NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,563
    • กระทู้ 2,564
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 2 รายการลงในแคตตาล็อก

      เมื่อวันที่ 10 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 2 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
      • CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand dd97e004-14d0-4651-b264-9352948152c6-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 4 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 4 รายการ เมื่อวันที่ 10 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      ICSMA-26-253-01 NextGen Mirth Connect
      ICSMA-26-253-02 Orthanc DICOM Server
      ICSA-26-253-01 AVEVA Pipeline Integrity Monitor
      ICSA-26-183-01 ST Engineering iDirect iQ-Series Terminals (Update A)

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 79d6973d-9d0c-4173-85fe-31aec01f48ec-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 8 รายการลงในแคตตาล็อก

      เมื่อวันที่ 8-9 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 8 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
      • CVE-2026-81963 Microsoft Windows Link Following Vulnerability
      • CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability
      • CVE-2026-86218 N-able N-central Static Code Injection Vulnerability
      • CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
      • CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
      • CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability
      • CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog
      https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 501a514a-b633-4249-8113-0ea4d282fa64-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบเครือข่ายร้านค้าออนไลน์ปลอม DoppelCart ใช้กว่า 119,000 โดเมน หลอกขโมยข้อมูลบัตรชำระเงิน

      พบเครือข่ายร้านค้าออนไลน์ปลอม DoppelCart ใช้กว่า 119,000 โดเมน หลอกขโมยข้อมูลบัตรชำระเงิน.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand dd5e4a01-a3ac-4763-b1eb-d5be9a1ac387-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบ Plex Media Server กว่า 36,000 เครื่องเปิดสู่อินเทอร์เน็ต ยังไม่ได้แพตช์ช่องโหว่ล่าสุด

      พบ Plex Media Server กว่า 36,000 เครื่องเปิดสู่อินเทอร์เน.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 7b1ba684-04b8-4a37-84f0-1e4213bfe1c1-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบแคมเปญ Phishing อาศัยบริการของ Google สร้างลิงก์ส่งต่อหลายทอดเพื่อขโมยข้อมูลและควบคุมเครื่อง

      พบแคมเปญ Phishing อาศัยบริการของ Google สร้างลิงก์ส.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ec8cec7e-88dd-44ae-9b63-6f62af7aa697-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 10 September 2026

      Industrial Sector

      • ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
        "Industrial giants Schneider Electric, Siemens, and Aveva have published September 2026 Patch Tuesday advisories, informing customers about vulnerabilities found in their ICS products. Schneider Electric published four new security advisories and updated four others, including one originally released in 2019. The most severe of the newly addressed issues is a critical authentication vulnerability in Modicon M580 and Modicon M580 Safety controllers. Tracked as CVE-2026-3869, the flaw has a CVSS score of 9.2."
        https://www.securityweek.com/ics-patch-tuesday-schneider-electric-siemens-fix-critical-flaws/

      New Tooling

      • AI-Infra-Guard: Open-Source Security Scanner For AI Systems
        "Tencent’s Zhuque Lab built AI-Infra-Guard, an open-source security scanner for AI systems. It fingerprints running services such as Ollama, vLLM and ComfyUI and checks them against more than 1,600 known CVEs, inspects MCP servers and agent skills across 14 categories of risk, and runs jailbreak evaluations against a target model. To check a skill, the platform asks a language model whether it looks malicious. Zhuque Lab scores that call against SkillTrustBench, a public set of 5,520 human-labeled samples across nine risk categories. False positive rates there run from 1.20 percent to 18.67 percent, depending on which model does the judging."
        https://www.helpnetsecurity.com/2026/09/09/ai-infra-guard-open-source-security-scanner-ai-systems/
        https://github.com/Tencent/AI-Infra-Guard

      Vulnerabilities

      • Active Exploitation Of Cisco Secure Firewall Management Center Vulnerabilities
        "Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account."
        https://blog.talosintelligence.com/fmc-ongoing-exploitation/
        https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/
      • Fortinet Patches Critical Vulnerabilities In FortiMonitorOnSight, Chrome Extension
        "Fortinet on Tuesday released patches for 10 vulnerabilities across its products, including critical security defects. The first critical bug, tracked as CVE-2026-84390 (CVSS score of 9.6), is described as an inclusion of sensitive information in source code issue affecting the FortiMonitorOnSight web portal. A remote, unauthenticated attacker could exploit the flaw to bypass authentication via a forged or reused JSON Web Token (JWT). The second critical vulnerability is an improper authentication issue in the Fortinet Privileged Access Agent Chrome extension, tracked as CVE-2026-84388 (CVSS score of 9.1)."
        https://www.securityweek.com/fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension/
      • Ivanti Patches Critical Flaws Across Enterprise Security Products
        "Ivanti on Tuesday announced security updates that address vulnerabilities rated critical and high severity in its Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM) products. Neurons for ITSM received fixes for the largest number of security defects. Of the eight bugs, six are critical-severity issues that could lead to remote code execution, Ivanti warns. These include CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646 (CVSS score of 9.9/10), described as missing authorization issues; and CVE-2026-12650 (CVSS score of 9.9/10), CVE-2026-12744, and CVE-2026-12745 (CVSS score of 9.8/10), described as deserialization of untrusted data weaknesses."
        https://www.securityweek.com/ivanti-patches-critical-flaws-across-enterprise-security-products/
      • Google Fixes Yet Another Actively Exploited Chrome Zero-Day (CVE-2026-87491)
        "Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. “Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in a Tuesday security advisory. The fix has been shipped in Chrome 153.0.8010.36 and .37 for Windows and macOS and Chrome 153.0.8010.36 for Linux."
        https://www.helpnetsecurity.com/2026/09/09/google-chrome-cve-2026-87491-zero-day-flaw/
        https://www.bleepingcomputer.com/news/security/google-patches-seventh-chrome-zero-day-exploited-in-attacks-this-year/
        https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html
        https://www.securityweek.com/chrome-153-patches-seventh-zero-day-of-2026/
        https://securityaffairs.com/198757/security/google-fixes-the-seventh-actively-exploited-chrome-zero-day-of-2026.html
      • DeepSeek Harness < 0.1.2-Alpha.1 Authentication Bypass Via Host Header Spoofing
        "DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP control-plane API that allows attackers to gain full agent control by supplying a spoofed Host header, as the server validates only the client-supplied Host header value rather than the actual TCP connection origin. Attackers can exploit this flaw to invoke privileged commands such as commands/execute with danger-full-access permissions, escalate session approval policies to unconfined execution, and retrieve all stored conversations without any credential or API key."
        https://www.vulncheck.com/advisories/deepseek-harness-alpha-1-authentication-bypass-via-host-header-spoofing
        https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html
      • Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
        "Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through v1.18.5, all released before August 2025, and Alby said one user has been affected so far."
        https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html
      • CISA Adds Four Known Exploited Vulnerabilities To Catalog
        "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
        CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
        CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability
        CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog
      • Skullcandy Dime 3 Wireless Earbuds Contain An Unauthenticated Bluetooth Pairing Vulnerability
        "Skullcandy Dime 3 wireless earbuds, running firmware version 1.0.0.28, accept a new Bluetooth Classic (BR/EDR) pairing request from an unpaired device without requiring the earbuds to be placed into pairing mode or requiring any physical confirmation or interaction from the owner."
        https://kb.cert.org/vuls/id/859658
        https://www.bleepingcomputer.com/news/security/skullcandy-dime-3-earbuds-expose-users-to-bluetooth-hijacking/
      • Over 36,000 Exposed Plex Servers Vulnerable To Recent Flaws
        "Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. Plex urged users a week ago to secure their media servers immediately against security issues that still lack CVE IDs for easy tracking. While the company didn't provide additional details on Tuesday when it issued the warning, these security flaws are known to affect Plex Media Server v1.43.2 and earlier."
        https://www.bleepingcomputer.com/news/security/over-36-000-plex-servers-unpatched-against-recently-disclosed-flaws/
      • New Microsoft Defender 'ShieldCrash' Zero-Day Grants SYSTEM Access
        "An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. ShieldCrash is described as a bypass for the ShieldBreak Defender privilege escalation flaw patched on Thursday, which itself bypassed RoguePlanet, another Defender flaw disclosed in June and patched by Microsoft in July."
        https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldcrash-zero-day-grants-system-access/
        https://thehackernews.com/2026/09/researcher-drops-new-microsoft-defender.html
        https://securityaffairs.com/198726/security/chaotic-eclipse-released-shieldcrash-a-poc-for-microsoft-defender-zero-day.html
        https://www.theregister.com/security/2026/09/09/serial-microsoft-0-day-hunter-drops-yet-another-defender-exploit/5295335
      • Android’s September 2026 Updates Patch 180 Vulnerabilities
        "After two ‘no security vulnerabilities’ bulletins in July and August, Google on Tuesday announced the release of patches for 180 vulnerabilities as part of the September 2026 Android security updates. As usual, the updates are split into two parts. The first part arrives on devices as the 2026-09-01 security patch level and resolves 95 bugs across Android runtime, Framework, System, Setup Wizard, and multiple Project Mainline components (patched via Google Play system updates). “The most severe of these issues is a critical security vulnerability in the System component that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation,” Google notes in its advisory."
        https://www.securityweek.com/androids-september-2026-updates-patch-180-vulnerabilities/
      • Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories
        "Major chipmakers AMD, Arm, and Nvidia published new security advisories on Tuesday to notify customers of vulnerabilities recently discovered in their products. AMD announced fixes for CVE-2026-43603, a NULL pointer dereference flaw in its Linux GPU kernel driver that could lead to system crashes and a denial-of-service (DoS) condition. The company credited Maxime Rossi Bellom and Ramtine Tofighi Shirazi from SecMate for reporting the security defect."
        https://www.securityweek.com/chipmaker-patch-tuesday-nvidia-amd-arm-issue-security-advisories/
      • New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code As Root
        "cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected. The flaw is tracked as CVE-2026-67401. cPanel's advisory calls it an SQL injection issue in EmailTrack, but does not say which cPanel feature or privilege an account needs. cPanel's developer documentation lists an EmailTrack module that tracks email statistics, and the advisory does not say whether that is the affected code."
        https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html
      • One Blank Field Bypasses Direct Send Control
        "ReliaQuest observed that an empty Simple Mail Transfer Protocol (SMTP) envelope sender can bypass RejectDirectSend, a Microsoft 365 control in Exchange Online intended to block unauthenticated Direct Send emails from an organization’s domain. An external sender can omit the envelope domain while retaining an internal-looking address, making phishing messages more likely to be trusted. Direct Send allows devices and applications to send email to recipients in the same Microsoft 365 tenant without authentication. RejectDirectSend evaluates the domain in the SMTP envelope sender, but an empty value means there’s no domain to check. In testing, changing only this field caused Microsoft 365 to accept and queue a message it otherwise rejected."
        https://reliaquest.com/blog/threat-spotlight-one-blank-field-bypasses-direct-send-control

      Malware

      • Once In a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome And Windows Zero-Days
        "Beginning in late August and continuing into September 2026, Proofpoint identified multiple espionage-motivated threat actors rapidly adopting the BlueMoon exploit kit in targeted spearphishing campaigns. Several characteristics of this activity are consistent with a capability that was opportunistically adopted and deployed ahead of an anticipated patch. While the chain exploited vulnerabilities present in the latest stable versions of Chrome and Chromium-based browsers (such as Microsoft Edge), it was paired with a Windows LPE vulnerability present only in older Windows builds. This pairing substantially narrows the pool of viable targets and reduces the chain's overall probability of success."
        https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit
        https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html
        https://therecord.media/china-hackers-chrome-browser-zero-day-multiple-groups
        https://cyberscoop.com/china-espionage-groups-exploit-chain-zero-days/
        https://www.theregister.com/research/2026/09/09/novel-blue-moon-kit-targeting-chrome-and-windows-reflects-new-reality-of-ai-driven-exploits/5295399
      • Workflow Identity Hijacking: The Silent Backdoor In AI Workflows
        "An attacker sends a benign message to a company’s public support email. Minutes later, the attacker receives the quarterly sales numbers from the Finance Director's most recent email. The company's AI workflow read the message, understood the request, searched for the requested information, and replied. No prompt injection was required, no account was breached, and no workflow was hijacked. All the attacker had to do was ask."
        https://noma.security/noma-labs/workflow-identity-hijacking-the-silent-backdoor-in-ai-workflows
        https://www.darkreading.com/threat-intelligence/identity-based-ai-attack-security-enterprise-data
      • Vwork: Weaponized Open-Source Software As An Addon For Gigabud
        "During the “Hook for Gold” research, Group-IB discovered an application called Vwork that was installed within minutes after initial Gigabud infection along with tampered banking applications. Trials to find a sample of Vwork lead to Gigabud samples that are intentionally built to interact with Vwork. The significance of this finding meant that Vwork on infected devices cannot be considered a coincidence anymore. This article reveals what Vwork is, and how it is related to Gigabud."
        https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
        https://www.infosecurity-magazine.com/news/gigabud-android-app-cloning-fraud/
      • Threat Spotlight: Phishing Pages That Exist Only Inside The Victim’s Browser
        "Most phishing campaigns rely on a hosted webpage that security tools can retrieve, analyze, categorize, and eventually block. A recent campaign analyzed by Barracuda researchers breaks that model. Instead of delivering a phishing page from a web server, the malicious content is assembled inside the victim’s browser using a blob URL — a temporary browser-generated URL that points to content stored locally in memory rather than on a website. By the time the phishing page appears, the victim has already been routed through legitimate Microsoft services, including Microsoft OAuth and Microsoft Teams, with little visible indication that anything malicious is taking place."
        https://blog.barracuda.com/2026/09/09/browser-based-phishing-blob-urls-microsoft-redirects
        https://www.securityweek.com/new-phishing-attack-creates-malicious-pages-inside-the-victims-browser/
      • Signing In Without Actually Signing In
        "The price of AI tokens and subscriptions is increasing as AI model providers seek to recoup investment costs. As a result, these accounts are becoming more valuable targets for account takeover. Stopping this is paramount for enterprises. AI theft increases token bills. In three recent cases, it was to the tune of nearly $1 million for one organization, a shock $25,000 bill for a software architect and $600,000 in AI credits for an AI testing organization due to a stolen API key. Some AI providers are detecting this abuse and automatically logging affected users out and removing their payment cards on record to limit the damage. Malware developers and phishing operators have shown interest in applying AI to their operations, and attackers have been documented using stolen AI inference."
        https://www.okta.com/blog/threat-intelligence/signing_in_without_actually_signing_in/
        https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html
      • Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
        "A recent Unit 42 investigation into seemingly low-priority enterprise infections demonstrates how the most effective camouflage in cybercrime is not necessarily in the use of sophisticated techniques, but in how unremarkable the threat appears. The activities that we investigated would typically not require escalation or further inquiry. But upon closer inspection, we discovered a massive cybercrime campaign largely targeting young gamers. Tracked as CL-CRI-1171, in accordance with Unit 42’s attribution framework, the group behind this cluster has operated under the radar for at least two years, distributing an indeterminate number of payloads."
        https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
      • Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
        "GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. GreyNoise has been tracking malicious use of 45[.]142[.]193[.]132 since early July 2026 due to its use for attacks against internet facing technologies and devices from Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE."
        https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf

      Breaches/Hacks/Leaks

      • AdaptHealth Confirms 4.1 Million People Exposed In July Cyberattack
        "Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. The company provides home medical devices, supplies, and related services, including sleep-apnea and respiratory equipment, oxygen therapy, hospital beds, and mobility products. AdaptHealth first disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC) on July 2, 2026, informing that attackers accessed its systems and exfiltrated private data."
        https://www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-people-exposed-in-july-cyberattack/
      • Veradigm Warns Of Patient Data Breach After Ransomware Gang Claims Attack
        "Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. The company says the incident did not cause operational disruptions but affected a small number of customers. Formerly known as Allscripts Healthcare Solutions, Veradigm is a Chicago-based healthcare technology company that supplies medical practices with electronic health records, e-prescribing, patient-engagement, practice-management, and revenue-cycle software."
        https://www.bleepingcomputer.com/news/security/veradigm-discloses-patient-data-breach-after-gentlemen-gang-claims-attack/
        https://therecord.media/electronic-health-record-company-says-customer-data-stolen-in-breach

      General News

      • August 2026 Cyber Threat Landscape: GenAI Data Exposure Emerges As a New Enterprise Risk As Attacks, Phishing, And Ransomware Accelerate
        "August showed that cyber risk is intensifying on multiple fronts at once. Global attacks continued to rise, ransomware volumes accelerated, and phishing remained a consistent entry point for threat actors. GenAI added a more nuanced but equally important signal: while August recorded the lowest rate of high-risk for data exposure in GenAI prompts in several months, enterprise AI usage continued to expand sharply, with the average number of prompts per user rising from around 78 in June to 95 in July and 106 in August."
        https://blog.checkpoint.com/security/august-2026-cyber-threat-landscape-genai-data-exposure-emerges-as-a-new-enterprise-risk-as-attacks-phishing-and-ransomware-accelerate/
      • FBI Officials Say AI Is Bolstering Adversaries, Emphasizing Need To Focus On Cyber Basics, Patching
        "Artificial intelligence is souping up the speed and capabilities of malicious hackers, a top FBI official said Tuesday. And the speed of vulnerability discoveries is forcing organizations to patch more frequently, said another top FBI official. The officials made their remarks one day before the release of a new FBI cyber strategy Wednesday, which touches on AI, relief and justice for victims and other bureau priorities. Speaking to both CyberScoop and at the Billington CyberSecurity Summit, Jason Bilnoski, deputy assistant director of the FBI’s cyber division, said AI is “taking actors to the next level.”"
        https://cyberscoop.com/fbi-cyber-strategy-ai-threats-patching/
      • The Anthropic Glasswing Receipts Are Starting To Trickle In
        "Anthropic’s Project Glasswing is approaching 5 months old, and Anthropic published its Vulnerability Disclosure Ledger on May 22nd. It hadn't received an update until this past week, when it backfilled the ledger with additional findings and updates, so naturally I thought it would be worthwhile to take a look at the receipts. For a bit more context, I've been tracking Project Glasswing since they launched the project on April 7, and have published a series of blog posts covering the project:"
        https://www.vulncheck.com/blog/anthropic-glasswing-receipts
        https://www.darkreading.com/application-security/mythos-vulnerability-firehose-hits-human-bottleneck
      • Gartner: 70% Of SOCs Will Pilot AI Agents. Only 15% Will See Results
        "In the Gartner report Validate the Promises of AI SOC Agents With These Key Questions, analysts Craig Lawson and Andrew Davies posit that “By 2028, 70% of large SOCs will pilot AI agents to augment Tier 1 and Tier 2 operations, but only 15% will achieve measurable improvements without structured evaluation.” Just last year, Gartner placed AI SOC Agents at the Innovation Trigger stage with single-digit adoption. As of earlier this year, Gartner’s Hype Cycle for Security Operations, 2026 put them at the Peak of Inflated Expectations."
        https://www.helpnetsecurity.com/2026/09/09/prophet-security-evaluating-ai-soc-agents/
      • 2026 SpyCloud Identity Threat Report
        "Identity exposure is measurable and fixable – yet most organizations are still navigating with an outdated map, drawn for marked trails rather than the backcountry attackers now roam. The terrain has expanded past employee credentials to session tokens, non-human identities, and third-party ecosystems, and closing the gap means surveying what’s exposed beyond the camp’s edge before attackers get there first. This year’s Identity Threat Report [1] – a survey of security leaders and practitioners across North America, UK and select European Markets – benchmarks how enterprise organizations detect, remediate, and govern identity threats – and what separates the most mature programs from the rest."
        https://spycloud.com/resource/report/identity-threat-report-2026/
        https://www.infosecurity-magazine.com/news/nhis-number-one-corporate-entry/
      • This Key Will Self-Destruct: An Open Standard For Revocable API Keys
        "Every security leader has lived some version of this incident. A researcher, a scanner, or a well-meaning stranger finds one of your API keys sitting in a public repository. Now the clock is running, but instead of a kill switch, what follows is a scavenger hunt. Which company issued this key? Who do I contact? Is there a security.txt? Does anyone read that inbox? By the time the right person revokes the right credential, hours or days have passed, and attackers needed minutes. Bots scrape public repos constantly, and the majority of leaked secrets are still active years later."
        https://www.securityweek.com/this-key-will-self-destruct-an-open-standard-for-revocable-api-keys/
      • Scam Center Strike Force Conducts Seizures Of Chinese-Run Illicit Scammer Marketplace, And Restrains $52 Million In Laundered Crypto Scammer Funds In One Day
        "U.S. Attorney Jeanine Ferris Pirro, together with major federal law enforcement and interagency partners, announced actions taken by the Department of Justice’s Scam Center Strike Force to secure America against Southeast Asian cryptocurrency-related fraud and scams. The Strike Force and the Department of the Treasury took coordinated actions against Xinbi Guarantee (“Xinbi”), an illicit marketplace for scam services, and the Strike Force deployed to Madagascar to assist in the taking down of 13 Chinese-run scam compounds. Approximately $52 million of cryptocurrency involved in scam money laundering was restrained in one day, bringing the total restrained by the Scam Center Strike Force to approximately $938 million."
        https://www.justice.gov/usao-dc/pr/scam-center-strike-force-conducts-seizures-chinese-run-illicit-scammer-marketplace-and
        https://thehackernews.com/2026/09/us-disrupts-xinbi-guarantee-scam.html
        https://therecord.media/us-disrupts-xinbi-guarantee-marketplace-cybercrime

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) c1c561a3-1bce-4607-94f6-362419364e87-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 09 September 2026

      Industrial Sector

      • CareCam Pro IP Cameras
        "Successful exploitation of this vulnerability could allow an attacker to take full control of the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-251-01

      Vulnerabilities

      • Microsoft September 2026 Patch Tuesday Fixes 966 Flaws, 2 Zero-Days
        "Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. This Patch Tuesday addresses 105 "Critical" vulnerabilities, 81 of which are remote code execution, 20 are elevation of privileges, 2 are information disclosure, and 1 security feature bypass."
        https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/
        https://blog.talosintelligence.com/microsoft-patch-tuesday-for-september-2026/
        https://www.darkreading.com/vulnerabilities-threats/patch-tuesday-another-record-974-cves
        https://therecord.media/microsoft-patch-tuesday-september-2026
        https://cyberscoop.com/microsoft-patch-tuesday-september-2026/
        https://www.securityweek.com/microsoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days/
      • SAP Warns Of Maximum Severity 'OVERPASS' Kernel Vulnerability
        "SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. Tracked as CVE-2026-44756 and dubbed OVERPASS by Onapsis security researchers who reported it, the vulnerability stems from a classic buffer overflow weakness in the Extended Passport Protocol (EPP) processing library. Successful exploitation lets unprivileged threat actors run arbitrary commands on vulnerable SAP hosts with administrative privileges, leading to full compromise of the underlying SAP processes and business data."
        https://www.bleepingcomputer.com/news/security/sap-warns-of-maximum-severity-overpass-kernel-vulnerability/
        https://onapsis.com/blog/sap-overpass-remediation/
        https://www.securityweek.com/sap-patches-critical-extended-passport-processing-vulnerability/
      • Adobe Fixes Critical Magento Zero-Day Exploited To Backdoor Servers
        "Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. E-commerce security company Sansec discovered that the flaw has been leveraged in attacks since at least September 4 to plant a backdoor on vulnerable websites. The backdoor disguised its command-and-control (C2) host as a regular Network Time Protocol (NTP) server. However, it still leaves distinct signs of activity on compromised hosts, such as "Payment Transaction Failed Reminder" emails."
        https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-magento-zero-day-exploited-to-backdoor-servers/
        https://helpx.adobe.com/security/products/magento/apsb26-146.html
        https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html
      • Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
        "Adobe has released patches for more than 170 vulnerabilities across its products, including urgent hotfixes for a critical-severity flaw in Adobe Commerce and Magento Open Source that has been exploited in the wild as a zero-day. Tracked as CVE-2026-75650 (CVSS score of 10/10), the flaw is a code injection issue that can be exploited without authentication for remote code execution (RCE)."
        https://www.securityweek.com/adobe-patches-over-170-vulnerabilities-including-commerce-zero-day/
      • FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
        "A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The FreeIPA project has already fixed its side in version 4.13.4. Red Hat says it reproduced the chain twice on a default installation, most recently on a machine with no access at all."
        https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html
      • CISA Adds Four Known Exploited Vulnerabilities To Catalog
        "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
        CVE-2026-81963 Microsoft Windows Link Following Vulnerability
        CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability
        CVE-2026-86218 N-able N-central Static Code Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog

      Malware

      • China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
        "China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) (hereafter referred to as the authoring agencies) are releasing this joint Cybersecurity Advisory to alert organizations about these malicious activities and techniques and recommend mitigations to reduce their potential impact."
        https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a
        https://cyberscoop.com/us-accuses-chinese-ai-companies-distillation/
        https://www.bankinfosecurity.com/us-warns-chinese-ai-firms-are-illicitly-distilling-models-a-32773
      • DoppelCart: 119,000 Domains In What May Be The Largest Documented Fake-Shop Network
        "Around 119,000 domains, connected by shared infrastructure and recurring features in their shop software. Product catalogs from real businesses, copied descriptions and original images. And customers whose complaints end up with the legitimate store. We investigated a fake-shop network whose scale surprised even us. We call it DoppelCart. To our knowledge, DoppelCart is the largest fake-shop cluster publicly documented to date, measured by the number of associated domains. Its .shop domains alone account for 2.72 percent of the .shop domain population in our snapshot. That is roughly one in every 37 domains."
        https://nebty-id.com/en/doppelcart-fake-shop-network/
        https://www.bleepingcomputer.com/news/security/doppelcart-fraud-network-uses-119-000-fake-shops-to-steal-credit-cards/
      • Dissecting a PHP Web Server Rootkit
        "SophosLabs recently acquired a Linux implant associated with compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components. The malware demonstrates advanced techniques including custom ELF loading, function hooking, and runtime code patching to evade detection while maintaining persistent access through hidden web shells. The implant delivers a familiar outcome – on-demand server‑side code execution commonly associated with web shells – but implements it using deeper Linux- and Apache‑specific tradecraft."
        https://www.sophos.com/en-us/blog/dissecting-a-php-web-server-rootkit
        https://www.bleepingcomputer.com/news/security/hackers-breach-f5-big-ip-apm-devices-to-deploy-linux-rootkit/
      • ClearFake WebDAV Infection Chain Delivers Amatera Stealer, ZigCryptoStealer, And NetSupport Manager
        "Cisco Talos began an investigation after observing a DLL named "verification.google" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload. Pivoting around the similar WebDAV behavior led to a second loader named "pf.ch" and allowed us to reconstruct its earlier delivery stages. The chain uses a Cloudflare Worker to inject JavaScript code stored on BNB Smart Chain and a ClickFix prompt impersonating Google CAPTCHA, leading to download and execution of Amatera stealer. The chain is likely very similar to what has caused the WebDAV-based execution at the Ukraininan government organization."
        https://blog.talosintelligence.com/clearfake-webdav-infection-chain/
      • ClickFix Moves Into The Browser: Cryptocurrency Theft With Google-Hosted C2
        "Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session. The actors use a variation on ClickFix social engineering. Instead of convincing targets to run commands against the operating system, they convince targets to paste JavaScript into the Chrome address bar or install it into the Tampermonkey browser extension, which also provides persistence."
        https://blog.talosintelligence.com/clickfix-moves-into-the-browser/
        https://www.darkreading.com/endpoint-security/clickfix-campaigns-legitimate-services-persistent-access
      • Bypassing The Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure Into a Trust Proxy
        "In addition to everyday users, Google's infrastructure is trusted by email security gateways, enterprise firewalls and automated URL detonation platforms. Threat actors know this. In this KnowBe4 Threat Lab analysis, we break down an active, wide-scale phishing campaign that routes victims through a deliberate chain of legitimate Google services before landing them on credential harvesters or deploying remote access tools. The execution here is unusually complete: six distinct Google properties abused across multiple redirect paths, a landing page that dynamically impersonates the victim's own organization in real time, and a dual-track post-redirect architecture that delivers either credential theft or persistent remote access depending on the lure context."
        https://blog.knowbe4.com/bypassing-the-gatekeepers-how-a-global-phishing-campaign-turns-googles-infrastructure-into-a-trust-proxy
        https://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaign
      • Hagaseca: Inside a Packed Android RAT Loader
        "Hagaseca is an Android malware cluster associated with exposed Android Debug Bridge (ADB) services. This analysis examines the Hagaseca Android RAT loader known as THost9. RAT stands for remote access trojan. A RAT can let an attacker control an infected device remotely. The loader hides executable code inside an Android application package (APK). It then loads tc9.dex, a separate stage with shell access, file transfer, and ADB propagation capabilities."
        https://darkatlas.io/blog/hagaseca-inside-a-packed-android-rat-loader
        https://www.infosecurity-magazine.com/news/thost9-android-rat-packed-loader/
      • WeWorm
        "At Calif, our mission is to keep the Internet together by occasionally taking it apart. We believe everyone deserves a safe and secure Internet, including the people who cannot protect themselves. Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. This is the first installment in a series exploring zero-click attack surfaces in mobile messaging apps. WeChat is an "everything app" used by virtually everyone in China and by Chinese communities worldwide. Simply by calling a victim, WeWorm can hijack their account and call their friends, spreading from phone to phone. If exploited, actors can compromise over a billion phones (or accounts), upending livelihoods and breaking communities worldwide."
        https://calif.io/research/weworm
        https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html
        https://securityaffairs.com/198688/hacking/wechat-worm-can-hijack-accounts-without-victims-answering-calls.html
        https://www.helpnetsecurity.com/2026/09/08/wechat-weworm-vulnerability-exploit-account-hijacking/
      • Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
        "A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment service Pix, digital asset platforms, and financial entities' cloud environments," CrowdStrike said."
        https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html
        https://go.crowdstrike.com/rs/281-OBQ-266/images/CrowdStrike-2026-Threat-Hunting-Report.pdf
      • BengalSEO Part 1: Anatomy Of The Operation
        "In March 2026, our team identified an SEO poisoning campaign leading to malware deployment and tech support scams. Further research into this campaign revealed a sophisticated and widespread scam operation that has been operating since at least 2015. Our team attributes this operation, with high confidence, to a group of core individuals and IT service providers operating out of Rajasthan, India, which our team tracks collectively as BengalSEO. Using indicators gathered from the identified SEO poisoning campaign, our team was able to correlate this activity with information posted on scam hunting forums. This discovery led our team to a company named WeConnect Solutions LLC (previously iConnect Soft Solutions LLC), which operates a tech support call center located in Kota, Rajasthan."
        https://thedfirreport.com/2026/08/24/bengalseo-part-1-anatomy-of-the-operation/
        https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html
      • Anatomy Of a Layered, Multi-Brand Phishing Campaign
        "Barracuda Research has analyzed a multi-layered, multi-brand phishing campaign that reflects a trend for attackers to embed authentication requests inside familiar business workflows. Similar to platforms such as Kali365, which we recently reported on, the objective is to make authentication appear a routine step in a document-sharing, signing or collaboration process. However, unlike Kali365’s device-code phishing and token-focused attacks, this campaign relies on browser-in-the-browser (BitB) deception to harvest credentials directly."
        https://blog.barracuda.com/2026/09/08/browser-in-the-browser-phishing-docusign-adobe-microsoft

      Breaches/Hacks/Leaks

      • ShinyHunters Hackers Claim Breach Of Florida "DAVID" DMV Database
        "The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state. As proof of the breach, the threat actor has released a screenshot of Jeffrey Epstein's DMV record, including his address and registered vehicles. DAVID is the "Driver and Vehicle Information Database" platform operated by the Florida Highway Safety and Motor Vehicles (FLHSMV) agency, used by law enforcement and officials to look up information about a particular driver."
        https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/
        https://hackread.com/shinyhunters-florida-dmv-breach-jeffrey-epstein-proof/
      • 220 Million Traveler Records Exposed In Vietnam-Linked APIS Leak
        "An Advance Passenger Information System (APIS) database holding more than 220 million passenger and crew records, including passport numbers and flight details, was accessible online through a chain of security misconfigurations. The system appears linked to a Vietnamese organization, according to the researchers who discovered it. Advance Passenger Information Systems are used worldwide to collect identity, passport, and flight information from airlines before passengers and crew arrive at or depart from a country."
        https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/
        https://securityaffairs.com/198671/data-breach/massive-vietnam-linked-apis-database-exposes-passport-and-flight-data.html
      • Cyberattack Encrypts Systems At Bavarian Municipal Utility
        "A municipal utility in Bavaria said Monday that hackers encrypted its central IT network in a cyberattack last week. In a notice to customers, Stadtwerke Landsberg said the attack disrupted office systems but is not affecting electricity, water and other essential services. The incident began overnight on September 1, the utility said, prompting it to disconnect the affected systems from the internet, activate its crisis team and bring in external cybersecurity specialists."
        https://therecord.media/cyberattack-bavaria-germany-utility

      General News

      • GTIG AI Threat Tracker: From Prompting To Autonomy – The Evolution Of Adversarial AI
        "Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, build, and execute an agent-enabled mass credential harvesting campaign in under six hours. We also tracked UNC6780 using multiple tactics to trick AI coding assistants and large language model (LLM) security scanners into its open source software supply chain compromises."
        https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai
        https://www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-credential-theft/
        https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html
        https://www.infosecurity-magazine.com/news/ai-coding-tools-threat-actors/
        https://www.theregister.com/research/2026/09/08/extortion-crews-have-their-eyes-on-high-value-ai-data-google-warns/5294640
        https://www.helpnetsecurity.com/2026/09/08/ai-agents-cyberattacks-automation-google-research/
      • ChatGPT Let Attackers Read Victims’ Gmail Through a Hidden Channel Between Accounts
        "Enterprises are connecting AI assistants to more of their real infrastructure every month, from inboxes to file drives to internal tools, on the assumption that the isolation between users and accounts holds. Check Point Research just tested that assumption against ChatGPT and found a way to break it. Using an internal service that was never meant to carry user data at all, CPR opened a working channel between two completely separate ChatGPT accounts and used it to hand one victim’s session a task from a total stranger, all while the victim’s own conversation looked entirely normal."
        https://blog.checkpoint.com/research/chatgpt-let-attackers-read-victims-gmail-through-a-hidden-channel-between-accounts/
        https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/
        https://thehackernews.com/2026/09/chatgpt-flaw-let-planted-prompt-send.html
      • Russian National Extradited To United States For Bank Account Takeover Fraud Scheme Causing Millions Of Dollars In Losses
        "Sergei Anatolyevich Filimonov, 36, a Russian national and web developer who was allegedly involved in a transnational cyber‑fraud conspiracy responsible for large‑scale bank account takeover activity, was arraigned Friday in the Northern District of Georgia after being extradited from the Republic of Georgia. Filimonov was indicted by a federal grand jury on Nov. 4, 2025, for charges relating to a credential‑harvesting and bank‑fraud operation that targeted victims across the United States."
        https://www.justice.gov/opa/pr/russian-national-extradited-united-states-bank-account-takeover-fraud-scheme-causing
        https://therecord.media/russian-cybercrime-bank-extradition
        https://cyberscoop.com/russian-national-extradited-bank-account-takeover-sergei-filimonov/
      • Scammer Behind $245 Million Crypto Heist Pleads Guilty To RICO Charges
        "A Singaporean national pleaded guilty to racketeering charges on Tuesday for his role leading a group of scammers who stole more than $245 million in cryptocurrency. Malone Lam, 22, will appear in U.S. District Court in Washington D.C. on December 8 for more information on sentencing. Participating in a RICO conspiracy charges carry sentences ranging from 7 to 20 years. Lam was indicted on scamming charges in September 2024 after drawing law enforcement scrutiny for parlaying stolen crypto into lavish Hamptons vacations, cars and private jets. Prosecutors said Lam, known as “Anne Hathaway,” or “$$$,” ran an operation where he and others would conduct social engineering scams to steal cryptocurrency."
        https://therecord.media/scammer-behind-245-million-crypto-heist-pleads-guilty-rico
        https://www.securityweek.com/partys-over-for-crypto-scammers-who-went-on-a-spending-spree-after-a-240-million-bitcoin-theft/
      • French Prosecutors Confirm Arrest Of Suspected ZeroBytes Hacker Behind Tax Cyberattack
        "French authorities detained an 18-year-old suspected member of the ZeroBytes hacking group over cyberattacks targeting the country's tax authority and other organizations, the Paris prosecutor's office confirmed to Recorded Future News. The suspect was arrested in the Paris region on August 18 and placed in pretrial detention two days later. A second suspect, who is under 16, was arrested on August 26 and later released while investigators examine his devices, prosecutors said Tuesday in response to a media inquiry."
        https://therecord.media/france-hacker-arrest-zerobytes

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) c1c561a3-1bce-4607-94f6-362419364e87-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบบริการฟิชชิง BigBear 2.0 ข้าม MFA ของ Microsoft 365 เพื่อสวมรอยเข้าถึงบัญชี

      พบบริการฟิชชิง BigBear 2.0 ข้าม MFA ของ Microsoft 365 เพื่อสว.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand eee2494d-c57d-4417-8304-67e4adfcb70e-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Mathspace แจ้งเหตุข้อมูลรั่วไหล กระทบนักเรียน บุคลากร และผู้ปกครองกว่า 1 ล้านราย

      Mathspace แจ้งเหตุข้อมูลรั่วไหล กระทบนักเรียน บ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 8b286300-759f-4d0e-b9fe-174c23bd34da-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • เตือนภัย การโจมตีทางโทรศัพท์แอบอ้างเป็นเจ้าหน้าที่ไอที เพื่อหลอกขโมยข้อมูลบนระบบ Microsoft 365

      เตือนภัย การโจมตีทางโทรศัพท์แอบอ้างเป็นเ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 6dc316d9-986e-400e-bbb9-64f78f791836-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ConnectWise เตือนปัญหา ScreenConnect กระทบการโอนไฟล์ระหว่างเซสชัน ยังไม่มีแพตช์แก้ไข

      ConnectWise เตือนปัญหา ScreenConnect กระทบการโอนไฟล์ระหว่.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 88f894b4-b567-47bc-a1dd-27fbdbb22ed0-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • N-able ออก Hotfix แก้ช่องโหว่ RCE ระดับร้ายแรงใน N-central

      N-able ออก Hotfix แก้ช่องโหว่ RCE ระดับร้ายแรงใน N-central.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 1007e661-c008-4c86-8c24-be87b088100d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • มัลแวร์ JSCeal สามารถหลีกเลี่ยงการตรวจสอบสิทธิ์ของ Google โดยใช้คุกกี้เซสชันที่ถูกขโมยมา

      มัลแวร์ JSCeal สามารถหลีกเลี่ยงการตรวจสอบสิทธ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand aadb2660-39db-44b6-8791-3e47d2e469d9-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 08 September 2026

      New Tooling

      • ToolHive: The Open-Source Way To Run Any MCP Server Securely
        "ToolHive is an open-source platform that runs Model Context Protocol servers inside containers. An MCP server is the connector that lets an AI client like Cursor or Claude Code reach an outside tool, and Stacklok ships ToolHive under Apache 2.0, so the runtime, the Kubernetes operator, and the registry cost nothing to self-host. A server you install by hand sits on the machine with the machine’s credentials and the machine’s network access. ToolHive drops each one into its own container with a minimal permission file and no local credentials attached. Point it at an authentication source and it starts enforcing identity and access policy per request, with audit logs to match. Don’t, and you have a sandbox and not much else."
        https://www.helpnetsecurity.com/2026/09/07/toolhive-open-source-mcp-server-security/
        https://github.com/stacklok/toolhive

      Vulnerabilities

      • N-Able Patches Max Severity N-Central Flaw Amid Ongoing Attacks
        "N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. IT departments and managed service providers (MSPs) use the N-central platform to monitor, manage, and maintain client networks and devices from a centralized web-based console. Tracked as CVE-2026-86218, this RCE vulnerability allows threat actors without privileges to execute malicious code on unpatched N-central instances exposed online in low-complexity attacks."
        https://www.bleepingcomputer.com/news/security/n-able-patches-max-severity-n-central-flaw-amid-ongoing-attacks/
        https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html
        https://www.infosecurity-magazine.com/news/nable-hotfix-critical-rce/
        https://www.helpnetsecurity.com/2026/09/07/n-able-n-central-hotfix-cve-2026-86218/
      • ConnectWise Warns Of New ScreenConnect Flaw Without Patch
        "ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week. ScreenConnect is an on-premises or cloud-hosted remote access platform typically used by managed service providers (MSPs), IT departments, and support teams for troubleshooting, patching, and system maintenance. The security flaw affects both cloud and on-premises deployments, and it has not yet received a CVE ID for easy tracking."
        https://www.bleepingcomputer.com/news/security/connectwise-warns-of-new-screenconnect-flaw-without-patch/
        https://thehackernews.com/2026/09/rogue-screenconnect-clients-spread-four.html
        https://www.securityweek.com/modified-screenconnect-clients-used-in-worm-like-campaign/
        https://www.helpnetsecurity.com/2026/09/07/connectwise-screenconnect-file-transfer-flaw/
      • LG TV Flaws Could Let Attackers Listen In, Even In Standby Mode
        "Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices. In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR)."
        https://www.malwarebytes.com/blog/privacy/2026/09/lg-tv-flaws-could-let-attackers-listen-in-even-in-standby-mode
      • Telerik UI Padding-Oracle Bug Chained To Unauthenticated RCE — Public Exploit Released
        "Security firm TantoSec has published a working exploit chain targeting vulnerabilities in Telerik UI for ASP.NET AJAX that can allow an unauthenticated attacker to execute remote code on the server hosting a vulnerable application. Progress Software patched the flaws in July, and exploitation requires a non-default configuration — but the release pairs a detailed write-up with a ready-to-run tool and two payloads, putting a complete attack path in public hands for the first time."
        https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html
      • Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
        "The security researcher known as Nightmare Eclipse has dropped three zero-day exploits targeting products from Avast, CrowdStrike, and Nvidia. Also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, the security researcher came to fame for a series of zero-day exploits targeting Microsoft’s products, but has recently moved to other vendors as well. In late August, Nightmare Eclipse released a privilege escalation zero-day in a Kaspersky endpoint security product. Dubbed HardBreacher, the exploit has been patched by Kaspersky on August 31."
        https://www.securityweek.com/nightmare-eclipse-drops-crowdstrike-nvidia-avast-zero-day-exploits/
        https://securityaffairs.com/198589/hacking/chaotic-eclipse-released-a-poc-for-nvidia-greensection-memory-corruption-zero-day.html

      Malware

      • Tracking BigBear 2.0 Evilginx2 Phishing Campaign
        "CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA."
        https://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign
        https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/
      • NoName057(16) Renews #OpJapan
        "On August 24, 2026, NoName057(16), a pro-Russian hacktivist collective active since 2022, best known for its crowdsourced DDoSia attack platform, announced the (re)launch of #OpJapan, a DDoS campaign against Japanese entities. Motivation is cited as Japan’s continued support for Ukraine and NATO amid the Russia-Ukraine war."
        https://blog.checkpoint.com/exposure-management/noname05716-renews-opjapan/
      • Beyond Lazarus: Organization Of DPRK Cyber Capabilities
        "The Democratic People's Republic of Korea (DPRK) has established itself as one of the more prominent state actors in cyberspace. For Pyongyang, cyber operations serve as an instrument of sanctions evasion, a means of projecting reach beyond a diplomatically and economically constrained periphery, and a source of revenue for a structurally weakened economy. These capabilities are the product of a deliberate strategy, considerably reinforced under Kim Jong-un, which situates information warfare at the centre of contemporary geopolitical confrontation."
        https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities
        https://www.infosecurity-magazine.com/news/north-korea-lazarus-six-cyber/
      • PEEP: A Browser RAT Posing As a Chrome Extension
        "The Threat Research Unit (STRU) at SOCRadar’s Extended Threat Intelligence (XTI) platform identified and analyzed PEEP, a Chromium-based emerging post-exploitation toolkit disguised as “Smart Bookmarks.” Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium’s own Secure Preferences integrity values. A native-messaging tool then extends it beyond browser telemetry to host-level command execution and file management."
        https://socradar.io/blog/peep-browser-rat-chrome-extension/
        https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html
      • Fake IT Calls Target Executives In Microsoft 365 Data Theft And Extortion Attacks
        "Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff, is being tracked by Arctic Wolf under the moniker PREY-0058, adding it shares significant tradecraft similarities with a data extortion group that Google-owned Mandiant calls UNC6671."
        https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html
        https://github.com/rtkwlf/wolf-tools/tree/main/pack_alerts/202609-cloud-data-theft-extortion-vishing-proxies
      • Breaking The Seal: Static Deobfuscation Of JSCeal’s Compiled V8 Bytecode
        "JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early 2025. Our previous publication from July 2025 [1] focused on the campaigns, delivery chain, and targeting. In this article, we focus on the analysis problem hidden inside the final payload."
        https://research.checkpoint.com/2026/breaking-the-seal-static-deobfuscation-of-jsceals-compiled-v8-bytecode/
        https://thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html
        https://securityaffairs.com/198573/malware/jsceal-hides-crypto-malware-in-v8-bytecode.html

      Breaches/Hacks/Leaks

      • Mathspace Discloses Data Breach Affecting Over 1 Million People
        "Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. Founded in Sydney in 2010, Mathspace is now used by thousands of schools across Australia, New Zealand, the United States, and the United Kingdom (3,432 in Australia and 3,557 abroad according to statistics reported by the company in 2023). In a Saturday blog post, Mathspace CTO Alvin Savoy said that unknown attackers gained access to the company's systems and stole personal information belonging to school staff and students, as well as their parents and guardians."
        https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/
      • Berlin Investigates New Data Leak After Hackers Publish Stolen Login Credentials
        "German authorities are investigating another trove of data stolen from Berlin’s government network after hackers published login credentials and other information over the weekend. The latest release follows a cyberattack discovered in mid-August that compromised two Berlin ministries responsible for urban development and housing, and for transport, mobility, climate protection and the environment. Berlin’s government said Sunday that the newly released data includes login credentials but did not say what systems they could be used to access or whether they were still valid. The authorities have not attributed the attack to a specific threat actor."
        https://therecord.media/germany-berlin-second-data-breach-city-agencies
        https://www.bankinfosecurity.com/berlin-responds-after-data-leaked-by-cyber-extortion-group-a-32763
        https://www.infosecurity-magazine.com/news/rhysida-berlin-data-extortion/
        https://securityaffairs.com/198545/cyber-crime/berlin-ransomware-leak-exposes-state-secrets.html
      • Hackers Drain $320M In Bitcoin From Liquid Network, Claim They're The Good Guys
        "Hackers have drained roughly $320 million in Bitcoin from the federation wallet backing the Liquid Network, while claiming to be the good guys. Liquid, a Bitcoin sidechain developed by Blockstream and used by exchanges and other financial institutions, said in a post on X on Sunday that around 4,000 BTC had been withdrawn from its federation wallet by what it cautiously described as "purported white-hat hackers.""
        https://www.theregister.com/security/2026/09/07/hackers-drain-320m-in-bitcoin-from-liquid-network-claim-theyre-the-good-guys/5294770
      • Condé Nast Data Of 32.8 Million Users Offered For Sale After WIRED Leak
        "A database said to contain 32.8 million Condé Nast user records is being offered for $15,000 on a Russian-language cybercrime forum. Ransomnews reviewed a 5,000-record sample and concluded that it is consistent with genuine Condé Nast account data collected between September and late October 2025, including records that have not appeared publicly before. Ransomnews’ original report provides the underlying analysis."
        https://securityaffairs.com/198628/data-breach/conde-nast-data-of-32-8-million-users-offered-for-sale-after-wired-leak.html

      General News

      • Qatar’s Digital Boom Has a Blind Spot: What The 2025-26 Threat Data Is Telling Us
        "Qatar is racing toward a knowledge-based, fully digital economy. Smart infrastructure, cloud-first government services, a financial sector that’s increasingly API-driven, and critical energy assets like QatarEnergy’s LNG operations layering more connected OT/ICS systems every year. That pace of transformation makes Qatar an attractive target in the cyber realm, right now. Attackers don’t need to compromise everything; they just need one high-value foothold, and Qatar’s expanding digital footprint keeps handing them more doors to try. This risk is showing up in the data as well."
        https://cyble.com/blog/qatar-digital-boom-blindspot/
      • Zero Trust AI Agents Demand a Different Kind Of Security
        "In this interview, Chris Webber, VP, Product Marketing at Teleport, explains why zero trust principles need to change for AI agents. He covers how agents act fast, unpredictably, and continuously, and why old ideas like least privilege and point-in-time verification fall short. Webber also discusses Teleport’s approach: trusted runtimes with zero starting privileges, and identity security that watches agent behavior in real time. He argues that security teams must move from spotting anomalies after the fact to enforcing rules at every step an agent takes."
        https://www.helpnetsecurity.com/2026/09/07/chris-webber-teleport-zero-trust-ai-agents/
      • 18 Ways To Check Whether Data Can Be Trusted For AI
        "ETSI has published TR 104 180, a technical report that defines 18 metrics for measuring data quality, giving companies a way to check whether their data is good enough for AI before they use it. The report defines each metric and includes the formulas needed to calculate it. The metrics fall into four groups. The first deals with the basics, whether data is complete, accurate, consistent, and free of duplicates. The second asks whether the data can be used, meaning it’s available when needed, documented well enough to trace back to its source, and up to date."
        https://www.helpnetsecurity.com/2026/09/07/etsi-ai-data-quality-metrics/
      • The Hidden Risks Of Shadow AI
        "Over the past few years, the use of artificial intelligence (AI) has grown rapidly in many workplaces with employees increasingly exploring how such tools can be incorporated into their jobs. AI can help people complete tasks more quickly, improve decision-making, save costs and increase productivity. However, organisations’ policies and guidance, which should reflect and manage the risks associated with using these new technologies, have not always developed at the same pace."
        https://www.ncsc.gov.uk/blogs/the-hidden-risks-of-shadow-ai
        https://www.infosecurity-magazine.com/news/ncsc-warns-shadow-ai-security-risks/
      • Why AI Agent Sandboxes Are Failing Security Tests
        "The recent case involving OpenAI test agents and Hugging Face should concern security teams, but not for the reason implied by headlines about an imminent AI “takeover.” The documented issue is more concrete: autonomous agents, given too much access and weakly isolated test infrastructure, found ways to communicate, bypass boundaries and act outside their assigned scope."
        https://securityaffairs.com/198563/ai/why-ai-agent-sandboxes-are-failing-security-tests.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) e72a3502-977c-4ab5-a551-b0a8188d2379-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 4 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/04/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 1d374e2e-ff1f-4266-a1c4-04f3ab63f292-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 07 September 2026

      Industrial Sector

      • IXON VPN Client
        "Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-02
      • Pyramid Solutions NetStaX EtherNet/IP Stack
        "Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-07
      • Inductive Automation Ignition
        "Successful exploitation of this vulnerability could allow any authenticated user to create projects."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-06
      • Tycon Systems TPDIN-Monitor-WEB3
        "Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08
      • OPCFoundation OPC UA LocalDiscoveryServer (LDS)
        "Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-01
      • Rockwell Automation ControlFLASH
        "Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-03
      • Rockwell Automation ArmorStart LT
        "Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-04
      • Rockwell Automation 1756-ENBT Module
        "Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-05

      Vulnerabilities

      • Critical Citrix NetScaler Auth Bypass Now Leveraged In Attacks
        "Attackers have begun targeting a critical-severity Citrix NetScaler flaw in the wild, according to vulnerability intelligence company Previdian. Tracked as CVE-2026-19490, this security flaw can allow unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured."
        https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/
      • Google Warns Of New Chrome Zero-Day Flaw Exploited In Attacks
        "Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. The exploited security issue, identified as CVE-2026-85046, is described as a type confusion. It was reported to Google by researcher Salvatore Gulizia, known online as “Serotav.” The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the advisory reads."
        https://www.bleepingcomputer.com/news/security/google-warns-of-new-chrome-zero-day-flaw-exploited-in-attacks/
        https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html
        https://www.securityweek.com/google-patches-6th-chrome-zero-day-of-2026/
        https://securityaffairs.com/198405/security/google-fixes-the-sixth-actively-exploited-chrome-zero-day-of-2026.html
        https://www.helpnetsecurity.com/2026/09/04/google-chrome-zero-day-cve-2026-85046/
      • StyleSmuggler: Magento And Adobe Commerce 0-Day RCE Under Active Attack
        "Sansec discovered StyleSmuggler, an unpatched Magento and Adobe Commerce zero-day that gives unauthenticated attackers remote code execution. All current versions are affected, including 2.4.9. Attacks started September 4th. Sansec is rolling out emergency mitigation."
        https://sansec.io/research/stylesmuggler
        https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html
      • Critical Vulnerabilities In MikroTik RouterOS Are Being Actively Exploited. Immediate Update Recommended
        "The CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS. Combining two of them allows an attacker to take full control of the device without authentication if the device supports remote access using the SSH protocol. To make this chain easier to identify, we have given it a common name, MikroTrick. In recent days we have been observing attacks against RouterOS devices accessible from the internet. We have obtained confirmation that the attackers are exploiting this combination of vulnerabilities to take full control of devices whose SSH service is accessible from public networks. It has also been confirmed that the released patches prevent the observed attacks. We recommend applying the update immediately."
        https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
        https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html
        https://securityaffairs.com/198538/security/your-mikrotik-router-may-already-be-compromised-look-for-ssh-user-2.html
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/04/cisa-adds-one-known-exploited-vulnerability-catalog
        https://securityaffairs.com/198455/security/u-s-cisa-adds-google-chromium-v8-flaw-to-its-known-exploited-vulnerabilities-catalog-2.html
      • PostGREShell: The Database Powering Much Of The Internet Had An Open Door For 12 Years
        "Imagine you've built a fortress. Guards at the front gate, scanners at every door, a guest list checked twice. You hired the best architects, ran the audits, passed the compliance reviews. By every measure, the place is locked down. But you missed something. Around the back, there's a small, unmarked entrance used by the cleaning crew. It's been there for years, and nobody thought to put a guard on it. Then one day, someone figures out that if you walk in through that entrance wearing a cleaning uniform, the entire fortress opens up: the armory, the vault, the control room. Once you're inside, everyone assumes you belong."
        https://www.cyera.com/research/postgreshell-the-database-powering-much-of-the-internet-had-an-open-door-for-12-years
        https://thehackernews.com/2026/09/postgresql-fixes-12-year-old-logical.html
        https://www.securityweek.com/12-year-old-postgresql-vulnerability-enables-database-server-takeover/
        https://securityaffairs.com/198433/security/postgresql-hit-by-12-year-old-vulnerability-allowing-server-takeover.html

      Malware

      • Attack Cases In Korea Involving The Installation Of Radmin And UltraVNC
        "The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases that exploited Radmin and UltraVNC. Although the Initial Intrusion method remains unknown, the attackers installed Radmin—a remote control tool—and then installed UltraVNC. The threat actors exploited the remote control tools to gain control of the infected systems and installed Netch and CCProxy to use the infected systems as proxy nodes. Recently, they have been installing SoftEther VPN to exploit the infected systems as VPN servers."
        https://asec.ahnlab.com/en/95230/
      • X Money Rollout Linked To Password-Reset Attacks
        "X says attackers may be targeting accounts because its X Money payments service is now more widely available. The company is investigating a wave of unsolicited password-reset emails sent to users. While their arrival alongside the wider X Money rollout has fueled account-takeover concerns, X says it has found no evidence of a breach or successful account takeovers so far."
        https://www.malwarebytes.com/blog/scams/2026/09/x-money-rollout-linked-to-password-reset-attacks
      • Angry Birds: Toy Ghouls’ New Toys
        "We continue tracking the activity of Toy Ghouls (also known as Bearlyfy, Laboo.boo, and Feral Wolf), a financially motivated group that has been targeting Russian organizations since 2025. The attackers initially relied exclusively on tools pulled from public GitHub repositories along with leaked Babuk and LockBit ransomware builders, later shifting to their own custom ransomware, GenieLocker. In early July 2026, we observed the group using a custom backdoor for the first time. We identified two versions of this backdoor: one uses the HiveMQ MQTT broker as its C2 server, while the other relies on the Element messenger."
        https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/
      • ASCII Smuggling Crosses Over From AI Prompt Injection To Phishing Evasion
        "Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling. Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as ‘funding’ to prevent email filters from parsing them. The finding emerged from Microsoft Defender for Office 365 prompt injection protection research, showing how AI-era evasion techniques can surface in traditional phishing campaigns. In Microsoft telemetry, hits on a hunting signature designed to detect ASCII-smuggling increased sharply beginning February 9, 2026, and remained elevated on weekdays for approximately three months. Microsoft Defender for Office 365 telemetry showed that the majority of messages were flagged by layered protections rather than by reliance on a single Unicode-specific signal."
        https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/
        https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html
        https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/
        https://www.theregister.com/security/2026/09/04/ascii-smuggling-isnt-just-an-ai-security-risk/5294595
      • DPRK APTs: Ted Backdoor And CurlRAT Target South Korean Media And Automotive Sectors
        "A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engage in long-term surveillance."
        https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/
        https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html
      • Attackers Actively Exploiting Critical Vulnerability In Super Forms Plugin
        "On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. The vendor released the fully patched version on July 8th, 2026, and we disclosed this vulnerability in the Wordfence Intelligence vulnerability database on July 9th, 2026. Our records indicate that attackers started exploiting the issue on July 14th, 2026, the same day we released the firewall rule. The Wordfence Firewall has already blocked over 250,000 exploit attempts targeting this vulnerability."
        https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-super-forms-plugin/
        https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html
      • Chinese-Speaking Operator Uses AI Agents To Target Government And Education Systems Across Asia
        "In July, we published research on a Chinese-speaking operator who embedded Claude Code and DeepSeek into intrusions across four countries. This is a second, separate campaign with different infrastructure, tooling, and targets, but the same pattern: commercial AI models used as operational components. Targets included Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam. The most extensive compromise hit a Fengtai District government environment, where the operator achieved command execution, collected LSASS and registry hives, accessed government and health records, and deployed multiple Windows implants. Separate activity exposed a Chinese education AI platform and obtained root database access to a university campus-card system."
        https://hunt.io/blog/chinese-operator-secflow-claude-qwen-deepseek-asia
        https://securityaffairs.com/198417/ai/chinese-hackers-use-ai-agents-in-multi-country-cyber-campaign.html
      • Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizations
        "Datadog Security Research observed a password spraying campaign targeting the AWS root user account. The campaign ran from July 24 to August 23, 2026. During this period, attackers made repeated failed authentication attempts against AWS root user accounts at more than 150 organizations. Organizations saw a median of two attempts each, with some experiencing up to eight attempts across the campaign window."
        https://securitylabs.datadoghq.com/articles/aws-root-user-bruteforce-campaign/
      • Chained Account Takeovers: AiTM Phishing Campaign Propagating Across Healthcare And Academic Medical Institutions
        "SRA identified an active adversary-in-the-middle (AiTM) phishing campaign propagating across healthcare and healthcare-education organizations by chaining compromised accounts. SRA reconstructed one chain across a university and two health systems, where a single compromised account phished recipients at more than 90 distinct .edu domains in roughly 13 minutes. Open-source analysis shows the observed chain is a part of a broader operation that pairs credential and session theft with a parallel malware delivery track, masking its infrastructure so effectively it scores clean on public reputation tools. Organizations in healthcare and higher education should hunt for the redirect and inbox-rule patterns detailed below, confirm session-token revocation on any affected account, and prioritize phishing-resistant MFA."
        https://sra.io/blog/chained-account-takeovers-aitm-phishing-campaign-propagating-across-healthcare-and-academic-medical-institutions/
      • Anatomy Of a Silent Domain Takeover
        "Modern AD attacks use legitimate protocols end-to-end, no malware, no exploit, nothing for signature tools to fingerprint. The evidence is already in the logs; what is missing is the narrative linking five benign-looking Windows events into a single attack. A full domain takeover can be completed in 54 minutes, from the first password spray to the forged Golden Ticket, with each individual event appearing normal."
        https://blog.qualys.com/product-tech/2026/09/02/anatomy-of-a-silent-domain-takeover-ad-real-time-monitoring
      • Malware On The Blockchain: An Ongoing Campaign’s New WebRTC Twist
        "EtherHiding, a technique that uses blockchain smart contracts as takedown-resistant payload storage, has been seen across more than 5,400 compromised websites in the last few months. The compromised websites have little in common beyond being small businesses (clinics, plumbers, e-commerce shops) with no shared industry, region, or owner. These compromised sites include either an inline script or a spoofed package that calls the BSC testnet and downloads a ClickFix overlay as the next step of the attack, which instructs visitors to run a command on their PC. We also observed a newer variant that, instead of a ClickFix overlay, opens a covert WebRTC data channel for Command and Control."
        https://www.netskope.com/blog/malware-on-the-blockchain-an-ongoing-campaigns-new-webrtc-twist
        https://www.bleepingcomputer.com/news/security/over-5-400-hacked-sites-serve-clickfix-payloads-stored-on-the-blockchain/
      • Discovery Of a New OpenAI Agent Message Board
        "We found ~18,000 posts from autonomous AI agents (self-identifying as from OpenAI) using the public internet to communicate during a web-retrieval task. These AIs colluded to share answers, research their environment, and bypass sandbox restrictions. Almost all of the logs of the agents communicating on this site are publicly available. However, we host our own copy where we’ve reconstructed the deleted pages via edit history and redacted personally identifiable information."
        https://collusion.wiki/
        https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/
        https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html
        https://securityaffairs.com/198524/ai/ai-agents-hijacked-german-wiki-to-cheat-openai-delayed-disclosure.html
      • Attackers Exploit PaperCut Flaws To Steal Credentials From Schools And Universities
        "Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as create privileged accounts. "Observed post-exploitation activity included delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands used to identify hosts, users, processes, and sensitive configuration data," Arctic Wolf said."
        https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html
        https://securityaffairs.com/198476/hacking/papercut-flaws-exploited-in-attacks-on-u-s-and-european-schools.html
      • REVSTEALER Ramps Up: Analysis Of Up-And-Coming Infostealer
        "Elastic Security Labs is tracking an emerging infostealer, REVSTEALER, under REF2859. This family has gained momentum in recent months, with higher distribution volume, and has emerged as a formidable threat, featuring a comprehensive credential harvester, an embedded sandbox scoring system, and a Polygon blockchain-based dead drop for resilience. Beyond credential theft, REVSTEALER targets gaming platforms for additional monetization; the developer clearly understands that victim accounts on these platforms hold real monetary value in resale markets."
        https://www.elastic.co/security-labs/threat-command/revstealer-credential-harvesting-infostealer
        https://assets.contentstack.io/v3/assets/bltefdd0b53724fa2ce/blt9cd59668ba5a104d/6a97978bd04dac6f166ca8ce/REVSTEALER_-_White_paper.pdf
      • Detection And Removal Of The Syslogk Rootkit In a Linux Environment
        "The AhnLab SEcurity intelligence Center (ASEC) continuously monitors various threats targeting Linux environments. Techniques that modify the Linux kernel to conceal malware and signs of compromise have been used for a long time, and Syslogk is one such rootkit that operates in this manner. This document provides an analysis of the key features and operational mechanisms of the Syslogk rootkit, along with detection and remediation strategies for our products developed based on this analysis."
        https://asec.ahnlab.com/en/95254/

      Breaches/Hacks/Leaks

      • Cybercrooks Trawl Fishbrain To Net Password Hashes
        "Cybercriminals have reeled in password hashes and corresponding salts belonging to users of popular fishing app Fishbrain, opening the door to cracking attempts. Fishbrain AB, which says its eponymous app serves more than 20 million anglers, disclosed the August 19 breach to the California Attorney General's Office this week. The unknown perpetrators helped themselves to a trawl of user data, including names, dates of birth, email addresses, phone numbers, Fishbrain usernames, country information, password hashes, and salts."
        https://www.theregister.com/cyber-crime/2026/09/03/cybercrooks-trawl-fishbrain-to-net-password-hashes/5294158
      • Attackers Breached JetBrains Cadence Via Unpatched TeamCity, Extracting AWS Credentials
        "JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said. "They should also treat all executions, including their inputs and outputs in your Cadence project, as potentially untrusted.""
        https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html
      • Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
        "Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets."
        https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html

      General News

      • Why Judgment Is Emerging As Cybersecurity’s Defining Skill
        "AI is getting better at much of what security teams have long spent time on: analyzing information, identifying patterns, and providing technically sound recommendations quickly. As those capabilities become more routine, they are changing what security practitioners spend their time on. Reaching a technically sound recommendation is also getting easier, which puts more weight on the judgment about what to do with it. A recommendation can make complete sense from a security perspective and still carry consequences for the systems, people and business around it that change what the right decision is."
        https://cyberscoop.com/ai-security-operations-human-context-ciso-op-ed/
      • Insurers Search For Answers To Rein In Rogue AI
        "When Maria Long heard about OpenAI's rogue model attacking AI-model service provider Hugging Face, her first stop was to review her firm's technology errors and omissions (Tech E&O) policy. As the chief underwriting officer for cybersecurity insurance services firm Resilience, she understood that rogue AI agents causing inadvertent compromises could result in significant losses to insurers in the future. This incident showed that the future wasn't that far off. For Hugging Face, the incident would almost certainly be covered by cyber-liability insurance as a classic security breach. However, if AI agents routinely escape containment, insurers have to consider that the volume of policy claims could grow."
        https://www.darkreading.com/cyber-risk/insurers-search-answers-rogue-ai
      • What The AI Warning Letter Completely Missed
        "Recently, more than 100 technology companies — OpenAI, Anthropic, Microsoft, and Google among them — published an open letter warning that AI is about to make sophisticated cyberattacks far cheaper and far more common, and that "we have a limited window to strengthen cyber defenses." I read it twice. The first time as the head of a security organization, nodding along to very nearly every line. The second time hunting for the part about who actually does the work. I did not find it."
        https://www.darkreading.com/cyberattacks-data-breaches/ai-warning-letter-missed-people
      • Companies Have 6 Months To Prepare For Automated Attacks
        "With multiple benchmarks confirming that at least one frontier model can autonomously execute an end-to-end compromise, cybersecurity experts are warning that companies have to pick up the pace in securing their attack surfaces and adopting AI-speed defenses. On Sept. 2, consulting firm Booz Allen became the latest organization to confirm that a frontier model — Anthropic's Mythos 5 — can act as a fully autonomous hacker and compromise a production-grade enterprise network. The company also released a metric, dubbed the Cyber Weapon Index (CWI), to benchmark a model's capabilities, pairing the ability to find and exploit vulnerabilities with the ability to execute and attack a target."
        https://www.darkreading.com/cybersecurity-operations/companies-six-months-prepare-automated-attacks
      • AI Is Ending The Era Of Hidden Vulnerabilities — Are Vendors Ready?
        "Vulnerabilities are running out of places to hide, thanks to frontier AI models, and it could create problems for those that sell software. The "vulnpocalypse," or the onslaught of vulnerabilities surfaced through the proliferation of AI, is having far-reaching consequences on the economics and demands previously associated with bug hunting. Software publishers are used to operating in a world where code reviews, researcher attention, and discovery capacity are finite. But over the past two years, things have changed. Large language models (LLMs) have automated and sped up large portions of the bug discovery pipeline, and frontier models could accelerate that process even further."
        https://www.darkreading.com/vulnerabilities-threats/ai-ending-era-hidden-vulnerabilities-are-vendors-ready
      • US Offers $10 Million For Info On Iranian Allegedly Behind Cyberattacks On Critical Infrastructure
        "A $10 million reward has been posted by the State Department for information on the whereabouts of senior Iranian official Amir Yaryab. Yaryab allegedly leads the Islamic Revolutionary Guard Corps’ (IRGC) Cyber-Electronic Command (CEC). U.S. officials accused Yaryab of directing multiple Iranian hacking groups that have targeted “critical infrastructure sectors including defense, news, shipping, travel (hotels and airlines), energy, and financial and telecommunications systems in the United States, Europe, and the Middle East.”"
        https://therecord.media/us-reward-amir-yaryab-iran-irgc-cyberattacks
      • H1 2026 Malware And Vulnerability Trends
        "H1 2026 activity showed a continued adversary preference for abusing legitimate tools, trusted platforms, and routine workflows already present in enterprise and consumer environments. Threat actors used exposed software, developer tools, remote access utilities, payment workflows, and third-party services to gain access, steal credentials, move laterally, and monetize intrusions while blending into expected activity. This emphasis on evasion through normalcy rather than technical novelty increases the risk that malicious activity will progress through approved tools and trusted services before defenders recognize it, reinforcing the need for stronger exposure management, identity and credential governance, behavioral detection, developer-environment security, backup resilience, mobile fraud monitoring, and third-party oversight."
        https://www.recordedfuture.com/research/h1-2026-malware-vulnerability-trends
        https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0903.pdf

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) a0344717-380a-49ff-969f-52d35634883f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 04 September 2026

      Vulnerabilities

      • HPE Patches Critical ArubaOS-CX Remote Code Execution Flaw
        "Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. Tracked as CVE-2026-73749, the security issue is a buffer overflow that allows unauthenticated remote attackers to send specially crafted packets to an affected daemon process, achieving code execution with elevated privileges. “Multiple vulnerabilities exist in a daemon of ArubaOS-CX that may allow for improper processing of malformed input,” reads HPE’s bulletin."
        https://www.bleepingcomputer.com/news/security/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw/
      • Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code As Root
        "Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is a case of binding to an unrestricted IP address that leaves TCP ports 43210 and 43211 reachable in the default Layer 3 virtual routing and forwarding (VRF) instance."
        https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html
        https://www.securityweek.com/cisco-warns-of-unpatched-secure-email-flaws-patches-critical-switch-vulnerabilities/
        https://securityaffairs.com/198366/security/cisco-fixed-critical-rce-in-nexus-9000-series-switches.html
      • Plex Warns Users To Patch Security Vulnerabilities Immediately
        "Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. These flaws have not yet been assigned CVE IDs for easy tracking, and while Plex didn't provide additional details on Tuesday, the security issues are known to affect Plex Media Server v1.43.2 and earlier. Plex also emailed users running affected versions and asked them to update as soon as possible to address these security flaws."
        https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/
      • VMSA-2026-0007: VMware Workstation And Fusion Updates Address Integer-Overflow And Buffer Overflow Vulnerabilities (CVE-2026-59346, CVE-2026-59347)
        "An integer-overflow and a buffer-overflow vulnerabilities in VMware Workstation and Fusion were privately reported to Broadcom. Updates are available to remediate these vulnerabilities in affected Broadcom products."
        https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38288
      • Attackers Actively Exploiting Critical Vulnerability In Elementor Pro Plugin
        "On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more than 6,000,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site takeover. The vendor released the fully patched version on August 19th, 2026, and we originally disclosed this vulnerability in the Wordfence Intelligence vulnerability database on the same day. The Wordfence Firewall has already blocked over 190,000 exploit attempts targeting this vulnerability."
        https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-elementor-pro-plugin/
        https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploited-to-take-over-wordpress-sites/

      Malware

      • Coder's Registry Infrastructure Compromised To Push Malicious Modules
        "Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. The Coder platform enables organizations to provide developers with secure, self-hosted cloud development environments for building and deploying software, including AI applications. The project is used by prominent private and government organizations, including Dropbox, Palantir, Square, Mercedes-Benz, KKR, EnBW, the U.S. government, and defense companies."
        https://www.bleepingcomputer.com/news/security/coders-registry-infrastructure-compromised-to-push-malicious-modules/
      • The NDA Was The Payload: Inside Phantom Deal, a Fake Acquisition Fraud Campaign
        "It started with an innocent WhatsApp message. “Hi David, I hope you are well. Are you at the office?” The sender claimed to be a real Gen executive based in Dublin. The profile used his name, photograph and an Irish telephone number. Nothing in the opening message mentioned money, urgency or an acquisition. It was simply designed to establish whether the recipient was available and willing to respond. The recipient, whom we will call David, worked in Gen’s legal team and knew the colleague being impersonated. The unfamiliar telephone number raised suspicion, and the first phone conversation confirmed it: the caller’s voice did not match."
        https://www.gendigital.com/blog/insights/research/phantom-deal
        https://www.darkreading.com/cyberattacks-data-breaches/large-enterprises-fake-merger-acquisition-scams
      • Someone Else Is Using Your AI
        "Generative AI is quickly becoming one of the more lucrative uses for stolen cloud credentials. Attackers no longer need to set up crypto miners or exfiltrate data to cash in on a leaked IAM key. They can instead subscribe to foundation models through AWS Marketplace and resell inference access, a technique called LLMjacking, first documented in 2024. FortiCNAPP recently investigated a case that shows how fast and mechanical that pivot has become. FortiGuard Labs recently analyzed a long-lived AWS IAM access key with administrator privileges that was used to create a new IAM identity, subscribe it to foundation models on AWS Marketplace, and begin invoking them."
        https://www.fortinet.com/blog/threat-research/someone-else-is-using-your-ai
      • The Outsider Phishing Kit: A Resilient Threat In The Face Of Law Enforcement Action
        "During an investigation into phishing kits sold, Group-IB researchers uncovered the “Outsider Phishing Kit” (局外人), a sophisticated Phishing-as-a-Service (PaaS) platform operated by the threat actor known as “ChenLun.” The kit incorporates Adversary-in-the-Middle (AiTM) capabilities, enabling attackers to intercept authentication flows and bypass multi-factor authentication (MFA). The scale of this operation is staggering. From December 2025 to May 2026, Group-IB has identified over 100,000 phishing pages targeting 54+ countries, leveraging 267 (and growing) phishing templates. These numbers underscore the increasingly low barrier to entry for threat actors to launch and operate large-scale phishing campaigns."
        https://www.group-ib.com/blog/chenlun-outsider-phaas-kit/
        https://www.infosecurity-magazine.com/news/outsider-phishing-kit-survives/
      • Attackers Expose Ongoing AI Tool Use Targeting Organizations In Latin America
        "We have analyzed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America. Corroborating recent findings from the broader threat intelligence community, we observed attackers leveraging artificial intelligence (AI) to enhance their capabilities."
        https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/
      • US Becomes Top Target In RMM Phishing Campaign Spanning 46 Countries
        "An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses fake documents to trick victims into installing legitimate remote monitoring and management (RMM) software. The attackers adapt their lures to different targets, using shipping and UPS communications, Adobe PDFs, tax notices, US Social Security Administration themes, invoices, and other documents. Rapidly rotated, disposable Vercel infrastructure makes the campaign harder to track and detect."
        https://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.html
      • Node.js: Old Technique Makes a Comeback
        "Between March and July 2026, attackers who compromised a technology start-up in Asia ran into a problem: almost every payload they attempted to deploy, including AdaptixC2 agents and Cobalt Strike Beacon, was blocked on the victim's network. Their response was to download the official Node.js installer from nodejs.org and use the trusted, signed runtime to execute a malicious implant. The implant maintained its foothold for months and made repeated connections to Ethereum blockchain gateways, most likely to retrieve commands or additional payloads hidden in a blockchain smart contract, a technique known as EtherHiding."
        https://www.security.com/threat-intelligence/node-js-returns-ransomware
        https://thehackernews.com/2026/09/attackers-turn-trusted-nodejs-runtime.html
      • Shai-Hulud's Reach Just Grew To 469 Credential Locations. Here's What That Means
        "In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs. Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have stopped trying to break trust relationships and started using the credentials that already make those relationships work. Software supply chains have always depended on trust."
        https://thehackernews.com/2026/09/shai-huluds-reach-just-grew-to-469.html
      • Researcher Releases FalconFlank PoC Showing Privilege Escalation In CrowdStrike Falcon
        "The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in a GitHub README file, adding the cybersecurity company may already have detections for the flaw by now. "So if you want to test, you either have to add it to the exclusions or obfuscate the PoC and change the DLL load technique.""
        https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html
        https://securityaffairs.com/198342/hacking/chaotic-eclipse-releases-crowdstrike-falcon-zeroday-falconflank.html
      • Impersonating IT Support: How Threat Actors Turn a Remote Session Into Enterprise-Wide Access
        "Microsoft Threat Intelligence has observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into granting an interactive remote session. Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node.js runtime and an obfuscated JavaScript implant that provides persistent command execution and command and control (C2)."
        https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/

      Breaches/Hacks/Leaks

      • US And Canadian Court Data Exposed In Thomson Reuters Breach
        "Sealed court information and sensitive personal data were exposed in a breach of a Thomson Reuters records platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands and Canada, the company publicly disclosed Wednesday. Thomson Reuters has not said how the attacker gained access, who was responsible or how much data was taken. The number of people affected also remains unclear. The company stressed the breach occurred within its environment and was not caused by the networks, systems or data security of the affected courts."
        https://therecord.media/thomson-reuters-cyberattack-data
        https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html
        https://www.infosecurity-magazine.com/news/us-canada-court-breach-thomson/
        https://www.helpnetsecurity.com/2026/09/03/thomson-reuters-reveals-breach-that-exposed-u-s-and-canadian-court-records/
      • Manchester Airports Group Data On 8.8 Million People Leaked After Ransom Refusal
        "Data allegedly stolen from the Manchester Airports Group (MAG) and leaked online this week includes the email addresses and phone numbers of 8.8 million people. MAG disclosed the incident last week, warning that hackers had breached its systems, stealing car park, lounge, and Fast Track booking data, along with in-airport Wi-Fi sign-ups at the Manchester, London Stansted, and East Midlands airports. The airport operator disclosed that hackers had exfiltrated email addresses, phone numbers, vehicle registrations, and postcodes, noting that its operations were not affected by the incident."
        https://www.securityweek.com/manchester-airports-group-data-on-8-8-million-people-leaked-after-ransom-refusal/
      • 412,000 The Town 2025 Ticket Buyers’ Data Hits The Dark Web
        "A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, claiming over 412,000 Latin American purchase records with a heavy concentration of Brazilian data. Ransomnews’s analysis confirms the sample is genuine ticket-buyer data from The Town 2025, the São Paulo music festival, though who actually lost the data and how remains unconfirmed. “The listing is headed “SELLING NEW TICKETMASTER DATABASE” and describes a global ticketing platform, Latin America region, with an internal ticketing database as the source and a breach date of 28 August 2026."
        https://securityaffairs.com/198354/data-breach/412000-the-town-2025-ticket-buyers-data-hits-the-dark-web.html
      • Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline
        "Recently leaked records show that Bauman Moscow State Technical University’s Department No. 4 operated as a long-term training pipeline for Russian military intelligence and cyber operations. The department served several elements of the Russian General Staff and trained roughly 250 career and reserve students across three specialties: special intelligence (“Служба специальной разведки”), operational information-technical effects (“Применение сил и средств информационно-технического воздействия и защиты от информационно-технического воздействия”), and information-technology protection (”3ащита информационных технологий”). The curriculum combined both offensive and defensive techniques for cyber defense, as well as offensive doctrine for active measures campaigns and GRU activities. Field placements then moved students from classroom instruction into military units and academies aligned with their specialties, giving them supervised exposure to intelligence operations and preparing them for military and government operations careers."
        https://dti.domaintools.com/research/threat-intelligence-report-university-leak-exposes-russias-military-cyber-training-pipeline
        https://securityaffairs.com/198332/intelligence/2000-leaked-documents-reveal-how-russia-turns-engineering-students-into-gru-cyber-operators.html

      General News

      • G7 Says Migrating To PQC Early Is Cheaper Than Later
        "An international public-private cyber alliance is making a call to action on transitioning to post-quantum cryptography and offers strategies to lower the cost of the strenuous effort. The G7 Cybersecurity Working Group of government agencies and banks from seven economically advanced countries along with the European Union outlined many risks that can happen after quantum computers break classic encryption and told every country to consider PQC as a "foreseeable evolution of cryptographic best practices" that cannot be avoided."
        https://www.bankinfosecurity.com/g7-says-migrating-to-pqc-early-cheaper-than-later-a-32738
        https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/asset_files/external/g7preparingfortheqostquantumeraacalltoaction.pdf
        https://cyberscoop.com/g7-quantum-computing-encryption-warning/
      • Crypto Agility: Why PQC Is Not a One-Time Upgrade
        "Crypto agility is the ability to update cryptographic algorithms, protocols, libraries, and implementations while minimizing disruption and avoiding unnecessary replacement of the underlying infrastructure. For networks, that means adopting post-quantum cryptography (PQC) while preserving the ability to accommodate future standards and defenses primarily through software. This capability matters because networking platforms often take years to develop and may remain deployed for a decade or longer."
        https://blogs.cisco.com/security/crypto-agility-why-pqc-is-not-a-one-time-upgrade
      • Supply Chain Attacks In 2026: Why Threat Intelligence Is The Only Early Warning System That Works
        "Supply chain attacks in 2026 are no longer an edge-case risk buried in a vendor questionnaire — they are a primary breach vector that regulators, incident responders, and CISOs now treat as a first-order threat. Verizon’s 2026 Data Breach Investigations Report found third-party involvement in 48% of breaches, up 60% year over year, following the 2025 edition, which already recorded a jump from 15% to 30%. Every vendor integration, every open-source dependency, and every managed file transfer tool expands the attack surface that an organization does not directly control. That is the core problem with supply chain security today: the weakest link is rarely the enterprise itself."
        https://cyble.com/blog/supply-chain-attacks-in-2026-vendor-risk/
      • Your AI Agent’s System Prompt Is Not a Security Control
        "An AI agent told in its system prompt to show a user only what that user is cleared to see will hand over more the moment someone talks it into doing so. Gee Rittenhouse, who oversees Security Hub, GuardDuty, and Inspector at AWS, and Eric Johnson, a fellow at the SANS Institute, put the fix one layer down: scope the query to the user’s permissions at retrieval time, inside the role-based or attribute-based access system the company already runs, and filter the results before they reach the model’s context window."
        https://www.helpnetsecurity.com/2026/09/03/sans-aws-agentic-ai-security/
      • Your Threat Feed Is Someone Else’s Database: What Ingesting Malware Intel At Scale Takes
        "The advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is the operating manual, because the access was never the hard part. A threat feed is someone else’s database. Someone else’s processes built it, someone else’s judgement calls shaped it, and someone else’s bad Tuesday is sitting it right now, waiting for the automation to act on it. I lead the team that runs Dependabot at GitHub, which monitors more than 30 million repositories for vulnerable and malicious dependencies as of 2026. This year we extended malicious-package advisories from npm, where we had been flagging malware since March, to eight package ecosystems, by ingesting community intelligence from OpenSSF’s malicious-packages repository."
        https://www.helpnetsecurity.com/2026/09/03/github-threat-intelligence-feed-ingestion/
      • When AI Quietly Breaks Things, Who Pays?
        "David Halbreich, an insurance recovery partner at Reed Smith, breaks down how AI companies should handle coverage gaps that come up as the industry grows. He covers straddle claims that fall between tail and go-forward D&O policies after a merger, how governance disclosures in applications can turn into warranties an insurer uses to deny a claim, who should sign off on AI use questions, when the claim clock starts for slow-building model degradation, and how business interruption coverage applies to outages at cloud and compute vendors."
        https://www.helpnetsecurity.com/2026/09/03/david-halbreich-reed-smith-ai-insurance-coverage-gaps/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) e52ccc9b-7672-4b70-bd36-017039b11b7b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการโจมตีช่องโหว่ StyleSmuggler ใน Magento และ Adobe Commerce เสี่ยงรันโค้ดและฝัง Backdoor

      พบการโจมตีช่องโหว่ StyleSmuggler ใน Magento และ Adobe Commerce เสี.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5e803fd4-d4bc-42eb-8884-fac403ec6c4a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Broadcom ออกแพตช์แก้ช่องโหว่ VM Escape ระดับ Critical ใน VMware Workstation และ Fusion

      Broadcom ออกแพตช์แก้ช่องโหว่ VM Escape ระดับ Critical ใน VMware Wor.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 59e809e5-7e23-4bc9-8934-c224cd4aed7f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT