NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,585
    • กระทู้ 2,586
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • พบช่องโหว่ในปลั๊กอิน The Events Calendar บน Wordpress เสี่ยงถูกใช้รันคำสั่งและยึดเว็บไซต์

      พบช่องโหว่ในปลั๊กอิน The Events Calendar บน Wordpress เสี่ยงถ.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 0a415252-45f5-4378-a50f-68bd822d6397-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Google ออกแพตช์ Android Zero-Day บนอุปกรณ์ Pixel หลังพบการโจมตี

      Google ออกแพตช์ Android Zero-Day บนอุปกรณ์ Pixel หลังพบการโจม.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fee872ee-86c8-4a79-b9bc-ff47a38a6046-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบมัลแวร์ KREMLIN โจมตีผู้ใช้งานเบราว์เซอร์ Chrome และ Edge เพื่อขโมยข้อมูลบัญชีธนาคาร

      พบมัลแวร์ KREMLIN โจมตีผู้ใช้งานเบราว์เซอร์ Chrome .jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand b76daab4-3a46-460a-ac9e-61572ca2afdd-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 17 September 2026

      Industrial Sector

      • Digital Watchdog VMAX DVR And NVR Product Lineups
        "Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-01
      • MySCADA MyPRO Manager
        "Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-03
      • Siemens Reyrolle 7SR5
        "Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-05
      • Wärtsilä FOS-Onboard
        "Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-02
      • Siemens Mendix SAML
        "Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-06
      • Schneider Electric SCADAPack x70 Products
        "Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-04
      • Siemens Teamcenter
        "A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released new versions for the affected products and recommends to update to the latest versions."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-07
      • CareCam CM2507
        "Successful exploitation of these vulnerabilities could allow an attacker to access live video and sensitive device information, enable unauthorized services, execute arbitrary code, modify device operation, and recover stored credentials."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-08

      New Tooling

      • DeepZero: Open-Source Hunting For Vulnerable Windows Drivers
        "DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, scans them, throws most of them away, and asks a language model whether what survives can be attacked. Pipelines are written in YAML, the code is Python 3.11 and up. Rehman Ahmadzai, who maintains the project, said DeepZero has “found multiple verified vulnerabilities in a subset of the Snappy Driver Installer corpus, with some still undergoing the disclosure process.” The bundled pipeline targets BYOVD, short for bring your own vulnerable driver: an attacker loads a legitimately signed driver that contains a flaw and uses it to reach the kernel."
        https://www.helpnetsecurity.com/2026/09/16/vulnerable-windows-drivers-deepzero-open-source/
        https://github.com/416rehman/DeepZero

      Vulnerabilities

      • Oracle Patches 800+ Vulnerabilities In September 2026 Security Update
        "Oracle on Tuesday announced the release of 673 new security patches as part of its September 2026 Critical Security Patch Update (CSPU). The security updates appear to resolve more than 800 vulnerabilities: there are 672 unique CVEs in the 17 risk matrices included in the September 2026 CSPU advisory, but Oracle also notes that more than 130 additional CVEs have been resolved with the patches for other flaws. More than 100 of the newly addressed security defects are critical-severity flaws, and over 240 are remotely exploitable without authentication."
        https://www.securityweek.com/oracle-patches-800-vulnerabilities-in-september-2026-security-update/
      • Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading To Remote Code Execution In The Events Calendar Plugin
        "On August 21 and August 22, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability chains in The Events Calendar, a WordPress plugin active on more than 600,000 websites. Both chains begin in the plugin’s widget-rendering pipeline and can ultimately lead to Remote Code Execution without authentication through two separate methods. The first chain uses PHP Object Injection to execute arbitrary operating system commands on the underlying server. The second chain bypasses the object-injection guard and abuses an arbitrary-callable primitive to reset an administrator’s password, after which an attacker can upload a malicious plugin and take complete control of the site."
        https://www.wordfence.com/blog/2026/09/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin/
        https://www.securityweek.com/unauthenticated-rce-flaws-could-expose-200000-wordpress-sites-to-takeover/
        https://hackread.com/critical-calendar-wordpress-plugin-flaws-site-takeover/
      • Google Fixes Actively Exploited Android Zero-Day On Pixel Devices
        "Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. "There are indications that CVE-2026-58704 may be under limited, targeted exploitation," the company warned on Wednesday. "All supported Google devices will receive an update to the 2026-09-05 patch level. We encourage all customers to accept these updates to their devices.""
        https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-zero-day-on-pixel-devices/
        https://thehackernews.com/2026/09/google-patches-pixel-modem-flaw-amid.html
        https://www.malwarebytes.com/blog/mobile/2026/09/google-pixel-owners-urged-to-patch-actively-exploited-modem-flaw
        https://www.securityweek.com/pixel-modem-zero-day-exploited-in-targeted-attacks/
        https://securityaffairs.com/199193/hacking/google-patches-pixel-modem-zero-day-exploited-in-targeted-attacks.html
      • Chrome, Firefox Updates Patch 115 Vulnerabilities
        "Google and Mozilla have released fresh security updates for Chrome and Firefox users, resolving a total of 115 vulnerabilities. The new Chrome 153 release patches 42 security defects, including three critical-severity and 28 high-severity bugs. The critical flaws include CVE-2026-91726, an out-of-bounds read in WebGL, and CVE-2026-91721 and CVE-2026-91749, use-after-free issues in Internals and Workers, respectively."
        https://www.securityweek.com/chrome-firefox-updates-patch-115-vulnerabilities/
      • Issabel Framework Hard-Coded JWT Key RCE Via Pbxapi/manager/originate
        "The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09."
        https://www.vulncheck.com/advisories/issabel-pbx-hard-coded-jwt-key-rce-via-pbxapi-manager-originate
        https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html
      • Authentication Bypass And DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 In TP-Link Tapo Cameras
        "TP-Link Tapo cameras are widely used smart security devices designed for home and small-business monitoring. As network-connected cameras, these devices combine video streaming, remote management, mobile application integration, and other services within a compact embedded system. This connectivity also makes security especially important. A vulnerability that allows an attacker to bypass authentication or access privileged functionality could compromise the camera and potentially provide a foothold within the network where the device is deployed."
        https://www.opswat.com/blog/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras
        https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras/
      • ParaShells: Parallels Desktop Turns Appliance Install Into a Root Shell
        "Your Mac runs a vulnerable version of Parallels Desktop. A malicious package, compromised CI job, or other unprivileged process is already running on it. No admin access. No Parallels-signed client. One appliance-install request later, attacker-controlled code runs as root. While testing Desktop 26.4.0 (build 57513) on Apple silicon, we found that an unprivileged local user could execute code as root through prl_disp_service. The exploit combines its world-writable Unix socket with weak local-client authentication and argument injection in the appliance extraction path."
        https://jfrog.com/blog/parallels-desktop-turns-appliance-install-into-root-shell/
        https://www.helpnetsecurity.com/2026/09/16/parallels-desktop-cve-2026-90894-parashells-vulnerability/
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-58704 Google Pixel Improper Authorization Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-one-known-exploited-vulnerability-catalog
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
        CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-two-known-exploited-vulnerabilities-catalog

      Malware

      • Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
        "A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. "JWT authentication can be bypassed when a token is signed using an unsupported algorithm, allowing unauthorized access," according to an advisory released by WSO2 in May 2026. "Successful exploitation of the vulnerability may lead to unauthorized access, including potential compromise of administrative accounts and full account takeover.""
        https://thehackernews.com/2026/09/active-exploitation-attempts-target.html
        https://www.securityweek.com/enterprises-warned-of-attacks-exploiting-wso2-vulnerability/
      • Critical ScreenConnect Flaw Now Actively Exploited In Attacks
        "Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). ConnectWise shared temporary mitigation measures for this missing-authorization flaw on September 7, advising security teams to disable TransferFiles permissions to block potential attacks. The vulnerability (now tracked as CVE-2026-84869 and patched in ScreenConnect 26.6.5 and later) affects ScreenConnect clients and can let threat actors with basic privileges transfer or execute files in low-complexity attacks that don't require user interaction."
        https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-screenconnect-flaw/
      • AI Helps Scammers Build Convincing Antivirus Renewal Pages
        "Antivirus renewal scams often begin with a message claiming that your subscription has automatically renewed. When you follow the instructions to cancel it, you are taken to a fake page designed to collect your contact details. The renewal charge never existed. Receiving a message that names the antivirus software you use does not necessarily mean the sender has access to your device or account. Scammers impersonate popular brands and send the same message to large numbers of people, knowing that some recipients will be customers."
        https://www.malwarebytes.com/blog/threat-intel/2026/09/ai-helps-scammers-build-convincing-antivirus-renewal-pages
      • NightEagle Targets Russian Companies
        "Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia, as we reported previously. We have now identified attacks by the group targeting businesses in Russia. This post examines both known and new tools NightEagle used in its latest campaign."
        https://securelist.com/tr/nighteagle-apt-ghostcontainer-and-tunneling/121323/
        https://thehackernews.com/2026/09/three-threat-groups-target-russian.html
      • Atomic MacOS (AMOS) Stealer Activity
        "This article reviews an Atomic macOS (AMOS) stealer malware infection generated in a lab environment. While several sources have published articles analyzing AMOS stealer, the associated indicators constantly change. This article presents a snapshot of indicators seen in early August 2026 and is designed to help readers better understand AMOS stealer."
        https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/
      • Scammers Are Watching Airline Complaints And Posing As Customer Support
        "A delayed flight. Missing luggage. A refund that never arrived. For frustrated customers, social media has become a direct route to customer support. They tag the company, explain the problem, and wait for a response. However, threat actors are watching those same conversations. A Check Point Exposure Management investigation uncovered a coordinated social engineering campaign in which scammers monitor public complaints, impersonate customer support accounts, and approach customers seeking help. Researchers engaged directly with the scammers and followed the attack from the first social media interaction through WhatsApp conversations and payment flows."
        https://blog.checkpoint.com/exposure-management/scammers-are-watching-airline-complaints-and-posing-as-customer-support/
      • N0va Phishkit Targets US And EU Businesses: A New Challenge For Identity Security
        "N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud resources. The longer that access goes unnoticed, the greater the potential for wider compromise, operational disruption, and financial loss."
        https://thehackernews.com/2026/09/n0va-phishkit-targets-us-and-eu.html
      • BragJack: How We Hijacked 5 Of The World's Most Popular Browsers Using Their Built-In AI Assistants
        "We just hacked 5 of the world’s most popular browsers using a brand-new technique that relies on AI. And we don’t mean “some AI hacking model that we trained”. No no no… we mean the browser’s own built-in AI assistants that you probably have installed right now. Yes, if you’re using Google Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, or Claude in Chrome… that means you. The interesting thing is that we didn’t even have to bypass the AI’s guardrails to do it. In fact, we didn’t even use prompt injection, because we discovered something worse."
        https://forever.security/blog/bragjack-hijacking-5-browsers-via-built-in-ai-assistants
        https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html
        https://www.darkreading.com/endpoint-security/bragjack-browser-agentic-ai
      • Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, And BASHNATCH
        "In August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity in January 2026, APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. During our investigation, ThreatLabz discovered new malware families and post-compromise tools, as well as significant post-compromise activity. The new tools include the RUSTYSHADE backdoor, the RUSTYMOVE post-compromise tool, and the PSNATCH and BASHNATCH file-stealing tools."
        https://www.zscaler.com/blogs/security-research/operation-rapidrust-apt36-deploys-rustyshade-rustymove-psnatch-and
      • PhantomRaven: An LLM-Generated Information Stealer Developed For Bug Bounty Hunting
        "CrowdStrike Counter Adversary Operations identified a financially motivated threat actor who works as a bug bounty hunter and who developed and distributed the JavaScript (JS)-based information stealer PhantomRaven via npm, a platform on which developers can access open-source packages to build applications and software. The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns."
        https://www.crowdstrike.com/en-us/blog/phantomraven-llm-generated-information-stealer-for-bug-bounty-hunting/
        https://hackread.com/crowdstrike-ai-phantomraven-malware-bug-bounty-hunter/
      • Silent Push Exposes North Korean IT Worker Recruiting Facilitators Through Discord Servers
        "Silent Push identified a North Korean fake job recruitment scam channel hosted on a Discord server by a defender colleague, and we engaged the recruitment representative to ask about their offering and determine whether the individual was actually a North Korean IT worker. After connecting via Telegram, we asked the suspect NK persona “Tec Guru” about virtual private networks (VPNs); they advised us to use Astrill VPN, a VPN often used by North Korean IT workers We identified the threat actor’s primary tactic as identity and proxy theft, under the guise of a front/facilitator recruitment scheme."
        https://www.silentpush.com/blog/nk-it-worker/
      • Mythic C2 Activity At Internet Scale
        "Mythic was created as a successor to an earlier macOS-focused project (Apfell). It was designed as a language-agnostic, cross-platform framework with a web-based UI. It is provided in a dockerfile to suit your environment with the ability to choose and configure separately available agents. This modular design lets operators combine agents for different platforms with various transport profiles without modifying the core framework. These agents, C2 profiles, wrappers, and services are shared and supported by the Mythic Community."
        https://censys.com/blog/mythic-c2/
      • TrustSink: How a Rogue External MFA Provider Steals Passwords
        "Varonis Threat Labs identified a credential-phishing technique we call TrustSink. It turns a trusted external authentication provider into a persistent credential trap within a legitimate sign-in flow. While the technique can work in any provider, we demonstrated TrustSink end-to-end using Microsoft Entra. An attacker with high privileges can register a rogue External Authentication Method (EAM) and place a convincing password page inside the legitimate sign-in flow. The page captures the password in plaintext while the provider returns a valid signed token, completing the login without an error."
        https://www.varonis.com/blog/trustsink

      Breaches/Hacks/Leaks

      • 280,000 Impacted By Premier Medical Group Data Breach
        "New York healthcare provider Premier Medical Group (PMG) is notifying over 280,000 patients that their personal and medical information was stolen in a data breach. PMG offers in-depth patient care across cardiology, dermatology, gastroenterology, neurology, plastic surgery, gynecology, and internal medicine fields through multiple office locations in the Hudson Valley. The data breach occurred in June, when some of PMG’s systems were disrupted, the healthcare provider said in an incident notice."
        https://www.securityweek.com/280000-impacted-by-premier-medical-group-data-breach/
      • International Meteor Organization Says Cyberattack Dealt ‘critical Blow’ To Website
        "A cyberattack has shut down the website of the premier international organization responsible for tracking meteors. The International Meteor Organization (IMO) has continued tracking asteroids and meteor through its Facebook page, but its website now carries a static page notifying visitors of the cyberattack. “We recently suffered a cyberattack that dealt a critical blow to aging infrastructure, taking much of our site offline,” the organization said. “We expect several weeks of partial downtime as we transition to new infrastructure and services. We will bring features back as they become available.”"
        https://therecord.media/international-meteor-organization-cyberattack

      General News

      • Securing The Unpatchable In An Age Of AI-Driven Vulnerabilities
        "AI-assisted code analysis is uncovering decades of technical debt. Every new patch removes a newly identified coding mistake. Little by little, we are improving the state of software engineering, but the price is a cadence of patching that organizations may struggle to implement. These efforts leave unsupported systems, or systems that are not able to be patched for whatever reason, with unmitigated known vulnerabilities. How can such systems be secured in a world where AI is steadily improving its ability to identify new vulnerabilities?"
        https://blog.talosintelligence.com/securing-the-unpatchable-in-an-age-of-ai-driven-vulnerabilities/
      • The Adversary We Are Fighting Is Now a Full-Force Industry: Inside Cybercrime's New Economy
        "The disruption we’re witnessing isn’t because of a new threat category. It is the industrialization of conventional ones. Cybercrime went corporate years ago: affiliate programs, Ransomware-as-a-Service (RaaS), Initial Access Brokers (IABs), support desks on underground portals. AI did not start that but what it did was collapse the cost and the skill floor of every stage of the attack at the same time. Attacks did get smarter, but the part most underestimate is that mediocre attackers became competent, and competent ones became industrial."
        https://www.group-ib.com/blog/adversary-full-force-industry/
      • NIST And CISA Finalize Playbook To Stop Token Theft And Forgery
        "NIST and CISA have finalized guidelines to help federal agencies and cloud service providers (CSPs) protect identity and access tokens from forgery, theft, and misuse. The guidance, Protecting Tokens and Assertions from Forgery, Theft, and Misuse (NIST IR 8587), explains how agencies and cloud providers can strengthen key management, token verification, and token lifecycle controls. It also covers how identity providers and authorization servers should be designed and managed."
        https://www.helpnetsecurity.com/2026/09/16/nist-cisa-cloud-token-security-guidance/
        https://nvlpubs.nist.gov/nistpubs/ir/2026/NIST.IR.8587.pdf
        https://www.infosecurity-magazine.com/news/cisa-nist-cloud-identity-token/
      • What Happens When AI Agent Governance Is Missing At Scale
        "In this interview with Help Net Security, Gourab Basu, Global Head of Engineering at meshIQ, discusses governance in AI agent systems. He argues that instructions written into a prompt are not enough to control what an agent does, since agents can change their own path as they work. Real control means checking proposed actions before they reach production systems, such as pausing a large refund for human approval. He also covers what breaks when a company scales from ten agents to a thousand, and how to build governance that works across different agent frameworks."
        https://www.helpnetsecurity.com/2026/09/16/gourab-basu-meshiq-ai-agent-governance/
      • The Modern Attack Chain: Rethinking Google Workspace Security In The Age Of AI
        "Over the past two months, I’ve written about the Vercel breach and the Composio breach separately. Both offer lessons to learn on their own. But reading them together, I keep coming back to the same observation: these aren’t isolated incidents. They’re the same attack, run twice, against different targets, where email was not the entry point into the workspace. And once you see the pattern clearly, it changes what you think you need to defend. It also raises an uncomfortable question that I’ve been sitting with. The pattern I’m describing, where an OAuth grant is used to access an account, read sensitive data from email and Drive, and use that access to move past the workspace, doesn’t only describe what attackers do. It increasingly describes what AI agents do, by design, every day."
        https://www.helpnetsecurity.com/2026/09/16/material-google-workspace-attack-chains/
      • MSPs Say Nearly Half Their Customers Rely On Them For CISO Services
        "MSPs estimate that 46% of their customers, on average, look to them to act as CISOs, according to Sophos. Most of those providers do that job without the full set of compliance services, and many spread the work across several tools. Most providers expect this work to grow. For many of those customers, the MSP is the closest thing they have to a security leader."
        https://www.helpnetsecurity.com/2026/09/16/msp-ciso-services-compliance/
      • Cyber-Attacks Cost Organizations $52,000 On Average
        "Nearly a third (29%) of organizations globally have been hit by at least one successful cyber-attack in the past 12 months, with incidents having substantial financial, operational and human impacts on victims. The Hiscox Cyber Readiness Report 2026 found that those affected by cyber-attacks reported an average of four incidents over the period. UK-based firms were most likely to experience an incident, with successful attacks reported by 38% of organizations. US organizations were least likely to experience an attack, at 20%."
        https://www.infosecurity-magazine.com/news/cyberattacks-cost-organizations/
      • Major Cyber Threat Detection Vendors Shift From MITRE To UK Testing Program
        "UK-based security testing and advisory provider SE Labs is launching a new testing program to help buyers evaluate cybersecurity vendors – and has attracted some prestigious names. The six-month testing program, called PIVOT, was unveiled by SE Labs on September 15. It will evaluate how effectively cybersecurity vendors can defend against the world’s most dangerous hacking groups and attack techniques."
        https://www.infosecurity-magazine.com/news/cyber-vendors-mitre-uk-testing/
      • Mythos Has Made 2026 Patching Hell. It Might Make 2027 a Breeze
        "When Microsoft delivered over 970 patches last week, many saw a nightmare for beleaguered security staff. Gartner research vice president Craig Lawson thinks infosec workers might soon see sunlit uplands as their workloads ease. Lawson outlined that scenario at Gartner’s IT Symposium in Australia today and explained it by theorising that the increased volume of vulnerability discoveries made possible by Anthropic’s Mythos and other bug-hunting AI might be getting close to finding most of the flaws in established codebases."
        https://www.theregister.com/security/2026/09/16/mythos-has-made-2026-patching-hell-it-might-make-2027-a-breeze/5296747
      • Threat Intelligence Alone Won't Close The Exploitation Gap
        "A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to react. Intelligence is still the earliest signal defenders get, and a leaked credential turning up in a feed is proof of how useful that signal has become. The problem sits one step later, in what happens after the signal arrives."
        https://thehackernews.com/2026/09/threat-intelligence-alone-wont-close.html
      • Using Cyber Decoys To Strengthen Detection And Response
        "CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data. Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI). As organizations adopt Zero Trust models, they should assume that a malicious threat actor may gain some level of access to their environment and plan accordingly."
        https://www.cisa.gov/resources-tools/resources/using-cyber-decoys-strengthen-detection-and-response
        https://www.cisa.gov/sites/default/files/2026-09/using-cyber-decoys-to-strengthen-detection-and-response_508c.pdf
        https://cyberscoop.com/cisa-guidance-cyber-decoys-critical-infrastructure/
      • Spain's Data Agency Gets First Report Of AI-Powered Data Breach
        "The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). The organization reporting the incident said that the AI agent searched for flaws, logged into their systems, and then probed apps for additional security issues. In the final stages of the attack, the agent modified personal data and accessed financial documents. Although the Spanish agency has yet to investigate the incident and verify the information, the AEPD says the notification shows AI-related data breaches are no longer merely theoretical."
        https://www.bleepingcomputer.com/news/security/spains-data-agency-gets-first-report-of-ai-powered-data-breach/
        https://www.securityweek.com/first-agentic-ai-data-breach-reported-to-spanish-regulator/
      • AI Security Spending Jumps As Fear Outpaces Proof Of Value
        "Organizations are pouring more money into AI for cybersecurity without waiting for clear evidence of what they might be getting in return. Multiple factors are driving the spending trend. These include the rapid shift of AI from experimentation into production, the growing use of AI by attackers to automate and accelerate their operations, and in some cases, fear of being left behind as other organizations race to adopt the technology."
        https://www.darkreading.com/cybersecurity-operations/ai-security-spending-jumps-fear-outpaces-proof-value
        https://hs-50428896.f.hubspotemail.net/hubfs/50428896/2026 Security Budget Benchmark Report Budget Snapshot Version 09142026.pdf

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 7a217715-199c-48af-9a72-26a61595831a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการโจมตีช่องโหว่ใน WooCommerce Wholesale Lead Capture เสี่ยงถูกยึดเว็บไซต์ WordPress

      พบการโจมตีช่องโหว่ใน WooCommerce Wholesale Lead Capture เสี่ยงถ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand afce7416-a020-4349-a725-b019bce8e0ec-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ญี่ปุ่นเผยเหตุโจมตี VPN กระทบแพลตฟอร์มเครือข่ายกลางภาครัฐ เสี่ยงข้อมูลรั่วไหล 246,000 รายการ

      ญี่ปุ่นเผยเหตุโจมตี VPN กระทบแพลตฟอร์มเครือ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 59bf17ab-e36f-4596-ad7e-fbba23466d83-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • บัญชี Reddit ทางการของ HBO Max ถูกเจาะระบบเพื่อแพร่กระจายมัลแวร์ขโมยข้อมูลผ่านโฆษณาแฝง

      บัญชี Reddit ทางการของ HBO Max ถูกเจาะระบบเพื่อแพร่.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 69e51612-441c-438b-8834-dc03558c2e69-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 16 September 2026

      Vulnerabilities

      • Attackers Actively Exploiting Critical Vulnerability In WooCommerce Wholesale Lead Capture Plugin
        "On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with an estimated 6,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. We added this vulnerability to the Wordfence Intelligence vulnerability database on February 25th, 2026. The Wordfence Firewall has already blocked over 100,000 exploit attempts targeting this vulnerability."
        https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-woocommerce-wholesale-lead-capture-plugin/
        https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/
      • Cisco Patches Secure Email Gateway Zero-Day Exploited In Attacks
        "Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. "In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," the company warned in a Monday security advisory. The security flaw (tracked as CVE-2026-76461) was found in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway and affects virtual and physical appliances, regardless of the device configuration."
        https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root/
        https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
        https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html
        https://securityaffairs.com/199137/hacking/cisco-warns-of-ongoing-exploitation-of-critical-email-gateway-zero-day.html
        https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited/
        https://www.securityweek.com/root-rce-zero-day-in-cisco-secure-email-gateway-under-active-exploitation/
        https://www.theregister.com/security/2026/09/15/cisco-email-security-boxes-can-be-rooted-by-an-email/5296604
        https://www.helpnetsecurity.com/2026/09/15/cve-2026-76461-cisco-email-gateway-zero-day-exploited/
      • Acronis Warns Of Actively Exploited Flaw In Its cPanel Backup Plugin
        "Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. cPanel & WHM and Plesk are used by web hosting companies and server administrators to manage websites and servers through graphical interfaces. Acronis’ backup add-ons connect the hosting control panel to the company's infrastructure, allowing administrators to back up and restore websites, files, databases, mailboxes, and hosting accounts from within the cPanel and Plesk interfaces."
        https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/
      • Apple Patches 200 Vulnerabilities With New iOS 27, MacOS Golden Gate 27 Releases
        "Apple on Monday announced patches for a record number of vulnerabilities across its desktop and mobile operating systems, including more than 200 flaws patched with the latest major releases: iOS 27 and macOS Golden Gate 27. iOS 27 and iPadOS 27 include fixes for about 126 security flaws, 20 of which affect the kernel. macOS Golden Gate 27 addresses 210 vulnerabilities, roughly 100 of which are shared with the iOS 27 release. macOS Tahoe 26.7 patches 153 unique CVEs, including 26 security defects in the kernel that could lead to memory corruption, privilege escalation, system termination, and information leaks."
        https://www.securityweek.com/apple-patches-200-vulnerabilities-with-new-ios-27-macos-golden-gate-27-releases/
        https://www.theregister.com/security/2026/09/15/the-vulnpocalypse-rains-ibugs-down-on-apple-with-record-setting-number-of-patches/5296679
      • CISA: Critical VMware RCE Flaw Now Exploited By Ransomware Gangs
        "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. Broadcom addressed the security flaw (tracked as CVE-2026-59310) on July 29, describing it as a critical directory traversal vulnerability in the vCenter Syslog server that unauthenticated attackers can exploit to execute arbitrary code."
        https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/
      • LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access On a Shared Server
        "A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers, many customers' sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself, according to the advisory. cPanel said it had received notice of the flaw, which affects versions before 6.3.7, and urged administrators to update to that release, which LiteSpeed published on September 11."
        https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html
        https://securityaffairs.com/199127/security/shared-hosting-at-risk-litespeed-enterprise-bug-can-grant-root-from-a-single-tenant.html

      Malware

      • Malcious Admin Menu Editor Pro Plugin Backdoors 1,500 WordPress Sites
        "Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates that created a hidden user account. Developer Janis Elsts says an unauthorized party accessed the adminmenueditor.com website on Monday and uploaded version 2.35 as an update for the plugin’s Pro version. The update included an includes/wp-user-consent.php file that installed a web shell on affected websites."
        https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/
        https://adminmenueditor.com/blog/security-incident-affecting-customers-2026-09-14/
      • The Banana Stand: Brokering And Managing Infections Across Asia Using MQTT
        "Black Lotus Labs®, the threat research division at Lumen, uncovered BambooToken, an emerging malware family using the Message Queueing and Telemetry Transport (MQTT) to quietly control infected Windows and Linux systems. Active since at least 2023, the campaign points to a skilled threat actor using stealthy infrastructure, side-loading techniques and broad access to collect data from targeted environments across Asia and South America. The findings show how early detection, supply chain visibility and proactive threat mitigation can help expose discreet techniques before adversaries expand them against higher-value targets."
        https://www.lumen.com/blog/en-us/the-banana-stand-brokering-and-managing-infections-across-asia-using-mqtt
        https://www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt/
        https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html
      • Iranian Cyber Targeting Of Dissidents, Activists And Journalists
        "CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025. CHOSEN BRICK enables Iranian state cyber actors to collect information on a target’s contacts, emails and social media messages, which could enable tracking of their movements. Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists. In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime."
        https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists
        https://www.bankinfosecurity.com/iranian-hackers-dodging-corporate-defenses-to-reach-critics-a-32822
      • VectraRAT: An Undocumented Full-Stack MaaS Built From Scratch
        "SOCRadar’s Threat Research Unit (STRU) has documented VectraRAT, a Malware-as-a-Service platform built entirely from scratch rather than forked from leaked RAT code. Renting from $250 a month, it gives operators hidden-desktop control, keylogging, clipboard hijacking, browser credential theft, and a UAC bypass that elevates with no prompt. The operator “Vectra” is a rebrand of “Nyxel”, active since at least August 2022 with no prior public reporting. STRU traced live infrastructure from an exposed open directory across more than ten servers and campaigns using Amadey and ClickFix, where 48% of recovered victim entries were corporate Windows editions, including exfiltration from Windows Server 2025."
        https://socradar.io/blog/vectrarat-undocumented-stack-maas/
        https://www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises
      • Search Results Are Sending People To Fake Bitrefill Checkouts
        "Bitrefill is a legitimate company that sells gift cards for popular stores like Amazon, Deliveroo, Apple, Nintendo, and thousands of others. They also sell eSIMs, and mobile top-ups. You can pay on their website for all of these with cryptocurrency. The scam is designed to catch people searching for Bitrefill or something it sells, like a gift card. Victims see a search result that appears to lead to Bitrefill but actually points to a lookalike domain. The fake site then takes them through what appears to be a normal purchase. The fake sites are not operated by or affiliated with Bitrefill; scammers have copied its branding and checkout process."
        https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts
      • The Extension You Never Installed: KREMLIN Forges Chrome's Own Integrity Checks To Steal Banking Sessions
        "Elastic Security Labs has tracked REF9334, a Brazilian banking malware operation, since May 2025. Its toolkit is called KREMLIN (as named by the malware author, Kr3mlin4rt1st), though nothing about the operation is Russian. Lures impersonate twelve Brazilian banks; error messages and code comments are written in Portuguese, and the operators' Ethereum transactions cluster during São Paulo working hours. Over 15 months and seven campaigns, they built a malicious browser extension that installs itself in Chrome and Edge, and the browser then loads it as though the user approved it. This post covers the infection chain, the extension internals, all seven campaigns, and the wallet trail connecting them."
        https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware
        https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html
      • Iranian Hackers Use Telegram-Controlled Malware To Spy On Dissidents And Journalists
        "Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record audio. The FBI calls it HEAVYGRAM, and the U.K.'s National Cyber Security Center (NCSC) calls it CHOSEN BRICK."
        https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html
        https://www.ic3.gov/CSA/2026/260915-2.pdf
        https://therecord.media/iran-cyber-spies-use-fake-mri-scans-as-lure
        https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646
      • Mind The (Patch) Gap: Multiple Chinese Threat Actors Chain 0-Day Exploits In Chrome & Windows
        "On September 1, 2026, Volexity’s Network Security Monitoring (NSM) service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers at multiple non-governmental organizations (NGOs). The emails contained a message encouraging the users to a click a link that led to the website of a US-based university. These links abused a reflected cross-site scripting (XSS) vulnerability on the website, redirecting recipients to threat-actor-controlled infrastructure hosting a multi-stage exploit chain that included a Google Chrome zero-day, CVE-2026-85046. Volexity analyzed its email telemetry and discovered that another Chinese threat actor it tracks as JungleBamboo (also known as APT31/Violet Typhoon/TA412) was also exploiting the same vulnerability chain against a different set of targets using different infrastructure and post-exploitation malware."
        https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/
        https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html
        https://securityaffairs.com/199104/apt/one-exploit-chain-two-espionage-campaigns-chrome-and-windows-under-fire.html
      • How Money Laundering, Scams, And Espionage Hide In a Web Full Of Casino Garbage
        "Many security teams ignore online gambling and casino domains, especially Chinese-language websites. Over the last decade there’s been massive growth in both gambling websites catering to Chinese audiences and similar casino sites targeting people all over the world. There’s also been growth in legal gambling and casino websites, but the scale of these compared to the malicious casinos is marginal."
        https://www.infoblox.com/blog/threat-intelligence/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage/
        https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652
      • Google Doc Sidebar Sends Mac And Windows Users Down Different Paths To Malware
        "Many Black Hat and DEFCON attendees come home to an inbox full of DMs. While catching up on the expected post-conference networking last month, a Huntress researcher realized they were being targeted in an X exchange with someone posing as a crypto marketing executive. The threat actor sent a link to a real Google Doc with a custom sidebar designed to trick the recipient into downloading malware: an AMOS infostealer on macOS, or PowerShell loader chain on Windows. Immediately picking up on the scam, our researcher didn't download any malware on their machine, but they did keep chatting with the threat actor, who ended up sending more malware and eventually a million-dollar offer. What started with a DM ended with a rogue certificate authority sitting in the Huntress testing environment."
        https://www.huntress.com/blog/google-doc-sidebar-malware-mac-windows

      Breaches/Hacks/Leaks

      • CenterPoint Energy Confirms Customer Data Stolen In Cyberattack
        "CenterPoint Energy disclosed a breach compromising some customers’ personal information after an attacker leaked data allegedly stolen from the utility company. An investigation started after the company discovered an online post from a threat actor claiming to have stolen 7.49 million records. CenterPoint Energy is a Houston-based public utility company that provides electric and natural gas services and operates power generation facilities."
        https://www.bleepingcomputer.com/news/security/centerpoint-energy-confirms-customer-data-stolen-in-cyberattack/
        https://therecord.media/centerpoint-energy-data-breach
        https://www.securityweek.com/texas-utility-centerpoint-energy-confirms-breach-after-hacker-leaks-data/

      General News

      • CVE Authorities Make Score 8 Look More Like The New 10
        "The U.S. government-backed CVE program is the gold standard for cataloging vulnerabilities, but its CVSS scores should be taken with a grain of salt, as the numbers can fluctuate for the same bug. Under version 4.0 of the scoring system, vendors assign a base score reflecting a vulnerability's highest possible severity, while threat factors such as whether exploitation has been observed can later modify the threat-adjusted score. "We need to stop talking about 'the CVSS score' as though there is only one number," Douglas McKee, director of vulnerability intelligence at Rapid7, told ISMG."
        https://www.bankinfosecurity.com/cve-authorities-make-score-8-look-more-like-new-10-a-32829
      • Your Employees Are Already Using AI Tools You Never Approved
        "Seventy-four percent of respondents report departmental or scaled AI adoption at their organizations, including within individual teams or departments, across business functions, and as part of processes and operations, according to the latest OneTrust 2026 AI-Ready Governance Report. The remaining respondents are planning, evaluating, or experimenting with AI, while 1% report no AI use."
        https://www.helpnetsecurity.com/2026/09/15/onetrust-enterprise-ai-governance-trends-report/
      • Most Chief Audit Executives Can’t Tell You What AI Is Worth Yet
        "Auditors are using AI in their daily work, and their departments have mostly left them to figure it out alone. 93% of audit leaders and auditors report some level of AI use, while 15% say their department has deployed formal use cases and runs them routinely in audits, according to Gartner. Chief audit executives (CAE) have to defend that arrangement to stakeholders, and most of them cannot say what it returns. Of the 142 CAEs polled in May, 54% have not started measuring the value of audit’s use of AI. Seven percent tie AI to cost metrics such as reduced external spend or avoided hiring, which is worth remembering the next time someone suggests the tools should pay for themselves in headcount."
        https://www.helpnetsecurity.com/2026/09/15/gartner-ai-in-internal-audit/
      • Most Fraudulent Hires Receive Credentials Before Detection
        "Most fraudulent hires receive corporate credentials and internal network access before being detected, according to a new report by HYPR. Fraudulent candidates successfully navigate pre-hire screening and take up their roles in 42% cases. Just 3% are subsequently detected as fraudulent on the same day as they are officially hired. Around a third (32%) are discovered within one to three days, 45% within four to six days and 20% go undetected for up to three weeks. This means that fraudulent hires have an average of 5.73 days of unmonitored access to corporate networks, posing significant data security risks to organizations."
        https://www.infosecurity-magazine.com/news/fraudulent-hires-credentials/
      • The State Of Recoverability 2026
        "Cybersecurity has spent two decades organized around a single idea: keep them out. That idea is being retired as the measure of success. Gartner now advises security leaders to define success around resilience rather than prevention, on the grounds that resilience, unlike absolute security, can be tested, practiced, measured, and improved. Regulators are now writing recovery obligations into law, insurers are pricing recovery posture into premiums, and boards have stopped asking if the organization is secure and started asking how long it would be down."
        https://fenix24.com/2026-state-of-recoverability-report/
        https://www.infosecurity-magazine.com/news/four-of-800-clients-hit-ransomware/
      • “We Think The Security Control Is Working” Is No Longer Good Enough
        "Security, risk, and control assessments are typically done for the sake of compliance: tools deployed, audits passed, workflows completed, boxes checked. That’s no longer enough for boards, customers, and regulators, who all want an answer to a harder question: ‘can you prove your controls are working right now?’ I often ask CISOs a version of that question, and the honest answer is usually some form of “we think so.” It’s not because they’re careless. Most control checks still happen the way a dentist visit does. When your dentist asks whether you brush and floss every day, you could fib and say yes, but one look at your x-ray tells the real story."
        https://www.securityweek.com/we-think-the-security-control-is-working-is-no-longer-good-enough/
      • Swiss Court Sentences 52-Year-Old Ukrainian Ransomware Dev To Nearly 13 Years In The Cooler
        "A Swiss court has sentenced a 52-year-old Ukrainian ransomware developer to 12 years and nine months in prison for his role in attacks on companies including Stadler Rail. Zurich District Court found that the man developed LockerGoga, MegaCortex, and Nefilim, but was not the mastermind behind the operations. He also received a ten-year ban from Switzerland. The judgment is not final and can be appealed. He had been held in pretrial detention since October 2021 and consistently denied knowing that his software was being used for criminal purposes."
        https://www.theregister.com/security/2026/09/15/swiss-court-sentences-52-year-old-ukrainian-ransomware-dev-to-nearly-13-years-in-the-cooler/5296482

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 1d813dc0-8ebe-4f5c-84aa-5d4dab6c7b70-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 15 September 2026

      New Tooling

      • Permify: Open-Source Authorization As a Service
        "Permify is an open-source authorization service that answers access questions at run time: can user X view document Y, which posts can members of team Y edit. It keeps those rules in one place, apart from the application code that would otherwise carry them. Permify follows the design of Google Zanzibar, the authorization system Google runs across its own products. Teams reach for something like it when permissions get specific and start nesting inside each other, and when the same rules have to hold across several applications at once."
        https://www.helpnetsecurity.com/2026/09/14/permify-open-source-authorization-as-a-service/
        https://github.com/Permify/permify

      Vulnerabilities

      • ConnectWise Patches ScreenConnect Vulnerability Exploited In Worm-Like Attacks
        "ConnectWise has released urgent patches for a critical-severity vulnerability in the ScreenConnect remote access and support software that has been exploited in worm-like attacks. Tracked as CVE-2026-84869 (CVSS score of 9.9/10), the security defect is described as a missing authorization and improper privilege management issue. The bug creates “a condition in the ScreenConnect client that may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances,” ConnectWise explains in its advisory."
        https://www.securityweek.com/connectwise-patches-screenconnect-vulnerability-exploited-in-worm-like-attacks/
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/14/cisa-adds-one-known-exploited-vulnerability-catalog
      • New DDRop Attack Breaks Intel TDX And AMD SEV-SNP Confidential Computing
        "Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it were current. The attack requires an attacker who already controls the server's software and can briefly access the machine to insert a small circuit board, called an interposer, between the processor and a memory module."
        https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html
        https://ddropattack.eu/
        https://www.theregister.com/security/2026/09/14/new-hardware-device-can-ram-into-encrypted-memory-expose-your-data/5296377

      Malware

      • Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens To Russian Bot Service
        "Socket’s Threat Research Team identified a cross-store browser extension, “Twitch Enhanced Viewer | JeetBot,” that forwards each user’s live Twitch OAuth session token to proxy servers operated by a Russian commercial bot service. The extension ships on both the Chrome Web Store (extension ID pnhhdhhcadcjfckjhpmjneldiegbojfb, 30,000 users) and Firefox Add-ons (twitchenhancedviewer@example[.]com, 552 users). Both listings are live at time of writing."
        https://socket.dev/blog/malicious-twitch-browser-extension
        https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html
        https://www.bleepingcomputer.com/news/security/twitch-extension-with-30k-installs-exposes-users-oauth-tokens/
        https://www.infosecurity-magazine.com/news/malicious-twitch-extension-oauth/
      • HBO Max Ads On a Compromised Reddit Account Exposed a Massive PasteSwitch ClickFix Operation
        "In September 2026, the cybersecurity community uncovered a massive, highly coordinated malvertising campaign leveraging the official, verified HBO Max Reddit account (u/hbomax). Over a frantic 48-hour period, the compromised account pushed 108 distinct “ClickFix” advertisements to users across the platform. Through joint research conducted by Hudson Rock and Kirk from ADAMnetworks (with additional thanks to Tuxxin from Whack.sh and Emiliano from The Matrix Project), we can confirm this incident is part of a massive, cross-platform delivery operation we are dubbing PasteSwitch. This operation spans macOS stealers, Windows loaders, deceptive TLS tactics, and contract-controlled cryptocurrency clippers."
        https://www.hudsonrock.com/blog/hbo-max-ads-on-a-compromised-reddit-account-exposed-a-massive-pasteswitch-clickfix-operation
        https://adamnet.works/blog/hbo-max-ads-exposed-the-pasteswitch-clickfix-operation/
        https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/
        https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408
      • Cloud Takeover: Mass Scanning For Exposed Vite Endpoints (CVE-2026-39364)
        "August 2026 saw an escalation in automated reconnaissance targeting internet-exposed developer tooling. Honeynet sensors recorded a sustained scanning operation focused on pulling cloud credentials and infrastructure state files out of exposed Vite development servers. The campaign generated 807 session-grouped attacks, roughly 32,000 raw events over the monthly analysis window. The activity was anchored by probes matching CVE-2026-39364, a high-severity file-read vulnerability that entered the monthly top-CVE tracking list, alongside recurring signatures for older Vite bypass flaws. Rather than target a single file, the scanning fleet systematically cycled through extensive wordlists of environment files, AWS keys, Azure tokens, and Infrastructure-as-Code state files."
        https://www.f5.com/labs/articles/cloud-takeover-mass-scanning-for-exposed-vite-endpoints-cve-2026-39364
        https://www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/
      • Fake Voicemail Transcript Emails Target 7,800+ Organizations In Large-Scale Credential Phishing
        "Automated voicemail transcripts have become part of the daily rhythm of enterprise communication. They arrive with familiar subject lines, system-generated formatting, and little human context, exactly the qualities that make them easy to trust and easy to overlook. Attackers are now exploiting that familiarity, turning routine call-transcription notifications into a vehicle for credential phishing. Check Point researchers identified a large-scale phishing campaign that exploits this shift in enterprise behavior. The emails impersonate automated voicemail-transcript notifications and deliver malicious Scalable Vector Graphics (SVG) attachments that redirect users to credential-harvesting pages, converting a familiar collaboration workflow into a potential path for account takeover."
        https://blog.checkpoint.com/security/fake-voicemail-transcript-emails-target-7800-organizations-in-large-scale-credential-phishing/
      • “Eye” Spy: Cyclops Blink Returns With Extended Capabilities
        "In August 2026, Counter Threat Unit™ (CTU) researchers analyzed a malicious 64-bit Linux executable named timezone_check that was discovered on multiple compromised Cisco Firewall Management Center (FMC) devices. The sophisticated modular implant provides persistent remote access to a compromised Linux system. CTU™ analysis indicates that it is a variant of the Cyclops Blink malware previously analyzed by the UK National Cyber Security Centre (NCSC) in 2022 and is likely associated with the Russia-based IRON VIKING threat group (also known as Sandworm and Seashell Blizzard). Cisco published details about this campaign on September 9, prompting CTU researchers to publicly release their analysis."
        https://www.sophos.com/en-gb/blog/-eye-spy-cyclops-blink-returns-with-extended-capabilities
        https://www.darkreading.com/cyberattacks-data-breaches/sandworm-chains-cisco-vulnerabilities-cyclops-blink
      • Smish. Click. Drained: Inside The Smishing Triad's Phishing Cockpit
        "A widespread smishing campaign was identified in which victims received fraudulent SMS messages impersonating official entities and were instructed to click a link inside the SMS in order to “complete a verification“, “settle an outstanding fee”, or “re-confirm delivery details”. The link resolved through a short URL into a disposable apex domain hosting the phishing kit analysed in this writeup. The kit then walked the victim through a multi-stage credential capture funnel identity, card, OTP, sometimes a second bank, sometimes a wallet while a human operator on the back end watched the session in near-realtime and pushed control instructions as needed."
        https://www.group-ib.com/blog/smishing-triad-outsider-jwr/
      • Machine Speed, Hold The AI: Hand-Rolled Marimo CVE-2026-39987 Exploit
        "AI is lowering the barrier to entry for attackers; that much is settled. But what’s still up for debate is whether skilled threat actors can keep up with their LLM-driven competitors. Recently, the Sysdig Threat Research Team (TRT) watched a single threat actor go from an open WebSocket to a live SSH session on a bastion host in eight seconds. There was no agent in the loop, nor was there any sign of LLM-generated scripts or tooling. Instead, the operator used a Python toolkit they wrote and debugged by hand, in-session, over the preceding four hours."
        https://www.sysdig.com/blog/machine-speed-hold-the-ai-hand-rolled-marimo-cve-2026-39987-exploit
        https://www.infosecurity-magazine.com/news/human-attacker-machine-speed/
      • The Fake Worker Threat And The Rise Of Human Infiltration
        "The Democratic People’s Republic of Korea (DPRK), commonly known as North Korea, has thousands of highly skilled workers engaged in remote employment and related activities around the world. In most cases these workers have constructed false identities as individuals based in the United States (U.S.), Germany, Portugal, the United Kingdom (UK) and other Western countries. They often mask their locations through something like remote laptop farms and virtual private networks (VPNs). This is the ‘North Korea fake worker scam,’ also known as the ‘fake IT worker scam.’ It is believed to have cost victim organizations hundreds of millions of dollars since its emergence in 2017."
        https://blog.barracuda.com/2026/09/14/the-fake-worker-threat-and-the-rise-of-human-infiltration
      • Red Heron Exploits Gitea n-Day Flaw In Multinational Campaign, Exposing New Linux Rootkit
        "Acronis Threat Research Unit (TRU) uncovered a multinational campaign in which a Chinese-speaking threat actor, tracked as Red Heron, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, a self-hosted source-code management platform. The activity progressed from source-code theft to persistent access, credential collection, and lateral movement, including root-level access to a three-node Proxmox cluster. TRU traced a Linux implant to Red Heron’s exposed staging server, revealing the actor’s exploitation tools, reconnaissance databases, command history, stolen repositories, and malware. This provided rare visibility into the operation, from target selection and vulnerability weaponization to post-exploitation activity."
        https://www.acronis.com/en/tru/posts/red-heron-exploits-gitea-n-day-flaw-in-multinational-campaign-exposing-new-linux-rootkit/
        https://thehackernews.com/2026/09/red-heron-exploits-gitea-rce-to.html
      • Pro-Ukraine Hacking Cat Group Deploying New Malware Against Russian Targets
        "Researchers have uncovered new hacking tools used by the pro-Ukraine hacktivist group Hacking Cat, which has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets. The group often works alongside other Ukraine-linked hackers and uses a wide range of custom-built tools, making it “significantly more difficult” to attribute individual attacks to a specific threat actor, Russian cybersecurity firm Kaspersky said in a recent report."
        https://therecord.media/ukraine-malware-russia-ransomware
      • Hundreds Of Fake Government Websites Target Users In Central Asia
        "Cybercriminals have created hundreds of fake government and news websites to target people in Uzbekistan, Belarus and Tajikistan with bogus offers promising cash payments or passive income. Researchers at cybersecurity firm F6 identified more than 360 fraudulent domains tied to the campaign. The sites are designed to collect victims’ contact details, which scammers then use to target them through phone or email to steal money, personal information or gain access to their devices."
        https://therecord.media/hundreds-of-fake-gov-websites-central-asia-scam
      • One Host, Six Operations: How Two Open Directories Exposed a Multi-Target Campaign
        "Hunt.io Attack Capture™↗ (opens in a new tab) flagged two open directories at IP Address "69[.]48[.]228[.]86" on port 80 (August 14) and on port 9001 (August 24), ten days apart in August 2026. A full inventory of both directories reveals a single operator running six parallel operations such as fraud against roughly 2,500 self-hosted "New API" LLM-reseller gateways, LLM-assisted mapping of Vietnam's government and military hierarchy, password-spraying and reconnaissance against Pakistan's National Defence University and armed forces, SQL-injection probing of the Chinese social platform uu-chatroom.com, opportunistic census-style scanning of unrelated hosting-provider IP ranges, and one completed database breach of commercial targets in Mexico."
        https://www.infrahunter.com/research/two-open-directories-on-a-singapore-vps
      • The Ghost In The Chat: How a Bot That Isn't In Your Group Steals Messages From Telegram HTML Exports
        "A stored XSS in Telegram Desktop lets an attacker plant invisible JavaScript in an exportable chat through a bot's inline keyboard button. The payload can sit in message history for months and detonates when a participant opens an HTML export page containing that message. No second click, no warning: every message and metadata field rendered in that document can be shipped to the attacker's server, and the page itself can be rewritten. The bot never joins the target chat — one forwarded message can be enough."
        https://expatch.com/writeups/telegram-html-export-xss.html
        https://thehackernews.com/2026/09/telegram-desktop-flaw-lets-hidden.html

      Breaches/Hacks/Leaks

      • Japan's Digital Agency Says VPN Flaw Exposed 246,000 Personnel Records
        "Japan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. The agency says that the attacker gained initial access by exploiting a vulnerability in a VPN device used by the Government Solution Service (GSS). An investigation started on June 25, after the agency detected a large-scale file access from the account of a maintenance and operations staff member."
        https://www.bleepingcomputer.com/news/security/japans-digital-agency-says-vpn-flaw-exposed-246-000-personnel-records/
      • Telus Warns Customers Of Account Breaches
        "Telus, one of Canada’s largest telecom providers, is notifying some customers that their accounts have been breached and their personal information has been accessed. In data breach notifications sent to customers whose consumer telecom accounts were affected, Telus said the intrusions occurred between February 2025 and June 2026. According to the company, the attacker used compromised credentials to access Telus accounts and the information they store, including names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history."
        https://www.securityweek.com/telus-warns-customers-of-account-breaches/
      • Thai Broadband Provider Targeted Via FortiGate SSL-VPN And MeshCentral Persistence
        "Open directories are one of the most reliable windows into active threat actor operations. When an attacker misconfigures their staging server, everything they have been doing becomes accessible. Hunt.io's AttackCapture™ discovered an open directory hosted at 92[.]63[.]180[.]133:8888, a server on Bangmod Enterprise Co., Ltd. infrastructure in Thailand. The directory contained 298 files across 30 subdirectories totaling 19 MB, first captured on June 3, 2026, including exploitation scripts, privilege escalation tools, brute-force utilities, a live MeshCentral agent configuration, and a device inventory of already-compromised machines, all targeting 3BB (Triple T Broadband). Before going deeper, these are the findings that shaped the entire analysis."
        https://hunt.io/blog/thai-broadband-fortigate-sslvpn-meshcentral-intrusion
        https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html

      General News

      • Turn It Off And On Again, But For Critical Infrastructure
        "Researchers at KTH Royal Institute of Technology built a container replica of a segmented industrial network, attacked it repeatedly across 14 days of running time, and used the captured traffic to train a defense agent that decides on its own when to intervene. The agent sees six numbers per interval: packet counts crossing the network’s segments and moving to and from individual machines. From those counts it infers how far an intruder has progressed, and acts."
        https://www.helpnetsecurity.com/2026/09/14/ot-intrusion-response-agent/
        https://arxiv.org/pdf/2609.10298
      • Cybersecurity Attention Fades Within Months After a Breach
        "Cybersecurity attention often rises after an incident, then recedes as organizations return to their existing priorities and practices, according to a new ManageEngine survey of 700 IT and cybersecurity leaders in the US and Canada. All of them had already been through a breach or incident. Still, 91% said they trust their organization’s current cybersecurity posture. Only 8% said cybersecurity becomes a permanent priority once the incident is behind them. “The belief that breaches are inevitable has lowered the bar for security,” said Dr. Erik Huffman, a cyberpsychology researcher who commented on the findings. “We’ve said ‘it’s not a matter of if, but when’ for far too long. But we still have control over the security processes that directly influence the outcome.”"
        https://www.helpnetsecurity.com/2026/09/14/manageengine-cybersecurity-breach-confidence-report/
      • Certificate Failures Can Cost Firms Over $250,000
        "The move toward 47-day public TLS certificates by 2029 will increase the certificate management workload for enterprises, according to DigiCert’s Certificate Management Outlook. Organizations will need to renew certificates more than eight times as often as under the previous certificate lifecycle and conduct 40 times as many domain validations. Certificate failures can disrupt business operations. Some 34% of companies experienced a service outage caused by an expired certificate, while 40% reported downtime linked to certificate mismanagement."
        https://www.helpnetsecurity.com/2026/09/14/digicert-certificate-management-automation-report/
      • Google’s New Search Redirects Make Links Harder To Check Before You Click
        "Google is changing how some links in its search results work. Instead of linking directly to the destination, Google has started routing some search result links through opaque google.com/goto?url=... redirects. The url parameter does not show a readable version of the destination but uses a custom, Google-specific encoding."
        https://www.malwarebytes.com/blog/news/2026/09/googles-new-search-redirects-make-links-harder-to-check-before-you-click
      • Security Through Obscurity Is Dead, And AI Delivered The Fatal Blow
        "The term "security through obscurity" describes an old idea that networks and systems will remain secure so long as their architecture, along with any vulnerabilities or other weaknesses, remains secret or hidden. It was never a sound strategy for protecting sensitive assets and systems, but many organizations leaned on it due to lack of resources or complacency. Now it’s obsolete. Don’t believe us? Here’s proof."
        https://www.theregister.com/security/2026/09/13/security-through-obscurity-is-dead-and-ai-delivered-the-fatal-blow/5296000
      • New Warnings About The Risks Of AI To Humanity Revive a Long-Running Debate
        "New warnings from within the artificial intelligence industry have revived a long-running debate over whether advanced AI could escape human control and ultimately threaten humanity’s survival, and whether the companies developing the technology are doing enough to prevent such a scenario. The CEO of Anthropic, the San Francisco company behind Claude, said he thought the industry needed to reduce the speed of its work, cautioning Saturday that a swarm of AI agents might be able to take over the internet in six months to a year unless companies devoted more time to putting safeguards in place."
        https://www.securityweek.com/new-warnings-about-the-risks-of-ai-to-humanity-revive-a-long-running-debate/
      • SecondSight Threat Hunting Report
        "Authored by the Trellix Advanced Research Center, this report (1) highlights threat hunting insights, intelligence, and guidance gleaned from multiple sources of critical data, including Trellix SecondSight, on the top five critical campaigns observed in the first half of 2026, and (2) develops expert, thorough case studies to inform and enable best practices in defending against these types of campaigns. This edition focuses on data and insights captured primarily between January 1, 2026, and June 30, 2026."
        https://www.trellix.com/advanced-research-center/threat-reports/secondsight-threat-hunting-report-september-2026/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 08fc5bc9-d01a-45e0-9a3e-e2f00007494b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการใช้ Google Play Early Access เผยแพร่ แอป Android หลอกลวง

      พบการใช้ Google Play Early Access เผยแพร่แอป Android หลอกลวง.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand b5bb997f-6e24-4592-b583-eecba9182c04-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • GitLab เตือนช่องโหว่ CVE-2026-85706 ระดับ Critical เสี่ยงถูกอ่านไฟล์สำคัญโดยไม่ต้องยืนยันตัวตน

      GitLab เตือนช่องโหว่ CVE-2026-85706 ระดับ Critical เสี่ยงถูกอ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand bad8182d-22e1-49a2-9e26-48a40c677300-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ศาลสหรัฐฯ พิพากษาจำคุก 4 ปี แฮกเกอร์ผู้อยู่เบื้องหลังกลุ่มมัลแวร์เรียกค่าไถ่ Conti

      ศาลสหรัฐฯ พิพากษาจำคุก 4 ปี แฮกเกอร์ผู้อยู่.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 562122c3-b435-498a-91b2-9e93ac7f2a25-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 14 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/14/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand bdd0e824-8245-4e14-b475-65f922e4992e-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบผู้โจมตีใช้ Claude วิเคราะห์แอป Android กว่า 1.8 ล้านไฟล์ เพื่อค้นหาข้อมูลรับรอง

      พบผู้โจมตีใช้ Claude วิเคราะห์แอป Android กว่า 1.8 ล้า.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand a8822dbb-66ce-42da-bc5a-57ea96a5aafc-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ใน Artifactory ถูกใช้โจมตีเพื่อยกระดับสิทธิ์และฝัง Backdoor บนเซิร์ฟเวอร์

      ช่องโหว่ใน Artifactory ถูกใช้โจมตีเพื่อยกระดับสิ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 64142ea1-62b3-4622-9b80-4f12e0153c0a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • แฮกเกอร์ใช้ช่องโหว่ในแอปพลิเคชันของ Tencent เพื่อแพร่กระจายมัลแวร์ GrayRabbit

      แฮกเกอร์ใช้ช่องโหว่ในแอปพลิเคชันของ Tencent เ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand f3258537-fc48-4126-823c-faa54adc52fc-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 4 รายการลงในแคตตาล็อก

      เมื่อวันที่ 11 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 4 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability
      • CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability
      • CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
      • CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog
      https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 3d00ca75-4ca9-4d75-957a-93ff351c0b28-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 14 September 2026

      Vulnerabilities

      • Artifactory Under Attack: In-The-Wild Exploitation Of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
        "Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities affecting JFrog Artifactory: CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329. Attackers are chaining these vulnerabilities to bypass authentication, escalate privileges, and gain administrative control over vulnerable Artifactory instances. Observed post-exploitation activity includes the creation of persistent administrator accounts, the deployment of malicious Groovy plugins for code execution, and the installation of Rust-based backdoors to establish persistence. This blogpost provides an analysis of the exploitation patterns observed, the impact on affected organizations, and actionable guidance for security teams to detect and remediate these threats."
        https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201
        https://www.bleepingcomputer.com/news/security/artifactory-flaws-chained-in-attacks-deploying-backdoor-malware/
        https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html
        https://www.theregister.com/security/2026/09/11/more-jfrog-artifactory-bugs-under-attack-and-all-3-have-patches/5295943
      • GitLab Urges Users To Patch Max Severity Path Traversal Flaw
        "GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. The security flaw, discovered by a security researcher using the 's3ntago' handle and reported via GitLab's HackerOne bug bounty program, stems from improper path confinement and missing authentication enforcement in the repository commits API. Unauthenticated attackers can exploit CVE-2026-85706 "under certain conditions" to read arbitrary data (e.g., credentials, secrets, and sensitive information) from vulnerable servers."
        https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/
        https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html
        https://cyberscoop.com/gitlab-critical-flaws-path-traversal-scans/
        https://www.securityweek.com/gitlab-vulnerability-exploited-one-day-after-disclosure/
        https://securityaffairs.com/198945/hacking/gitlab-cve-2026-85706-one-http-request-no-authentication-full-file-read-exploited-within-24-hours.html
      • PaperCut Replaces Emergency Patches With Fixes For Two Actively Exploited Flaws
        "PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases (MR) that have gone through complete QA testing," it said. "They contain all of the security fixes issued in Emergency Patch Releases 1, 2 and 3, plus additional security hardening, and they have been through our standard release testing process.""
        https://thehackernews.com/2026/09/papercut-replaces-emergency-patches.html
        https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
      • CISA Adds Three Known Exploited Vulnerabilities To Catalog
        "CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability
        CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability
        CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog
        https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog
      • GuardBreaker: Derailing AI-Assisted Malware Analysis With a Code Comment
        "Malware developers have long adapted their code and tactics to the defenses and scrutiny that are likely to stand in their way. Using various evasion and anti-analysis methods, they routinely attempt to hinder code analysis or prevent their malware from revealing its true behavior while under inspection. Other tools – notably, EDR killers, documented extensively by ESET researchers – go straight after security solutions themselves. As LLM-based tools increasingly assist with various security tasks, including code triage and analysis, it was only a matter of time before threat actors began to look for practical ways to subvert them, too. Alongside conventional evasion techniques, some are taking a different tack: the adversarial input that’s intended to frustrate analysis is left in plain sight."
        https://www.welivesecurity.com/en/business-security/guardbreaker-derailing-ai-assisted-malware-analysis-code-comment/
        https://www.darkreading.com/cyber-risk/ai-governance-cannot-wait
      • Direct Send: How Attackers Weaponize Your Infrastructure Against You
        "An employee at your company receives an email from [email protected]. The domain matches. There is no warning banner. The message asks them to review a payment approval document. They click. That email was never sent by your HR team. An attacker sent it, and your own Microsoft email infrastructure delivered it, with no password and no credentials required."
        https://blog.knowbe4.com/direct-send-how-attackers-weaponize-your-infrastructure-against-you
        https://www.infosecurity-magazine.com/news/hackers-us-business-hours-m365/
      • The Exposed AI Supply Chain — Mysterium VPN Research
        "36,769 self-hosted AI endpoints across model servers, agent builders, and vector stores are reachable and identify themselves in a single scanning index. Only 2.02% return an HTTP authentication challenge; for the overwhelming majority, there’s no network-layer gate whatsoever. Open WebUI: 18,529 reachable, 1 behind a gate: The most widely deployed local-LLM front-end has, as a population, no perimeter."
        https://www.mysteriumvpn.com/blog/data-and-research/we-exposed-ai-supply-chain
        https://securityaffairs.com/198898/ai/the-ai-supply-chain-has-a-security-problem-and-much-of-it-is-sitting-on-the-open-internet.html

      Malware

      • Protecting Organizations From AI-Assisted Executive Impersonation And Invoice Fraud
        "Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive team members. While this technique is not new, the adoption of AI has enabled threat actors to improve their campaign templates and construct emails tailored to their recipients. Additionally, threat actors are incorporating multiple techniques within the same email to improve the overall narrative further."
        https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/
        https://www.darkreading.com/cyberattacks-data-breaches/1m-personalized-fraud-emails-3-days
        https://therecord.media/invoice-scam-emails-new-features-microsoft-researchers
        https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html
      • Gray Rabbits And The Tale Of a One-Click Backdoor
        "Gen Threat Labs discovered a critical remote code execution vulnerability (CVE-2026-51990) in Sogou Input Method, one of the most widely used Chinese-language input method editors with hundreds of millions of installations. The vulnerability chains three separate weaknesses into a single, one-click exploit: unvalidated command-line argument injection in the sgbiz: custom protocol handler, unrestricted URL navigation in a CEF-based webview, and a severely outdated, unsandboxed Chromium browser engine. We observed this vulnerability actively exploited in the wild by the UNC3569 threat group to deploy the GRAYRABBIT backdoor through a crafted link."
        https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou
        https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html
        https://www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware/
        MacSync: The Evasive MacOS Stealer Exploiting ClickFix Lures
        "MacSync Stealer is a family of macOS information stealers and remote-access stagers designed to evade detection and sold commercially under a malware-as-a-service (MaaS) model. In the attack chain, MacSync binaries are native stagers and multi-part exfiltration engines. Rather than standalone harvesters, the payloads are lightweight 64-bit Mach-O executables that detach silently from terminal sessions, load credential-dumping modules directly into memory, and reliably exfiltrate stolen credentials back to campaign infrastructure."
        https://www.seqrite.com/blog/macsync-the-evasive-macos-stealer-exploiting-clickfix-lures/
      • DarkTortilla Malware: How It Works And How To Test Your Defenses
        "DarkTortilla is a highly configurable .NET-based crypter and multi-stage loader active since at least August 2015. It targets Windows systems, spreading through logistics-themed phishing emails. Unlike typical loaders, DarkTortilla hides its encrypted configuration inside bitmap pixel data and can pull its core processor DLL from public paste sites. It runs payloads only inside injected legitimate processes, applies three interchangeable persistence mechanisms, and pairs a WatchDog executable with the loader so each restarts the other."
        https://www.picussecurity.com/resource/blog/darktortilla-malware-how-it-works-and-how-to-test-your-defenses
      • I Just Trusted The Security Certificate Prompt… Beware Of The LegionLoader Malware Being Distributed Via The ClickFix Method
        "The AhnLab SEcurity intelligence Center (ASEC) recently identified the LegionLoader malware, which is currently being distributed via the ClickFix method. There are two main distribution methods identified so far; both involve tricking users into visiting a malicious URL and then prompting them to directly execute malicious PowerShell commands through a fake Cloudflare CAPTCHA screen."
        https://asec.ahnlab.com/en/95374/
      • OpenAI Agents Linked To RubyGems Campaign That Gained RCE On RubyDoc Servers
        "The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the Ruby programming language with hundreds of junk gems, prompting the maintainers to suspend new user sign-ups for about four days."
        https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html
        https://www.rubyhack.ai/

      Breaches/Hacks/Leaks

      • Novo Nordisk Data Breach Tied To Stolen GitHub Access Tokens
        "Hardcoded credentials recovered from corporate cloud environments are giving hackers ongoing, easy access to experimental drug data, customer records and more. Cyber extortionist group FulcrumSec, which specializes in ransoming sensitive data, continues to employ this strategy, going so far as to dub it the "Hardcoded Horrorshow." The group's victims have included England's Manchester Airport Groups, London-based consultancy Arup Group and Singapore-based Global Schools Group, among others."
        https://www.bankinfosecurity.com/novo-nordisk-data-breach-tied-to-stolen-github-access-tokens-a-32802
      • UK Council Attack Linked To Mass Exploitation Of SonicWall Flaw
        "On July 17, 2026, the Borough Council of King’s Lynn and West Norfolk announced it had detected a cyberattack affecting council services. Hunt.io has since published a detailed technical analysis linking that incident, with moderate confidence, to a wider mass-exploitation campaign against SonicWall SMA1000 appliances using CVE-2026-15409, a maximum-severity SSRF flaw that received a CVSS score of 10.0."
        https://securityaffairs.com/198864/hacking/uk-council-attack-linked-to-mass-exploitation-of-sonicwall-flaw.html
      • Revolut Confirms Customer Data Breach Through Fake Government Requests
        "British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses, according to a notification emailed to affected customers and reviewed by TechCrunch. The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification."
        https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/
        https://securityaffairs.com/198922/data-breach/revolut-exposed-kyc-data-after-fraudulent-government-email-passed-security-checks.html

      General News

      • Why AI Is So Good At Scamming Humans
        "If there's one thing that AI models are remarkably good at, it's manipulation. That's according to security researcher Fred Heiding, who spoke with Dark Reading's senior news director, Rob Wright, at the Dark Reading News Desk at Black Hat USA 2026 last month. Heiding, executive director at Menlo Park Intelligence, and former US National Cyber Director Chris Inglis, spoke at the conference about their research on AI security."
        https://www.darkreading.com/cyber-risk/ai-scamming-humans
      • Phishing Research Challenges Conventional Security Awareness Testing
        "The message is simple: fine-tune future in-house phishing simulation tests through the findings and analysis of Pistachio’s research. Pistachio was founded in Oslo Norway in 2019, with additional offices in London and Valencia. It specializes in automated human risk management, employee security awareness training, and phishing simulations. Between 1 June, 2025 and 31 May, 2026, Pistachio sent 2.47 million simulated phishing attempts to more than 123,000 employees in more than 1,200 organizations. Its subsequent analysis looked at clicking, leaking, and reporting."
        https://www.securityweek.com/phishing-research-challenges-conventional-security-awareness-testing/
        https://hs-5440974.f.hubspotemail.net/hubfs/5440974/The-Phishing-Behaviour-Report-2026-Pistachio.pdf
        https://www.helpnetsecurity.com/2026/09/11/pistachio-employee-phishing-risk-report/
      • AI Is Changing What Salesforce Security Needs To Govern
        "Existing security and governance practices have largely focused on identities, permissions, access, configurations and controls. WithSecure’s Navigating Trust in the Modern Salesforce Ecosystem paper says Salesforce environments also require organizations to understand what information they rely on, how trust extends across connected systems, what actions are performed and what outcomes those actions produce."
        https://www.helpnetsecurity.com/2026/09/11/withsecure-salesforce-ai-trust-governance-paper/
      • Most Organizations Skip Permissions Reviews Before Deploying AI Tools
        "AI is being deployed faster than the data foundation beneath it is being checked, a new Syskit study has revealed. In its latest State of Microsoft 365 Governance Report, published on September 10, security governance firm Syskit has found that three-quarters (76%) of organizations in the UK and the US have deployed or piloted an enterprise AI tool such as Copilot on Microsoft 365 data. Despite this wide adoption, only 43% of respondents confirmed they had completed a thorough review of permissions and oversharing risk before deploying these tools. The rest admitted to only having run a partial review or none at all."
        https://www.infosecurity-magazine.com/news/organizations-skip-permissions-ai/
        https://www.syskit.com/ebooks/state-of-m365-governance-report-2026
      • Anthropic CEO Dario Amodei Says AI Industry Needs To Give Safety Measures Time To Catch Up
        "The CEO of Anthropic said Saturday the artificial-intelligence industry should slow its fast-moving development to give safety measures time to catch up. Without such a slowdown, Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet. The warning comes as worries about AI grow inside and outside the industry and reports continue to emerge about increasingly powerful systems that solve problems beyond human capacity but could also go rogue and carry out other, more harmful tasks. The worries have grown so loud that the CEO of OpenAI, the company behind ChatGPT, said in an interview with Fortune that his company would wait until next year to start selling its stock to investors on Wall Street as it focuses on safety."
        https://www.securityweek.com/anthropic-ceo-dario-amodei-says-ai-industry-needs-to-give-safety-measures-time-to-catch-up/
      • August 2026 Dark Web Breach Incident Trend Report
        "In August 2026, widespread instances of database leaks, the sale of internal data, and the trading of initial access privileges were observed on dark web and deep web forums. Due to the nature of the sources, it was difficult to fully verify the accuracy of some posts."
        https://asec.ahnlab.com/en/95385/
      • August 2026 Dark Web Threat Actor Trend Report
        "The August 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—active on the deep web and dark web. It is noted that the accuracy of some information could not be verified."
        https://asec.ahnlab.com/en/95390/
      • August 2026 Dark Web Issue Trend Report
        "The August 2026 Dark Web Issue Trend Report summarizes Major Issues that occurred on the deep web and dark web. The report notes that, due to the nature of its sources, it may contain some information whose accuracy cannot be fully verified."
        https://asec.ahnlab.com/en/95391/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) d168aa57-b314-4f37-8db1-a086fb31b6c9-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการใช้ช่องโหว่ Fortinet โจมตีอุปกรณ์เพื่อติดตั้งมัลแวร์ PivotC2

      พบการใช้ช่องโหว่ Fortinet โจมตีอุปกรณ์เพื่อติด.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand d8bc7771-2a8d-4a1e-9361-0d7defac3437-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Trezor เตือนลูกค้าระวัง Phishing หลังผู้ให้บริการ Email ภายนอกถูกเจาะระบบ

      Trezor เตือนลูกค้าระวัง Phishing หลังผู้ให้บริการ Email.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand d126ea42-1b7e-4012-b143-7bdaa7cd3ffe-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT