NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,402
    • กระทู้ 2,403
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 4 รายการลงในแคตตาล็อก

      เมื่อวันที่ 21 กรกฏาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 4 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability
      • CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
      • CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability
      • CVE-2026-60137 WordPress Core SQL Injection Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand a5b71026-0cee-43a3-ba5f-96ab381a8916-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 10 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 10 รายการ เมื่อวันที่ 21 กรกฏาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-202-01 Tycon Systems TPDIN-Monitor-WEB2
      • ICSA-26-202-02 Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
      • ICSA-26-202-03 Siemens Opcenter X
      • ICSA-26-202-04 Siemens SIDIS Secured SmartPlug
      • ICSA-26-202-05 Siemens IAM Client
      • ICSA-26-202-06 Siemens CADRA
      • ICSA-26-202-07 Rockwell Automation FactoryTalk Services Platform
      • ICSA-26-202-08 Rockwell Automation 1718-AENTR/1719-AENTR
      • ICSA-26-202-09 Rockwell Automation 1734 POINT I/O
      • ICSA-26-202-10 Rockwell Automation Studio 5000 Logix Designer

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories 26245063-2214-4993-9369-9423c9b4fd7e-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 22 July 2026

      Industrial Sector

      • Tycon Systems TPDIN-Monitor-WEB2
        "Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-01
      • Siemens Opcenter X
        "Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-03
      • Siemens SIDIS Secured SmartPlug
        "SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-04
      • Siemens CADRA
        "CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-06
      • The Air Gap Is a Myth And Other OT Security Truths
        "Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth. Bachmann covers how containment plans get negotiated before an incident, how to build visibility on old equipment through network monitoring, and how ransomware crews price their demands on downtime. He also questions the idea that people are the weakest link in OT security."
        https://www.helpnetsecurity.com/2026/07/21/benjamin-bachmann-bilfinger-ot-security/
      • Siemens RUGGEDCOM APE1808 With Palo Alto Networks Virtual NGFW
        "Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-02
      • Siemens IAM Client
        "Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-05
      • Rockwell Automation FactoryTalk Services Platform
        "Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-07
      • Rockwell Automation 1718-AENTR/1719-AENTR
        "Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-08
      • Rockwell Automation 1734 POINT I/O
        "Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-09
      • Rockwell Automation Studio 5000 Logix Designer
        "Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-10

      Vulnerabilities

      • Zimbra Update Patches Critical Vulnerabilities
        "Zimbra on Monday announced patches for several critical-severity vulnerabilities, including a command injection bug disclosed in late June. The critical command injection impacts the SNMP monitoring component of the collaboration suite if SNMP notifications are enabled and the integrated Swatchdog service is running. An unauthenticated attacker could send crafted payloads to execute arbitrary OS commands in the background and compromise the email server."
        https://www.securityweek.com/zimbra-update-patches-critical-vulnerabilities/
        https://thehackernews.com/2026/07/zimbra-patches-critical-snmp-command.html
        https://securityaffairs.com/195752/security/zimbra-10-1-20-patches-multiple-security-issues-including-a-critical-command-injection-bug.html
      • Windows LegacyHive Zero-Day Flaw Gets Free, Unofficial Patches
        "Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. The vulnerability (dubbed LegacyHive and without a CVE ID for easy tracking) was found by a security researcher using the "Nightmare Eclipse" handle in the Windows User Profile Service. Nightmare Eclipse disclosed it the day Microsoft released its July 2026 Patch Tuesday updates, together with a stripped proof-of-concept exploit designed to make it harder for threat actors to weaponize this security issue in attacks."
        https://www.bleepingcomputer.com/news/security/windows-legacyhive-zero-day-flaw-gets-free-unofficial-patches/
      • Broken Access Control In Meta.com Customer Support Infrastructure
        "I discovered a critical broken access control vulnerability within Meta’s support infrastructure. What initially appeared to be a product-specific authorization issue ultimately revealed a broader weakness affecting multiple support experiences built on shared backend infrastructure. The vulnerability allowed unauthorized access to sensitive customer support interactions, including Meta.com support emails, support cases, customer support chats, and internal case information. Additionally, certain support workflows could be modified without possessing the intended permissions."
        https://whiteauth.com/2026/07/17/broken-access-control-in-meta-com-support-infrastructure/
        https://www.securityweek.com/meta-pays-78000-bounty-for-vulnerability-exposing-customer-support-data/
      • CISA Adds Four Known Exploited Vulnerabilities To Catalog
        "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability
        CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
        CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability
        CVE-2026-60137 WordPress Core SQL Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog
      • Using LLMs To Find And Prioritize Vulnerabilities Is No Easy Task
        "Current methods of prioritizing vulnerabilities are falling flat, with too many false positives, poor prioritization, and a failure to take into account reachability. So far, large language models (LLMs) have not really helped. In tests of more than a dozen application-scanning tools, more than 60% of flagged vulnerabilities continue to be false positives, are in unreachable code, or are low severity, says Arshan Dabirsiaghi, chief technology officer and co-founder at Pixee, an AI-powered application-security (AppSec) startup. In a presentation at Black Hat USA in August, Dabirsiaghi plans to detail results from those tests and show that the lack of context in stock models means that AI models are not the solution."
        https://www.darkreading.com/application-security/finding-and-prioritizing-vulnerabilities-no-easy-task
      • Apple Fixes Hide My Email Bug That Exposed Real Addresses In Mail Logs
        "Apple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermining the feature's privacy guarantees. 404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, after more than a year, when it was disclosed to the company by Tyler Murphy, co-founder of EasyOptOuts."
        https://thehackernews.com/2026/07/apple-fixes-hide-my-email-bug-that.html
      • When The AI Edits Its Own Trust Boundary: Remote Code Execution Vulnerability In AWS's Agentic IDE
        "AI coding agents are powerful, highly capable, and equipped with risky tools, such as the ability to execute shell commands. Which raises the question, how can we protect our environment from them? The answer is built around a simple safety promise, the risky actions happen only when a human approves them. The user stays in the loop, reviews what the agent wants to do, and clicks “allow.” That approval step is the security boundary. We found a vulnerability in Kiro, AWS’s agentic IDE, that breaks this promise. By planting hidden instructions in a web page Kiro reads, an attacker can make Kiro rewrite its own MCP (Model Context Protocol) server configuration file and gain arbitrary code execution on the developer’s machine. No suspicious approval prompt is ever shown to the user. All the developer asked Kiro to do was perform a legitimate action."
        https://research.intezer.com/blog/2026/07/remote-code-execution-kiro/
        https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html
      • Open-Source Android AI Agents Could Let Invisible Screen Text Run Code On Host PCs
        "An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent. Researchers demonstrated that chain, plus six other attacks, against five open-source mobile agent frameworks: AppAgent, AppAgentX, Mobile-Agent-v3, Open-AutoGLM, and MobA. Everyone fell to at least six of the seven."
        https://thehackernews.com/2026/07/open-source-android-ai-agents-could-let.html
        https://arxiv.org/abs/2607.00333

      Malware

      • Exploitation In The Wild Of Wp2shell
        "Wiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137). Attackers are deploying persistent webshells on vulnerable servers. Organizations should prioritize patching or applying WAF mitigations."
        https://www.wiz.io/blog/wp2shell-cve-2026-63030-cve-2026-60137
        https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html
        https://www.bleepingcomputer.com/news/security/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells/
      • Cookie Crumbles: How Exploitation Of CVE-2026-0257 Leads To Qilin Ransomware
        "During June 2026, Arctic Wolf Labs investigated multiple intrusions during which threat actors exploited CVE-2026-0257 as a consistent initial access vector, rapidly transitioning from perimeter compromise to domain-wide Qilin ransomware encryption across distinct victim environments."
        https://arcticwolf.com/resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/
        https://www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/
        https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html
        https://securityaffairs.com/195730/cyber-crime/qilin-ransomware-affiliates-abuse-cve-2026-0257-to-gain-unauthorized-vpn-access.html
      • Who Needs a Job? DPRK ClickFake Interview Campaign Drops PylangGhost And GolangGhost RATs
        "This article by SOCRadar Threat Research Unit (STRU) analyzes the latest ClickFake Interview campaign, a North Korean social engineering operation that targets cryptocurrency and Web3 professionals with fake job interviews. Operators posing as recruiters walk targets through a bogus skill assessment that ends in a copy-and-paste command, delivering the PylangGhost RAT on Windows and the GolangGhost RAT on macOS. North Korea, officially the Democratic People’s Republic of Korea (DPRK), is well known for their financially motivated cyber operations. To circumvent international sanctions, they persistently attack organizations to steal funds and support the regime’s missile, nuclear, and espionage programs. From historically targeting SWIFT transactions and ATMs, they now focus on stealing crypto assets, with $643M stolen so far this year."
        https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/
        https://www.infosecurity-magazine.com/news/north-korean-clickfake-campaign/
      • New Project CAV3RN Module Abuses Outlook Calendar Events For C2 And DNS AAAA Records For Configuration Recovery
        "In June 2026, as part of our Kaspersky Threat Intelligence Reporting service, we published extensive research on Project CAV3RN, a sophisticated modular framework used for cyberespionage activity against targets in Israel. We have been tracking this cluster since December 2025, and in late April 2026 we observed a major architectural shift: the developers moved from a three-component framework consisting of a downloader, executor, and uploader to a controller-based architecture with a dedicated WebSocket-enabled C2 communication component and a more extensible plugin system designed to support modular post-exploitation capabilities."
        https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/
      • Critical SharePoint RCE Flaw Exploited To Steal Machine Keys
        "Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. An attacker obtaining them can create valid authentication tokens to impersonate users and access available resources such as SharePoint sites and documents with the privileges of the forged identity. Microsoft describes the security issue as a deserialization-of-untrusted-data flaw that allows a remote attacker to execute code over a network without authentication."
        https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/
        https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html
        https://securityaffairs.com/195760/security/public-poc-triggers-active-exploitation-of-critical-sharepoint-rce-vulnerability-cve-2026-50522.html
      • Click To Sync: From Google Ads Maintenance Notice To Credential Theft
        "Threat actors continue to exploit trusted brands to lure users into phishing attacks. Using social engineering techniques that create scenarios that mimic parts of a user’s daily routine, they leverage a sense of urgency and familiarity to manipulate people’s behavior. The Cofense Phishing Defense Center (PDC) has observed a new phishing campaign targeting Google Ads Sync Accounts (MMC), in which attackers send fake system upgrade notifications that urge recipients to synchronize their accounts immediately. Brand impersonation remains one of the most common tactics used to establish trust with victims."
        https://cofense.com/blog/click-to-sync-from-google-ads-maintenance-notice-to-credential-theft
      • From Payroll To Pyongyang: The DPRK IT Worker Money Trail
        "A year ago, DTEX detailed how DPRK IT workers and cyber operators function as a coordinated arm of the regime. A year of open-source and multilateral reporting has since reinforced the model mapped, one built on infiltrating global hiring pipelines and blending of full spectrum cyber operations. New DTEX i³ research, expanded on by reporting through April 2026, picks up where the employment story ends. It follows the money through how payments are reported, who controls the process, and how funds move through internal DPRK channels tied to state activity. At the center of the research is a new interactive map that traces the money through the DPRK system, providing context to where it ultimately leads."
        https://www.dtex.ai/blog/dprk-it-worker-money-trail/
        https://cyberscoop.com/north-korea-it-worker-scheme-funds-russia-war-ukraine/
      • Cato CTRL™ Insights: How One Threat Actor Turned Frontier AI Into An Offensive Platform
        "A Russian-speaking threat actor known as “Trim” has spent the better part of 2026 systematically dismantling the guardrails on publicly available frontier AI models and rebuilding them as offensive tools. What started in March as a knowledge-sharing post on a Russian cybercrime forum detailing how to break Claude Opus into writing malware, had evolved by June into a fully productized, commercially marketed AI-powered penetration testing platform. Trim didn’t need a vulnerability to exploit. He didn’t need to build a novel AI, steal model weights, or compromise a datacenter. He simply picked powerful models off the shelf, figured out how to talk to them in the right way, and turned them into weapons. His story is not just one threat actor’s journey, it is a blueprint that the entire criminal underground is beginning to follow, and in his latest post he shares he is also utilizing a modified system prompt leaked from Fable!"
        https://www.catonetworks.com/blog/cato-ctrl-how-one-threat-actor-turned-frontier-ai-into-an-offensive-platform/
        https://www.darkreading.com/cyber-risk/hacker-ai-jailbreaks-offensive-attack-platform
        https://www.infosecurity-magazine.com/news/trim-jailbroken-claude-ai-pentest/
      • Fake FBI Agents Use IC3 Complaint Scams To Target Fraud Victims
        "The FBI is warning that scammers are impersonating its personnel and offering to help with Internet Crime Complaint Center complaints. Some scammers claim they have recovered stolen money or can help victims retrieve it, but their real aim is to steal information or money from people who have already suffered financial fraud. An updated FBI public service announcement, issued July 20, describes an ongoing scheme involving AI-generated videos, fake social media profiles and websites designed to resemble IC3.gov, the official website for the Internet Crime Complaint Center (IC3)."
        https://hackread.com/fake-fbi-agents-ic3-complaints-scam-victims/
        https://www.ic3.gov/PSA/2026/PSA260720
        https://www.infosecurity-magazine.com/news/fbi-deepfake-videos-ic3/
        https://www.malwarebytes.com/blog/news/2026/07/dont-trust-that-fbi-agent-in-your-dms
        https://www.helpnetsecurity.com/2026/07/21/fbi-ic3-impersonation-scam-warning/
      • A New Extortion Cocktail: Office Printers, Small Ransoms, And BitLocker
        "Recently, our teams in Latin America investigated a series of incidents involving misconfiguration, the deployment of BitLocker, and the exploitation of corporate printers. Attackers used the devices to notify organizations that their infrastructure had been compromised and they had to pay a ransom to recover their data. This article analyzes two incidents that occurred in June in Colombia and in May in Mexico. We highlight the similarities in the attackers’ communications and outline emerging trends in ransom amounts."
        https://securelist.com/new-extortion-scheme-printers-bitlocker/120718/

      Breaches/Hacks/Leaks

      • Clover Health Investments Discloses Data Breach
        "Healthcare technology company Clover Health Investments has disclosed a data breach impacting customers’ personal and health information. Discovered on July 4, the incident was the result of a social engineering attack that compromised three non-managerial health plan employee accounts. Clover Health Investments says it activated its response plan immediately after discovering the attack, and engaged third-party cybersecurity experts to contain and investigate the intrusion."
        https://www.securityweek.com/clover-health-investments-discloses-data-breach/
      • Anubis Ransomware Claims Coca-Cola Fairlife Attack, Threatens Data Leak
        "The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. Fairlife is one of Coca-Cola's dairy brands and produces a range of ultra-filtered milk products, protein shakes, and nutrition drinks sold throughout the United States. The company's product lineup includes Ultra-Filtered Milk, Core Power Protein Shakes, and Nutrition Plan. On July 16, The Coca-Cola Company disclosed that a ransomware attack had disrupted Fairlife's operations, forcing the company to suspend production at its U.S. facilities."
        https://www.bleepingcomputer.com/news/security/anubis-ransomware-claims-coca-cola-fairlife-attack-threatens-data-leak/
      • Kenya Probes Hack Of President's Website After Bitcoin Ransom Demand
        "Kenya is investigating a cyberattack that temporarily defaced the president's official website with an anti-government message demanding a ransom of five bitcoins (about $330,000). The website was hacked on Saturday, when its homepage was replaced with a message displaying a cryptocurrency wallet address and threatening to publish unspecified information about President William Ruto unless the ransom was paid."
        https://therecord.media/kenya-probes-hack-of-presidents-website-after-ransom-demand
      • AI Music Platform Suno Hits Bum Note As 55M Users Exposed In Data Breach, Claims Infosec Expert
        "A data breach at AI music generator platform Suno exposed more than 55 million user accounts, according to Troy Hunt's Have I Been Pwned service, which ingested the files. The dump consisted mostly of email addresses, although phone numbers were also included where users had signed up with them instead, HIBP said. Tens of thousands of Stripe records further revealed data such as names, physical addresses, purchase amounts, as well as partial credit card data, such as card type, expiry date, and the last four digits of the card number."
        https://www.theregister.com/security/2026/07/21/breach-of-ai-music-platform-suno-affected-55m-user-accounts/5275514

      General News

      • Nobody Was Checking The Drives That Encrypt Your Laptop
        "A drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG Opal2 standard. Milan Brož and three colleagues bought 38 of those drives and ran them through a test bench. Brož maintains cryptsetup, the tool that configures disk encryption on most Linux systems. The drives came from Samsung, Western Digital, Micron, Kioxia, and others, a mix of new stock and secondhand units pulled from laptops. The team treated each one as a black box and sent it only the commands the Opal2 documentation defines."
        https://www.helpnetsecurity.com/2026/07/21/hdd-self-encrypting-drive-security/
      • PR3TACK Preemptive Framework Maps Threats Before Attackers Use Them
        "Defensive frameworks in cybersecurity record what attackers have already done. Analysts study a breach, document the method, and build detections around confirmed activity. This cycle leaves a gap between the moment an attacker invents a technique and the moment defenders learn to catch it. PR3TACK, the Preemptive Tactics and Countermeasures Knowledgebase, aims to close that gap. Vishal Thakur of Atlassian built the open framework that catalogs plausible attacker tactics, techniques, and procedures that remain unobserved in the wild."
        https://www.helpnetsecurity.com/2026/07/21/first-pr3tack-preemptive-framework/
      • AI Agents Are Still Logging In As Humans
        "Most large companies run more than one AI platform at the same time. Developers pull up coding assistants, marketing teams lean on writing tools, and analysts query enterprise search across separate vendors. Single-provider setups keep giving way to mixed stacks as companies keep their options open. Sanctioned tools and personal accounts sit side by side inside many organizations. Anonymized sign-on data from more than 20,000 organizations on the Okta tracked this spread from June 2022 through June 2026. Each new tool arrives with its own set of logins and permissions."
        https://www.helpnetsecurity.com/2026/07/21/report-enterprise-ai-identity-risk/
      • Police Dismantle Kratos Phishing Platform, Arrest Developer
        "Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. During the operation, authorities seized more than 200 servers, effectively disrupting the malicious service and rendering it inoperable. The action was led by Frankfurt’s Prosecutor General Office (ZIT), Germany’s Federal police (BKA), which worked in collaboration with U.S. law enforcement agencies."
        https://www.bleepingcomputer.com/news/security/police-dismantle-kratos-phishing-platform-arrest-developer/
        https://www.theregister.com/security/2026/07/21/german-authorities-lead-takedown-of-kratos-phishing-platform/5275666
      • Cheating Behaviour In Frontier Model Evaluations
        "Can you trust an AI model to do what you intended? This is a central question both for those deploying AI systems and for those seeking to evaluate their capabilities. In deployment, a model that pursues a goal through unintended or unauthorised means may cause harm, particularly in high-stakes use cases. In an AI capability evaluation, the same behaviour may undermine the validity of the result: the model may appear to demonstrate a capability by completing a difficult task, when it has instead exploited the task or its environment."
        https://www.aisi.gov.uk/blog/cheating-behaviour-in-frontier-model-evaluations
        https://cyberscoop.com/ai-models-cheat-deceive-users-aisi-report/
      • 2026 Ransomware Report
        "Black Kite tracked 7,551 publicly disclosed ransomware victims between April 2025 and March 2026. That's a 24.9% increase over the previous reporting period, and the fourth straight year that ransomware disclosures have set a new high. The threat actor ecosystem grew right alongside the victim count, reaching 127 active groups by the close of the period and 146 by June 2026. This report analyzes those 7,551 victims by geography, industry, and revenue band, then goes further. It pairs victim data with Black Kite's own security posture signals, captured before disclosure and rechecked after, to show what ransomware groups could already see and what stayed visible once the incident closed. It also maps five distinct actor models operating inside the same 12 months, tracks how trusted vendor platforms became attack paths, and measures where AI is already lowering the cost of running a ransomware operation."
        https://blackkite.com/reports/2026-ransomware-report
        https://www.darkreading.com/cyberattacks-data-breaches/ransomware-is-accelerating-not-ai
        https://www.infosecurity-magazine.com/news/new-ransomware-weekly/
      • Choose Wisely: AI-Generated Coding Risk Varies, a Lot
        "There may not be a clear winner in terms of which AI model is the best or worst for coding, but there are better (and far worse) models for organizations depending on the development environment or framework one codes in. Software governance firm Secure Code Warrior today unveiled its AI Trust Index, a body of data attempting to quantify the risk established via large language model (LLM)-powered coding tools. AI-assisted development has become exceedingly popular at the organizational level, using tools to generate code, test for vulnerabilities, and audit for general integrity. It is by no means a secret that these tools are expensive, while introducing both vulnerabilities and risk, no matter the efficiency gains."
        https://www.darkreading.com/application-security/choose-wisely-ai-generated-coding-risk-varies
      • CISO Conversations: Andreas Gaetje – From Economics To CISO At Körber AG
        "Korber AG is the holding company of a diverse German technology and manufacturing organization with around 13,000 employees in 100 locations around the world. “Take Pharma,” comments Andreas Gaetje. “Probably every vaccine you ever received has been through our machines.” Korber services companies that supply consumers. So, despite its size and importance, it is rarely known to or recognized by the eventual consumer. Gaetje is the CISO at Korber AG."
        https://www.securityweek.com/ciso-conversations-andreas-gaetje-from-economics-to-ciso-at-korber-ag/
      • Understanding Illicit Ecosystems: Inside Rehub’s Rise As a Primary Ransomware Marketplace
        "Rehub, also known as ReHub or RehubCom, is a Russian-language cybercrime forum founded in August 2025 by a former XSS moderator following its shutdown in the summer of 2025. Rehub dedicates itself to the commercial and marketplace use of ransomware, while its counterpart, DamageLib, serves as a knowledge base archive and exchange. Operating both on Clear Web domains and an onion domain, the forum positions itself as free from state and law enforcement interference, framing existing XSS iterations as compromised. After law enforcement seized the RAMP (RAMP4U) forum in January 2026, Rehub absorbed a significant portion of the displaced cybercriminal community and became one of the primary destinations for ransomware operators."
        https://flashpoint.io/blog/understanding-illicit-ecosystems-inside-rehub-ransomware-marketplace/
      • Volume Is Not Risk: Making Sense Of The “Vulnpocalypse”
        "Around 66,000 common vulnerabilities and exposures (CVEs) are projected to be disclosed this 2026, according to the FIRST 2026 Mid-Year Vulnerability Forecast. Vulnerability researcher Jerry Gamblin revealed that disclosures in the first half of the year ran nearly 50% ahead of the same window in 2025, which itself finished at a record 48,185 CVEs. His analysis draws on National Vulnerability Database (NVD) and CVE Program data. The steep climb from the roughly 40,000 CVEs recorded in 2024 might make the “vulnpocalypse” panic justified."
        https://www.trendmicro.com/en_us/research/26/g/making-sense-of-the-vulnpocalypse.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 4c091242-b697-4b6d-80b3-41afeabe53d4-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Microsoft ออกอัปเดตนอกกำหนดการ แก้ปัญหา Dell บางรุ่นปิดตัวลงเอง

      Microsoft ออกอัปเดตนอกกำหนดการ แก้ปัญหา Dell บางรุ่.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 04fb66d5-69d9-4a83-9e1d-d50fc96a3076-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Estée Lauder แจ้งเหตุข้อมูลรั่วไหล หลังระบบ Oracle E-Business Suite ถูกใช้โจมตี

      Estée Lauder แจ้งเหตุข้อมูลรั่วไหล หลังระบบ Oracle E-Busines.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 238dd9ab-dfbf-4277-9400-dfbd8bb0563c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • เตือนภัยมัลแวร์ HollowGraph ใช้ปฏิทินบน Microsoft 365 เป็นช่องทางลับสั่งการและขโมยข้อมูล

      เตือนภัยมัลแวร์ HollowGraph ใช้ปฏิทินบน Microsoft 365 เป็น.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 0b97e94a-d471-4b5f-b7fb-3b67ba80c091-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Chrome ออกแพตช์แก้ช่องโหว่ Memory Safety ระดับ Critical หลายรายการ

      Chrome ออกแพตช์แก้ช่องโหว่ Memory Safety ระดับ Critical หลายร.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5d364bb0-51ef-4c76-a799-04284c9bf231-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ServiceNow เตือนช่องโหว่ RCE ร้ายแรงใน AI Platform เริ่มถูกใช้โจมตีจริง

      ServiceNow เตือนช่องโหว่ RCE ร้ายแรงใน AI Platform เริ่มถูก.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand dd4f85cf-8782-47d3-83b7-9f4949e43973-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Hugging Face แพลตฟอร์ม AI โอเพนซอร์สรายใหญ่ ถูกแฮกโดย AI Agent อัตโนมัติ

      Hugging Face แพลตฟอร์ม AI โอเพนซอร์สรายใหญ่ ถูกแฮกโ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e8ae87cc-a500-4b3b-b1c5-fb76cbd75780-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 3 รายการลงในแคตตาล็อก

      เมื่อวันที่ 16 กรกฏาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 3 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability
      • CVE-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability
      • CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 3ffcca6b-402c-4f41-a413-00e1ef08d68f-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 2 รายการลงในแคตตาล็อก

      เมื่อวันที่ 15 กรกฏาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 2 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
      • CVE-2026-46817 Oracle E-Business Suite Improper Privilege Management Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 97ca5939-1a95-4160-98d6-65226ade5e52-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 9 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 9 รายการ เมื่อวันที่ 16 กรกฏาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-197-01 Rockwell Automation Arena
      • ICSA-26-197-02 Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
      • ICSA-26-197-03 NASA Core Flight System (cFS) Health & Safety (HS) Application
      • ICSA-26-197-04 AutomationDirect Productivity Suite
      • ICSA 26-197-05 Siemens SICAM 8
      • ICSA-26-197-06 Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix
      • ICSA-26-197-07 SALTO ProAccess Space
      • ICSA-26-197-08 Rockwell Automation Flex 5000 Adapter
      • ICSA-26-197-09 Rockwell Automation FactoryTalk DataMosaix

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories 851544c1-dbd0-4eed-afe1-51f6a7193cdf-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 21 July 2026

      New Tooling

      • New Index Tracks Material Breaches — And Refuses To Add Up The Losses
        "A longtime cybersecurity executive has built a website that tracks disclosed material breaches, aiming to give cybersecurity professionals, journalists, policymakers, and everyday citizens a resource that doesn’t currently exist. The tracker was created by Richard Bird, who is currently Chief Strategy and Chief Security Officer at enterprise AI governance company Singulr AI. He previously held leadership roles at JPMorgan Chase and several cybersecurity companies."
        https://www.securityweek.com/new-index-tracks-material-breaches-and-refuses-to-add-up-the-losses/
      • Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
        "Financial services giant Capital One has released an internally developed AI-powered security tool to the public as open source. Dubbed “VulnHunter”, the tool was designed to find and fix software vulnerabilities at the code level, but Capital One says it is not a traditional, passive vulnerability scanner. “We designed VulnHunter with a developer-first mindset to solve a massive industry pain point: overwhelming false positives that create friction and slow down daily workflows,” Chris Nims, EVP & Chief Information Security Officer (CISO) at Capital One, explained in a LinkedIn post."
        https://www.securityweek.com/capital-one-open-sources-ai-powered-vulnhunter-security-tool/
        https://github.com/capitalone/vulnhunter

      Vulnerabilities

      • Chrome 150 Update Patches Severe Memory Safety Bugs
        "Google has released a Chrome 150 security update that resolves seven memory safety bugs, including critical and high-severity use-after-free vulnerabilities. The browser refresh patches three critical-severity use-after-free flaws impacting Chrome’s CameraCapture, GPU, and Network components. All three weaknesses were discovered by Google. Additionally, the update fixes three high-severity use-after-free issues in Cast, Ozone, and Aura; Google discovered these vulnerabilities as well."
        https://www.securityweek.com/chrome-150-update-patches-severe-memory-safety-bugs/
      • The Week Of Sandbox Escapes
        "Over several months, Pillar Research found and reproduced sandbox escapes and boundary bypasses across Cursor, Codex, Gemini CLI, and Antigravity. In almost every case, the agent did not need to break the sandbox directly. It only had to write something that a trusted component outside the sandbox would later run, load, scan, or treat as safe. In aggregate, these vulnerabilities show that AI coding agents change the endpoint threat model, and that most sandbox designs have not caught up."
        https://www.pillar.security/blog/the-week-of-sandbox-escapes
        https://www.bleepingcomputer.com/news/security/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/
      • Malicious Cloud Customers Can Bring Down The Power Grid
        "AI datacenters wreak havoc on the power grid under normal circumstances, so what happens if a bad actor controls all the GPUs and wants to cause harm? Cybersecurity researchers in China have devised a way for malicious tenants to attack their infrastructure provider, potentially causing blackouts or damaging equipment. The attack, dubbed Bit2Watt, imagines an adversary masquerading as a legitimate cloud tenant to launch GPU workloads that have the potential to damage datacenters and supporting electrical systems. It's intended to demonstrate the need to extend cybersecurity defenses to datacenter workload scheduling."
        https://www.theregister.com/ai-and-ml/2026/07/20/malicious-cloud-customers-can-bring-down-the-power-grid/5275193
        https://arxiv.org/abs/2607.05993

      Malware

      • Critical ServiceNow Code Execution Flaw Now Exploited In Attacks
        "Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows. Cybersecurity company Searchlight Cyber, which found this critical vulnerability and reported it on April 1st, says that it allows unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow platform in high-complexity attacks."
        https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/
        https://www.helpnetsecurity.com/2026/07/20/servicenow-cve-2026-6875-exploited/
      • HOLLOWGRAPH: Turning Microsoft 365 Calendars Into Covert Command-And-Control Channels
        "The Group-IB Threat Intelligence team has identified HOLLOWGRAPH, a new malware sample that we attribute, with high confidence, to the Cavern backdoor framework. This malware is one component of a larger toolkit, and it uses the Microsoft Graph API through a compromised Microsoft 365 account observed in Israel to communicate with its operators — a technique that helps conceal command-and-control traffic within legitimate Microsoft 365 communications. The malware supports just two commands, get and send, and executes both exclusively through trusted Microsoft cloud infrastructure. Using the Microsoft Graph API, it treats the compromised mailbox’s calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached. To avoid catching the mailbox owner’s attention, every event is dated far into the future — 13 May 2050 — with payloads attached as files to the event."
        https://www.group-ib.com/blog/hollowgraph-microsoft-365/
        https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html
        https://www.bleepingcomputer.com/news/security/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms/
        https://www.infosecurity-magazine.com/news/hollowgraph-microsoft-calendars/
        https://www.theregister.com/security/2026/07/20/microsoft-365-calendars-become-spy-drop-boxes-in-hollowgraph-campaign/5274982
        https://www.helpnetsecurity.com/2026/07/20/hollowgraph-malware-microsoft-365-calendar/
      • Fake Games Spread Stealers With RenPy Loader, MSBuild And EtherHiding
        "We have detected several campaigns using fake downloads of games, mods, cracks, and software to spread RenPy Loader. Once installed, the loader starts a complex, multi-stage infection chain that abuses MSBuild and the EtherHiding technique before ultimately delivering Amatera Stealer. Amatera is an infostealer—a type of malware designed to steal sensitive information from an infected device. It can target passwords and other data stored in browsers, cryptocurrency wallets, browser extensions, messaging apps, and local files. Stolen credentials and session data may also allow attackers to access the victim’s online accounts."
        https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding
      • Unpacking “Cruciferra”: An Analysis Of a Sophisticated Crypter Service
        "Proofpoint researchers are tracking Cruciferra, a crypter service that is used by multiple unrelated threat actors. Crypters are commonly used within the cybercriminal ecosystem to conceal malicious payloads, evade security controls, and improve malware delivery success rates. During our analysis, Proofpoint researchers identified both production and apparent testing samples, including variants containing debugging functionality and experimental features. Cruciferra is written in Mono and features numerous techniques designed to evade detection, analysis, and incident response efforts."
        https://www.proofpoint.com/us/blog/threat-insight/unpacking-cruciferra-analysis-sophisticated-crypter-service
        https://www.infosecurity-magazine.com/news/cruciferra-crypter-process-ghosting/
      • SleeperGem: Compromised Git_credential_manager, Dendreo, And Fastlane RubyGems Drop a Persistent Backdoor
        "Between July 18 and July 19, 2026, malicious versions of three RubyGems packages were published to RubyGems.org in a coordinated supply chain attack that researchers named SleeperGem. The compromised gems are git_credential_manager, which impersonates the official Microsoft Git Credential Manager, along with Dendreo and fastlane-plugin-run_tests_firebase_testlab. Each malicious release is a loader. It fetches a second stage from an attacker controlled Forgejo host, checks whether it is running in a build system and skips if it is, and on a developer machine it drops a native daemon and installs persistence."
        https://www.stepsecurity.io/blog/sleepergem-compromised-rubygems-drop-persistent-backdoor
        https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html
      • JADEPUFFER Evolves: The Agentic Threat Actor Deploys Ransomware Built To Destroy AI Models
        "Ransomware operators make a bet that their victims don’t keep backups. In a new development, the operator behind JADEPUFFER has doubled down on that bet, using ransomware to destroy the one thing an organization can’t simply restore: a trained AI model. For organizations, training a single model can cost upwards of $500,000 in compute and engineering alone. On July 1, 2026, the Sysdig Threat Research Team (TRT) documented JADEPUFFER: an agentic threat actor (ATA) that exploited Langflow through CVE-2025-3248."
        https://www.sysdig.com/blog/jadepuffer-evolves-the-agentic-threat-actor-deploys-ransomware-built-to-destroy-ai-models
        https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-attacks-now-target-ai-model-data-with-ransomware/
        https://www.infosecurity-magazine.com/news/jadepuffer-ai-model-ransomware/
      • LG Monitors Silently Install Software Through Windows Update Without User Consent
        "Connecting some LG monitors to a Windows PC may automatically install software that promotes McAfee subscriptions. Gamers Nexus reproduced the behavior with an LG UltraGear 34GX900A-B after receiving reports from monitor owners."
        https://videocardz.com/newz/lg-monitors-silently-install-software-through-windows-update-without-user-consent
        https://hackread.com/lg-monitors-install-adware-app-windows-pcs/
      • The Odyssey Piracy Scams Appear Within Hours Of The Movie’s Release
        "Christopher Nolan’s The Odyssey is one of the biggest movie releases of the year and scammers wasted no time taking advantage of it. Within hours of the film’s release, we found scams targeting people looking for pirated copies. Some used fake browser warnings on piracy sites, while others disguised malware as movie downloads. Some used fake browser error messages designed to funnel people through malvertising networks. Others offered what appeared to be movie downloads that were actually Windows executables disguised as video files."
        https://www.malwarebytes.com/blog/threat-intel/2026/07/the-odyssey-piracy-scams-appear-within-hours-of-the-movies-release
        https://www.helpnetsecurity.com/2026/07/20/odyssey-movie-piracy-scams-malware/
      • Targeted Attack On Government Entities In The Middle East | Part 1
        "In July 2026, Zscaler ThreatLabz observed new activity by a threat actor with links to East Asia targeting government entities in the Middle East. During analysis, ThreatLabz captured post-compromise activity and uncovered previously undocumented malware tooling, including TELESHIM, MIXEDKEY, and BINDCLOAK. The campaign used a multi-stage attack chain to establish and maintain access on infected systems, with TELESHIM abusing the Telegram API for command-and-control (C2) communication to blend in with legitimate internet traffic."
        https://www.zscaler.com/blogs/security-research/targeted-attack-government-entities-middle-east-part-1
      • AgentBaiting: How 800+ Fake AI Skills And MCP Servers Delivered Malware
        "Island security research uncovered about 7,600 malicious GitHub repositories, with more than 800 of them posing as AI Skills or MCP servers in a wave that peaked in April 2026. Those AI capability repositories appeared more than 600 times across public AI registries and catalogs, while the wider FakeGit operation recorded more than 14 million measured downloads. FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP files to deliver SmartLoader malware. Once executed, SmartLoader establishes persistence and installs StealC, an information stealer targeting credentials, active sessions, and other sensitive data."
        https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware
        https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html
      • From a Single Alert To 1,000 Files: Inside An Exposed WebDAV Malware Delivery Lab
        "An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery paths, social engineering lures, and WebDAV execution methods. Our analysis reveals an interesting shift in adversary operations: attackers are adopting generative AI to move beyond individual exploits and operate like modern software product teams. By leveraging LLMs for rapid lure generation, detailed README documentation, and automated testing, they are significantly accelerating their development cycle."
        https://www.rapid7.com/blog/post/tr-exposed-webdav-malware-delivery-lab-analysis/
        https://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.html
      • Russian Intelligence Hacks IP Cameras To Spy On Military Logistics Across NATO States And Ukraine
        "At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands' civilian and military intelligence services, which describe the operation as ongoing."
        https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html
        https://english.aivd.nl/documents/2026/07/10/brochure-cybersecurity-advisory-russian-state-actors-are-compromising-ip-cameras
        https://securityaffairs.com/195708/intelligence/dutch-intelligence-warns-russia-uses-hacked-ip-cameras-for-military-espionage.html

      Breaches/Hacks/Leaks

      • Software Provider To More Than 2,000 US Hospitals Says Hackers Stole Employee And Customer Data
        "A British company whose software is used by thousands of U.S. hospitals said Monday that hackers broke into its internal network and stole data on employees, customers and business partners. Craneware, which is headquartered in Edinburgh and listed on London's AIM market, told investors it detected unauthorized access to a “subset” of its data environment and has since brought in outside forensic investigators. The company said it has reported the incident to the FBI and to Britain’s Information Commissioner’s Office."
        https://therecord.media/software-provider-for-us-hospitals-customer-data-breach
      • Estée Lauder Discloses Data Breach Via Oracle E-Business Flaw
        "Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. The company says that last month it identified an intrusion that had occurred on August 9, 2025, which led to the threat actor obtaining " personal information of certain individuals." “We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes,” the notification says."
        https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
      • Hackers Steal $23.7 Million In Crypto From Ostium In Off-Chain Attack
        "The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. According to an update from the platform yesterday, the attacker submitted illegitimate price reports disguised as valid ones, then rapidly opened and closed large positions to generate artificial profits. Trader collateral was held in a separate contract and was not affected, while existing positions remain open, the company clarified."
        https://www.bleepingcomputer.com/news/security/hackers-steal-237-million-in-crypto-from-ostium-in-off-chain-attack/
      • Paidwork Breach Exposes Sensitive Data Of 23 Million User
        "Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets itself as a way to earn money through simple tasks like watching ads, testing apps, and completing surveys, with most jobs paying only a few cents at a time. For its users, many of whom are drawn to the platform for small, incremental earnings, the fallout from this breach could end up costing far more than they ever made."
        https://www.helpnetsecurity.com/2026/07/20/paidwork-data-breach-23-million-users/
      • India Says Allegedly Leaked Nuclear Plant Files Pose No Safety Risk
        "India's state-owned nuclear operator said that documents recently posted online and purportedly linked to the country's largest nuclear power plant contain no information affecting safety or security. The statement came after the media reported last week that the cybercrime group World Leaks had published thousands of files apparently connected to the Kudankulam Nuclear Power Plant (KKNPP)."
        https://therecord.media/india-nuclear-plant-kudankulam-world-leaks-documents
      • Hackers Were Inside South Korea's Diplomat Training System For 9 Months
        "Unidentified hackers compromised an online education system used by South Korea's diplomatic academy, stealing personal information belonging to former and current employees of the country's Ministry of Foreign Affairs, the department announced Monday. In a data protection notice, the MoFA said the breach of the Korea National Diplomatic Academy's e-learning platform occurred from April 2025 to February 2026, when a related government authority notified the ministry of abnormal access to the system."
        https://therecord.media/south-korea-cyberattack-foreign-ministry

      General News

      • A Forensic Tool For Backdoored Code Completions In AI Assistants
        "Developers lean on AI coding assistants for a growing share of their daily work, letting the tools predict the next few lines and accepting many suggestions with a quick glance. Those tools learn from large collections of code, and some of that code can be tampered with before training starts. A poisoned example teaches a model to write insecure code when it sees a certain cue, and the flaw sits quietly until the right prompt sets it off. Most defenses aim to catch this poisoning early, screening training data or scanning outputs for known problems. A team from the University of Louisville and the University of North Texas built a system called CodeTracer for the moment after those defenses let something slip. Their work starts from a model that has already produced a harmful completion. The job is to trace that completion back to the training examples that taught the behavior."
        https://www.helpnetsecurity.com/2026/07/20/tracing-backdoored-code-completions/
        https://arxiv.org/pdf/2607.08011
      • Nearly Half Of Open-Source AI Projects Never Reach Production
        "Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles as model capability improves. “Without investment in the infrastructure, tooling, and governance around open models, we risk locking in a system where only restrictive, closed AI can scale – and that doesn’t serve the public interest, or sovereignty over tech policy decisions,” said Raffi Krikorian, Mozilla’s Chief Technology Officer."
        https://www.helpnetsecurity.com/2026/07/20/mozilla-open-source-ai-adoption-report/
      • Why Blocking AI Models Won’t Stop The Cyber Threats They Create
        "2026 has turned out to be the year when predictions about AI-powered cyberattacks, long hypothesized as a potential risk associated with AI improvement, seem to be coming true. New models have capabilities on par with the best human hackers, marking a pivotal window of opportunity in both AI and cybersecurity policy. This is a transitional period where new technologies are pushing existing American cybersecurity infrastructure to the brink. The real question isn’t whether cybersecurity still matters, but rather: How will the risks that AI introduces be managed before they outpace defenses, and who will step up to lead this challenge?"
        https://cyberscoop.com/why-blocking-ai-models-wont-stop-cyber-threats-op-ed/
      • Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push
        "Amid growing concern about threats actors using artificial intelligence for cyberattacks, one software vendor is finding success with deploying large-language models (LLMs) for vulnerability remediation. Last month, Ivanti disclosed CVE-2026-10520, a critical maximum-severity flaw in its Sentry mobile gateway product. But the vulnerability, which received a 10 out of 10 CVSS score, wasn't discovered by a security researcher, a third-party vendor, or even Ivanti's own engineers; rather, an LLM was the finder."
        https://www.darkreading.com/cybersecurity-operations/remediating-vulnerabilities-llms-ivanti-automation
      • CISOs Pressured To Stay Silent About Cyber Attacks Need Evidence-Led Governance For Protection
        "CISOs are facing growing pressure to stay quiet about cyber incidents despite stricter regulatory demands for transparency. That’s one of the findings from Splunk’s 2026 CISO report, which shows that one in five security leaders have been pressured by their organization not to report incidents or compliance issues. The situation is proving to be so problematic that almost eight in ten (78%) are now concerned about their own liability for security incidents, a sharp spike compared to last year (56%)."
        https://www.techradar.com/pro/cisos-pressured-to-stay-silent-about-cyber-attacks-need-evidence-led-governance-for-protection
        https://www.darkreading.com/cybersecurity-operations/cisos-feel-heat-ai-risk
      • Cybersecurity Keeps Events 'Uneventful'
        "The threats surrounding major events often begin long before anyone reaches the gate. A compromised hotel system can reveal where athletes, executives, or delegations are staying. A breach involving government or ministry offices can expose schedules and movements. Threats aimed at fan events, themed gatherings, or transit hubs can target the outer ring of security, where crowds are harder to control and attackers may see more opportunity."
        https://www.darkreading.com/cyber-risk/cybersecurity-keeps-events-uneventful
      • Demystifying AI Exploits: A Blueprint For AI-Assisted Vulnerability Management
        "As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration and continuous delivery (CI/CD) pipelines for automated vulnerability discovery and remediation. However, deploying privileged artificial intelligence (AI) agents without mature integration processes introduces new architectural risks."
        https://cloud.google.com/blog/topics/threat-intelligence/ai-assisted-vulnerability-management

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) a97e8594-0635-4d8e-bf66-5843432ff27e-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Microsoft เตือนการโจมตีด้วย ACR Stealer เพิ่มสูงขึ้น มุ่งขโมยรหัสผ่านและข้อมูลสำคัญ

      Microsoft เตือนการโจมตีด้วย ACR Stealer เพิ่มสูงขึ้น มุ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 1ab85a7a-6637-4f09-8a22-5b931c9db5f2-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Ernst & Young แจ้งเหตุข้อมูลรั่วไหล หลังระบบ Support Ticket ภายนอกถูกโจมตี

      Ernst _ Young แจ้งเหตุข้อมูลรั่วไหล หลังระบบ Support Ticket .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand a1c65952-8423-4e01-9cdb-95abbe0dd37d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • กลุ่มแฮกเกอร์ UAC-0145 ใช้เทคนิค ClickFix และแอปพลิเคชันปลอมโจมตีผู้ใช้งานในยูเครน

      กลุ่มแฮกเกอร์ UAC-0145 ใช้เทคนิค ClickFix และแอปพลิเค.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand c1b7b520-6b2a-436f-b556-7c30f42db32b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 20 July 2026

      Industrial Sector

      • Three Steps To The Terminal: A Siemens ROX II Zero-Day Trilogy
        "We conducted this research in close partnership with Siemens, reflecting our shared commitment to advancing the security and resilience of critical infrastructure. This report details a critical, chained exploit comprising three zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949) discovered in Siemens ROX II operational technology (OT) switches. Successful exploitation of this chain would allow an attacker to achieve full privilege escalation and persistent root-level access on these devices, which are critical components of industrial control networks. The vulnerabilities range from Medium to Critical severity, with CVSS 3.1 scores of 6.8 (CVE-2025-40948), 7.5 (CVE-2025-40947), and 9.1 (CVE-2025-40949)."
        https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/

      Vulnerabilities

      • OpenSSL HollowByte: A DoS Hiding In 11 Bytes
        "Every so often, a vulnerability reminds us how deeply our digital infrastructure relies on foundational libraries. Recently, the Okta Red Team discovered HollowByte, a Denial of Service (DoS) vulnerability in OpenSSL. By sending a malicious payload of just 11 bytes, a remote, unauthenticated attacker can force a server to allocate disproportionate chunks of memory before any security handshake even begins. Here is the breakdown of how it works."
        https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/
        https://www.bleepingcomputer.com/news/security/hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-byte-payload/
        https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html
        https://securityaffairs.com/195588/hacking/openssl-fixes-hollowbyte-memory-exhaustion-bug.html
      • Wp2shell: Pre Authentication RCE In WordPress Core
        "Searchlight Cyber’s security research team has discovered a pre-authentication RCE in WordPress Core. The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins. It is estimated that over 500 million websites use WordPress. Given the severity of the bug and to give defenders time to patch, we are not releasing technical details at this time. We are, however, releasing a website to determine if your instance is vulnerable. You can find it here: https://wp2shell.com/"
        https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core
        https://wp2shell.com/
        https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
        https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/
        https://securityaffairs.com/195597/hacking/attackers-can-take-over-wordpress-sites-using-newly-released-wp2shell-exploits.html
        https://www.helpnetsecurity.com/2026/07/18/wordpress-vulnerabilities-wp2shell-cve-2026-60137-cve-2026-60137/

      Malware

      • Proxying To Compromise: SonicWall Secure Mobile Access 0-Day Exploitation
        "In early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised SonicWall Secure Mobile Access (SMA) VPN appliances through a chain of multiple zero-day exploits in the devices. The initial compromise was discovered after suspect authentication and lateral movement attempts were observed from the SonicWall SMA appliances. Following public disclosure by SonicWall on July 14, 2026, Volexity is now able to share details on the exploits used, when they were used, and what the threat actor did with their access."
        https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/
        https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html

      • None And Done? Kittykatkrew’s Short-Lived Ransomware Play
        "kittykatkrew is a financially motivated ransomware and data-extortion threat actor that announced its operation on February 22, 2026. In the roughly two months that followed, the group claimed two victims on its leak site, appeared to release a stolen law-enforcement dataset, and then went quiet. No confirmed ransom payment, no verified breach and no further activity as of mid-2026. The data leak site was offline as of April 9, 2026."
        https://blog.barracuda.com/2026/07/16/none-and-done-kitty-kat-krew-ransomware-group

      • Sequel To ChainVeil Npm Malware Targets Vite Ecosystem
        "When we published our ChainVeil report in June 2026, we noted something that didn’t fit: the SuccessKey campaign’s Command and Control (Command and Control (C2)) infrastructure contained a secondary server at 198.105.127[.]210 and a tertiary server at 23.27.202[.]27 that no known ChainVeil package ever called home to. We predicted additional campaigns were already running on the same backend. We were right."
        https://checkmarx.com/zero-post/sequel-to-chainveil-npm-malware-targets-vite-ecosystem/
        https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html

      • NadMesh Botnet Analysis: A Product-Grade Threat For The AI Service Era
        "In early July 2026 we observed a Go-based botnet pushing bot samples onto the internet at scale. It folds scanning, exploitation, and credential/AI-service intelligence harvesting into a single autonomous platform. Because its controller calls itself n4d mesh controller in the source, we named it NadMesh. NadMesh is not a one-off worm outbreak. It is a continuously iterated, autonomous botnet aimed squarely at AI infrastructure and the MCP ecosystem. What sets it apart from traditional worms:"
        https://blog.xlab.qianxin.com/nadmesh-botnet-analysis-a-product-grade-threat-for-the-ai-service-era-en/
        https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html

      • Introducing CylindricalCanine: The GoldenEyeDog Subgroup Responsible For The April DigiCert Incident
        "In this blog, we review the behavior and capabilities of a malware we call Golden Gh0st Loader and Golden Gh0st RAT. We believe these malware are used exclusively by a sub-group dubbed “GoldenEyeDog”, a Chinese cybercrime group. In April 2026, the actors behind the malware were able to gain access to DigiCert to intercept code-signing certificates intended for DigiCert customers, and then used the certificates to sign their own malware. This piqued our interest in the malware, leading us to use DeceptionPro to monitor the malware over days in a controlled enterprise environment—and create a tool to decrypt the malware’s network communications."
        https://expel.com/blog/introducing-cylindricalcanine/
        https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html

      • New North Korean Campaign Uses Fake Coding Interviews To Steal Developer Credentials
        "Elastic Security Labs found a new Contagious Interview campaign, tracked as REF9403, hiding malware inside SVG image files using steganography. To our knowledge, this specific infection chain has not been previously documented. We found it after the DPRK-aligned group targeted our own community Slack workspace with a fake job posting and a "coding challenge" project. Any user who ran the project ended up with a four-stage payload aligned with OTTERCOOKIE: a browser credential and crypto wallet stealer, a file stealer, a Socket.IO-based remote access trojan (RAT), and a clipboard stealer."
        https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography
        https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html

      • ACR Stealer: Two Observed Intrusion Chains Amid Increased Threat Activity
        "From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments. Successful compromise can expose browser credentials, session tokens, authentication artifacts, and sensitive enterprise data, potentially enabling account compromise, unauthorized access to cloud resources, and follow-on intrusion activity. Security teams should prioritize monitoring for ClickFix lures, suspicious WebDAV activity, obfuscated PowerShell execution, and attempts to access browser credential stores."
        https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/
        https://thehackernews.com/2026/07/acr-stealer-uses-clickfix-lures-to.html
        https://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/

      • Inside Qilin Ransomware: Custom Rust Loader And Kernel-Level EDR Killer
        "In this post we analyze Qilin ransomware’s new custom Rust loader, break down the inner workings of its sophisticated kernel-level EDR killer, and explore how organizations can defend against these aggressive defense evasion tactics. Flashpoint customers can access the full intelligence report—complete with deeper technical analysis and all associated IOCs—directly within Flashpoint Ignite."
        https://flashpoint.io/blog/inside-qilin-ransomware/

      • **Breaches/Hacks/Leaks

      • Abbott Probes Two Cyber Incidents Amid Extortion Claims**
        "Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data. The company confirmed the Cancer Diagnostics incident after the ShinyHunters extortion gang added Abbott to its data leak site, initially threatening to publish allegedly stolen data after July 18 unless the company negotiated with the group, before later extending the deadline to July 21."
        https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/

      • Ernst & Young Discloses Data Breach After Support System Hack
        "Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. According to the company, support tickets submitted through the platform may have included documents containing client tax information. Ernst & Young (EY) is among the world’s four largest auditing and professional services providers, offering auditing, tax, consulting, and transaction advisory services to major organizations in more than 150 countries."
        https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/
        https://securityaffairs.com/195550/data-breach/ernst-young-ey-investigates-data-breach-involving-third-party-support-tickets.html

      • Hugging Face Discloses AI-Agent-Driven Breach Of Internal Clusters
        "The interesting part of Hugging Face's security incident write-up, published July 16, is not that a dataset hub got popped, but how. The company says the intrusion was "driven, end to end, by an autonomous AI agent system." A malicious dataset abused two code-execution paths in Hugging Face's dataset processing, a remote-code loader and template injection in dataset configuration, to run on a processing worker. From there the agent escalated to node access, harvested cloud and cluster credentials, and moved laterally into several internal clusters over a weekend, generating what the disclosure calls "many thousands of individual actions across a swarm of short-lived sandboxes.""
        https://aiweekly.co/alerts/hugging-face-discloses-ai-agent-driven-breach-of-internal-clusters
        https://huggingface.co/blog/security-incident-july-2026

      General News

      • Two Key Members Of Chinese Money Laundering Network Charged With Laundering $43 Million In Investment Fraud Proceeds
        "A New York man and woman made an initial appearance today in Brooklyn, New York on charges of conspiracy to launder money derived from cyber investment fraud scams. According to the indictment unsealed today, between 2020 and 2022, Zhuoying Chen, 27, of Brooklyn, New York and Haojie Zhang, 38, of Queens, New York managed a network of more than a dozen individuals based in Queens and Brooklyn, who opened 140 bank accounts in the name of approximately 45 shell companies to launder at least $43 million in proceeds of investment scams. Then, Chen and Zhang allegedly conspired with China-based co-conspirators to transfer the funds involved in the fraud schemes abroad."
        https://www.justice.gov/opa/pr/two-key-members-chinese-money-laundering-network-charged-laundering-43-million-investment
        https://www.bleepingcomputer.com/news/security/us-charges-two-over-laundering-43-million-from-investment-fraud/
      • The Real AI Threat Is Blind Trust
        "A recent attack involving an autonomous AI agent exposed a growing enterprise risk many organizations are not prepared for: AI systems capable of transforming untrusted input into authorized action. No passwords were stolen. No malware was deployed. No firewall was breached. From the system's perspective, the transaction was entirely legitimate. Using a string of Morse code dots and dashes, attackers manipulated one AI agent into generating what appeared to be a legitimate instruction for another AI system authorized to move funds. The second agent complied without hesitation."
        https://www.darkreading.com/application-security/real-ai-threat-blind-trust
      • Prompt Injection Is Becoming The XSS Of The Web Agent Era
        "Autonomous web agents read whatever a page displays, and much of that content comes from strangers. Product reviews, seller listings, and advertisements sit beside trusted site menus on a single page. An agent that reads all of that text as instructions can be steered by any of it. A group at UC Berkeley describe Cross-Site Prompting, or XSP, as the agent-era version of Cross-Site Scripting. Their system, Prismata, sits between a web agent and the browser. It filters the content an agent sees and limits the actions the agent can take."
        https://www.helpnetsecurity.com/2026/07/17/xss-web-agent-prompt-injection/
        https://arxiv.org/pdf/2607.08147
      • The Script, Not The Voice, Is What Makes AI Voice Phishing Work
        "The call comes in at 4:40 on a Friday. The voice belongs to a senior manager, or sounds close enough, and she needs a password reset before a flight. She is polite, she is in a hurry, and she has the last four of the badge number. Researchers at Harvard Kennedy School, Meta and elsewhere ran a version of that moment past 4,100 US adults, using six commercial voice systems and human callers as a control. The results land in an odd place for anyone buying deepfake detection."
        https://www.helpnetsecurity.com/2026/07/17/research-ai-voice-phishing/
        https://arxiv.org/pdf/2607.09970
      • Government Ransomware Roundup: H1 2026 Stats On Attacks, Ransoms, And Data Breaches
        "From January to June 2026, Comparitech researchers logged an average of one ransomware attack on a government entity every day. Attacks jumped by over 13 percent when compared to H2 2025, increasing from 165 to 187 attacks. Of the 187 attacks recorded in H1 2026, 89 were confirmed by the targeted entities."
        https://www.comparitech.com/news/government-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/
        https://www.infosecurity-magazine.com/news/government-ransomware-daily/
      • Ransomware And Cyber Extortion In Q2 2026
        "Three of Q1's dominant ransomware groups lost significant ground in Q2 2026, but the techniques driving risk across the landscape barely changed. As “Qilin,” “DragonForce,” and “Coinbase Cartel” declined in terms of named victim counts, “The Gentlemen” claimed the top spot for the first time. Overall, ransomware groups posted 2,252 victims in Q2—down 15% from Q1 but up about 51% year over year, and the top ranks are still shifting. Defenders must focus on attacker behaviors, not the leaderboard shuffle, especially as some of the most disruptive groups may never crack the top ranks at all."
        https://reliaquest.com/blog/threat-spotlight-ransomware-and-cyber-extortion-in-q2-2026/
        https://www.infosecurity-magazine.com/news/the-gentlemen-most-prolific/
      • Armenia Detains Russian Tourist On U.S. Warrant For REvil Hacker, Lawyers Say Wrong Man
        "Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan's Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a side room. His lawyers say Washington has the wrong man."
        https://thehackernews.com/2026/07/armenia-detains-russian-tourist-on-us.html

      อ้างอิง
      Electronic Transactions Development Agency (ETDA)a162f8c3-6c3e-4013-ad08-39ba510b00b7-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Microsoft ออกแพตช์กรกฎาคม 2026 แก้ไข 622 ช่องโหว่ และ 2 Zero-Day ที่ถูกใช้โจมตีจริง

      Microsoft ออกแพตช์กรกฎาคม 2026 แก้ไข 622 ช่องโหว่ และ 2 Z.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand ca4c90e4-339e-49ac-9ea4-91f8acac505b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • F5 ออกแพตช์แก้ช่องโหว่หลายรายการใน NGINX และ BIG-IP เสี่ยง DoS และรันโค้ดบนระบบ

      F5 ออกแพตช์แก้ช่องโหว่ใน NGINX และ BIG-IP เสี่ยง DoS แล.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 12120ecf-1e73-49f3-947f-8da081fc25e6-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Zoom แจ้งเตือนช่องโหว่ เสี่ยงถูกยึดบัญชีผู้ใช้งานบนระบบปฏิบัติการ Windows

      Zoom แจ้งเตือนช่องโหว่ เสี่ยงถูกยึดบัญชีผู้.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5a7859bd-399f-440e-908c-5cf14fdcdb6b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT