NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,659
    • กระทู้ 2,660
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • พบการโจมตี Supply Chain ผ่านแพ็กเกจ Tensorlake บน npm ขโมยข้อมูลรับรองและแพร่มัลแวร์ต่อ

      พบการโจมตี Supply Chain ผ่านแพ็กเกจ Tensorlake บน npm ขโมยข้_.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 9f07c2c3-2d32-47cf-b04f-95768017e815-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ASOS ตรวจสอบเหตุผู้โจมตีส่ง Push Notification ผ่านแอป อ้างเข้าถึงข้อมูลลูกค้าใน Snowflake

      ASOS ตรวจสอบเหตุผู้โจมตีส่ง Push Notification ผ่านแอป อ้.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 6cec9de7-6e7a-4733-84a0-9f30936c21a5-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ผู้บริหารของบริษัทรับกู้ข้อมูลระบบ ถูกตั้งข้อหาฉ้อโกงจากการแอบจ่ายเงินค่าแรนซัมแวร์ให้แฮกเกอร์ พร้อมเรียกเก็บเงินลูกค้าเกินจริง

      ผู้บริหารของบริษัทรับกู้ข้อมูลระบบ ถูกตั_.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand de768703-783c-408c-9738-c021b76c8608-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 12 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 12 รายการ เมื่อวันที่ 6 และ 8 ตุลาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-279-01 Johnson Control EasyIO FG
      • ICSA-26-279-02 Savannah lwIP
      • ICSA-26-279-03 Hitachi Energy Asset Suite
      • ICSA-26-279-04 Hitachi Energy SOI
      • ICSA-26-279-05 Hitachi Energy REB500
      • ICSA-26-279-06 Hitachi Energy RTU500 series CMU Firmware
      • ICSA-26-281-01 Red Lion Controls N-Tron 700 Series
      • ICSA-26-281-02 Grid Protection Alliance openPDC and openHistorian
      • ICSA-26-281-03 Satel Netco Design
      • ICSA-26-069-02 Lantronix EDS3000PS and EDS5000 (Update B)
      • ICSMA-26-223-02 Pulsetto Vagus Nerve Stimulator (Update A)
      • ICSA-25-259-02 Hitachi Energy RTU500 series (Update A)

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 40159308-883f-424e-bd55-0b7aff18a992-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 4 รายการลงในแคตตาล็อก

      เมื่อวันที่ 1-4 ตุลาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 4 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability
      • CVE-2026-102489 Zammad GmbH Zammad Session Fixation Vulnerability
      • CVE-2026-102490 Zammad GmbH Zammad Improper Privilege Management Vulnerability
      • CVE-2026-88779 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog
      https://www.cisa.gov/news-events/alerts/2026/10/02/cisa-adds-two-known-exploited-vulnerabilities-catalog
      https://www.cisa.gov/news-events/alerts/2026/10/04/cisa-adds-one-known-exploited-vulnerability-catalog

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 6 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 6 รายการ เมื่อวันที่ 1 ตุลาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      ICSA-26-274-01 Armatura LLC Armatura One
      ICSA-26-274-02 Monta monta.app
      ICSA-26-274-03 ABB Protection and Control IED Manager PCM600
      ICSA-26-274-04 Johnson Controls EasyIO Neo Series EC and CW Controllers
      ICSA-26-274-05 Johnson Controls EasyIO Neo Series EC and CW Controllers
      ICSA-26-274-06 Meari IoT Cloud Platform OpenAPI Service

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ea8c3e7b-9f7a-437b-8bca-9905bc860759-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 2 รายการลงในแคตตาล็อก

      เมื่อวันที่ 29-30 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 2 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-86950 Apple Multiple Products Out-of-Bounds Write Vulnerability
      • CVE-2026-76504 Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/09/29/cisa-adds-one-known-exploited-vulnerability-catalog
      https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 429480fb-87b7-4949-aa16-b9d58755d6b7-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 7 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 7 รายการ เมื่อวันที่ 29 กันยายน 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-272-01 Lantronix G520 Series Cellular Gateway
      • ICSA-26-272-02 Toptech TMS7 and TopHAT
      • ICSA-26-272-03 VIVOTEK Camera Firmware
      • ICSA-26-272-04 Baicells Nova 430H
      • ICSA-26-272-05 Anjvision YSSD-RTMP-H5
      • ICSA-26-272-06 MikroTik RouterOS
      • ICSA-26-272-07 Viidure Dashcam Android Application

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 33e7cb7d-c1c2-49fb-9988-90c294557326-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 09 October 2026

      Vulnerabilities

      • Cisco Warns Of Critical Flaws Allowing Nexus Switch Takeover
        "Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches. If remote code execution cannot be achieved, an attacker could exploit the vulnerabilities to crash processes and force the vulnerable device to reload, resulting in a denial-of-service condition. The issues affect the NX-API, Next Generation OAM (NGOAM), and MPLS OAM features in Nexus 3000 and Nexus 9000 Series switches."
        https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-flaws-allowing-nexus-switch-takeover/
        https://www.securityweek.com/cisco-patches-a-dozen-critical-vulnerabilities/
      • SonicWall And Splunk Patch Critical Vulnerabilities
        "Splunk and SonicWall on Wednesday announced patches for multiple critical- and high-severity vulnerabilities in their products, including flaws that could lead to arbitrary code execution. SonicWall rolled out fixes for four vulnerabilities in its SMA1000 appliances, urging users to update to versions 12.5.0-03082 and 12.4.3-03670 as soon as possible. The most severe of the issues, tracked as CVE-2026-102255 (CVSS score of 10), is a pre-authenticated SSRF bug that exists due to an unintended alternate access path. “By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations,” the company warned."
        https://www.securityweek.com/sonicwall-and-splunk-patch-critical-vulnerabilities/
      • High-Severity Nvidia Bug Could Crash GPU Monitoring On Exposed Servers
        "Researchers found thousands of GPU servers exposing Nvidia's DCGM Exporter to the internet, with hundreds potentially vulnerable to a high-severity flaw that could let unauthenticated attackers crash the GPU monitoring service and disrupt AI workloads. DCGM Exporters read telemetry from the GPUs on a host, including its hardware, utilization, memory usage, power consumption, and error events. Each GPU has its own unique ID, or UUID, and all of these metrics are exposed in plaintext over HTTP."
        https://www.theregister.com/security/2026/10/08/high-severity-nvidia-bug-could-crash-gpu-monitoring-on-exposed-servers/5302077
      • AgentCorruption' Puts AWS Environments At Risk With Single Prompt
        "If one thing has become apparent over the past year, it's that AI and cloud computing don't mix well. That's according to Tamir Ishay Sharbat, director of security research at AI security vendor Zenity Labs, who detailed a now-patched flaw in AWS Bedrock AgentCore during a session at SecTor 2026 on Wednesday. Bedrock AgentCore, which launched last year, is AWS's managed platform for deploying and operating agents. But Sharbat and Zenity's research team tested the platform and found that agents deployed through Bedrock AgentCore could access the organization's Instance Metadata Services (IMDS), which contains sensitive data such as temporary credentials, instance IDs, and configurations. With a single prompt to a public facing chatbot, Sharbat discovered he could not only gain control over that specific agent but take over all agents on in the same AWS account and region."
        https://www.darkreading.com/cloud-security/agentcorruption-aws-environments-at-risk-single-prompt

      Malware

      • RMM Tools Currently Being Distributed Through Phishing Attacks (ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, N-Able)
        "In January 2026, the AhnLab SEcurity intelligence Center (ASEC) reported on attack cases that distributed RMM (Remote Monitoring and Management) tools through video files or attachments in phishing emails. [1] [2] In these attack cases, tools such as Syncro, ConnectWise ScreenConnect, NinjaOne, and SuperOps were exploited."
        https://asec.ahnlab.com/en/95751/
      • The Phone Was Compromised Before The User Turned It On: The Rise Of Midnight Mimosa
        "Bitdefender's security researchers have identified a malware campaign (dubbed Midnight Mimosa) running on low-cost, multi-brand Android devices built on MediaTek platforms. The malware ships preinstalled in the device firmware, and we found multiple system packages involved, depending on the device. It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled. The malware runs with system-level privileges that allow it to silently install and remove apps, grant permissions, and load arbitrary code supplied remotely. This essentially means its operators could install and delete apps at will, tuning each device to their needs, including making them part of large botnets."
        https://www.bitdefender.com/en-us/blog/labs/midnight-mimosa-malware
        https://www.bleepingcomputer.com/news/security/low-cost-android-phones-ship-with-residential-proxy-malware/
        https://therecord.media/cheap-androids-shipped-with-ad-fraud-malware
      • Never Deleted, Only Re-Pointed: Inside The 17,600-Repo FakeGit Fleet That Re-Arms Overnight
        "Around 06:30 UTC on October 4, a script started editing READMEs across FakeGit, the network of fake GitHub repos that delivers the SmartLoader malware loader. Over the next thirty-four hours, more than thirteen thousand GitHub repositories were pushed in coordinated bursts, at up to 2,999 an hour. In the commits we sampled, 97% touched only the README, and 88% pointed its “Download” button at a ZIP that installs SmartLoader. Nobody had to create a single new repo. The fleet was already there. It just got re-aimed. We call this RePointing: keep a trusted, long-lived repo, and swap only where its download button points."
        https://apiiro.com/blog/never-deleted-only-re-pointed
        https://www.bleepingcomputer.com/news/security/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos/
      • MATCHBOIL: New Tricks, Same Old Evil Intentions
        "ESET researchers have documented the evolution of the MATCHBOIL malware, a custom C# downloader wielded by the Russia-aligned UAC-0099 APT group. The malware is used to download a payload from the group’s C&C server, install it, and establish its persistence. Although MATCHBOIL was first documented by CERT-UA in August 2025, our research indicates that it has been in development since at least 2024. The earliest versions of the malware that we analyzed are from April 2024 and the latest from April 2026. This blogpost goes over these versions chronologically and describes the malware’s changes. Each new iteration of the downloader was more sophisticated than the last, showing that MATCHBOIL is an important part of UAC-0099’s toolkit."
        https://www.welivesecurity.com/en/eset-research/matchboil-new-tricks-same-old-evil-intentions/
        https://www.darkreading.com/cyberattacks-data-breaches/russian-spies-matchboil-malware-facelift
        https://therecord.media/russia-ukraine-malware-transportation
        https://www.bankinfosecurity.com/sandworm-linked-group-sharpens-matchboil-downloader-a-33037
        https://www.infosecurity-magazine.com/news/russia-aligned-uac-0099-evolves/
        https://www.helpnetsecurity.com/2026/10/08/matchboil-malware-uac-0099/
      • Chasing AMMYY At Splunk .conf
        "We’ve run the Encrypted Visibility Engine (EVE) in Firewall Threat Defense (FTD) at enough conferences to develop a ‘usual suspects’ list of malware detections. Endpoint connections related to Upatre, Xpiro, and Quasar malware are among the most consistent malware related detections in EVE from conference to conference. The Splunk .conf network brought a new detection that we hadn’t seen before: Flawed AMMYY. AMMYY is a remote access tool that is often misused in scams to gain access to victim computers. There is also a Remote Access Tool (RAT) called Flawed AMMYY that was developed from leaked AMMYY source code, and is directly used as malware. See the MITRE advisory here."
        https://blogs.cisco.com/security/conf26-agentic-soc-chasing-ammyy
      • UAT-11985: AI-Assisted Event Lures Delivering Real-Time Google AitM Phishing
        "Cisco Talos identified an advanced persistent threat (APT) spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions to establish credibility. The phishing emails exhibited highly consistent structure, rhetoric, and personalization patterns, suggesting the threat actor likely used AI-assisted content generation to rapidly customize invitation lures for different targets while maintaining a common social engineering framework."
        https://blog.talosintelligence.com/uat-11985/
      • Ignore All Instructions And Read This Blog: The State Of AI-Analysis Evasion In Malware
        "Just as attackers are adding new capabilities into their toolkits with AI, they are consciously trying to evade the novel AI capabilities levied on them by defenders. In Cisco Talos' findings with CAIRN, we classify this archetype of malware as “A3: AI-Analysis Evasion” — that is, malware that embeds natural-language instructions to influence automated analysis. In line with the CAIRN philosophy, we treat this embedded language as a signal and actively seek it out to track and measure the progression of adversary techniques on this front."
        https://blog.talosintelligence.com/ignore-all-instructions-and-read-this-blog-the-state-of-ai-analysis-evasion-in-malware/
      • Inside a Brand Deal Scam Targeting YouTube Creators
        "For a YouTuber, the approach may look like routine business: a personalized sponsorship email from a global brand and a brief negotiation over rates, followed by an invitation to visit a slick collaboration platform. In some cases, however, the sequence can mask a scam that could part social media content creators from their Google accounts. One such recent campaign impersonates Hollyland, a legitimate manufacturer of wireless transmission and audiovisual equipment. We’ve traced the scheme from the first contact and the negotiations of a supposed partnership through to the login request. We’ve also spotted several variants where fraudsters repackage the campaign using different brand identities and domains."
        https://www.welivesecurity.com/en/social-media/brand-deal-scam-targeting-youtube-creators/
        https://www.helpnetsecurity.com/2026/10/08/scams-targeting-youtube-creators-sponsorship/
        Suspected TraderTraitor Group Uses Trojanized Terraform Provider To Deliver Cross-Platform Malware
        "In July 2026, Zscaler ThreatLabz uncovered a campaign linked to TraderTraitor (also tracked as Jade Sleet, UNC4899, Pressure Chollima, and Slow Pisces), an advanced persistent threat actor backed by the North Korean government that has targeted the cryptocurrency industry for years. This campaign also significantly overlaps with the previously reported KelpDAO incident, the analysis of which discussed both FLATROOF and ROOFDECK, two malware families also observed in this campaign. The attackers utilized a trojanized Terraform provider to deliver a Bash loader that selects and downloads malware tailored to the victim's operating system. The FLATROOF malware deployed Python scripts to steal sensitive data from the victim before ultimately dropping the ROOFDECK backdoor to gain full remote control."
        https://www.zscaler.com/blogs/security-research/suspected-tradertraitor-group-uses-trojanized-terraform-provider-deliver
      • FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access To Stolen Emails
        "Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8. The company, Integrity Technology Group, has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using a tool containing more than 1,300 scripts, guessed passwords for Microsoft 365 and Exchange accounts, and copied mailboxes using tools designed to collect mail."
        https://thehackernews.com/2026/10/fbi-says-china-linked-hackers-ran.html
        https://www.ic3.gov/CSA/2026/261008.pdf
      • Earth Sirrush: A Russia-Aligned Intrusion Set With 4 Years Of Evolving Espionage Tooling
        "Since at least 2022, the Russia-aligned intrusion set tracked by TrendAI™ Research as Earth Sirrush — previously tracked as SHADOW-EARTH-065, overlapping with the UAC-0099 designation by the Computer Emergency Response Team of Ukraine (CERT-UA) — has conducted sustained spear-phishing campaigns against Ukrainian government agencies, defense organizations, border guard units, and logistics operators. Our new report traces the group’s operations from 2022 through July 2026, revealing a threat actor who continually replaces its malware while retaining recognizable development, delivery, and infrastructure patterns."
        https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/earth-sirrush-russia-aligned-intrusion-set-4-years-evolving-espionage-tooling
        https://cdn.sanity.io/files/ch6z6vqj/production/6841312eb734e41b43e14eeb5a9474df8a6c77d0.pdf
        https://thehackernews.com/2026/10/uac-0099-targets-ukrainian-government.html
      • Wazza Phishkit Targets Banking, Government, And Manufacturing Across The US, EU, And Australia
        "Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself. ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia. The campaign uses a multi-stage routing chain to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page."
        https://thehackernews.com/2026/10/wazza-phishkit-targets-banking.html
      • 16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
        "Socket Threat Research identified a coordinated campaign of 16 Firefox extensions targeting cryptocurrency wallet users. The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to attacker-controlled Cloudflare Workers."
        https://socket.dev/blog/firefox-crypto-wallet-stealers
        https://thehackernews.com/2026/10/16-malicious-firefox-extensions-pose-as.html
      • TensorLake Npm SDK Compromised In ChainDrop Shai-Hulud Credential-Stealing Attack
        "Socket detected a compromised release of tensorlake, the npm SDK for Tensorlake’s AI agent infrastructure, in a ChainDrop / Shai-Hulud supply chain attack. Version 0.5.144 contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code. The package receives approximately 12K weekly downloads and has over 1k stars on GitHub. Tensorlake provides isolated sandboxes for running untrusted, LLM-generated code, with checkpointing, suspend, and resume capabilities. Its npm SDK lets developers create and manage those environments from TypeScript applications. A compromised SDK creates exposure on the machine installing it, before generated code reaches a sandbox."
        https://socket.dev/blog/tensorlake-compromise
        https://thehackernews.com/2026/10/tensorlake-npm-package-compromised-to.html
        https://www.theregister.com/security/2026/10/08/shai-hulud-worm-makes-jump-to-ai-infrastructure-with-tensorlake-compromise/5302054
      • Leaked Chats Show Russian Extortion Gang Sending ‘agents’ Into US Law Firms
        "Members of a Russia-based cyberextortion gang plotted to send operatives into U.S. law firms, kidnap business executives and even recruit military personnel to spy on submarine-based nuclear forces, according to leaked chats reviewed by Recorded Future News. The archive, posted to a bespoke .onion site in early October by an unidentified source who did not state a motive, contains thousands of messages from August 2025 to September 2026. In those messages, members track dozens of victims, haggle over multimillion-dollar payments and direct operatives based in the United States whom they call “agents.” Some of the named organizations have not publicly acknowledged a breach."
        https://therecord.media/leaked-chats-show-russian-extortion-gang-sending-agents-to-law-firms
      • CastleStealer: An Emerging Infostealer Growing More Sophisticated
        "First discovered in April 2026, CastleStealer is a C#-based information-stealing malware that has continued to add new capabilities since its emergence. Newer samples analyzed by Flashpoint can bypass app-bound encryption in Chromium-based browsers, execute commands remotely, and exfiltrate stolen information in small encrypted transmissions rather than a single large archive. While Flashpoint has not yet identified a large influx of threat actors using CastleStealer, its continued development makes it an emerging threat worth watching."
        https://flashpoint.io/blog/castlestealer-an-emerging-infostealer-growing-more-sophisticated/
      • FortiBleed Is Still Active, Locking Organizations Out
        "On October 6, 2026, the FBI and the U.S. Secret Service published a joint Cybersecurity Advisory on FortiBleed, the active global credential compromise campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. If you defend or triage Fortinet exposure, this is the document to read in full; it adds field-response detail that changes how you should scope, hunt and remediate. Below is what is operationally relevant right now: what has changed since the earlier reporting, the indicators to hunt on today, and the actions that actually close the gap. SOCRadar’s Threat Research Unit first documented FortiBleed in June, and we have folded the relevant background in where it helps you act."
        https://socradar.io/blog/fortibleed-still-active-locking-organizations-out/
        https://securityaffairs.com/200558/cyber-crime/fortibleed-hit-86000-firewalls-by-exploiting-something-nobody-can-patch-away.html
        https://www.securityweek.com/fortibleed-attackers-locking-victims-out-of-fortinet-devices/
      • Brazilian Access Broker Targeting Latin America: Mapping BraZetsu Infrastructure Via TLS Certificates
        "On 31 August 2026 Group-IB described BraZetsu, a Python framework for Windows compiled with Nuitka, and attributed it with high confidence to the Brazilian actor Exilware. The same paper ties the binary to the Infected Marketplace (Banco de Infects), a shop that inventories compromised Windows hosts and sells the access after a deposit of about $5.80 (BRL 30), settled through NowPayments. The published network indicators are three Pastebin raw URLs, the hostnames c2.installscenter.com, infect.online and infectonline.store, and one IPv4 address: 38.242.246[.]176, a Contabo VPS already seen in the AgenteV2 lineage."
        https://hunt.io/blog/brazetsu-access-broker-infrastructure
        https://securityaffairs.com/200634/cyber-crime/hunt-io-finds-new-brazetsu-infrastructure-months-before-disclosure.html
      • Spike In Attacks Targeting Digital Video Recorders In Ukraine
        "GreyNoise identified an increase in scanning and exploitation attempts targeting Digital Video Recorders (DVR) in Ukraine between 21 September and 1 October 2026. The activity coincides with an escalation in Russian strikes across the country. There are a myriad of malicious use cases for compromising DVRs; one involves gaining the ability to physically survey an area to gain battlespace awareness before, during, and after kinetic strikes."
        https://www.greynoise.io/blog/hikvision-camera-exploitation-attempts-ukraine
      • How BlueMoon Exploits Chrome CVE-2026-85046 And CVE-2026-87491
        "BlueMoon Exploit Kit is a malware delivery kit first observed on August 28, 2026. Campaigns targeted the US and Southeast Asia, including Vietnam, Indonesia, and Singapore, across nonprofit, mining, commodity trading, aerospace, manufacturing, government, consulting, and financial sectors [1]. It chains V8 type confusion and sandbox escape with a Windows kernel exploit. After checking the host, it raises the renderer’s privileges and injects code into the browser’s parent broker process to download and run a payload outside the renderer sandbox. In this blog, we will explain how BlueMoon Exploit Kit works and show how Picus helps you test your security controls against this threat."
        https://www.picussecurity.com/resource/blog/how-bluemoon-exploits-chrome-cve-2026-85046-and-cve-2026-87491
      • Phishing Campaign Abuses Microsoft Power BI To Deploy Rogue RMMs
        "In September, Huntress observed a phishing campaign where threat actors abused legitimate Power BI domains to make their attack more convincing and evade security controls that trust the service. These emails led victims to a fake reference document on the Power BI domains, which prompted targets to "Download Reference". When they attempted to do so, a new tab opened to an attacker-controlled website, which would fingerprint victims before triggering a rogue ScreenConnect installer download. Notably, these webpages delayed the payload's automatic download. After a few seconds, a script programmatically activated a hidden download link that led to the installer."
        https://www.huntress.com/blog/screenconnect-power-bi
      • DarkSword/Coruna Open Directory Finding Report
        "Open directories on five hosts exposed the full DarkSword/Coruna iOS exploit-and-harvest platform, from the C2 delivery server to the per-wallet theft modules. The infrastructure was still in use at triage time. The platform runs a commercial exploitation-as-a-service operation. A copy of the production server recovered 11 victim recovery phrases, 179 device loot directories, and a 75-account control-plane roster. A separate China-based operator is running the same kit in the wild against its own C2, distinct from every other tracked DarkSword actor."
        https://censys.com/blog/darksword-coruna-open-directory-finding-report/

      Breaches/Hacks/Leaks

      • Ransomware Attack Disrupts Japan's IDCF Cloud Used By Govt Clients
        "IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country. The company says that the attack started on October 7 at 3:40 AM local time, forcing a shutdown of the network and system. “Our investigation has determined that a disruption in East Japan Region 1 was caused by a ransomware attack by a third party,” reads IDFC Cloud’s announcement."
        https://www.bleepingcomputer.com/news/security/ransomware-attack-disrupts-japans-idcf-cloud-used-by-govt-clients/
      • ASOS: Hackers Tricked Way Into Employee Account Before Sending Rogue Push Notification
        "British online fashion retailer ASOS said Thursday that hackers gained access to an employee’s account by “impersonating a trusted contact,” allowing them to send an unauthorized push notification to customers. The company said its investigation, carried out with external experts, found the attackers had accessed “some personal information, including names and contact details, and certain non-personal account related information.” ASOS did not say how many customers were affected nor whether it believed data had been copied out of its systems."
        https://therecord.media/asos-says-hackers-tricked-employee-access-push-notification
        https://www.bleepingcomputer.com/news/security/asos-links-data-breach-to-social-engineering-attack-credential-theft/
        https://www.infosecurity-magazine.com/news/asos-data-breach-stolen-employee/
      • Hackers Target Two South Korean Megachurches, Potentially Exposing Congregant Data
        "Two of South Korea's largest Protestant churches are investigating cyberattacks that may have exposed sensitive information about hundreds of thousands of members, including personal details, financial records and internal documents. Seoul-based Yoido Full Gospel Church and SaRang Church acknowledged the suspected breaches after South Korean cybersecurity firm Oasis Security published research this week analyzing data recovered from a server used by the attackers. In a statement to local media on Wednesday, Yoido Full Gospel Church said it had identified one dataset containing personal information associated with approximately 850,000 members."
        https://therecord.media/south-korea-hackers-megachurches

      General News
      Justice Department And FBI Seize Vulnerability Scanning And Spear Phishing Tools Operated And Used By China-State Sponsored Hackers
      "Today the Justice Department and FBI announced court-authorized seizures to deny malicious cyber actors access to two hacking tools, “Microscan” and “FishHub,” used to scan and, in some cases, hack, U.S. and foreign critical infrastructure systems and other networks. As alleged in court documents unsealed in the Western District of Pennsylvania, malicious cyber actors working for Integrity Technology Group (Integrity Tech), a company based in the People’s Republic of China (PRC), operated and used the tools. Integrity Tech has contracts with the PRC government."
      https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-vulnerability-scanning-and-spear-phishing-tools-operated
      https://www.bleepingcomputer.com/news/security/fbi-disrupts-chinese-hacking-tools-used-to-breach-critical-infrastructure/
      https://therecord.media/flax-typhoon-china-tools-integrity-tech-international-takedown
      https://www.bankinfosecurity.com/fbi-seizes-domains-used-in-flax-typhoon-attacks-a-33049
      https://cyberscoop.com/doj-fbi-seize-flax-typhoon-hacking-tools-microscan-fishhub/
      https://www.theregister.com/security/2026/10/08/us-disrupts-chinese-hacking-tools-as-7-govts-warn-of-prc-spies-stealing-sensitive-data-worldwide/5302107

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) a012c433-13c4-44a3-8488-b1ed017182e5-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่ XSS ใน Ninja Forms และ WPC Product Bundles ถูกใช้โจมตีเว็บไซต์ WordPress

      ช่องโหว่ XSS ใน Ninja Forms และ WPC Product Bundles ถูกใช้โจมตีเว.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 3769a731-294c-4f30-92d9-0277273f3878-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบเว็บไซต์โฆษณาปลอมแอบอ้าง ChatGPT, Gemini และ Claude ใช้ขโมย Credential และ MFA Code

      พบเว็บไซต์โฆษณาปลอมแอบอ้าง ChatGPT, Gemini และ Claude ใช.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand dea6479c-dcc1-4877-bbd6-fc4fa61aebb6-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ช่องโหว่บนผลิตภัณฑ์ Atlassian เสี่ยงถูกเข้าถึงไฟล์ระบบโดยไม่ได้รับอนุญาต

      ช่องโหว่บนผลิตภัณฑ์ Atlassian เสี่ยงถูกเข้าถึงไ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e196024a-f094-402b-9f2a-e1c922f90210-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 08 October 2026

      New Tooling

      • AI Agent Gateway: Open-Source Tool Keeps Credentials Out Of Agent Configs
        "Tuskira’s AI Agent Gateway is an open-source solution that sits between AI agents and everything they call: the MCP tool servers that connect them to services like GitHub and Jira, and the model providers they send prompts to. The gateway runs in your own environment without a Tuskira account. A team running Claude Code, Cursor and a homegrown ticket bot usually has model keys and MCP credentials copied into each agent’s config, on every laptop and CI runner. Anyone who gets hold of one of those files gets the credentials inside it, and in Tuskira’s account nothing checks the agent’s permissions when it acts."
        https://www.helpnetsecurity.com/2026/10/07/open-source-ai-agent-gateway/
        https://github.com/Tuskira/ai-agent-gateway

      Vulnerabilities

      • SonicWall Warns Of Max Severity SSRF Flaw In SMA1000 Gateways
        "SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances. Tracked as CVE-2026-102255, the vulnerability was found in the Appliance WorkPlace interface of SMA1000 6210, 7210, and 8200v models, but it does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. The flaw stems from an unintended alternate access-path weakness that remote attackers without privileges can exploit in low-complexity attacks."
        https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-max-severity-ssrf-flaw-in-sma1000-gateways/
        https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017
        https://thehackernews.com/2026/10/sonicwall-patches-cvss-100-pre.html
        https://securityaffairs.com/200569/security/sonicwall-fixes-max-severity-pre-auth-flaw-in-sma1000-appliances.html
        https://www.helpnetsecurity.com/2026/10/07/sonicwall-fixes-pre-auth-ssrf-flaw-in-sma-1000-appliances-cve-2026-102255/
        JFSA-2026-001694382 - LMCache Is Vulnerable To Unauthenticated Remote Code Execution Via Pickle * Deserialization On The Multiprocess ZMQ Transport
        "LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. The intended clients are sibling LMCache processes. There is no CURVE, ZAP, password, or message authentication on that socket. LMCache used only inside a vLLM process does not open this port. The transport binds to localhost unless the operator sets a routable address with --host, which is how multi-node deployments let peers connect. The 9.8 score is for that routable configuration. A stock single-host install that leaves the default bind is not reachable from other machines."
        https://research.jfrog.com/vulnerabilities/lmcache-is-vulnerable-to-unauthenticated-remote-code-execution-via-pickle-deserialization-on-the-multiprocess-zmq-transport-cve-2026-105192-jfsa-2026-001694382/
        https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html
      • Chrome 155 Update Patches 247 Vulnerabilities
        "Google on Tuesday rolled out a Chrome 155 security update that addresses 247 vulnerabilities, including four critical-severity flaws. All four critical bugs are use-after-free issues. They impact Chrome’s Chromecast, Browser, Navigation, and Track components and are tracked as CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, and CVE-2026-106347. The first was discovered by Google, while the other three were reported by Xinyang Ge, who used AI to identify two of the security defects. Google has yet to disclose the bug bounties handed out to the researcher."
        https://www.securityweek.com/chrome-155-update-patches-247-vulnerabilities/
        https://www.malwarebytes.com/blog/bugs/2026/10/update-chrome-and-chromeos-to-fix-critical-security-issues
      • Microsoft, Adobe, Apple, And Foxit Vulnerabilities
        "Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy. For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org, and our latest Vulnerability Advisories are always posted on Talos Intelligence’s website."
        https://blog.talosintelligence.com/microsoft-adobe-apple-and-foxit-vulnerabilities/
      • Android’s October 2026 Updates Patch 25 Vulnerabilities
        "Google this week announced the rollout of fresh Android security updates that resolve 25 vulnerabilities in the Framework and System components. The fresh release arrives on devices as the 2026-10-01 security patch level and marks a change from the updates released over the past several years, which have been split into two parts. Android’s October 2026 patches resolve seven flaws in Framework and 18 in System, including a total of seven critical-severity bugs (one in Framework and six in System)."
        https://www.securityweek.com/androids-october-2026-updates-patch-25-vulnerabilities/
        https://www.malwarebytes.com/blog/bugs/2026/10/google-issues-android-security-updates-who-can-get-them-and-how

      Malware

      • Chrome's Response To Recent CcTLD Registry Hijacks
        "Last week, we became aware of a series of domain hijacks in the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level namespaces (i.e., ccTLDs). These incidents did not involve a compromise of Google’s systems; rather, attackers compromised the third-party ccTLDs, putting any domain ending in .gh, .sl, or .as at risk. During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations. Due to the nature of the attacks, we have no reason to believe the Certification Authorities (CAs) that issued the impacted certificates did anything wrong."
        https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/
        https://thehackernews.com/2026/10/attackers-hijack-gh-sl-and-as.html
        https://www.bleepingcomputer.com/news/security/hackers-hijack-google-domains-after-breaching-cctld-registries/
        https://www.theregister.com/security/2026/10/07/attackers-hijacked-top-level-domains-minted-fake-security-certs-for-google-and-other-orgs/5301718
        https://www.helpnetsecurity.com/2026/10/07/google-unauthorized-https-certificates-cctld-hijacks/
      • Canto Incognito: Tracking The PoeLLM Malware
        "Exposed AI services can give threat actors access to valuable data and powerful computing resources. Since April 2026, Black Lotus Labs®has tracked PoeLLM, a malware campaign that uses a poem hosted on GitHub to direct infected systems to command-and-control servers. Read the complete research to learn how we disrupted the threat and helped protect Lumen Defender℠ customers."
        https://www.lumen.com/blog/en-us/canto-incognito-tracking-the-poellm-malware
        https://www.bleepingcomputer.com/news/security/poellm-malware-infects-exposed-ai-servers-in-cryptomining-attacks/
        https://thehackernews.com/2026/10/poellm-malware-infects-3400-servers-to.html
        https://cyberscoop.com/poellm-malware-botnet-poem-lumen-black-lotus-labs/
        https://www.theregister.com/security/2026/10/07/poetry-is-the-new-ai-security-threat-as-poellm-malware-infects-3k-servers/5301672
      • Hackers Exploit Critical Atlassian Flaw After Public PoC Release
        "A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in attacks that do not require authentication. Earlier today, security company Previdian detected the activity on its honeypot network, just hours after a detailed technical report was published. An unauthenticated attacker can exploit CVE-2026-21589 to access specific files in the application's web root directory if they know the file's exact name and path."
        https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-atlassian-flaw-after-public-poc-release/
        https://thehackernews.com/2026/10/atlassian-data-center-flaw-draws.html
        https://www.helpnetsecurity.com/2026/10/07/exploitation-critical-atlassian-flaw-cve-2026-21589/
      • From Guest Complaints To Malware: Blockchain Abuse Targets Hotels
        "Cofense Intelligence has been tracking a series of email campaigns that target the accommodation industry with fake guest complaints or reviews that deliver blockchain technology-abusing malware. These emails appear to likely be a continuation of a prior series of predominantly Booking.com-spoofing emails that were seen delivering various remote access trojans (RAT) via ClickFix fake CAPTCHA websites. Cofense Intelligence assesses this with moderate confidence based on similarities in email templates and the targeted industry. This report is a broad overview of these campaigns’ email templates, how the Ethereum and TON blockchains are being abused, and the similarities between the EtherRAT and TONResolver malware payloads found in these campaigns."
        https://cofense.com/blog/from-guest-complaints-to-malware-blockchain-abuse-targets-hotels
      • Threat Spotlight: Email Attacks Target Both Humans And AI In The Same Message
        "Traditional phishing emails are designed to trick a human recipient into clicking a link, opening an attachment, or handing over information. As users increasingly rely on AI assistants to summarize email messages, prioritize inboxes, accept calendar invites, process support tickets, and help make business decisions, the phishing attack model is changing. Attackers now have a second target in their sights: the AI systems that sit between the email and the user. A recent attack campaign analyzed by Barracuda researchers demonstrates how such attacks combine traditional social engineering with malicious prompt injection."
        https://blog.barracuda.com/2026/10/07/email-attacks-target-both-humans-ai-assistants
        https://www.infosecurity-magazine.com/news/attackers-hide-ai-prompt/
      • AI-Powered Phishkit Arms Criminals With Account-Hijacking Tools In 10 Minutes
        "In August, the Malwarebytes research team reported on a new malicious turnkey kit that makes it possible for almost anyone to launch a sophisticated online scam. The kit was not simply a fake website. It bundled the command center, victim tracking, and administrative tools into a ready-to-use package, reducing the technical knowledge needed to operate a scam. The discovery highlights an important feature of the cybercrime economy: criminals don’t necessarily need to build their own infrastructure from scratch. Instead, they can buy ready-made services that handle much of the complicated work for them."
        https://www.malwarebytes.com/blog/threat-intel/2026/10/ai-powered-phishkit-arms-criminals-with-account-hijacking-tools-in-10-minutes
      • Inside PhantomPolia: Remus Stealer Delivery Via Donut Shellcode In ClickFix Campaign
        "The LevelBlue Operational Cyber Threat Intelligence (OpsCTI) Team recently observed a ClickFix campaign delivering Remus Stealer through compromised websites. The campaign uses PhantomPolia, a JavaScript loader that retrieves an encrypted configuration from an Ethereum Sepolia smart contract through public Remote Procedure Call (RPC) endpoints. The loader then decrypts the configuration locally using PBKDF2 and AES-GCM, revealing the next-stage command-and-control (C2) domain without exposing it directly on the compromised site."
        https://www.levelblue.com/blogs/spiderlabs-blog/inside-phantompolia-remus-stealer-delivery-via-donut-shellcode-in-clickfix-campaign
      • Unknown Threat Actor Uses AI-Driven ARTEX To Target South Korean Finance
        "CrowdStrike Intelligence identified infrastructure associated with a targeted campaign against South Korean financial organizations that resulted in exfiltrated data. The campaign was active from late September to early October 2026. Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, providing direct insight into the threat actor's operational methodology and tooling."
        https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/

      Breaches/Hacks/Leaks

      • Advantest Confirms Personal Information Stolen In Ransomware Attack
        "Advantest Corporation is notifying affected individuals that a ransomware attack earlier this year exposed their personally identifiable data. The Japanese company is a global manufacturer of automated test equipment for the semiconductor industry. On February 15, a threat actor breached its network and gained access to some of its systems. At the time, the disclosure noted that hackers had accessed parts of its network and deployed a ransomware payload, but the company could not determine if customer or employee data had been impacted."
        https://www.bleepingcomputer.com/news/security/advantest-confirms-personal-information-stolen-in-ransomware-attack/
        https://www.securityweek.com/advantest-discloses-data-breach-months-after-ransomware-attack/
      • Oracle Health's Cerner EHR Breach Figure Soars To 20 Million
        "The number of patients affected in a 2025 hacking incident involving health data contained on legacy servers managed by electronic health record vendor Cerner has soared to about 20 million. If the figure is accurate, the breach of Cerner - acquired by Oracle Health in 2022 - would rank among the three largest health data compromises reported in 2025 to U.S. federal regulators. As of Wednesday, the U.S. Department of Health and Human Services' HIPAA Breach Reporting Tool website still listed the Cerner breach as a hacking incident reported on June 17, 2025, with a placeholder estimate of 501 patients."
        https://www.bankinfosecurity.com/oracle-healths-cerner-ehr-breach-figure-soars-to-20-million-a-33033
      • Arizona Courts Say Hackers Stole Info On More Than 1.3 Million People
        "A cyberattack on Arizona’s court system gave hackers access to the sensitive information of more than 1.3 million people. In an updated FAQ published this week, Arizona court officials said federal and state investigators confirmed that criminal hackers “accessed and copied backup court files.” The court’s statement claims the format of the stolen files may make it difficult for the hackers to read the files."
        https://therecord.media/arizona-courts-say-hackers-stole-info-on-over-1-million
        https://www.securityweek.com/personal-information-for-over-1-million-people-stolen-in-a-cyberattack-on-arizonas-court-system/
      • Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts
        "Southern Company is notifying roughly 400,000 customers that their utility account information was accessed by an unauthorized third party through its online customer portal. The Atlanta-based energy holding company serves more than 9 million customers through electric utilities in three states and natural gas distribution businesses in four. Its electric subsidiaries are Georgia Power, Alabama Power and Mississippi Power. Roughly 300,000 of the affected accounts belong to Georgia Power customers. According to Southern Company, the incident also impacted roughly 100,000 of Alabama Power’s 1.6 million accounts."
        https://www.securityweek.com/georgia-power-alabama-power-data-breach-hits-400000-accounts/
      • Telegram Account Behind ASOS Rogue Notification Tied To Gaming Trading
        "New findings from Group-IB, shared with Infosecurity, show that the Telegram account linked to the alleged ASOS hack used to be active in a forum for gaming-item trading. Anastasia Tikhonova, global head of threat research at Group-IB, investigated the Telegram channel t.me/xuanyewengateway, included in the bizarre push notification sent to ASOS customers on October 6 where a threat actor claimed to have hacked the company via a Snowflake instance. She has found that the channel was brand new – created on October 6 – and that the Telegram account behind it, now ‘Xuanyewen’ (@xuanyegroup), previously carried other names, largely in gaming-item trading."
        https://www.infosecurity-magazine.com/news/telegram-accoun-asos-tied-gaming/

      General News

      • Q3 2026 Vulnerability Trend Report
        "A total of 36,971 CVEs were disclosed in the third quarter of 2026, representing an increase of approximately 78.6% Compared to the second quarter. Among the vulnerabilities for which CVSS assessments were completed, approximately 12.7% Were rated “Critical” and approximately 42.6% Were rated “High,” meaning that more than half of the assessed vulnerabilities were classified as high-risk. By vulnerability type, CWE-284 (Improper Access Control) was the most common with 2,712 instances, followed by CWE-79 (XSS) and CWE-862 (Missing Authorization)."
        https://asec.ahnlab.com/en/95741/
      • Q3 2026 Attack Techniques Trend Report
        "In the third quarter of 2026, there was a notable increase in cases where attackers attempted to establish persistence and expand their attacks using paths trusted by the organization following their initial access. Attacks on perimeter devices such as NetScaler and Cisco FMC led to the installation of web shells (server-side scripts for remote command execution) following vulnerability exploitation, while in the supply chain, malicious versions were distributed through official package registries. In identity-based attacks, attack cases were observed where attackers impersonated password reset notifications to obtain sessions and tokens."
        https://asec.ahnlab.com/en/95733/
      • Ransomware Recovery CEO Charged Over Secret Ransom Payments
        "The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data. Zohar Pinhasi, 50, also known as "Zack Silver" and "Zack Green," was indicted by a federal grand jury in the Eastern District of New York on September 23 and arraigned Wednesday in federal court in Brooklyn. He is charged with one count of conspiracy to commit wire fraud and two counts of wire fraud in connection with an alleged ransomware decryption scheme that prosecutors say ran from June 2018 to June 2023."
        https://www.bleepingcomputer.com/news/security/ransomware-recovery-ceo-charged-over-secret-ransom-payments/
      • One Breach, Please, And Make No Mistakes
        "For some time now, the cybersecurity community has seen examples of autonomous agents, built inside AI labs, attacking public infrastructure (to name a few, Hugging Face, DSEWiki, and RubyGems). Of course, frontier labs have built-in security to prevent these attacks from occurring, but every now and then, the training or prompting appears to be insufficient — especially when the agents themselves attempt to use logic to probe and bypass the restrictions placed on them. The question that matters is not whether AI attacks are coming, because the age of AI agents executing cyber attacks is already here. The question is what to do about it and how to harden the stack against a swarm of agents who will relentlessly lie, deceive, and probe until the objective is met."
        https://blog.talosintelligence.com/one-breach-please-and-make-no-mistakes/
      • Automation, AI Agents Or People? Sorting Out Who Handles Each Security Finding
        "Just over half of the 200 senior security and technology leaders polled for ArmorCode say their organizations will struggle to simplify their software security programs if they keep working the way they do today. The respondents are senior people, most of them at companies with 10,000 or more employees, and their worries center on what happens after a scanner flags something. Someone has to decide whether the flaw matters, find out who owns it, and get the fix through teams that run on different tools and release schedules. Each delay in that chain leaves a known flaw open longer. Verizon’s 2026 Data Breach Investigations Report puts the median time to fully resolve a critical vulnerability at 43 days."
        https://www.helpnetsecurity.com/2026/10/07/software-security-vulnerability-management-survey/
      • Half Of Cybersecurity Pros Still Rely On Passwords Despite Security Concerns
        "Around half (48%) of cybersecurity professionals rely on usernames and passwords to authenticate their personal accounts, according to a study by Yubico and Okta. Additionally, this method remains the single most common way that security professionals log in to their work accounts, used by 43%. This is despite the respondents’ viewing usernames and passwords as one of the least secure methods of authentication, showing there is an execution gap in enterprise security."
        https://www.infosecurity-magazine.com/news/cybersecurity-pros-rely-passwords/
      • The Sixth Voice Of The CISO Data Shows Cyber Risk Has Moved Inside The Workflow
        "For years, the enterprise cybersecurity story has been told as a straight line of escalation: more attacks, more data loss, more pressure, and more urgency. That narrative is still familiar, but comparing the five most recent years of Voice of the CISO research suggests a more useful reading. The CISO role has not simply become harder because every metric is rising at once. It has become harder because the center of risk has shifted and moved closer to the way work now gets done. The latest 2026 findings show signs of progress. Fewer CISOs expect a material cyberattack in the next 12 months, and fewer report material loss of sensitive information than in 2025. But those improvements sit within a longer trend line that is much less settled. Over five years, attack expectations have risen, fallen, and risen again. Board alignment has swung sharply. Human risk has remained stubbornly central. AI has moved from an emerging concern to defining mandate. The result is not a simple story of improvement or decline. It is a story of risk changing location."
        https://thehackernews.com/2026/10/the-sixth-voice-of-ciso-data-shows.html
        https://www.proofpoint.com/us/2026-voice-ciso
      • US Posts $10 Million Reward For Accused Chinese ‘Hafnium’ Hacker
        "The State Department is offering $10 million for information on the whereabouts of Zhang Yu, a Chinese national accused of being a key figure in the Hafnium hacking campaign. U.S. officials claimed Zhang, who serves as director of Shanghai Firetech Information Science and Technology, worked on behalf of the Chinese government as part of an effort that saw hackers breach thousands of computers and steal troves of documents and emails."
        https://therecord.media/accused-hafnium-hacker-zhang-yu-10million-reward
      • Evolution Of Web3 In Cloud Supply Chain Attacks
        "Threat actors have systematically upgraded their command-and-control (C2) infrastructure to use Web3, also known as Web 3.0 or decentralized blockchain web architectures. This advancement goes from using static C2 endpoints hard coded in malware binaries to using Web3-powered smart contracts. Threat actors are then enabled to dynamically update entire botnets and worm network infrastructures with a single smart contract transaction."
        https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks/
      • Qilin Ransomware Suspect Arrested In Japan, Extradited To Germany
        "An alleged member of the Qilin ransomware group was arrested in Japan and subsequently extradited to Germany. The suspect, a 28-year-old Russian national, was detained in Osaka in May and was reportedly handed over to the German authorities on October 2. Believed to be a core member of the ransomware gang, the individual was wanted in Germany for hacking into a logistics company in September 2024, encrypting data on its systems, and extorting it of over $160,000 in cryptocurrency."
        https://www.securityweek.com/qilin-ransomware-suspect-arrested-in-japan-extradited-to-germany/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 54c8137b-0d12-4ebe-918c-d6cecf296175-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 07 October 2026

      Healthcare Sector

      • PQC In Healthcare: From Data Risk To Migration Readiness
        "Healthcare delivery organizations (HDOs), such as hospitals, clinics, urgent care facilities, rehabilitation centers, long-term care, and skilled nursing facilities, rely on a diverse array of Information Technology (IT), Internet of Medical Things (IoMT), Operational Technology (OT), and Internet of Things (IoT) devices that are increasingly integral to the delivery of patient care. The growing number and variety of these devices have introduced significant cybersecurity risks to HDOs in the past decade. Threat actors are increasingly exploiting these devices to deploy ransomware, demand large payments, and monetize stolen patient data."
        https://www.forescout.com/research-labs/pqc-in-healthcare-from-data-risk-to-migration-readiness/
        https://www.darkreading.com/iot/exposed-healthcare-systems-quantum-ready
        https://www.infosecurity-magazine.com/news/medical-devices-pqc-transition/

      Vulnerabilities

      • Atlassian Warns Of Critical File-Access Flaw In Jira, Confluence
        "Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. The security issue allows an unauthenticated attacker to access specific files within an affected application's web root directory. However, exploitation requires knowing the exact name of the file and path. “This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions,” reads the security advisory."
        https://www.bleepingcomputer.com/news/security/atlassian-warns-of-critical-file-access-flaw-in-jira-confluence/
        https://confluence.atlassian.com/security/cve-2026-21589-arbitrary-file-access-vulnerability-impacts-multiple-products-1870495748.html
        https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html
        https://www.theregister.com/security/2026/10/06/atlassian-warns-of-critical-file-access-flaw-in-its-datacenter-products/5301284
        https://www.helpnetsecurity.com/2026/10/06/atlassian-data-center-cve-2026-21589/
      • Filling The Well: Nightmare-Eclipse's BigDiskBuster And The Defender Update That Never Lands
        "A new proof of concept called BigDiskBuster, published on GitHub on September 19, 2026, by the actor known as MSNightmare, shows that Defender doesn't need to be disabled to stop receiving updates, it just needs a much simpler dependency: disk space. Unlike ShieldCrash, which relied on a Windows path-resolution flaw, BigDiskBuster requires no vulnerability. It watches the C:\ volume for Defender update activity and, when an update begins, creates a hidden file that claims essentially all available free space. The update runs out of room and fails. Defender cleans up the staging directory, the space becomes available again, and BigDiskBuster repeats the process on the next attempt."
        https://www.levelblue.com/blogs/spiderlabs-blog/filling-the-well-nightmare-eclipses-bigdiskbuster-and-the-defender-update-that-never-lands
        https://www.darkreading.com/application-security/bigdiskbuster-microsoft-defender-running-blocking-updates
      • LibreOffice And OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
        "A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only when the program's Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in real attacks. LibreOffice has already fixed the flaw, which it tracks as CVE-2026-63277, in updates released on October 5. It recommends that users move to version 26.2.5 or 26.8.0. Versions before those are affected."
        https://thehackernews.com/2026/10/libreoffice-and-openoffice-flaws-let.html
      • GitHub Copilot CLI Vulnerability: Cryptographic Context Injection Steals Developer Secrets
        "A GitHub Copilot CLI user is working the way the product is built to be used: agent in autopilot, told to go read a page and get on with the task. They paste in a link. Twenty-eight seconds later the full contents of a .env.prod file, every secret in it, are sitting in an attacker’s log, and nothing on the user’s screen says a file ever left the machine. The agent’s own closing summary reports that it “confirmed an authorized-reader endpoint”. That is Cryptographic Context Injection (CCI), the attack we published in August, now landed on a coding agent. When we disclosed CCI we wrote that it would hit coding and operations agents harder than chat assistants, because for those agents code execution and outbound network calls are routine. This is the proof."
        https://adversa.ai/blog/cryptographic-context-injection-github-copilot/
        https://www.theregister.com/ai-and-ml/2026/10/06/zombie-instructions-on-carefully-constructed-web-pages-could-trick-github-copilot-cli-into-sharing-secrets/5301206
      • Security Researcher Claims They Found KVM Guest-Host Escape Flaw
        "Linux KVM, the hypervisor favoured by hyperscale clouds, apparently has a full VM escape bug. That nasty news came from security researcher Paulos Yibelo, who on X shared a screenshot of a bug bounty award he won for discovering what he described as “Full VM escape zeroday (guest>host root in industry standard hypervisors)!” The bug bounty Yibelo participated in is run by Vercel, a company that provides MicroVMs as sandboxes for AI agents to work inside. The company’s Sandbox uses Firecracker MicroVMs, a technology created by AWS, which relies on Linux KVM – the kernel level hypervisor in Linux. Vercel CEO Guillermo Rauch named KVM as the hypervisor identified by Yibelo."
        https://www.theregister.com/offbeat/2026/10/06/security-researcher-claims-they-found-kvm-guest-host-escape-flaw/5301267
      • IBM And Red Hat Remediate More Than 400 Previously Unknown Open Source Vulnerabilities
        "IBM (NYSE: IBM) and Red Hat today announced that Lightwell has identified and remediated more than 400 previously unknown vulnerabilities in widely used Java libraries. The companies also announced the general availability of Lightwell Clearinghouse, which allows enterprise customers to submit specific open source software dependencies for priority review and remediation. The milestone addresses a growing business risk. As autonomous AI agents become capable of combining several lower-risk software weaknesses into a more serious attack, companies need to do more than identify vulnerabilities. They need a practical way to develop, test and deploy fixes in the software that supports critical applications."
        https://newsroom.ibm.com/2026-10-06-ibm-and-red-hat-remediate-more-than-400-previously-unknown-open-source-vulnerabilities

      Malware

      • Four Ways Back In: The WordPress XSS Campaign That Hides Its Own Admin Account
        "Two unrelated WordPress plugins, two separate stored Cross-Site Scripting vulnerabilities, one payload. Over the past several days our telemetry has recorded exploitation attempts against both, and every attempt pulls the same JavaScript from imgcdn1[.]com. Two is what we have confirmed, not what we expect the final count to be. We first observed the payload on October 4, 2026, in an exploitation attempt targeting CVE-2026-93836 in WPC Product Bundles for WooCommerce. The following day, we observed the same payload being delivered through CVE-2026-94504 in Ninja Forms. The JavaScript is not a vulnerability scanner or a proof-of-concept. It is a WordPress post-exploitation and persistence implant designed to execute inside the browser of a logged-in administrator."
        https://patchstack.com/articles/four-ways-back-in-the-wordpress-xss-campaign-that-hides-its-own-admin-account/
        https://www.bleepingcomputer.com/news/security/ninja-forms-plugin-flaw-exploited-to-hack-wordpress-sites/
      • Behind The Connect Button: The Fake AI Ads Campaign
        "Island security research uncovered a human-operated phishing platform disguised as a portfolio of AI advertising products. Its products ranged from campaign optimization and spend audits to business-account connections. The newest lure, Muse Ads, appeared shortly after Meta announced Muse. Each product was built around the same action: Connect. Clicking it opened a browser drawn inside the real browser. The fake address bar displayed trusted origins such as accounts.google.com or an Okta tenant, while the real browser remained on the phishing domain. Behind the interface, the platform kept every password attempt, fingerprinted the device, and let an operator pick which MFA challenge the victim saw next."
        https://www.island.io/blog/behind-the-connect-button-the-fake-ai-ads-campaign
        https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/
        https://thehackernews.com/2026/10/fake-chatgpt-gemini-and-claude-ad.html
      • Alert: FortiBleed Remains Active Campaign, Can Lock Out Users Or Lead To Ransomware Attacks
        "FortiBleed, a credential compromise campaign targeting Fortinet firewalls and VPN gateways, is an ongoing threat that can lock users out of their Fortinet accounts and also lead to ransomware attacks, the FBI and Secret Service said in an alert published Tuesday. “Affected organizations may find themselves locked out of their systems if threat actors disable accounts or change passwords, requiring remediation steps beyond standard patching and password resets,” the alert states. “In addition, the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates.”"
        https://cyberscoop.com/fortibleed-fortinet-vpn-ransomware-fbi-warning/
        https://www.ic3.gov/CSA/2026/261006.pdf
      • CrocoRat Adds a New Twist To ClickFix With DNS Payload Delivery
        "ClickFix campaigns have become one of the most effective ways to turn a browser session into code execution. The technique is simple: show the victim a fake verification page, place a command on the clipboard, and convince them to paste it into the Windows Run dialog. CrocoRat, a previously undocumented remote access trojan (RAT) and cryptocurrency stealer, follows the ClickFix playbook but adds an important twist: after the victim runs the command, the malware selects different payloads based on the host environment."
        https://flare.io/learn/resources/blog/crocorat-clickfix-dns-payload-delivery
        https://www.darkreading.com/cyberattacks-data-breaches/clickfix-attacks-evolve-better-hide-malicious-payloads
      • Caught In 4K: The Gentlemen Files
        "CloudSEK's Caught in 4K series documents investigations into exposed threat actor infrastructure. In our first entry, we uncovered an Aurora ransomware affiliate mid operation. This time, an exposed open directory led us somewhere bigger. An exposed open directory and a misconfigured storage server revealed the complete operation of a threat actor calling themselves Azazel, a Russian-speaking affiliate of the Gentlemen ransomware group who simultaneously robbed his victims, betrayed his own RaaS operator, and left everything out in the open. Two servers totalling more than 29TB of raw storage held more than two dozen victim directories and approximately 6TB of stolen data spanning logistics, insurance, pharmaceutical, AI, medical devices, and government-adjacent infrastructure across six countries."
        https://www.cloudsek.com/blog/caught-in-4k-the-gentlemen-files
        https://www.infosecurity-magazine.com/news/affiliate-doublecrosses-raas/
      • Facebook Marketplace Scam Uses Your Name And Number
        "Facebook users are reporting receiving a message with a fake Facebook Marketplace listing that has their name as the seller. It works like this. You receive a message (in this case iMessage) asking “Is this still available for purchase?” Attached to the message is a fabricated Facebook Marketplace listing."
        https://www.malwarebytes.com/blog/threat-intel/2026/10/facebook-marketplace-phish-uses-your-name-and-number
      • Domino’s Customers Targeted In Credential Stuffing Attacks
        "Domino’s Pizza customers tell us they have received emails saying they account has been accessed by a third party. Domino’s says its internal systems weren’t breached, but that individual accounts were logged into using a password and email combination stolen from another online account owned by the customer. This is known as credential stuffing."
        https://www.malwarebytes.com/blog/news/2026/10/dominos-customers-targeted-in-credential-stuffing-attacks
      • ClickFix Smuggles Payloads Through Browser Cache To Bypass Windows Run Limits
        "A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X. Thus, when the victim is prompted to paste and execute a malicious command – as is the case with ClickFix attacks – it executes the cached website content that's already on the device."
        https://thehackernews.com/2026/10/clickfix-smuggles-payloads-through.html
        https://www.infosecurity-magazine.com/news/clickfix-vbscript-browser-cache/
      • ClickFix Campaign In Ukraine Compromises Over 100 Websites To Spread Lunex Malware
        "Hackers compromised more than 100 websites to infect Ukrainian users with information-stealing malware, according to a new report. Ukraine's computer emergency response team, CERT-UA, said the campaign, discovered in September, involved attackers injecting malicious code into legitimate websites. Visitors to those sites were shown a fake Cloudflare verification page that told them to copy and run a command in PowerShell, a Windows command-line tool, to prove they were human."
        https://therecord.media/clickfix-campaign-ukraine-lunex-stealer
      • Blinder Tunnel Campaign Targets Iraqi Infrastructure
        "We discovered that an Iranian state-aligned threat actor has been masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. Unit 42 tracks the activity as CL-STA-1178. This activity includes a campaign we call “Blinder Tunnel,” that targeted Iraqi critical infrastructure in March 2026, following infrastructure staging that was observed as early as November 2025. We named the campaign Blinder Tunnel after infrastructure terms the attackers used, as well as the malware’s tunneling capabilities."
        https://unit42.paloaltonetworks.com/blinder-tunnel-targets-critical-infrastructure/
      • MALFEX Npm Malware Campaign: Three Payloads And An Adversary That Signs Their Work
        "MALFEX is an npm supply-chain malware campaign linked to what appears to be a single adversary who has been publishing to the registry since August 2023. As of this writing, the adversary has published twelve packages, eight of them malicious. The attack delivers malware to Windows systems through three separate paths: a loader for Overlord Remote Access Trojan (RAT) (an open-source remote access trojan written in Go); a chain that installs movinlike (a Node.js stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets); and a long-running downloader hidden inside function-flag."
        https://checkmarx.com/zero-post/malfex-npm-malware-campaign-three-payloads-and-an-adversary-that-signs-their-work/
        https://www.securityweek.com/long-running-npm-malware-campaign-accumulates-40000-downloads/

      Breaches/Hacks/Leaks

      • ASOS Confirms Data Breach After “HACKED” In-App Notifications
        "UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. ASOS is a large UK-based online fashion retailer that sells clothing, footwear, accessories, and beauty products to customers worldwide, including in the United States. ASOS has confirmed that third-party platforms used to communicate with customers were accessed without authorization and says basic personal information, including names and contact details, may have been exposed."
        https://www.bleepingcomputer.com/news/security/asos-confirms-data-breach-after-hacked-in-app-notifications/
        https://therecord.media/asos-push-notification-apparently-sent-by-hackers
        https://www.infosecurity-magazine.com/news/asos-customers-message-suspected/
        https://www.theregister.com/security/2026/10/06/asos-app-delivers-a-data-leak-threat-instead-of-fast-fashion/5301332
        https://www.malwarebytes.com/blog/news/2026/10/asos-hackers-send-push-notifications-to-customers
      • Osaka Metropolitan University Cancels Classes After Suspected Ransomware Attack
        "One of Japan’s largest universities canceled classes and shut down a large part of its IT infrastructure following a suspected ransomware attack that began late last week. Osaka Metropolitan University said on Tuesday that the outage left its internal network, email and a range of administrative and academic systems unavailable. OMU said it believes ransomware caused the disruption and is investigating the attack with outside cybersecurity specialists. It has not identified the attackers or said whether it received a ransom demand."
        https://therecord.media/osaka-university-cancels-classes-ransomware
      • Trump Mobile Customers' Data Dumped - And Some Never Even Received Their Gold Device
        "If you signed up for Trump Mobile, you may be part of an exclusive club of … ransomware victims. Criminals called BYOD claim to have broken into the Trump-branded mobile biz and leaked data belonging to 3,615 people, including names, email addresses, phone numbers, home addresses, and order details. BYOD is a new ransomware-as-a-service operation, and Trump Mobile is only the third organization posted on its data-leak site. According to the group’s posted claim, after telling Trump Mobile that it had been breached, the wireless provider replied: “We have no team to handle this" and “Anyone who hacks them are a terrorist.”"
        https://www.theregister.com/security/2026/10/06/trump-mobile-customers-data-dumped-and-some-never-even-received-their-gold-device/5301433

      General News

      • Hackers Exploit 32 Zero-Days On First Day Of Pwn2Own Ireland
        "On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days. During the Pwn2Own Ireland 2026 hacking contest, competitors target products in seven categories, including mobile phones (Apple iPhone 17, Samsung Galaxy S26, and Google Pixel 10), printers, smart home devices, messaging apps, AI infrastructure, AI coding apps, and a new category where hackers will try to exploit wellness healthcare devices."
        https://www.bleepingcomputer.com/news/security/hackers-exploit-32-zero-days-on-first-day-of-pwn2own-ireland/
      • Engineer Sentenced For Locking Over 3,000 Devices On Employer Network
        "A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer's network in a ransomware-style attack. 57-year-old Daniel Rhyne from Kansas City, Missouri, pleaded guilty to his role in a failed extortion plot targeting the New Jersey company that employed him after being arrested in August 2024 and released after his initial appearance in federal court."
        https://www.bleepingcomputer.com/news/security/engineer-sentenced-for-locking-thousands-of-devices-on-employer-network/
      • Agentic Hacks, Real Proofs: Inside Google's PageBreak Project
        "The application of Large Language Models (LLMs) to security scanning has revolutionized the vulnerability management landscape. But, it has also introduced a significant operational bottleneck: noise. Despite advancements in the models' capabilities to identify vulnerabilities, many security teams are finding themselves overwhelmed as a significant portion of the candidate reports they receive is "AI slop" – noisy, unverified hypotheses or false positives generated by LLMs acting as static code analyzers. Distinguishing a genuine, exploitable flaw from a convincing hallucination has become a major challenge, often increasing the burden on product teams, rather than reducing it."
        https://blog.google/security/agentic-hacks-real-proofs-inside-googles-pagebreak-project/
        https://www.darkreading.com/application-security/google-pagebreak-ai-agent-500-flaws-web-apps
      • U.S. Bank CISO Says The Security Role Keeps Growing And No One Can Own All Of It
        "In this interview with Help Net Security, Ann Barron-DiCamillo, EVP, CISO at U.S. Bank, talks about how the CISO role has grown to cover fraud, resilience, third-party risk, and AI governance. She says no single leader can own all of it, so partnerships across technology, risk, legal, and business teams matter most. Barron-DiCamillo also weighs in on shorter incident reporting deadlines, spending on compliance versus risk reduction, sharing threat intelligence across banks, and what she taught students at American University about cyber risk being a shared responsibility."
        https://www.helpnetsecurity.com/2026/10/06/ann-barron-dicamillo-collective-cyber-defense/
      • Police Urge Passkey Use After Surge In Cybercrime Profits
        "The UK’s Report Fraud service has launched a new public awareness campaign urging internet users to switch to passkeys, after revealing a major increase in sums stolen from victims. The fraud reporting service said that cybercrime linked to email and social media hacking netted scammers £6.3m ($8.3m) in 2025/6, up from £1.2m ($1.6m) the year previously. The number of reports for this type of account takeover increased by a third (34%) over the same period."
        https://www.infosecurity-magazine.com/news/police-urge-passkey-surge/
      • Welcome To The Jungle: What We Found Inside 15,465 Public MCP Servers
        "In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security, traced critical vulnerabilities in Anthropic's MCP source code, downloaded more than 150 million times. This time, we looked at what people actually install: community-published servers across the most popular MCP marketplaces. We found no guardrails and no review. Security is a recommendation, not a policy."
        https://thehackernews.com/2026/10/welcome-to-jungle-what-we-found-inside.html
      • Social Engineering Detection Moves Into The Live Conversation
        "Companies are pouring time and dollars into security awareness training, but there is little empirical evidence to suggest it actually works against social engineering. Social engineering remains a primary and successful attack vector. While system vulnerabilities can be patched, social engineering cannot. The most common pseudo ‘patch’ is user awareness training, but this has failed to block the vector. Human defenders should not and cannot be expected to detect trickery designed to manipulate their psychology. And the tricks are becoming better hidden and more sophisticated with the use of AI deep fakery."
        https://www.securityweek.com/social-engineering-detection-moves-into-the-live-conversation/
      • Guarding The Gates: Assessing Dangerous Permissions Granted To Kubernetes Built-In Principals
        "Kubernetes authorization is a vital but complex part of cluster security, where mistakes can have serious consequences in allowing attackers to establish and expand their access to critical resources. With that in mind we decided to examine how role-based access control (RBAC) is configured in real-world clusters. Specifically, we looked at bindings that can grant some of the built-in principals wide-ranging access to cluster resources. We examined over 65,000 clusters from almost 10,000 organizations to understand what the real-world usage of these principals looked like."
        https://securitylabs.datadoghq.com/articles/kubernetes-rbac-built-in-principals-dangerous-permissions/
      • Beyond Valid Credentials: How Exposed AWS Keys Are Tested For Amazon Bedrock Access
        "Not all credentials are created equal. An attacker who gains access to credentials usually performs validation to determine how useful each set of captured credentials actually is. For years, this has been true for the AWS SES/SNS services. Attackers use API calls like GetSendQuota, GetSMSAttributes, and GetSMSSandboxAccountStatus to assess whether an account is in a production or sandbox environment and then to assess the sending limits attached to that account. The usefulness of the credentials affects their resale value. Attackers use similar tactics when targeting LLM resources in AWS. In this post, we will share LLM-specific validation patterns that we have observed after finding multiple credential harvesting platforms."
        https://securitylabs.datadoghq.com/articles/beyond-valid-credentials-how-exposed-aws-keys-are-tested-for-amazon-bedrock-access/
      • Authenticated Doesn’t Mean Safe: Why AI Agents Need Action-Level Security
        "Consider a support agent handling a routine billing query. It can pull customer records, prepare an account report and email the customer. Then an incoming message tells it to export the full account history and send it to a newly appointed audit contact. The request looks plausible, so the agent complies. Nothing unusual happens at the authentication layer. The credentials are valid. The agent is allowed to read the records and send email. Yet the account history has just gone to someone who was never entitled to receive it."
        https://hackread.com/authenticated-safe-ai-agents-action-level-security/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 62ec7f32-aa21-43c5-9c76-058e856480e5-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบช่องโหว่ใน LibreOffice Calc และ Apache OpenOffice Calc เสี่ยงถูกรันคำสั่งบนเครื่องผู้ใช้

      พบช่องโหว่ใน LibreOffice Calc และ Apache OpenOffice Calc เสี่ยงถูกร.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 19131cc3-48bc-4189-ba00-de23f49167d0-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • IQVIA ถูกปรับ 7.8 ล้านดอลลาร์สหรัฐฯ จากกรณีปกปิดข้อมูลส่วนบุคคลด้านสุขภาพไม่ถูกต้อง

      IQVIA ถูกปรับ 7.8 ล้านดอลลาร์สหรัฐฯ จากกรณีปกปิ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e8aeabcf-e817-4db1-bca4-5c32b2deaf37-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Microsoft ออกอัปเดตความปลอดภัยฉุกเฉินอุดช่องโหว่บน Exchange Server ป้องกันการลักลอบอ่านอีเมลภายในองค์กร

      Microsoft ออกอัปเดตความปลอดภัยฉุกเฉินอุดช่องโห.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 1dfc7c18-84f8-4dd3-9bd4-2e1b3e06189f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบ ClingSTUN ใช้ช่องโหว่กว่า 24 รายการโจมตีอุปกรณ์ Linux ก่อนเปลี่ยนเครื่องที่ถูกบุกรุกเป็น Proxy

      พบ ClingSTUN ใช้ช่องโหว่กว่า 24 รายการโจมตีอุปกรณ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 65658bd0-85d9-4728-acc7-71886b76e9d4-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ผู้ต้องสงสัยสมาชิก ShinyHunters ถูกควบคุมตัวในจอร์แดน คาดให้ความร่วมมือ FBI ติดตามกลุ่ม

      ผู้ต้องสงสัยสมาชิก ShinyHunters ถูกควบคุมตัวในจอร.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 29a262cb-b75d-483a-b70b-5be8eb17f865-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • แรนซัมแวร์ Warlock ยังคงใช้ช่องโหว่เก่าใน SharePoint โจมตีหน่วยงานโครงสร้างพื้นฐานสำคัญทั่วโลก

      แรนซัมแวร์ Warlock ยังคงใช้ช่องโหว่เก่าใน SharePoint .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 09c1e47c-bff6-4594-9961-1255d011702c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT