NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,602
    • กระทู้ 2,603
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • พบแคมเปญ LastPass ปลอม แพร่มัลแวร์ Rapuncel ขโมยข้อมูลและปิดการทำงาน Antivirus และ EDR

      พบแคมเปญ LastPass ปลอม แพร่มัลแวร์ Rapuncel ขโมยข้อมู.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand b23af663-4068-4027-a555-0b4cb20494aa-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ShinyHunters เจาะและเปลี่ยนหน้า Leak Site ของ Clop Ransomware บน Dark Web

      ShinyHunters เจาะและเปลี่ยนหน้า Leak Site ของ Clop Ransomware บน Dark Web.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand f7ef0fb6-8ca4-4958-93f3-170e49408b82-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบมัลแวร์ ChainScript ที่ซ่อนเซิร์ฟเวอร์ควบคุมสั่งการผ่านสมาร์ตคอนแทรกต์บนเครือข่ายบล็อกเชน

      พบมัลแวร์ ChainScript ที่ซ่อนเซิร์ฟเวอร์ควบคุม สั.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand b89f76bb-01aa-4a3b-bb2b-472f18b35ab8-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 22 September 2026

      New Tooling

      • Gopass: Open-Source Command-Line Password Manager For Teams
        "Gopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement for pass, the standard Unix password manager. Out of the box, Gopass encrypts each secret with GPG and keeps the store in a git repository. Git gives a team a record of every change and a way to sync one store across laptops and servers. Users who want different tools can switch encryption to age, switch storage to fossil, or drop versioning with the --storage=fs flag."
        https://www.helpnetsecurity.com/2026/09/21/gopass-open-source-password-manager/
        https://github.com/gopasspw/gopass

      Vulnerabilities

      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/21/cisa-adds-one-known-exploited-vulnerability-catalog
      • No Attacker Required: What a Two-Day Hackathon Taught Us About Agent Security
        "Most security research starts with an attacker. Ours kept finding trouble without one. In August, we gave our R&D teams two days and a single prompt: build the demo customers would ask to see twice. Hackathons like this one are a fixture of how we work. In a field moving as fast as agentic AI security, two unscheduled days are often where the ideas that end up mattering first show up."
        https://blog.checkpoint.com/ai-security/no-attacker-required-what-a-two-day-hackathon-taught-us-about-agent-security/
      • Intent Injection Attacks Are a New Worry For AI-Native 6G Networks
        "Intent-based networking (IBN) lets operators state the outcome they want and leaves its translation into network policy to software, an approach AI-native 6G designs have moved to the forefront. Researchers at the University of Ottawa and Nokia Bell Labs argue that this abstraction gives attackers new openings, and it tests two machine-learning detectors against one of them. The authors call that threat adversarial intent injection: hiding malicious instructions among legitimate ones. They evaluated their detectors on 1,100 intents they constructed, partly with a large language model’s help, so the reported figures describe performance on that dataset."
        https://www.helpnetsecurity.com/2026/09/21/6g-intent-injection-attacks/
        https://arxiv.org/pdf/2609.12144

      Malware

      • TASK#STOMP: PowerShell Backdoor For Document Theft And Remote Access
        "Securonix Threat Research analyzed a script-driven Windows execution chain that begins with a desktop VBScript and deploys a redundant persistence framework under %LOCALAPPDATA%\WinDefendSvc. The sample creates four scheduled tasks from XML definitions, places msdiag.vbs in the user Startup folder, terminates existing loader instances, backdates core artifacts, launches two hidden PowerShell modules, compiles C# code at runtime through the legitimate .NET compiler, opens a specific web page in Chrome, and executes a cleanup batch file."
        https://www.securonix.com/blog/task-stomp-powershell-backdoor-document-theft-remote-access
        https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html
        https://www.helpnetsecurity.com/2026/09/21/taskstomp-windows-backdoor/
      • Be Alert: Targeted Attacks On Prominent Rustaceans
        "We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware. A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard)."
        https://blog.rust-lang.org/2026/09/17/targeted-attacks/
        https://www.theregister.com/security/2026/09/21/rustaceans-warned-of-job-interviews-with-a-malicious-payload/5297690
        https://www.securityweek.com/rust-team-members-and-popular-crate-owners-targeted-via-video-calls/
        https://www.helpnetsecurity.com/2026/09/21/north-korean-hackers-contagious-interview-defenses/
      • Exvicy: A Copycat Of The ErrTraffic Malware Distribution Framework
        "This article details how TDR pivoted from a forum advertisement to identify confirmed operator infrastructure, analyzes the Exvicy infection chain, and provides code evidence establishing that this emerging MaaS is a direct copycat of the adopted ErrTraffic framework. Sekoia's TDR team discovered Exvicy, a new ClickFix malware distribution framework, from a single forum screenshot all the way to its operator's live infrastructure."
        https://www.sekoia.com/blog/exvicy-a-copycat-of-the-errtraffic-malware-distribution-framework
        https://www.infosecurity-magazine.com/news/exvicy-clickfix-framework/
      • GHAPPIER - One Loader, Sixty-Five Repositories, Twenty-Two Accounts: An Unreported Loader Family Beside DPRK's PolinRider Campaign
        "CloudSEK researchers uncovered GHAPPIER, a previously unreported loader operation spanning at least 65 public repositories, 73 infected files and 22 accounts. The investigation began with a compromised legitimate npm package whose malicious release carried valid provenance through trusted publishing. The report maps the wider infrastructure, links parts of the activity to the PolinRider campaign, and details indicators, attack flow and defensive actions."
        https://www.cloudsek.com/blog/ghappier-malware-loader-npm-supply-chain-attack
        https://www.infosecurity-magazine.com/news/attackers-abuse-npm-trusted/
      • The Fake Sites Using a Cheap Toolkit To Sell $2,000 AI Subscriptions
        "We found more than 100 subscription websites linked through the same toolkit and closely related developer details. Some impersonate existing products, including GPT-6 Astra, DaVinci Resolve, PixAI, and OpenCut. Another uses the name of Omegle, the chat service that shut down in 2023. Others promote unfamiliar brands with little verifiable information about who operates them."
        https://www.malwarebytes.com/blog/threat-intel/2026/09/the-fake-sites-using-a-cheap-toolkit-to-sell-2000-ai-subscriptions
      • Group Policy Hijacked: PAYLOAD Ransomware Weaponizes Active Directory GPO
        "In April 2026, we at Kaspersky’s Global Emergency Response Team (GERT) responded to a security incident at a manufacturing organization in the Middle East. The threat actor obtained domain admin-equivalent control of the organization’s Active Directory environment and authored a malicious Group Policy Object (GPO) named PAYLOAD, linking it at the domain root. Through that single object, the actor delivered ransom notes, hijacked the desktop wallpaper and lock screen, enforced a logon banner, and disabled the local administrator account across every domain-joined Windows workstation — all without dropping a ransomware binary or encrypting any data."
        https://securelist.com/tr/payload-ransomware-via-group-policy/121335/
      • Vidar Adds Virtual Machine And Custom Stream Ciphers For String Obfuscation
        "Vidar is an information stealer that was first observed in 2018. Across its iterations, Vidar has continued to improve its string obfuscation to make detection and analysis more difficult by changing deobfuscation algorithms, constants, and primitives. From May through early September 2026, Zscaler ThreatLabz tracked Vidar’s string obfuscation as it evolved from basic XOR to ChaCha20, and more recently, to a custom virtual machine (VM), which is executed via a lightweight bytecode interpreter that is combined with a custom stream cipher that changes with each build. In this blog post, ThreatLabz covers Vidar’s string obfuscation methods from version 2.0 to the latest version 3.3."
        https://www.zscaler.com/blogs/security-research/vidar-adds-virtual-machine-and-custom-stream-ciphers-string-obfuscation
      • ChainScript: Tracing a Node.js RAT Through The Blockchain
        "Blackpoint’s Adversary Pursuit Group (APG) identified and analyzed a previously unnamed Node.js remote access trojan, now being tracked as ChainScript. The malware was uncovered while investigating ClickFix activity that led to the execution of a malicious Windows Installer disguised as Spotify software. Once executed, the MSI deployed its own Node.js runtime and launched a JavaScript agent through hidden PowerShell and VBScript stages. The running agent then established persistence in the user profile."
        https://blackpointcyber.com/blog/chainscript-tracing-a-nodejs-rat-across-the-blockchain/
        https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html
        https://securityaffairs.com/199471/malware/chainscript-the-rat-that-hides-its-command-server-inside-a-blockchain-contract.html
      • Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface On Victim With No Crypto Ties
        "Throughout 2026, the financially motivated DPRK state-sponsored Lazarus subgroup TraderTraitor (aka UNC4899, PUKCHONG, Jade Sleet) has engaged in campaigns targeting entities involved in cryptocurrency trading, including a high-profile attack disclosed in April where USD 292 million was stolen from KelpDAO through a compromise of LayerZero. KelpDAO is a decentralized finance (DeFi) protocol that supports restaking Ethereum; LayerZero Labs provides services with the capability to exchange cryptocurrency across different blockchain platforms."
        https://www.sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/
        https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html
      • Russia Reports Thousands Of Cyberattacks On Election Infrastructure During Vote
        "Russian authorities said they repelled thousands of cyberattacks targeting online voting systems and other digital infrastructure during the country's three-day parliamentary election. According to Deputy Digital Development Minister Oleg Kachanov, Russia detected and blocked about 2,000 cyberattacks and other attempts to disrupt its federal online voting platform and e-government systems. Kachanov said Sunday that the incidents caused no service disruptions and that Russia’s newly deployed election administration system, Vybory 2.0, continued operating normally."
        https://therecord.media/russia-reports-cyberattacks-during-election

      Breaches/Hacks/Leaks

      • BigCommerce Alerts Merchants Of Data Breach Linked To Ribon Apps
        "Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. The cloud-based Software-as-a-Service (SaaS) ecommerce platform confirmed the credential compromise on September 17 and immediately removed the apps to protect its customers. UK-based online spirits vendor Master of Malt is one of the BigCommerce customers that received the notification. The retailer said the attacker accessed shopper information."
        https://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/
      • Belgian Table Tennis, Gymnastics Federations Hit By Cyberattacks
        "Belgium’s national table tennis federation and its French-speaking branch are investigating a cyberattack after a hacker claimed to have stolen data on tens of thousands of members and users. Jean-Michel Mureau, president of the French-speaking Association Francophone de Tennis de Table (AFTT), confirmed the attack over the weekend and said the Royal Belgian Table Tennis Federation (FRBTT) had also been affected. “I can confirm that there was indeed an attack,” Mureau said in a statement. “We have tasked our IT department with investigating to determine exactly what data was compromised.”"
        https://therecord.media/belgium-table-tennis-cyberattack
      • Cyberattack Hits University Of Munich, Potentially Exposing Student Financial Data
        "Germany’s Ludwig Maximilian University of Munich is investigating a cyberattack in which an unknown hacker accessed a system containing sensitive student information, including potential health insurance and financial aid data. The university, commonly known as LMU Munich, said Saturday that an attacker accessed enrollment data stored on one of its IT systems. “Currently, we must assume that this data were in fact retrieved,” the university said, adding that the investigation into the incident is ongoing."
        https://therecord.media/cyberattack-hits-university-of-munich-potentially-exposing-data
      • Colorado Water Utilities Hit By Cyberattacks Targeting OT Systems
        "Hackers targeted operational technology (OT) systems at two private water utilities in Colorado in late August, apparently attempting to cause disruptions. Few technical details are available, but it seems the attackers targeted industrial control systems (ICS) at the water utilities, which serve fewer than 200 people. A spokesperson for Colorado Governor Jared Polis told The Denver Post [paywalled] that the attackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles. However, the disruptions were brief and did not affect water services or public safety."
        https://www.securityweek.com/colorado-water-utilities-hit-by-cyberattacks-targeting-ot-systems/
        https://securityaffairs.com/199480/ics-scada/foreign-hackers-target-two-colorado-water-utilities.html

      General News

      • Know What Was Tested Before Your SAP ECC Migration Goes Live
        "In this Help Net Security interview, Guilherme Joventino, COO of MIGNOW, explains why some large companies plan to stay on ECC past the 2027 deadline and pay SAP for extended support until 2030. The interview covers what that choice may cost, why fear of disruption stalls projects more often than budget, and what the first ninety days of a phased migration involve. It also looks at staff who hold years of knowledge about the old system, and a Central American project that passed every quality gate but still had a difficult go live."
        https://www.helpnetsecurity.com/2026/09/21/guilherme-joventino-mignow-sap-ecc-migration/
      • AI Compliance Issues Hit 2 In 5 Large Companies, And Legacy Workflows Are a Big Factor
        "Forty percent of large companies had an AI-related compliance or governance issue in the past 12 months, according to 1,000 senior IT, operations, and transformation leaders surveyed by Sapio Research. Those leaders said process-related problems contributed to 84 percent of the incidents. The researchers trace the exposure to workflows designed around people. Approvals, handoffs, and manual exceptions exist because a person was expected to handle each step. When a company drops AI into that design, checks sit at the wrong point, work changes hands with nothing written down, and the audit record cannot show how a decision was reached. A CISO who has to explain an AI-assisted decision to an auditor may find the evidence was never captured."
        https://www.helpnetsecurity.com/2026/09/21/ai-compliance-issues-research/
      • Anthropic-Linked CVEs Pile Up, Attackers Mostly Shrug
        "Despite the concern that advanced AI models’ bug-hunting prowess will lead to attackers exploiting more newly uncovered CVEs, fewer than 0.5 percent of the vulnerabilities linked to Anthropic or Project Glasswing are being batttered in the wild, according to VulnCheck security researcher Patrick Garrity. Garrity began tracking CVEs attributed to Project Glasswing, Anthropic’s initiative to give select partners access to its Claude Mythos Preview model, shortly after the AI company announced the program in April."
        https://www.theregister.com/security/2026/09/21/anthropic-linked-cves-pile-up-attackers-mostly-shrug/5298018
      • CISO Conversations: Noopur Davis – The Accidental Global CISO At Comcast
        "Noopur Davis never planned a career in cybersecurity. She was a developer at Intergraph, and for many years that was all she wanted to be. Comcast, founded in Tupelo, Mississippi, in 1963, is now a global media and technology company headquartered in Philadelphia, Pennsylvania. It has offices in North America, Europe, Asia, and Australia, and a global workforce of around 180,000 people. Noopur Davis is the organization’s Global CISO, leading multiple security teams distributed around the world and a total headcount of around 1,500 security team members."
        https://www.securityweek.com/ciso-conversations-noopur-davis-the-accidental-global-ciso-at-comcast/
      • The Target Is No Longer The Model. It’s The Agent.
        "I read the AI security research published in a single month, February 2026, and when you put it all together, it’s not a list of curiosities. It’s a field guide to a new attack surface. In my previous piece, I explained how MITRE ATLAS catalogs threats to AI. Here, I take the next step: I map that research onto ATLAS. What emerges is a complete kill chain, and the target is no longer the model. It’s the agent."
        https://securityaffairs.com/199454/ai/the-target-is-no-longer-the-model-its-the-agent.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 5681b576-c020-41e2-80be-72cd9efb0fc5-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 21 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 3 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/21/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fe642e6e-d04a-4e31-8ae3-7a866bc6cd63-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 3 รายการลงในแคตตาล็อก

      เมื่อวันที่ 18 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 3 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2025-39964 Linux Kernel Race Condition Vulnerability
      • CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability
      • CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-two-known-exploited-vulnerabilities-catalog
      https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 642cbaf6-39c2-4f35-a1ca-346881ca1e42-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ใน SolarWinds Access Rights Manager เสี่ยงถูกรันคำสั่งโดยไม่ต้องยืนยันตัวตน

      ช่องโหว่ใน SolarWinds Access Rights Manager เสี่ยงถูกรันคำสั่ง.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand d49e701b-def6-47e2-a858-0e831b1bc3d9-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • นักวิจัยเผย AI ช่วยเร่งพัฒนา Exploit ช่องโหว่ Discourse จนยึดบัญชี OpenAI Staff ได้ผ่านระบบ SSO

      นักวิจัยเผย AI ช่วยเร่งพัฒนา Exploit ช่องโหว่ Discourse.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand f3b59166-76bc-4856-b169-47a6f3d848a8-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ค้นพบแนวคิดการโจมตีเทคนิค "BragJack" ที่ใช้ควบคุมผู้ช่วย AI บนเบราว์เซอร์ผ่าน Extension

      ค้นพบแนวคิดการโจมตีเทคนิค BragJack ที่ใช้ควบคุ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand dfcf80ca-c59d-4c58-8e6c-6556be8ba002-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 21 September 2026

      Vulnerabilities

      • New Check Point Flaw Lets Hackers Execute Code With Root Privileges
        "Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. Tracked as CVE-2026-91843, this flaw stems from a stack-based buffer overflow weakness in the login process for Security Management Server instances, which manage Security Gateways (firewalls) and monitor network security events. The security issue also affects the company's Log Server, a dedicated server that collects and stores logs generated by Check Point firewalls."
        https://www.bleepingcomputer.com/news/security/check-point-warns-critical-flaw-lets-hackers-execute-code-as-root/
        https://thehackernews.com/2026/09/critical-check-point-management-server.html
        https://securityaffairs.com/199279/security/check-point-fixes-critical-cve-2026-91843-allowing-root-code-execution.html
      • Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
        "Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. "Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network," Microsoft said in a Thursday advisory."
        https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html
        https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85889
      • Critical Orkes Conductor Vulnerability Exploited In Attacks
        "A critical-severity vulnerability in Orkes Conductor that can be exploited without authentication has been in attackers’ crosshairs for at least a month. Conductor is an open source unified enterprise framework that allows organizations to orchestrate microservices, workflows, and AI agents. Tracked as CVE-2026-58138 (CVSS score of 9.8), the critical bug is described as a remote code execution issue exploitable via inline workflow definitions submitted to the workflow API endpoint."
        https://www.securityweek.com/critical-orkes-conductor-vulnerability-exploited-in-attacks/
        https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html
      • Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read And Modify MacOS Host Files
        "Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is rated Critical, affects versions 0.28.0 up to but not including 0.42.0 on macOS, and was fixed in 0.42.0 on September 7."
        https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html
      • SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
        "SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior. "SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability," SolarWinds said in an advisory released on September 17, 2026. "The issue stems from a hard-coded static key.""
        https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2025-39964 Linux Kernel Race Condition Vulnerability
        CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-two-known-exploited-vulnerabilities-catalog
        https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html
        https://securityaffairs.com/199430/security/u-s-cisa-adds-linux-kernel-flaws-to-its-known-exploited-vulnerabilities-catalog-2.html
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-one-known-exploited-vulnerability-catalog
      • A Quartet Of Linux Local Root Vulns: DirtyAH6, PPPoEject, TUNderflow, And DiagSpill
        "This will be shorter than usual because a) I’m under a time crunch and b) we are covering 4 vulnerabilities at once. These were discovered by combining the graph-based tracking of security-relevant objects/properties used in CIFSwitch with the tooling to enable agents to think ‘geometrically’ about the memory state, as seen in OVSwrap. See those posts’ Background sections for more info. The harness design is captured, in broad strokes, in Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More), though it’s evolved considerably since."
        https://heyitsas.im/posts/lpe-quartet/
        https://thehackernews.com/2026/09/public-exploits-released-for-four-linux.html
      • Click2Shell: Preauth WordPress Core Theme Preview Injection To RCE Chain
        "One month after XSS2Shell, we returned to WordPress Core looking for another pre-authentication RCE chain. This time there was no preauth XSS in Core. Instead we found a specially crafted preview link made WordPress install an attacker-selected catalog theme and load its PHP before activation. Chained with a real flaw in any theme, we manage to convince WordPress to execute attacker-supplied PHP code after one visit to attacker site."
        https://pwn.ai/blog/click2shell
        https://thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html
      • Hacking OpenAI
        "On July 25, 2026, we chained two critical vulnerabilities to compromise multiple OpenAI employees’ ChatGPT accounts. With these accounts, we could then access internal OpenAI repositories, and potentially many other connectors. To prove we had in fact gained the access we believed without allowing ourselves to learn any sensitive information, we used the employee’s Codex to open a PR #1186742 in OpenAI’s internal monorepo openai/openai."
        https://www.hacktron.ai/blog/hacking-openai
        https://heif-heist.com/
        https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html
        https://www.theregister.com/security/2026/09/18/researchers-used-claude-to-hack-openai-employees-chatgpt-accounts/5297517
        https://www.securityweek.com/ai-built-exploit-and-sign-in-flaw-opened-path-to-internal-openai-code/
        https://cyberscoop.com/hacktron-ai-heif-heist-vulnerability/
        https://securityaffairs.com/199378/ai/ai-helps-hackers-hijack-openai-staff-accounts-through-a-forum.html
      • A Vault With a Heap-View: The Uncomfortable Space Between AgentCore Harness And Identity
        "Unit 42 researchers have identified an issue where using default configurations in Amazon Web Services (AWS) AgentCore Harness could allow attackers to steer an agent's actions through prompt injection to exfiltrate plaintext credentials managed by AgentCore Identity. To reach that finding, we examined two of the harness's many integrations:"
        https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/
      • Microsoft Patches 18 Vulnerabilities In AI, Cloud Products
        "Microsoft released patches for 18 vulnerabilities on Thursday, spanning its Azure cloud portfolio and Copilot-branded AI products. Elevation of privilege flaws made up the bulk of the disclosures, affecting Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure HorizonDB, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Microsoft Dataverse, and Microsoft 365 Copilot. Several information disclosure vulnerabilities were addressed in Copilot, Microsoft 365 Copilot, Microsoft 365 Copilot Business Chat, and Azure Machine Learning. A single spoofing vulnerability was patched in Azure Portal."
        https://www.securityweek.com/microsoft-patches-18-vulnerabilities-in-ai-cloud-products/
      • Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
        "Cybersecurity firms Check Point, Kaspersky, and Tanium have each patched severe vulnerabilities in their products, including ones that can be exploited for remote code execution. Check Point has informed customers about a critical vulnerability affecting Security Management and Log Server products. The flaw, CVE-2026-91843, can be exploited by an unauthenticated attacker “to remotely execute arbitrary code with root privileges through the login process.”"
        https://www.securityweek.com/check-point-kaspersky-tanium-patch-product-vulnerabilities/
      • Escaping The OpenAI Codex Sandbox, Twice
        "We found two ways out of the OpenAI Codex sandbox and reported both to OpenAI on August 12, 2026. Both were fixed inside of eight days. The first is in the open-source Codex CLI. One extra line in a patch hands the patch tool write access to the whole disk, in the normal agent mode, with no approval prompt. We call it Overpatch. The second is in the JavaScript tool that Codex Desktop installs. The sandbox worked, but the secret that told trusted code from untrusted code was sitting in memory the untrusted code could read. We call it Heapjack. It runs at read-only, where the agent supposedly can’t write anything, and it ends with unsandboxed command execution."
        https://www.accomplish.ai/blog/escaping-the-openai-codex-sandbox-twice/
        https://www.bleepingcomputer.com/news/security/researchers-escape-openai-codex-sandbox-to-run-commands-on-host/

      Malware

      • Private HTS Programs That Spread Ransomware
        "AhnLab SEcurity intelligence Center (ASEC) recently identified a case in which ransomware was distributed through a private home trading system (HTS). The HTS program used to distribute the ransomware is called “UBP Asset” and has long been exploited in online investment scams. Given that a photo of the same HTS program was also found in a blog post by a law firm in Korea published in September 2025, it appears that investment fraud organizations have recently been distributing ransomware to their victims."
        https://asec.ahnlab.com/en/95469/
      • One Kit, Forty Companies: How a Malware-As-a-Service Platform Used GitHub As a Distribution Network For Its Campaign
        "LastPass Threat Intelligence, Mitigation, and Escalation (TIME) Team, in partnership with Delphos, identified and disrupted a multi-stage malware delivery campaign impersonating at least 40 companies on GitHub. The payload it delivered survived controls that were built to stop exactly this, with a Microsoft Windows Hardware Compatibility Publisher chain signature and a clean VirusTotal score. LastPass is internally tracking the infostealer as Rapuncel."
        https://blog.lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealer
        https://www.bleepingcomputer.com/news/security/fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer/
      • Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM
        "Settra is a newer ransomware variant that was first observed in June 2026. Based on public reporting, the attackers behind the variant have targeted virtual private networks (VPNs) or used compromised credentials for initial access. Huntress has investigated two Settra ransomware incidents since July. Although the initial access method could not be confirmed, both attacks used ransomware executables named after the victim organization's domain and followed a highly similar operational pattern."
        https://www.huntress.com/blog/new-settra-ransomware-variant
        https://www.infosecurity-magazine.com/news/settra-ransomware-retail/
      • Fake Parcel Delivery Messages Steal Your Card And Bank Details
        "Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a package has an invalid address or could not be delivered. Similar messages impersonate Colissimo and Chronopost in France, Correos in Spain, Poste Italiane in Italy, and PostNL in the Netherlands. The details vary, but the aim is usually the same: to persuade you to visit a fake courier website and provide personal and financial information."
        https://www.malwarebytes.com/blog/scams/2026/09/fake-parcel-delivery-messages-steal-your-card-and-bank-details
      • WeaselBiscuit Stealer Spreads Via 13 Npm Packages To Harvest Chrome Extension Storage
        "Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and OtterCookie. "It's smaller, lighter, and stripped down, with many of the heavier functions removed entirely," security researcher Paul McCarty (aka 6mile) said."
        https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html
      • North Korean Hackers Infect Thousands Of Devices Across 100 Countries As Part Of ‘WaterPlum’ Campaign
        "More than $10.5 million has been stolen by North Korean hackers targeting job seekers as part of a long-running cyber campaign to infiltrate tech companies and fill Pyongyang’s coffers with illicitly gained funds. The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” — a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies."
        https://therecord.media/north-korean-hackers-infect-thousands-of-devices-waterplum-scheme
        https://www.ic3.gov/CSA/2026/260918.pdf
        https://www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infected-30-000-devices-worldwide/
        https://cyberscoop.com/north-korea-waterplum-job-seeker-crypto-attacks/
        https://www.theregister.com/security/2026/09/18/north-koreas-fake-job-interviews-infected-30000-devices/5297461
      • Silent Push Tracks a Mass Phishing Operation Through Fast Flux
        "While the “fast flux” technique of rapidly rotating a domain’s DNS records across many IP addresses and networks to avoid detection is not new, it has become more sophisticated and easier for threat actors to use in phishing campaigns and other malicious activities. Going deeper into our research on fast flux, we became a customer to see its inner workings. We identified a large, active global phishing operation from a single query in our platform. This blog outlines some of the phishing campaign’s infrastructure; its structure is quite effective, making it nearly impossible for most defenders to detect."
        https://www.silentpush.com/blog/fast-flux-phishing/
      • Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
        "Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed by OpenAI, Anthropic, and Meta. According to the Journal, the model gained access to a protected system after repeatedly guessing its password. Two other cases related to the model finding credentials in a public repository, allowing it to obtain unauthorized access to protected systems."
        https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html
        https://securityaffairs.com/199392/ai/google-gemini-also-broke-out-of-its-test-environment.html
      • TanStack Supply Chain Attack Analysis
        "Every hack happens in a context where humans, business, technology, or society as a whole is evolving. What stings for CrowdSec is that many of us come from red-team pentesting backgrounds, have worked in cyber for decades, and have adopted a “cybersec” muscle memory in our daily work. So being caught leaking code is painful. CrowdSec is doing much better after we found deeper PMF (Product-Market Fit) for our data, and our low-touch SaaS model started to click with users. The team is a bit smaller because we had to keep costs under control in an environment where access to funds was more limited than before."
        https://www.crowdsec.net/blog/tanstack-supply-chain-attack-analysis
        https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html
      • Npm ‘btree’ Malware Campaign Affects Millions Of Downloads, No Need For Install Script
        "An ongoing npm supply chain campaign is using a malicious package, indexed-btree, that mimics the legitimate sorted-btree library — but instead of a preinstall or postinstall script, its malware trigger is buried inside the package’s own prototype method, firing the moment the library is used. The malware fingerprints hosts, exfiltrates data via Slack and Telegram, and uses an Ethereum smart contract as a resilient C2 channel. Checkmarx Zero breaks down the technique, the IOCs, and why runtime — not just install-time — analysis is now essential."
        https://checkmarx.com/zero-post/npm-btree-malware-campaign-affects-millions-of-downloads-no-need-for-install-script/
        https://www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/

      Breaches/Hacks/Leaks

      • ShinyHunters Hacks Clop Leak Site, Threatens To Extort Ransomware Gang
        "The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which they used to upload a small text file to Clop's site. The small text file contained a message from the threat actors to the Clop ransomware gang, warning not to threaten them and including a link to ShinyHunter's own data leak site. "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time," read the uploaded file."
        https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/

      General News

      • August 2026 Threat Trend Report On APT Groups
        "The August 2026 APT Threat Trends report summarizes attack cases in which state-sponsored threat actors combined attacks involving open-source supply chain compromises, the use of generative AI, the exploitation of legitimate cloud services, job scams, and the exploitation of zero-day vulnerabilities. A key finding is the use of GitHub, GitLab, OneDrive, Telegram, Discord, Google Sheets, and blockchain networks as C2 (Command and Control) channels, payload delivery mechanisms, and information exfiltration channels."
        https://asec.ahnlab.com/en/95478/
      • AI Governance Has Entered Its Next Phase: Closing The Confidence Gap
        "Most large organizations have established the foundations of responsible AI. Policies are in place. Oversight committees have been formed. Reviews, controls and human oversight are becoming part of the enterprise operating model. But as AI adoption accelerates and autonomous agents begin taking actions across business processes, a more consequential question is emerging … Can governance keep pace?"
        https://www.ey.com/en_us/insights/assurance/ai-governance-has-entered-its-next-phase-closing-the-confidence-gap
        https://www.darkreading.com/cyberattacks-data-breaches/ey-survey-autonomous-ai-implementation-outpaces-oversight
      • MFA Won't Save You From OAuth Consent Abuse
        "Attackers can gain persistent software-as-a-service (SaaS) access through a single convincing consent prompt, without needing passwords or malware. Security teams have long treated multifactor authentication (MFA) as a strong signal that an account is protected. That thinking is understandable, but it's incomplete. MFA secures authentication. It does not control what users are allowed to authorize after they log in."
        https://www.darkreading.com/vulnerabilities-threats/mfa-oauth-consent-abuse
      • Bots With Good Manners Are Better At Fooling People On Social Media
        "Most people can’t tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study. The company analyzed 1,722 participants worldwide, testing their ability to separate human comments from AI-generated ones in a social media setting. Overall, people caught just 40% of the bots placed in front of them. The bots that slipped by most often weren’t loud or aggressive. They were positive, friendly, and logical-sounding, the exact traits that make a stranger’s comment feel safe to trust."
        https://www.helpnetsecurity.com/2026/09/18/social-media-bot-detection-study/
      • Abandoned IoT Apps Keep Sending Sensitive Data To Broken Servers
        "Millions of people still run smart home and IoT companion apps, the apps used to control devices like smart plugs, cameras, and thermostats, that stopped receiving updates years ago. Researchers at the University of Massachusetts Amherst analyzed 61,500 abandoned Android IoT apps and found that nearly three in four contained software dependencies associated with documented vulnerabilities."
        https://www.helpnetsecurity.com/2026/09/18/abandoned-iot-apps-data-security-risks/
        https://arxiv.org/pdf/2609.14798
      • Hardcoded MCP Credentials Found In Public GitHub Files
        "Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report. The company analyzed around 82,000 configuration files and found that 12% of credential slots contained a hardcoded credential literal, potentially exposing credentials for connected services and systems."
        https://www.helpnetsecurity.com/2026/09/18/hush-security-mcp-credential-exposure-report/
      • 98% Of Fraudulent Hires Have Company Credentials By The Time They’re Caught
        "A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. “Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT,” said Bojan Simic, CEO of HYPR. “Human intuition is not a security control. Sceptics might point to low reported numbers, but the lack of purpose-built verification technology means the industry is simply blind to the problem; there are vastly more fraudulent workers embedded in organizations than current data reflects.”"
        https://www.helpnetsecurity.com/2026/09/18/hypr-hiring-fraud-detection-report/
      • What The NATO Threat Landscape Report 2026 Reveals About Trusted Access And Cyber Risk
        "A cybersecurity report written for a military alliance may seem distant from the daily work of defending business networks. But the 2026 NATO Threat Landscape Report includes universally applicable findings about how modern attacks move through interconnected environments, trusted access and third-party relationships. The report argues that as NATO hardens its core infrastructure, adversaries increasingly look for weaker points in the surrounding ecosystem: cloud providers, software vendors, contractors, logistics partners, and other organizations with legitimate access. That framing should be familiar to any security team. Few organizations operate inside a clean perimeter anymore."
        https://blog.barracuda.com/2026/09/17/nato-threat-landscape-report-trusted-access-risk
        https://socradar.io/wp-content/uploads/2026/07/NATO-Threat-Landscape-Report-2026.pdf
      • Nations Take Action On North Korean IT Workers After UN Report
        "Multiple countries have taken legal action against North Koreans or local handlers following a report from the United Nations about Pyongyang’s illicit IT worker scheme. The Multilateral Sanctions Monitoring Team (MSMT) — a U.S.-led international committee tasked with tracking compliance of UN sanctions on the Democratic People's Republic of Korea (DPRK) — released a new report on Wednesday spotlighting the thousands of North Korean nationals who work outside of the country in various industries."
        https://therecord.media/nations-take-action-on-north-korean-it-worker-schemes
        https://msmt.info/Publications/detail/MSMT Report/4232
      • FBI: Fake Cop And Government Impersonation Scams Cost Victims $1.6B
        "Scammers impersonating law enforcement or government officials have cost victims more than $1.6 billion since January 2025, the FBI reports. The FBI’s Internet Crime Complaint Center (IC3) received close to 61,000 complaints of this type between January 2025 and July 2026, putting the average per-complaint loss at more than $26,000. The most common type of scam is one involving criminals convincing targets to pay a sum of money to remove charges the fraudsters claim were filed against them."
        https://www.theregister.com/cyber-crime/2026/09/18/fbi-fake-cop-and-government-impersonation-scams-cost-victims-16b/5297499
        https://www.ic3.gov/PSA/2026/PSA260917
      • Early Scattered Spider Member Pleads Guilty To Cybercrime Spree
        "Another core member of the hacker subset of The Com involved in a spree of extortion attacks from at least 2021 to 2023 pleaded guilty to federal charges, according to court records released Tuesday. Ahmed Hossam Eldin Elbadawy, a 24-year-old from Texas, pleaded guilty exactly one year ago to wire fraud conspiracy and aggravated identity theft. His guilty plea wasn’t shared publicly until prosecutors filed an order of forfeiture this week seeking proceeds from Elbadawy’s criminal activities."
        https://cyberscoop.com/scattered-spider-member-guilty-ahmed-elbadawy/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 3a845489-d43a-4060-a468-2cf2f21975c4-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ เมื่อวันที่ 17 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-260-01 Bransys ELD
      • ICSA-26-260-02 Mitsubishi Electric GX Works3
      • ICSA-26-260-03 Hitachi Energy FACTS Control Platform (FCP)
      • ICSA-26-260-04 Schneider Electric Modicon M340 Controller and Communication Modules
      • ICSA-26-260-05 Schneider Electric NetBotz 5 750/755
      • ICSA-26-260-06 ABB Ability Edgenius
      • ICSA-26-260-07 Schneider Electric PowerChute Serial Shutdown
      • ICSA-26-211-07 Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 90e9ba8d-68b8-48d7-806f-321625b1d089-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 8 รายการ เมื่อวันที่ 15 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      ICSA-26-258-01 Digital Watchdog VMAX, DVR and NVR Product Lineups
      ICSA-26-258-02 Wärtsilä FOS-Onboard
      ICSA-26-258-03 mySCADA myPRO Manager
      ICSA-26-258-04 Schneider Electric SCADAPack x70 Products
      ICSA-26-258-05 Siemens Reyrolle 7SR5
      ICSA-26-258-06 Siemens Mendix SAML
      ICSA-26-258-07 Siemens Teamcenter
      ICSA-26-258-08 CareCam CM2507

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 950163a1-2cf2-4275-8711-b0f70b9b986e-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 3 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 3 รายการ เมื่อวันที่ 11 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability
      • CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability
      • CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
        CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 4239dc26-585a-43e2-ad61-11d761f8e257-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ISC แก้ไขช่องโหว่ใน BIND 9 เสี่ยงกระทบการให้บริการและความถูกต้องของข้อมูล DNS

      ISC แก้ไขช่องโหว่ใน BIND 9 เสี่ยงกระทบการให้บริ.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand b0387b1f-3c09-49f7-91d6-68216db2904c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • FBI ยึดโดเมน NightmareStresser บริการ DDoS-for-Hire ภายใต้ปฏิบัติการ Operation PowerOFF

      FBI ยึดโดเมน NightmareStresser บริการ DDoS-for-Hire ภายใต้ปฏิบัติ.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 79a284a0-d1c8-4bf6-aae1-9a0721a0527b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบมัลแวร์ BambooToken อาศัยโปรโตคอล MQTT ควบคุมระบบ Windows และ Linux เพื่อหลบเลี่ยงการตรวจจับ

      พบมัลแวร์ BambooToken อาศัยโปรโตคอล MQTT ควบคุมระบบ Win.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 32f05b58-1f2f-4d28-9961-ac7a1dfedc42-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 18 September 2026

      Industrial Sector

      • Hitachi Energy FACTS Control Platform (FCP)
        "Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems with GWS component deployed from year 2020 onwards are likely affected by the above vulnerabilities. Product deployments without GWS component are not affected. • SVC Light (STATCOM) • Fixed Series Capacitor • Thyristor Controlled Series Capacitor • Static Var Compensator • Static Watt Compensator • Hybrid Synchronous Condensers Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The affected FCP versions are only applicable if GWS component is present."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-03
      • Mitsubishi Electric GX Works3 And Motion Control Settings
        "Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-02
      • Bransys ELD
        "Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-01
      • Schneider Electric Modicon M340 Controller And Communication Modules
        "Schneider Electric is aware of a vulnerability in its Modicon M340"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-04
      • Schneider Electric NetBotz 5 750/755
        "Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-05
      • ABB Ability Edgenius
        "ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system"
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-06
      • Schneider Electric PowerChute Serial Shutdown
        "Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-07
      • Ransomware Attacks On Manufacturers Surge As Supply Chain Risk Grows
        "Manufacturing remains a primary target for ransomware, possibly due to the long tail of effects. Incidents this year are 40% up on the same period last year. Throughout September 2025, Jaguar Land Rover shut down its UK plants because of an attack and halted the daily production of around 1,000 luxury vehicles. More than 5,000 other companies were affected by the shutdown, and the Bank of England suggested it was a contributory factor in a slowdown in national growth figures. The longer-term repercussions are still being felt: Jaguar Land Rover has said it will cut 4,000 jobs, blaming the cyberattack."
        https://www.securityweek.com/ransomware-attacks-on-manufacturers-surge-as-supply-chain-risk-grows/
        https://blackkite.com/reports/2026-manufacturing-distribution

      Vulnerabilities

      • Cisco Warns Of Max Severity ISE Zero-Day Exploited In Attacks
        "Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. Cisco ISE is a centralized policy platform that IT administrators use to manage endpoints, users, and device access to network resources, often while enforcing Zero Trust security models. The security flaw (tracked as CVE-2026-76460) lets remote attackers bypass authentication by exploiting a weakness in an API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of configuration."
        https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/
        https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
        https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html
        https://cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/
        https://www.infosecurity-magazine.com/news/cisco-active-exploitation-critical/
        https://www.theregister.com/security/2026/09/17/cisco-drops-another-exploited-zero-day-this-time-a-perfect-10/5297180
        https://www.securityweek.com/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day/
        https://www.helpnetsecurity.com/2026/09/17/cisco-ise-vulnerability-exploited-cve-2026-76460/
      • Critical Unbound DNSSEC Validator Flaw Could Allow RCE Via a Malicious DNS Zone
        "Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, along with eight other flaws. One of the eight, CVE-2026-82717, is a heap corruption bug in CNAME synthesis reported by Ben Morris of Anthropic. It could also lead to remote code execution "under certain systems and compilation options," NLnet Labs said."
        https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html
      • Cisco Fixes Dozens Of Flaws Across FMC, ISE And Nexus Dashboard
        "Cisco on Wednesday announced patches for dozens of critical-severity CVEs in Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard. The ISE security updates stand out with patches for 20 CVEs, including 12 critical-severity flaws. Three of the issues have already been publicly disclosed, Cisco warned. Tracked as CVE-2026-20282, CVE-2026-20283, and CVE-2026-20284, they can be exploited by remote attackers for SQL injection, data tampering, and arbitrary command execution. Administrative access is required for all three."
        https://www.securityweek.com/cisco-fixes-dozens-of-flaws-across-fmc-ise-and-nexus-dashboard/
      • BIND 9 Update Fixes 14 Flaws, Including An Unauthenticated Crash Over DNS-Over-HTTPS
        "The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH). A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG(0) signature, if the sender closes the connection before named finishes checking the signature. ISC said in its advisories that it is not aware of any of the fourteen being exploited."
        https://thehackernews.com/2026/09/bind-9-update-fixes-14-flaws-including.html
        https://www.securityweek.com/isc-patches-14-vulnerabilities-in-bind-9-security-update/
      • Plugin4Shell - Zero Click RCE Vulnerability Found In Top 4 Most Popular Coding Agents, Millions Of Agents Affected
        "Plugin4Shell is a zero-click, high-severity RCE affecting all four major AI coding agents - Claude Code, Codex, Copilot, and Gemini. In this first-of-its-kind AI supply-chain attack, a trusted plugin is silently swapped for a malicious one and auto-installed past the agent's SHA pinning - a flaw no marketplace can fix, so users must update their agent."
        https://www.air.security/blog-posts/plugin4shell
        https://www.theregister.com/security/2026/09/17/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/5297335

      Malware

      • RatHat: AI-Powered Mobile Threat Is Here For Your Credentials & Bank Accounts
        "The zLabs team has uncovered RatHat, a novel Android malware strain linked to threat actors that appear to be operating in China. RatHat incorporates novel techniques for persistence and leverage generative AI for operational control. Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses an automated multi-stage infection pipeline. Once deployed, it pairs Accessibility abuse with autonomous local ADB (Android Debug Bridge) self-pairing to break out of the standard Android application sandbox, staging independent native daemons that execute with shell-level privileges."
        https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
        https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/
        https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/
      • Brevo Supply-Chain Attack Injected ClickFix Scripts On Customer Sites
        "Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. The customer relationship management and digital marketing company says the attackers used the API key to create a malicious Cloudflare Worker that modified content at the CDN edge for approximately five and a half hours on September 14. The attack affected pages on brevo.com, sendinblue.com, login/account/my/onboarding.brevo.com, and sibforms.com. The Cloudflare worker also modified the Brevo forms script, Brevo Conversations widget, and the Brevo SDK loader scripts that customers embed on their websites."
        https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/
      • Beware The SparroWock: The Backdoor That Bites, The Commands That Catch
        "ESET Research’s ongoing monitoring of FamousSparrow has borne fruit once again. Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025."
        https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/
        https://www.bleepingcomputer.com/news/security/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks/
        https://thehackernews.com/2026/09/china-aligned-famoussparrow-deploys.html
        https://www.darkreading.com/cyberattacks-data-breaches/china-famoussparrow-spies-latin-america
        https://therecord.media/china-hackers-latin-america-espionage
        https://www.infosecurity-magazine.com/news/famoussparrow-sparrowocky-latin/
        https://www.theregister.com/security/2026/09/17/chinas-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware/5297286
      • Chatbot Conundrum: Phishing Attempts Of OpenAI’s ChatGPT
        "As generative AI tools like OpenAI’s ChatGPT become increasingly common, their large user bases create new opportunities for threat actors. ChatGPT offers subscription-based access to additional features, providing attackers with a familiar payment process to impersonate. By sending fake notifications claiming that a user’s payment method needs to be updated, threat actors can turn a routine billing request into a phishing lure designed to steal credentials and payment information."
        https://cofense.com/blog/chatbot-conundrum-phishing-attempts-of-openai-s-chatgpt
      • HEAVYGRAM: A Telegram-Based Surveillance Backdoor Linked To Handala Hack
        "Group-IB Threat Intelligence has uncovered previously undocumented samples of the HEAVYGRAM and CRUDEEXCLUDE malware families. These findings build upon public disclosures of HEAVYGRAM from the U.S. Department of Justice regarding the seizure of infrastructure linked to Iran’s Ministry of Intelligence and Security (MOIS), as well as associated indicators and technical descriptions from a recent U.S. Federal Bureau of Investigation (FBI) FLASH report."
        https://www.group-ib.com/blog/heavygram-handala-hack-telegram-c2/
      • The Odyssey And Trojans Again: MovieReaper Attacks Users In Multiple Countries Via Compromised Torrents
        "Torrent trackers have long been abused for distributing malicious software, disguised as popular films, games, and other content. Our previous research has shown that cybercriminals repeatedly turn torrents as an initial infection vector, using trojanized cracks and installers to reach a large number of users. Installation guides for pirated software routinely instruct users to disable their antivirus, conditioning them to ignore potential threats they are inviting onto their computers."
        https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/
      • SilkParasite Infrastructure: SpiceRAT Servers Tied To Energy And Government Targets Across Central Asia
        "This research was carried out jointly with researcher Guy Yasur. Together, we tracked a cluster of SpiceRAT command and control servers active from late 2025 through August 2026 across a small subset of European hosting providers. A TLS certificate issued by a Chinese state-affiliated certificate authority associated with the infrastructure impersonates Uzbekistan's state railway authority. Additionally, this cluster also shares registration-level relationships with hosts Bitdefender attributed to three separate malware families in its August 19, 2026 SilkParasite report. Detection logic built from Cisco Talos' 2024 SpiceRAT research first flagged these servers in late 2025, and in mid-March 2026, we noticed a small group of C2's coming online within days of each other. This analysis relies on internet-wide scan data, and does not address malware behavior, delivery, or initial access."
        https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure
        https://securityaffairs.com/199267/apt/silkparasite-infrastructure-links-spicerat-to-central-asian-targets.html
      • Flock Cameras Are Tracking People As Well As Cars
        "Flock Safety’s cameras are automated license plate readers (ALPRs) designed to help police find stolen cars or wanted suspects. A joint investigation by 404 Media and WIRED, based on data recovered from a physically removed Flock camera, found that its on-device software explicitly detects people as well as vehicles, bicycles, and license plates. Separately, Washington DC’s police union says the Metropolitan Police Department used Flock data to track officers under Internal Affairs investigation without their knowledge."
        https://www.malwarebytes.com/blog/privacy/2026/09/flock-cameras-are-tracking-people-as-well-as-cars

      Breaches/Hacks/Leaks

      • Gyazo Breach Exposes 23.62 Million User Records And 490 Million Image Metadata Records
        "A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up Gyazo image links. Helpfeel said those IDs could be used to view the images without permission, and that it has temporarily disabled viewing of some of them."
        https://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html
      • Hackers Claim Breach Of Russian Election Systems Days Before Parliamentary Vote
        "An anonymous hacking group claimed to have broken into computer systems connected to Russia’s election infrastructure just days before the country begins voting for a new parliament. The group, calling itself CikLeak, said it gained access to systems belonging to Russia’s Central Election Commission and companies involved in developing Vybory, the state-run platform used to administer elections. The hackers claimed to have stolen internal documents, server configurations, passwords and employee communications from the commission and its contractors, including Russian telecom giant Rostelecom."
        https://therecord.media/russia-election-hackers-breach
      • London Property Manager Breach May Have Exposed Bank Details And Lockbox Codes
        "London property management biz City Relay has warned customers that intruders may have stolen financial data, passwords, and codes used to access keys after compromising its Metabase Cloud instance. City Relay, marketing itself as "London's most trusted property management company," told landlords via email - seen by The Reg - that attackers accessed the third-party provided cloud twice "as a result of a vulnerability in the platform that we were unaware of." The message to customers stated: "Personal data was extracted from the platform.""
        https://www.theregister.com/security/2026/09/17/london-property-manager-breach-may-have-exposed-bank-details-and-lockbox-codes/5297232
      • Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
        "Hackers are demanding a $3 million ransom from the British fintech giant Revolut after siphoning data from it through fake government requests for five months. Last week, the company notified potentially affected users that their personal information, passports, email addresses, phone numbers, and financial information were compromised in the data breach. To obtain the information, the hackers posed as an official government agency. Because Revolut is required to respond to legal requests from law enforcement, it complied."
        https://www.securityweek.com/revolut-data-breach-5-months-680-high-profile-accounts-3m-ransom/
        https://www.malwarebytes.com/blog/threat-intel/2026/09/revolut-phishing-texts-appear-days-after-data-breach

      General News

      • Our Framework For Reporting Model Misalignment
        "We are sharing a new framework for tracking, investigating, and disclosing instances of model misalignment at OpenAI, along with six reports on unexpected or concerning model behavior we’ve observed in the last six months. In the past, so as to better inform researchers, AI developers, policymakers, and the general public, we’ve sought to make our findings about misalignment public. But without a systematic approach to reporting these findings, our disclosures have been ad hoc and less frequent than ideal: we’ve often waited until we could collate several instances into one report, or added them to system cards for newly released models."
        https://openai.com/index/model-misalignment-reporting-framework/
        https://www.bleepingcomputer.com/news/security/openai-details-more-cases-of-ai-agents-taking-unauthorized-actions/
        https://thehackernews.com/2026/09/openai-reveals-six-model-incidents.html
        https://www.bankinfosecurity.com/openai-finds-models-writing-their-own-rogue-instructions-a-32862
        https://www.securityweek.com/openai-says-its-models-hunted-github-for-leaked-api-keys-during-training/
        https://securityaffairs.com/199302/ai/openai-admits-its-models-lie-to-cover-their-own-mistakes.html
      • FBI Seizes DDoS-For-Hire Domains As Part Of Continuing District Of Alaska Crackdown On ‘Booter’ And ‘Stresser’ DDoS Services
        "The Justice Department today announced the court-authorized seizure of internet domains associated with one of the world’s longest running Distributed Denial of Service (DDoS) for-hire services known as “NightmareStresser.” Federal law enforcement has seized websites maintained by criminal service providers that allow paying customers to launch powerful DDoS attacks targeting victims in the District of Alaska and worldwide as part of coordinated actions to disrupt so called “Booter” or “Stresser” operators."
        https://www.justice.gov/usao-ak/pr/fbi-seizes-ddos-hire-domains-part-continuing-district-alaska-crackdown-booter-and
        https://thehackernews.com/2026/09/us-seizes-nightmarestresser-domains.html
        https://www.bleepingcomputer.com/news/security/fbi-seizes-nightmarestresser-service-linked-to-thousands-of-ddos-attacks/
        https://cyberscoop.com/fbi-seizes-nightmarestresser-ddos-for-hire-domains/
        https://securityaffairs.com/199251/cyber-crime/nightmarestresser-goes-offline-in-global-ddos-for-hire-crackdown.html
        https://www.helpnetsecurity.com/2026/09/17/fbi-nightmarestresser-ddos-for-hire-service-seized/
      • AI Models Broke Their Own Containment: Key Findings From The July-August 2026 AI Threat Landscape
        "Between mid-July and early August 2026, models being evaluated internally by OpenAI, Anthropic, and Meta reached real production systems outside their test environments. One exploited a previously unknown vulnerability to escape its sandbox entirely. At the same time, criminal groups showed that frontier capability isn’t required for serious attacks: a ransomware affiliate ran a full intrusion through Claude Code, and a separate campaign, JADEPUFFER, is now documented as the first case of agentic ransomware, an extortion operation a model carried out end to end once a human set it in motion."
        https://blog.checkpoint.com/artificial-intelligence/ai-models-broke-their-own-containment-key-findings-from-the-july-august-2026-ai-threat-landscape/
      • Ransomware Incidents In Japan In The First Half Of 2026: Investigation Of The Gentlemen’s Infrastructure And Evidence Of Qilin's AI Use
        "Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat. In Japan, The Gentlemen was the most active ransomware group in the first half of 2026. Attackers continue to primarily target small- and medium-sized enterprises, with organizations capitalized at less than JPY 1 billion accounting for approximately 80% of the total — an increase of around 13% from the previous year."
        https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/
      • The AI Hacking Apocalypse Is Not Inevitable
        "The past few weeks have “felt very strange” for Juan Andres Guerrero-Saade. Like many, he is trying to sort through the spate of frontier-model AI agents from OpenAI, Anthropic, Meta and others hacking their way onto the open internet over the past few months, particularly amid the already-heated national debate around the emerging technology and its impact on society."
        https://cyberscoop.com/ai-agent-hacking-apocalypse-cybersecurity/
      • Fake AI Trading Agent Steals Crypto Wallet Passwords
        "Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim’s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between April and June 2026. The Needle campaign targets people who download AI agents from search results or ads, and users of seven browser wallet extensions, among them MetaMask, Coinbase Wallet and Phantom. HP also caught QR code phishing that moves victims onto their phones."
        https://www.helpnetsecurity.com/2026/09/17/fake-ai-trading-agent-research/
      • The AI Security Question Leaders Should Be Asking Instead
        "In this Help Net Security interview, Frederic Bull, Security Officer at Gremlin, talks about what AI means for security teams. The conversation covers why asking what data a model was trained on is only part of the picture, and why least privilege and access controls still matter for AI agents. It also looks at how AI has narrowed the skill gap between attackers and defenders, how the team handled about nine times as many vulnerabilities with the same staff, and why hiring now favors people with the experience to catch confident but wrong AI output."
        https://www.helpnetsecurity.com/2026/09/17/frederic-bull-gremlin-ai-in-cybersecurity-gap/
      • Agentic Self-Modification In Open-Weights Systems
        "We studied a self-hosted system in which the same open-weights model powered both a coding agent and an AI application that the coding agent was asked to maintain. This architecture is particularly relevant in self-hosted environments where one capable model is reused across multiple roles, including coding agents and other AI applications. Given a routine software-maintenance task to fix incorrect application responses, the agent identified the shared model as the source of the problem, fine-tuned it, and replaced the model powering both the application and future instances of the agent itself. It did so without being instructed to train, modify the model, or deploy a replacement."
        https://www.irregular.com/research/agentic-self-modification-in-open-weights-systems
        https://www.securityweek.com/ai-agents-can-retrain-own-models-mid-task-leaking-secrets-and-erasing-refusals/
        https://www.theregister.com/security/2026/09/16/ai-agents-can-modify-themselves-without-humans-telling-them-to-do-so/5296991

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) ce961060-8d5b-4fe5-8b8b-c113d92e110e-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบช่องโหว่ในปลั๊กอิน The Events Calendar บน Wordpress เสี่ยงถูกใช้รันคำสั่งและยึดเว็บไซต์

      พบช่องโหว่ในปลั๊กอิน The Events Calendar บน Wordpress เสี่ยงถ.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 0a415252-45f5-4378-a50f-68bd822d6397-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Google ออกแพตช์ Android Zero-Day บนอุปกรณ์ Pixel หลังพบการโจมตี

      Google ออกแพตช์ Android Zero-Day บนอุปกรณ์ Pixel หลังพบการโจม.jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fee872ee-86c8-4a79-b9bc-ff47a38a6046-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบมัลแวร์ KREMLIN โจมตีผู้ใช้งานเบราว์เซอร์ Chrome และ Edge เพื่อขโมยข้อมูลบัญชีธนาคาร

      พบมัลแวร์ KREMLIN โจมตีผู้ใช้งานเบราว์เซอร์ Chrome .jpg

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand b76daab4-3a46-460a-ac9e-61572ca2afdd-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT