NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,577
    • กระทู้ 2,578
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • Cyber Threat Intelligence 15 September 2026

      New Tooling

      • Permify: Open-Source Authorization As a Service
        "Permify is an open-source authorization service that answers access questions at run time: can user X view document Y, which posts can members of team Y edit. It keeps those rules in one place, apart from the application code that would otherwise carry them. Permify follows the design of Google Zanzibar, the authorization system Google runs across its own products. Teams reach for something like it when permissions get specific and start nesting inside each other, and when the same rules have to hold across several applications at once."
        https://www.helpnetsecurity.com/2026/09/14/permify-open-source-authorization-as-a-service/
        https://github.com/Permify/permify

      Vulnerabilities

      • ConnectWise Patches ScreenConnect Vulnerability Exploited In Worm-Like Attacks
        "ConnectWise has released urgent patches for a critical-severity vulnerability in the ScreenConnect remote access and support software that has been exploited in worm-like attacks. Tracked as CVE-2026-84869 (CVSS score of 9.9/10), the security defect is described as a missing authorization and improper privilege management issue. The bug creates “a condition in the ScreenConnect client that may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances,” ConnectWise explains in its advisory."
        https://www.securityweek.com/connectwise-patches-screenconnect-vulnerability-exploited-in-worm-like-attacks/
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/14/cisa-adds-one-known-exploited-vulnerability-catalog
      • New DDRop Attack Breaks Intel TDX And AMD SEV-SNP Confidential Computing
        "Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it were current. The attack requires an attacker who already controls the server's software and can briefly access the machine to insert a small circuit board, called an interposer, between the processor and a memory module."
        https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html
        https://ddropattack.eu/
        https://www.theregister.com/security/2026/09/14/new-hardware-device-can-ram-into-encrypted-memory-expose-your-data/5296377

      Malware

      • Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens To Russian Bot Service
        "Socket’s Threat Research Team identified a cross-store browser extension, “Twitch Enhanced Viewer | JeetBot,” that forwards each user’s live Twitch OAuth session token to proxy servers operated by a Russian commercial bot service. The extension ships on both the Chrome Web Store (extension ID pnhhdhhcadcjfckjhpmjneldiegbojfb, 30,000 users) and Firefox Add-ons (twitchenhancedviewer@example[.]com, 552 users). Both listings are live at time of writing."
        https://socket.dev/blog/malicious-twitch-browser-extension
        https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html
        https://www.bleepingcomputer.com/news/security/twitch-extension-with-30k-installs-exposes-users-oauth-tokens/
        https://www.infosecurity-magazine.com/news/malicious-twitch-extension-oauth/
      • HBO Max Ads On a Compromised Reddit Account Exposed a Massive PasteSwitch ClickFix Operation
        "In September 2026, the cybersecurity community uncovered a massive, highly coordinated malvertising campaign leveraging the official, verified HBO Max Reddit account (u/hbomax). Over a frantic 48-hour period, the compromised account pushed 108 distinct “ClickFix” advertisements to users across the platform. Through joint research conducted by Hudson Rock and Kirk from ADAMnetworks (with additional thanks to Tuxxin from Whack.sh and Emiliano from The Matrix Project), we can confirm this incident is part of a massive, cross-platform delivery operation we are dubbing PasteSwitch. This operation spans macOS stealers, Windows loaders, deceptive TLS tactics, and contract-controlled cryptocurrency clippers."
        https://www.hudsonrock.com/blog/hbo-max-ads-on-a-compromised-reddit-account-exposed-a-massive-pasteswitch-clickfix-operation
        https://adamnet.works/blog/hbo-max-ads-exposed-the-pasteswitch-clickfix-operation/
        https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/
        https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408
      • Cloud Takeover: Mass Scanning For Exposed Vite Endpoints (CVE-2026-39364)
        "August 2026 saw an escalation in automated reconnaissance targeting internet-exposed developer tooling. Honeynet sensors recorded a sustained scanning operation focused on pulling cloud credentials and infrastructure state files out of exposed Vite development servers. The campaign generated 807 session-grouped attacks, roughly 32,000 raw events over the monthly analysis window. The activity was anchored by probes matching CVE-2026-39364, a high-severity file-read vulnerability that entered the monthly top-CVE tracking list, alongside recurring signatures for older Vite bypass flaws. Rather than target a single file, the scanning fleet systematically cycled through extensive wordlists of environment files, AWS keys, Azure tokens, and Infrastructure-as-Code state files."
        https://www.f5.com/labs/articles/cloud-takeover-mass-scanning-for-exposed-vite-endpoints-cve-2026-39364
        https://www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/
      • Fake Voicemail Transcript Emails Target 7,800+ Organizations In Large-Scale Credential Phishing
        "Automated voicemail transcripts have become part of the daily rhythm of enterprise communication. They arrive with familiar subject lines, system-generated formatting, and little human context, exactly the qualities that make them easy to trust and easy to overlook. Attackers are now exploiting that familiarity, turning routine call-transcription notifications into a vehicle for credential phishing. Check Point researchers identified a large-scale phishing campaign that exploits this shift in enterprise behavior. The emails impersonate automated voicemail-transcript notifications and deliver malicious Scalable Vector Graphics (SVG) attachments that redirect users to credential-harvesting pages, converting a familiar collaboration workflow into a potential path for account takeover."
        https://blog.checkpoint.com/security/fake-voicemail-transcript-emails-target-7800-organizations-in-large-scale-credential-phishing/
      • “Eye” Spy: Cyclops Blink Returns With Extended Capabilities
        "In August 2026, Counter Threat Unit™ (CTU) researchers analyzed a malicious 64-bit Linux executable named timezone_check that was discovered on multiple compromised Cisco Firewall Management Center (FMC) devices. The sophisticated modular implant provides persistent remote access to a compromised Linux system. CTU™ analysis indicates that it is a variant of the Cyclops Blink malware previously analyzed by the UK National Cyber Security Centre (NCSC) in 2022 and is likely associated with the Russia-based IRON VIKING threat group (also known as Sandworm and Seashell Blizzard). Cisco published details about this campaign on September 9, prompting CTU researchers to publicly release their analysis."
        https://www.sophos.com/en-gb/blog/-eye-spy-cyclops-blink-returns-with-extended-capabilities
        https://www.darkreading.com/cyberattacks-data-breaches/sandworm-chains-cisco-vulnerabilities-cyclops-blink
      • Smish. Click. Drained: Inside The Smishing Triad's Phishing Cockpit
        "A widespread smishing campaign was identified in which victims received fraudulent SMS messages impersonating official entities and were instructed to click a link inside the SMS in order to “complete a verification“, “settle an outstanding fee”, or “re-confirm delivery details”. The link resolved through a short URL into a disposable apex domain hosting the phishing kit analysed in this writeup. The kit then walked the victim through a multi-stage credential capture funnel identity, card, OTP, sometimes a second bank, sometimes a wallet while a human operator on the back end watched the session in near-realtime and pushed control instructions as needed."
        https://www.group-ib.com/blog/smishing-triad-outsider-jwr/
      • Machine Speed, Hold The AI: Hand-Rolled Marimo CVE-2026-39987 Exploit
        "AI is lowering the barrier to entry for attackers; that much is settled. But what’s still up for debate is whether skilled threat actors can keep up with their LLM-driven competitors. Recently, the Sysdig Threat Research Team (TRT) watched a single threat actor go from an open WebSocket to a live SSH session on a bastion host in eight seconds. There was no agent in the loop, nor was there any sign of LLM-generated scripts or tooling. Instead, the operator used a Python toolkit they wrote and debugged by hand, in-session, over the preceding four hours."
        https://www.sysdig.com/blog/machine-speed-hold-the-ai-hand-rolled-marimo-cve-2026-39987-exploit
        https://www.infosecurity-magazine.com/news/human-attacker-machine-speed/
      • The Fake Worker Threat And The Rise Of Human Infiltration
        "The Democratic People’s Republic of Korea (DPRK), commonly known as North Korea, has thousands of highly skilled workers engaged in remote employment and related activities around the world. In most cases these workers have constructed false identities as individuals based in the United States (U.S.), Germany, Portugal, the United Kingdom (UK) and other Western countries. They often mask their locations through something like remote laptop farms and virtual private networks (VPNs). This is the ‘North Korea fake worker scam,’ also known as the ‘fake IT worker scam.’ It is believed to have cost victim organizations hundreds of millions of dollars since its emergence in 2017."
        https://blog.barracuda.com/2026/09/14/the-fake-worker-threat-and-the-rise-of-human-infiltration
      • Red Heron Exploits Gitea n-Day Flaw In Multinational Campaign, Exposing New Linux Rootkit
        "Acronis Threat Research Unit (TRU) uncovered a multinational campaign in which a Chinese-speaking threat actor, tracked as Red Heron, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, a self-hosted source-code management platform. The activity progressed from source-code theft to persistent access, credential collection, and lateral movement, including root-level access to a three-node Proxmox cluster. TRU traced a Linux implant to Red Heron’s exposed staging server, revealing the actor’s exploitation tools, reconnaissance databases, command history, stolen repositories, and malware. This provided rare visibility into the operation, from target selection and vulnerability weaponization to post-exploitation activity."
        https://www.acronis.com/en/tru/posts/red-heron-exploits-gitea-n-day-flaw-in-multinational-campaign-exposing-new-linux-rootkit/
        https://thehackernews.com/2026/09/red-heron-exploits-gitea-rce-to.html
      • Pro-Ukraine Hacking Cat Group Deploying New Malware Against Russian Targets
        "Researchers have uncovered new hacking tools used by the pro-Ukraine hacktivist group Hacking Cat, which has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets. The group often works alongside other Ukraine-linked hackers and uses a wide range of custom-built tools, making it “significantly more difficult” to attribute individual attacks to a specific threat actor, Russian cybersecurity firm Kaspersky said in a recent report."
        https://therecord.media/ukraine-malware-russia-ransomware
      • Hundreds Of Fake Government Websites Target Users In Central Asia
        "Cybercriminals have created hundreds of fake government and news websites to target people in Uzbekistan, Belarus and Tajikistan with bogus offers promising cash payments or passive income. Researchers at cybersecurity firm F6 identified more than 360 fraudulent domains tied to the campaign. The sites are designed to collect victims’ contact details, which scammers then use to target them through phone or email to steal money, personal information or gain access to their devices."
        https://therecord.media/hundreds-of-fake-gov-websites-central-asia-scam
      • One Host, Six Operations: How Two Open Directories Exposed a Multi-Target Campaign
        "Hunt.io Attack Capture™↗ (opens in a new tab) flagged two open directories at IP Address "69[.]48[.]228[.]86" on port 80 (August 14) and on port 9001 (August 24), ten days apart in August 2026. A full inventory of both directories reveals a single operator running six parallel operations such as fraud against roughly 2,500 self-hosted "New API" LLM-reseller gateways, LLM-assisted mapping of Vietnam's government and military hierarchy, password-spraying and reconnaissance against Pakistan's National Defence University and armed forces, SQL-injection probing of the Chinese social platform uu-chatroom.com, opportunistic census-style scanning of unrelated hosting-provider IP ranges, and one completed database breach of commercial targets in Mexico."
        https://www.infrahunter.com/research/two-open-directories-on-a-singapore-vps
      • The Ghost In The Chat: How a Bot That Isn't In Your Group Steals Messages From Telegram HTML Exports
        "A stored XSS in Telegram Desktop lets an attacker plant invisible JavaScript in an exportable chat through a bot's inline keyboard button. The payload can sit in message history for months and detonates when a participant opens an HTML export page containing that message. No second click, no warning: every message and metadata field rendered in that document can be shipped to the attacker's server, and the page itself can be rewritten. The bot never joins the target chat — one forwarded message can be enough."
        https://expatch.com/writeups/telegram-html-export-xss.html
        https://thehackernews.com/2026/09/telegram-desktop-flaw-lets-hidden.html

      Breaches/Hacks/Leaks

      • Japan's Digital Agency Says VPN Flaw Exposed 246,000 Personnel Records
        "Japan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. The agency says that the attacker gained initial access by exploiting a vulnerability in a VPN device used by the Government Solution Service (GSS). An investigation started on June 25, after the agency detected a large-scale file access from the account of a maintenance and operations staff member."
        https://www.bleepingcomputer.com/news/security/japans-digital-agency-says-vpn-flaw-exposed-246-000-personnel-records/
      • Telus Warns Customers Of Account Breaches
        "Telus, one of Canada’s largest telecom providers, is notifying some customers that their accounts have been breached and their personal information has been accessed. In data breach notifications sent to customers whose consumer telecom accounts were affected, Telus said the intrusions occurred between February 2025 and June 2026. According to the company, the attacker used compromised credentials to access Telus accounts and the information they store, including names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history."
        https://www.securityweek.com/telus-warns-customers-of-account-breaches/
      • Thai Broadband Provider Targeted Via FortiGate SSL-VPN And MeshCentral Persistence
        "Open directories are one of the most reliable windows into active threat actor operations. When an attacker misconfigures their staging server, everything they have been doing becomes accessible. Hunt.io's AttackCapture™ discovered an open directory hosted at 92[.]63[.]180[.]133:8888, a server on Bangmod Enterprise Co., Ltd. infrastructure in Thailand. The directory contained 298 files across 30 subdirectories totaling 19 MB, first captured on June 3, 2026, including exploitation scripts, privilege escalation tools, brute-force utilities, a live MeshCentral agent configuration, and a device inventory of already-compromised machines, all targeting 3BB (Triple T Broadband). Before going deeper, these are the findings that shaped the entire analysis."
        https://hunt.io/blog/thai-broadband-fortigate-sslvpn-meshcentral-intrusion
        https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html

      General News

      • Turn It Off And On Again, But For Critical Infrastructure
        "Researchers at KTH Royal Institute of Technology built a container replica of a segmented industrial network, attacked it repeatedly across 14 days of running time, and used the captured traffic to train a defense agent that decides on its own when to intervene. The agent sees six numbers per interval: packet counts crossing the network’s segments and moving to and from individual machines. From those counts it infers how far an intruder has progressed, and acts."
        https://www.helpnetsecurity.com/2026/09/14/ot-intrusion-response-agent/
        https://arxiv.org/pdf/2609.10298
      • Cybersecurity Attention Fades Within Months After a Breach
        "Cybersecurity attention often rises after an incident, then recedes as organizations return to their existing priorities and practices, according to a new ManageEngine survey of 700 IT and cybersecurity leaders in the US and Canada. All of them had already been through a breach or incident. Still, 91% said they trust their organization’s current cybersecurity posture. Only 8% said cybersecurity becomes a permanent priority once the incident is behind them. “The belief that breaches are inevitable has lowered the bar for security,” said Dr. Erik Huffman, a cyberpsychology researcher who commented on the findings. “We’ve said ‘it’s not a matter of if, but when’ for far too long. But we still have control over the security processes that directly influence the outcome.”"
        https://www.helpnetsecurity.com/2026/09/14/manageengine-cybersecurity-breach-confidence-report/
      • Certificate Failures Can Cost Firms Over $250,000
        "The move toward 47-day public TLS certificates by 2029 will increase the certificate management workload for enterprises, according to DigiCert’s Certificate Management Outlook. Organizations will need to renew certificates more than eight times as often as under the previous certificate lifecycle and conduct 40 times as many domain validations. Certificate failures can disrupt business operations. Some 34% of companies experienced a service outage caused by an expired certificate, while 40% reported downtime linked to certificate mismanagement."
        https://www.helpnetsecurity.com/2026/09/14/digicert-certificate-management-automation-report/
      • Google’s New Search Redirects Make Links Harder To Check Before You Click
        "Google is changing how some links in its search results work. Instead of linking directly to the destination, Google has started routing some search result links through opaque google.com/goto?url=... redirects. The url parameter does not show a readable version of the destination but uses a custom, Google-specific encoding."
        https://www.malwarebytes.com/blog/news/2026/09/googles-new-search-redirects-make-links-harder-to-check-before-you-click
      • Security Through Obscurity Is Dead, And AI Delivered The Fatal Blow
        "The term "security through obscurity" describes an old idea that networks and systems will remain secure so long as their architecture, along with any vulnerabilities or other weaknesses, remains secret or hidden. It was never a sound strategy for protecting sensitive assets and systems, but many organizations leaned on it due to lack of resources or complacency. Now it’s obsolete. Don’t believe us? Here’s proof."
        https://www.theregister.com/security/2026/09/13/security-through-obscurity-is-dead-and-ai-delivered-the-fatal-blow/5296000
      • New Warnings About The Risks Of AI To Humanity Revive a Long-Running Debate
        "New warnings from within the artificial intelligence industry have revived a long-running debate over whether advanced AI could escape human control and ultimately threaten humanity’s survival, and whether the companies developing the technology are doing enough to prevent such a scenario. The CEO of Anthropic, the San Francisco company behind Claude, said he thought the industry needed to reduce the speed of its work, cautioning Saturday that a swarm of AI agents might be able to take over the internet in six months to a year unless companies devoted more time to putting safeguards in place."
        https://www.securityweek.com/new-warnings-about-the-risks-of-ai-to-humanity-revive-a-long-running-debate/
      • SecondSight Threat Hunting Report
        "Authored by the Trellix Advanced Research Center, this report (1) highlights threat hunting insights, intelligence, and guidance gleaned from multiple sources of critical data, including Trellix SecondSight, on the top five critical campaigns observed in the first half of 2026, and (2) develops expert, thorough case studies to inform and enable best practices in defending against these types of campaigns. This edition focuses on data and insights captured primarily between January 1, 2026, and June 30, 2026."
        https://www.trellix.com/advanced-research-center/threat-reports/secondsight-threat-hunting-report-september-2026/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 08fc5bc9-d01a-45e0-9a3e-e2f00007494b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการใช้ Google Play Early Access เผยแพร่ แอป Android หลอกลวง

      พบการใช้ Google Play Early Access เผยแพร่แอป Android หลอกลวง.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand b5bb997f-6e24-4592-b583-eecba9182c04-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • GitLab เตือนช่องโหว่ CVE-2026-85706 ระดับ Critical เสี่ยงถูกอ่านไฟล์สำคัญโดยไม่ต้องยืนยันตัวตน

      GitLab เตือนช่องโหว่ CVE-2026-85706 ระดับ Critical เสี่ยงถูกอ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand bad8182d-22e1-49a2-9e26-48a40c677300-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ศาลสหรัฐฯ พิพากษาจำคุก 4 ปี แฮกเกอร์ผู้อยู่เบื้องหลังกลุ่มมัลแวร์เรียกค่าไถ่ Conti

      ศาลสหรัฐฯ พิพากษาจำคุก 4 ปี แฮกเกอร์ผู้อยู่.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 562122c3-b435-498a-91b2-9e93ac7f2a25-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 14 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/14/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand bdd0e824-8245-4e14-b475-65f922e4992e-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบผู้โจมตีใช้ Claude วิเคราะห์แอป Android กว่า 1.8 ล้านไฟล์ เพื่อค้นหาข้อมูลรับรอง

      พบผู้โจมตีใช้ Claude วิเคราะห์แอป Android กว่า 1.8 ล้า.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand a8822dbb-66ce-42da-bc5a-57ea96a5aafc-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ใน Artifactory ถูกใช้โจมตีเพื่อยกระดับสิทธิ์และฝัง Backdoor บนเซิร์ฟเวอร์

      ช่องโหว่ใน Artifactory ถูกใช้โจมตีเพื่อยกระดับสิ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 64142ea1-62b3-4622-9b80-4f12e0153c0a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • แฮกเกอร์ใช้ช่องโหว่ในแอปพลิเคชันของ Tencent เพื่อแพร่กระจายมัลแวร์ GrayRabbit

      แฮกเกอร์ใช้ช่องโหว่ในแอปพลิเคชันของ Tencent เ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand f3258537-fc48-4126-823c-faa54adc52fc-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 4 รายการลงในแคตตาล็อก

      เมื่อวันที่ 11 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 4 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability
      • CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability
      • CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
      • CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog
      https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 3d00ca75-4ca9-4d75-957a-93ff351c0b28-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 14 September 2026

      Vulnerabilities

      • Artifactory Under Attack: In-The-Wild Exploitation Of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
        "Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities affecting JFrog Artifactory: CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329. Attackers are chaining these vulnerabilities to bypass authentication, escalate privileges, and gain administrative control over vulnerable Artifactory instances. Observed post-exploitation activity includes the creation of persistent administrator accounts, the deployment of malicious Groovy plugins for code execution, and the installation of Rust-based backdoors to establish persistence. This blogpost provides an analysis of the exploitation patterns observed, the impact on affected organizations, and actionable guidance for security teams to detect and remediate these threats."
        https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201
        https://www.bleepingcomputer.com/news/security/artifactory-flaws-chained-in-attacks-deploying-backdoor-malware/
        https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html
        https://www.theregister.com/security/2026/09/11/more-jfrog-artifactory-bugs-under-attack-and-all-3-have-patches/5295943
      • GitLab Urges Users To Patch Max Severity Path Traversal Flaw
        "GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. The security flaw, discovered by a security researcher using the 's3ntago' handle and reported via GitLab's HackerOne bug bounty program, stems from improper path confinement and missing authentication enforcement in the repository commits API. Unauthenticated attackers can exploit CVE-2026-85706 "under certain conditions" to read arbitrary data (e.g., credentials, secrets, and sensitive information) from vulnerable servers."
        https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/
        https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html
        https://cyberscoop.com/gitlab-critical-flaws-path-traversal-scans/
        https://www.securityweek.com/gitlab-vulnerability-exploited-one-day-after-disclosure/
        https://securityaffairs.com/198945/hacking/gitlab-cve-2026-85706-one-http-request-no-authentication-full-file-read-exploited-within-24-hours.html
      • PaperCut Replaces Emergency Patches With Fixes For Two Actively Exploited Flaws
        "PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases (MR) that have gone through complete QA testing," it said. "They contain all of the security fixes issued in Emergency Patch Releases 1, 2 and 3, plus additional security hardening, and they have been through our standard release testing process.""
        https://thehackernews.com/2026/09/papercut-replaces-emergency-patches.html
        https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
      • CISA Adds Three Known Exploited Vulnerabilities To Catalog
        "CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability
        CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability
        CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog
        https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog
      • GuardBreaker: Derailing AI-Assisted Malware Analysis With a Code Comment
        "Malware developers have long adapted their code and tactics to the defenses and scrutiny that are likely to stand in their way. Using various evasion and anti-analysis methods, they routinely attempt to hinder code analysis or prevent their malware from revealing its true behavior while under inspection. Other tools – notably, EDR killers, documented extensively by ESET researchers – go straight after security solutions themselves. As LLM-based tools increasingly assist with various security tasks, including code triage and analysis, it was only a matter of time before threat actors began to look for practical ways to subvert them, too. Alongside conventional evasion techniques, some are taking a different tack: the adversarial input that’s intended to frustrate analysis is left in plain sight."
        https://www.welivesecurity.com/en/business-security/guardbreaker-derailing-ai-assisted-malware-analysis-code-comment/
        https://www.darkreading.com/cyber-risk/ai-governance-cannot-wait
      • Direct Send: How Attackers Weaponize Your Infrastructure Against You
        "An employee at your company receives an email from [email protected]. The domain matches. There is no warning banner. The message asks them to review a payment approval document. They click. That email was never sent by your HR team. An attacker sent it, and your own Microsoft email infrastructure delivered it, with no password and no credentials required."
        https://blog.knowbe4.com/direct-send-how-attackers-weaponize-your-infrastructure-against-you
        https://www.infosecurity-magazine.com/news/hackers-us-business-hours-m365/
      • The Exposed AI Supply Chain — Mysterium VPN Research
        "36,769 self-hosted AI endpoints across model servers, agent builders, and vector stores are reachable and identify themselves in a single scanning index. Only 2.02% return an HTTP authentication challenge; for the overwhelming majority, there’s no network-layer gate whatsoever. Open WebUI: 18,529 reachable, 1 behind a gate: The most widely deployed local-LLM front-end has, as a population, no perimeter."
        https://www.mysteriumvpn.com/blog/data-and-research/we-exposed-ai-supply-chain
        https://securityaffairs.com/198898/ai/the-ai-supply-chain-has-a-security-problem-and-much-of-it-is-sitting-on-the-open-internet.html

      Malware

      • Protecting Organizations From AI-Assisted Executive Impersonation And Invoice Fraud
        "Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive team members. While this technique is not new, the adoption of AI has enabled threat actors to improve their campaign templates and construct emails tailored to their recipients. Additionally, threat actors are incorporating multiple techniques within the same email to improve the overall narrative further."
        https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/
        https://www.darkreading.com/cyberattacks-data-breaches/1m-personalized-fraud-emails-3-days
        https://therecord.media/invoice-scam-emails-new-features-microsoft-researchers
        https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html
      • Gray Rabbits And The Tale Of a One-Click Backdoor
        "Gen Threat Labs discovered a critical remote code execution vulnerability (CVE-2026-51990) in Sogou Input Method, one of the most widely used Chinese-language input method editors with hundreds of millions of installations. The vulnerability chains three separate weaknesses into a single, one-click exploit: unvalidated command-line argument injection in the sgbiz: custom protocol handler, unrestricted URL navigation in a CEF-based webview, and a severely outdated, unsandboxed Chromium browser engine. We observed this vulnerability actively exploited in the wild by the UNC3569 threat group to deploy the GRAYRABBIT backdoor through a crafted link."
        https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou
        https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html
        https://www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware/
        MacSync: The Evasive MacOS Stealer Exploiting ClickFix Lures
        "MacSync Stealer is a family of macOS information stealers and remote-access stagers designed to evade detection and sold commercially under a malware-as-a-service (MaaS) model. In the attack chain, MacSync binaries are native stagers and multi-part exfiltration engines. Rather than standalone harvesters, the payloads are lightweight 64-bit Mach-O executables that detach silently from terminal sessions, load credential-dumping modules directly into memory, and reliably exfiltrate stolen credentials back to campaign infrastructure."
        https://www.seqrite.com/blog/macsync-the-evasive-macos-stealer-exploiting-clickfix-lures/
      • DarkTortilla Malware: How It Works And How To Test Your Defenses
        "DarkTortilla is a highly configurable .NET-based crypter and multi-stage loader active since at least August 2015. It targets Windows systems, spreading through logistics-themed phishing emails. Unlike typical loaders, DarkTortilla hides its encrypted configuration inside bitmap pixel data and can pull its core processor DLL from public paste sites. It runs payloads only inside injected legitimate processes, applies three interchangeable persistence mechanisms, and pairs a WatchDog executable with the loader so each restarts the other."
        https://www.picussecurity.com/resource/blog/darktortilla-malware-how-it-works-and-how-to-test-your-defenses
      • I Just Trusted The Security Certificate Prompt… Beware Of The LegionLoader Malware Being Distributed Via The ClickFix Method
        "The AhnLab SEcurity intelligence Center (ASEC) recently identified the LegionLoader malware, which is currently being distributed via the ClickFix method. There are two main distribution methods identified so far; both involve tricking users into visiting a malicious URL and then prompting them to directly execute malicious PowerShell commands through a fake Cloudflare CAPTCHA screen."
        https://asec.ahnlab.com/en/95374/
      • OpenAI Agents Linked To RubyGems Campaign That Gained RCE On RubyDoc Servers
        "The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the Ruby programming language with hundreds of junk gems, prompting the maintainers to suspend new user sign-ups for about four days."
        https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html
        https://www.rubyhack.ai/

      Breaches/Hacks/Leaks

      • Novo Nordisk Data Breach Tied To Stolen GitHub Access Tokens
        "Hardcoded credentials recovered from corporate cloud environments are giving hackers ongoing, easy access to experimental drug data, customer records and more. Cyber extortionist group FulcrumSec, which specializes in ransoming sensitive data, continues to employ this strategy, going so far as to dub it the "Hardcoded Horrorshow." The group's victims have included England's Manchester Airport Groups, London-based consultancy Arup Group and Singapore-based Global Schools Group, among others."
        https://www.bankinfosecurity.com/novo-nordisk-data-breach-tied-to-stolen-github-access-tokens-a-32802
      • UK Council Attack Linked To Mass Exploitation Of SonicWall Flaw
        "On July 17, 2026, the Borough Council of King’s Lynn and West Norfolk announced it had detected a cyberattack affecting council services. Hunt.io has since published a detailed technical analysis linking that incident, with moderate confidence, to a wider mass-exploitation campaign against SonicWall SMA1000 appliances using CVE-2026-15409, a maximum-severity SSRF flaw that received a CVSS score of 10.0."
        https://securityaffairs.com/198864/hacking/uk-council-attack-linked-to-mass-exploitation-of-sonicwall-flaw.html
      • Revolut Confirms Customer Data Breach Through Fake Government Requests
        "British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses, according to a notification emailed to affected customers and reviewed by TechCrunch. The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification."
        https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/
        https://securityaffairs.com/198922/data-breach/revolut-exposed-kyc-data-after-fraudulent-government-email-passed-security-checks.html

      General News

      • Why AI Is So Good At Scamming Humans
        "If there's one thing that AI models are remarkably good at, it's manipulation. That's according to security researcher Fred Heiding, who spoke with Dark Reading's senior news director, Rob Wright, at the Dark Reading News Desk at Black Hat USA 2026 last month. Heiding, executive director at Menlo Park Intelligence, and former US National Cyber Director Chris Inglis, spoke at the conference about their research on AI security."
        https://www.darkreading.com/cyber-risk/ai-scamming-humans
      • Phishing Research Challenges Conventional Security Awareness Testing
        "The message is simple: fine-tune future in-house phishing simulation tests through the findings and analysis of Pistachio’s research. Pistachio was founded in Oslo Norway in 2019, with additional offices in London and Valencia. It specializes in automated human risk management, employee security awareness training, and phishing simulations. Between 1 June, 2025 and 31 May, 2026, Pistachio sent 2.47 million simulated phishing attempts to more than 123,000 employees in more than 1,200 organizations. Its subsequent analysis looked at clicking, leaking, and reporting."
        https://www.securityweek.com/phishing-research-challenges-conventional-security-awareness-testing/
        https://hs-5440974.f.hubspotemail.net/hubfs/5440974/The-Phishing-Behaviour-Report-2026-Pistachio.pdf
        https://www.helpnetsecurity.com/2026/09/11/pistachio-employee-phishing-risk-report/
      • AI Is Changing What Salesforce Security Needs To Govern
        "Existing security and governance practices have largely focused on identities, permissions, access, configurations and controls. WithSecure’s Navigating Trust in the Modern Salesforce Ecosystem paper says Salesforce environments also require organizations to understand what information they rely on, how trust extends across connected systems, what actions are performed and what outcomes those actions produce."
        https://www.helpnetsecurity.com/2026/09/11/withsecure-salesforce-ai-trust-governance-paper/
      • Most Organizations Skip Permissions Reviews Before Deploying AI Tools
        "AI is being deployed faster than the data foundation beneath it is being checked, a new Syskit study has revealed. In its latest State of Microsoft 365 Governance Report, published on September 10, security governance firm Syskit has found that three-quarters (76%) of organizations in the UK and the US have deployed or piloted an enterprise AI tool such as Copilot on Microsoft 365 data. Despite this wide adoption, only 43% of respondents confirmed they had completed a thorough review of permissions and oversharing risk before deploying these tools. The rest admitted to only having run a partial review or none at all."
        https://www.infosecurity-magazine.com/news/organizations-skip-permissions-ai/
        https://www.syskit.com/ebooks/state-of-m365-governance-report-2026
      • Anthropic CEO Dario Amodei Says AI Industry Needs To Give Safety Measures Time To Catch Up
        "The CEO of Anthropic said Saturday the artificial-intelligence industry should slow its fast-moving development to give safety measures time to catch up. Without such a slowdown, Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet. The warning comes as worries about AI grow inside and outside the industry and reports continue to emerge about increasingly powerful systems that solve problems beyond human capacity but could also go rogue and carry out other, more harmful tasks. The worries have grown so loud that the CEO of OpenAI, the company behind ChatGPT, said in an interview with Fortune that his company would wait until next year to start selling its stock to investors on Wall Street as it focuses on safety."
        https://www.securityweek.com/anthropic-ceo-dario-amodei-says-ai-industry-needs-to-give-safety-measures-time-to-catch-up/
      • August 2026 Dark Web Breach Incident Trend Report
        "In August 2026, widespread instances of database leaks, the sale of internal data, and the trading of initial access privileges were observed on dark web and deep web forums. Due to the nature of the sources, it was difficult to fully verify the accuracy of some posts."
        https://asec.ahnlab.com/en/95385/
      • August 2026 Dark Web Threat Actor Trend Report
        "The August 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—active on the deep web and dark web. It is noted that the accuracy of some information could not be verified."
        https://asec.ahnlab.com/en/95390/
      • August 2026 Dark Web Issue Trend Report
        "The August 2026 Dark Web Issue Trend Report summarizes Major Issues that occurred on the deep web and dark web. The report notes that, due to the nature of its sources, it may contain some information whose accuracy cannot be fully verified."
        https://asec.ahnlab.com/en/95391/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) d168aa57-b314-4f37-8db1-a086fb31b6c9-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการใช้ช่องโหว่ Fortinet โจมตีอุปกรณ์เพื่อติดตั้งมัลแวร์ PivotC2

      พบการใช้ช่องโหว่ Fortinet โจมตีอุปกรณ์เพื่อติด.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand d8bc7771-2a8d-4a1e-9361-0d7defac3437-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Trezor เตือนลูกค้าระวัง Phishing หลังผู้ให้บริการ Email ภายนอกถูกเจาะระบบ

      Trezor เตือนลูกค้าระวัง Phishing หลังผู้ให้บริการ Email.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand d126ea42-1b7e-4012-b143-7bdaa7cd3ffe-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ในหูฟังไร้สาย Skullcandy Dime 3 เสี่ยงถูกแฮ็กผ่านบลูทูธและดักฟังเสียงโดยไม่ได้รับอนุญาต

      ช่องโหว่ในหูฟังไร้สาย Skullcandy Dime 3 เสี่ยงถูกแฮ็.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 11788b85-8eeb-4b74-8af3-ac776f095371-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 11 September 2026

      Healthcare Sector

      • NextGen Healthcare Mirth Connect
        "Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition."
        https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01
        https://www.bankinfosecurity.com/nextgen-mirth-connect-flaws-expose-downstream-system-logins-a-32789
      • Orthanc DICOM Server
        "Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition."
        https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-02

      Industrial Sector

      • AVEVA Pipeline Integrity Monitor
        "Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-253-01

      Vulnerabilities

      • Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
        "Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security Management Server, the console used to configure them. Check Point disclosed the flaws on September 9 in a notice to its customer community, and began delivering fixes the same day. The company says it found both itself and has no indication that either has been used in an attack."
        https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
        CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog
      • Off Guard: Breaking LiteLLM From Authentication Bypass To Cloud Compromise
        "Nearly 1 in 10 publicly accessible LiteLLM instances accept a default master key or require no authentication at all. We found this while scanning roughly 3,000 internet-facing deployments of the most popular open-source LLM gateway. The usual concern with that kind of exposure is LLMjacking -someone using the credentials to run API calls on your bill - however, we wanted to check whether an attacker could do worse than that: could they achieve code execution on the host? Furthermore, could they exploit this to compromise the wider environment? We decided to use Claude Code to work through LiteLLM's codebase, looking for features that accept user-controlled input and pass it to an execution context. We found multiple issues, as detailed below."
        https://www.wiz.io/blog/off-guard-breaking-litellm-from-authentication-bypass-to-cloud-compromise
        https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html

      Malware

      • Mantax Otax: Indonesian Mobile Ransomware With Spyware Integration
        "The zLabs research team has discovered a sophisticated and highly aggressive mobile malware strain linked to Indonesian threat actors, that marks a dangerous tactical evolution by seamlessly integrating comprehensive spyware capabilities with traditional ransomware functionality into a single attack vector. This hybrid threat systematically compromises user privacy through an intrusive suite of surveillance features, which includes recording device screens in real-time, extracting browser history, stealing lock screen PINs, harvesting contact lists, call logs, and SMS messages, exfiltrating local files, and capturing unauthorized photographs."
        https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration
        https://www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
        https://www.darkreading.com/mobile-security/indonesia-android-banking-app-cloning-campaign
        https://www.infosecurity-magazine.com/news/mantaxotax-android-malware/
      • CISA: WatchGuard RCE Flaw Now Exploited In Ransomware Attacks
        "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. This flaw is tracked as CVE-2025-14733 and stems from an out-of-bounds write allowing unauthenticated threat actors to execute malicious code remotely in low-complexity attacks. This vulnerability affects firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3."
        https://www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/
      • PuzzleMask: The Prompt Injection Hiding In Plain Sight
        "Most prompt injection detection is built to catch the obvious. Encoding anomalies, invisible unicode, emoji smuggling, the signatures a classifier can pattern match against. PuzzleMask, a newly disclosed technique, sidesteps all of it. It embeds a policy-violating payload inside fluent, properly punctuated prose, and gets that payload past an LLM-based gatekeeper without tripping any heuristics naively looking for obfuscation on the input side."
        https://blog.checkpoint.com/security/puzzlemask-the-prompt-injection-hiding-in-plain-sight/
        https://research.checkpoint.com/2026/puzzlemask-abusing-plain-prose-as-a-covert-ai-attack-vector/
      • False Allegations, Real Threats: Sexual Misconduct Claims Used As Phishing Lures
        "Threat actors are impersonating leaders of partner universities in emails alleging a sexual misconduct violation has occurred, using sensitive claims to trick victims into installing abused, technically legitimate Remote Access Tools (RATs) on their computers. The alleged misconduct case is entirely fabricated, serving as a façade for delivering malware."
        https://cofense.com/blog/false-allegations,-real-threats-sexual-misconduct-claims-used-as-phishing-lures
      • From Infostealer Log To Marketplace Listing: A Technical Walkthrough Of The Credential Theft Pipeline
        "Infostealer malware is behind a large share of today’s credential compromise — and it usually doesn’t start with a breach at all. When a security team hears “data breach,” the instinct is to look for the moment a database was exfiltrated or a network was penetrated. But more often, the real starting point is a single endpoint infection, often on a personal device, that has nothing to do with the organization’s perimeter. By the time stolen credentials show up in a breach notification or a dark web alert, they’ve already passed through several distinct, mechanical stages. Understanding that pipeline — rather than waiting for the final alert — is what separates reactive security teams from ones that catch exposure early."
        https://cyble.com/blog/infostealer-malware-credential-theft-pipeline/
      • Passkey-Themed Social Engineering Leads To Identity And Cloud Compromise
        "Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins were followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and email collection through REST APIs. Microsoft Security Research assesses that this sequence is consistent with automated collection from compromised cloud identities using proxy-associated infrastructure, the activity has been observed since May 2026."
        https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/
        https://www.darkreading.com/threat-intelligence/voice-callers-exploit-byod-microsoft-365-corporate-data
        https://www.helpnetsecurity.com/2026/09/10/microsoft-365-social-engineering-personal-phones/
      • Casbaneiro: A Banking Trojan With Distributed Data-Receiving Servers
        "In August 2026, FortiGuard Labs observed a Casbaneiro attack campaign targeting users in Latin America, using phishing emails and PDF files themed around fake invoices and legal notices as the initial stage. Casbaneiro exhibits characteristics common to other malware families targeting financial institutions and users in Latin America, including clipboard injection and the use of fake windows to facilitate fraudulent activities. However, our analysis of the recent attack revealed several distinctive network behaviors that differentiate this campaign from previously observed Casbaneiro behavior."
        https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers
      • Grand Theft Auto VI Hype Leads To Malware
        "Threat actors are taking advantage of overeager gamers searching for a leaked version of the upcoming Grand Theft Auto VI (GTA6), using fake game downloads as an initial access lure. Huntress has seen several examples of SEO poisoning designed to rank highly in searches for GTA6, as well as ISOs published on gaming forums, social media, and various torrenting sites. Huntress analyzed an ISO file masquerading as a leaked version of GTA6 found in a sandbox. The package includes a fake installer, several RATs, an infostealer, ransomware being used as a wiper, and a web browser. Based on the language in the initial prompts and eventual ransom note, the malware appears to be targeting Russian gamers."
        https://www.huntress.com/blog/fake-gta6-download-malware-analysis
        https://www.helpnetsecurity.com/2026/09/10/fake-gta-6-downloads-malware-ransomware/
      • SloppyRAT: A New Tool For Ransomware Attacks
        "In June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered through a multi-stage ClickFix infection chain. The malware supports a variety of features including a large number of built-in PowerShell-like commands, encrypted code blocks, EtherHiding for command-and-control (C2) resolution through the Polygon JSON-RPC protocol, and multiple anti-analysis techniques. Beyond SloppyRAT’s capabilities, the malware is notable because the codebase includes numerous software flaws, which suggest that it is still under development."
        https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks
      • Google Play's Early Access Program May Be Exploited By Potentially Deceptive Apps
        "An analysis of Google Play apps installed by Bitdefender users reveals thousands of Early Access applications that appear to include fake casino games and reward apps, as well as titles that may infringe on third-party trademarks and potentially misleading utilities. Many are aggressively promoted through TikTok, Facebook, and other social media platforms using misleading advertisements that include videos using AI-generated celebrity deepfakes. The result is an ecosystem in which consumers have almost no way to warn one another before installing questionable software."
        https://www.bitdefender.com/en-au/blog/hotforsecurity/google-play-early-access-exploit-deceptive-apps
        https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html
        https://www.securityweek.com/deceptive-android-apps-exploit-google-play-early-access-to-evade-reviews/
      • Trezor Warns Users Of Email Provider Breach, Phishing Attacks
        "Cryptocurrency hardware wallet maker Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. Affected customers received fake "critical security alert" emails from [email protected] claiming that a "hardware microcontroller vulnerability" in the STM32 microcontrollers used by Trezor cold storage wallets could expose their seeds to brute-force cracking. The company said that it's investigating the breach and that the domain has been taken down to stop the attacks."
        https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/
        https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders
        https://www.helpnetsecurity.com/2026/09/08/trezor-shipping-partner-breach-phishing-attacks/
      • The Machine With Many Faces: Post-Exploitation Identity Misuse In SPIFFE/SPIRE
        "This research demonstrates post-exploitation techniques that could allow an attacker with root access on a compromised Kubernetes node to misuse an open standard and reference implementation for machine identity known as SPIFFE/SPIRE to impersonate co-located workloads and harvest SPIFFE Verifiable Identity Documents (SVIDs). We show how the trust assumption at the core of every machine-identity system — that the node is trusted — collapses once an attacker obtains root on that node. Unit 42 has not observed this technique exploited in the wild."
        https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/
      • CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT
        "One of the most common entry points for attackers is the exploitation of public-facing edge devices (such as VPNs, routers, and firewalls). Over the years, FortiGate firewalls have remained a consistent target, as evidenced by the recent widespread FortiBleed campaign conducted jointly by the INC and Lynx ransomware groups. The SOCRadar Threat Research Unit (STRU) identified, with high confidence, exploitation of CVE-2025-25249, a heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager cw_acd daemon. Successful exploitation delivers PivotC2, a Node.js Remote Access Trojan (RAT) designed specifically as a FortiGate post-exploitation tool. PivotC2 supports features such as interactive shells, tunneling, network scanning, and configuration harvesting."
        https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/
        https://www.securityweek.com/fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks/
      • Shai-Hulud Rises From The Dead After 111 Days
        "Hello internet, Do you remember the Shai-Hulud attack that hit @AntV on May 19th, 2026? I know, it feels like a lifetime ago by now in the supply chain world. A compromised maintainer account pushed 639 malicious versions of @antv packages to npm in a single hour. We, along with most of the npm security community, tore that payload apart within hours. It was nothing novel, technique-wise. It was just another day of waking up and there being a supply chain attack. Business as usual."
        https://www.aikido.dev/blog/shai-hulud-npm-resurfaces

      Breaches/Hacks/Leaks

      • Surfshark VPN Says Hackers Breached Internal Testing, Proxy Servers
        "Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. The VPN service provider said the incident did not affect its customers and did not extend to other parts of its infrastructure, but it exposed service configurations and build-related credentials. “Due to a human error, an internal test server used by our engineering teams was misconfigured in a way that made it reachable from the internet,” Surfshark explained on its website."
        https://www.bleepingcomputer.com/news/security/surfshark-vpn-says-hackers-breached-internal-testing-proxy-servers/
      • An Alignment Assessment Of Recent Cybersecurity Incidents
        "We present an alignment assessment of four incidents in which Claude models gained unauthorized access to real third-party systems. We described three of these incidents on July 30; we identified these after a scan of roughly 141,000 transcripts in which we believed Claude could have obtained internet access during a cyber evaluation. Given the volume of transcripts and our desire to disclose incidents quickly, our scan relied on an agentic search. This missed a set of transcripts that also turned out to have internet access; we identified these in August while assembling transcripts to share with METR. We scanned these transcripts and identified a fourth incident, from January 2026, involving an early version of Claude Opus 4.6. We have notified all affected parties."
        https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents
        https://thehackernews.com/2026/09/anthropic-ai-models-breached-real.html
        https://www.infosecurity-magazine.com/news/anthropic-another-cybersecurity/
        https://www.theregister.com/ai-and-ml/2026/09/10/anthropic-reveals-fourth-likely-crime-committed-by-its-ai/5295412
        https://www.securityweek.com/widened-scan-turns-up-fourth-rogue-claude-cyber-incident/
        https://securityaffairs.com/198814/hacking/a-new-claude-s-sandbox-failure-shows-how-ai-can-rationalize-real-world-harm.html
      • IDScan Confirms Breach After Hackers Offer 153 Million Driver’s License Scans For Sale
        "Identity verification firm IDScan said hackers obtained customer data held in its cloud platform following recent reports connecting the company to a database breach exposing scans of some 153 million driver’s licenses. The company confirmed a hack in a notice published on its website on September 4 and said it became aware of the breach on or around September 1 — the same day a journalist reported the news based on dark web activity."
        https://therecord.media/idscan-data-breach-notice-drivers-licenses
        https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/
      • ShinyHunters Expose 6.4M In Attack On Medical Supplier McKesson
        "McKesson's cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first time. ShinyHunters initially claimed to have stolen 284 million documents from the medical and pharmaceutical supply company in August, although HIBP did not confirm that figure."
        https://www.theregister.com/security/2026/09/10/shinyhunters-expose-64m-in-attack-on-medical-supplier-mckesson/5295550

      General News

      • Ukrainian National Sentenced To Four Years In Prison For Wire Fraud Conspiracy In Connection With Conti Ransomware
        "Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspiracy to commit wire fraud in connection with a conspiracy to deploy Conti, a ransomware variant that infected the computers of more than 1,000 victims worldwide. According to court documents, Lytvynenko, formerly of Cork, Ireland, conspired with others to deploy Conti ransomware to extort victims and steal their data. From 2020 until 2022, Conti was used to attack computers and networks in 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico. The FBI estimates that, as of January 2022, there had been victim payouts associated with Conti ransomware exceeding $150,000,000."
        https://www.justice.gov/opa/pr/ukrainian-national-sentenced-four-years-prison-wire-fraud-conspiracy-connection-conti
        https://cyberscoop.com/conti-ransomware-developer-sentenced/
      • Detecting And Countering Misuse Of AI: September 2026
        "Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity. In this report, we share case studies from those operations and describe how malicious use of Claude has evolved since our previous threat reports in March, August, and November 2025. In each case, we disrupted the activity, used what we learned to strengthen our safeguards, and shared intelligence with authorities and industry partners, where appropriate."
        https://www.anthropic.com/threat-intelligence-report-september-2026
        https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf
        https://cyberscoop.com/anthropic-report-ai-enabled-cyber-attacks/
      • AI Adoption Brings New Security Headaches For Already Stretched CISOs
        "CISOs are taking on AI governance without a matching increase in resources or expertise, adding to an already broad remit spanning data protection, identity, resilience and compliance, according to Proofpoint’s 2026 Voice of the CISO report. GenAI is creating new concerns around sensitive data, access and employee activity. Seventy-eight percent of CISOs consider it a security risk, with the potential loss of customer data through public AI platforms a key concern."
        https://www.helpnetsecurity.com/2026/09/10/proofpoint-ciso-ai-security-risks-report/
      • CISA Updates Insider Threat Guide With New Mitigation Advice
        "The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Insider Threat Mitigation Guide with new case studies, statistics and guidance on hybrid and remote work, artificial intelligence and adverse employee separations. The agency published the revision on September 9. First issued in 2020, the guide supports security and human resources professionals who run insider threat programs, along with leaders at any level, and CISA said any organization can use it regardless of the maturity of its security."
        https://www.infosecurity-magazine.com/news/cisa-updates-insider-threat-guide/
      • More Capable AI, Not Enough Guardrails
        "Jacob Coxon, a researcher who spent three years working on model training at OpenAI and later Anthropic, left Anthropic this week with a blunt warning: AI companies are moving toward increasingly capable systems faster than they can build reliable safeguards around them. I resigned from Anthropic today. I spent the last three years doing pretraining research at both OpenAI and Anthropic. Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives. More thoughts below."
        https://securityaffairs.com/198833/ai/more-capable-ai-not-enough-guardrails.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 00cac1d3-ee2b-4f03-b209-cc9ded07c652-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 2 รายการลงในแคตตาล็อก

      เมื่อวันที่ 10 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 2 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
      • CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand dd97e004-14d0-4651-b264-9352948152c6-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 4 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 4 รายการ เมื่อวันที่ 10 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      ICSMA-26-253-01 NextGen Mirth Connect
      ICSMA-26-253-02 Orthanc DICOM Server
      ICSA-26-253-01 AVEVA Pipeline Integrity Monitor
      ICSA-26-183-01 ST Engineering iDirect iQ-Series Terminals (Update A)

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 79d6973d-9d0c-4173-85fe-31aec01f48ec-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 8 รายการลงในแคตตาล็อก

      เมื่อวันที่ 8-9 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 8 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
      • CVE-2026-81963 Microsoft Windows Link Following Vulnerability
      • CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability
      • CVE-2026-86218 N-able N-central Static Code Injection Vulnerability
      • CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
      • CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
      • CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability
      • CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog
      https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 501a514a-b633-4249-8113-0ea4d282fa64-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบเครือข่ายร้านค้าออนไลน์ปลอม DoppelCart ใช้กว่า 119,000 โดเมน หลอกขโมยข้อมูลบัตรชำระเงิน

      พบเครือข่ายร้านค้าออนไลน์ปลอม DoppelCart ใช้กว่า 119,000 โดเมน หลอกขโมยข้อมูลบัตรชำระเงิน.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand dd5e4a01-a3ac-4763-b1eb-d5be9a1ac387-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบ Plex Media Server กว่า 36,000 เครื่องเปิดสู่อินเทอร์เน็ต ยังไม่ได้แพตช์ช่องโหว่ล่าสุด

      พบ Plex Media Server กว่า 36,000 เครื่องเปิดสู่อินเทอร์เน.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 7b1ba684-04b8-4a37-84f0-1e4213bfe1c1-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบแคมเปญ Phishing อาศัยบริการของ Google สร้างลิงก์ส่งต่อหลายทอดเพื่อขโมยข้อมูลและควบคุมเครื่อง

      พบแคมเปญ Phishing อาศัยบริการของ Google สร้างลิงก์ส.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ec8cec7e-88dd-44ae-9b63-6f62af7aa697-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT