the deployment of a fully featured C2 agent. The stealer extracts credentials and data from seven Chromium-based browsers, exfiltrates cryptocurrency wallets, and establishes persistent remote filesystem access through a PowerShell-based Native Messaging Host installed within the victim’s browser."
        https://www.ontinue.com/resource/lunex-unmasked-a-new-information-stealer-deployed-through-byovd/
        https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html
      • OpenAI Says Its Models Engaged With US Government Websites In New Model Misbehavior Disclosure
        "OpenAI disclosed Friday that its artificial intelligence agents had interacted with several U.S. government websites in unexpected ways, discovered as part of an ongoing review into the company’s models’ unanticipated behavior. The AI giant’s models accessed publicly available information on two websites operated by the Securities and Exchange Commission as well as U.S. Census Bureau data, the company revealed Friday. OpenAI did not find any use of SEC credentials, access to accounts or nonpublic information, changes to SEC data or systems, or evidence of a compromise or vulnerability, the company said."
        https://www.securityweek.com/openai-says-its-models-engaged-with-us-government-websites-in-new-model-misbehavior-disclosure/
        https://securityaffairs.com/199815/ai/openai-agents-accessed-us-government-websites-without-authorization.html

      Breaches/Hacks/Leaks

      • ShinyHunters Hacked Clop Leak Site Using Grav CMS Path Traversal Flaw
        "The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. The Clop leak site was breached earlier this month by the ShinyHunters extortion gang, which first uploaded a small text file and later replaced the site with a full-page defacement displaying its Umbreon Pokémon logo and a link to its own data leak site."
        https://www.bleepingcomputer.com/news/security/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw/
      • Hackers Steal $351.6 Million In Bitget Crypto Exchange Hack
        "Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. The company discovered the breach Thursday evening after its security systems flagged multiple unauthorized transfers from a limited number of crypto wallets. Bitget has temporarily suspended all withdrawals while investigating the incident with help from law enforcement agencies, on-chain security institutions, and cybersecurity experts at Mandiant and SlowMist."
        https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/
        https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html
        https://therecord.media/crypto-ceo-accuses-north-korea-of-387-million-theft
        https://www.securityweek.com/north-korea-suspected-in-351-million-bitget-crypto-heist/
        https://securityaffairs.com/199754/cyber-crime/cryptocurrency-exchange-bitget-says-north-korea-linked-hackers-stole-351-6-million.html
        https://www.theregister.com/cyber-crime/2026/09/25/bitget-blames-north-korea-for-3875m-crypto-wallet-raid/5299218
      • Cyberattack Hits Welsh Police Force, May Have Affected Staff Data
        "Dyfed-Powys Police in Wales said Friday a cyberattack affecting the force disrupted some non-emergency systems and may have compromised staff information. The force said it identified the incident earlier this month. It has found no evidence that information belonging to members of the public was affected. The police are still investigating whether information involving employees was accessed or compromised, a spokesperson said."
        https://therecord.media/wales-cyberattack-police-breach

      General News

      • Rydox Marketplace Admin Pleads Guilty, Faces 22 Years In Prison
        "A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. Kosovo law enforcement and Albania's Special Anti-Corruption Body (SPAK) arrested 28-year-old Ardit Kutleshi and two other Rydox administrators (Jetmir Kutleshi and Shpend Sokoli) in December 2024. The arrests were part of a joint international law enforcement operation that also shut down the Rydox marketplace, seized the Rydox[.]cc domain, and seized its servers in Kuala Lumpur with the help of the Royal Malaysian Police."
        https://www.bleepingcomputer.com/news/security/rydox-marketplace-admin-pleads-guilty-faces-22-years-in-prison/
        https://www.securityweek.com/kosovar-owner-of-rydox-marketplace-pleads-guilty-in-us-court/
        https://securityaffairs.com/199825/uncategorized/rydox-admin-faces-20-years-after-selling-stolen-data-and-fraud-tools.html
      • Former U.S. Soldier Sentenced For Hacking And Extortion Scheme That Exposed Sensitive Data Of U.S. Government Official
        "Cameron John Wagenius, 22, a former Army soldier who was most recently stationed in Texas, was sentenced today to 70 months in prison and ordered to pay $294,978 in restitution for conspiring to hack into telecommunications companies’ databases, access sensitive records, and extort the companies by threatening to release the stolen data unless ransoms were paid. In November 2024, Wagenius made two online posts that disclosed stolen confidential non-content call detail records belonging to a government official and family members of another former official and threatened to release additional confidential records unless paid a ransom. The text of one of these online posts suggested that Wagenius was motivated by a desire to retaliate for the then-recent arrest of another cybercriminal."
        https://www.justice.gov/opa/pr/former-us-soldier-sentenced-hacking-and-extortion-scheme-exposed-sensitive-data-us
        https://cyberscoop.com/cameron-wagenius-att-snowflake-attacks-sentenced/
      • AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
        "In 1983, WarGames imagined a teenager accessing military systems and nearly triggering a nuclear conflict. The cultural impact was immediate. Congress held hearings, policymakers questioned whether such a scenario was possible, and concerns about computer security entered the mainstream. Forty years later, autonomous AI agents have sparked a similar reaction. Recent disclosures from OpenAI and Anthropic described cybersecurity agents reaching beyond the boundaries of the test environments designed to contain them. The headlines were predictable: AI had "escaped the sandbox.""
        https://www.darkreading.com/cyberattacks-data-breaches/ai-sandbox-escapes-forensic-readiness
      • Stopping IT Worker Scams Requires Revamped HR Process
        "When a suspected North Korean operative applied for a remote AI engineering position at human-risk management firm Nisos in June 2025, the company decided to run its own operation on the fraudster. Nisos notified law enforcement, conducted an HR interview, "hired" the worker, and sent a laptop to that person's US address in Florida — a laptop "farm" — with surveillance implants. "When they opened the laptop, we could see that [the computer was] in a closet with a bunch of other companies' computers," says Ryan LaSalle, the firm's CEO. "We could see it so well that we could see the names of the other companies on the screens across the closet.""
        https://www.darkreading.com/cyber-risk/stopping-it-worker-scams-revamped-hr-process
      • Threat Detection Dashboards Are Masking Security Coverage Gaps
        "A detection rule can show up as deployed on a coverage dashboard and still never fire when an attacker uses the technique it was built to catch. Conifers assessed 14,652 detections in its customer base, including rules written by customers and detections managed by vendors in SIEM, endpoint, cloud, identity, email and network tools. The research found that 47% of detections in the average organization need attention."
        https://www.helpnetsecurity.com/2026/09/25/threat-detections-coverage-gaps-report/
      • Stop Watching What AI Agents Say And Start Watching What They Do
        "In this interview with Help Net Security, Ariel Assaraf, CEO of Coralogix, explains why a system prompt can describe a boundary for an AI agent but cannot enforce one. Assaraf covers how his team builds AI agent guardrails at the execution layer, limits context without expanding authority, and tunes controls by risk so agents stay useful during incidents. He describes how he tracks the consequences of agent actions, since an agent can return 200s and still do harm."
        https://www.helpnetsecurity.com/2026/09/25/ariel-assaraf-coralogix-ai-agent-guardrails/
      • Your Incident Count Is Missing a Few Incidents
        "If you run security for a brand with hundreds or thousands of locations, the tools you’ve bought may have little to do with whether an attack stays at one store. A new VikingCloud survey asked 200 security and IT leaders at U.S. and European chains about the past year. None of the 13 security technologies it measured was tied to less spread between sites, and neither was real-time visibility. One policy decision was. The sections below cover that decision and why it matters most if franchisees run some of your sites. They also cover how many serious incidents never reach executive leadership, and the exposure that opens with every new store. Eighty percent of these chains open a location before central monitoring and enforcement reach it. The problem is widespread: 86% of respondents were attacked in the past year, and 77% of those saw the attack move past its starting point into other locations, corporate systems, or shared vendors."
        https://www.helpnetsecurity.com/2026/09/25/eu-usa-retail-chain-cyberattacks/
      • Exploit.in Database Reveals The Roots Of Today’s Ransomware Ecosystem
        "Ransomnews researcher Dancho Danchev dug up a database dump of Exploit.in covering its first three years, from February 2005 to May 2008, and the numbers inside it tell a story about Russian cybercrime that enforcement press releases don’t. The dump contains 9,647 registered members, 13,925 threads, and 80,891 posts. The researcher who analyzed it had been reading Russian-language forums since those years and expected to recognize the layout. What surprised them wasn’t the marketplace threads selling shells and credit cards next to botnet rental offers. It was how many of the people from 2005 are still on the boards twenty years later."
        https://securityaffairs.com/199800/cyber-crime/exploit-in-database-reveals-the-roots-of-todays-ransomware-ecosystem.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) e81ab778-66d4-4f05-b311-2dd8be30a873-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการใช้ AI Agents สนับสนุนการโจมตีเว็บไซต์อีคอมเมิร์ซและขโมยข้อมูลบัตรเครดิต

      พบการใช้ AI Agents สนับสนุนการโจมตีเว็บไซต์อีคอ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 6d7fc5c5-5125-47be-afc2-1b630c2b922d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบแคมเปญปลอม LastPass บน GitHub แพร่ Infostealer พร้อมปิดการทำงาน Security Tools กว่า 145 รายการ

      พบแคมเปญปลอม LastPass บน GitHub แพร่ Infostealer พร้อมปิดการ_.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand eb0831a3-78d6-44a2-89f0-4eba5baf41ab-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • IonQ พัฒนาตัวถอดรหัสแก้ข้อผิดพลาดควอนตัม มุ่งแก้ปัญหาคอขวดในการประมวลผล

      IonQ พัฒนาตัวถอดรหัสแก้ข้อผิดพลาดควอนตัม มุ_0.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 6d30afaf-af2e-454c-872f-659793951f5c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 25 September 2026

      Industrial Sector

      • Botslab G980H Dashcams
        "Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, gain unauthorized access to sensitive data and privileged device functionality, modify device configuration, disrupt device operation."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01
      • Eufy Omni C20, Omni X10 Pro
        "Successful exploitation of these vulnerabilities could allow an attacker to run system level commands or execute arbitrary code."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-02
      • OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise On ICS Integrators
        "NIST this week released a draft of Special Publication 800-82 Revision 4, titled Guide to Operational Technology (OT) Security. Public comments are due by November 30, 2026. The document covers how to secure OT while accounting for the performance, reliability and safety demands specific to these systems. The revision expands the guide’s sector coverage to include building automation, water and wastewater systems, food and agriculture, freight rail, maritime vessels, and the convergence of industrial IoT and cloud. The guide is now organized around NIST Cybersecurity Framework 2.0, and the former risk management section has been reorganized to focus on the framework’s Govern function."
        https://www.securityweek.com/ot-security-guidance-nist-drafts-updated-guide-cisa-fbi-advise-on-ics-integrators/
        https://csrc.nist.gov/pubs/sp/800/82/r4/ipd

      Vulnerabilities

      • SolarWinds Patches Critical RCE Flaws In Observability Self-Hosted
        "SolarWinds has released patches for two severe vulnerabilities in Observability Self-Hosted that could be exploited for remote code execution (RCE). Observability Self-Hosted is an on-premises and hybrid IT monitoring solution that provides organizations with unified monitoring across environments, configuration management, and control over operational data and security compliance. The first flaw, tracked as CVE-2026-28324 (CVSS score of 9.8), is an insufficient integrity check issue leading to RCE on deployments that run non-default and non-secure configurations."
        https://www.securityweek.com/solarwinds-patches-critical-rce-flaws-in-observability-self-hosted/
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability
        CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalog
      • Hackers Now Exploit Critical Roundcube Flaw In Code Injection Attacks
        "A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. Roundcube Webmail is a browser-based IMAP email client used as the default mail interface by thousands of services with millions of users, and it is pre-installed with the widely used cPanel web hosting control panel. In May, the Roundcube security team patched the flaw (tracked as CVE-2026-48842), describing it as a pre-authenticated SQL injection in the virtuser_query built-in plugin, which handles database-driven user lookups and maps users to email addresses."
        https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/
      • CISA: Ransomware Gangs Now Exploiting Critical TeamCity Flaw
        "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. JetBrains patched the security flaw (tracked as CVE-2026-63077) on July 25 in TeamCity On-Premises versions 2025.11.7 and 2026.1.3, saying it is a critical authentication bypass vulnerability that lets attackers with HTTP(S) access execute arbitrary operating system commands."
        https://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw/
      • A Decision Model Breaks Like Any Other Language Model: A First Look At Jev
        "Nobody reads a decision. That is the whole reason we ran this test. A model that writes text gets checked by the person reading the text. A model that returns a verdict gets wired straight into the system that acts on it: an application proceeds to the next hiring stage, a recommendation goes to a committee, or an insurance claim gets rejected. There is no paragraph to disagree with, because there is not one."
        https://blog.checkpoint.com/ai-security/jev-is-not-a-language-model-but-it-breaks-like-one-prompt-injection-against-a-typed-decision-model/
      • Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
        "A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not said which. OnePlus confirmed both flaws in May. In the same reply, the company told Moorats that it alone decides when to make a flaw public and warned that publishing without its permission could result in legal liability. He published on September 24 anyway, when OnePlus had released no fix."
        https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html

      Malware

      • MacSync Under The Microscope: New Delivery Methods And a New Payload
        "MacSync is a relatively young, rapidly evolving family of crypto/info stealers. First advertised on the dark web in 2025 as Mac.c, the stealer was later renamed to MacSync by its creators. The initial versions were implemented as AppleScripts and closely resembled the AMOS stealer family, but over time, MacSync developed distinctive features of its own, including a backdoor module. In this report, we discuss a new infection chain that differs significantly from previous variants. We first spotted it in the wild in September 2026."
        https://securelist.com/macsync-new-version/121383/
        https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/
      • CARBONATO:​ ​a​ ​botnet​ ​built​ ​around An AI Agent​
        "In August 2026, we found an unauthenticated Docker registry that had been publicly exposed since May. Over one day of passive, read-only collection, we recovered 59 repositories, 234 image tags, 605 verified blobs, and 4.3 GB of image data. The archive spans October 2024 through August 2026. It documents two linked product lines: a factory distributing trojanized cryptocurrency wallet apps, and a botnet that compromises Docker daemons exposed on port 2375."
        https://www.threatdown.com/blog/carbonato/
        https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/
      • SalesBleed: Hijacking Agentforce In Slack For Anonymous Phishing Attacks
        "We discovered that Agentforce agents could be hijacked to send phishing messages in Slack. This issue originated from the default Slack Knowledge subagent template and its built-in Reply to a Slack Thread action, which allowed messages to be sent without user confirmation and without any way for other users to know who really initiated the message. Combined with the URL-redaction bypass described in our first post, this vulnerability could allow either an internal user or an external attacker to deliver phishing links using the agent’s own identity."
        https://labs.zenity.io/post/salesbleed-hijacking-agentforce-in-slack-for-anonymous-phishing
        https://www.darkreading.com/application-security/salesbleed-exploits-salesforce-agents-slack-phishing
        https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958
      • Uncovering a SectopRAT Variant Embedded In Legitimate Software
        "The FortiGuard Incident Response (FGIR) team recently investigated an intrusion involving SectopRAT, which was used to control the victim’s device. SectopRAT (also known as ArechClient2) is a .NET-based remote access trojan (RAT) that provides a range of functions through multiple control commands. These include collecting sensitive data from the victim’s device, capturing screens, remotely managing processes and files, controlling bots, and other forms of remote device management."
        https://www.fortinet.com/blog/threat-research/uncovering-a-sectoprat-variant-embedded-in-legitimate-software
        https://www.darkreading.com/cyberattacks-data-breaches/sectoprat-returns-hiding-inside-legitimate-application
      • Ghost Service Accounts Enable M365 Data Theft In Chile
        "Hackers are leveraging overlooked machine accounts in Microsoft 365 (M365) to steal enterprise data from organizations in Chile. Within any organization's M365 environment, there are accounts that belong to humans, sure, but also shared functional identities and accounts for applications and automated processes. Individuals are responsible for their own identities, but who keeps track of, maintains, and secures those nonhuman ones? Without due diligence, those types can fall out of focus and become forgotten relics with default credentials and excessive permissions."
        https://www.darkreading.com/cyberattacks-data-breaches/ghost-service-accounts-m365-data-theft-chile
      • "n0n Ransomware" Emerges As a New Threat Group With Destructive Extortion Claims
        "n0n is a financially motivated cyber extortion group that emerged in September 2026, first seen on September 18, 2026, with activity tracked through September 22, 2026. The group operates a double-extortion model, combining data theft with threats to destroy or encrypt victims' backup and shadow-copy infrastructure, publishing victims to a dedicated Tor-hosted leak site ("no js | no mercy") when payment deadlines are not met.n0n has published 13 victims to date across 10 identified countries, spanning sectors including financial services, education, retail & e-commerce, technology, and healthcare/pharmaceuticals. Of these 13 listings, 2 remain active with pending payment deadlines and 11 have already had data leaked after deadlines expired."
        https://cyberxtron.com/resources/blogs/-n0n-ransomware-emerges-as-a-new-threat-group-with-destructive-extortion-claims--8167
        https://www.infosecurity-magazine.com/news/ransomware-gang-uses-backup/
      • The Psychedelic Stealer: When a CAPTCHA Becomes An Installer
        "Arctic Wolf Labs is tracking an ongoing campaign that compromises legitimate Ukrainian business websites and uses injected iframes to display a Ukrainian-language fake Cloudflare verification page. When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the Windows Run dialog. The command retrieves an MSI package that ultimately delivers a previously unidentified infostealer containing the embedded tag “Psychedelic.”"
        https://arcticwolf.com/resources/blog/psychedelic-stealer-fake-clickfix-captcha-targets-ukraine/
        https://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.html
      • Inside Corp MDM, The Android Spyware Targeting Logistics Companies
        "A malware campaign targeting the logistics sector used fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file disguised as a system service. The delivered app, package com.corp.mdm, is a compact surveillance implant designed to exfiltrate newly received SMS content, divert calls, and maintain a hidden foreground service. The implant is narrow by design. It does not contain the broad surveillance functions often associated with commercial Android spyware. We assess that the threat actor likely used AI during development, and the spyware contains bugs that hinder its capabilities."
        https://haveibeensquatted.com/blog/inside-corp-mdm-android-spyware-targeting-logisitics
        https://thehackernews.com/2026/09/corp-mdm-spyware-targets-logistics.html
      • 17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report By CTM360
        "ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why blocking malicious domains is no longer a useful defense. A particular kind of security problem no patch will close. ClickFix is one of them. The attack begins with a page that presents a problem the user believes is theirs to solve. A human verification check that will not complete. A browser that cannot render the page. A document that will not open. A Mac that is running low on storage. The page offers a remedy in the form of instructions, quietly writes the "fix" to the clipboard, and asks the user to open a system interface they already trust, paste, and press Enter."
        https://thehackernews.com/2026/09/17000-urls-reveal-how-clickfix-turns.html
        https://www.ctm360.com/reports/clickfix-beyond
      • The Rogue RMM Stack: One Phish, Multiple Persistence Paths
        "Attackers are increasingly turning to trusted software your business already depends on instead of custom malware or exploits. In one recent Huntress Security Operations Center (SOC) investigation, a secure-document lure hid the installation of a remote monitoring and management (RMM) tool. The employee didn't know the file they opened would lead to an attacker's successful intrusion, ultimately installing a rogue ITarian client, followed by a ScreenConnect session for persistent access."
        https://www.huntress.com/blog/rogue-rmm-abuse-phishing-persistent-access
      • Russia Escalating Hybrid Attacks Across Europe
        "Since Russia’s full-scale invasion of Ukraine in February 2022, Russia has escalated its use of hybrid, asymmetric warfare across Europe, far beyond the former Soviet Union, where Russia historically focused its aggression. These tactics fall under a Russian military strategy known as New Generation Warfare (NGW). Insikt Group assesses that Russia is likely to escalate NGW tactics over the next two years, potentially culminating in a full-scale NGW campaign. Europe-based private and public sector entities are very likely at risk of physical and cyber sabotage as Russia deploys NGW tactics. Critical infrastructure entities in Europe are at high risk of being targeted, potentially resulting in data loss, physical damage to facilities, or injury or death of personnel."
        https://www.recordedfuture.com/blog/russia-new-generation-warfare
      • When Business Email Compromise Starts Rewriting Reality
        "Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets. This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details and broader findings based within the Zimbra Collaboration Suite. Our investigation disrupted the traditional BEC model in unexpected ways. We uncovered over 50 vulnerabilities, and found that several allow attackers not just to observe environments, but to actively rewrite them by impersonating senders without credentials, controlling inbox visibility, and altering shared documents and calendars."
        https://www.rapid7.com/blog/post/ve-business-email-compromise-rewriting-reality-zimbra-cve/

      Breaches/Hacks/Leaks

      • Early Rogue AI Agent Activity And Attempts To Hack Found On Urlquery[.]net
        "We present evidence that AI agents used the web security service urlquery.net to bypass restrictions and expand their access to the public internet. The agents also tried on three occasions to hack public data providers, including an Australian government website. We link at least some of this activity to agent swarms previously attributed to OpenAI. We also find evidence of earlier agent activity going back to at least March 6th, 2026, and potentially earlier, predating the previously reported Hugging Face, collusion.wiki, and RubyGems incidents by at least two months."
        https://transluce.org/agent-activity
        https://www.bleepingcomputer.com/news/security/openai-hacked-australian-medicare-govt-site-probed-data-providers/
        https://thehackernews.com/2026/09/openai-agent-bypassed-australian.html
        https://therecord.media/openai-australia-health-breach
        https://www.bankinfosecurity.com/rogue-openai-agent-hacks-australian-medicare-site-a-32921
        https://www.infosecurity-magazine.com/news/openai-hacks-australian-medicare/
        https://www.malwarebytes.com/blog/ai/2026/09/openai-agent-breached-medicare-statistics-portal-then-took-months-to-report-it
        https://www.securityweek.com/openai-agents-probed-websites-for-vulnerabilities-while-fetching-public-data/
        https://securityaffairs.com/199662/ai/openai-agent-bypassed-an-australian-government-health-portal-during-internal-research.html
        https://www.helpnetsecurity.com/2026/09/24/openai-agent-hacking-australia/
      • Astrana Latest Healthcare Tech Firm To Report Data Breach To SEC
        "The healthcare company Astrana warned regulators this week that a recent cyberattack exposed confidential information. The company filed a report with the Securities and Exchange Commission (SEC) on Tuesday evening about a recent incident in which hackers impersonated Astrana personnel and spoofed the company’s main corporate telephone number. The hackers contacted employees using the spoofed number and eventually were able to gain access to company servers."
        https://therecord.media/astrana-cyberattack-sec-ransomware
        https://www.securityweek.com/astrana-health-data-breach-impacts-private-confidential-information/
      • Someone Went Shopping In ASUS's eShop – For Customer Data
        "Asus has warned eShop customers that an intruder got into part of its online store and may have helped themselves to contact details and order records. The PC maker disclosed the incident in an email sent to customers, first reported by KitGuru, in which it said had identified "unauthorized access to part of the Asus eShop environment," although exactly when that access occurred remains unclear. "Our investigation indicates that certain customer order information, including contact details and order records, may have been accessed," the company said."
        https://www.theregister.com/security/2026/09/24/someone-went-shopping-in-asuss-eshop-for-customer-data/5298860

      General News

      • How To Build A SASE Framework For Modern Cybersecurity
        "Secure Access Service Edge (SASE) has demonstrated it can address many of the security concerns that arise at the intersection of on-premises, cloud and edge systems that many organizations need to combine to keep up their digital operations. But adopting SASE comes with its own challenges, and it's not a one-and-done process. To build an effective SASE framework, organizations need to rethink security governance, shift the focus of their policies, retrain teams internally and build new relationships externally. This transition can last 6-18 months, maybe longer, and requires maintaining security on both legacy and SASE systems simultaneously."
        https://www.darkreading.com/cloud-security/how-to-build-sase-framework
      • Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'
        "A simple but powerful prompt-injection vulnerability in a popular AI platform, Manus, could have opened the door for data theft and compromise —- and showcases the ongoing risk that users face from prompt injection. Manus is an agentic AI app whose rise to prominence was dramatic. Within a week of its launch in March 2025, 2 million people reportedly had signed up for its user waitlist. The same year it launched, it agreed to a sale to Meta for $2 billion, until the deal was scuppered by the Chinese government. It is now attempting to obtain new funding, which assumes a company valuation of $4 billion."
        https://www.darkreading.com/application-security/prompt-injection-bug-agentic-ai-app-manus
      • SASE Converges Network & Security Into One Cloud Solution
        "Hybrid cloud systems and the adoption of edge computing among enterprises has solved a number of modern problems, from the latency demands of real-time applications to the regulatory demands of data privacy in a global economy. But the intersection of on-premises, cloud and edge computing has created challenges in securing diverse systems under the same roof. Secure Access Service Edge (SASE) addresses this fragmentation. It integrates software-defined networking, threat prevention, access control, and application security into a unified, cloud-delivered platform accessed through a single management interface."
        https://www.darkreading.com/cloud-security/sase-converges-network-security-one-cloud
      • What To Do First When You Get 90 Days To Secure AI Agent Data
        "In this interview with Help Net Security, Kelly Herrell, CEO at Nol8, explains where AI agents create exposure inside organizations. The first thing to examine is the data path: what an agent can reach, what enters its context, and where results go. Ticketing systems, CRM platforms and shared drives hold years of sensitive context that agents can pull together in seconds. The conversation covers a 90-day plan for data access limits, the tension between business and security teams, and the case for enforcing policy in the data path."
        https://www.helpnetsecurity.com/2026/09/24/kelly-herrell-nol8-ai-agent-data-security/
      • Over 75% Of Organizations Experience Microsoft 365 Governance Issues
        "An estimated 77% of global organizations experienced at least one Microsoft 365 governance incident over the past year, with overconfidence in AI controls creating new risks, according to ShareGate. The governance specialist ran two surveys of nearly 1800 IT professionals and leaders across nine countries to produce its second annual State of Microsoft 365 report. Of those that suffered an incident, 38% admitted to leaving former employees or guests with access they should have lost, 35% encountered an audit or compliance gap and 26% had sensitive content reach the wrong people."
        https://www.infosecurity-magazine.com/news/75-organizations-microsoft-365/
      • Data Overtakes Skills As Top Threat Hunting Challenge, SANS Study Finds
        "Data has overtaken skills as the number one barrier for threat hunters, for the first time in the five years the SANS Institute has surveyed the industry. The research organization polled 500 cybersecurity practitioners and leaders across North America, Europe, Latin America and Asia to compile the SANS 2026 Threat Hunting Survey: The Evolution of Threat Hunting. Half (50%) of those respondents named data quality or quantity as their biggest hurdle to threat hunting, up from 41% last year and 34% in 2023."
        https://www.infosecurity-magazine.com/news/data-top-bottleneck-barrier-threat/
      • Autonomous AI Hacks Raise Thorny Questions Of Legal Accountability
        "The Justice Department has a long history of investigating and prosecuting hackers who break into a private company’s network. But what happens when the hackers aren’t human? That’s the question at the center of a public policy debate roiling Silicon Valley and Washington following disclosures by leading tech companies that their artificial intelligence models went rogue and hacked into other organizations. The attacks have generated calls even from within the industry for greater oversight and regulation, spurred congressional inquiries and raised questions about whether a years-old legal framework designed to punish criminal hackers is sufficient in an era of autonomous actors capable of engineering their own havoc."
        https://www.securityweek.com/autonomous-ai-hacks-raise-thorny-questions-of-legal-accountability/
      • Europe’s Technology Backbone Is Becoming a Cyber Target
        "Disruptive attacks on public-facing services, financially motivated cybercrime and compromises of shared technology providers are increasing cybersecurity risks across Europe. ENISA’s Threat Landscape 2026 identifies cybercrime, state-linked activity, foreign information manipulation and interference, hacktivism and vulnerability exploitation as key threats. Geopolitical developments influence attackers’ targets, and interconnected digital systems allow disruption to spread across organizations."
        https://www.helpnetsecurity.com/2026/09/24/enisa-eu-cyber-threats-report/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 5ad2779f-1f02-455a-a537-887c008a4800-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ Linux Kernel บน Ubuntu เสี่ยงหลุดจาก Container หลังมี Exploit เผยแพร่

      ช่องโหว่ Linux Kernel บน Ubuntu เสี่ยงหลุดจาก Container หลังม.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 182efd2c-d9f3-47a2-9c79-c72a07aeb67b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • นักวิจัยพบเทคนิค TrustSink ใช้ MFA Provider ปลอมขโมย Password ระหว่าง Login

      นักวิจัยพบเทคนิค TrustSink ใช้ MFA Provider ปลอมขโมย Password ร.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 700cd314-449c-4686-a1d3-51a4a35b6f62-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • FBI เร่งตรวจสอบ เหตุกลุ่ม ShinyHunters อ้างการโจมตีเว็บไซต์สมัครงานและเข้าถึงข้อมูลเจ้าหน้าที่

      FBI เร่งตรวจสอบ เหตุกลุ่ม ShinyHunters อ้างการโจมตีเ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 6d94fb95-1241-42bb-a9be-d96d1de01b65-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 24 September 2026

      New Tooling

      • Prismor: Open-Source Runtime Control Plane For AI Agents
        "Prismor is a free, open-source security layer for AI coding agents. It sits between an agent such as Claude Code, Codex, or Cursor and the actions that agent wants to take, and it checks each tool call against a policy before the call runs. Every call gets one of three verdicts: allow, warn, or block. AI coding agents run shell commands, read and write files, handle credentials, and call outside APIs, often chaining many steps with little human review. Anyone running one is exposed to a poisoned file, issue, or web page that redirects the agent mid-task, to an agent that opens a .env file while debugging and sends its contents out, and to installs of compromised packages. Endpoint security tools watch the kernel and file system, so they only see what the agent does after the choice is made. PrismorSec built Prismor to step in before that point."
        https://www.helpnetsecurity.com/2026/09/23/prismor-open-source-ai-agent-security/
        https://github.com/PrismorSec/prismor

      Vulnerabilities

      • Check Point Warns Of Hackers Exploiting Security Gateway VPN RCE Flaw
        "Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. The same advisory also warns of threat actors exploiting a pre-authentication path traversal flaw tracked as CVE-2026-93616, which impacts the Management web service and can allow script execution and Java class loading. The company says that CVE-2026-93616 has been exploited as a zero-day since July 23."
        https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/
      • Critical Next.js ImageResponse Flaw Can Lead To Server Code Execution Via Crafted SVG Input
        "A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed the flaw on September 22 in version 16.3.6. The flaw, tracked as CVE-2026-94545, affects Next.js 16.2.0 through 16.3.5 when ImageResponse runs on the Node.js runtime, which Next.js uses by default. Vercel's advisory rates it critical, with a CVSS score of 9.5. The Edge version of ImageResponse is not affected, and neither is Next.js 15."
        https://thehackernews.com/2026/09/critical-nextjs-imageresponse-flaw-can.html
      • CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After The Patch
        "Yesterday we wrote up CVE-2026-87902, the unauthenticated local file inclusion in WordPress page template resolution fixed in 7.1.2. That post covered the sink, the preconditions and the fix. This is the follow-up on what we are seeing hit our firewall. Update, 23 September 2026: when this post first went up, every request we had seen was reconnaissance against harmless core files. That is no longer true. Attackers are now including pearcmd.php and using it to write PHP files to disk, and public scanning tooling for this CVE is in circulation. The Update section below covers what changed. The original first day analysis is kept underneath it as a record."
        https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/
        https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/
        https://securityaffairs.com/199564/hacking/cve-2026-87902-how-close-is-your-wordpress-to-remote-code-execution.html
        https://www.helpnetsecurity.com/2026/09/23/cve-2026-87902-wordpress-7-1-2-security-release/
      • F5 Patches BIG-IP APM Zero-Day Flaw Exploited In RCE Attacks
        "F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. BIG-IP APM (short for Access Policy Manager) is the company's centralized access management proxy solution that helps admins secure access to their organizations' networks, applications, cloud, and application programming interfaces (APIs). Tracked as CVE-2026-94127, the flaw affects instances configured as an OAuth Authorization Server when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server."
        https://www.bleepingcomputer.com/news/security/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/
        https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html
        https://www.theregister.com/security/2026/09/23/someones-attacking-a-critical-0-day-rce-in-f5-big-ip-apm/5298659
        https://www.securityweek.com/critical-f5-big-ip-vulnerability-exploited-as-zero-day/
        https://securityaffairs.com/199619/security/f5-big-ip-apm-zero-day-exploited-in-zero-day-rce-attacks.html
      • New cPanel Flaw Lets a Hosting Account Run Code As Root, Take Full Server Control
        "A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts. cPanel has released fixed versions for both, along with a fix for a third flaw in the same service, which stores each account's calendars and contacts. That third flaw lets a local user on the server read other accounts' calendar events and contacts, but not change them or gain root access."
        https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html
      • Adobe Patches Critical Flaws In Connect, AEM Forms
        "Adobe on Tuesday rolled out patches for 36 vulnerabilities across its products, including critical-severity flaws in Connect and Experience Manager (AEM) Forms. The Adobe Connect update resolves nine security defects, including six critical issues that could be exploited for arbitrary code execution and privilege escalation. Tracked as CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, and CVE-2026-75698, they are described as SQL injection, cross-site scripting (XSS), and improper input validation flaws."
        https://www.securityweek.com/adobe-patches-critical-flaws-in-connect-aem-forms/
      • Chrome 154 Patches 108 Vulnerabilities
        "Google on Tuesday announced the release of Chrome 154 to the stable channel with patches for 108 vulnerabilities, including 11 critical-severity bugs. The critical security defects include buffer overflows (three in ANGLE and one in WebGL), out-of-bounds writes (two in GPU and one in WebGL), and use-after-free bugs in ServiceWorker, Fullscreen, WindowDialog, and AdFilter. Nine of the critical issues were reported by external researchers. In total, 32 of the newly patched flaws were reported externally, while the rest were discovered by Google."
        https://www.securityweek.com/chrome-154-patches-108-vulnerabilities/
      • Send GitLab An Email, Push To Main
        "GitLab projects have a button labeled "Email work item to this project". If you click it, GitLab shows you a private email address. Email anything to that address and a new issue appears in that project, authored by you. incoming+project-id-glimt-XXXXXXXXXXXXXX-issue@incoming.gitlab.com. The glimt- string in the middle of that address is a credential. It's a long-lived token tied to your account, and it never expires."
        https://www.aikido.dev/blog/gitlab-email-push-to-main
        https://www.darkreading.com/application-security/gitlab-email-addresses-supply-chain-attacks
        https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html
      • MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password Or SSH Key
        "Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2. As previously reported, CERT Polska warned on September 5 that attackers were using RouterOS flaws to take control of devices whose SSH service was reachable from public networks."
        https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html
      • Containers Are No Longer a Security Boundary
        "Containers are generally considered as a robust security isolation boundary and are widely used to isolate workloads across enterprise and cloud environments. As AI accelerates kernel vulnerability discovery and exploitation, the barrier to escaping containers by attacking kernel has fallen so significantly that we must assume attackers can do so at will. There are nearly 6000 kernel CVEs published as of September 2026. In this post, we demonstrate such a case using CVE-2026-80521, a Linux kernel use-after-free vulnerability in the AF_UNIX subsystem discovered with dfs-large1. The exploit code is available on GitHub. Organizations should move sensitive and untrusted workloads to stronger isolation technologies such as Firecracker or Kata Containers."
        https://depthfirst.com/research/containers-are-no-longer-safe
        https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html
      • Stealing OAuth Tokens Through Microsoft's Front Door
        "I was hunting for the next regsvr32. Not that binary specifically, but its category: a Microsoft-signed binary already on every Windows box that will fetch remote code and run it, so an attacker never has to drop anything unsigned. I pulled a catalog of signed binaries that don't appear in LOLBAS and filtered for anything that could reach the network and execute what it got back. The AppX web-host family came up in that filter, and one binary stood out. WWAHost.exe, the Windows Web App Host, will render whatever web content an AppX package points it at. That alone makes it interesting. However, what made me stop was the manifest flag: declare WindowsRuntimeAccess="all" and the remote JavaScript it renders doesn't just run, it inherits the full Windows Runtime API surface, including the API that drives OAuth sign-in. That was the moment it clicked as an attack. If a page I controlled could reach that sign-in API, it could stand up a real Microsoft login and pocket the tokens it handed back. I wanted to know if it actually worked."
        https://www.huntress.com/blog/stealing-oauth-tokens-through-microsofts-front-door

      Malware

      • Placeholder Domain Used In Dev Docs Now Serves ClickFix Attacks
        "The "third-party[.]com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands. The domain third-party[.]com has long been used in documentation to represent an arbitrary external website, API, or service, similar to how developers use domains such as example[.]com. However, unlike example[.]com, example[.]net, and example[.]org, which IANA reserves specifically for documentation, third-party[.]com is a normally registered domain whose content its owner can control."
        <https://www.bleepingcomputer.com/news/security/placeholder-domain-used-in-dev-docs-now-* serves-clickfix-attacks/>
      • RemControl: AI Built The Overlays. Victims Lose Their PINs
        "Group-IB researchers have discovered a previously undocumented Android banking trojan, internally named RemControl by its operator, targeting retail banking customers across Western Europe, the Middle East, and Canada. The malware abuses Android’s Accessibility Service to inject phishing overlays over legitimate banking applications, stream the device screen in real time, log keystrokes, and provide the operator with full remote control over infected devices. It is distributed through fake Google Play Store pages impersonating the TVTap IPTV application, with malvertising campaigns confirmed as one of the delivery channels."
        https://www.group-ib.com/blog/remcontrol-android-banking-trojan/
        https://www.bleepingcomputer.com/news/security/new-remcontrol-android-banking-malware-targets-users-in-europe-and-canada/
      • Autonomous AI Agents Are Breaking Into Hundreds Of Online Retailers For $25 a Target In An Ongoing Campaign
        "A financially motivated threat actor is using open source AI harnesses to attack hundreds of online retailers, at a marginal cost of tens of dollars per company. Gambit Security's Threat Intelligence team recovered the operator's staging server and reconstructed the campaign from it. Between 10 and 15 September alone, 105 attack projects were launched and at least 27 companies were compromised to varying degrees. The activity goes back to July 2026 and is still running."
        https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company
        https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/
      • Dark Sourcery: How Hackers Manipulate AI To Scam You
        "ChatGPT, Gemini, and Google AI Overview are being poisoned by a massive AI disinformation attack. When users look up everyday info of hundreds of major companies, AI is delivering phishing traps disguised as trusted answers. Attackers are flooding the web with carefully optimized posts, PDFs, reviews, and fake support pages, to trick AI into presenting fraudulent phone numbers, email addresses, and login pages. The targets included Delta, Lufthansa, Qatar Airways, Chase, Bank of America, Airbnb, TripAdvisor, and hundreds more."
        https://medium.com/@arielsimon/dark-sourcery-how-hackers-manipulate-ai-to-scam-you-88df434d2073
        https://www.darkreading.com/threat-intelligence/attackers-manipulate-ai-chatbots-mass-disinformation-phishing-campaign
      • DarkMe Email Campaign Broadens Targeting For APT RAT
        "DarkMe, a Visual Basic 6 (VB6) spy trojan and remote access tool became well known in February 2024 for its use of zero days to deliver malware. But this malware family was first observed in September 2021 and publicly documented a year later by NSFOCUS under "Operation DarkCasino" attributed to a group called EvilNum. Researchers at Trend Micro and SonicWall have also tied this malware, with the usual attribution caveats, to Water Hydra, an APT group with the unusual profile of chasing money rather than espionage. Its campaigns are typically financially motivated, targeting forex traders, stock-trading forums, online gambling platforms, and cryptocurrency users."
        https://www.huntress.com/blog/darkme-rat-abandons-exploits
        https://www.helpnetsecurity.com/2026/09/23/darkme-rat-phishing-email-hits-corporate-targets/
      • Fake Claude Max Giveaway Hides a Google Account Phishing Trap
        "Phishing follows whatever people want at the moment, and right now that includes AI subscriptions they don’t have to pay for. We recently uncovered a new variation on this theme: A fake Claude Max giveaway that uses a convincing Google sign-in window to steal login information. Claude’s paid plans start at $20 a month and cost considerably more for higher usage limits, while free accounts have stricter limits. That makes the promise of a free upgrade an attractive lure."
        https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-claude-max-giveaway-hides-a-google-account-phishing-trap
        https://www.helpnetsecurity.com/2026/09/23/fake-claude-max-giveaway-phishing/
      • x47.c Botnet Comes With 18 Attack Methods, Including AI API Draining
        "x47.c is a previously undocumented Windows botnet advertised with 18 attack methods, credential theft, SOCKS5 proxies, and an AI module designed to help it remain on infected machines. Qrator Research Labs identified the offering, sold by WraithTools, during routine threat hunting. One of the advertised methods, “AI API drain,” is designed to exhaust a victim’s paid AI credits. Using a valid API key, an operator can send repeated requests that consume the account’s balance or increase its bill. OWASP describes this type of attack as Denial of Wallet (DoW)."
        https://qrator.net/blog/details/x47.c-botnet
        https://www.infosecurity-magazine.com/news/x47c-botnet-ai-api-draining-18/
      • MemTensor Npm And PyPI Packages Hit By a Go Worm
        "On September 23, 2026, an attacker published malicious versions of two MemTensor packages. The affected packages are the OpenClaw plugin @memtensor/memos-cloud-openclaw-plugin on npm and the MemOS Python library MemoryOS on PyPI. Both versions contain the same Go implant, sckit. The binary runs in the background each time the package loads. It collects credentials from the home directory and sends them to servers under skyleen[.]fr. It also includes the code it needs to copy itself into other repositories and packages that the stolen credentials can reach. The attacker got the publish tokens from MemTensor’s own GitHub Actions release pipelines. To do this, they pushed commits that made the release job hand its npm or PyPI token to the attacker before the job published anything."
        https://safedep.io/memtensor-sckit-worm-npm-pypi/
        https://www.aikido.dev/blog/supplychain-local-memtensor-npm-pypi
        https://socket.dev/blog/memtensor-compromise
        https://www.stepsecurity.io/blog/sckit-supply-chain-worm-hits-memtensor-npm-pypi-scopes
        https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html
      • Meet AvisLoader: A Windows Loader Built To Outlast a Takedown
        "Varonis Threat Labs recently discovered AvisLoader, a new Windows loader named after the Latin word for bird. We found it on an exposed staging server alongside a ClickFix lure, supporting tools, and its Command Center. The attack starts with a familiar ClickFix lure. A page posing as a document-signing request asks visitors to copy and run an attacker-supplied command on their machine. The more interesting part is how AvisLoader stays connected. It communicates via Tox, an encrypted peer-to-peer (P2P) messaging network that carries commands and additional payloads from the operator."
        https://www.varonis.com/blog/meet-avisloader-a-windows-loader-built-to-outlast-a-takedown
      • Operation Conflict Compass: Konni Targets Ukraine Via Malicious LNK Lures
        "Since 2009, the Democratic People’s Republic of Korea (DPRK) has fully integrated cyber operations into its national strategy, leveraging state-nexus threat groups to execute cyberespionage, conduct sabotage and influence operations, and generate revenue for state-sponsored nuclear weapons programs. Recently, the SOCRadar Threat Research Unit (STRU) uncovered Operation Conflict Compass, a targeted campaign by the DPRK-aligned actor Konni, aimed at gathering intelligence on the ongoing trajectory of the Russian invasion of Ukraine."
        https://socradar.io/blog/operation-conflict-compass-konni-ukraine-lnk-lure/

      Breaches/Hacks/Leaks

      • GitHub App Private Keys: 474 Leaked Keys Exposed
        "Supply-chain security has been a hot topic in recent years. Threat actors have exploited the npm, PyPI, and Rust ecosystems to compromise developer machines at scale, and GitHub has played a central role as an entry point through badly configured Action workflows. GitHub Apps are a lesser-explored vector in that same landscape. Because of the privileges they hold, they are one of the most sensitive components in the GitHub ecosystem, capable of reaching into every repository an installation covers and, in the worst cases, taking over the organizations that installed them. The recent CISA leak showed exactly how far that reach can go: a single compromised App became an open door into the organization's information system."
        https://blog.gitguardian.com/github-app-private-keys-leaked/
        https://www.infosecurity-magazine.com/news/hundreds-leaked-github-app-keys/

      General News

      • InfraTrust Report Warns Network Management Systems Under Attack
        "Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. This was reported in the September edition of Eclypsium's InfraTrust Pulse, a monthly report tracking security advisories affecting network devices, servers, firmware, chips, and other infrastructure. Between August 25 and September 17, InfraTrust tracked 158 new security advisories across 17 vendors, covering 1,699 vulnerabilities."
        https://www.bleepingcomputer.com/news/security/infratrust-report-warns-network-management-systems-under-attack/
        https://pulse.infra-trust.org/september-2026/
      • Ryuk Ransomware Member Sentenced To 24 Months In Prison
        "An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. 35-year-old Karen Serobovich Vardanyan (also known online as "Maneeken" or "Karl Lagerfeld"), who specialized in gaining initial access to corporate networks, pleaded guilty in July after being extradited from Kyiv, Ukraine, following his April 2025 arrest. According to court documents, Vardanyan hacked into the networks of multiple U.S. organizations in Ryuk ransomware attacks between March 2019 and approximately June 2020."
        https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-sentenced-to-24-months-in-prison/
        https://therecord.media/ransomware-ryuk-sentenced-doj
        https://cyberscoop.com/ryuk-ransomware-operator-karen-vardanyan-sentenced/
      • CISA Lays Out Future Of CVE Vulnerability Program
        "The U.S. Cybersecurity and Infrastructure Security Agency published a short whitepaper Wednesday, laying out four "dimensions of quality" it will pursue to improve the Common Vulnerabilities and Exposures program it oversees, which catalogs and characterizes newly discovered software vulnerabilities. The CVE program is widely regarded as one of the world's most trusted and widely used cybersecurity public goods. It's employed by cyber defenders all over the world. Its future is a matter of enormous importance to the large cybersecurity vendor ecosystem that has grown up around vulnerability prioritization and management."
        https://www.bankinfosecurity.com/cisa-lays-out-future-cve-vulnerability-program-a-32912
        https://cyberscoop.com/cisa-cve-data-quality-white-paper-expert-reaction/
      • How The CISO-CMO Alliance Builds Trust Before Crisis Strikes
        "Chief information security officers (CISOs) and chief marketing officers (CMOs) sit at the intersection of a critical tension: CMOs seek to leverage vast pools of customer data to drive growth, brand loyalty, and market share. CISOs work to minimize risk exposure and protect that same data. But rather than viewing these objectives as opposing forces, forward-thinking organizations recognize that CISO-CMO alignment is foundational to a competitive advantage. Unfortunately, as is often the case, if this relationship isn't already established, miscommunication and misalignment can turn a security incident into a brand disaster."
        https://www.darkreading.com/cybersecurity-operations/how-ciso-cmo-alliance-builds-trust-before-crisis
      • Cyberthreats To The Gulf States In H1 2026
        "A high level of economic development, a key role in the global energy sector driven by oil and gas exports, and heavy investments in digital technologies make the Gulf states an attractive target for financially motivated cybercriminals. Additionally, the tense geopolitical climate in the region has led to increased activity from hacktivists and advanced persistent threat (APT) groups. This report analyzes the cyberthreat landscape in the Gulf states during the first half of 2026. The countries covered include Bahrain, Iraq, Iran, Kuwait, Oman, Qatar, Saudi Arabia, and the United Arab Emirates (UAE)."
        https://positechglobal.com/en/research/analytics/cyberthreats-to-the-gulf-states-in-h1-2026/
        https://www.darkreading.com/threat-intelligence/uae-saudi-arabia-face-onslaught-of-increasingly-sophisticated-automated-cyberattacks
      • Cloud Intrusions Now Move At Machine Speed
        "Cloud-native environments are vital to AI initiatives and business transformation. That also makes them high-value targets. Fortinet FortiCNAPP intelligence shows that threat actors are now using automated attack workflows to identify vulnerable deployments, breach them, and quickly turn access into profit. The 2026 Cloud-Native Threat Landscape Report draws exclusively on FortiCNAPP intelligence to examine the scale of adversary activity, the paths attackers use, the gaps they exploit, and the actions security leaders must now take to strengthen cloud resilience and accelerate defender velocity."
        https://www.fortinet.com/blog/industry-trends/cloud-intrusions-now-move-at-machine-speed
      • Nearly Two-Thirds Of Tested Websites Fail Every Bot Test
        "Malicious bot activity increased 124% between July 2025 and June 2026, compared with 13.2% growth in human traffic. Traffic from AI agents and large language model crawlers rose 82.3% during the same period, according to DataDome’s State of Bot & Agent Security Report 2026. The company analyzed trillions of requests across more than 75,000 customer sites during the 12-month period. Bots and AI agents generated approximately 26.5% of all traffic in the dataset."
        https://www.helpnetsecurity.com/2026/09/23/datadome-growing-bad-bot-traffic-report/
      • Ransomware Attacks Reach Record High For 2026
        "Over 1000 organizations globally were hit with ransomware attacks during August, as the number of cyber extortion campaigns reached a new high for 2026, analysis of incidents has warned. According to NCC Group’s Cyber Threat Intelligence Report for August 2026, published on September 23, 1073 companies fell victim to ransomware attacks during the month. The report stated the figure represented a record high for 2026 and a 12% increase on the 973 organizations hit by ransomware attacks during July. During August, North America was the most common target for ransomware attacks, accounting for 44% of incidents, organizations in Europe accounted for 26% of known incidents, while 13% of ransomware attacks targeted victims in Asia."
        https://www.infosecurity-magazine.com/news/ransomware-attacks-reach-record/
      • EU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response
        "The EU’s top audit institution has criticized the union for various “shortcomings” that are hindering its detection and response to large-scale cyber incidents. The EU Court of Auditors said in a new report that the bloc’s €1.4bn ($1.6bn) budget for cybersecurity is doing some good, but that it suffers from an Achilles heel, “The insufficient exchange of information.” A lack of formally defined roles is hampering cooperation between country-level CSIRTs and European Cyber Crisis Liaison Organisation Network (EU-CyCLONe), it warned."
        https://www.infosecurity-magazine.com/news/eu-auditors-slam-blocs-cyberinfo/
      • Anthropic And OpenAI Models Still Attempt Restricted Actions In Safety Tests
        "Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a "major step up from Opus 5," and "achieves the best scores of any model to date on our automated behavioral audit, our alignment suite that tests Claude across thousands of simulated scenarios." The AI company said the model is less likely than its other recent models to carry out hard-to-reverse actions or act outside the boundaries it's been given, adding it's more resistant than Opus 5 to prompt injection."
        https://thehackernews.com/2026/09/anthropic-and-openai-models-still.html
      • Latvia Arrests Suspected Hacker For Electronics Repair Company Breach
        "Latvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims, authorities said Wednesday. The first attack was detected in February, while a second — using similar methods — was discovered in early September at TSC, an electronics repair company belonging to Latvian telecommunications group LMT."
        https://therecord.media/latvia-hacker-arrest-cyberattack
      • A Look At AI Doomsday Scenarios That Researchers Say Could Put Humanity At Risk
        "For years, artificial intelligence researchers have warned of ways the technology could wipe out humanity: AI bots could design an unstoppable disease, unleash a nuclear war, or transform all of Earth into paper clip factories, as one thought experiment goes. Debates inside the AI industry and beyond over the plausibility of these doomsday scenarios have heated up since several executives endorsed slowing the technology’s development for safety reasons. Despite warnings of the potential for humans to lose their grip on the technology, some suspect the worst-case scenarios described by the AI companies themselves have more to do with validating the importance of their work than reality."
        https://www.securityweek.com/a-look-at-ai-doomsday-scenarios-that-researchers-say-could-put-humanity-at-risk/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 35ca38ff-ea20-42c8-a6e0-def15a987a6b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Microsoft เตือนช่องโหว่ CVE-2026-65660 ใน SharePoint อาจนำไปสู่การรันคำสั่งบนเซิร์ฟเวอร์

      Microsoft เตือนช่องโหว่ CVE-2026-65660 ใน SharePoint อาจนำไปสู่กา.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e5a469f3-c2bc-4972-930a-a8efc5f74e4f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • BigCommerce แจ้งเหตุข้อมูลรั่วไหล หลัง Credential ของแอป Ribon ถูกใช้ฝังสคริปต์อันตรายบนร้านค้าออนไลน์

      BigCommerce แจ้งเหตุข้อมูลรั่วไหล หลัง Credential ของแอป .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5fe31742-90a5-446e-bb24-84c2ed859d04-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ผู้ไม่หวังดีเจาะระบบควบคุมการผลิตน้ำประปาในรัฐโคโลราโด สหรัฐอเมริกา

      ผู้ไม่หวังดีเจาะระบบควบคุมการผลิตน้ำประ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 9ca85fac-7789-4c7f-a529-f33ddff3558d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT