NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,422
    • กระทู้ 2,423
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 7 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 7 รายการ เมื่อวันที่ 28 กรกฏาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-209-01 Siemens Desigo CC
      • ICSA-26-209-02 Siemens Mendix Runtime
      • ICSA-26-209-03 Siemens SIMATIC S7-PLCSIM Advanced
      • ICSA-26-209-04 Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
      • ICSA-26-209-05 MikroTik RouterOS and Cloud Hosted Router
      • ICSA-26-209-06 igloohome Smart Lock Mobile Application
      • ICSA-26-209-07 ABB KNX Update Tool

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories 73d87d32-5fa2-4969-881e-1a69bc3a1b68-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 7 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 7 รายการ เมื่อวันที่ 28 กรกฏาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-209-01 Siemens Desigo CC
      • ICSA-26-209-02 Siemens Mendix Runtime
      • ICSA-26-209-03 Siemens SIMATIC S7-PLCSIM Advanced
      • ICSA-26-209-04 Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
      • ICSA-26-209-05 MikroTik RouterOS and Cloud Hosted Router
      • ICSA-26-209-06 igloohome Smart Lock Mobile Application
      • ICSA-26-209-07 ABB KNX Update Tool

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories a598f98b-adee-4261-b133-e61952567044-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 29 July 2026

      Industrial Sector

      • CI Fortify – Advice For Isolating Vital Systems
        "This CI Fortify guide helps critical infrastructure organisations improve their cyber resilience. Developed with international partners, the guide explains how organisations can isolate critical operational technology (OT) and supporting systems from other networks during cyber incidents or periods of increased cyber threat. It provides practical guidance and strategic advice for OT owners, operators, and cyber security teams. By reviewing and applying this guidance, organisations can strengthen their ability to prepare for, respond to, and recover from cyber incidents."
        https://www.cyber.gov.au/business-government/secure-design/operational-technology-environments/ci-fortify/ci-fortify-advice-for-isolating-vital-systems
        https://www.bleepingcomputer.com/news/security/cisa-shares-advice-on-isolating-vital-systems-during-cyberattacks/

      Vulnerabilities

      • Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code As Root
        "OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6 REQUEST. odhcpd runs as root, and the advisory notes that embedded hardware commonly lacks stack canaries and address space layout randomization (ASLR), making code execution a realistic outcome on typical devices."
        https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html
      • Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
        "JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already been updated. JetBrains has credited Antoni Tremblay with discovering and reporting the flaw on July 10, 2026. "If exploited, this flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process," JetBrains said."
        https://thehackernews.com/2026/07/critical-teamcity-flaw-could-let.html
        https://securityaffairs.com/196169/security/jetbrains-patches-cvss-9-8-teamcity-flaw-allowing-server-takeover.html
        https://www.helpnetsecurity.com/2026/07/28/teamcity-rce-cve-2026-63077-fixed/
      • How We Hacked Thousands Of Data Centers In Minutes Using a 20-Year-Old Vulnerability
        "A Baseboard Management Controller (BMC) is a highly privileged management processor that provides remote control over a server independently of its operating system. It allows administrators to manage and troubleshoot servers remotely, eliminating the need for physical access to the hardware. We identified 36,872 internet-exposed server-management interfaces running IPMI, a protocol introduced more than two decades ago for remote control over physical servers. Of the systems we tested, 24,650 disclosed password-derived authentication hashes before login because of CVE-2013-4786, a vulnerability in the IPMI 2.0 authentication protocol that enables offline password-cracking attempts."
        https://lavahq.io/research/bmc-exposure-alert
        https://thehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html
        https://www.bleepingcomputer.com/news/security/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/
        https://www.darkreading.com/cyber-risk/flaw-exposes-data-centers-server-takeover
        https://www.helpnetsecurity.com/2026/07/28/exposed-bmc-ipmi-vulnerability-research/
      • FaceHugger: Vulnerabilities In Hugging Face Diffusers Open Door To Supply Chain Attacks On Enterprise AI
        "Zafran Labs discovered a set of high-severity vulnerabilities in Hugging Face's diffusers library that let a malicious model repository silently execute arbitrary code on any client machine that loads it. These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the custom pipelines loading process. Hugging Face has become a critical part of the AI software supply chain, rapidly evolving to be the "GitHub of the AI era". Its libraries and repositories are widely integrated into development, research, and production environments."
        https://www.zafran.io/resources/facehugger-vulnerabilities-in-hugging-face-diffusers-open-door-to-supply-chain-attacks-on-enterprise-ai
        https://www.infosecurity-magazine.com/news/hugging-face-diffusers-trust/
      • Apple Patches 87 Vulnerabilities In iOS, 155 In MacOS Tahoe
        "Apple announced on Monday that it has released patches for dozens of vulnerabilities discovered recently in its operating systems. The company patched 87 vulnerabilities with the release of iOS 26.6 and iPadOS 26.6. The flaws can be exploited to access sensitive user data, fingerprint users, cause a DoS condition, execute arbitrary code, delete files, modify the file system, bypass security, add contacts without authorization, spoof the UI, and escalate privileges. In macOS Tahoe 26.6, Apple fixed 155 vulnerabilities, including ones allowing access to sensitive user data, arbitrary code execution, security bypasses, and DoS attacks."
        https://www.securityweek.com/apple-patches-87-vulnerabilities-in-ios-155-in-macos-tahoe/
        https://www.malwarebytes.com/blog/news/2026/07/july-apple-updates-are-especially-important-if-you-receive-images
      • Libssh2 Flaws Let Malicious SSH Servers Corrupt Client Memory
        "Four new libssh2 vulnerabilities put SSH and SFTP clients at risk. Each one lets a malicious SSH server corrupt memory on the machine that connects to it. VulnCheck disclosed the flaws on July 24, 2026, and upstream fixes are ready."
        https://securityonline.info/libssh2-vulnerabilities/
      • When AI Makes 0-Days Feel Like N-Days
        "After my n-day analysis on net/tls bugs and exploit writing for a patched net/rxrpc bug, I moved on to 0-day bug hunting. With the help of AI, I found a UAF bug in net/sched, and went about creating an LPE exploit based on it. This blog goes into the technical details of that exploit, and how I optimized it to target CentOS 9 desktop in TyphoonPwn 2026. Additionally, I will show a glimpse of two other exploitable bugs I found in kernel/events/core.c (with an LPE exploit for one)."
        https://starlabs.sg/blog/2026/07-when-ai-makes-0-days-feel-like-n-days/
        https://thehackernews.com/2026/07/researcher-says-ai-helped-develop-linux.html
        https://www.infosecurity-magazine.com/news/ai-linux-kernel-zero-day-net-sched/

      Malware

      • Call Of Duty Mobile Scam Uses Fake Free Points To Steal Player Accounts
        "Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway. Victims are asked to log in with their email address and password to claim free Call of Duty Points (CP), the game’s premium currency. They’re then redirected to a second page asking for their two-factor authentication (2FA) code. The site has no connection to Activision. Its only purpose is to steal the login details needed to take over accounts."
        https://www.malwarebytes.com/blog/threat-intel/2026/07/call-of-duty-mobile-scam-uses-fake-free-points-to-steal-player-accounts
        https://www.helpnetsecurity.com/2026/07/28/call-of-duty-mobile-players-scam/
      • Mirage Kitten Targets Middle East And Africa Region With New Malware
        "Mirage Kitten – also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore – is an advanced persistent threat (APT) group focused on cyber-espionage operations against aerospace, aviation, defense, and telecommunications sectors across the Middle East and Europe, using highly targeted spear-phishing campaigns, fake recruitment portals, and custom multi-stage malware to gain persistent access and exfiltrate sensitive data. During recent threat research, we identified a previously undocumented malware set developed and used by Mirage Kitten. The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture; and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, for covert network access and operator-controlled tunneling."
        https://securelist.com/mirage-kitten-new-tools/120811/
        https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html
      • CubePilot Drone Software Dev Hit By DNS Hijacking To Intercept Traffic
        "CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. Hijacking domain name system (DNS) records allows threat actors to redirect users to their infrastructure, diverting traffic intended for a legitimate service. This exposes users to dangerous scenarios such as sensitive data interception, malware delivery, and phishing. According to a status update published on CubePilot’s website, an attacker gained control of the cubepilot[.]org domain DNS settings on July 24, allowing them to intercept traffic intended for internal systems."
        https://www.bleepingcomputer.com/news/security/cubepilot-drone-software-dev-hit-by-dns-hijacking-to-intercept-traffic/
      • Notes From Underground: Adversarial Prompt Injection
        "AI’s impact on the threat landscape continues to be top of mind for most organizations, both in terms of how malicious actors will leverage the technology in attacks and how defenders will secure their own operationalized AI and agentic applications. Proofpoint Threat Research continues to observe widespread incorporation of large language model (LLM) assisted tooling and generated material into attack chains. This is leading to enhanced scale, velocity, and variability of activity within malicious campaigns. The noted increase of device code phishing frameworks is one good example."
        https://www.proofpoint.com/us/blog/threat-insight/notes-underground-adversarial-prompt-injection
      • Tengu: A Modernized Mirai That Doesn’t Want To Leave
        "Tengu is a modern Mirai-derived IoT malware family that shows how today’s botnets are evolving beyond simple distributed denial-of-service tooling. We selected tengu for deeper analysis because it stood out from the many Mirai-derived samples we track, and because it was surfaced by our machine-learning system for identifying previously unknown malware families. It combines a custom encrypted command-and-control protocol, proxy functionality, payload updates, system and network discovery, and a broad set of denial-of-service capabilities targeting multiple protocols and services. It also includes multiple persistence and self-defense mechanisms designed to keep the malware running on compromised Linux-based devices and make recovery more difficult."
        https://www.nozominetworks.com/blog/tengu-a-modernized-mirai-that-doesnt-want-to-leave
        https://thehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html

      Breaches/Hacks/Leaks

      • Origin Energy Data Breach Affects 900,000 Australians
        "Australian power company Origin Energy Limited said the recent data breach affects 900,000 current and former customers. Origin Energy, which has roughly 4.8 million customers, is one of Australia’s largest electricity and gas retailers. The company recently started investigating a cybersecurity incident and determined that threat actors gained access to customer data, including names, dates of birth, phone numbers, addresses, account information, and partial payment card or bank account numbers."
        https://www.securityweek.com/origin-energy-data-breach-affects-900000-australians/
      • Coordinated Cyberattack Disrupts Water Utilities In 30+ Minnesota Communities
        "More than 30 Minnesota communities saw their water and wastewater utilities disrupted by a coordinated cyberattack on Sunday and Monday, the state’s technology bureau announced Tuesday. Among those was the City of Braham, a community of 1,700 people that brands itself the “Homemade Pie Capital of Minnesota.” Braham officials on Monday morning announced on the city website that its water plant was “offline for an unknown reason” and asked its residents to minimize water use because the city water tower held only a “limited quantity.” A second notice later that day noted that the plant was back online, explaining that the outage had been the result of “a malicious cyber-attack of computerized operating systems by unknown actors.”"
        https://statescoop.com/coordinated-cyberattack-disrupts-water-utilities-in-30-minnesota-communities/

      General News

      • Shadow AI Incident Response Begins With Logs That May Already Be Gone
        "In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound traffic to AI platforms are often gone before responders arrive, and what regulators look for when they assess whether a company did enough. Wityak also discusses the gap between an AI policy in a wiki and a control a company can defend, and when documentation helps or hurts."
        https://www.helpnetsecurity.com/2026/07/28/brandy-wityak-levelblue-shadow-ai-incident-response/
      • For Some, So-Called ‘Skynet Day’ Came Too Close To Sci-Fi After a Rogue Agent Hacked Into a Startup
        "To be fair, James Cameron did warn us. Long before OpenAI broke out of its test corral and hacked into Hugging Face, before the internet and Sam Altman were even born, Cameron wrote a screenplay about an autonomous artificial intelligence system that triggers a nuclear apocalypse. That system, “Skynet,” was solidly science fiction — and, for its day, pure speculation. But four decades after it appeared in “The Terminator,” it looks more like a forecast of the “unprecedented cyber incident” in which a rogue artificial intelligence system hacked into another AI company on its own."
        https://www.securityweek.com/for-some-so-called-skynet-day-came-too-close-to-sci-fi-after-a-rogue-agent-hacked-into-a-startup/
      • Fast Remediation Is The New Trust Model: JFrog And OpenAI Collaboration On Zero-Day Security Findings
        "Just last week, OpenAI and Hugging Face jointly disclosed what may be the first incident of its kind: during an internal evaluation of frontier cyber capabilities, OpenAI’s models, running deliberately without production safeguards in an isolated research environment, autonomously discovered and employed chained vulnerabilities to escape its sandbox, reach the open internet, and extract evaluation answers from Hugging Face’s infrastructure. The industry is right to pay attention. This is a preview of a world where software, not humans, probes, chains, and exploits vulnerabilities at machine speed. We want to share how the JFrog and OpenAI teams collaborate on security incidents to drive them to resolution, and why we believe the outcome demonstrates the trust model the industry now needs."
        https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/
        https://www.bleepingcomputer.com/news/security/openai-models-used-artifactory-zero-days-to-escape-to-the-internet/
        https://thehackernews.com/2026/07/jfrog-confirms-openai-models-exploited.html
      • VulnCheck State Of Exploitation 1H-2026
        "Over the past six months, we’ve seen a significant change in vulnerability discovery and disclosure resulting in a substantial increase in the number of CVEs disclosed. This increase has come with warnings about the increase in vulnerability discovery by Autonomous AI systems, creating a “dangerous” scenario for the software ecosystem. So, I was curious to explore: are more vulnerabilities being discovered and disclosed, resulting in more vulnerabilities being exploited? Is the rate at which vulnerabilities are being exploited faster? Are vulnerabilities being discovered with AI tools more dangerous? Or are we all feeding into the AI-Assisted vulnerability discovery hype cycle?"
        https://www.vulncheck.com/blog/state-of-exploitation-1h-2026
        https://www.bankinfosecurity.com/many-more-bugs-but-exploits-stay-steady-a-32346
        https://cyberscoop.com/ai-assisted-security-tools-are-finding-more-bugs-but-the-threat-level-has-not-changed/
      • IR Trends Q2 2026: Phishing And Weaponized Remote Management Tools Drive Attack Chains
        "Phishing was the primary means of gaining initial access this quarter, appearing in over half of all Cisco Talos Incident Response (Talos IR) engagements – an increase from approximately a third of engagements last quarter. Attackers continued to innovate their delivery methods to evade defenses, deploying QR code-embedded PDFs to bypass traditional email gateways and hosting links on trusted cloud platforms. We also saw a spike in authentication abuse this quarter — observed in 65 percent of engagements compared to 35 percent last quarter — with attackers frequently bypassing or defeating multi-factor authentication (MFA) using adversary-in-the-middle (AitM) proxies, session-token theft, MFA fatigue attacks, and self-enrolled devices, amongst other methods."
        https://blog.talosintelligence.com/ir-trends-q2-2026/
        https://www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/
      • Discovering Cryptographic Weaknesses With Claude
        "Using Claude Mythos Preview, researchers at Anthropic have discovered improved ways to attack cryptographic algorithms (the mathematical methods used to keep online data private). The first attack significantly weakens HAWK, a digital signature scheme that was built for a post-quantum world. The second identifies a new way to attack round-reduced AES, the most widely used symmetric cipher. These are substantial research advances, but they do not currently affect any production systems. This post describes both findings in more detail and discusses the implications for cryptography in an age of powerful AI models."
        https://www.anthropic.com/research/discovering-cryptographic-weaknesses
        https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html
        https://cyberscoop.com/anthropic-claude-mythos-encryption-flaws-hawk-aes-pqc/
      • Ghost Credentials Expose Cloud Systems To Hidden Identity Risks
        "A seemingly minor insider incident last year involving a small, isolated cloud account turned out to be a harbinger of a potentially larger identity problem. When an AI‑enabled workflow agent that had been idle for 30 days suddenly woke up and began firing off API calls at unusual times, it triggered an anomaly investigation. During the course of the investigation, Aleksandr Krasnov, a distinguished security architect at Ducker Tech Consulting, discovered a mesh of "ghost credentials" and non‑human identities — tokens, agents, and service accounts that lived outside traditional trust boundaries but were still able to move laterally through the environment and escalate privileges to access systems."
        https://www.darkreading.com/cloud-security/non-human-identity-sprawl-creates-a-new-cloud-attack-path
      • When AI Agents Escape Sandboxes, Old Security Rules Apply
        "In a world where AI agents can discover vulnerabilities, escape sandboxes, and take autonomous action across networks, organizations should double down on some of cybersecurity's oldest principles. On July 21, OpenAI detailed a security incident in which it took responsibility for a breach against part of Hugging Face's production infrastructure. According to a blog post from the AI giant, a combination of OpenAI agents based on models including GPT‑5.6 Sol as well as "an even more capable pre-release model" broke containment during a sandboxed evaluation intended to quantify said models' cyber capabilities."
        https://www.darkreading.com/application-security/ai-agents-escape-sandboxes-old-security-rules-apply
      • Stronger AI Safety Requires Peeking Inside The 'Black Box'
        "Adding security to AI often treats the large language model (LLM) or AI system as a black box, focusing on analyzing the tokenized inputs and outputs but not what goes on inside the model. The resulting techniques are often complex and individualized to specific models. A group of offensive-security researchers hopes to change that, presenting at the Black Hat USA 2026 in August a model-agnostic approach to activation analysis with standardized rules for processing activation events. Rather than labeling certain activation distributions as "cybercrime" or "hate speech," the approach uses a more granular scheme of cognitive elements (CEs) that can be combined in rules."
        https://www.darkreading.com/cybersecurity-analytics/stronger-ai-safety-requires-peeking-inside-black-box
      • Agentic Browsers Rewind Web Security By 20 Years
        "As business users and developers alike tap into agentic browsers to take work off their plates, the very traits that make them useful are also introducing a whole new class of risks. Security researchers warn that to make it easier for agents to reach across different Web domains to get things done for the user, agentic browsers have "ripped out" some key security mechanisms from the browser. Unsurprisingly, this has opened up every commercial agentic browser out in the market to new attack possibilities that range from account takeover to full-blown browser escape and remote compromise of the underlying system running the browser."
        https://www.darkreading.com/endpoint-security/agentic-browsers-rewind-web-security-20-years
      • Why Resetting Passwords No Longer Stops Attackers
        "The surge in device-code phishing attacks highlights how threat actors are increasingly stealing passwords to target authentication sessions, tokens, and trust relationships that enable them to masquerade as legitimate users and maintain persistent access. Compromised tokens and sessions allow attackers to operate within trusted identity environments, making malicious activity indistinguishable from legitimate user behavior. Device code phishing, for instance, exploits a legitimate sign-in process designed for devices with limited input capabilities, such as smart TVs and Internet of Things (IoT) devices."
        https://www.darkreading.com/endpoint-security/why-resetting-passwords-no-longer-stop-attacks
      • Former Citigroup CISO Blauner On What Makes A Great Security Leader
        "The role of the chief information security officer (CISO) has transformed dramatically over the past three decades, evolving from an emerging technical position into one of the most strategically important leadership roles in business. Few people have witnessed that evolution as closely as Charles Blauner, who served as CISO at JPMorgan, Citigroup, and Deutsche Bank after entering the field at the dawn of information security. In this episode of Heard It From a CISO, Blauner reflects on the influence of Steve Katz, who is regarded as “The Godfather” of the CISO role, and explains how mentorship, collaboration, and a culture of paying it forward helped shape the profession."
        https://www.darkreading.com/cybersecurity-operations/former-citigroup-ciso-blauner-great-security-leader
      • While External Threats Are Driving Security Awareness, Internal Risks Are Growing
        "External threats remain among the primary reasons organizations invest in security awareness and training. Phishing, ransomware, credential theft, social engineering, and attacks on peer organizations all reinforce the same point: Employee behavior directly affects an organization’s cyber risk. According to the Fortinet Training Institute 2025 Security Awareness and Training Global Research Report, 41% of respondents cite external threats as the primary driver for implementing security awareness and training programs. Organizations face a threat landscape shaped by organized cybercrime, ongoing reconnaissance, shorter time-to-exploit, and the growing use of stolen credentials and access paths. These pressures help explain why external threats remain the top motivator for cybersecurity training in 2025."
        https://www.fortinet.com/blog/industry-trends/while-external-threats-are-driving-security-awareness-internal-risks-are-growing
      • Hugging Face Breach Reignites Open-Weights Debate, Raises Liability Questions
        "The first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident post-mortem compiled with the input from Hugging Face and several hundred members of Cloud Security Alliance’s CISO community, the nonprofit organization laid out the most salient points for security leaders and advised on what they should do next."
        https://www.helpnetsecurity.com/2026/07/28/hugging-face-breach-ciso-playbook-open-weight-llms/
      • Hacker Conversations: Tal Kollander’s Journey From Black Hat To Hack Blocker
        "Tal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks. Based in Tel Aviv, Israel, Tal Kollander has the mindset of a hacker (we’re talking specifically about computer hackers). She believes hackers use creative skills to access computers by ‘non-legit’, basically criminal but creative, methods. A hacker to Kollander is anyone who accesses a computer without proper authorization to do so. Hackers are then subdivided by their subsequent actions. A ‘good’ hacker will report findings to the computer owner. “This is what I found. Now go fix it,” explains Kollander. These are white hat hackers."
        https://www.securityweek.com/hacker-conversations-tal-kollanders-journey-from-black-hat-to-hack-blocker/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 42c8b188-ea9f-4458-9389-e85ac794737d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 2 รายการลงในแคตตาล็อก

      เมื่อวันที่ 28 กรกฏาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 2 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
      • CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 67768399-fed7-490b-8f31-1e46a4d9320a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 28 July 2026

      Industrial Sector

      • Johnson Controls C-CURE 9000 And Victor Application Server
        "Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01
      • Panduit IntraVUE
        "Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-04
      • Weintek cMT3092X
        "Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-03
      • Johnson Controls XAAP Android
        "Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-02
      • Rockwell Automation ThinManager
        "Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-05
      • MZ Automation LibIEC61850
        "Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06
      • MZ Automation Lib60870
        "Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-07
      • Marathon Petroleum’s CISO On OT Security Automation, Supply Chain Risk
        "In this interview with Help Net Security, Mary Rose Martinez, CISO at Marathon Petroleum, talks about what happens to security when automation reaches deep into refineries, pipelines, and terminals. She explains why the old idea of air-gapped operational technology has faded, how the Purdue model helps her team apply controls without stopping production, and where supply chain risk sits when vendors and their vendors hold the keys. She also covers cross-skilling the workforce and working with government agencies as state aligned actors probe energy systems."
        https://www.helpnetsecurity.com/2026/07/27/mary-rose-martinez-marathon-petroleum-ot-security-automation/

      New Tooling

      • Nono: Open-Source Sandbox For AI Agents
        "An AI coding agent opens a terminal, reads a config file, and finds a live cloud key sitting in plaintext. It runs with the permissions of the person who launched it. Every file that person can read, the agent reads. Every credential in the environment, the agent can use. That reach is where the damage starts. A prompt injection, a mistyped command, or a hallucinated path points that access at the company’s own credentials and production systems."
        https://www.helpnetsecurity.com/2026/07/27/nono-open-source-ai-agent-sandboxing/
        https://github.com/nolabs-ai/nono

      Vulnerabilities

      • Arista Patches VeloCloud Orchestrator Zero-Day Exploited In Attacks
        "Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. The vulnerability, tracked as CVE-2026-16812, is an unauthenticated OS command injection flaw with severity scores of 10.0, the maximum score that can be given to flaws. VeloCloud Orchestrator, also known as VCO, is a centralized management platform used to configure, monitor, and manage VeloCloud SD-WAN deployments and associated edge devices."
        https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/
      • vBulletin Runtime Template RunMaths Preauth RCE
        "A vulnerability in vBulletin has been identified, the vulnerability allows an unauthenticated user to cause the vBulletin to execute arbitrary code (PHP) on the remote server."
        https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
        https://thehackernews.com/2026/07/public-exploit-released-for-patched.html
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
        CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
      • Breaking The Sandbox Again: Bypassing n8n's CVE-2026-27577 Patch
        "n8n is one of the most popular open-source workflow automation platforms in the world, with over 200,000 GitHub stars and deployments ranging from solo developers to enterprise AI pipelines. It lets users connect APIs, databases, LLMs and cloud services using a visual workflow editor. At the heart of each workflow is an expression evaluator - a JavaScript sandbox that lets users write dynamic logic like ={{ $input.first().json.name }} directly inside node parameters. That sandbox is the attack surface."
        https://www.securityjoes.com/blog/breaking-the-sandbox-again-bypassing-n8n-s-cve-2026-27577-patch
        https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html

      Malware

      • New Dysphoria DDoS Botnet Spreads To 200k Devices Worldwide
        "A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. According to QiAnXin XLab cybersecurity researchers, Dysphoria evolved from the ‘jackskid’ and ‘fbot' malware by adding a covert blockchain-based command-and-control (C2) resolution mechanism. Specifically, the botnet uses Ethereum ENS and Solana SNS domains to retrieve infrastructure information, while C2 addresses are concealed inside fake IPv6 strings and recovered using a custom byte-transformation algorithm."
        https://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/
        https://thehackernews.com/2026/07/dysphoria-iot-botnet-adds-blockchain-c2.html
      • MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions
        "We recently came across a sample of MedusaHVNC, a new remote access trojan (RAT) being sold as malware-as-a-service (MaaS). When we took it apart, we found a hidden virtual network computing (HVNC) module that opens a browser on a separate Windows desktop, out of sight of the victim. The browser still runs on the victim’s device, so it can load an existing profile, including cookies and session state. This gives the operator access to live, logged-in sessions while the activity continues to come from the victim’s usual machine."
        https://www.blackfog.com/medusahvnc-a-hidden-desktop/
        https://securityaffairs.com/196111/malware/medusahvnc-trojan-creates-hidden-desktops-to-hijack-browsers-and-steal-data.html
        https://www.securityweek.com/medusahvnc-malware-uses-hidden-windows-desktops-to-evade-detection/
      • Helpdesk Hijackers: Teams Vishing, Quick Assist, And GoGRPC Backdoor
        "Zscaler ThreatLabz has been tracking attacks from a threat actor that is likely an initial access broker for ransomware attacks since January 2026. The threat actor targets organizations by leveraging vishing techniques through Microsoft Teams and deploying a variety of tools including a Go-based backdoor that we named GoGRPC. ThreatLabz has identified at least four variants of GoGPRC that we named Lep, Giver, Pet, and Kind. In some instances, the threat actor has deployed additional malware tools that include a backdoor that we named BlindDoor, a Go-based reverse SOCKS proxy we named RevSocket, a Python-based reverse SOCKS proxy we named PyGRPC, and two other tools we named S3Siphon and RSOX."
        https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor
      • Operation BlueDash: Multi-RMM Workplace Phishing
        "ZeroBEC investigated a live Microsoft Teams-themed phishing operation that began with a "secure document" email and ended with the silent enrollment of the victim endpoint into attacker-controlled remote monitoring and management environments. The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened. The active download delivered supportdev.exe, an Inno Setup-based loader that launched PowerShell in a hidden window, retrieved the official Level RMM installer, and registered the endpoint using an attacker-controlled enrollment secret. The same command attempted to deploy ScreenConnect in parallel, providing a redundant remote-access channel."
        https://zerobec.com/blog/operation-bluedash-multi-rmm-workplace-phishing
        https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html
      • Check And Protect: Analysis Of Telegram Phishing Operation Targeting Exiled Activist
        "In July 2026, RESIDENT.NGO investigated an instance of a cloaked Telegram phishing campaign used against an exiled Belarusian activist living in Lithuania. Delivered in a private Telegram Secret Chat as a fake Telegram security alert, the phishing link led to a convincing Telegram-themed page designed to capture one-time login codes in real time. The operation’s defining feature was not the phishing page itself but its browser- and device-aware cloaking: visitors using browser and platform configurations accepted by the server, together with a syntactically valid token, could receive the phishing interface, while other configurations—including many automated scanners and some common desktop browsers—were shown decoy content or redirected to Telegram’s legitimate website."
        https://resident.ngo/lab/writeups/check-and-protect-analysis-of-telegram-phishing-operation-targeting-exiled-activist/
        https://therecord.media/telegram-belarus-activist-russia-cyberattack
      • DinDoor, DenoRAT, And NightshadeC2: Analyzing TAG-150's Evolving Tradecraft
        "In June 2026, eSentire's Threat Response Unit (TRU) disrupted a malicious ClickFix-style command in a Finance customer's environment. Further investigation found that the command installs DinDoor, a Deno-based loader, DenoRAT, a Deno-based Remote Access Trojan (RAT), and NightshadeC2, a sophisticated RAT and information stealer associated with TAG-150, a threat group active since March 2025."
        https://www.esentire.com/blog/dindoor-denorat-and-nightshadec2-analyzing-tag-150s-evolving-tradecraft
      • APT42: AI-Assisted Rapport Phishing And a More Resilient TAMECAT
        "APT42 continues to refine a familiar operating model, making it harder to detect and easier to scale. Three developments define the current picture. SpearSpecter combined prolonged WhatsApp engagement, Windows search-ms and WebDAV abuse, and a substantially expanded TAMECAT backdoor. APT42 also incorporated generative AI into target research, persona and pretext development, translation, malware engineering, debugging, code generation, and exploitation research. In March 2026, TA453 activity overlapping APT42 targeted a US think tank with a live credential-phishing operation during an active regional conflict."
        https://darkatlas.io/blog/apt42-ai-assisted-phishing-tamecat-analysis

      Breaches/Hacks/Leaks

      • Coca-Cola Confirms Data Theft In Fairlife Ransomware Attack
        "The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. In a short statement earlier today, the global beverages giant says that it is still working to restore some of the impacted systems and operations, but most of the production in the U.S. has been resumed. Coca-Cola disclosed the cyberattack in a filing with the U.S. Securities and Exchange Commission (SEC) on July 16, revealing that a ransomware attack had disrupted production operations at Fairlife."
        https://www.bleepingcomputer.com/news/security/coca-cola-confirms-data-theft-in-fairlife-ransomware-attack/
        https://www.securityweek.com/coca-cola-confirms-data-breach-after-fairlife-ransomware-attack/
      • Ernst & Young Data Breach Claimed By ShinyHunters Extortion Gang
        "The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack. Ernst & Young disclosed the breach earlier this month, saying a third-party support ticket system used by its IT personnel was compromised and support tickets that may contain client tax information were stolen. EY says it detected unusual activity on April 23 and determined that the attacker accessed the platform between March 28 and April 12, downloading multiple documents."
        https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
      • Health System In South Carolina, Georgia Closes Offices After Malware Affects Networks
        "A non-profit health system serving South Carolina and Georgia is dealing with a cyber incident that forced it to close dozens of departments. On Sunday, AnMed published a statement online saying they were “experiencing a cybersecurity disruption involving malware” and were working to restore systems and determine the scope of the incident. Earlier in the day, the company had warned of a phone and internet outage across all of its facilities. The company on Monday published a breakdown of the dozens of facilities and departments that were closed due to the incident. Urgent care services remain open but all imaging, OBGYN and primary care clinics are closed, as well as all medical group offices."
        https://therecord.media/health-system-south-carolina-georgia-disruptions-malware
        https://www.bankinfosecurity.com/malware-attack-forces-anmed-to-close-care-facilities-a-32336
      • Bank Of Baroda Breach Tests Disclosure Readiness
        "India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer and internal data surfaced online. The incident stemmed from the "compromise of an employee's email account, resulting in unauthorized access to certain data," the state-owned lender said in a post on X. The statement followed claims that the Triple X ransomware group published the data on the dark web on July 24. The relatively new group, first observed in May, primarily uses a double-extortion model: stealing data first, then threatening to leak it."
        https://www.bankinfosecurity.com/bank-baroda-breach-tests-disclosure-readiness-a-32335
      • DentaQuest Data Breach Potentially Impacts Over 23 Million People
        "Dental and vision benefits administrator DentaQuest is notifying millions of people that their personal and dental health information might have been stolen in a data breach. The incident was discovered on May 20, and DentaQuest’s investigation determined that the hackers had access to the organization’s network between May 17 and May 20. During the timeframe, the attackers accessed information such as names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, benefits provider names, diagnosis, treatment details, and billing information."
        https://www.securityweek.com/dentaquest-data-breach-potentially-impacts-over-23-million-people/
        https://securityaffairs.com/196100/data-breach/dentaquest-disclosed-a-data-breach-that-impacted-23-million-individuals.html
      • MCBS Data Breach Affects 1.2 Million Individuals
        "A data breach suffered last year by Atlanta-based medical business management company MCBS (Medical Computer Business Services) affects more than 1.2 million individuals. According to a data breach notification posted on its website, MCBS was targeted by hackers in September 2025. An investigation showed that attackers had access to its systems between September 22 and September 26, potentially stealing files that contained personal information such as name, address, SSN, date of birth, health insurance information, and medical information."
        https://www.securityweek.com/mcbs-data-breach-affects-1-2-million-individuals/

      General News

      • The Branding And Attribution Behind Cybercrime
        "Threat actor names can sound simple. LockBit. Fancy Bear. BlackCat. Scattered Spider. Anonymous Sudan. Each name gives the impression of a clear group with a defined identity. In threat intelligence, however, the name is rarely the whole story. Some names are chosen by attackers. Others are assigned by researchers, security vendors, governments, or public databases. One name may represent a ransomware brand, a hacktivist identity, a research label, a campaign, a malware family, or an activity cluster observed across different incidents."
        https://blog.checkpoint.com/exposure-management/the-branding-and-attribution-behind-cybercrime/
      • APTs Top The List Of Most Active Threat Actors In H1 2026
        "You may have heard your peers say, “Cybercrime has become industrialized.” But did you have any proof? We do. Cyble Research and Intelligence Labs (CRIL) closed out its tracking for the first half of 2026 with a deep analysis of the Global Threat Landscape spanning ransomware, initial access brokers, data breaches and leaks, nation-state espionage, and hacktivism, among others."
        https://cyble.com/blog/most-active-threat-actors-h1-2026/
      • FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
        "Undermining affiliates' trust and strong international partnerships were the keys to dismantling LockBit, one the most successful ransomware-as-a-service (RaaS) groups of its time, which at its peak was responsible for a quarter of all ransomware attacks. LockBit operated primarily between 2020 and 2024, and Brett Leatherman, assistant director of the FBI's Cyber Division, tells Dark Reading that during its time it victimized more than 2,500 organizations across at least 120 countries, with more than 1,800 of these attacks occurring in the US. Overall, the group collected more than $500 million in ransom payments, and the group and its leader, a Russian national named Dmitry Yuryevich Khoroshev, seemed invincible."
        https://www.darkreading.com/cybersecurity-operations/fbi-breaking-affiliate-trust-lockbit-takedown
      • Adversaries Don't Need a Zero-Day — They Read Your Rulebook
        "Recently, Robert Lemos reported in Dark Reading that confidence in autonomous penetration testing is falling: The share of organizations willing to rely on it dropped to 9% in 2026, down from 29% a year earlier, according to a Cobalt report. Companies are still experimenting with AI systems that hunt for weaknesses, but far fewer are leaning on them the way they did a year ago. The obvious explanation is that the technology overpromised and is now settling into a trough. I think something more specific is going on, and it carries a lesson that applies to autonomous defense just as much as offense."
        https://www.darkreading.com/threat-intelligence/adversaries-do-not-need-zero-day-they-read-your-rulebook
      • Ransomware Evolution Report Q22026
        "Q2 2026 recorded 1,988 attack claims from 89 groups across 101 countries. The quarter was defined by a change at the top of the ecosystem, tooling built to blind security products, and the arrival of AI inside the attack chain. TheGentlemen overtook its former parent group for the lead by June. Qilin still finished the quarter ahead on volume but lost ground each month, while DragonForce and a resurgent LockBit rounded out a reshaped top tier. Among the key trends observed, the disabling of endpoint defenses shifted from edge case to standard practice across the ecosystem, and Iran-linked actors expanded their use of ransomware as cover for state objectives."
        https://www.halcyon.ai/ransomware-evolution-report/q2-2026
        https://www.infosecurity-magazine.com/news/ransomware-q2-2026-edr-kill/
      • Most Smart Watches, Rings, And Bands Lack Basic Transparency Reports And Key Privacy Features
        "Oura Rings, Garmin GPS fitness watches, Apple Watches, Whoop bands—every year, more and more tech devices are promising to monitor our health and fitness, guide us toward healthier living, and provide useful health metrics to take to our doctors. But few of these tools provide the sorts of privacy and security promises we demand from all technology, let alone tech that captures personal health data. It’s time they step up and start providing transparency reports and stronger encryption options."
        https://www.eff.org/deeplinks/2026/07/most-smart-watches-rings-and-bands-lack-basic-transparency-reports-and-key-privacy
        https://securityaffairs.com/196085/security/eff-most-smart-wearables-still-fall-short-on-privacy-and-transparency.html
      • LockBit5 And Qilin Lead Ransomware Attacks Against Italian Organizations
        "Six months, 148 confirmed ransomware claims against Italian targets, and one sector taking the brunt of it. That’s the headline number from a new semi-annual tracker compiled by ransomNews under its RedACT project, which pulls together OSINT and SOCMINT sources to build a manual, deduplicated picture of who’s getting hit and by whom. The pace works out to roughly 25 claims a month, just under six a week. Attackers claim to have exfiltrated over 13,400 GB of data across the period, though that figure only covers 64 of the 148 cases; where a volume is actually disclosed, it averages around 61 GB. Read that gap as a reminder that leak-site numbers are marketing copy from criminals, not audited disclosures."
        https://securityaffairs.com/196045/security/lockbit5-and-qilin-lead-ransomware-attacks-against-italian-organizations.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) e338a97e-9ec9-4c73-b016-d5072d145ed7-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบการโจมตีผ่าน Wi-Fi โรงแรม มุ่งขโมยข้อมูลบัญชี Microsoft 365

      พบการโจมตีผ่าน Wi-Fi โรงแรม มุ่งขโมยข้อมูลบัญ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 66e2ff25-e204-4b94-9248-38f6eba77333-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ข้อมูลรั่วไหลจาก ShinyHunters ถูกนำไปใช้ส่ง Email หลอกลวงแบบ Sextortion เรียก Bitcoin มูลค่า 2,000 ดอลลาร์สหรัฐ

      ข้อมูลรั่วไหลจาก ShinyHunters ถูกนำไปใช้ส่ง Email หลอ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 05be8dea-7f95-4d9a-b2fe-1e515eb5e895-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • แคมเปญ SourTrade อาศัยโฆษณาแฝงมัลแวร์ หลอกให้เบราว์เซอร์ประกอบไฟล์อันตราย

      แคมเปญ SourTrade อาศัยโฆษณาแฝงมัลแวร์ หลอกให้เบ_0.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 532d1f10-cc8f-418b-a4f5-2cd78fb7522c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 27 July 2026

      Healthcare Sector

      • Ransomware Gangs Go After EMEA Healthcare’s Supply Chain
        "A ransomware attack against a hospital makes headlines, while attacks on the rest of the ecosystem around it tend to stay quiet despite doing damage that can be just as bad. Flare researcher Assaf Morag analyzed ransomware leak-site activity tied to healthcare organizations in the EMEA region between 2024 and 2026, and found that ransomware groups are going after the entire healthcare supply chain."
        https://www.helpnetsecurity.com/2026/07/24/emea-healthcare-ransomware-activity/

      Vulnerabilities

      • Fastjson RCE (≤1.2.83): Active Exploitation Detected — Detection & Mitigation
        "A remote code execution vulnerability in Fastjson affects every version up to and including 1.2.83. A remote attacker can run arbitrary code on a vulnerable server by sending it specially crafted JSON — no user privileges, no victim interaction, and no third-party libraries required. ThreatBook TDP® (Threat Detection Platform) has already captured this vulnerability being exploited in the wild, so if you run an affected version without SafeMode enabled, treat remediation as urgent."
        https://threatbook.io/blog/fastjson-rce-1.2.83-active-exploitation-detected-detection-mitigation
        https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-16723-critical-fastjson-1-x-zero-day-rce/
        https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html
      • Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
        "A critical vulnerability in Microsoft's Azure Automation service could have exposed accounts to cross-tenant identity takeovers due to a default setting that had the potential to make account identities become public. Azure Automation is widely used by Microsoft internally and by enterprises running Azure for DevOps, resource deployment, patching, and secrets rotation using scripted runbooks tied to embedded managed identities. Shay Shavit, a senior security researcher on Microsoft's Azure Networking Security Research team, discovered the vulnerability last year and reported it to the Microsoft Security Response Center (MSRC), which issued an advisory."
        https://www.darkreading.com/cloud-security/default-azure-automation-setting-cross-tenant-identity-takeover
      • Tego AI Discloses Second Claude Flaw In a Week: Hidden Link Silently Sends Files To Attackers
        "One week after disclosing that Anthropic’s Claude Tag Slack integration could be driven by plain “@Claude” text, Tego AI today published a second piece of research on the Claude ecosystem. This one focuses on Claude Code, Anthropic’s agentic command-line coding tool. Cloning an ordinary repository and starting Claude Code can cause the tool to read a file from outside the project and include it in the model’s first request, without a warning or approval prompt the user would recognize."
        https://hackread.com/tego-ai-discloses-second-claude-flaw-in-a-week-hidden-link-silently-sends-files-to-attackers/
      • Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
        "Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync. Microsoft patched the Active Directory Certificate Services (AD CS) issue ten days earlier as CVE-2026-54121. Microsoft classed the flaw as improper authorization and assigned it a CVSS score of 8.8."
        https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html
      • Bing Images Flaws Let Crafted SVGs Run Commands As SYSTEM On Microsoft's Servers
        "A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing's image tier, not on one bad machine. Microsoft issued two critical CVEs, CVE-2026-32194 and CVE-2026-32191, and rated both 9.8 on the CVSS scale."
        https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html
      • Finding Eight High-Severity Vulnerabilities In NodeBB In Six Hours
        "While improving our AI Pentest, we ran a whitebox assessment on NodeBB, a forum software powered by NodeJS. The result? Eight high-severity vulnerabilities that would all be exploitable on default instances of NodeBB. This includes Cross-Site Scripting (XSS), two of which require interaction with a custom Federation server that the AI agent had to set up itself. Another affects practically every input on NodeBB due to a template injection. Apart from these issues, there were clever authorization bypasses to hijack and read various data that shouldn't be public. We've explained all of the interesting technical details below."
        https://www.aikido.dev/blog/eight-high-severity-vulnerabilities-nodebb
        https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html
      • Kimi K3 Agents Found Redis Zero-Days And Built RCE Exploit, Researchers Say
        "Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution."
        https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html
      • Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands As Git
        "Security researchers depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update. Any authenticated user who can push to a project can run it. The attacker commits a crafted Jupyter notebook and opens its commit diff, which leaks a heap pointer. Enough of those and an automated probe can locate the libraries in memory. Two more notebooks then fire the payload. No administrator rights, no CI or runner access, no victim interaction, no access to anyone else's project."
        https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html

      Malware

      • Clop Ransomware Targets Windchill, FlexPLM In Data Theft Attacks
        "The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances. As cybersecurity company ReliaQuest reported on Thursday, Clop operators have been deploying JSP webshells that allow them to exfiltrate sensitive data from targeted companies' compromised PLM platforms."
        https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/
        https://ransom-isac.org/blog/clop-windchill-flexplm-exploitation/
        https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html
      • DNS Poisoning Tactics Expand To Hospitality Wi-Fi
        "Adversaries have been compromising public Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack the accounts of traveling corporate employees. Once they control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, in activity ongoing since at least June 2026. ReliaQuest assesses this tradecraft is similar to that of “APT28” (also known as “Fancy Bear” and “Forest Blizzard”), a Russian military intelligence group that was previously linked to similar router-based campaigns compromising Microsoft 365 accounts."
        https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/
        https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/
        https://www.infosecurity-magazine.com/news/hotel-wifi-dns-poisoning/
        https://securityaffairs.com/196017/security/hackers-hijack-hotel-wi-fi-to-steal-microsoft-365-credentials.html
      • Operation RoundPress Rolls On With More Half-Click Webmail Zero-Days From TA458
        "TA458 is an espionage threat actor with prolific access to “half-click” cross-site scripting (XSS) exploits in webmail software. TA458 is likely aligned with Russia’s General Staff Main Intelligence Directorate (GRU). In March 2026, Proofpoint discovered TA458 exploiting a zero-day vulnerability in the SOGo webmail platform, which we reported to the vendor, Alinto; it was patched as CVE-2026-8496 in version 5.12.8. TA458 primarily targets Ukrainian government and Eastern European military and government entities across Albania, Greece, Moldova, and Türkiye, with occasional targeting of chemical, telecommunications, and technology firms. TA458 continues to use SpyPress - an obfuscated JavaScript-based malware seen in Operation RoundPress - which the adversary modifies based on the targeted mailserver."
        https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits
      • Inside a DPRK BlueNoroff ClickFix Kit
        "JUMPSEC has obtained and analysed the source code behind an active BlueNoroff phishing kit used to impersonate Zoom and Microsoft Teams meetings. Unlike previous reporting, this research provides source-level visibility into how the operation works after operators mistakenly exposed JavaScript source maps on live infrastructure. This is not simply a fake Zoom lure. We demonstrate how BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet reconnaissance and malware delivery into a repeatable victim acquisition pipeline."
        https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/
        https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html
      • TAG-195 Upgrades MaaS Ecosystem With Modular Tools
        "Insikt Group identified four new TAG-195 ("Golden Chickens", “Venom Spider”) malware families through ongoing tracking of the TAG-195 MaaS ecosystem. We named two of the families "TinyEgg" and “ChonkyChicken"; the third is a modularized variant of ChonkyChicken. The fourth family, which includes a modified browser credential theft helper, we named “ChromEggscalator". TAG-195 is a financially motivated malware-as-a-service (MaaS) developer whose tooling Insikt Group has previously linked to TAG-127 as an operator and customer. (Insikt Group has directly observed TAG-127 deploying TinyEgg via “ClickFix”-style campaigns that use fake security verification pages to trick victims into manually executing malicious commands that download and install malware payloads via a legitimate Windows system utility.)"
        https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem
        https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0723.pdf
        https://thehackernews.com/2026/07/golden-chickens-resurfaces-with-four.html
      • Silent Replacement Of Trusted MacOS App Executables
        "A vulnerability in macOS allows an attacker to silently replace the main executable of any application downloaded from the web without requiring elevated privileges. As a result, trusted applications can be made to execute attacker-controlled code without triggering security warnings when relaunched. Apple assessed the reported behaviour as not requiring a security fix."
        https://mysk.blog/2026/07/23/macos-overwrite-app-executables/
        https://www.theregister.com/security/2026/07/24/researchers-replace-downloaded-macos-apps-with-evil-twins-apple-shrugs/5277858
      • The Signs Were There: What The First Autonomous Ransomware Case Confirms
        "Ransomware has always had a person behind it. Someone picks the target, buys or builds the access, runs the tools, and extorts the victim for a payout. However, in an intrusion documented this month by the security firm Sysdig and dubbed JADEPUFFER, no one did. By their account, a large language model (LLM) agent broke into a live production system, harvested credentials, moved deeper, encrypted a database, destroyed the originals, and left a ransom note. It was choosing and sequencing every step itself in near real time, with no human at the keyboard between the break-in and the damage."
        https://www.trendmicro.com/en_us/research/26/g/autonomous-ransomware.html
      • Steam Forum ClickFix Attacks Infect Gamers With XMRig Cryptominers
        "Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. BleepingComputer learned of the campaign from a reader, who told us threat actors are creating random Steam accounts to post what appears to be helpful fixes for people's posts about games crashing, lost inventory items, and other technical issues."
        https://www.bleepingcomputer.com/news/security/steam-forum-clickfix-attacks-infect-gamers-with-xmrig-cryptominers/
      • SourTrade: Browser-Assembled Malware Delivered Through Malvertising
        "SourTrade is a malvertising operation that has been running ads since late 2024, impersonating TradingView, Solana, and Luno to reach retail traders and crypto investors across 12 countries in 25 languages. It is built to separate real targets from analysts and bots. Security researchers see a blank page, legitimate victims see a convincing replica of a platform they trust. What makes SourTrade technically distinct is what happens on its landing page. It does not distribute finished malware. Instead, it delivers assembly instructions to the victim’s browser, retrieves a clean legitimate file from separate infrastructure, and directs the browser to build the final malware in memory on the victim’s machine. No finished malware ever exists on the network."
        https://blog.confiant.com/p/sourtrade-browser-assembled-malware
        https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/
        https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html
      • ShinyHunters Data Leaks Fuel $2,000 Sextortion Email Scam
        "Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. The emails claim to come from ShinyHunters and tell recipients that hackers compromised their devices after obtaining their email addresses from breached company databases. However, the messages appear to be sent by someone who downloaded data previously leaked by ShinyHunters rather than by the extortion group itself, using the exposed email addresses to make the threats appear more legitimate."
        https://www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam/
      • Funky Mantis: Platform, Coordination And Locker Analysis
        "Funky Mantis , publicly tracked as DevMan, is a centrally administered ransomware-as-a-service operation that combined affiliate management, access distribution, payload generation, victim negotiation, and revenue tracking by late 2025. The evidence set contains two generations of its web panel, private and group communications and a Windows encryptor. These independent sources support the assessment that the service progressed beyond advertising or development and was used in at least one real intrusion."
        https://catalyst.prodaft.com/public/report/funky-mantis-platform-coordination-and-locker-analysis/overview
        https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html

      Breaches/Hacks/Leaks

      • Thailand's Ministry Of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
        "Attackers have started handing routine offensive work to AI agents, and the agents are doing it without anyone watching. We have seen this in ransomware and cloud intrusions, and now in espionage. An open directory left exposed on a staging server gave us a look at one of these operations mid-run: an agent enumerating a government ministry's network on its own. From July 9 - 13, 2026, Hunt.io Attack Capture™ identified three simultaneous open directories on 43.246.208[.]207, hosted on AS132883 (TOPIDC) in Hong Kong. The directories contained exploit code for multiple CVEs, webshells, suo5 HTTP tunnels, custom scripts with hardcoded stolen credentials targeting mail infrastructure and Apache Hadoop."
        https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent
        https://www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry/
        https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html
        https://securityaffairs.com/195941/hacking/thailands-ministry-of-finance-targeted-with-hermes-ai-agent-running-unattended-hades-implant-staged.html
      • OnTrac Notifies Customers Of Data Breach After Network Hack
        "OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. The incident was detected on March 23, and an internal investigation revealed that the attacker accessed certain files between March 20 and 22. Apart from names, it is unclear what type of information was exposed, as the company redacted the data elements in the notification sample shared with authorities."
        https://www.bleepingcomputer.com/news/security/ontrac-notifies-customers-of-data-breach-after-network-hack/
      • Vatican's Official Prayer App Leaks 700K+ Global Users' PII
        "A popular Vatican website and mobile app has been leaking hundreds of thousands of users' names and email addresses. "Click to Pray" is the Vatican's official prayer app. Users can sign up for access to daily prayers, and a steady stream of papal content on their phones or computers. It's available on iOS and Android, and via a Web browser. According to its website, Click to Pray is used in more or less every country on the planet."
        https://www.darkreading.com/vulnerabilities-threats/vatican-official-prayer-app-leaks-700k-pii
        https://www.theregister.com/security/2026/07/24/popes-official-prayer-app-commits-cardinal-sin-leaks-700k-users-info/5278603

      General News
      June 2026 Threat Trend Report On Ransomware
      "This report summarizes the quantity of ransomware samples collected, the number of affected systems, statistics on targeted businesses, and major Korean & global issues during the month of June 2026. Statistics on targeted businesses were compiled based on information posted on DLS (Dedicated Leak Sites) operated by ransomware groups, which publish details of attacks."
      https://asec.ahnlab.com/en/94619/

      • June 2026 Threat Trend Report On APT Attacks (South Korea)
        "AhnLab monitored domestic APT (Advanced Persistent Threat) attacks—which are conducted covertly and persistently—using its own infrastructure. This report summarizes the classification and statistics on domestic APT attacks identified in June 2026 and describes the capabilities of each type of APT attack."
        https://asec.ahnlab.com/en/94594/
      • Europol-Led Action Against Nihilistic Violent Extremist Network "The Com"
        "Over several weeks in June and July 2026, Europol supported an action targeting nihilistic violent extremist content online. Investigators from nine countries participated in these ‘Referral Action Days’, with the common goal to disrupt The Com online ecosystem and limit propaganda dissemination, as well as to find new investigative leads. The action also aimed at enhancing platforms’ response to and awareness of terrorist content online produced and disseminated by The Com groups."
        https://www.europol.europa.eu/media-press/newsroom/news/europol-led-action-against-nihilistic-violent-extremist-network-com
        https://www.bleepingcomputer.com/news/security/europol-flags-4-340-urls-for-removal-in-the-com-crackdown/
        https://www.bankinfosecurity.com/europol-flags-4340-urls-tied-to-com-network-a-32325
        https://www.theregister.com/cyber-crime/2026/07/24/europol-flags-4340-horrific-urls-linked-to-the-com/5278556
      • Man Gets Six Years For Hacking 750 Women's Snapchat Accounts
        "An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos, which he later traded or sold online. After being charged in December, 26-year-old defendant Kyle Svara admitted in February to having used various social engineering tactics to phish Snapchat access codes from over 750 women. Between May 2020 and February 2021, he targeted more than 4,500 victims while posing as a representative of Snap Inc and using anonymized phone numbers."
        https://www.bleepingcomputer.com/news/security/man-gets-six-years-for-hacking-750-womens-snapchat-accounts/
      • Symbiotic Parasites: The Modern Proxy Ecosystem
        "Residential proxy networks may sound technical, but their impact is easy to understand: they help criminals hide in everyday internet traffic. In this post, we break down how these massive botnet-powered ecosystems enable fraud, evade detection and quickly recover after disruption—and why stopping them will take coordinated action across the security community."
        https://www.lumen.com/blog/en-us/symbiotic-parasites-the-modern-proxy-ecosystem
        https://cyberscoop.com/botnets-residential-proxy-networks-proliferate-lumen-black-lotus-labs/
      • CISOs Vs. Boards: Myth Or Misunderstanding?
        "The rumors are exaggerated. Executive boards aren't apathetic to security threats; they're often struggling with a cybersecurity language barrier. Increasingly disruptive cyberattacks require preventative and remediation efforts from positions across organizations, yet chief information security officers (CISOs) and IT teams feel unsupported by the powers that be. This adds pressure on the CISOs, as they fend off attacks and manage potentially devastating fallout."
        https://www.darkreading.com/cybersecurity-operations/cisos-vs-boards-myth-or-misunderstanding-
      • Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
        "The hack of Hugging Face by a rogue AI agent created by Open AI engineers does not surprise researchers and AI-security professionals who best know machine-learning and AI systems. In a study of the behavior of seven different models, a research team at Carnegie Mellon University (CMU), for example, found that all of them escaped alignment in some scenarios. In a paper published to Arxiv.org in May, the team of six researchers found that every model violated "corrigibility" — an AI design principle that aims to make agents cooperative, correctable, and amenable to being shut down or modified by their human operators."
        https://www.darkreading.com/cybersecurity-operations/incorrigible-ai-models-resist-rehabilitation
      • Europe's Multilingual Reality Exposes AI Security Gaps
        "Not all languages are treated equally when it comes to AI model function and safety, and European organizations face a particular risk when it comes to this reality. The modern large language model (LLM) ecosystem relies heavily on natural language, whether a user is speaking to a chatbot, issuing specific instructions for software development, generating emails, or performing large-scale data analysis. This reliance is further illustrated through the wide range of prompt injection attacks that rely on language-based trickery."
        https://www.darkreading.com/cybersecurity-operations/europes-multilingual-reality-exposes-ai-security-gaps
      • The Automotive Software Vulnerabilities Hiding In Your Dashboard
        "Pop the hood on a new car and you won’t find much you can fix with a wrench. What you’ll find is software, and a lot of it. The screen in the dash probably runs Android or a flavor of Linux. The system watching the road for you might run QNX or VxWorks, the same kind of code that flies aircraft and runs factory floors. Carmakers spent the last decade making this switch, and it bought them app stores, wireless updates, and quicker release cycles. It also handed them something less welcome: every old, publicly documented bug those platforms have collected over the years."
        https://www.helpnetsecurity.com/2026/07/24/car-research-automotive-software-vulnerabilities/
        https://arxiv.org/pdf/2607.07226
      • The Best-Funded Companies Open The Most Phishing Attachments
        "An employee gets an email dressed as a password reset. She clicks the link, types her credentials into a page built to copy her company’s login screen, and moves on with her morning. She tells no one. That silence is the exposure. Across 13.9 million simulated phishing messages, one in ten recipients flagged the attempt to their security team. The rest let it through, and a live attacker needs only one of them."
        https://www.helpnetsecurity.com/2026/07/24/phishing-simulation-benchmark-report/
        https://static.fortra.com/corporate/pdfs/other/fta-phishing-simulation-benchmark-report.pdf
        Education Ransomware Roundup: H1 2026 Stats On Attacks, Ransoms, And Data Breaches
        "Attacks on the education sector dropped by 13 percent in the first half of 2026, declining from 120 attacks in H2 2025 to 104 attacks in H1 2026. This decline wasn’t consistent across all levels of education, however. Attacks on K-12 (primary and secondary education) decreased 26 percent from H2 2025 but attacks on higher education increased more than eight percent."
        https://www.comparitech.com/news/education-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/
        https://www.infosecurity-magazine.com/news/university-ransomware-attacks-rise/
      • CertiK Intel3D H1 2026 Wrench Attacks
        "H1 2026 confirms that wrench attacks are no longer a fringe phenomenon or an edge-case risk for cryptocurrency holders. Over the first six months, CertiK recorded 52 verified incidents worldwide, representing a 33.3% year-over-year (YoY) increase. The increase was driven by activity during the first quarter, which recorded 35 verified incidents compared to 22 in Q1 2025. Recorded losses and ransom demands reached approximately $124.1 million in H1 2026, compared with approximately $10.5 million in H1 2025. These figures remain indicative, not exhaustive: many ransoms, failed demands, recovered funds, frozen funds, and private settlements are not publicly disclosed or are partially disclosed."
        https://www.certik.com/certik-report/intel3d/intel3d-wrench-h1-2026
        https://therecord.media/wrench-attacks-against-cryptocurrency-holders
      • The AI Trust Paradox: Businesses Are Racing Ahead, But Consumers Are Hesitating
        "Businesses are rapidly adopting AI, with 93% planning deployment, but consumer trust lags far behind: only 23% trust companies to use AI with their data, revealing a major “AI trust gap.” Research from Thales shows trust depends on transparency and use case, as users favor Artificial intelligence for cybersecurity but resist it in high-risk areas like financial decisions. To close this gap and reduce fears, organizations must clearly communicate how AI is used, where it adds security, and where humans remain in control."
        https://securityaffairs.com/195915/ai/the-ai-trust-paradox-businesses-are-racing-ahead-but-consumers-are-hesitating.html
      • Don’t Swing At Everything
        "Lately I've found myself thinking a lot about the Australian TV series Mr. Inbetween (IMDb 8.7/10) — not because I'm a hitman for hire, but because I literally feel in-between. Specifically, in-between what I'd call the "pre-Mythos" and “post-Mythos” eras. We've crossed a capability threshold, and it's not just one model family driving that — Codex 5.3 and GPT-5.5 deliver comparable or better performance, and Tulongfeng or GLM-5.2 (an incredibly powerful open-weight model, MIT-licensed) show the frontier isn't limited to closed models anymore."
        https://blog.talosintelligence.com/dont-swing-at-everything/
      • Email Threat Landscape: Q2 2026 Trends And Insights
        "The second quarter of 2026 (April–June) was largely defined by the continuing downstream effects following Microsoft’s Digital Crimes Unit-led disruption efforts against the Tycoon2FA phishing-as-a-service (PhaaS) platform in March. Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs. Despite ongoing efforts to rebuild operations, Tycoon2FA did not recover its previous scale or influence during Q2, and no single service emerged to replace the platform at comparable scale."
        https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/
      • The KEV Gap: How Fast Do Exploited Bugs Get Flagged?
        "The Cybersecurity and Infrastructure Security Agency (CISA) keeps a public list called the Known Exploited Vulnerabilities catalog, or KEV: the security bugs it has confirmed attackers are actually using. U.S. federal agencies must patch everything on the list by a deadline, and many private security teams use it as their top fix-first queue. Each bug on the list has two dates: the day it was first published as a Common Vulnerabilities and Exposures (CVE), and the day CISA added it to KEV. The days between those two dates are the “KEV gap.” A common worry is that the gap is growing; that it takes longer and longer to flag a dangerous bug. It doesn’t. For new bugs, CISA is fast: the typical gap is about nine days, and nearly half are flagged within a week. The long delays you see in the raw numbers come from a separate group: old bugs, published years ago, that attackers have started using again."
        https://blog.barracuda.com/2026/07/24/KEV-gap-how-fast-do-exploited-bugs-get-flagged
      • Updated Cyber Threat Actor Naming System
        "Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. Historically, Mandiant and Google’s Threat Analysis Group (TAG) maintained distinct tracking systems, relying on parallel naming schemas that grew independently over time. The creation of GTIG has necessitated a new, fused tracking system, and a new naming system."
        https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 271fc13f-d4d8-4677-89f3-1d62e41f79b8-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 7 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 7 รายการ เมื่อวันที่ 23 กรกฏาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-204-01 Johnson Controls C-CURE 9000 and Victor application server
      • ICSA-26-204-02 Johnson Controls XAAP Android
      • ICSA-26-204-03 Weintek cMT3092X
      • ICSA-26-204-04 Panduit Intravue
      • ICSA-26-204-05 Rockwell Automation ThinManager
      • ICSA-26-204-06 MZ Automation libIEC61850
      • ICSA-26-204-07 MZ Automation lib60870

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories ca7e5be9-a78c-4888-be2d-1deea0ab1d35-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 24 July 2026

      Vulnerabilities

      • New RefluXFS Linux Flaw Lets Attackers Gain Root Privileges
        "A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. Dubbed RefluXFS by the Qualys Threat Research Unit (TRU), which found and reported it, the security flaw affects systems with an XFS filesystem with reflink enabled (a default configuration on major enterprise Linux distributions), running Linux kernel v4.11 or later, with a directory writable by an unprivileged local user, and a high-value target (a root-owned configuration file or SUID-root binary)."
        https://www.bleepingcomputer.com/news/linux/new-refluxfs-linux-flaw-lets-attackers-gain-root-privileges/
        https://cdn2.qualys.com/advisory/2026/07/22/RefluXFS.txt
        https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-gives.html
      • SharedRoot; Escaping The Claude Cowork Sandbox
        "Untrusted content in a Claude Cowork session can escape the VM it's sandboxed in and read and write files anywhere on your Mac. The kernel bug that makes it possible isn't the interesting part. Four design decisions are, and they'd have stopped the next kernel bug too."
        https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/
        https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html
      • Millions Of Cars Could Be Tracked And Unlocked By a Hidden Security Flaw
        "A car alarm vendor’s coding mistake has left millions of vehicles vulnerable to theft and location tracking. Thanks to the way dealers sell car alarms, many affected drivers don’t even know they have one installed. The device is the KARR Security System, a Bluetooth-enabled aftermarket alarm built by Acrisure Protection Group. It’s installed by dealers, primarily at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California."
        https://www.malwarebytes.com/blog/bugs/2026/07/millions-of-cars-could-be-tracked-and-unlocked-by-a-hidden-security-flaw

      Malware

      • Attack Cases By The Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)
        "AhnLab SEcurity intelligence Center (ASEC) previously disclosed an attack case in which the Kimsuky group used spear phishing attacks to install the PebbleDash malware in a post titled “Analysis of the Kimsuky Group’s Latest Attacks Exploiting PebbleDash and RDP Wrapper” [1]. The same threat actors have continued their activities in 2026 and have recently been conducting spear phishing attacks by impersonating diplomatic personnel. These spear phishing attacks utilize LNK malware to install various tools, including the PebbleDash backdoor, the PrxClient proxy malware, RDP Wrapper, UACMe, and KeyLogger. The decoy document files created during the attack process contain diplomatic-related content."
        https://asec.ahnlab.com/en/94552/
      • New Dolphin X Malware Uses AI To Rank High-Value Targets
        "A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. The malware was analyzed by Varonis Threat Labs researcher Daniel Kelley, who spotted it being advertised on a cybercrime forum by a vendor using the alias "Kontraktnik," promoting it as an all-in-one remote access trojan. According to Varonis, the operator panel lists 329 features across ten categories, including a credential-stealing feature that claims to target more than 300 applications."
        https://www.bleepingcomputer.com/news/security/new-dolphin-x-malware-uses-ai-to-rank-high-value-targets/
        https://www.infosecurity-magazine.com/news/new-dolphin-x-stealer-ai-targets/
      • Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations With SectopRAT
        "Between July 21 and July 22, 2026, Huntress' Security Operations Center (SOC) lit up with a swathe of unusual executable installs, Defender exclusions, and anomalous persistence across 29 organizations, all coming from ClaudeDesktop.exe. The attacks had one common denominator: victims had searched for the Claude desktop app and were taken to a malicious public Claude Artifact on the actual Claude AI domain, which appeared to be a legitimate download link for the desktop app."
        https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat
        https://www.bleepingcomputer.com/news/security/fake-claude-app-promoted-by-bing-ads-pushes-sectoprat-malware/
        https://www.helpnetsecurity.com/2026/07/23/anthropic-claude-artifacts-download-malware/
      • Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users Of Zimbra Collaboration Suite
        "A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecurity industry tracking), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD)."
        https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a
        https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF
        https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits
        https://unit42.paloaltonetworks.com/russian-webmail-espionage/
        https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/
        https://thehackernews.com/2026/07/russian-espionage-group-exploited.html
        https://www.darkreading.com/cyberattacks-data-breaches/russian-hackers-zimbra-zero-day-us-ukraine-targets
        https://therecord.media/zimbra-webmail-zero-click-phishing-russia-laundry-bear
        https://cyberscoop.com/russian-laundry-bear-zimbra-exploit/
        https://www.infosecurity-magazine.com/news/russian-hackers-zero-click/
      • Hackers Abuse Notepad++ Plugins To Stealthily Install Malware
        "Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. The campaign has been attributed to a threat cluster tracked as UAC-0099, which primarily targets organizations in Ukraine and has previously been linked to providing initial access for attacks carried out by APT44, also known as Sandworm. The attackers do not exploit any vulnerability or a supply-chain compromise impacting the popular software."
        https://www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-to-stealthily-install-malware/
      • Chaos Ransomware's MsaRAT: Living Off The Browser To Build a Covert C2 Channel
        "Chaos is a ransomware-as-a-service (RaaS) group whose activity was first confirmed in February 2025. Although the number of listings on their data leak site remains relatively low, the group consistently targets large organizations and employs double extortion tactics. For initial access, they rely on spam emails and voice-based social engineering, commonly known as vishing. Once inside a network, their traditional post-compromise methodology involves abusing remote monitoring and management (RMM) tools to establish persistent access, while leveraging legitimate file-sharing software to exfiltrate data. For a detailed breakdown of their tactics, techniques, and procedures (TTPs), please refer to our previous blog."
        https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/
        https://www.bleepingcomputer.com/news/security/new-msarat-malware-uses-chrome-edge-browsers-to-route-c2-traffic/
        https://thehackernews.com/2026/07/chaos-ransomware-uses-msarat-to-route.html
        https://securityaffairs.com/195876/malware/chaos-ransomware-deploys-browser-based-msarat-to-evade-network-detection.html
        https://www.helpnetsecurity.com/2026/07/23/cisco-talos-chaos-ransomware-msarat/
      • Lampion's Portugal-Focused Phishing Campaign Delivers Multistage Malware
        "Acronis Threat Research Unit (TRU) identified an active Lampion malware campaign targeting Portuguese users through phishing emails masquerading as financial and administrative communications. First publicly documented in December 2019, Lampion is a Brazilian banking malware family, derived from the ChePro lineage, that has consistently targeted Portugal and other Portuguese-speaking users rather than Brazilian victims. Initial payloads are delivered through ZIP archives containing heavily obfuscated HTML files designed to evade static detection and analysis. The HTML stage retrieves and executes additional script from attacker-controlled infrastructure, leading to the deployment of a multistage VBS infection chain."
        https://www.acronis.com/en/tru/posts/lampions-portugal-focused-phishing-campaign-delivers-multistage-malware/
        https://www.darkreading.com/cyberattacks-data-breaches/brazilian-banking-trojan-spreading-portugal
      • JadeProx: Tracing a China-Nexus Operation Through An OPSEC Mistake
        "In mid-April 2026, an exposed directory on an operator-owned Alibaba Cloud server gave us a complete view into an active China-nexus operation. The server with bash history, toolkits, webshell paths against victims, and staged phishing packages were all visible. The investigation uncovered simultaneous intrusions against a Vietnamese public hospital’s medical imaging system, the Malaysian Ministry of Foreign Affairs, and multiple Hong Kong educational institutions. Running in parallel, similar targeting of Honduras and phishing campaigns themed around fake Anthropic Claude software were observed."
        https://www.group-ib.com/blog/jadeprox-china-nexus-triback-loader/
        https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html
      • AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
        "OpenAI's Workspace Agents can connect to Outlook, Gmail, Slack, Google Drive, SharePoint, and Teams, execute actions across those services, and run on a schedule. They’re built through a conversational agent builder that lets users describe an agent in natural language, configure tools, preview its behavior, and publish it. During our research, we discovered that this workflow could be driven entirely by an attacker-controlled URL. We call it AgentForger: a Cross-Site Request Forgery (CSRF) that doesn't forge a single request; it forges an entire autonomous agent, attacker-controlled and living inside your organization's trust boundary."
        https://labs.zenity.io/p/agentforger-part-1-chatgpt-cross-site-agent-forgery
        https://labs.zenity.io/p/agentforger-part-2-the-autonomous-insider
        https://www.securityweek.com/openai-fixes-chatgpt-agent-flaw-that-could-let-attackers-forge-an-ai-insider/
      • Real Email Attacks. Stopped Cold.
        "Every month, Barracuda detects and blocks around 4.9 million brand and service impersonation emails, 46,065 QR code phishing (quishing), 242,300 CEO/executive impersonations attacks, 960,000 Bayesian-poisoning phishing emails, and 110,000 non-English phishing emails. To illustrate the many tactics and layers seen in today’s sophisticated email attacks, we selected seven examples. Each email is shown exactly as it arrived, alongside the signals that exposed it and where it would have taken anyone who clicked."
        https://blog.barracuda.com/2026/07/23/real-email-attacks-stopped-by-barracuda
      • Large-Scale GitHub Actions Abuse Powers a Distributed cPanel And WHM Exploitation Campaign
        "Our investigation into malicious Packagist development versions associated with a legitimate PHP and DevOps developer, dinushchathurya, uncovered a large-scale GitHub Actions abuse campaign. Although the investigation began in the PHP package ecosystem, the PHP library code itself was not the campaign’s execution mechanism. Instead, the malicious functionality was embedded in GitHub Actions workflow files committed to the developer’s source repositories."
        https://socket.dev/blog/github-actions-abuse-powers-cpanel-and-whm-exploitation
        https://thehackernews.com/2026/07/attackers-weaponize-github-actions.html
      • 13M+ Emails Sent In Tech Support Scam Targeting Users, Organizations In Japan
        "From mid-December 2025 through May 2026, we observed and analyzed a large-scale and sustained tech support scam campaign, luring victims to fake security alert websites via email. Over roughly five and a half months (165 days), we confirmed that more than 13 million emails were delivered from over 240,000 IP addresses, with more than 33,000 disposable fake alert sites serving as landing pages. Our analysis found that the campaign combined high-volume distribution, globally dispersed delivery infrastructure, rapidly rotating landing sites, and an expanding focus that appeared to include individuals within organizations:"
        https://www.trendmicro.com/en_us/research/26/g/tech-support-scams-targeting-japan.html
      • Behind The Refund: From GST Phishing To Remcos RAT Through a Multi-Stage .NET Infection Chain
        "Seqrite Labs recently identified a malware distribution campaign that abused the credibility of government institutions to increase infection success rates. The threat actors impersonated legitimate government departments and distributed malicious emails disguised as official notifications related to taxation, refunds, compliance requirements, and regulatory matters. By leveraging recognizable government branding, urgency, and financial incentives, the campaign was designed to persuade recipients to open malicious attachments or interact with embedded content. This activity highlights the continued effectiveness of government-themed social engineering techniques in facilitating malware delivery and compromising targeted users."
        https://www.seqrite.com/blog/behind-the-refund-from-gst-phishing-to-remcos-rat-through-a-multi-stage-net-infection-chain/

      Breaches/Hacks/Leaks

      • Australian Energy Provider Origin Says Data Breach Exposes Client Data
        "Australian energy provider Origin Energy has confirmed a data breach by an unknown threat actor that exposed customers' personally identifiable information (PII). The company has 4.8 million customers and is currently investigating how many of them have been impacted to inform them of the risk via individual notifications. Origin Energy is Australia’s largest energy retailer, providing electricity, natural gas, and broadband internet services to millions of clients across the country."
        https://www.bleepingcomputer.com/news/security/australian-energy-provider-origin-says-data-breach-exposes-client-data/
        https://therecord.media/australia-origin-energy-data-breach

      General News

      • Which Brands Are Impersonated Most? Inside The Q2 2026 Brand Phishing Report
        "Brand phishing is when a scammer impersonates a trusted, well known company, through email, a fake website, or both, in order to steal login credentials, payment details, or personal information. It works because trust is transferable. If a message looks like it came from a brand you already use and rely on, your guard drops. You’re not evaluating a stranger’s request. You’re responding to what feels like routine correspondence from a company you already have a relationship with. That single psychological shortcut is the entire business model behind brand phishing."
        https://blog.checkpoint.com/research/which-brands-are-impersonated-most-inside-the-q2-2026-brand-phishing-report/
      • Agentic AI Challenges Progress In Confidential Computing
        "After years of struggles, artificial intelligence (AI) is boosting enterprise adoption of confidential computing, but AI agents are creating new security challenges that current technology isn't designed to tackle. This is pushing proponents of the technology back to the drawing board. At last month's Linux Foundation's Confidential Computing Summit in San Francisco, these proponents advocated for a whole new paradigm."
        https://www.darkreading.com/endpoint-security/agentic-ai-challenges-progress-in-confidential-computing
      • Flaws In Passkey Implementation Show Old Attacks Still Work
        "Attackers can exploit flaws in Microsoft's passkey systems in ways surprisingly similar to old password attacks. But that doesn't mean it's time to give up on passkeys. Passkeys have received much attention in recent years. They're considered phishing-resistant, and their use of private keys means they are largely unaffected by data breaches when identity information and credentials are stolen. They also require zero memorization compared to traditional passwords because users embed authentication directly into the device by enabling biometrics or PINs. Even so, widespread adoption has been gradual."
        https://www.darkreading.com/identity-access-management-security/flaws-passkeys-implementation-old-attacks-work
      • Ransomware In 2026: Same Business, New Rules
        "The ransomware economy has entered a new phase. Affiliates are going independent, groups are absorbing their rivals, and encryption is becoming optional. Access to corporate networks has never been easier to buy. The market is splitting into a visible tier of opportunistic sales and an invisible tier of premium partnerships, and both are growing. AI-assisted malware development is already in production among multiple active groups, lowering the barrier to sophisticated operations and automating post-breach monetization."
        https://www.group-ib.com/blog/ransomware-2026-rules/
      • Multi-Patch Vulnerability Fixes Can Leave Open Source Exposed
        "Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A share work in a different way, arriving as a run of two or more commits where the first one leaves the flaw in place. Researchers at the University of Texas at Dallas went through 1,646 open source CVEs that carry more than one patch in the National Vulnerability Database, drawn from records filed between 1999 and 2025. Those cases are a small share of the whole, close to one in fifteen of the open source CVEs in the database that carry a linked patch. The operational weight sits in the interval between the first patch and the last one, a window in which the software stays open."
        https://www.helpnetsecurity.com/2026/07/23/research-multi-patch-vulnerability-fixes/
        https://arxiv.org/pdf/2607.13206
      • The AI Code Vulnerabilities That Grow With Your App
        "Theori built 28 apps with AI coding agents and scanned each one through its pentesting platform. Five models did the building, split between Anthropic and OpenAI, across apps written from a spec, thrown together from a casual prompt, and rewritten from an aging PHP codebase. The team went in expecting injection everywhere. SQL injection, cross-site scripting, the bugs that fill security tutorials. Those barely showed up. The models reached for prepared statements and ORMs on their own and sanitized their inputs."
        https://www.helpnetsecurity.com/2026/07/23/report-ai-code-vulnerabilities/
      • AI Agents Now The Enterprises Fastest Growing Exposed Attack Surface
        "The rapid adoption of enterprise AI tools is the fastest-growing source of new exposure for businesses, and it puts them at risk to additional cyber threats, a new report has warned. Published on July 22, the Sophos AI Security 2026 Report, warned that AI identities have become a new attack surface as AI agents and assistants are adopted in the workplace. Employees have deployed coding agents, agentic AI assistants, LLMs and other tools to help them with their work. It has become common for the agents to receive privileged access to core systems to aid with their efficiency."
        https://www.infosecurity-magazine.com/news/ai-agents-attack-surface/
        https://www.sophos.com/en-us/content/sophos-ai-security-2026-report
      • 2026 AI-Era Ransomware Report
        "Most organizations plan for ransomware as if it's a malware problem. The 2026 AI-Era Ransomware Report shows why that's the wrong playbook. Based on a global survey of security professionals, this report reveals how attackers are getting in through people—and why AI is making those attacks harder to catch."
        https://www.proofpoint.com/us/resources/threat-reports/ai-era-ransomware-report
        https://www.infosecurity-magazine.com/news/ai-boosts-ransomware-effectiveness/
      • Is Patching Dead? Vulnerability Management In The Post-Mythos Era
        "On July 14, 2026, the White House launched Gold Eagle: a federal clearinghouse that uses frontier AI to identify, rank, and coordinate the remediation of software vulnerabilities across government and critical infrastructure before attackers reach them. Bringing together the Treasury, DHS, DoD, open-source software partners, and operators of American critical infrastructure, Gold Eagle’s engine relies on frontier AI—including Anthropic’s Mythos, the same class of system that surfaced critical flaws inside classified U.S. government software during testing."
        https://www.securityweek.com/is-patching-dead-vulnerability-management-in-the-post-mythos-era/
      • The Upgrade Trap: When Upgrading Is The Wrong Answer To a CVE
        "The advice is always the same when a vulnerability tool flags a CVE: upgrade. Move to the patched version so you can close the ticket and move on. It’s become such a reflex that nobody stops to ask whether it’ll actually work. The proposed fix fails in three specific ways. There's no version to upgrade to and won't ever be, the patched version hasn't shipped yet, or the fix ships and breaks your application."
        https://www.aikido.dev/blog/cve-upgrade-breaking-changes-open-source

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 0d27e59e-f4ca-457c-a34d-a51405f73364-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • 🚨ระวัง! AI ไม่ได้เพียง “ช่วยเขียนโค้ด” อีกต่อไป—แต่กำลังช่วยค้นหา เจาะระบบ ยกระดับสิทธิ์ และขยายผลการโจมตีได้ด้วยความเร็วระดับเครื่องจักร

      🚨ระวัง! AI ไม่ได้เพียง “ช่วยเขียนโค้ด” อีกต่อไป—แต่กำลังช่วยค้นหา เจาะระบบ ยกระดับสิทธิ์ และขยายผลการโจมตีได้ด้วยความเร็วระดับเครื่องจักร

      กรณี Claude Mythos Preview แสดงให้เห็นความก้าวหน้าครั้งสำคัญในการดำเนินการโจมตีไซเบอร์แบบหลายขั้นตอน ขณะที่เหตุการณ์ก่อนหน้า ผู้ไม่หวังดีเคยนำ Claude Code ไปใช้สนับสนุนปฏิบัติการจารกรรมไซเบอร์ ตั้งแต่การสำรวจเป้าหมาย เจาะระบบ ขโมยข้อมูลรับรอง เคลื่อนที่ภายในเครือข่าย ไปจนถึงนำข้อมูลออกจากองค์กร ส่วนกรณีล่าสุดพบการใช้ Hermes AI Agent ทำงานหลังการเจาะระบบแบบอัตโนมัติ โดยสแกนเครื่อง ค้นหาเส้นทางยกระดับสิทธิ์ และสำรวจข้อมูลอย่างต่อเนื่องโดยไม่ต้องรอมนุษย์อนุมัติทุกคำสั่ง (Anthropic⁠, UK AI Security Institute⁠, The Hacker News⁠)

      ภัยสำคัญไม่ใช่เพียง AI สร้างช่องโหว่ใหม่ แต่คือ AI สามารถค้นหาและใช้ช่องโหว่เดิมได้เร็วขึ้น ต่อเนื่องขึ้น และครอบคลุมขึ้น—ตลอด 24 ชั่วโมง

      หน่วยงานจึงต้องเร่งยกระดับการป้องกันแบบ Defense in Depth ตั้งแต่ MFA, PAM และ Least Privilege การอัปเดตช่องโหว่ การแบ่งแยกเครือข่าย การควบคุม Outbound Traffic การเฝ้าระวังด้วย EDR/XDR, NDR และ SIEM/SOC ตลอดจนการกำกับ AI Agent ภายในองค์กรด้วย Audit Log และ Human Approval

      🔴 และอย่าลืมแนวป้องกันสุดท้ายเมื่อระบบหลักถูกโจมตี:

      “Backup ที่ไม่เคยทดสอบกู้คืน อาจไม่ใช่ Backup ที่ใช้งานได้จริง”

      สำรองข้อมูลตามหลัก 3-2-1-1-0 แยกบัญชีและระบบ Backup ออกจากระบบหลัก เก็บสำเนาแบบ Offline หรือ Immutable กำหนด RPO/RTO และทดสอบ Full Recovery อย่างสม่ำเสมอ

      AI ทำให้ผู้โจมตีเร็วขึ้น—หน่วยงานต้องตรวจจับให้เร็วกว่า จำกัดความเสียหายให้ทัน และกู้คืนบริการให้ได้จริง

      AIDrivenCyberAttack.png

      กรณีพบเหตุการณ์ภัยคุกคามทางไซเบอร์ หรือพฤติกรรมน่าสงสัย
      Email : [email protected] โทร 02 114 3531 (ตลอด 24 ชั่วโมง)
      ด้วยความปรารถนาดี สำนักงานคณะกรรมการการรักษาความมั่นคงปลอดภัยไซเบอร์แห่งชาติ (สกมช.) / ThaiCERT

      #ThaiCERT #CyberAlert #AIDrivenCyberAttack #AIAgent #CyberSecurity #DefenseInDepth #IncidentResponse #BackupAndRecovery #ImmutableBackup #CyberResilience

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบมัลแวร์ใหม่ Dolphin X ใช้ AI จัดอันดับเหยื่อ ช่วยแฮกเกอร์เลือกเป้าหมายมูลค่าสูงได้เร็วขึ้น

      พบมัลแวร์ใหม่ Dolphin X ใช้ AI จัดอันดับเหยื่อ ช่ว.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e145df5d-00b5-4040-adba-199a03af38b2-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Stadler Rail ปฏิเสธจ่ายค่าไถ่ 12.3 ล้านดอลลาร์สหรัฐ หลังถูกโจมตีทางไซเบอร์

      Stadler Rail ปฏิเสธจ่ายค่าไถ่ 12.3 ล้านดอลลาร์สหรัฐ ห.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 4e30003a-d1ed-4e6b-afae-7d585d678c01-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบมัลแวร์ใหม่ Dolphin X ใช้ AI จัดอันดับเหยื่อ ช่วยแฮกเกอร์เลือกเป้าหมายมูลค่าสูงได้เร็วขึ้น

      พบมัลแวร์ msaRAT ใช้ Chrome และ Edge เป็นช่องทางติดต่อ .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e3936bee-cb93-4e1f-a6f7-39beac62a22a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Zimbra ออกแพตช์แก้ช่องโหว่ Critical หลายรายการใน Zimbra Collaboration Suite

      Zimbra ออกแพตช์แก้ช่องโหว่ Critical ใน Zimbra Collaboration Suite.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand fa04ff4d-258d-4871-a892-37a8c9ae3ad0-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Google เปิดตัว Gemini 3.5 Flash Cyber โมเดล AI ด้าน Cybersecurity สำหรับค้นหา ตรวจสอบ และแก้ไขช่องโหว่ซอฟต์แวร์

      Google เปิดตัว Gemini 3.5 Flash Cyber โมเดล AI ด้าน Cybersecurity สำหรับค.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand bd3eccd7-7257-40bc-b921-806ab7f25404-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Apple แก้ไขช่องโหว่บริการ Hide My Email ป้องกันการรั่วไหลของที่อยู่อีเมลจริงใน Mail Logs

      Apple แก้ไขช่องโหว่บริการ Hide My Email ป้องกันการรั่.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 1438bf3a-9de7-4948-852e-c08f4b81eb0a-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 2 รายการลงในแคตตาล็อก

      เมื่อวันที่ 22 กรกฏาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 2 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability
      • CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/07/22/cisa-adds-two-known-exploited-vulnerabilities-catalog

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ab3c93ee-3efb-4417-977a-48ad69c66734-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 23 July 2026

      Financial Sector

      • Beyond The Vault: What Banking Sites Quietly Share Before You Ever Log In
        "Banks present themselves as the most careful custodians of personal and financial data. Customers expect that trust to extend to every digital interaction including public websites and online application flows. Yet Jscrambler’s Security Research Team found that many banking experiences transmit sensitive information to third-party advertising, analytics, and personalization platforms. In many cases, the data leaves the browser before the user has made a consent choice. In others, it continues to flow even after users have rejected tracking technologies."
        https://jscrambler.com/blog/beyond-the-vault-what-banking-sites-share
        https://www.darkreading.com/data-privacy/eu-financial-institutions-cookie-trackers
        https://www.bankinfosecurity.com/pixels-tracking-every-loan-you-take-on-eu-bank-websites-a-32296

      Industrial Sector

      • Federal Agencies Broaden Alert On Iran-Linked OT Attacks
        "The federal government has expanded a warning that it issued in April about attacks on internet-facing operational technology (OT) by hackers affiliated with the Iranian regime. The initial advisory focused on programmable logic controllers (PLCs) from manufacturers Rockwell Automation and Allen-Bradley. Wednesday’s revision “expands the manufacturer scope to include observed targeting of Schneider Electric, Siemens and possible other PLC manufacturers,” according to a news release from CISA."
        https://therecord.media/federal-agencies-broaden-alert-on-iran-linked-ot-attacks

      New Tooling

      • Snowpick: Open-Source ServiceNow Exposure Scanner
        "An employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and get records back. Bishop Fox ran that test across 166 ServiceNow instances during authorized penetration tests. The firm published the results along with the Go tool it used, Snowpick."
        https://www.helpnetsecurity.com/2026/07/22/servicenow-data-exposure-snowpick-open-source-scanner/
        https://github.com/BishopFox/snowpick
      • Now In Preview: Find And Fix Software Vulnerabilities With CodeMender
        "As adversarial AI threats accelerate attacks on code, security teams must counter them with machine-speed defenses that can automate code remediation and fight AI with AI. CodeMender is our managed code security agent, and starting today, we're bringing its code scanning and remediation capabilities directly to you in preview. CodeMender offers access to our generally available models via Gemini Enterprise Agent Platform, or it can be deployed as a core component of AI Threat Defense."
        https://cloud.google.com/blog/products/identity-security/find-and-fix-software-vulnerabilities-with-codemender
        https://www.infosecurity-magazine.com/news/google-codemender-available-ai/

      Vulnerabilities

      • Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
        "Oracle has patched more than 1,400 vulnerabilities with its July 2026 Critical Patch Update (CPU), with a vast majority of the flaws likely identified by artificial intelligence. According to Oracle, the latest quarterly CPU includes 1,449 security patches, addressing 1,434 unique CVEs across 334 products. Vulnerabilities have been patched in products such as Database Server, APEX, Autonomous Health Framework, Essbase, Global Lifecycle Management, GoldenGate, NoSQL Database, Spatial Studio, SQL Developer, TimesTen In-Memory Database, Application Testing Suite, Commerce, Communications, Construction and Engineering, and E-Business Suite."
        https://www.securityweek.com/oracle-patches-over-1400-vulnerabilities-with-quarterly-security-updates/
        https://www.oracle.com/security-alerts/cpujul2026.html
      • CVE-2026-8933: Local Privilege Escalation In Set-Capabilities Snap-Confine
        "The Qualys Threat Research Unit (TRU) has identified a Local Privilege Escalation (LPE) vulnerability in snap-confine (CVE-2026-8933). This flaw allows an unprivileged local user to gain full root access on default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The issue stems from a security hardening change that inadvertently introduced a race condition during sandbox initialization."
        https://blog.qualys.com/vulnerabilities-threat-research/2026/07/21/cve-2026-8933-snap-confine-local-privilege-escalation
        https://thehackernews.com/2026/07/ubuntu-snap-confine-flaw-could-give.html
        https://www.infosecurity-magazine.com/news/ubuntu-snap-confine-local-root-cve/
        https://hackread.com/ubuntu-desktop-vulnerability-local-access-root-control/
        https://securityaffairs.com/195833/security/cve-2026-8933-ubuntu-security-flaw-breaks-snap-sandbox-protections.html
      • Security Advisory – Action Required – July 2026 Security Update
        "As part of Check Point’s Frontier AI Readiness Program, we are releasing a jumbo hotfix with security and hardening fixes for our firewall and management products. This update includes a number of security hardening improvements and fixes, the most significant of which are outlined below. During a routine BLAST review, we discovered a few vulnerabilities. Following a thorough analysis, we identified one of those in the wild, affecting a handful of customers. This only affects a very specific configuration — when Management is exposed directly to the internet without IP restrictions. We’ve already notified the affected customers."
        https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/
      • When Your AI Reviewer Works For The Attacker: A Confused-Deputy Bug In Microsoft's Azure DevOps MCP Server
        "An invisible comment in an Azure DevOps pull request can turn a developer's own AI agent against them. Microsoft ships an official Azure DevOps MCP server that lets AI agents read and act on Azure DevOps (pull requests, pipelines, wikis, work items) on the user's behalf. An attacker with access to a single project can hide instructions inside an HTML comment, invisible in the Azure DevOps UI, delivered verbatim into the agent's context. When a victim asks their agent to review the PR, the hidden instructions hijack the agent's goal. Because the agent is holding the victim's credentials, it performs actions across projects the attacker can't reach on their own."
        https://www.manifold.security/blog/azure-devops-mcp-server-vulnerability
        https://thehackernews.com/2026/07/microsoft-azure-devops-mcp-flaw-lets.html
      • CISA Adds Two Known Exploited Vulnerabilities To Catalog
        "CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability
        CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/07/22/cisa-adds-two-known-exploited-vulnerabilities-catalog
      • New InfraTrust Report Reveals Infrastructure Flaws Admins Should Patch First
        "Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. The monthly report aggregates security advisories from major infrastructure vendors and highlights the vulnerabilities administrators should prioritize based on a flaw's exploitability, exposure, and real-world risk rather than severity scores alone."
        https://www.bleepingcomputer.com/news/security/new-infratrust-report-reveals-infrastructure-flaws-admins-should-patch-first/
        https://pulse.infra-trust.org/july-2026/
      • HermeticReader: The Vulnerability That Turned Adobe's 300M-Install Extension Into a Full WhatsApp Takeover
        "A single click on a malicious web page could turn the Adobe Acrobat Chrome extension, installed on roughly 329 million browsers, into a one-click WhatsApp exfiltration tool, quietly handing a visitor's entire WhatsApp clear-text chats, contacts, and private info to the attacker's hands. Here at Guardio Labs we uncovered a chain of vulnerabilities in the extension that compounds into a single powerful cross-origin exfiltration chain. A working, runtime-confirmed exploit followed within hours, thanks to our AI harness specially built to secure the browser extensions domain. Adobe's response to our full disclosure was phenomenal: acknowledged, patched, and shipped over a single weekend, with CVE-2026-48294 issued days later."
        https://guard.io/labs/hermeticreader---the-vulnerability-that-turned-adobe-300m-install-extension-into-a-full-whatsapp-takeover
        https://www.bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-let-sites-access-private-whatsapp-chats/
        https://thehackernews.com/2026/07/adobe-acrobat-extension-flaw-let.html
        https://www.securityweek.com/flaw-in-adobe-extension-with-300m-installs-enabled-whatsapp-data-theft/
        https://securityaffairs.com/195805/hacking/adobe-acrobat-chrome-extension-bug-enabled-silent-whatsapp-data-theft.html
      • Hackers Exploit Windmill Flaw To Read Arbitrary Server Files Without Authentication
        "A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log_file" endpoint ("/api/w/{workspace}/jobs_u/get_log_file/{filename}")."
        https://thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html
      • Open Directory Stages NGINX Rift And Ghost CMS Exploits Against Government And Finance Across Eleven Countries
        "NGINX sits in front of a large share of the internet's web traffic and Ghost CMS powers well over 100,000 publishing sites. Within months of each other earlier this year, critical vulnerabilities were found in both: NGINX Rift (CVE-2026-42945), a long-standing heap overflow in the rewrite module, and a blind SQL injection in the Ghost Content API (CVE-2026-26980). Exploit code for both became public quickly. What we found was a single host staging them alongside five other exploits, wired to confirm its own hits over out-of-band callbacks."
        https://hunt.io/blog/open-directory-nginx-rift-ghost-cms-multi-cve
      • Langflow Exploited To Build Custom DDoS Gafgyt Botnets
        "The cybersecurity world spent the last few years worrying about advanced AI threats — such as automated phishing, deepfakes, and autonomous malware. However, threat actors are proving that their immediate goals are much more pragmatic. They don't just want to manipulate AI; they want to hijack its underlying infrastructure to fuel traditional, high-volume cybercrime. Recent threat intelligence reveals a fascinating intersection of modern AI deployment and classic botnet architecture: Attackers are actively exploiting CVE-2025-3248 (an RCE vulnerability in Langflow) to drop a highly customized variant of the veteran Gafgyt/BASHLITE DDoS bot. In this blog post, I’ll describe how attackers are actively exploiting CVE-2025-3248 to turn cutting-edge AI frameworks into brute-force network weapons."
        https://www.akamai.com/blog/security-research/2026/jul/langflow-exploited-build-custom-ddos-gafgyt-botnets

      Malware

      • The Perfect Heist: NuGet Typosquat Targets Betting Platform To Rig Results
        "The JFrog Security Research team has discovered and disclosed a typosquatted NuGet package named Newtonsoftt.Json.Net. Note the double t and the .Net suffix. This package has been masquerading as the popular Newtonsoft.Json library while quietly shipping a trojanized fork. The trojan rigs Digitain, an online betting platform, and in later generations, exfiltrates rigged round results to an attacker-controlled server, utilizing the header X-Seq-ApiKey: theperfectheist2025. The author published seven versions under the same package, all sharing the same target-specific payload."
        https://jfrog.com/blog/nuget-typosquat-targets-betting-platform/
        https://thehackernews.com/2026/07/trojanized-newtonsoftjson-fork-hides.html
      • Denying The Worm: Detecting SANDWORM_MODE And The Emerging Class Of AI Toolchain Supply Chain Attacks
        "In February 2026, Socket.dev published research on a multi-stage npm supply chain worm operating under the internal flag SANDWORM_MODE. The campaign spanned 19 malicious packages in total across two unique publisher aliases and demonstrated a new class of supply chain attacks that targeted AI-augmented development workflows. Many recently observed supply chain attacks target build outputs, inject static backdoors, or conduct mass credential harvesting, but SANDWORM_MODE was unique in its exploitation of the runtime behaviors of AI coding assistants, CI automation, and LLM toolchains."
        https://www.crowdstrike.com/en-us/blog/denying-the-worm-sandworm-mode-and-ai-toolchain-supply-chain-attacks/
        https://www.darkreading.com/cyber-risk/attackers-live-off-ai-toolchain
        https://cyberscoop.com/sandworm-mode-malware-ai-supply-chain-crowdstrike/
      • How a Fake Bahrain Civil-Defense App Turns a Phone Into a Listening Post
        "Throughout July and including the day that this article is being published, Gulf states, including Bahrain and Kuwait have been activating civil-defense sirens and public-safety guidance for residents in the wake of Iranian missiles. During active air-defense events, official emergency-alert applications see sharp spikes in install demand. Some actors treat that demand as a distribution opportunity. On July 17, Dream researchers analyzed an Android application that impersonates a Bahraini Civil Defense “BH Alert” siren app."
        https://dreamgroup.com/blog/how-a-fake-bahrain-civil-defense-app-turns-a-phone-into-a-listening-post
        https://www.darkreading.com/mobile-security/fake-bahrain-alert-apps-android-surveillance-malware
      • Inside a TrickBot Variant Using DNS Tunneling For C2
        "FortiGuard Labs recently captured several malicious samples that were sending malformed DNS queries. After conducting an in-depth analysis, I determined that these samples are TrickBot variants that use DNS tunneling to communicate with their command-and-control (C2) servers. TrickBot is a modular malware family that FortiGuard Labs has repeatedly captured over the past decade. Its modular architecture enables it to extend its capabilities by downloading and executing additional modules on compromised devices. Previously observed TrickBot variants primarily relied on HTTP to communicate with its C2 servers."
        https://www.fortinet.com/blog/threat-research/inside-a-trickbot-variant-using-dns-tunneling-for-c2
        https://www.infosecurity-magazine.com/news/trickbot-dns-tunneling-c2/
      • Analysis Of Kimsuky's Attack On a South Korean Groupware Vendor Using a New Gomir Family Variant
        "The ENKI WhiteHat Threat Research Team tracked a campaign by Kimsuky, a North Korea-linked threat group, that infiltrated the internal networks of South Korean groupware vendors between 2025 and early 2026. Our analysis revealed that Kimsuky gained control of internet-facing servers through vulnerability exploitation and spear-phishing, and deployed Gomir and its variants. Kimsuky developed Gomir variants with significantly altered C2 communication methods to evade detection, including leveraging Google Drive as a C2 channel and implementing a new custom protocol. We also observed indicators of aggressive lateral movement, including compromising customer servers that used the affected vendors' groupware and tampering with groupware login pages to harvest employee credentials."
        https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant
        https://therecord.media/kimsuky-north-korea-espionage-groupware-companies
      • Device Code Phishing: Turning a Convenience Feature Into An MFA Bypass
        "For years, the advice to users was simple: turn on multi-factor authentication (MFA), and most account takeovers can be prevented. That advice still holds, and MFA still blocks most password-based attacks. The problem is that attackers adapt, and the more an organization relies on a single control, the more attention that control attracts. The first big shift was adversary-in-the-middle phishing, where a proxy site sits between the user and Microsoft and relays the login in real time to capture the session cookie. Device code phishing is the next step, and in some ways, it is cleaner for the attacker. There is no fake login site to build or to get blocked, and there is nothing visually wrong for the user to notice, because the page they enter their password on really is Microsoft. The only unusual thing is a short code and a plausible reason to enter it."
        https://www.trendmicro.com/en_us/research/26/g/device-code-phishing.html

      Breaches/Hacks/Leaks

      • Chick-Fil-A Discloses Data Breach After Credential Stuffing Attacks
        "American fast food restaurant chain Chick-fil-A is notifying an undisclosed number of customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. Self-described as the third-largest quick-service restaurant company in the United States, Chick-fil-A operates a network of more than 3,000 restaurants and provides catering services across the U.S., Canada, Puerto Rico, the United Kingdom, and Singapore. The company revealed in data breach notification letters sent to affected individuals and filed with multiple Attorney General offices that it detected the attacks after identifying suspicious login activity to certain Chick-fil-A One accounts."
        https://www.bleepingcomputer.com/news/security/chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks/
        https://www.malwarebytes.com/blog/data-breaches/2026/07/chick-fil-a-loyalty-accounts-hijacked-using-stolen-passwords
      • OpenAI Says Its AI Models Hacked Hugging Face During Testing
        "OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. As the company explained, instead of focusing on finding a solution for the ExploitGym public AI cybersecurity benchmark on their own, the AI models tried to cheat by stealing the test solutions by hacking Hugging Face after inferring that they could get the test solutions directly from its production database. In one of their attempts, the OpenAI agents chained zero-day vulnerabilities and used stolen credentials to find a remote code execution attack vector while trying to gain access to Hugging Face servers."
        https://www.bleepingcomputer.com/news/security/openai-says-its-ai-models-hacked-hugging-face-during-testing/
        https://openai.com/index/hugging-face-model-evaluation-security-incident/
        https://thehackernews.com/2026/07/openai-says-its-own-ai-models-escaped.html
        https://therecord.media/openai-cyberattack-hugging-face
        https://www.darkreading.com/cyber-risk/openai-models-autonomously-hack-hugging-face
        https://www.infosecurity-magazine.com/news/open-ai-hacked-another-company/
        https://www.securityweek.com/openai-says-its-ai-models-broke-loose-and-hacked-hugging-face/
        https://securityaffairs.com/195774/ai/openai-ai-models-exploited-zero-days-to-reach-hugging-face-in-benchmark-test.html
        https://hackread.com/openai-models-breached-hugging-face/
        https://www.helpnetsecurity.com/2026/07/22/hugging-face-breach-openai-testing/
      • Upbound Says Hack Caused $13 Million In Fraudulent Acima Leases
        "The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. In a filing with the U.S. Securities and Exchange Commission (SEC), the company says that it "experienced cybersecurity incidents in which certain non-sensitive customer information and other documents were obtained without authorization." The threat actor used the information to commit fraud in lease-to-own agreements, resulting in financial losses of about $13 million in the Acima segment in the second quarter of this year."
        https://www.bleepingcomputer.com/news/security/upbound-says-hack-caused-13-million-in-fraudulent-acima-leases/
      • South Korea Discloses Data Breach Impacting Diplomats Worldwide
        "South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. The incident occurred in April 2025 after an unknown threat actor exploited a vulnerability in the Academy's server. It impacts at least 6,000 individuals, 350 of them being current government attachés dispatched abroad. The education platform was set up in 2022 to support remote training during the COVID-19 pandemic, and has since been used for government personnel training and video-conferencing."
        https://www.bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide/
      • Swiss Rail Giant Stadler Rejects $12.3M Ransom Demand After Cyberattack
        "Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. The threat actor has not publicly claimed the attack, but the Swiss company says that it received an extortion letter from Everest ransomware asking for a ransom of 10 million Swiss francs. The company responded by saying that it will not pay the threat actor and filed a criminal complaint with the Thurgau cantonal police."
        https://www.bleepingcomputer.com/news/security/swiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack/

      General News

      • Security Issues In The Korean & Global Financial Sector In June 2026
        "In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third Attack Stage, demonstrating that multi-stage attack chains—progressing from the initial distribution of bait to the installation of additional malware and ultimately to Information Theft—are widely used."
        https://asec.ahnlab.com/en/94543/
      • Small Teams Are The Heaviest Users Of AI Coding Agents
        "The pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to read it. On GitHub that somebody is usually one developer sitting alone with the diff, and the rest of the project never sees the code. Maliha Noushin Raida and Daqing Hou at Rochester Institute of Technology sorted 25,264 agentic pull requests by who reviewed them and who committed to them. The repositories all carry at least 100 stars, the agents are the ones most developers have already met, GitHub Copilot and OpenAI Codex and Claude Code, and the window runs from May through July 2025."
        https://www.helpnetsecurity.com/2026/07/22/users-of-ai-coding-agents/
      • Security Teams Keep Finding Critical Flaws After Scheduled Testing Ends
        "Enterprise environments change between scheduled security assessments, leaving organizations with periods where new vulnerabilities can go undetected. Synack’s State of Continuous Security Validation report found that 95% of surveyed organizations identified high- or critical-severity vulnerabilities outside planned testing windows during the past year, with 42% encountering them at least once a month."
        https://www.helpnetsecurity.com/2026/07/22/continuous-security-testing-gaps-report/
      • Cloud Operations Become The Next Big Role For Agentic AI
        "Companies are using agentic AI to manage growing application environments, automate routine tasks, and support decisions. Business and IT leaders increasingly see the technology as part of cloud application management, according to Unisys’ AI & Cloud Insights Report. Most organizations remain in testing or early deployment. Nearly one quarter have started scaling agentic AI across business functions. Early uses center on employee productivity and cloud management. Spending plans show continued interest, with half of respondents planning higher investment during the next year."
        https://www.helpnetsecurity.com/2026/07/22/agentic-ai-cloud-operations-report/
      • Vibe-Coded Apps Riddled With Exploitable Security Flaws
        "Vibe-coding is increasing. Vibe-coded apps tend to be buggy. Is this a worrying sign for the future? Vibe coding, the use of AI to assist or perform code generation, is increasing dramatically. In May 2026, Hostinger reported, “90% of developers regularly use at least one AI tool at work as of January 2026.” This is likely to increase through the basic business pressure that applies to everything: we need more, faster and cheaper. But while vibe coding is increasing in volume, so are concerns over the security of vibe-developed apps."
        https://www.securityweek.com/vibe-coded-apps-riddled-with-exploitable-security-flaws/
        https://go.xint.io/the-top-security-vulnerabilities-generated-by-ai-code
      • When Identity Verification Fails: Lessons From a Real-World SIM Swap And Near Account Takeover
        "For years, organizations have encouraged users to enable multi-factor authentication (MFA), use one-time passwords (OTPs), and protect their accounts with passcodes. Those controls remain important. However, a recent attack against my own wireless services account demonstrated that point-in-time authentication is no longer sufficient against determined identity-focused adversaries. What began as a seemingly routine customer service call quickly evolved into a coordinated attack that combined social engineering, identity impersonation, stolen personal information, SIM swapping, session hijacking, and unauthorized account changes."
        https://www.securityweek.com/when-identity-verification-fails-lessons-from-a-real-world-sim-swap-and-near-account-takeover/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 0ab0f750-7528-4021-968d-eeaac841a990-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT