NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,638
    • กระทู้ 2,639
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • พบมัลแวร์ CloudSyncD ปลอมเป็นตัวติดตั้ง Zoom บน macOS หลอกขอรหัสผ่านและเปิด Backdoor

      พบมัลแวร์ CloudSyncD ปลอมเป็นตัวติดตั้ง Zoom บน macOS หล.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5e0ef658-6c76-48da-bac5-ae2b2fbd9245-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • GitLab ออกแพตช์แก้ช่องโหว่ Critical ใน AI Gateway เสี่ยงถูกสั่งดำเนินการคำสั่งบน Self-hosted Gateway

      GitLab ออกแพตช์แก้ช่องโหว่ Critical ใน AI Gateway เสี่ยงถูก.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 15207616-4de6-49bf-ae20-63ceff6cfc96-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Citrix ออกแพตช์อุดช่องโหว่ Zero-day ใน NetScaler หลังพบถูกโจมตีจริง

      Citrix ออกแพตช์อุดช่องโหว่ Zero-day ใน NetScaler หลังพบถูก.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 4ec5c194-3b05-4853-a06e-4c38713f5698-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 05 October 2026

      Financial Sector

      • 8 Out Of 10 Banks HATE This One Weird 3SKey RCE
        "1M+ users, an extension middleware+native host for authentication with eIDs, 3SKeys and other hardware signing tokens had a drive-by RCE which enabled any site or iframe a user saw to silently download and execute a dll due to a poor hand-rolled implementation of RSA-2048 token validation, enabling a use of uninitialized memory validation bypass which enabled "plugins" (DLLs) to be loaded. v2.16.0.0 of the extension and native host is vulnerable. CVE-2026-18397. CVSS 9.4."
        https://amibeingpwned.com/blog/8-in-10-banks
        https://www.darkreading.com/cybersecurity-operations/swift-banking-govt-middleware-rce

      Vulnerabilities

      • GitLab Warns Of Critical RCE Vulnerability In AI Gateway Service
        "GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. AI Gateway is a service that gives access to AI-native GitLab Duo features. While GitLab operates its own cloud-based AI Gateway instance used by GitLab.com, GitLab Self-Managed, and GitLab Dedicated, users can also deploy their own self-hosted instances on GitLab Self-Managed through GitLab Duo Self-Hosted. Tracked as CVE-2026-90970, this security flaw stems from an improper neutralization weakness and can let attackers with basic privileges and Duo Agent Platform access execute arbitrary commands on unpatched instances."
        https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/
        http://docs.gitlab.com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-19-4-1-released/
        https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html
        https://securityaffairs.com/200283/hacking/cve-2026-90970-critical-gitlab-ai-gateway-flaw-fixed.html
      • Dell Asks Admins To Patch Max Severity CSM Flaws As Soon As Possible
        "Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. CSM supports Dell's primary storage platforms (PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT), and it extends the capabilities of the standard Container Storage Interface (CSI) drivers for Kubernetes. In a security advisory published on Thursday, Dell said that both critical security flaws were found in the Dell CSM Authorization security module and stem from "missing authentication for critical functions" weaknesses."
        https://www.bleepingcomputer.com/news/security/new-max-severity-dell-csm-flaws-give-hackers-admin-privileges/
        https://www.dell.com/support/kbdoc/en-us/000515771/dsa-2026-448-security-update-for-dell-container-storage-modules-multiple-vulnerabilities
        https://thehackernews.com/2026/10/dell-csm-flaws-enable-unauthenticated.html
      • Fortra Patches Critical Vulnerabilities In BoKS
        "Fortra has released patches for eight vulnerabilities in Core Privileged Access Manager (BoKS), including three critical-severity bugs. BoKS provides organizations with central management of Unix and Linux fleets, enabling policy enforcement and access control across accounts. On Thursday, the company warned that BoKS Manager deployments relying on BoKS keytab for Active Directory service account management are affected by a critical flaw leading to authentication bypass."
        https://www.securityweek.com/fortra-patches-critical-vulnerabilities-in-boks/
      • Citrix Patches NetScaler SAML Zero-Day Exploited In Attacks
        "Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. The vulnerability is a memory buffer flaw affecting NetScaler ADC and NetScaler Gateway appliances using SAML authentication with Gateway or AAA functionality. The Citrix security advisory says the vulnerability has a CVSS score of 8.7 and has been used in targeted attacks against unmitigated NetScaler deployments, causing denial-of-service conditions."
        https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/
        https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-102489 Zammad GmbH Zammad Session Fixation Vulnerability
        CVE-2026-102490 Zammad GmbH Zammad Improper Privilege Management Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/10/02/cisa-adds-two-known-exploited-vulnerabilities-catalog
        https://securityaffairs.com/200248/security/u-s-cisa-adds-zammad-gmbh-zammad-flaws-to-its-known-exploited-vulnerabilities-catalog.html
      • How We Hijacked An AI Agent With a Single Email
        "Salt Labs found that the agentic AI platform Manus could be hijacked with a single email. By hiding malicious instructions inside an ordinary message, researchers got Manus to execute malicious code and, from there, reach the email, cloud storage, and code repository accounts a user had connected to it. The full attack required nothing from the victim beyond asking Manus to check their inbox. No stolen password, no clicked link. The most important finding is not the specific flaw, which has since been resolved and is no longer exploitable, but what it reveals about autonomous systems. Manus's own security guardrail detected the attack, but only after the code had already run. On a system that acts on its own, no human sits between the alert and the action, so a control that fires a moment too late provides no protection."
        https://salt.security/blog/how-we-hijacked-an-ai-agent-with-a-single-email
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-88779 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/10/04/cisa-adds-one-known-exploited-vulnerability-catalog

      Malware

      • SMTP Is The Key: BPFDoor And AVERAT Hitting The Network Edge
        "Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant we track as AVERAT, deployed against Taiwanese appliances. Additionally, we provide source code details of the Rapid7 BPFDoor controller introduced in our April 2026 blog, Stealthy BPFDoor Variants are a Needle That Looks Like Hay."
        https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge/
        https://www.darkreading.com/threat-intelligence/malicious-linux-implants-mimic-asian-mail-security
      • Convincing Free Mobile Phishing Emails Appear After Data Breach
        "Free Mobile, one of France’s main cellular providers, was fined €27 million by France’s data protection regulator, the CNIL, in January over failures to protect customer data. The October 2024 breach allowed an unauthorized party to access sensitive customer records, including bank account details and login information. Since the breach, we’ve seen many poorly written scam campaigns targeting Free Mobile customers. However, over the past few weeks, a well-written scam has appeared, closely copying the design of the official Free Mobile website and email templates."
        https://www.malwarebytes.com/blog/threat-intel/2026/10/free-mobile-phishing-texts-appear-days-after-data-breach

      Breaches/Hacks/Leaks

      • Frontline Education Breach Exposes School District Employee Data
        "Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. Frontline Education is an edtech company that provides administration and workforce management software and services used by school districts. Last night, a reader shared a data breach notification with BleepingComputer that Frontline sent to an impacted school district, stating that attackers breached its environment through a vulnerability in a third-party application."
        https://www.bleepingcomputer.com/news/security/frontline-education-data-breach-impacts-school-district-employees/
      • Microsoft’s X Account Hacked In Crypto Pump-And-Dump Scheme
        "On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. The attack began when the Microsoft account (@Microsoft) followed and reposted a tweet from another now-suspended X account (@clippymsftcto) impersonating Microsoft's Clippy virtual assistant, The Verge first reported. While @clippymsftcto has been suspended, another X account (@ClippyMSFT) that reposted Microsoft's tweet is still promoting a $Clippy crypto token, claiming that it has "has a liquidity pool paired directly with $MSFT.""
        https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/
        https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/
      • Mississippi Mayor Says Ransomware Incident Led City To Shut Down Systems
        "A ransomware attack has shut down the computer systems of Vicksburg, Mississippi, the city’s mayor told residents on Thursday evening. Mayor Willis Thompson published a statement in the local newspaper saying the city is investigating a ransomware attack that has not impacted emergency services but has affected payments for utilities. He said the system shutdown was “temporary.” Thompson said no one's services will be shut off while the investigation is ongoing and no penalties will be issued for late payments. He later told the Vicksburg Post that the city has been working on the recovery effort with the FBI, Department of Homeland Security and other state officials alongside private cybersecurity experts."
        https://therecord.media/vicksburg-mississippi-government-ransomware-attack
      • Danish University DTU Breach Exposes Data Of Up To 200,000 People
        "The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. ​The university says the attacker used compromised credentials to log into DTUBasen, its identity and access management (IAM) system, allowing access to more than two decades of user data. In a disclosure on Friday, DTU confirmed that it cannot “determine precisely what information was downloaded or how many people have been affected.”"
        https://www.bleepingcomputer.com/news/security/danish-university-dtu-breach-exposes-data-of-up-to-200-000-people/

      General News

      • Treasury Sanctions Financial Network Of Foreign Terrorist Organization, Tren De Aragua, After Theft Of Millions From U.S. Banks
        "Today, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) designated 10 targets involved in a Tren de Aragua (TdA) fraud scheme that has become a key source of revenue for the organization. TdA is a Foreign Terrorist Organization (FTO) responsible for violent and exploitative criminal activity across the Western Hemisphere—including drug trafficking, human trafficking, extortion, and murder-for-hire—making the disruption of its financial networks essential to protecting Americans. This operation is orchestrated by one of the FBI’s ten most-wanted fugitives, Anibal Alexander Canelon Aguirre (aka “Prometheus”). In addition to this network, today OFAC also designated Juan Gabriel Rivas Nunez (aka “Juancho”), a high ranking TdA leader directing operations in multiple South American countries."
        https://home.treasury.gov/news/press-releases/sb0640
        https://www.bleepingcomputer.com/news/security/us-sanctions-tren-de-aragua-members-in-atm-jackpotting-crackdown/
      • The Legal Questions Raised By Agentic AI Hacks
        "As AI agents escaping testing sandboxes and hacking organizations have gone from unprecedented to seemingly routine in a matter of weeks, policymakers, regulators and cybersecurity attorneys largely agree on one thing: Something must be done to hold AI companies accountable for the incidents. Exactly what can be done under our current laws and regulations is much less clear. The conversation has moved from policy and industry chatter to the floor where the future of liability will be determined. Speaking about the Hugging Face hack at a Senate hearing this week, Georgetown University law professor Paul Ohm summarized the argument."
        https://cyberscoop.com/ai-agent-hacks-legal-liability-cfaa/
      • Kiteworks & Citrix Incidents Show Challenges Of Zero-Day Response
        "On Sept. 24, threat detection firm GreyNoise Intelligence observed a single US-based IP address scanning for Citrix NetScaler installations and conducting remote code execution (RCE) attacks. The company issued alerts to customers about the malicious activity. Over the next two days, reports of potential zero-day attacks on NetScaler installations emerged on social media, and cybersecurity professionals debated whether the rumored attacks were true — some argued the activity targeted vulnerabilities already patched in August. On Sept. 26, however, Benjamin Harris, founder and CEO of exposure-management firm watchTowr, urged NetScaler users to take their systems offline."
        https://www.darkreading.com/cybersecurity-operations/kiteworks-citrix-incidents-challenges-zero-day-response
      • Is Your Organization Ready For 2027's AI Accountability Era?
        "Artificial intelligence (AI) risks have evolved significantly over the past year. Reports of OpenAI and Anthropic agents acting autonomously continue to unfold, igniting a development slowdown debate amid heightened security concerns. Organizations will need to address the state of their own AI security for 2027, but preparations begin now. Organizations spent 2026 deploying AI at record speeds across operations. Top executives pushed for new innovations and urged employees to use them. Now organizations must prove they can govern, secure, and benefit from AI – a task that may be more difficult than simply implementing it."
        https://www.darkreading.com/cybersecurity-operations/is-your-organization-ready-for-2027-s-ai-accountability-era-
      • Is It Fair To Blame 'Rogue' AI For Security Failures?
        "Experts are pushing back on classifying AI escape incidents as "going rogue" because it risks obscuring the real security problems behind these events, they say. The tech ecosystem has been inundated with stories of large language model (LLM) agents "going rogue," specifically referring to models breaking out of their sandboxes, harnesses, and other containments in some way, and causing trouble by interacting with and breaching third-party organizations. The incident that kicked off much of this discourse came in July, when OpenAI disclosed that two of its frontier models autonomously hacked AI model store Hugging Face during a security exercise. Other major firms, including Meta, Anthropic, and Google, soon disclosed their own AI escape incidents."
        https://www.darkreading.com/insider-threats/blame-rogue-ai-security-failures
      • Vulnerability Backlogs Are An Ownership Problem
        "Most enterprises drowning in vulnerabilities don't have a detection problem. They have an accountability problem wearing a detection problem's clothing. You can see it in how they spend. When a backlog gets big enough to reach the board, the reflex is to buy better scanning — wider coverage, faster cycles, richer threat intel, a single pane of glass. A year later, the organization has excellent visibility into a backlog that has grown. That's a misdiagnosis, not a tooling failure. Scanning capacity and remediation capacity are independent variables, and only one of them scales with a purchase order."
        https://www.darkreading.com/cybersecurity-operations/vulnerability-backlogs-ownership-problem
      • Criminal Recruiters Want People On Your Payroll
        "Legitimate employee access can let criminals circumvent security controls that would be difficult to overcome from outside an organization. Routine actions such as information lookups, account resets, transaction approvals and shipment changes can become services sold to criminal customers, according to Intel 471’s Insiders for Hire: Underground Recruitment, Access Claims and Insider-Enabled Services report."
        https://www.helpnetsecurity.com/2026/10/02/intel-471-insider-threat-recruitment-report/
      • AI Agents Keep Access To Company Data After Their Work Is Done
        "IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf, according to a Delinea’s 2026 Identity Security Report: The AI Enforcement Gap. “Written policy is only as good as your ability to enforce it at the moment an AI agent acts,” said Art Gilliland, CEO of Delinea. “Our research echoes what I hear from leaders constantly: they have the AI policies in place, but they can’t see or report on what their agents actually do.”"
        https://www.helpnetsecurity.com/2026/10/02/delinea-ai-policy-adoption-enforcement-report/
      • In Rare Move, Alleged Iranian State Hacker Extradited To US
        "An Iranian national indicted in the US for hacking hundreds of organizations was extradited from Montenegro this week. Acting on an arrest warrant issued by the FBI, Montenegrin authorities arrested the individual, a dual citizen of Turkey and Iran, on June 25. The suspect is accused of involvement in numerous cyberattacks against US organizations starting in 2013. The attacks caused losses of more than $3.4 billion. The Montenegrin authorities did not name the individual, but mentioned his initials, A.B., and that he is 40 years old."
        https://www.securityweek.com/in-rare-move-iranian-hacker-accused-of-working-for-irgc-extradited-to-us/
      • Why AI Coding Agents Keep Writing Broken Access Control
        "AI coding agents produce authorization logic that compiles, passes review, and enforces the wrong policy. Broken access control ranks first in the OWASP Top 10:2025, where 100% of applications tested showed some form of it, across 1,839,701 recorded occurrences, the highest count of any category on the list. One part of that category is also the part that pattern-based scanning was never built to reach. When an agent omits an ownership check, the rule it broke belongs to the application rather than to a signature database. That leaves no known-bad pattern to match against."
        https://snyk.io/blog/ai-coding-agents-broken-access-control/
      • ShinyHunters Hacker In FBI Data Theft Detained In Jordan, Cooperating With Bureau, Sources Say
        "A suspected member of the ShinyHunters hacking group, which ​says it stole data on every FBI employee, was detained in Jordan this week and is cooperating with the FBI, three people familiar with the matter told Reuters. Saif ‌al-Din Khader was detained by Jordanian authorities, the three sources said. Two of them said he was brought into custody on Tuesday. Reuters could not immediately determine the circumstances of Khader’s detention or where he is being held. Two sources said that he is helping the FBI and global law enforcement locate the other hackers in the group."

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 9eb48edf-7dad-4354-bc27-7b3fed87c2a5-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 02 October 2026

      Industrial Sector

      • Armatura LLC Armatura One
        "Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01
      • Monta Monta.app
        "Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-02
      • CISA Malcolm
        "The following versions of CISA Malcolm are affected:"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01
      • ABB Protection And Control IED Manager PCM600
        "Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-03
      • Johnson Controls EasyIO Neo Series EC And CW Controllers
        "Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-04
      • Johnson Controls EasyIO Neo Series EC And CW Controllers
        "Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-05
      • Meari IoT Cloud Platform OpenAPI Service
        "Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-06

      Vulnerabilities

      • Fortinet Warns Of Critical FortiMail Flaw Exploited In Zero-Day Attacks
        "Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. The vulnerability is rated critical, with a CVSS score of 9.8, and affects the FortiMail management interface. "An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests," Fortinet said in an advisory published Thursday."
        https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/
        https://fortiguard.fortinet.com/psirt/FG-IR-26-175
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog
      • Apple CoreGraphics PoC Emerges As WhatsApp PDF Checks Hint At Possible Delivery Path
        "Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working exploit is separate work the analysis does not demonstrate. Apple patched the flaw on September 28, crediting Meta Product Security with the discovery and noting it may have been used in an "extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.""
        https://thehackernews.com/2026/10/apple-coregraphics-poc-emerges-as.html
        https://securityaffairs.com/200175/hacking/public-poc-released-for-apple-coregraphics-zero-day-cve-2026-86950.html

      Malware

      • AI Agents Targeted U.S. And Canadian Government Websites
        "Following up on our previous blog post, we discovered several additional incidents where rogue AI agents appear to have used aggressive techniques to access publicly available data on government websites. This includes two rudimentary and failed hacking attempts, one against the U.S. Department of Education’s Civil Rights Data Collection, and one against Library and Archives Canada, a Canadian federal agency. These failed attempts connect to additional rogue activity where agents used an array of aggressive tactics short of hacking to probe U.S. government websites, often using sites in unintended ways and sometimes violating explicit usage policies. This activity targeted websites across the White House, the Departments of War, Justice, and Commerce, the CDC and SEC, and state agencies in California, Maryland, Illinois, Texas, and New York."
        https://transluce.org/us-canada-gov
        https://www.bleepingcomputer.com/news/security/autonomous-ai-agents-tried-to-hack-us-canadian-government-websites/
      • Hallucinating Credibility: China-Aligned TA419 Impersonates Its Way Into US AI Policy Circles
        "In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US. The group first sent benign conversation starter emails, which included calls to action themed around AI policy such as joining an “AI Policy Advisory Committee”, to build rapport and solicit a response from the target. Once the target replied, TA419 followed up with a multi-stage URL redirection chain that led to an Adversary-in-the-Middle (AitM) credential phish that employed a customized version of the open-source Browser-in-the-Browser (BitB) phishing tool Frameless BitB."
        https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy
        https://therecord.media/china-linked-phishing-scheme-backdoor-taiwan
        https://cyberscoop.com/china-cyber-espionage-ta419-phishing-us-ai-policy-experts/
        https://www.infosecurity-magazine.com/news/ta419-impersonates-ai-experts-us/
      • Warlock Ransomware Attackers Hit Water And Telecom Operators
        "The China-nexus group behind Warlock ransomware is still breaking into organizations through Microsoft SharePoint vulnerabilities, a tactic that brought it to prominence a year ago. In the past two months, the group, which Symantec tracks as Longlegs (aka Storm-2603), attacked at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. The victims included two critical infrastructure operators, a water utility and a telecommunications provider, along with a regional government body and a university."
        https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure
        https://www.darkreading.com/cyberattacks-data-breaches/warlock-ransomware-spanish-portuguese
      • Milk Dragon: Huge Discounts On Social Media? Think Twice Before You Buy
        "Phishing doesn’t always arrive in your inbox. In previous Group-IB blogs (GTFire Phishing Scheme and Phoenix Rising), we covered attacks that start with a suspicious email or text message. But some lures are designed to find you where your guard is at its lowest: your social media feed. Picture this. You’re doomscrolling late at night when an advertisement catches your eye. A brand you know and trust, selling products you actually want, at a discount that seems too good to pass up. No urgent warnings, no “act now or else,” no red flags screaming for attention. Just a deal that seems to pop up organically. That’s exactly what makes it dangerous: these attacks strike when your brain is on autopilot."
        https://www.group-ib.com/blog/milk-dragon-nailong-phishing-kit/
      • CloudSyncD: a Two-Stage MacOS Backdoor That Hides a Phished Password In Zero-Width Unicode
        "While performing routine monitoring of executables in VirusTotal, Jamf Threat Labs identified a macOS dropper buried within a disguised Zoom client. We are tracking this malware under the name CloudSyncD, after the daemon name its second stage runs under. We first encountered CloudSyncD on September 15, 2026, in a build that was plainly still under development. After two days of monitoring, we identified samples of the same family configured against live infrastructure across more than one command-and-control domain, indicating the operators have moved from testing toward deployment."
        https://www.jamf.com/blog/cloudsyncd-macos-backdoor-fake-zoom-installer/
        https://www.infosecurity-magazine.com/news/cloudsyncd-macos-backdoor-fake/
      • MI5 Warns Over 100 Academics Helped China's Espionage Plans
        "The UK’s domestic security agency has warned that over 100 academics have helped Beijing’s spies to improve their espionage capabilities. MI5 issued the rare espionage alert on September 30, calling out the China General Technology Research Institute (CGTRI), or China Academy of General Technology (CAGT), for its connection to China's Ministry of State Security (MSS). Unusually for a security agency, the MSS handles both domestic/counterintelligence and foreign intelligence. It is thought to employ hundreds of thousands of workers, including many hackers that have been responsible for some of China’s most audacious campaigns, via ‘groups’ such as Silk Typhoon and Salt Typhoon."
        https://www.infosecurity-magazine.com/news/mi5-alerts-academics-chinese/
      • Fake xStocks, Pendle, And Other Sites Bait Crypto Users With Rewards Votes
        "We found 70 websites that impersonate legitimate crypto projects that invite visitors to vote on the date of an upcoming rewards distribution. The pages copy the look of the real sites closely, and on most of them the offer is small and believable: Cast a vote, and as an active voter you get a 1.25x boost when the rewards are paid out. However, the vote is fake and clicking the Vote now button opens a wallet connection prompt. It’s the first step toward requests that could trick visitors into authorizing access to their tokens."
        https://www.malwarebytes.com/blog/threat-intel/2026/10/fake-xstocks-pendle-and-other-sites-bait-crypto-users-with-rewards-votes
      • SC WordPress Malware: A Self-Healing Mesh Of Loaders, Drop-Ins, And a Blockchain-Controlled Backdoor
        "During recent website cleanup work, we analyzed a WordPress compromise where the same backdoor kept returning within seconds of every removal, no matter how carefully the visible files were deleted. Throughout this article, we’ll refer to this family of malware as SC, named after the “SC_” markers found in the injected content. What makes SC worth documenting is how it survives. The payload lives in at least eight places at once, spread across files, the database, and shared memory, and every one of those places can rebuild all the others. Delete the plugin and a drop-in rewrites it. Delete the drop-in and the theme rewrites it. Clean every file on disk, and the next page load restores the whole set from the database or from a shared-memory segment. The result is a circular system with no single point you can remove to stop it."
        https://blog.sucuri.net/2026/09/sc-wordpress-malware-a-self-healing-mesh-of-loaders-drop-ins-and-a-blockchain-controlled-backdoor.html
        https://thehackernews.com/2026/10/wordpress-backdoor-rebuilds-itself.html
      • Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts And Hunt Indicators
        "CVE-2026-88771 is a critical pre-authentication command-injection vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. Citrix and security researchers have already documented the vulnerability and its underlying exploitation mechanism. This analysis focuses instead on exploitation activity identified by LevelBlue's Threat Hunt Operations & Research (THOR) team while hunting across multiple customer environments."
        https://www.levelblue.com/blogs/spiderlabs-blog/citrix-netscaler-cve-2026-88771-observed-exploitation-artifacts-and-hunt-indicators
        https://thehackernews.com/2026/10/citrix-netscaler-post-exploitation.html
      • Rogue Agents Investigation: Initial Findings
        "Asymmetric Security investigated suspicious AI agent activity on the public internet from March 6, 2026 to September 20, 2026. Below we list organizations whose data was accessed by these agents. In the vast majority of cases, all data retrieved was and is public. We also list tools the agents used to access the internet, in a capacity which we suspect was outside their remit. A more detailed writeup is now available."
        https://www.asymmetricsecurity.com/newsroom/rogue-agents-investigation-initial-findings/
        https://www.asymmetricsecurity.com/newsroom/rogue-agents-investigation/
        https://therecord.media/openai-software-attempted-to-secretly-scrape-data-from-dozens-of-websites
      • TIKTOUK: Tracing a WordPress Credential Collection Toolkit
        "TIKTOUK brings together WordPress probing, collection of exposed configuration data, recovery of encrypted email credentials, and JavaScript secret scanning. Its two Python components and Go-based Linux crawler turn website responses into structured results for a central hub: an HTTP service that distributes target tasks and receives collected data and status reports. The key security issue is the combination of exposed configuration material and encrypted plugin settings: the collection component used the corresponding keys to recover plaintext email credentials."
        https://www.levelblue.com/blogs/spiderlabs-blog/tiktouk-tracing-a-wordpress-credential-collection-toolkit

      Breaches/Hacks/Leaks

      • Metamask Discloses Security Incident Affecting Its Infrastructure
        "On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. The company is working to address the issue internally, with help from external partners and security advisors, and says there is "no immediate threat to MetaMask wallets." "As a precautionary measure, we are proactively exiting affected validators within our non-custodial staking operations, in coordination with clients and partners," MetaMask noted. "As a reminder, our staking operations are non-custodial in nature and we do not manage withdrawal keys for stake on behalf of our clients.""
        https://www.bleepingcomputer.com/news/security/metamask-discloses-security-incident-affecting-its-infrastructure/
        https://thehackernews.com/2026/10/metamask-security-incident-prompts-exit.html
      • Cyberattack On Major Polish Invoicing Platform Exposes Customer Data
        "One of Poland’s major online invoicing platforms suffered a data breach that may have exposed information belonging to its users, their customers and business partners. Fakturownia said earlier this week that an unidentified attacker exploited a vulnerability in its systems and gained unauthorized access to servers. The company, whose service is used by more than 600,000 businesses, is still trying to determine how many customers were affected."
        https://therecord.media/poland-cyberattack-invoice-software

      General News

      • Teenager Suspected Of Leading KillSec Ransomware Group As Law Enforcement Seizes Servers And Leak Site
        "On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of stolen files unless they paid a ransom. The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1 000 suspected attacks worldwide. Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds."
        https://www.europol.europa.eu/media-press/newsroom/news/teenager-suspected-of-leading-killsec-ransomware-group-law-enforcement-seizes-servers-and-leak-site
        https://www.bleepingcomputer.com/news/security/police-dismantle-killsec-ransomware-gang-allegedly-led-by-16-year-old/
        https://www.darkreading.com/cyberattacks-data-breaches/killsec-ransomware-mastermind-16-year-old
        https://thehackernews.com/2026/10/police-arrest-16-year-old-suspected-of.html
        https://therecord.media/killsec-ransomware-raas-arrests-europe
        https://www.bankinfosecurity.com/spain-arrests-teen-suspected-running-killsec-ransomware-a-33002
        https://cyberscoop.com/killsec-ransomware-group-arrests-operation-killswitch/
        https://www.securityweek.com/police-shut-down-killsec-ransomware-identify-alleged-teen-leader/
        https://securityaffairs.com/200200/cyber-crime/operation-killswitch-police-dismantle-killsec-ransomware-group.html
        https://www.helpnetsecurity.com/2026/10/01/killsec-ransomware-16-year-old-main-operator-arrested/
      • The Fine Art Of Frustrating The Adversary
        "Years ago, Cisco Talos blocked an adversary’s command-and-control (C2) traffic. The adversary responded by tweeting, “Write a rule for your a**.” A fine endorsement of our work, if I’ve ever heard one. Talos loves to see an adversary forced to change course. And if every alternative for them is slower, less stealthy, less reliable and more expensive? Chef’s kiss. Adversaries rely on certain advantages. They look for environments where tools and infrastructure allow them to blend in with normal activity. They also look for employees who can be pressured into acting before they have time to think."
        https://blog.talosintelligence.com/the-fine-art-of-frustrating-the-adversary/
      • Many Expect AI In The SOC To Make Entry Jobs Harder To Get
        "A junior analyst in a security operations center, or SOC, has usually learned the job the slow way. You work the same phishing lure dozens of times, chase the same familiar malware pattern and write up the same case note at the end of the shift. Eventually you know what normal looks like, which is how you notice when something isn’t. AI tools handle a lot of that repetitive work, and the people doing the job are glad to see it go. Nearly nine in ten respondents in a Swimlane survey of 500 security operations staff, all at organizations already using AI, say it has made their work more satisfying. The catch is who is saying it. About a quarter of respondents say AI has held back their ability to build security skills. Those analysts are just as happy with their jobs as the ones who say AI helped them learn: 91% versus 92%."
        https://www.helpnetsecurity.com/2026/10/01/ai-soc-entry-jobs/
      • Employment Scam Victims Tripled At Financial Firms In 21 Countries
        "Reported victims of employment scams more than tripled over the past 12 months at more than 370 banks and other financial institutions in 21 countries. The 258% rise outran every other scam type, while total reported scams across the same institutions grew 35%. Researchers at BioCatch, a fraud-detection vendor, compiled the figures from reports filed by the institutions that use its software. The numbers matter for anyone running fraud controls because of where the scams happen. Nine of every 10 scam sessions now start on a mobile device. Traditional unauthorized fraud, where a criminal works the account without the owner’s help, comes from mobile in 75% of cases."
        https://www.helpnetsecurity.com/2026/10/01/employment-scam-victims-research/
      • AI Threats Top Cybersecurity Preparedness Gap, PwC Finds
        "Threats targeting AI systems is the area that cybersecurity leaders currently feel last able to address, with skills, accountability and data protection gaps also looming large, according to PwC. The consulting giant polled 3934 business and tech leaders across 71 countries for its 2027 Global Digital Trust Insights report, published on October 1. Over half (52%) said adversarial AI attacks represent the biggest cyber preparedness gap. The challenge of responding to these risks is compounded by governance issues."
        https://www.infosecurity-magazine.com/news/mitigating-adversarial-ai-top/
        https://www.securityweek.com/enterprises-struggle-to-prepare-for-ai-and-quantum-threats-pwc-says/
      • Shadow AI Explained: The Work Shortcut That Could Leak Your Company’s Secrets
        "Using an AI chatbot, assistant, or browser to speed up your work is tempting, but doing it without your employer’s knowledge can put sensitive data at risk. You’re swamped, so you paste a long email thread into a free chatbot and ask for a summary. It works, it saves an hour, and nobody notices. But the thread may contain customer details or confidential plans you’ve just shared with an outside service. If your employer hasn’t approved that tool or how you’re using it, that’s shadow AI."
        https://www.malwarebytes.com/blog/ai/2026/10/shadow-ai-explained-the-work-shortcut-that-could-leak-your-companys-secrets
      • Hacker Conversations: Rob Juncker, a Knock At The Door And a Moral Compass
        "Rob Juncker is chief product and technology officer at Mimecast. Is he a hacker? “Unequivocally yes,” he says. “And I think every security leader should be able to answer ‘yes’ to that question, for so many reasons.” He started early, when his parents brought home an Apple IIc. He was 10. They wanted to use it for word processing; but within two days of it arriving he had the lid off, trying to figure out how it worked. He had a driving curiosity to understand it. This curiosity, which he describes more as a thirst for knowledge, started before the arrival of the Apple – but with hands-on access, it rapidly focused on technology."
        https://www.securityweek.com/hacker-conversations-rob-juncker-a-knock-at-the-door-and-a-moral-compass/
      • AI Has Changed Attack Speed, Not Security Fundamentals
        "People who know me well know that I am a very direct person and as such, I don’t enjoy overcomplicating terms used to describe straightforward things. In recent months, Frontier AI and other tools have allowed attackers and defenders alike to shorten the time required to identify vulnerabilities and develop exploits for those vulnerabilities. With this has come an awful lot of hype and buzz around the topic of “virtual patching.”"
        https://www.securityweek.com/ai-has-changed-attack-speed-not-security-fundamentals/
      • Treasury Blacklists Most-Wanted ATM Malware Developer And His Network
        "The US Treasury Department has sanctioned the alleged developer of malware used in ATM jackpotting attacks linked to Tren de Aragua (TdA), along with members of his network and two Mexico-based companies. Anibal Alexander Canelon Aguirre, known as ‘Prometheus,’ was added in March to the FBI’s Ten Most Wanted Fugitives list, becoming the first person on the list wanted for cybercrimes. Treasury describes him as “the alleged engineer of the malware used in ATM jackpotting attacks.” TdA typically uses the malware named Ploutus. Canelon Aguirre’s network is based in Mexico and Venezuela but targets ATMs in the United States. The stolen cash is laundered, including through cryptocurrency, and moved to TdA members in various countries."
        https://www.securityweek.com/treasury-blacklists-most-wanted-atm-malware-developer-and-his-network/
      • Microsoft Says Threat Actors Are Ahead In The Early AI Race
        "Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. This comes from Microsoft's 2026 Digital Defense Report, which strongly focuses on how artificial intelligence is changing both offensive and defensive cybersecurity operations. Microsoft says AI is reducing the time, expertise, and cost required to discover and exploit weaknesses, while allowing attackers and defenders alike to operate with greater speed, scale, and autonomy."
        https://www.bleepingcomputer.com/news/security/microsoft-says-threat-actors-are-ahead-in-the-early-ai-race/
        https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/2026-Microsoft-Digital-Defense-Report.pdf
      • Federal PQC Orders Are Here: How To Prioritize Migration Before Q-Day
        "The United States is in a race to develop its quantum capabilities and to migrate critical systems to post-quantum cryptography before standard encryption practices become obsolete. That’s because AI is merging with quantum computing and rapidly accelerating the timeline to Q-day. Frontier models can allow technologists to identify more efficient ways to design, architect, and scale quantum computers. In fact, it is now estimated that previous timelines predicting Q-day’s arrival in 2031 are even further compressed."
        https://www.forescout.com/blog/federal-pqc-orders-are-here-how-to-prioritize-migration-before-q-day/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 42ee4b28-a045-4db4-bc3c-21ea7ed6e64b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 01 October 2026

      New Tooling

      • OWASP Noir: Open-Source Static Analysis Tool
        "OWASP Noir is an open-source static analysis tool that reads an application’s source code and lists the endpoints it exposes: paths, HTTP methods, parameters, headers, and cookies, each tied to the file and line it came from. Here’s where it gets useful. Shadow APIs, the endpoints that live in the code but never made it into any documentation, show up in Noir’s inventory right next to everything else, along with deprecated routes and undocumented handlers."
        https://www.helpnetsecurity.com/2026/09/30/owasp-noir-open-source-static-analysis-tool/
        https://github.com/owasp-noir/noir

      Vulnerabilities

      • Cisco Warns Of New SD-WAN Zero-Day Exploited In Attacks
        "Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. Formerly known as SD-WAN vManage, Catalyst SD-WAN Manager is network management software that lets admins monitor and manage up to 6,000 SD-WAN devices from a single dashboard. "In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," the company warned on Wednesday. "Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.""
        https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/
        https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
        https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html
      • TeamViewer Urges Users To Patch Severe Flaws “as Soon As Possible”
        "Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. The highest-severity flaw is a remote session access control bypass (CVE-2026-92370) stemming from an improper access control weakness in TeamViewer Full Client and Host software for Windows, Linux, and macOS that could let remote threat actors perform unauthorized actions leading to remote code execution on targeted systems."
        https://www.bleepingcomputer.com/news/security/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible/
      • WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
        "WatchGuard on Tuesday announced fixes for 15 vulnerabilities in Fireware OS, including a critical-severity remote code execution (RCE) bug. Tracked as CVE-2026-86131 (CVSS score of 9.2), the flaw is described as a code injection issue in how the operating system handles BOVPN over TLS client configurations. Successful exploitation could allow a remote attacker who controls the remote VPN server to execute commands with root privileges on the connecting Firebox appliance."
        https://www.securityweek.com/watchguard-patches-critical-fireware-os-code-injection-vulnerability/
        https://securityaffairs.com/200108/security/watchguard-fixes-critical-fireware-os-flaw-allowing-remote-code-execution.html
      • Chrome, Firefox Updates Patch Over 100 Vulnerabilities
        "Google and Mozilla on Tuesday announced fresh Chrome and Firefox updates that address over 100 vulnerabilities. The latest Chrome release was rolled out with fixes for 32 security defects, including a critical-severity buffer overflow issue in ANGLE tracked as CVE-2026-102331 and reported by an external researcher. Google addressed 25 high-severity security weaknesses, most of which are uninitialized resource and use-after-free vulnerabilities. It also resolved five high-severity type confusion flaws in the V8 JavaScript and WebAssembly engine."
        https://www.securityweek.com/chrome-firefox-updates-patch-over-100-vulnerabilities/
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-76504 Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog
      • OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
        "A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way through being sent. The flaw, tracked as CVE-2026-84782, is fixed in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8. Fixed versions for the older 3.0, 1.1.1 and 1.0.2 branches go only to customers who pay for OpenSSL's premium support. OpenSSL 3.0 stopped getting public security fixes on September 7."
        https://thehackernews.com/2026/09/openssl-fixes-high-severity-dtls-flaw.html
        https://www.securityweek.com/high-severity-vulnerabilities-patched-in-openssl-wolfssl/

      Malware

      • Beware Of Malware Infection In Facebook Ads Offering Cryptocurrency Rewards
        "Just because it’s a familiar tactic doesn’t mean you can let your guard down. A similar attack method using cryptocurrency rewards as bait has recently been identified again. This time, a case was confirmed in which the Node.Js-based malware JSCEAL was distributed through Facebook ads impersonating a cryptocurrency exchange. The threat actors lured users to a site designed to resemble a real exchange, then sent different installation files depending on the operating system to execute the malware. Over the past two months, JSCEAL infections have been confirmed on approximately 1,500 PCs in Korea, with both Windows and macOS systems included as Attack Targets. Let’s take a look at how JSCEAL deceives users, from the moment they click an ad to the malware code execution."
        https://asec.ahnlab.com/en/95645/
      • Beware Of SMS Messages Claiming To Protect Your Pi Coin Account—phishing Sites Are Stealing Wallets
        "One day, out of the blue, I received a text message claiming to protect my cryptocurrency account. However, this message concealed a sinister intent: to steal the user’s wallet information. Recently, a smishing campaign was identified that impersonated Pi Coin account protection to lure users to phishing pages and steal their cryptocurrency wallet information. The threat actors present a screen designed to look like the actual Pi Network service and trick users into directly entering the confidential information needed to recover their wallets. Since this tactic has been consistently observed in various regions—including the US, Europe, India, and Vietnam—users in Korea cannot afford to let their guard down. Let’s take a closer look at the Pi Coin smishing scheme hidden behind the phrase “account protection.”"
        https://asec.ahnlab.com/en/95646/
      • SilverFox: Tracking The Distribution Of a Domestic Variant Of a Malicious Installation File Posing As KakaoTalk
        "The threat actor used SEO poisoning (a technique that exploits search results to redirect users to fake sites) to distribute a malicious installer disguised as a KakaoTalk installer. The appearance and packaging method of the installer changed continuously, and the threat actor sequentially used NSIS, Advanced Installer, and Inno Setup. It contained both legitimate installation files and malicious files. When a user ran the disguised installation file, shellcode (code loaded into memory and executed) was triggered, and the malicious payload was executed."
        https://asec.ahnlab.com/en/95642/
      • China-Nexus UAT-11587 Targets Government And Policy Organizations Across Asia With Antino Backdoor
        "Talos first identified UAT-11587’s campaign while investigating a spear-phishing campaign directed at Taiwan's academic, think tank, and civil society policy community in March 2026. The message recreated Gmail's attachment interface and directed the target into a cloud-hosted, multi-stage infection chain. Across this activity, our researchers assessed that the actor used several delivery methods, loader families, and post-compromise tools. One recurring final-stage payload was a custom Rust backdoor that Talos tracks as Antino. Antino communicates with Microsoft 365 applications and uses Outlook and OneDrive objects as dead drops, rather than depending on a conspicuous dedicated command server."
        https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/
      • Disrupting a Coordinated Model-Distillation Campaign
        "We recently identified and disrupted a coordinated campaign designed to extract protected reasoning from our models, with the earliest observed activity occurring in the first week of July. This activity is consistent with adversarial distillation: the systematic and unauthorized use of one model’s outputs or reasoning to help train, reproduce, or improve another model. Protected reasoning is the model’s internal record for working through a task; extracting it can reveal information withheld from the final answer and help others reproduce the model’s capabilities."
        https://openai.com/index/disrupting-a-coordinated-model-distillation-campaign/
        https://cyberscoop.com/openai-moonshot-ai-model-distillation-attack/
      • 2CLoader: A New Malware Loader Delivering Vidar And Remus
        "In August 2026, Zscaler ThreatLabz identified a new loader, which we track as 2CLoader. ThreatLabz has observed the loader being used to distribute information stealers including Vidar and Remus in addition to XWorm RAT. 2CLoader has the ability to perform a wide range of anti-analysis and evasion techniques, including indirect system calls, anti-analysis checks, and installing Windows API hooks. In this blog post, ThreatLabz provides a technical deep dive into 2CLoader, covering its core features, evasion techniques, loader configuration, network communication, payload decryption, and execution options."
        https://www.zscaler.com/blogs/security-research/2cloader-new-malware-loader-delivering-vidar-and-remus
      • Unauthenticated Command Injection On Internet-Facing Mail Servers: Tracking CVE-2026-73570
        "Microsoft Threat Intelligence identified and tracked exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability in the Zimbra Collaboration Suite SNMP notification path. Exploitation can be triggered by a specially crafted email against internet-facing Zimbra servers when the optional zimbra-snmp package is installed and SNMP notifications are enabled, without requiring authentication or user interaction."
        https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/
        https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html
      • Phishing Abuses RMM Tools For Persistent Access
        "In July 2026, Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed a masqueraded MSP360 Remote Monitoring and Management (RMM) installer through meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected devices and enabled threat actors to gain an initial foothold using trusted administrative software."
        https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/
        https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html
      • US-Focused CSuite Phishing Steals Microsoft 365 Sessions And Deploys RMM Tools For Remote Access
        "ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud, and persistent access to business systems."
        https://thehackernews.com/2026/09/us-focused-csuite-phishing-steals.html
      • Mobile Malware Warning From Ukrainian Researchers Includes iPhone Exploit Kit
        "Russian hackers are increasingly targeting the smartphones of Ukrainian military personnel and government officials for espionage and financially motivated attacks, according to a Ukrainian government report published this week. The hackers are going after both Android and iOS devices using malicious apps and sophisticated exploits, according to Ukraine’s State Service of Special Communications and Information Protection (SSSCIP)."
        https://therecord.media/ukraine-ssscip-mobile-malware-warning-ios-android
      • MALFEX - A Malicious Npm Postinstall No Advisory Has Caught For Fourteen Months
        "Between August 2023 and September 2026, a single operator publishing under Portuguese-language accounts uploaded at least twelve packages to npm and one payload repository to GitHub. Five packages carry MAL- advisories, three are malicious but unadvised, and four are benign tools the operator ships as cover. The three packages without advisories are the only active threats defenders can target today: function-flag (continuously malicious since 18 July 2025), cdn-img-fetch (still installable after npm seized its parent package, img-to-native), and function-color (a wrapper that pulls function-flag in as a dependency)."
        https://www.cloudsek.com/blog/malfex-malicious-npm-postinstall-supply-chain-campaign
      • AI-Assisted Attacks Still Leave a Behavioral Trace
        "AI is increasingly being used to accelerate cyber-attacks, but attackers still leave detectable behavioral traces. This blog explores how Darktrace identified suspicious file delivery, command-and-control communications, beaconing activity, and other anomalies linked to AI-assisted campaigns through behavioral analysis."
        https://www.darktrace.com/blog/ai-assisted-attacks-still-leave-a-behavioral-trace
      • TerminalFix And Lorem Ipsum Loader Enable Covert Tunneling
        "In August 2026, Sophos analysts began investigating a series of Managed Detection and Response (MDR) cases that involved ClickFix-style lures and resulted in the deployment of a Python-based tunneling implant. Instead of a typical ClickFix lure that instructs victims to open the Run dialog box, these lures direct users to open a Windows Terminal window. This ClickFix variation is known as ‘TerminalFix’. TerminalFix is not linked to a specific threat group or a single campaign. In 2026, Sophos analysts have observed several malicious campaigns that incorporated these lures (see Figure 1) and resulted in multiple infection chains."
        https://www.sophos.com/en-us/blog/terminalfix-and-lorem-ipsum-loader-enable-covert-tunneling

      Breaches/Hacks/Leaks

      • DIVD Says Zammad Zero-Days Enabled AI-Driven Network Breach
        "The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. Previously, the nonprofit organization of volunteer security researchers said the attack was “loud and very, very messy,” driven by an AI agent that moved autonomously and decided its next steps without external intervention or direction. DIVD retrieved extensive details about the attack because the AI agent left behind clear explanations of its decisions, allowing the organization to reconstruct the incident."
        https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/
      • GitHub Repos Exposed 543,699 Credentials. Nobody Revoked Them.
        "We scanned 224 million public GitHub repositories, a snapshot of public code assembled to train AI models (The Stack v3), and found 543,699 unique credentials that still authenticated when we tested them in July 2026. The median one had been sitting in a public default branch for 784 days. The oldest was committed in 2009 and still works. Just under 200,000 of them were pushed after GitHub turned push protection on by default. The block does work where it applies, roughly halving the rate at which the credentials it recognises reach public code, but 51.8 percent of what is still live is a shape it does not recognise, and nothing about it helps the half million already there."
        https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them
        https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/
      • Bitget Hacked Via Zero-Day In Third-Party Security Products
        "Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. According to Bitget, two separate investigations by blockchain security firm SlowMist and Google Cloud's cyber-defense arm Mandiant said the threat actors accessed Bitget's wallet environment after compromising two security appliances with zero-day exploits."
        https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/
      • South Africa Seeks Help After Cyberattack Targets Air Traffic Control
        "The South African state-owned company that provides air traffic control (ATC) and weather operations for approximately 10% of the world's airspace discovered ransomware-linked malware in an operational technology (OT) network, according to public documents released this month. The company, Air Traffic and Navigation Services (ATNS), believes that its technical team stopped the attack, but it issued a request for quotes (RFQ) seeking cyber-forensics firms to investigate the incident. A second attack, possibly an insider's theft of data, is also part of the investigation request."
        https://www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control
      • PixelLeak: How AI Agents Exposed Developer Screenshots From Leading Tech Companies
        "Every day, developers hand the last mile of their work to an AI coding agent: summarize your changes, attach screenshots showing the changes, then submit them for review. It’s common sense that screenshots of internal, unreleased development work should not be posted where anyone can see them. But many AI agents have been doing just that. Glow Labs has identified over 13,000 internal images published openly on GitHub by developers at over 300 organizations, including one of the world's largest tech companies, a frontier AI lab, a major enterprise software provider, and a Fortune 500 travel company. In this post we share how AI agents quietly leaked thousands of pre-release screenshots, why no security team caught it, and how to check if you're affected."
        https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies
        https://thehackernews.com/2026/09/ai-coding-agents-exposed-13000-internal.html
        https://www.helpnetsecurity.com/2026/09/30/ai-coding-agents-github-screenshot-leak/
      • OpenInfra Europe’s JFrog Artifactory Instance Breached, Packages Potentially Compromised
        "Attackers have compromised a self-hosted JFrog Artifactory instance operated by OpenInfra Europe, the regional hub of the OpenInfra Foundation warned in a security notice prominently displayed on its homepage. “Anyone who downloaded or installed artifacts from https://artifactory.nordix.org/ from August 28 and September 15, 2026 should immediately stop using them, remove them from their pipelines, and treat these packages as potentially compromised,” the message says."
        https://www.helpnetsecurity.com/2026/09/30/openinfra-jfrog-artifactory-instance-compromised/

      General News

      • August 2026 Threat Trend Report On APT Attacks (South Korea)
        "AhnLab monitored APT (Advanced Persistent Threat) attacks targeting entities in Korea using its own infrastructure. This report summarizes the types and statistics on domestic APT attacks identified during the month of August 2026."
        https://asec.ahnlab.com/en/95649/
      • Vulnerability Discovery And Exploitation Trends In The AI Era
        "Google Threat Intelligence Group (GTIG) examines vulnerability disclosure and exploitation statistics to evaluate the impact of artificial intelligence (AI) on the vulnerability threat landscape. We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered."
        https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era
        https://therecord.media/google-vulnerabilities-cyberattacks-ai
        https://www.bankinfosecurity.com/google-ai-finding-more-medium-risk-flaws-a-32979
        https://www.infosecurity-magazine.com/news/ai-found-vulnerabilities-rce/
        https://www.securityweek.com/google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery/
      • EU Cyber Resilience Act Requirements For Containers And Kubernetes
        "Starting in full force on Dec. 10, 2024, the EU Cyber Resilience Act (CRA) is a regulation (EU 2024/2847) that defines mandatory cybersecurity requirements for all products with digital elements sold in EU markets. Reporting obligations will begin on Sept. 11, 2026, with full enforcement kicking in on Dec. 11, 2027. The CRA brings new requirements for teams working with containers and Kubernetes regarding how cloud native applications are built, distributed, and maintained throughout their lifecycle."
        https://www.helpnetsecurity.com/2026/09/30/rapidfort-cra-container-compliance/
      • Most Open Critical And High Flaws Are Over 90 Days Old
        "Detectify analyzed exposure data from 1,293 of its customers in the US, the UK and the Nordics and found that most serious flaws still open on their internet-facing systems are months old. Of the critical and high-severity vulnerabilities open at the time of the snapshot, 97% in the Nordics had been exposed for more than 90 days, along with 92% in the UK and 86% in the US. The organizations already know about these flaws. Detectify says it confirms findings with payload-based testing, which sends a working attack request and checks the response, so the backlog consists of issues its scanner judged exploitable. In the best-performing market, fewer than one in seven open critical or high findings is less than three months old."
        https://www.helpnetsecurity.com/2026/09/30/research-unpatched-vulnerabilities-backlog/
      • Most Organizations Need Six Months Or Longer To Roll Out New Security Controls
        "Cisco surveyed 8,000 security professionals in 30 markets about how well their organizations defend against AI-era threats, and only 8% landed in the top group. Cisco gave the most weight in its scoring to internal friction, meaning the delays and turf problems inside a company that slow a security team when something changes. Cisco says frontier AI models can find software vulnerabilities at a scale and speed no human team working alone can match. Fewer than one in ten respondents are confident they can stay ahead of the flood of new threats. Their answers put the slowdown inside the company: procurement delays, infrastructure decisions that IT owns, and priorities the C-suite sets elsewhere. Cisco says teams have the tools, and the drag comes from how the organization runs."
        https://www.helpnetsecurity.com/2026/09/30/relentless-defense-cisco-cybersecurity-survey/
      • Your Car’s App Could Be Telling Big Tech Who You Are And Where You Go
        "A study testing 21 cars from 19 brands and 30 companion apps found connections to advertising and tracking companies, and evidence that some apps shared sensitive personal data. Modern cars can unlock remotely, route around traffic, stream entertainment, summon roadside help, and cool or heat the cabin before you get in. But those conveniences come with a privacy cost that drivers may struggle to see and are unable to refuse. We’ve covered cars and privacy a few times before, especially after Mozilla researchers described cars as a “privacy nightmare.”"
        https://www.malwarebytes.com/blog/news/2026/09/your-cars-app-could-be-telling-big-tech-who-you-are-and-where-you-go
        https://therecord.media/automakers-routinely-share-connected-car-data-third-parties
      • Ransomware Leverage Is Growing By The Terabyte: Takeaways From ThreatLabz 2026 Ransomware Report
        "Ransomware is no longer defined only by how many organizations get hit. The most important shifts are happening beneath the headline victim counts; in how attackers gain access, who they target first, and how much data they steal once they’re in. The newly released Zscaler ThreatLabz 2026 Ransomware Report examines ransomware activity from April 2025 through March 2026, with a focus on groups and affiliates, victim targeting, attack techniques, data theft, and payment patterns."
        https://www.zscaler.com/blogs/security-research/ransomware-leverage-growing-terabyte-takeaways-threatlabz-2026-ransomware
      • EvilTokens Takedown Shows Why Cybercrime Platforms Are Getting Harder To Stop
        "Microsoft’s disruption of the EvilTokens phishing-as-a-service platform highlights a growing challenge for defenders: Cybercrime infrastructure may be getting easier to rebuild than it is to dismantle. AI-assisted development, inexpensive infrastructure, and increasingly decentralized services are enabling criminal groups to recover quickly when individual platforms are taken offline."
        https://blog.barracuda.com/2026/09/30/eviltokens-takedown-cybercrime-platforms-harder-to-stop
      • Know Your Enemy: Browser-Based Attack Techniques In 2026
        "Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most dangerous techniques that should be on every security team's radar in 2026."
        https://thehackernews.com/2026/09/know-your-enemy-browser-based-attack.html
      • More Than Half Of UK Businesses Lack Confidence In Basic Cyber Skills
        "More than half of UK businesses lack confidence in their ability to perform at least one basic cybersecurity task, according to the government's latest skills survey. The annual research found 57 percent of businesses reported a basic technical skills gap, up from 49 percent last year despite tighter national standards and repeated government warnings about cyber resilience."
        https://www.theregister.com/security/2026/09/30/more-than-half-of-uk-businesses-lack-confidence-in-basic-cyber-skills/5299991

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) c8bc407b-2488-4787-9004-7305c576d79b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบมัลแวร์ SC บน WordPress ฝังตัวหลายตำแหน่งและกู้คืน Backdoor หลังถูกลบ

      พบมัลแวร์ SC บน WordPress ฝังตัวหลายตำแหน่งและกู้.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5947d358-87db-4418-a7b8-7ca731b94b3e-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • WatchGuard ออกแพตช์แก้ช่องโหว่ Critical ใน Fireware OS เสี่ยงถูกสั่งดำเนินการคำสั่งด้วยสิทธิ์ Root

      WatchGuard ออกแพตช์แก้ช่องโหว่ Critical ใน Fireware OS เสี่ยงถ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 830a225e-91c0-4a41-943d-31d358dce779-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการใช้ช่องโหว่ Zimbra (CVE-2026-73570) เพื่อติดตั้ง Web Shell และขโมยข้อมูลสำคัญ

      พบการใช้ช่องโหว่ Zimbra (CVE-2026-73570) เพื่อติดตั้ง Web Shell.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5cac0302-7e71-4f28-a6c3-0cabc617d98f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ใน TeamViewer Full Client และ Host เสี่ยงถูกรันคำสั่งและยกระดับสิทธิ์

      ช่องโหว่ใน TeamViewer Full Client และ Host เสี่ยงถูกรันคำสั.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 47197471-7679-4a2b-9190-4d62859700b9-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ANSSI เผยเหตุขโมยข้อมูลภาษี ใช้ Password เจ้าหน้าที่ที่ถูกขโมย เข้าถึงข้อมูลนาน 7 สัปดาห์โดยไม่ถูกตรวจพบ

      ANSSI เผยเหตุขโมยข้อมูลภาษี ใช้ Password เจ้าหน้าที.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand f2cfffbc-dac2-44be-a1b4-2e89e31172b4-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • นักวิจัยพบ AI ที่ใช้สรุปอีเมล ถูกหลอกให้บิดเบือนข้อมูลได้ด้วยการแทรกข้อความปลอม

      นักวิจัยพบ AI ที่ใช้สรุปอีเมล ถูกหลอกให้บิด.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 631eb31b-81be-4f14-ab48-3a3b9cec77cf-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบช่องโหว่ CoreGraphics ในอุปกรณ์ Apple เสี่ยงถูกใช้รันคำสั่งบนอุปกรณ์

      พบช่องโหว่ CoreGraphics ในอุปกรณ์ Apple เสี่ยงถูกใช้ร.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 598eb855-8bcc-4a57-8eef-c170cdf84673-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Infostealer มุ่งเป้าบัญชี AI องค์กร เสี่ยงเปิดเผย Session, API Key และข้อมูลสำคัญ

      Infostealer มุ่งเป้าบัญชี AI องค์กร เสี่ยงเปิดเผย Sessi.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 3f2cb96a-1bc2-4a0d-ac00-f201ce6b3410-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 30 September 2026

      Industrial Sector

      • Toptech TMS7 And TopHAT
        "Successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02
      • VIVOTEK Camera Firmware
        "Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-03
      • Anjvision YSSD-RTMP-H5
        "Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05
      • MikroTik RouterOS
        "Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06
      • Viidure Dashcam Android Application
        "Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire platform."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07
      • Lantronix G520 Series Cellular Gateway
        "Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-01
      • Baicells Nova 430H
        "Successful exploitation of this vulnerability could allow an attacker to inject malformed messages which may lead to a denial-of-service condition."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-04

      New Tooling

      • OperTraitors: How Kubernetes Operators Betray Your Security Posture
        "Kubernetes operators are coded to drastically reduce operational toil by acting as automated site reliability engineers. However, their reliance on highly privileged service accounts introduces a severe, often overlooked security weak spot. To quantify and combat threats aiming to take advantage of this weak spot, we have released OperTraitor, an open-source, large language model (LLM)-powered analysis engine. OperTraitor ingests raw role-based access control (RBAC) configurations directly from locally installed operators and the OperatorHub catalog. Upon doing so, it calculates the difference between an operator's documented functionality and its actual granted privileges."
        https://unit42.paloaltonetworks.com/agentic-ai-kubernetes-operator-risks/
        https://github.com/paloaltonetworks/opertraitor

      Vulnerabilities

      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-86950 Apple Multiple Products Out-of-Bounds Write Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/29/cisa-adds-one-known-exploited-vulnerability-catalog
      • New Spectre v2 Attack Variant Leaks Linux Root Password Hash In Minutes
        "A new Spectre v2 attack variant called Branch Target Reuse (BTR) can recover root password hashes from Intel computers running Linux in just a few minutes. A BTR attack exploits stale information in a processor's branch predictor after a just-in-time (JIT) engine reuses memory for new code. By manipulating this leftover information, an attacker can trick the processor into temporarily executing the wrong instructions and potentially expose sensitive data."
        https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/
        https://www.vusec.net/projects/btr
        https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html
        https://www.securityweek.com/new-spectre-v2-variant-exposes-intel-amd-arm-cpus-to-data-leaks/
      • Kiteworks Patches Critical Flaw, Brings Customer Systems Online
        "American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. Formerly known as Accellion, it operates a Private Content Network (PCN) that integrates enterprise email, file sharing, Managed File Transfer (MFT), APIs, and web forms into a single platform. Kiteworks provides services to thousands of global corporations and government agencies, and its Private Data Network has over 100 million end-users."
        https://www.bleepingcomputer.com/news/security/kiteworks-lifts-shutdown-warning-after-patching-critical-flaw/
        https://www.kiteworks.com/company/press-releases/kiteworks-restores-systems-credible-threat/
        https://thehackernews.com/2026/09/kiteworks-fixes-critical-flaw-found.html
        https://cyberscoop.com/kiteworks-lifts-shutdown-advisory-after-credible-threat-intelligence-from-federal-authorities/
        https://www.infosecurity-magazine.com/news/kiteworks-customers-restart/
      • Look, Don't Load: Model Inspection In Unsloth Studio Leads To Critical Arbitrary Code Execution
        "What is Unsloth. Unsloth is one of the most popular open-source libraries for fine-tuning and quantizing LLMs, and it makes work that used to require deep systems knowledge accessible to a very large community. Studio is its browser-based front end, currently in beta. Enterprise relevance. Unsloth is part of established AI development workflows: Databricks includes the library in its AI v5 environment. Its role also extends to model distribution. Hugging Face ranks Unsloth as the third-largest source of model derivatives on the Hub, behind Qwen and Google, and a Forbes analysis highlights the need for enterprises to track the third-party artifacts they consume. These facts establish Unsloth’s relevance to enterprise AI teams, though they do not measure adoption of the affected Studio interface."
        https://www.pillar.security/blog/look-dont-load-model-inspection-in-unsloth-studio-leads-to-critical-arbitrary-code-execution
        https://www.darkreading.com/application-security/unsloth-studio-flaw-model-inspection-code-execution
      • Package Name To Role Credentials In Code Interpreter: Two RCE CVEs In The AgentCore Python SDK
        "One package name was all it took: the BeyondTrust Phantom Labs team turned a routine pip install into remote code execution inside an Amazon Bedrock AgentCore Code Interpreter sandbox twice, and, where the customer had configured the interpreter with an execution role, into that role's AWS credentials. This blog breaks down both CVEs in the AgentCore Python SDK and the proof-of-concept exploits behind them."
        https://www.beyondtrust.com/blog/entry/amazon-bedrock-agentcore-python-sdk-rce-cves
        https://www.infosecurity-magazine.com/news/aws-agentcore-sdk-flaws-ai/
      • Cycode Uncovers Account Takeover In MCP Python SDK
        "A malicious MCP server tricked the SDK into sending login credentials to the attacker instead of the real login provider. The Model Context Protocol (MCP) is an open standard introduced by Anthropic and donated to the Linux Foundation’s Agentic AI Foundation (AAF), which maintains it."
        https://cycode.com/blog/mcp-python-sdk-oauth-account-takeover/
        https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html
      • Self-Replicating Prompt Injections Exist
        "We show the existence of a new variety of prompt injection, which can self-propagate akin to a computer worm. No impact was observed outside of the simulated tool calls in training and evaluation; we are sharing this due to the novel nature of the prompt injection, not because of any incident."
        https://alignment.openai.com/misalignment-reports/self-replicating-prompt-injections-exist/
        https://www.theregister.com/security/2026/09/29/add-one-more-ai-worry-to-the-nightmare-scenario-self-replicating-prompt-injections/5299922

      Malware

      • Swarming Against Citrix 0-Day Exploitation
        "GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. GreyNoise also expands the GOG through Project Swarm, which enables the broader security community to join the effort. The activity discussed in this blog was derived from a Swarm participant sensor."
        https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation
        https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances
        https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/
        https://cyberscoop.com/citrix-netscaler-zero-day-attacks-three-weeks-undetected/
        https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867
        https://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/
      • Beware Of Phishing Emails Disguised As Quote Requests
        "Recently, the AhnLab SEcurity intelligence Center (ASEC) confirmed that phishing emails disguised as requests for project quotes are being circulated. The email body is disguised as a request to submit a quote for discussing the project budget and prompts recipients to download an attached compressed file for verification."
        https://asec.ahnlab.com/en/95599/
      • Beware Of Phishing Emails That Disguise Themselves As Project Material Purchase Requests
        "Recently, the AhnLab SEcurity intelligence Center (ASEC) identified a case of phishing emails that disguise themselves as project material purchase request forms. These emails impersonate employees of a specific company in Korea and trick recipients into opening a malicious XLS file attached to the email, which is disguised as a project material purchase request form."
        https://asec.ahnlab.com/en/95598/
      • Attackers Abuse ChatGPT Custom GPTs To Deliver RAT Via ClickFix
        "Attackers are abusing ChatGPT Custom GPTs to impersonate legitimate product offerings, then directing victims to a malicious "backup" site through a trusted ChatGPT-hosted interface. Huntress researchers found two Custom GPTs linked to the same campaign that were being used in this manner. The campaign uses a ClickFix lure to trick victims into running PowerShell, which downloads a malicious MSI and begins a multi-stage, obfuscated infection chain. The payload establishes resilient access through dual persistence and DLL sideloading, using a Canon-signed executable (and, in a later wave, a Stardock-signed one) to load malicious code. Huntress investigated at least 40 related incidents, including two confirmed Custom GPT-driven infections."
        https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat
        https://www.bleepingcomputer.com/news/security/custom-chatgpts-push-clickfix-attacks-to-deploy-rat-malware/
        https://www.securityweek.com/hackers-use-chatgpt-custom-gpts-in-clickfix-attacks/
        https://www.helpnetsecurity.com/2026/09/29/malicious-chatgpt-custom-gpt-malware-via-clickfix/
      • Star Blizzard Refines Phishing And Malware Delivery With The RedFlick Technique
        "Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique that Microsoft tracks as “RedFlick”. These changes represent a notable shift in the actor’s operational tradecraft and support ongoing cyberespionage activity targeting Ukrainian individuals and institutions as well as international non-government organizations (NGOs), Western think tanks, governments, and other organizations associated with international policy—particularly those with a nexus in supporting Ukraine."
        https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/
        https://cyberscoop.com/microsoft-star-blizzard-redflick-phishing-campaigns/
      • From BlackCat To Panda Workshop: Inside The Evolving C2 Panel Behind RATHat
        "RATHat is an Android banking trojan recently documented in public reporting, distinguished by an architecture in which the malicious application is only the entry point. Once granted the Accessibility Service, the application enables wireless debugging on its own, pairs with the device's ADB daemon to obtain a shell, and uses it to stage a native Go service and an FRP client that opens a reverse tunnel to the operator. The service runs outside the application's process and permission model, keeps its own channel to the C2, and survives the removal of the application until the next reboot. A shell that the malware grants itself, rather than a permission the user grants the application, is a model other families may adopt, and security controls should extend to this scope."
        https://www.cleafy.com/cleafy-labs/from-blackcat-to-panda-workshop-inside-the-evolving-c2-panel-behind-rathat
        https://www.infosecurity-magazine.com/news/rathat-c2-panel-malware-as-a/
      • Fake iPhone Duo Preorder Scam Triggers DarkSword Attack
        "Apple announced its first foldable iPhone on September 9, and scammers were ready to ‘deliver’ one before anyone could buy it. Most of what we found around the launch of the iPhone Duo and iPhone 18 Pro was familiar fraud. But one fake preorder page was different."
        https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-iphone-duo-preorder-scam-triggers-darksword-attack
      • From EDU Account Takeover To Job Scam Abuse: West African Fraud Actors Target Universities
        "Proofpoint is tracking a cluster of threat activity specifically targeting U.S. universities. The fraud ecosystem observed in campaigns aligns with known advance fee fraud (AFF) tactics. The campaigns begin with credential harvesting attempts that lead to job scam monetization leveraging AFF. University students, staff, and alumni are a perennial target for many different types of cybercrime, including job scams, fake scholarships, and account takeover (ATO) activities. Threat actors find higher education email accounts valuable for a variety of reasons including: younger students may have less experience with email correspondence and are new to engaging with potential work or money-making opportunities; alumni may still have active email accounts, but may not use them frequently, providing an opportunity for threat actors to hijack their contact lists; and staff and faculty are constantly receiving communications from students, parents, community members, etc. from a variety of personal and university emails."
        https://www.proofpoint.com/us/blog/threat-insight/edu-account-takeover-job-scam-abuse-west-african-fraud-actors-target
      • PhantomSub: Malicious Npm Campaign Secretly Adds Users To WhatsApp Spam Channels
        "The OX Research team identified 101 npm packages as part of a malicious WhatsApp group subscriber campaign. The malicious packages abuse the “Baileys” WhatsApp open source project to add the victims to groups without their consent. 16 of those packages were removed from npm as of September 28, 2026. Earlier reports of Baileys WhatsApp campaign were made by SafeDep, OSV and Xygeni back in August and September 2026. Baileys is an open source project containing an unofficial implementation of the WhatsApp API used by developers to automate actions through their WhatsApp accounts – such as customer support bots, chat managers or data scraping."
        https://www.ox.security/blog/phantomsub-malicious-npm-campaign-secretly-adds-users-to-whatsapp-spam-channels/
        https://thehackernews.com/2026/09/101-malicious-npm-packages-add.html
      • Operation Master: Deconstructing a Multi-Tiered Intrusion And Monetization Pipeline
        "SOCRadar Threat Research Unit (STRU) has uncovered an end-to-end cybercrime operation dubbed Operation Master, in which a threat actor compromised enterprise networks, stole customer and billing databases, offered portions of the data for sale on underground forums, and later repurposed those exact assets to power an automated, multi-tenant invoice fraud platform. Operating across multiple countries, the threat actor compromised critical network infrastructure, including VPN gateways via a GlobalProtect authentication bypass (CVE-2026-0257), while concurrently executing advanced web application exploits, deploying the AdaptixC2 framework, and leveraging an AI-assisted development workflow."
        https://socradar.io/blog/operation-master-intrusion-monetization-pipeline/

      Breaches/Hacks/Leaks

      • It Was a Matter Of When, Not If...
        "Security people always say it’s not a matter of if, but when you get hacked. It took us (almost) seven years but we can now say that we’re the hackers that got hacked. We noticed suspicious activity, investigated, and came to the inevitable conclusion that damn, we got hacked. So what do hackers do when they get hacked? Handle it the way we think it should be handled. That is open, transparent and honest, even if it sucks. So far, we’ve been in full incident response mode, blocked access to our infrastructure and started a forensics investigation with the assistance of a third party incident response team."
        https://www.divd.nl/newsroom/articles/when-no-if/
        https://www.bleepingcomputer.com/news/security/automated-ai-agent-used-to-breach-cybersecurity-nonprofit-divd/
      • French Tax Data Theft Using Stolen Staff Passwords Went Undetected For Seven Weeks
        "An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a report (in French) published on Tuesday: it worked because of weak login protection, poorly separated networks and gaps in monitoring. The tax administration, known as the DGFIP, runs France's tax website, impots.gouv.fr. The data came from E-Contact, the tool taxpayers use to message the tax administration."
        https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html
      • Russian Pizza Chain With 1,500 Locations Confirms Cyberattack Following Hacker Claims
        "Hackers breached the systems of popular Russian fast-food chain Dodo Pizza and gained access to some customers’ personal information, the company said Monday. According to Dodo Pizza, the potentially compromised information included customers’ names, addresses, email addresses, phone numbers, dates of birth and order details. The company said it does not store customers’ payment information and that payment data was therefore not compromised. “The attackers’ access has been blocked, and an internal investigation is ongoing,” Dodo Pizza said, adding that it had notified Russian communications regulator Roskomnadzor about the incident."
        https://therecord.media/russian-pizza-chain-dodo-confirms-data-breach
      • Arizona Supreme Court Says Hackers Stole Residents’ Personal Data
        "The Arizona Supreme Court announced Friday that the state’s court system was attacked by hackers who stole the personal information of “many Arizonans.” Arizona Supreme Court Chief Justice Ann Scott Timmer said in a statement that the state court system was targeted by criminal hackers “or their bots.” “Court leaders believe the criminal hackers copied personally identifiable information about many Arizonans,” Timmer said. “The Supreme Court’s Administrative Office of the Courts is in the process of alerting as many people as possible whose information it believes the criminal hackers copied.”"
        https://therecord.media/arizona-supreme-court-says-hackers-stole-data
      • Pentagon Personnel Agency Data Breach Impacts 3 Million People
        "The US Defense Manpower Data Center (DMDC), which maintains personnel records for the Pentagon, has started notifying people that their personal information was exposed. According to the DMDC’s notice, unauthorized users had access to one of its file-sharing servers for roughly nine months. A copy of the notification letter, dated September 18 and shared online by a recipient, says the problem was discovered in mid-July."
        https://www.securityweek.com/pentagon-personnel-agency-data-breach-impacts-3-million-people/
        https://securityaffairs.com/200017/uncategorized/three-million-affected-in-pentagon-personnel-agency-data-breach.html

      General News

      • Former US Air Force Members Sent To Prison Over BEC Attacks
        "Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. According to court documents, 25-year-old Chijioke Timothy Odimegwu and 26-year-old Harafat Mogaji carried out these attacks while stationed at Dover Air Force Base in Delaware."
        https://www.bleepingcomputer.com/news/security/former-us-air-force-members-sent-to-prison-over-bec-attacks/
        https://therecord.media/us-air-force-members-given-6-year-sentence-cyber
      • Vietnamese Man Charged In $16 Million 'pig Butchering' Crypto Scam
        "A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. 37-year-old Trung Nguyen Van entered the United States through the San Ysidro, California / Mexico pedestrian border entry point on September 22 and was arrested before boarding a flight to Taiwan out of Los Angeles International Airport on September 24. One of Van's victims transferred about $16 million in cryptocurrency between June and August 2024 in transfers directly traceable to Van's cryptocurrency wallet, believing they were investing in a crypto investment platform called "Triangle.""
        https://www.bleepingcomputer.com/news/security/vietnamese-man-charged-in-16-million-pig-butchering-crypto-scam/
      • Pro-Russia Hacktivists Increase OT Intrusion Claims Across EU
        "Claims of cyberattacks against operational technology and industrial environments increased significantly in 2025 - particularly those involving pro-Russia hacktivist groups, the European Union Agency for Cybersecurity warned. ENISA released its annual Threat Landscape report last week, finding that ideology-driven malicious cyberattacks accounted for 57.3% of all incidents the agency recorded in 2025, followed by financially motivated activity at about 30%. In total, there were 4,709 hacktivist claims against European Union member states last year, 89.5% of which involved distributed denial-of-service attacks. The rest involved unauthorized access."
        https://www.bankinfosecurity.com/pro-russia-hacktivists-increase-ot-intrusion-claims-across-eu-a-32966
        https://www.enisa.europa.eu/sites/default/files/2026-09/ENISA Threat Landscape 2026_Final.pdf
      • OpenAI’s GPT-6 Astra Ran Supply Chain Attacks Despite Being Told Not To
        "OpenAI’s GPT-6 Astra carried out supply chain attacks on software outside the scope of a security test, according to the UK AI Security Institute (AISI). AISI tested the model before its public release. The tests ran inside a simulation, so no live systems were touched. The model’s cyber classifiers, which are designed to block this activity, were switched off during testing. “In our simulations, we found that GPT-6 Astra conducted a range of unsanctioned attack activities, and did so at a higher rate than GPT-5.6 Sol and GPT-5.5. Attack activities included GPT-6 Astra creating fake identities which it used to deceive developers, posting comments from fake accounts arguing against the results of accurate security reviews, and delivering malicious payloads to open-source codebases,” the UK government research organization wrote."
        https://www.helpnetsecurity.com/2026/09/29/openai-gpt-6-astra-supply-chain-attacks-test-simulations/
        https://www.aisi.gov.uk/blog/gpt-6-astra-performs-unsanctioned-supply-chain-attacks-in-simulations
        https://securityaffairs.com/199947/ai/gpt-6-astra-and-the-supply-chain-attack-it-wasnt-asked-to-launch.html
      • OpenAI Agents Go Rogue: When AI Agents Bypass Guardrails
        "Recently and rather quietly, there have been reports that describe an alarming case where thousands of AI agents used a dormant wiki as a coordination mechanism. On the surface, it’s a fascinating technical story. But for technology leaders, it serves as something more important: a case study or a cautionary tale of how autonomous systems behave when given marching orders, tools, and enough freedom to pursue and produce outcomes."
        https://blog.barracuda.com/2026/09/29/openai-agents-go-rogue-ai-agent-governance
      • Four Cyber Threats Harboring Big Plans For The Future
        "Not unlike the fictional Skynet sending increasingly sophisticated ‘Terminators’ as older versions of the monster failed to achieve their earthly missions, cyberattacks are growing more persistent and automated, further testing an organization’s security maturity. To stay in tune with future risks, it has become imperative to treat resilience as an operational objective in constant flux."
        Priority: 3 - Important
        Relevance: General
        https://www.securityweek.com/four-cyber-threats-harboring-big-plans-for-the-future/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 032a1bd9-803f-4861-9aca-1f06b4e89063-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 5 รายการลงในแคตตาล็อก

      เมื่อวันที่ 24-25 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 5 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability
      • CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability
      • CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability
      • CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
      • CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalog
      https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalog
      https://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ec918105-23fc-4085-ab86-750f02fa84ab-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 4 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 4 รายการ เมื่อวันที่ 24 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-267-01 Botslab G980H Dashcams
      • ICSA-26-267-02 Eufy Omni C20, Omni X10 Pro
      • ICSA-26-258-02 Wärtsilä FOS-Onboard (Update A)
      • ICSA-26-209-02 Siemens Mendix Runtime (Update A)

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 6bc07576-215d-45c1-a498-4cff5d651cc8-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 4 รายการลงในแคตตาล็อก

      เมื่อวันที่ 22 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 4 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability
      • CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability
      • CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
      • CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fcf6c52f-7679-4063-8e28-e01df193dbc0-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ เมื่อวันที่ 22 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-265-01 lwIP TCP/IP Stack MQTT Client Application
      • ICSA-26-265-02 lwIP (Lightweight IP)
      • ICSA-26-265-03 Siemens Siveillance Control
      • ICSA-26-265-04 Siemens SIPLUS and SIMATIC Products
      • ICSA-26-265-05 Siemens Desigo CC family
      • ICSA-26-265-06 Siemens Industrial Edge Management
      • ICSA-26-265-07 Siemens SIMOVE Fleetmanager and SIPLANT
      • ICSA-26-265-08 Siemens WTV676 and WTV776
      • ICSA-26-265-09 OpenPLC Runtime v3

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand d8295e0c-f186-4c5d-a589-bd1f6daea8e1-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 29 September 2026

      Financial Sector

      • Security Issues In The Korean & Global Financial Sector In August 2026
        "In Attack Stage 1, phishing was the highest at 2.1, Up from 1.8 The previous month. In Attack Stage 2, dropper/downloader was the highest at 1.1, Down from 3.2 The previous month. In Stage 3 of the attack, Infostealers were the most prevalent at 0.3, Down from 0.4 The previous month. WebShells, Backdoors, HackTools, Ransomware, and CoinMiners remained at low levels."
        https://asec.ahnlab.com/en/95589/

      Industrial Sector

      • One Packet Can Crash OT Servers In Industrial Sectors
        "A newly disclosed flaw in an open source database used in industrial and Internet of Things (IoT) environments could let unauthenticated attackers crash vulnerable servers with a single specially crafted network packet. The zero-day vulnerability, tracked as CVE-2026-42542 affects TDengine, a time-series database that organizations in sectors like manufacturing, energy, automotive, and IoT use to store and analyze large volumes of data collected over time. Examples of such data include readings from sensors and industrial equipment, as well as application- and infrastructure-related performance metrics."
        https://www.darkreading.com/ics-ot-security/one-packet-crash-servers-tdengine
      • Update
        CVE-2026-42542 affected TDengine v3.4.0.0 through v3.4.1.5 and was fixed in v3.4.1.6, released
        Official advisory: https://docs.tdengine.com/security-guide/security-advisories/
        Release notes: https://docs.tdengine.com/release-history/notes/3.4.1.6/

      New Tooling

      • Authorizer: Open-Source Authentication And Authorization For Your Apps
        "Authorizer is an open-source server for sign-in and access control in web and mobile apps. Teams run it on their own infrastructure and keep user accounts in a database they choose. Its maintainers have built a permissions engine and an interface for AI agents into the same Go program that logs users in, so a chatbot can ask whether a user may see a document before it fetches that document. This affects any team that connects an AI assistant to company files. A vector search, which is the lookup that finds text similar to a question, returns close matches without checking who asked. Authorizer gives the search a list of documents the user is allowed to see, and everything else is dropped before it is scored."
        https://www.helpnetsecurity.com/2026/09/28/authorizer-open-source-authentication-server/
        https://github.com/authorizerdev/authorizer

      Vulnerabilities

      • How I Could've Accessed 17 Trillion Microsoft Records
        "An estimated 17.3 trillion stored rows across a wide range of Microsoft datasets were reachable through a single internal analytics service, all because it never checked the signature on a login token. That flaw let me claim an administrator’s identity and submit unauthorized SQL queries without any real credentials. I used only table descriptions, metadata, and bounded sample rows to understand the potential scope."
        https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records
        https://www.helpnetsecurity.com/2026/09/28/microsoft-titan-jwt-signature-flaw/
      • “Drunk” AI Is Terrible At Keeping Secrets
        "AI models taught to write like drunk people became easier to jailbreak and more likely to leak secrets shared in confidence. That is the finding of UNSW Sydney researchers Anudeex Shetty, Aditya Joshi and Salil Kanhere, published in their paper “In Vino Veritas and Vulnerabilities.” “The key research question from the natural language processing (NLP) side for me was, how do we get LLMs drunk?” said Aditya Joshi, a senior lecturer at the UNSW School of Computer Science and Engineering. “And the cyber security question was, how do we measure their vulnerabilities once they are drunk?”"
        https://www.helpnetsecurity.com/2026/09/28/drunk-ai-models-jailbreak-research/
      • Apple Patches CoreGraphics Flaw Possibly Exploited In Targeted Attacks
        "Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the issue was addressed with improved bounds checking. It credited Meta Product Security with discovering and reporting the issue."
        https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html

      Malware

      • Vulnerability Attack Case: Installation Of a Web Shell And Execution Of a Scanner By Exploiting a Telerik UI Vulnerability
        "The AhnLab SEcurity intelligence Center (ASEC) has identified two vulnerability attack cases that exploited a remote code execution vulnerability (CVE-2019-18935) targeting unpatched Telerik UI for ASP.NET AJAX servers. In the first incident, after exploiting the vulnerability, the attacker executed a reverse shell, attempted to perform privilege escalation, and installed a web shell; in the second incident, the attacker ran a scanner tool to search for additional Attack Targets."
        https://asec.ahnlab.com/en/95561/
      • Storm-3168: Agentic-Driven Cloud Attacks Using Compromised Service Principals
        "Microsoft Security Research has identified malicious cloud activity associated with JADEPUFFER, a threat actor discovered by Sysdig in July 2026 and reported to be the first documented agentic ransomware operation. Our investigation found an extensive Azure-focused resource destruction activity using compromised service principals and cloud credential collection that could be used to facilitate future exfiltration."
        https://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/
        https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html
        https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/
        https://www.darkreading.com/cloud-security/jadepuffer-ai-actor-azure-tenant-destructive-cloud-attack
        https://securityaffairs.com/199905/cyber-crime/storm-3168-linked-to-jadepuffer-abused-stolen-azure-identities.html
      • Chrome Store Hosts 'Poper Blocker' Spyware Downloaded By Millions
        "Millions of people have downloaded infostealers disguised as legitimate ad-blocking browser extensions, in part because Google has provided them with seals of approval on the Chrome Web Store. That's the word from Bay Area Labs, which uncovered one such app, "Poper Blocker," lurking in the Chrome Web Store. Poper Blocker has every trapping of a legitimate, mainstream app: It sports a big, green "Featured" badge, and its developer has earned a trustworthy "Established Publisher" status with Google. It enjoys a 4.8 out of 5 star rating from more than 81,000 reviewers. It claims more than 2 million active users. In short, no user could spot anything untoward about this program were they to come across it while shopping for an ad blocker."
        https://www.darkreading.com/application-security/chrome-store-poper-blocker-spyware-downloaded-millions
      • NeedyMantis: Unpacking a Post-Compromise Malware Family Used In Targeted Operations
        "Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Based on observed activity, NeedyMantis is typically deployed after a threat actor has already established access to a target environment, indicating that the malware is used to maintain long-term access and support follow-on operations."
        https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/
        https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html
      • RatHat Android Malware Console Uses Gemini To Identify Higher-Value Victims
        "RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone, including text messages and passwords entered into fake login screens overlaid on banking apps. Its latest version asks Google's Gemini AI model to estimate each victim's bank balance from those messages and sorts the phones into high-value and mid-value groups."
        https://thehackernews.com/2026/09/rathat-android-malware-console-uses.html
      • The Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, And AI Environments
        "Identity has long been the primary attack surface of the cloud. Infostealer malware, distributed through an industrialized cybercrime economy, is a leading initial access vector for compromising enterprise cloud, code, and AI environments. By targeting unsecured endpoints of developers through social engineering and supply chain attacks, threat actors steal credentials, API keys, and active session tokens, thereby bypassing the stronger defenses protecting most cloud environments from more direct attacks. Stolen credentials are widely recognized as one of the most common initial infection vectors - Microsoft, Recorded Future, and Verizon’s DBIR all point to infostealers as a cause of major concern. These attacks begin with a simple malware infection on a personal device, and end with attackers gaining privileged access to your AWS, Azure, or GCP estate, and more recently to the code platforms used by your organization, such as GitHub or GitLab."
        https://www.wiz.io/blog/infostealer-incursion-cloud-ai-credentials
      • A Fake Security Locker, Delivered By Google Ads
        "Netskope Threat Labs has been tracking a cloud-hosted tech-support-scam (TSS) kit that hijacks a victim’s browser with a fake security alert and pressures them into calling a bogus support line, where the goal is to either extract payment for fake “support,” gain remote access, or collect personal and financial details. Victims arrive by clicking a Google ad and land on a loading spinner webpage then into what looks like an ordinary online store, with nothing that reads as malicious."
        https://www.netskope.com/blog/a-fake-security-locker-delivered-by-google-ads

      Breaches/Hacks/Leaks

      • Japan's Keio Confirms Ransomware Attack Disrupted Business Systems
        "Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. Following a system failure in the early hours of Saturday, the company confirmed the attack and shut down its network to prevent additional damage. The company said it is investigating the extent of the impact and whether the attackers accessed any customer or business partner information."
        https://www.bleepingcomputer.com/news/security/japans-keio-confirms-ransomware-attack-disrupted-business-systems/
      • Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
        "Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. The company announced the incident on September 25, saying that a third party had accessed its systems at the beginning of the month. Times Car took action to block the unauthorized access on September 26. At the time, the company said it was investigating whether the attackers accessed members' personal information, but confirmed the data theft in an update earlier today."
        https://www.bleepingcomputer.com/news/security/times-car-confirms-data-breach-affecting-66-million-user-accounts/
      • Everything Everywhere: Systemic Data Exposure In Supabase Apps
        "Since 2025, the database service Supabase has been known to leak data through a variety of configuration issues. Despite improvements to Supabase product security, those issues continue to exist; multiplied by Supabase’s growth as a favorite tool for Claude Code, there are now thousands of Supabase instances exposing personal information and other data. In the largest study of its kind, UpGuard Research shows how Supabase misconfigurations expose personal data for people all over the world."
        https://www.upguard.com/blog/everything-everywhere-systemic-data-exposure-in-supabase-apps
        https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/
      • FBI Job Portals Remain Offline After ShinyHunters Claims Breach Via PeopleSoft Zero-Day
        "The FBI’s online portals for job applicants (at apply.fbijobs.gov) and special agent applicants (at fbijobs.gov/special-agents) are still unavailable, following what appears to be successful compromises by the ShinyHunters cyber extortion group. Last week, the United States’ domestic intelligence and security service confirmed it was investigating ShinyHunters’ claim of having compromised personal information of FBI employees. ShinyHunters told The Register they leveraged a currently unspecified and unconfirmed Oracle PeopleSoft zero-day vulnerability to breach the portals."
        https://www.helpnetsecurity.com/2026/09/28/fbi-job-portals-offline-shinyhunters-breach/
        https://cyberscoop.com/fbi-data-breach-shinyhunters-agent-safety-risk/
        https://www.malwarebytes.com/blog/data-breaches/2026/09/fbi-agents-blood-tests-and-doctors-notes-surface-after-breach
      • Bitget Says Attacker Exploited Third-Party Security Product Flaw To Steal $388M
        "The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most customer funds in offline cold wallets and use hot and warm wallets to process withdrawals. Transfers from those wallets must still be approved before they are signed. The stolen funds came from part of Bitget's hot and warm wallets, and its cold wallets were not affected."
        https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html
        https://www.bleepingcomputer.com/news/security/bitget-resumes-bitcoin-withdrawals-after-3875-million-crypto-heist/
        https://www.infosecurity-magazine.com/news/bitget-restarts-withdrawals-387-5m/
      • Cyberattack On Polish Medical Software Provider Exposes Patient Data
        "Hackers stole personal data from a Polish healthcare software provider in the latest cyberattack to hit the country’s medical sector in recent months. Qbusoft, which develops the Medyc medical records and practice management platform, was breached after an attacker exploited an SQL injection vulnerability in August, according to a notification issued last week by one of the healthcare providers affected by the incident. SQL injection is a security flaw that allows hackers to trick a website into giving them access to information stored in its database."
        https://therecord.media/poland-cyberattack-medical-medyc
      • DC Health Agency Exposes 400,000 Beneficiary Records
        "The District of Columbia Department of Health Care Finance (DHCF) is notifying nearly 400,000 people that their personal information was potentially compromised in a data breach. According to the agency, the incident impacts Medicaid and the DC Healthcare Alliance beneficiaries who enrolled between 2023 and 2026. The data breach was not the result of hacking. Instead, DHCF discovered in July that two reports on its website contained hidden personal information accessible to unauthorized individuals."
        https://www.securityweek.com/dc-health-agency-exposes-400000-beneficiary-records/
        https://securityaffairs.com/199926/data-breach/nearly-400000-medicaid-beneficiaries-caught-in-medicaid-and-dc-healthcare-alliance-data-exposure.html

      General News

      • August 2026 Threat Trend Report On Ransomware
        "This report summarizes statistics on new ransomware samples, affected systems, and statistics on targeted businesses collected during the month of August 2026, as well as major Korean & Global ransomware issues. Statistics on targeted businesses were compiled based on the time when publicly available information from ransomware groups’ DLS (Dedicated Leak Sites, i.E., Ransomware PR sites or PR pages) was collected via the ATIP (AhnLab TIP, Threat Intelligence Platform) infrastructure."
        https://asec.ahnlab.com/en/95567/
      • Dutch Police Arrest ‘Reformed’ Hacker In Shiny Hunters Investigation
        "Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p."
        https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/
        https://databreaches.net/2026/09/28/still-on-probation-from-previous-arrest-for-hacking-and-extortion-dutch-national-is-arrested-again/
        https://www.bleepingcomputer.com/news/security/dutch-police-confirm-arrest-in-shinyhunters-hacking-investigation/
      • AI Agents Are Privileged Users; Who Is Auditing Their Access?
        "Enterprises spend heavily protecting the human perimeter. Security teams deploy phishing-resistant multifactor authentication (MFA), enforce rigid conditional access policies, and scrutinize every login from an unexpected IP address. Yet while we closely monitor the human employee, engineering teams are quietly granting broad production access to autonomous AI agents, which often operate as non-human identities (NHIs) backed by service accounts, API tokens, or delegated cloud permissions."
        https://www.darkreading.com/vulnerabilities-threats/ai-agents-are-privileged-users-who-is-auditing-their-access
      • If You Do One Security Check This Quarter, Make It Agent Memory
        "In this interview with Help Net Security, Chris Latimer, CEO of Vectorize, talks about the security risks hiding in AI agent memory. He found coding agents storing API keys, credentials, and sensitive documents in plain text on developer machines and in cloud services. Latimer explains how attackers could plant poisoned memories through plugins, skills, and MCP integrations, often aimed at new coders who trust too easily. He covers why access control for agent memory lags behind other areas, what to track after an incident, and the one audit he thinks every CISO should run this quarter."
        https://www.helpnetsecurity.com/2026/09/28/chris-latimer-vectorize-agent-memory-security/
      • AI Tests The Limits Of Enterprise Security Governance
        "AI agents are forcing enterprises to rethink security governance, human accountability and oversight as deployments scale. AWS’s Reimagine 2026 argues that organizations need to build governance into their systems and keep humans accountable for outcomes. The findings come from confidential interviews of 45 to 60 minutes with 154 executives at 128 organizations in 23 industries, conducted over nine months. A number of the organizations interviewed still apply review processes designed for six-month IT programs to work that takes days. If a two-week experiment waits a month for approval, some teams stop asking for permission. Policy in that situation is “pushing it underground,” the authors write."
        https://www.helpnetsecurity.com/2026/09/28/ai-agent-security-governance-aws-report/
      • Quantum Random Numbers Can Pass The Tests And Still Leak Clues To Attackers
        "The European Telecommunications Standards Institute’s (ETSI) technical report, ETSI TR 104 171, offers guidance on building and evaluating quantum random number generators (QRNGs). It focuses on weaknesses in the devices and their supporting systems that could make the numbers they produce less secure. A QRNG measures a quantum process and turns the raw results into usable random numbers. Cryptographic systems rely on unpredictable numbers to generate keys and perform other security functions. If an attacker can predict those numbers, the protection those systems provide may be weakened."
        https://www.helpnetsecurity.com/2026/09/28/quantum-random-number-generator-qrng-guidance/
      • Deepfakes Are Becoming a Costly Reality For Businesses, Report Warns
        "Three quarters of cybersecurity leaders say their organization has faced a suspected deepfake incident during the last year and a quarter of those hit by one say it cost the business over $1m in total, a new report has warned. The 2026 Pindrop Deepfake Readiness Index, published on 28 September, warned there is a significant gap between the threat of deepfake attacks and enterprise readiness to defend against them. Deepfakes are AI generated audio and videos of people. The technology has become increasingly sophisticated, making it difficult for anyone watching or listening to the deepfake to tell that it isn’t footage of a real person."
        https://www.infosecurity-magazine.com/news/deepfakes-costly-reality-for/
      • MCP Is Creating Major Governance Gaps, Researchers Warn
        "Model Context Protocol (MCP) servers are creating a silent enterprise governance gap which threatens to undermine cybersecurity efforts as AI deployments proliferate, according to new research from Ox Security. MCP connects AI applications to external tools and data in a standardized manner, so that developers don’t have to write custom code each time they want to connect AI to an API or database."
        https://www.infosecurity-magazine.com/news/mcp-creating-major-governance-gaps/
      • AI Accounts Are Becoming The New Target For Infostealers
        "SOCRadar analyzed stealer log data from the last 90 days and found 482 companies with exposed AI accounts and credentials. Of those, 295 appeared in active logs during that period, suggesting the exposure is recent rather than the result of historical cleanup. Together, these companies account for 5,434 stealer log records linked to 1,500 distinct corporate email addresses. The number that really stands out is the ChatGPT figure. A captured ChatGPT or OpenAI session appeared at 358 of the 482 companies, accounting for roughly 90% of all records in the study. Other platforms, including Zapier, Notion, Hugging Face, Replit, Lovable and ElevenLabs, were far behind."
        https://securityaffairs.com/199933/ai/ai-accounts-are-becoming-the-new-target-for-infostealers.html
        https://socradar.io/resources/report/ai-identity-exposure-report-2026.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) e6cb8319-d61a-4b1c-bbae-4272190ddf47-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT