NCSA Webboard
    • ล่าสุด
    • แท็ก
    • ฮิต
      • ติดต่อสำนักงาน
    • ลงทะเบียน
    • เข้าสู่ระบบ
    1. หน้าแรก
    2. NCSA_THAICERT
    3. กระทู้
    • รายละเอียด
    • ติดตาม 0
    • คนติดตาม 3
    • กระทู้ 2,489
    • กระทู้ 2,490
    • ดีที่สุด 0
    • Controversial 0
    • กลุ่ม 2

    โพสต์ถูกสร้างโดย NCSA_THAICERT

    • CISA เตือนช่องโหว่ Windows Task Host ถูกกลุ่ม Ransomware นำไปใช้โจมตี

      CISA เตือนช่องโหว่ Windows Task Host ถูกกลุ่ม Ransomware นำไปใช.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand d4d88a7b-7759-4019-b397-b54f6a47dd65-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • GitLab ออกแพตช์ฉุกเฉินแก้ช่องโหว่ GraphQL ระดับ Critical กระทบ Self-managed Server

      GitLab ออกแพตช์ฉุกเฉินแก้ช่องโหว่ GraphQL ระดับ Critical .png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 943c3bd8-27ae-4daf-a75a-d5b24757a072-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • กลลวงกลุ่ม Ransomware แอบอ้างว่าสามารถช่วยลบข้อมูลที่ถูกขโมยไปได้ แต่กลายเป็นการหลอกเรียกเงินซ้ำซ้อน

      กลลวงกลุ่ม Ransomware แอบอ้างว่าสามารถช่วยลบข้อ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e77540c2-0f19-4aa2-98e8-94199a1596b6-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 20 August 2026

      Financial Sector

      • Banks Look For Fraud Signals In Customer Behavior
        "Banks are dealing with more fraud in which customers authorize payments after being manipulated by criminals. ThreatMark’s Fraud Readiness Benchmark 2026 describes a banking environment where social engineering, reimbursement requirements and growing case volumes are changing fraud operations. Fifty-five percent of institutions surveyed said social engineering is involved in most of their fraud. Criminals may pose as bank employees or other trusted people to persuade customers to send money."
        https://www.helpnetsecurity.com/2026/08/19/threatmark-banking-fraud-prevention-report/

      Industrial Sector

      • Defending Against An Active Threat To Siemens S7 Series PLCs
        "The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA)—hereafter referred to as the authoring agencies—are releasing this Cybersecurity Advisory to warn owners and operators of industrial control systems (ICSs) of an active cyber threat to Siemens S7 Series PLCs and provide relevant mitigations to protect and defend them."
        https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a
        https://www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-infrastructure/
        https://therecord.media/nsa-fbi-warns-of-hackers-using-ai-generated-tools-critical-infrastructure
        https://cyberscoop.com/hackers-use-ai-target-siemens-plcs-critical-infrastructure/

      Vulnerabilities

      • 943 Patches Rolled Out With Oracle’s August 2026 Security Update
        "Oracle on Tuesday announced the release of 943 new security patches as part of the August 2026 Critical Security Patch Update (CSPU), its third monthly security rollout. The company’s advisory mentions more than 1,000 unique CVEs across two dozen products, including over 460 vulnerabilities that can be exploited remotely without authentication. The patches for dozens of vulnerabilities address additional security flaws. More than 150 of the security defects are critical-severity bugs, and nearly 90 of them have a CVSS score of 9.8 or higher."
        https://www.securityweek.com/943-patches-rolled-out-with-oracles-august-2026-security-update/
      • Chrome, Firefox Updates Patch Dozens Of Vulnerabilities
        "Google and Mozilla on Tuesday announced fresh Chrome and Firefox security updates that address multiple critical- and high-severity vulnerabilities. Firefox 154 was released to the stable channel with patches for 58 CVEs, including 20 high-severity flaws, roughly half of which are memory safety bugs that could be exploited for code execution. Resolved high-severity issues include six use-after-free defects, six privilege escalation vulnerabilities, two information disclosure bugs, one sandbox escape flaw, one site isolation issue, and one mitigation bypass weakness."
        https://www.securityweek.com/chrome-firefox-updates-patch-dozens-of-vulnerabilities/
        https://www.malwarebytes.com/blog/bugs/2026/08/update-chrome-now-two-critical-vulnerabilities-fixed
      • CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC And NetScaler Gateway
        "On August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges. NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products commonly positioned at or near the network perimeter. NetScaler ADC provides application delivery, traffic management, load balancing, SSL/TLS offloading, and application security capabilities, while NetScaler Gateway provides secure remote access and VPN functionality. Because these systems are frequently deployed in enterprise DMZs and exposed to the public internet, authentication bypass vulnerabilities affecting Citrix products are nearly always exploited by threat actors."
        https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway/
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/19/cisa-adds-one-known-exploited-vulnerability-catalog
      • Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker At 12 Bits/Second
        "Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021. The end-to-end experiment used an attacker Worker and a victim Worker controlled by the researchers, with the JWT intentionally placed in the victim's memory. The research paper stated that no customer data was accessed."
        https://thehackernews.com/2026/08/cloudflare-workers-spectre-attack-leaks.html
        https://arxiv.org/abs/2608.17043
      • Yet Another RCE In Gogs, But It's Fixed This Time!
        "Gogs is an open-source Git hosting platform like GitHub or GitLab. The application allows users to manage their own repositories and organizations. Under the hood, it relies heavily on the git CLI. There has been a long history of RCE's in Gogs, most taking a while to fix, requiring public disclosure before an officially patched version is even out. This case was different. After a few months of silence, it seems work has started again on securing Gogs by the maintainers, and all our reports were fixed as of version 0.14.3! We hope this trend continues and eventually brings Gogs into a secure state. However, there is currently still one unpatched bypass of a vulnerability we reported that our AI pentest agents found. We provide a manual code patch for that below."
        https://www.aikido.dev/blog/fixed-rce-gogs-cve-2026-52813

      Malware

      • Balonx Sistema: The Face Behind The PhaaS Affecting Mexican Banking
        "Mexico’s banking infrastructure has emerged as a primary target for sophisticated cyber threats in Latin America, ranking second only to Brazil in banking malware incidents in 2025. This escalation is tightly linked to the rise of Phishing-as-a-Service (PhaaS) platforms, which enable low-capability threat actors to execute industrial-scale financial fraud. More than 20 financial institutions in the country currently face these persistent, subscription-based operational threats. In response to this threat landscape, Group-IB conducted an in-depth technical analysis of Balonx Sistema, a highly structured PhaaS platform developed by an operative based in Mexico."
        https://www.group-ib.com/blog/balonx-sistema-mexico-phaas/
      • Operation CameraSwarm: Over 14,000 Dahua Cameras Compromised Across Ukraine And Russia
        "Between 17 June and 22 July 2026, a single operator compromised over 14,000 Dahua IP cameras. The scanning behind it was global: masscan sweeps ran against Russian address space first, then across the full IPv4 range, and the largest single haul actually landed in Mexican and Vietnamese ISP ranges before the operator's focus settled on Russian and CIS telecom netblocks. Where the confirmed, geolocated compromises concentrated was Ukraine and Russia, with Ukraine holding the largest share. This is the second Dahua-related camera compromise operation we've traced back to an exposed operator directory in as many weeks. Where last week's investigation centered on a Russian-speaking operator running a purpose-built platform against 58 cameras, this one is a different scale entirely."
        https://hunt.io/blog/operation-cameraswarm-dahua-cameras-compromised
        https://www.bleepingcomputer.com/news/security/hackers-compromise-14-500-dahua-web-cameras-in-35-day-campaign/
        https://thehackernews.com/2026/08/hackers-compromised-14500-dahua-devices.html
        https://securityaffairs.com/197527/iot/inside-operation-cameraswarm-how-one-actor-took-over-14000-dahua-cameras.html
      • Describing Attacks With Crime Script Analysis
        "Effective defense against cyber attacks requires understanding how attacks are carried out and identifying where the attack can be disrupted or detected. Lockheed Martin’s Cyber Kill Chain was one of the earliest models to describe the steps required to conduct a cyber attack. However, its seven-step linear sequence is too rigid to apply to many attacks. The Attack Flow model of the MITRE ATT&CK framework allows various tactics, techniques, and procedures (TTPs) to be chained together to describe exactly how attacks are conducted, including branches and loops if necessary. The resulting graphs are comprehensive, but can be daunting to a non-technical audience. In a world of evolving threats and shrinking budgets, defenders need techniques to communicate threats to a wider audience."
        https://blog.talosintelligence.com/describing-attacks-with-crime-script-analysis/
      • How Grok Unknowingly Powers Cybercrime
        "Our collective safety increasingly depends on frontier AI capabilities being prohibitively expensive for criminals to acquire. Our latest research found that access starts at just $12.99 a month. ‘Kriminal’ is one of the newest and most popular tools in the criminal AI market, and it isn’t hiding on the dark web. It’s living in plain sight on the clearnet, indexed by Google, with a login button and five pricing options. It markets itself as “the AI that answers everything. No filters, no guardrails.” On the surface, Kriminal claims to have done the economically impossible and created a frontier AI from scratch, built by and for cybercriminals. Under the hood its own code reveals that almost nothing is new: no model, no infrastructure, no original capability. It’s a storefront renting intelligence from the same legitimate AI industry it claims to circumvent."
        https://www.threatdown.com/blog/kriminal/
        https://www.darkreading.com/application-security/no-filter-kriminal-ai-platform-cybercrime-concerns
      • SilkParasite: Tracking a China-Nexus APT Across Central Asia
        "SilkParasite is a cyberespionage operation, assessed at medium confidence as China-nexus, that targeted government bodies across Central Asia. Bitdefender Labs found seven remote access tool (RAT) families in use, five of which were previously undocumented; we identified and named them: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered, and it carries traces of AI-assisted development."
        https://businessinsights.bitdefender.com/silkparasite-tracking-china-nexus-apt-across-central-asia
        https://thehackernews.com/2026/08/silkparasite-espionage-campaign-targets.html
        https://www.darkreading.com/threat-intelligence/silkparasite-central-asian-orgs-flurry-rats
      • 41 Deceptive Download Sites Show a Real Link, Then Send You Somewhere Else
        "We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer. The sites advertise everything from Counter-Strike, Half-Life, Fallout, Roblox, PUBG, and The Witcher to VLC, 7-Zip, Paint.NET, VMware, Total Commander, and Foxit PDF."
        https://www.malwarebytes.com/blog/threat-intel/2026/08/41-deceptive-download-sites-show-a-real-link-then-send-you-somewhere-else
      • Scammers Are Using Fake Crypto AML Checkers To Drain Your Wallet
        "Scammers are creating fake crypto wallet-checking sites that promise to tell you whether a wallet is linked to suspicious activity. Instead, they try to trick you into giving them access to your crypto. AML stands for anti-money laundering. These are rules that require banks and other regulated businesses to screen customers for ties to crime. It’s designed to prevent cybercriminals from hiding or moving illegally obtained money. In the crypto world, this usually means checking whether a wallet address has links to hacks, scams, sanctioned entities, or other suspicious activity based on its transaction history."
        https://www.malwarebytes.com/blog/threat-intel/2026/08/scammers-are-using-fake-crypto-aml-checkers-to-drain-your-wallet
      • Hunting MacSync Stealer Infrastructure Through Behavioral Pivots
        "MacSync Stealer is a macOS-focused information stealer that relies on changing infrastructure to deliver payloads, communicate with compromised devices, and exfiltrate data. Earlier reporting by RST Cloud identified the threat through a limited set of domains and documented rapid command-and-control (C2) replacement after public disclosure. Microsoft Defender Experts expanded that view by correlating recurring endpoints and network behaviors across the activity. This behavior-led approach connected more than 30 domains and showed that the infrastructure supported more than C2 communication, extending into active collection, staging, and exfiltration. The findings demonstrate that although domains may rotate quickly, repeated execution patterns, request characteristics, staging behavior, and upload methods provide defenders with more durable opportunities to investigate MacSync Stealer activity."
        https://www.microsoft.com/en-us/security/blog/2026/08/18/hunting-macsync-stealer-infrastructure-through-behavioral-pivots/
        https://thehackernews.com/2026/08/microsoft-links-30-rotating-domains-to.html
        https://securityaffairs.com/197514/malware/microsoft-tracks-macsync-stealer-by-its-behavior-not-its-domains.html
      • Malware-As-a-Service Cocktail: ErrTraffic And Cruciferra - Killing Your EDR Since 2025
        "In late July 2026, eSentire's Threat Response Unit (TRU) identified several ErrTraffic-generated ClickFix campaigns attempting to deliver Cruciferra - a malware loader marketed on underground forums that boasts EDR-killing capabilities. TRU found Cruciferra using a vulnerable driver to fulfill this behavior. The driver, also known as, "DCRCVDrv.sys", is signed by South Korean IT company MocoMsys and exposes an IOCTL that allows user-mode applications to terminate processes directly from the kernel. The Cruciferra Malware-as-a-Service (MaaS) first appeared in November 2025 and is currently sold for $1200 per month for the package with EDR killing features by the user Cruciferra on underground hacking forums."
        https://www.esentire.com/blog/malware-as-a-service-cocktail-errtraffic-and-cruciferra-killing-your-edr-since-2025
        https://www.infosecurity-magazine.com/news/maas-clickfix-errtraffic-cruciferra/
      • Grandoreiro Goes North: From Brazil To Mexico With a New DLL Sideloading Campaign
        "Grandoreiro is a notorious banking trojan that has been operating across Latin America since at least 2016, targeting financial institutions and their customers through phishing campaigns and social engineering techniques. Written in Delphi and Brazilian in origin, it is one of the many of Latin American banking trojans (alongside Guildma, Javali and Melcoz). Over the years, the malware has gone through multiple iterations and infrastructure changes to evade detection and sustain its operations. In January 2024, a coordinated operation led by Brazil's Polícia Federal and coordinated through INTERPOL — with Spanish authorities and private-sector partners — disrupted significant portions of its infrastructure and reduced its overall reach."
        https://www.acronis.com/en/tru/posts/grandoreiro-goes-north-from-brazil-to-mexico-with-a-new-dll-sideloading-campaign/
        https://www.infosecurity-magazine.com/news/grandoreiro-mexico-dll-sideloading/
      • A Revisit Of Remote Spectre Attacks On Cloudflare Workers
        "In 2021, we assessed remote Spectre attacks against Cloudflare Workers. Based on the results, we shipped a production defense called Dynamic Process Isolation (DyPrIs), which identifies maliciously looking scripts and isolates them into separate processes. Since then, newer techniques in the area of stabilizing Spectre attacks have been discovered. To understand if these techniques posed a threat to our Workers production environment, we decided to internally reassess the remote Spectre attack. Building an updated proof-of-concept on the production environment allowed us to empirically assess the risk of Spectre attacks under production workloads."
        https://blog.cloudflare.com/revisiting-spectre-attacks-on-workers/
      • Ray CVE-2025-62593: Critical Browser-Driven RCE Via DNS Rebinding
        "CVE-2025-62593 is a critical remote code execution vulnerability in Ray, a distributed computing framework widely used for Python and machine-learning workloads. The attack combines DNS rebinding with a flawed User-Agent-based browser check. An attacker-controlled webpage can use the victim's browser to reach a locally running Ray Dashboard on port 8265, bypass the browser-request protection, and access the Jobs API without requiring Ray credentials."
        https://www.resecurity.com/blog/article/ray-cve-2025-62593-critical-browser-driven-rce-via-dns-rebinding
      • CopyCop Targets AI Investment In Armenia
        "The Russian influence network CopyCop (Storm-1516) very likely targeted the joint United States (US) and Armenian-backed Firebird AI data center in Hrazdan, Armenia, as part of a broader campaign to undermine Armenia's westward geopolitical and economic realignment. Between June 24 and July 13, 2026, Insikt Group documented three separate CopyCop media impersonations targeting the facility ahead of its July 2026 opening. These impersonations fabricated an imminent earthquake risk, cast doubt as to the facility's economic and infrastructure viability, and, most recently, impersonated an official Iranian military communications that justified treating the data center as a legitimate military target. Reach expanded substantially across the three instances, growing from limited initial engagement to over 1.6 million combined views by the third, indicating growing audience viewership as the campaign progressed."
        https://www.recordedfuture.com/blog/copycop-targets-ai-investment
      • PurpleDelta's Fraudulent Employment Operations
        "Insikt Group has identified several clusters of activity linked to PurpleDelta, Recorded Future's designation for North Korean IT workers, comprising multiple operators likely based in China. Between late 2024 and early 2025, one cluster applied to jobs at over 1,100 companies, primarily in the software and technology, staffing and consulting, and healthcare and biotechnology sectors. PurpleDelta operators maintained at least 22 fabricated personas across multiple clusters, some of which were supported by AI-generated profile photos, custom-configured ChatGPT assistants, and identity documents sourced from an illicit ID-generation service, and were highly likely to be actively employed by at least ten organizations. PurpleDelta operators demonstrate a high operational tempo to this day. In some cases, the operators have applied to at least 60 positions per day across multiple job platforms, used multi-account management browsers and separate Google Chrome profiles to manage distinct personas simultaneously, and maintained detailed tracking spreadsheets to coordinate applications across identities."
        https://www.recordedfuture.com/research/purpledelta-fraudulent-employment-operations
        https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-nk-2026-0818.pdf
      • How a Google Search For Claude Led To MacSync
        "Picture this: You've just unboxed a shiny new Macbook, and now you're downloading all of your favorite apps. You type "How to install Claude Code on a Mac" in Google and click on the first link at the top of the page. You're presented with the following: Looks legit, right? It's even got a badge stating it's been shared by Apple Support. But look closer. While it's a real page hosted on the actual claude.ai domain, this shared conversation instructs you to paste a curl one-liner into Terminal that ultimately downloads a pernicious infostealer. Instead of Claude, you get MacSync."
        https://www.huntress.com/blog/fake-claude-macsync

      Breaches/Hacks/Leaks

      • CareCloud Data Breach Impact Grows To 3.7 Million Individuals
        "The recently disclosed CareCloud data breach affects more than 3.7 million individuals, far more than initially believed. The cloud-based healthcare solutions provider revealed in early July that it had detected a network intrusion in mid-March. The breach was discovered following a disruption involving an electronic health record environment. An investigation showed that threat actors gained access to one of CareCloud’s AWS environments between March 10 and March 16. The hackers claimed to have exfiltrated information from databases in the compromised environment, according to the company."
        https://www.securityweek.com/carecloud-data-breach-impact-grows-to-3-7-million-individuals/
        https://www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breach-impacts-37-million-patients/
        https://therecord.media/electronic-health-record-company-carecloud-data-breach
        https://www.bankinfosecurity.com/ehr-vendor-notifying-38-million-patients-data-theft-hack-a-32609
      • Live Stripe Keys For 659 Merchants, Published For Free
        "A dataset published on a data-trading forum on 18 August 2026 contains live Stripe API keys for 659 merchant accounts, along with roughly 35 GB of customer and payment data pulled from them. Ransomnews analysed the files offline and reported the exposure to Stripe before publishing. Stripe itself was not compromised. The keys belong to merchants. The listing went up in the early hours of 18 August under a headline claiming a breach of Stripe itself. That framing is wrong, and it matters, so it is worth dealing with first. Nothing in the dataset indicates any failure of Stripe’s own systems. What the files show is 659 merchants whose secret API keys ended up in someone else’s hands, after which that person used the keys the way any developer would, and pulled down everything the API would return."
        https://ransomnews.com/stripe-merchant-api-keys-leak-2026/
        https://securityaffairs.com/197504/cyber-crime/50000-stripe-secrets-leaked-in-public-code.html
      • Sakura Internet Hack Exposes Data Of Up To 1.36 Million Accounts
        "Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. In an update today to the initial notification from Monday, the company says the incident may have impacted up to 1,360,563 member accounts. However, as the investigation continues, the exact number of affected accounts remains to be determined."
        https://www.bleepingcomputer.com/news/security/sakura-internet-hack-exposes-data-of-up-to-136-million-accounts/
      • Latvian Officials Resign After Cyberattack Exposes Data On 1.2 Million People
        "Latvia’s road traffic agency confirmed that hackers stole data connected to about two-thirds of the country’s population in a major cyberattack that has prompted calls for senior officials to resign. The Road Traffic Safety Directorate, known as CSDD, said Tuesday that its investigation found hackers had accessed data from payment receipts dating back to 2008. The breach affected records belonging to more than 1.2 million people and 200,000 businesses and other legal entities. Latvia has a population of just over 1.8 million. CSDD is the state agency responsible for vehicle registration, driver’s licenses and other road safety services and operates under Latvia’s Transport Ministry."
        https://therecord.media/latvia-cyberattack-vehicle-data

      General News

      • UK Fraud Cases Hit Record High In 2026
        "Over 220,000 cases were filed with the UK’s National Fraud Database (NFD) between January and June, the highest number ever recorded during the first half of a year, according to Cifas. The non-profit, which runs the NFD and the Insider Threat Database, said identity fraud rose 9% year on year (YoY) to nearly 130,000 cases in the first half of 2026. This figure in turn was driven by scammers targeting bank accounts and plastic cards, which accounted for 68% of all these cases. Impersonation incidents using the victim’s real address increased by 12% YoY."
        https://www.infosecurity-magazine.com/news/uk-fraud-cases-hit-record-high/
      • Password Spraying Attacks Surge 155x As Hackers Exploit MFA Gaps
        "Huntress has observed a 155x increase in password spraying attacks in the first half of 2026. Brute force is old news, but the spin driving that spike is new. One major contributor was a campaign targeting Microsoft's Azure CLI, the command-line tool admins use to manage Azure and Entra resources. The traffic originated from an IPv6 range controlled by internet hosting provider LSHIY LLC. The campaign started months earlier, but in mid-June alone Huntress observed more than 81 million related login attempts and 78 account compromises in a two-week window."
        https://www.bleepingcomputer.com/news/security/password-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps/
      • Rising Number Of Cyberattacks Have AI-Assisted Fingerprints
        "Attackers are wielding artificial intelligence tools in semi-autonomous ways to help them perpetrate network intrusions at greater speed and scale than ever before. Their efforts are producing mixed results. "Abuse of AI seems to be business as usual for threat actors now," said Ben Folland, a security researcher at threat intelligence firm Ctrl-Alt-Intel. Proprietary and open-source large language models, often accessed illicitly, are being used to facilitate everything from network penetration and persistent access to data exfiltration and ransomware infections."
        https://www.bankinfosecurity.com/rising-number-cyberattacks-have-ai-assisted-fingerprints-a-32602
      • Back-To-School Cyber Risks Surge As Education Remains The World’s Most Attacked Sector
        "As students, teachers and families return to classrooms, campuses and online learning platforms at the end of summer, cyber-criminals are preparing for the new school year as well. According to Check Point Research, the education sector remains the world’s most targeted industry, facing significantly more cyberattacks than any other sector. Between January and July 2026, educational organizations such as colleges and universities, research institutes, and K-12 school systems alike, faced an average of 4,696 weekly cyberattacks per organization, representing an 8% increase compared to the same period in 2025 and more than double the global cross-industry average of 2,150 attacks. Education also ranked highest among all 23 tracked industries, experiencing attack volumes approximately 70% higher than the government sector, the second-most targeted industry."
        https://blog.checkpoint.com/research/back-to-school-cyber-risks-surge-as-education-remains-the-worlds-most-attacked-sector/
      • Staying Ahead Of Adversarial AI Through Agentic Source Code Review
        "Adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must scramble to identify and patch vulnerabilities while attackers deploy machine-speed AI tools against them. By structuring the analysis process, enforcing skeptical validation steps, and injecting domain-specific human expertise directly into the pipeline, we’ve achieved a leap in efficacy. Combining AI models with a deeply structured, human expert-driven orchestration layer to tip the scales so that defenders can beat adversaries to the punch."
        https://cloud.google.com/blog/topics/threat-intelligence/staying-ahead-of-adversarial-ai-through-agentic-source-code-review
        https://www.helpnetsecurity.com/2026/08/19/google-mandiant-avdh-ai-vulnerability-discovery-tool/
      • Threat Spotlight: The Average Web Application Has 20 Security Vulnerabilities
        "The average web application features 20 security vulnerabilities. Information disclosure and brand impersonation vulnerabilities account for 49% of detected flaws — they can help attackers map targets and deceive users. Most web application risk stems from common security oversights rather than sophisticated attacks, highlighting the importance of continuous monitoring, patching and security hygiene."
        https://blog.barracuda.com/2026/08/19/average-web-application-20-security-vulnerabilities

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) bf335ecb-14b4-4074-a43a-3b6fb1fe234c-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 2 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 2 รายการ เมื่อวันที่ 18 สิงหาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-230-01 CISA Malcolm
      • ICSA-26-230-02 Siemens Simcenter Nastran

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand e9648b19-9fb7-4dde-bee4-1f29f1adca86-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 19 August 2026

      Industrial Sector

      • CISA Malcolm
        "Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-01
      • Siemens Simcenter Nastran
        "Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions."
        https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-02

      Vulnerabilities

      • NASA Ground Control Software Flaw Enables Unauthenticated Commands
        "A critical vulnerability in NASA's open-source AMMOS Instrument Toolkit (AIT)-GUI ground software has been found that could allow unauthenticated attackers to issue spacecraft and instrument commands, execute server-side scripts and run command sequences. AIT-GUI is the browser-based operator console for NASA's AMMOS Instrument Toolkit, an open-source framework for ground data systems that communicate with instruments and spacecraft. The flaw, tracked as GHSA-p9r8-2q67-fp86 and given a CVSS ratting of 9.4, affects AIT-GUI versions through 2.5.1. No CVE has been assigned at the time of writing."
        https://www.infosecurity-magazine.com/news/nasa-ground-control-software-flaw/
      • Dozens Of WebKit Vulnerabilities Patched With Fresh MacOS, iOS Security Updates
        "Apple on Monday announced a fresh round of macOS, iOS, and iPadOS security updates that address dozens of vulnerabilities, most of which affect the web browser engine WebKit. macOS Tahoe 26.6.2 is now rolling out with fixes for 28 security defects, including 21 in WebKit that could lead to Safari/process crashes, memory corruption, and sensitive data disclosure. The update also resolves seven issues in Audio, ImageIO, IOGPUFamily, and Kernel that could lead to sensitive user information disclosure, denial-of-service (DoS), arbitrary code execution, memory corruption, system termination, and kernel memory disclosure or corruption."
        https://www.securityweek.com/dozens-of-webkit-vulnerabilities-patched-with-fresh-macos-ios-security-updates/
        https://www.malwarebytes.com/blog/bugs/2026/08/apple-fixes-another-image-processing-flaw-that-could-allow-code-execution
        https://www.theregister.com/security/2026/08/18/apple-plugs-image-processing-hole-ripe-for-spyware-abuse/5289031
      • Attackers Exploit MLflow SSRF Flaw To Steal Cloud Credentials And Secrets
        "Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts. According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows -"
        https://thehackernews.com/2026/08/attackers-exploit-mlflow-ssrf-flaw-to.html
      • CISA Adds Four Known Exploited Vulnerabilities To Catalog
        "CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
        CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability
        CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability
        CVE-2026-65400 Apple macOS Improper Authentication Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog
      • CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower
        "Varonis Threat Labs uncovered another one-click vulnerability in Microsoft Copilot Personal dubbed CoSnitch (critical, CVE-2026-24301), which quietly executes an attack chain that exfiltrates data from enterprises without obvious red flags. What makes CoSnitch unique is how Copilot surfaced its own vulnerabilities, a method we are calling meta-hacking. Our researchers didn't have to reverse-engineer the flaw. The AI exposed the weakness during normal use, highlighting a meaningful shift in how security flaws are found, and a preview of what's ahead as AI gets woven deeper into enterprise systems."
        https://www.varonis.com/blog/cosnitch
        https://www.darkreading.com/vulnerabilities-threats/cosnitch-attack-copilot-mapping-out-architecture
        https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html
        https://www.theregister.com/research/2026/08/18/copilot-tricked-into-telling-reseachers-how-to-hack-itself/5288857
      • AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
        "Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent coding collaboration and in a chain of paired agents modeled on OpenClaw, the open-source autonomous assistant formerly known as Clawdbot and Moltbot."
        https://thehackernews.com/2026/08/ai-mind-viruses-can-spread-between.html
        https://arxiv.org/abs/2608.10218

      Malware

      • Beware Of Phishing Emails Disguised As Requests To Review Quotes (PhantomStealer)
        "The AhnLab SEcurity intelligence Center (ASEC) recently identified a phishing email campaign that disguised itself as a request to review a quote. The threat actor impersonated a sales team member at a specific overseas company and, by claiming that a previous quote needed to be revised and product versions verified, tricked recipients into opening the Attachment. The email contained a malicious file named “7200_Quantum_Enterprise_LLC_SSO-0661.GZ” , which contained a malicious compressed file."
        https://asec.ahnlab.com/en/95000/
      • Beware Of Phishing Emails Disguised As Transaction Receipts
        "Recently, the AhnLab SEcurity intelligence Center (ASEC) identified instances of phishing emails that were disguised as transaction receipts. The emails impersonated employees of a specific US company. The body of the message stated that a transaction receipt was attached and asked the recipient to review it and confirm whether funds had been deposited into their account, thereby enticing the recipient to open the Attachment."
        https://asec.ahnlab.com/en/95001/
      • Attack Cases For Domestic Web Servers Running SoftEther VPN In Korea
        "The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases in which attackers targeted web servers in Korea to install SoftEther VPN. Attack cases involving the installation of SoftEther VPN, an open-source VPN, were previously discussed in the 2024 ASEC blog post titled “Analysis of Attack Cases Targeting ERP Servers in Korea to Install SoftEther VPN” [1]. The threat actor currently carrying out similar attacks exhibits the same characteristics as the case described above and is therefore classified as Larva-26010. It appears that the threat actor ultimately installed the SoftEther VPN service to use the infected systems as VPN servers."
        https://asec.ahnlab.com/en/94995/
      • Clop Returns With Custom Implant In Mass-Extortion Campaign
        "ReliaQuest identified a custom web shell highly likely linked to "Clop" (aka Cl0p), a financially motivated ransomware and extortion group known for mass-exploiting enterprise software vulnerabilities. The web shell is deployed after exploitation of CVE-2026-12569 (CVSS 9.3) in PTC Windchill, an industry-standard product lifecycle management (PLM) platform used by manufacturing enterprises worldwide to store engineering data and product designs. The web shell gives attackers a direct path to credential theft and large-scale data exfiltration, with no additional tooling required. Unlike generic command shells, this implant decrypts credentials, delivers malware, and maps stored files for exfiltration."
        https://reliaquest.com/blog/clop-returns-with-custom-implant-in-mass-extortion-campaign/
        https://www.bleepingcomputer.com/news/security/clop-created-custom-web-shell-for-windchill-data-theft-attacks/
      • CISA: Windows Task Host Flaw Now Exploited By Ransomware Gangs
        "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown. Tracked as CVE-2025-60710, this Windows privilege escalation security flaw was patched by Microsoft in November 2025 and stems from a link following weakness that affects Windows 11 and Windows Server 2025 devices."
        https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/
      • The Mistake That Exposed a Global Cyber Crime Operation
        "Most cyber crime investigations reveal the aftermath of an attack. Few reveal the attackers themselves. That’s what makes Check Point Research‘s latest investigation into StopAndProtect so unusual. While analyzing a newly identified cyber crime operation, researchers uncovered a series of operational security (OPSEC) mistakes that exposed the attackers’ own infrastructure including: victim logs, screenshots, source code, internal management tools, and evidence of a campaign impacting more than 5,000 infected computers worldwide. The investigation also uncovered files referencing close to 2,000 compromised WordPress domains, providing a rare look inside how a modern cyber criminal operation is built and managed."
        https://blog.checkpoint.com/research/the-mistake-that-exposed-a-global-cyber-crime-operation/
        https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/
      • Living Off The Cloud: A Python Implant Hiding Its Entire C2 Inside Microsoft 365 & Azure
        "The Ontinue Cyber Defense Center uncovered an undocumented Python implant framework while investigating an ongoing campaign in July 2026. We track it internally as TWINLOOT, named after its SharePoint C2 folder ‘TwinLoot’. TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services. Tasking flows through SharePoint Online file dead-drops via the Microsoft Graph API. Interactive operator access routes through WebRTC DataChannels relayed by Microsoft Teams TURN servers. Graph API traffic is driven through a headless instance of the victim’s own Edge browser, making it indistinguishable from legitimate user activity."
        https://www.ontinue.com/resource/python-implant-hiding-its-entire-c2-inside-microsoft-365-azure/
        https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.html
        https://www.darkreading.com/cloud-security/silent-twinloot-threat-operates-microsoft-cloud
      • Beware The Ransomware Rescuer: Ransom Busters
        "The GuidePoint Research and Intelligence Team (GRIT) has responded to several recent ransomware incidents in which victims received an unexpected email from an ostensible third-party entity referring to itself as “Ransom Busters.” In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous. While cybersecurity firms commonly reach out to ransomware victims to offer consulting or recovery services, it is generally done only after the attack becomes public knowledge. This ostensible third-party’s insight into an attack that was not yet public is alarming. It raises the question how “Ransom Busters” could know about the incident at all."
        https://www.guidepointsecurity.com/blog/beware-ransom-busters/
        https://www.darkreading.com/cyberattacks-data-breaches/ransom-busters-ransomware-actor-incident-recovery-service
        https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html
      • StubMaker RubyGems Campaign Delivers a Windows Infostealer
        "On August 15, 2026, we discovered newly-published RubyGems packages that installs a multi-stage Windows infostealer malware. This new malware harvests browser credentials, cryptocurrency wallets, seed phrases, and Telegram data. All of the malicious Rubygems packages appear to be typosquats of popular Ruby dependencies, but rather than the clever SEO-fueled typosquats we've seen from other threat actors (e.g. events-channel imitating the popular Node.js events module), they're all clumsy typos. But don't let that fool you into not taking them seriously. The threat actor still managed hundreds of downloads before the packages were taken down."
        https://opensourcemalware.com/blog/stubmaker-rubygems-windows-infostealer
        https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.html
      • More Than 200 Victims Of Medusa Ransomware Identified Over The Last Year, CISA Says
        "Federal cybersecurity agencies warned on Tuesday that troves of new victims of the Medusa ransomware gang have been identified over the last year. The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025."
        https://therecord.media/more-than-200-medusa-ransomware-victims-in-last-year-cisa
        https://cyberscoop.com/medusa-ransomware-tactics-cisa-advisory/
      • Hackers Target Ukrainian Agency Managing Assets Seized From Sanctioned Russians
        "Ukraine’s agency responsible for managing assets seized from criminals and sanctioned individuals said Tuesday that it had been targeted by a cyberattack as it investigates a potential coordinated effort to disrupt its operations. The Asset Recovery and Management Agency, known as ARMA, manages assets seized by Ukrainian authorities, including those linked to sanctioned Russians and alleged collaborators with Moscow. The agency said the latest attack came amid preparations to select a manager for seized corporate rights in IDS Ukraine, one of the country’s largest producers of bottled mineral water and beverages."
        https://therecord.media/hackers-target-ukraine-agency-sanctioned-russians
      • Weaponized AI: The Commoditization Of Cybercrime
        "The Trellix Advanced Research Center has been actively monitoring dark web forums and criminal communication channels for emerging threats tied to artificial intelligence (AI). What we are observing in 2026 is not speculative – it is operational. Underground threat actors are no longer simply discussing AI as a future capability. They are advertising, selling, and deploying AI-enhanced tools and services with increasing sophistication and commercial maturity. This blog documents the findings from our underground intelligence collection efforts, spanning autonomous kill-chain planning engines, uncensored AI-as-a-service platforms, AI-enhanced malware crypters, stolen API credential markets, and AI-assisted insider threat tooling."
        https://www.trellix.com/blogs/research/weaponized-ai-commoditization-of-cybercrime/
      • Operation ASTERIX: Anatomy Of a Crypto Fraud Pipeline
        "Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the campaign's development; recovered prompts, shell history, and project files show AI being used to package Electron applications, obfuscate code, troubleshoot builds, modify phishing infrastructure, and prepare malware for distribution."
        https://www.rapid7.com/blog/post/tr-operation-asterix-crypto-fraud-vishing-phishing/

      Breaches/Hacks/Leaks

      • Cyber Incident Disrupts Student Services At UT San Antonio
        "IT systems at the University of Texas (UT) San Antonio have been taken offline following a cyber incident, causing significant disruption to student registrations and payments ahead of the start of term this week. A statement released by university leaders on August 17 revealed that the institution had identified “attempted unauthorized activity” at the edge of its network, before reaching core systems. At this point, University Technology Solutions (UTS) took action with expert partners to contain the activity, resulting in some systems being taken offline so a thorough evaluation of the environment can take place and to assess whether additional protections need to be implemented."
        https://www.infosecurity-magazine.com/news/cyber-incident-ut-san-antonio/
        https://therecord.media/university-of-texas-forced-to-take-systems-offline-cyberattack-san-antonio
      • Berlin Cuts Two State Ministries Off Government Network After Security Breach
        "Two Berlin state ministries have been cut off from the city government’s IT network after authorities discovered a security breach. The affected ministries — one responsible for urban development, construction and housing, and the other for mobility, transport, climate protection and the environment — have been isolated from government networks since Friday as a precaution, the Berlin Senate Chancellery said in a statement on Monday. Officials have not said who was behind the breach, how the attackers gained access or whether any data was stolen. It is also unclear when the intrusion occurred."
        https://therecord.media/berlin-cuts-two-state-ministries-off-government-breach

      General News

      • 17 Iranians Charged With Conducting Massive Cyber Theft Campaign On Behalf Of The Islamic Revolutionary Guard Corps And Other Iranian Entities
        "A 14-count superseding (S2) indictment was unsealed today charging 17 members of the Mabna Institute, an Iran-based company that, since at least 2013, has conducted a coordinated campaign of cyber intrusions into computer systems for 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations (NGOs). The Mabna Institute stole more than 31 terabytes of academic data and intellectual property from these universities, as well as the email accounts of employees at the private sector companies, government agencies, and NGOs."
        https://www.justice.gov/opa/pr/17-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic-revolutionary
        https://cyberscoop.com/mabna-institute-iranian-hackers-indictment/
      • CISOs Break Their Silence In 'Declassified' Docuseries
        "Most attendees at RSAC and Black Hat conferences go to network and learn about emerging threats. But Danielle Lewan, Clint Howard II, and 11 long-time chief information security officers (CISOs) arrive with cameras rolling and a different agenda: turning their breach-response stories into compelling television. Last year, Lewan launched Red Mirror Studios, an independent film studio dedicated to cybersecurity alongside Howard, co-founder and chief creative officer. She founded the studio after working to produce a different docuseries titled "CISO: The Worst Job I Ever Wanted," while director of global marketing at Nagomi Security in 2025."
        https://www.darkreading.com/cyber-risk/cisos-break-their-silence-in-declassified-docuseries
      • A Hollowed Out Data Layer Is Making CISOs Fly Blind Into AI Attacks
        "The security industry is currently transitioning to an era where both offense and defense are AI-led, and every SOC operates at machine speed. However, what most CISOs have not yet reckoned with is that the AI defenders they are about to deploy will inherit a data foundation that two years of ingestion cost pressure has quietly hollowed out. The result is a security industry heading into an AI era with less visibility than it had five years ago. In the 2026 SANS SOC Survey, 24% of security leaders named lack of enterprise-wide visibility as their single biggest barrier to effective security operations, ranking it above staffing and automation gaps. That gap is widening at the exact moment offensive AI is closing the distance between attackers and defenders."
        https://www.helpnetsecurity.com/2026/08/18/siem-data-blind-spots-mapping/
      • Attackers Turn To AI For Help Identifying Files Worth Stealing
        "AI tools are being used by cyber attackers to write malicious code, build tools that harvest credentials, search compromised networks, identify valuable business information, manage technical infrastructure and generate commands during intrusions. Gambit Security researchers examined three unrelated threat actors that show how AI can support different stages of a cyberattack. Across the cases, attackers used AI to create scripts and exploitation tools, identify high-value business information, perform IT and DevOps tasks, and generate and refine commands during active intrusions."
        https://www.helpnetsecurity.com/2026/08/18/gambit-security-ai-cyberattack-tools-report/
      • 2026 Mid-Market Ransomware Report
        "The way ransomware gets covered centers on the biggest names and the highest ransoms. That framing leaves the impression that ransomware is mainly an enterprise problem. The data says otherwise. Across three and a half years of attacks, from 2023 through the first half of 2026 in North America and Europe, roughly three in four ransomware victims with a known revenue figure were mid-market companies earning $10 million to $1 billion a year. This is the first time the Black Kite Research Group has studied the mid-market as its own segment, rather than as companies scattered through larger studies."
        https://blackkite.com/reports/2026-mid-market-report
        https://www.infosecurity-magazine.com/news/threequarters-ransomware-attacks/
      • Passwords Stored In Public Google Doc Then Showed Up In Search Results
        "Welcome, once again, to PWNED, the weekly column where we highlight others’ security failures. Hopefully, there’s a lesson in all this, but it could just be “stop shooting yourself in the foot.” Our story today comes courtesy of Siim Kostabi, co-founder of Pageloot, a company that provides QR codes businesses can use for marketing. Kostabi’s tale of tech terror reminds us that credentials, even for a staging server, have a lot of value in the wrong hands."
        https://www.theregister.com/security/2026/08/13/passwords-stored-in-public-google-doc-then-showed-up-in-search-results/5287028
        https://www.malwarebytes.com/blog/news/2026/08/be-careful-what-you-put-in-anyone-with-the-link-google-docs
      • CISO Conversations: Nico Waisman – From Self-Taught Hacker To AI-Driven Offensive Security At XBOW
        "“I don’t think I ever chose a career in cybersecurity. It chose me.” Well, we’ll see… Nico Waisman was born and still lives in Argentina. If what he says is accurate, it suggests he was born in 1982; one year before a seven-year period of military dictatorship in Argentina came to an end. Argentine youngsters in the 1980s lived in a time of youthful rebelliousness against the law and the establishment, lingering after the dictatorships. For Waisman, this youthful rebelliousness turned toward emerging technology. He became fascinated by the idea of being able to subvert this tech into doing something he wanted it to do. In short, he became a young hacker – but it was the challenge and enjoyment of doing it rather than any desire to make money or cause harm from it that drove him."
        https://www.securityweek.com/ciso-conversations-nico-waisman-from-self-taught-hacker-to-ai-driven-offensive-security-at-xbow/
      • AI-Driven Vulnerability Surge Breaks The Traditional Patching Model
        "Recent analysis from Rapid7 demonstrates the fallacy of defenders continuing to rely on patching their way out of problems. “Q2 2026 was not just another busy quarter in cyber. It felt more like a stress test of the way we currently manage exposure. Traditional patch cycles are being overwhelmed by the sheer volume of vulnerabilities and attacker speed and precision,” writes Rapid7 in its latest report titled ‘the compression era’. “Vulnerabilities are being disclosed at higher volume, proof-of-concept code is appearing faster, exploitability is being tested earlier, and attackers are getting better at turning public information into operational access.” SecurityWeek spoke to Christiaan Beek, Rapid7’s VP of cyber intelligence for a deeper understanding of the cause and effect of this stress. But let’s be clear from the start: the compressive force behind this stress test is artificial intelligence (AI)."
        https://www.securityweek.com/ai-driven-vulnerability-surge-breaks-the-traditional-patching-model/
      • Ukrainian Software Developer Faces 12 Years In Swiss Ransomware Trial
        "Swiss prosecutors are seeking a 12-year prison sentence for a Ukrainian software developer linked to an international ransomware operation that caused hundreds of millions of dollars in damage to its victims. The 52-year-old defendant went on trial at Zurich District Court on Monday over his alleged involvement in attacks using LockerGoga, MegaCortex and Nefilim ransomware. His alleged victims included Swiss train manufacturer Stadler Rail, banking software developer Crealogix and building technology company Meier Tobler."
        https://therecord.media/ukrainian-software-developer-court-switzerland
      • How QR-Code Phishing Can Slip Past Corporate Security Measures
        "Familiarity might breed contempt. But in the world of cybersecurity, it also breeds complacency, which can be a lot more dangerous. So it is with QR codes, which have become a common sight on menus, lampposts and parking meters – and, increasingly, in emails over recent years. The challenge is that they’re also a great way to disguise malicious links, bypass some traditional corporate security filters, and to move the interaction from a corporate computer to a personal phone with fewer security controls. Attackers will continue to experiment and innovate with new ways to avoid detection. And new “quishing” techniques to snare unwitting employees. Here’s what you need to understand to keep your organization safe."
        https://www.welivesecurity.com/en/business-security/qr-code-phishing-slip-past-corporate-security-measures/

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 71eb888c-1594-4a25-9a5c-4479379a3d4b-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบช่องโหว่ Forminator เสี่ยงถูกอัปโหลดไฟล์ PHP และรันโค้ดบนเว็บไซต์ WordPress

      พบช่องโหว่ Forminator เสี่ยงถูกอัปโหลดไฟล์ PHP และร.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 015f8e92-fd4f-4930-93cc-b7fe2d12777d-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • ทีมนักวิจัยพบว่าพวก AI สร้างมัลแวร์เพื่อโจมตีกันเองระหว่างการทดสอบในระบบจำลอง

      ทีมนักวิจัยพบว่าพวก AI สร้างมัลแวร์เพื่อโจ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand b11224d5-d0dd-4395-ac76-e3c4836a22d3-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • SafePal แจ้งเหตุข้อมูลรั่วไหล กระทบลูกค้า 39,798 ราย จากช่องโหว่ใน Order-tracking Plugin

      SafePal แจ้งเหตุข้อมูลรั่วไหล กระทบลูกค้า 39,798 รา.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 04aaf8c2-1526-47be-8907-8feacff5f664-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบ PATCHCORD Backdoor ใช้ Google Sheets เป็น C2 ในแคมเปญจารกรรมไซเบอร์

      พบ PATCHCORD Backdoor ใช้ Google Sheets เป็น C2 ในแคมเปญจารกรรมไซ.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 52006770-2e01-4b9c-bc00-3b00fbacad76-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • DDoS Attack ขนาดใหญ่ทำให้บริการ Threema ขัดข้องเป็นวงกว้าง

      DDoS Attack ขนาดใหญ่ทำให้บริการ Threema ขัดข้องเป็นวง.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 062c6cd5-ce37-4fb6-a228-403517734e65-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • องค์กรระดับ Fortune 500 ตกเป็นเหยื่อของแคมเปญขโมยข้อมูล Azure

      องค์กรระดับ Fortune 500 ตกเป็นเหยื่อของแคมเปญขโม.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 336e96c9-b2cd-4421-9e75-10deb4bbb2dd-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 1 รายการลงในแคตตาล็อก

      เมื่อวันที่ 17 สิงหาคม 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 1 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้

      • CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability

      ทาง CISA จะปรับปรุงและเพิ่มช่องโหว่ใหม่เข้าสู่แคตตาล็อก KEV อย่างต่อเนื่อง เพื่อให้ครอบคลุมความเสี่ยงที่ตรวจพบจริงในปัจจุบันและอนาคต

      อ้างอิง
      https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand a865c16d-98b2-4831-a134-de1fbb77e3b3-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 18 August 2026

      Government/Law/Policy

      • ETSI Launches Approval Process For 17 European Standards Supporting The Cyber Resilience Act
        "ETSI is pleased to announce the availability of the 17 vertical final draft standards developed in the framework of the EU Cyber Resilience Act (CRA) and currently under Public Enquiry. These standards aim to become Harmonised Standards, giving manufacturers a recognised way to demonstrate compliance with the legislation, the so-called “presumption of conformity”. The ETSI EN 304 xxx series standards on cybersecurity requirements have been submitted this summer to 41 member organisations across Europe, including the national standardisation bodies of the European Economic Area. They will be able to provide comments as part of the first phase of the approval procedure. ETSI’s societal partners ANEC (the European consumer voice in standardisation), ECOS (the European Environmental Citizens’ Organisation for Standardisation), ETUC (the European Trade Union Confederation), and SBS (Small Business Standards), collectively known as the Annex III Organisations, will also be able to comment on these standards."
        https://www.etsi.org/newsroom/press-releases/etsi-launches-approval-process-for-17-european-standards-supporting-the-cyber-resilience-act/
        https://www.infosecurity-magazine.com/news/etsi-proposes-17-cybersecurity/

      New Tooling

      • Hazmat: Open-Source Containment For AI Agents
        "Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud credentials, and the pile of configuration in your home directory that has accumulated over years. Hazmat gives the agent a home of its own and shares only the project directory you point it at. Your keys and credential folders sit outside what the session can reach."
        https://www.helpnetsecurity.com/2026/08/17/hazmat-open-source-ai-coding-agent-containment/
        https://github.com/dredozubov/hazmat

      Vulnerabilities

      • 40,000 WordPress Sites Affected By Authentication Bypass Vulnerability In User Profile Builder WordPress Plugin
        "On July 14th, 2026, we received a submission for an Authentication Bypass vulnerability in User Profile Builder, a WordPress plugin with more than 40,000 active installations. This vulnerability makes it possible for unauthenticated attackers to log in as the user with ID 1, which is typically the site administrator, resulting in full administrative takeover of the site. The vulnerability is only exploitable on sites where the plugin’s Automatically Log In setting is enabled. Props to Supakiad S. (m3ez) who discovered and responsibly reported this vulnerability through the Wordfence Bug Bounty Program. This researcher earned a bounty of $975.00 for this discovery."
        https://www.wordfence.com/blog/2026/08/40000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-user-profile-builder-wordpress-plugin/
        https://www.infosecurity-magazine.com/news/wordpress-plugin-flaw-40000-sites/
      • 600,000 WordPress Sites Affected By Arbitrary File Upload Vulnerability In Forminator Forms WordPress Plugin
        "On July 14th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Forminator Forms, a WordPress plugin with more than 600,000 active installations. This vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site compromise. The vulnerability is only exploitable on sites that have a form containing both a File Upload field and a Select field."
        https://www.wordfence.com/blog/2026/08/600000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-forminator-forms-wordpress-plugin/
        https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html
      • Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
        "GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on August 17, 2026, the critical patch release arrived outside the company's usual schedule of twice-monthly updates on the second and fourth Wednesdays, five days after a routine patch release that carried no critical-rated issues."
        https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html
      • Microsoft Working On Defender Patch For ShieldBreak Zero-Day
        "On Friday, Microsoft confirmed it has begun working on a security patch for a Defender zero-day vulnerability named "ShieldBreak." A security researcher who uses the "Nightmare Eclipse" handle disclosed this privilege escalation vulnerability after Microsoft released the August 2026 Patch Tuesday security updates. ​"Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims," a Microsoft spokesperson told BleepingComputer when asked for a statement regarding the new ShieldBreak zero-day."
        https://www.bleepingcomputer.com/news/security/microsoft-working-on-defender-patch-for-shieldbreak-zero-day/
        https://www.bankinfosecurity.com/microsoft-faces-fresh-nightmare-eclipse-zero-day-a-32573
        https://www.malwarebytes.com/blog/bugs/2026/08/shieldbreak-bypasses-microsofts-patch-for-earlier-defender-flaw
      • Windows 11’s Strongest Security Defenses Can Be Bypassed Without a Screwdriver
        "Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already gained privileged access to the system. The attack, named “Download More RAM,” targets a small configuration chip found on Dual In-line Memory Modules (DIMMs), the RAM sticks inside most desktops and laptops. That chip stores information about the memory module, including its capacity and configuration. On several consumer memory modules, nothing stops software from rewriting critical parts of it."
        https://www.helpnetsecurity.com/2026/08/17/windows-11-security-bypass-research/
        https://www.usenix.org/system/files/usenixsecurity26-collins.pdf
      • CISA Adds One Known Exploited Vulnerability To Catalog
        "CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
        CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability"
        https://www.cisa.gov/news-events/alerts/2026/08/17/cisa-adds-one-known-exploited-vulnerability-catalog
      • UNISOC T612 LPE
        "UNISOC (Shanghai) Technologies Co., Ltd. is a top-three global fabless semiconductor company headquartered in Shanghai, specializing in 2G/3G/4G/5G mobile communication, IoT, and smart device chipsets. Formerly Spreadtrum, it serves major brands like Honor, realme, vivo, Samsung, and Motorola, with products in over 140 countries. A critical vulnerability has been identified in the Unisoc modem firmware that allows arbitrary code execution with kernel privileges from the modem context."
        https://ssd-disclosure.com/unisoc-t612-lpe/
        https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html
        https://www.darkreading.com/mobile-security/video-call-exploit-chains-two-flaws-unisoc-modems
        https://www.infosecurity-magazine.com/news/unisoc-modem-flaw-rce-calls/
      • Wiz Red Agent Finds Its Way Into Snowflake’s Internal Jira Through a Flaw In a GitHub Copilot–Assisted PR
        "As part of ongoing security research conducted through Snowflake’s HackerOne vulnerability disclosure program, Wiz Research’s "Red Agent"—an autonomous, AI-powered security research tool—identified a critical GitHub Actions workflow vulnerability in one of Snowflake’s public repositories. This incident highlights a new reality in software development: Critical vulnerabilities can still be introduced and approved within workflows involving AI coding agents, while autonomous AI security agents can rapidly discover and exploit them in the wild."
        https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug
        https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets_0330881554.html
        https://www.theregister.com/security/2026/08/17/an-ai-failed-to-detect-a-bug-in-snowflakes-code-then-another-ai-agent-exploited-it/5288666

      Malware

      • C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
        "In July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbitrary commands, performing reconnaissance, and deploying second-stage payloads. In this blog post, ThreatLabz provides a technical analysis of the identified C2Looper variants, including their network communication protocols and capabilities."
        https://www.zscaler.com/blogs/security-research/c2looper-new-backdoor-likely-tied-ransomware-github-c2
      • Global Exploitation Of CVE-2026–59310 By Suspected Chinese-Nexus APT & Related CVE-2026–59309 Activity
        "QUIRSO’s Incident Response team recently investigated a VMware vCenter compromise that uncovered a coordinated, global exploitation campaign targeting CVE-2026–59310 as well as exploitation of CVE-2026–59309 by a possible different actor. Our investigation enabled us to map affected systems across numerous countries and identify evidence pointing to a Chinese-nexus advanced persistent threat. We continue to track the campaign as it develops. This article presents our current findings on its scale, victimology, infrastructure, tooling and attribution, while acknowledging that the assessment may evolve as new evidence emerges."
        https://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d
        https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html
      • The Gentlemen Ransomware: Inside One Of The Fastest-Growing Extortion Operations
        "The Gentlemen is a financially motivated ransomware-as-a-service (RaaS) double-extortion operation. Originally appearing as affiliate activity under other ransomware programs, the core operators established The Gentlemen as an independent brand in mid-2025 and began recruiting experienced affiliates with a 90% share of ransom proceeds. This generous affiliate share is one of several reasons why the group has been able to expand so quickly. As of this writing, The Gentlemen has claimed more than 750 victims worldwide, and it continues to add new victims at a steady pace. Multiple reporting sources now rank the group alongside Qilin as the most active ransomware groups by victim volume this year."
        https://blog.barracuda.com/2026/08/17/the-gentlemen-ransomware--inside-one-of-the-fastest-growing-rans

      Breaches/Hacks/Leaks

      • Massive Azure Exfiltration Campaign Exposes Millions Of Enterprise Records Via Compromised Credentials (Mcdonald’s, Vodafone, Kyndryl & Others)
        "A significant Azure exfiltration campaign is currently underway, driven by a threat actor actively selling massive enterprise employee databases. These extensive directories were reportedly downloaded directly from the organizations’ Azure/Entra portals utilizing compromised credentials. Over the past week, a threat actor operating under the moniker “TheHatman” has flooded cybercrime forums with massive internal employee directories belonging to several Fortune 500 companies. The actor claims these dumps were extracted directly from the organizations’ Azure Tenants."
        https://www.infostealers.com/article/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others/
        https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/
        https://www.securityweek.com/fortune-500-companies-hit-in-azure-data-theft-campaign/
        https://securityaffairs.com/197322/cyber-crime/mcdonalds-employee-data-appears-in-leak-seller-claims-1-7m-records-stolen.html
        https://www.bankinfosecurity.com/azure-breach-campaign-claims-mcdonalds-vodafone-as-victims-a-32578
        https://www.theregister.com/security/2026/08/17/crook-hawks-millions-of-records-allegedly-plundered-from-corporate-azure-tenants/5288305
      • Pokémon Center Data Breach Exposes Customer Info, Cancels Some Orders
        "Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. While CEVA's systems were compromised in the cyberattack, the exposed records belonged to Pokémon Center customers who submitted orders on the site. The company then shared this information with the logistics provider to fulfill and ship PokemonCenter.com orders."
        https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/
      • Philips And GE Investigating Clop Ransomware Data Theft Claims
        "Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. While a GE spokesperson said the company is aware of the claim and is "working to assess the potential issue," a Philips spokesperson confirmed its systems were breached but said the incident has been contained and didn't affect customers. "Philips has identified ​and contained an attempted cybersecurity compromise of a specific enterprise server related to ⁠internal data," Philips said in a statement shared with Reuters. "This has no impact on customer environments.""
        https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/
        https://www.bankinfosecurity.com/clop-claims-data-theft-from-more-than-40-companies-a-32581
      • Hack On Med Software Firm Hits Half Of Poland's Population
        "A hack into IT systems of MyDr, a Polish provider of electronic medical documentation software, has affected more than 12,000 healthcare facilities and nearly 19 million people in Poland, about half the country's population. Government authorities said they launched an investigation Aug. 12 into the alleged 2.5 terabyte data theft incident, in which cybercriminals appeared to have gained access into MyDr's IT environment no later than Aug. 6."
        https://www.bankinfosecurity.com/hack-on-med-software-firm-hits-half-polands-population-a-32580
        https://therecord.media/poland-probes-mydr-healthcare-software-breach
      • The LiteLLM Supply-Chain Attack — TeamPCP “SANDCLOCK” CI/CD Credential-Harvesting Campaign Via a Backdoored Trivy GitHub Action
        "Resecurity has acquired 152.5 GiB of data following a supply-chain security breach involving LiteLLM, exposing stolen corporate credentials and configuration data linked to thousands of domains. Analysis of the attacker's victim archive from the March 2026 LiteLLM supply-chain compromise (TeamPCP / “SANDCLOCK” stealer): 415,427 on-host secret-capture files harvested from GitHub Actions / CI-CD runners across 898 owners and 2,038 repositories — with the Trivy→LiteLLM attack chain, captured-secret composition, real masked evidence, and named victims."
        https://www.resecurity.com/blog/article/the-litellm-supply-chain-attack-teampcp-sandclock-cicd-credential-harvesting-campaign-via-a-backdoored-trivy-github-action
        https://securityaffairs.com/197377/hacking/litellm-supply-chain-attack-technology-banking-and-healthcare-the-most-affected.html
      • Irregular Details How a Naming Error Let AI Models Attack a Real Company
        "AI safety testing firm Irregular has published its account of an incident in which models being evaluated inside one of its testing environments took offensive security actions against real systems rather than the simulated targets they were meant to attack. The Israeli company, which last year raised $80 million in funding, has been in the news in recent weeks after it came to light that AI models it tested on behalf of OpenAI, Anthropic, and Meta escaped their test environments and carried out real-world attacks. Irregular’s core business involves partnering with major AI labs to stress-test models before they are released to the public, running controlled simulations designed to measure a model’s capabilities in vulnerability research and offensive cyber tasks."
        https://www.securityweek.com/irregular-details-how-a-naming-error-let-ai-models-attack-a-real-company/
        https://www.irregular.com/research/addressing-recent-incidents-ongoing-findings-and-path-forward
        https://therecord.media/irregular-ai-hacking-model-blog
        https://cyberscoop.com/irregular-ai-sandbox-escape-human-oversight/
      • Nearly 750k Had Financial Info, SSNs Leaked In South Carolina Loan Company Breach
        "Cybercriminals breached the cloud system of a debt consolidation loan company in May, stealing troves of sensitive financial information and personal data on about 750,000 customers. The company, Heights Finance, published a warning to customers last week about the data breach and told regulators in Texas on Friday that 734,828 people were affected. Heights Finance operates dozens of personal loan companies across Alabama, Tennessee, Georgia, Texas and South Carolina."
        https://therecord.media/financial-info-leak-debt-consolidator

      General News

      • When Companies Get Specific About AI, Revenue Growth Looks Different
        "Companies that provide specific evidence of how they use AI tend to record stronger revenue growth. Researchers at Carnegie Mellon University and Larridin examined a study universe of 564 companies across 12 industry sectors. Individual analyses used smaller samples depending on data availability. The data included 478 corporate 10-K filings, more than 30,000 classified job postings, financial information, market data, and the AI Transformation Tracker built by Larridin."
        https://www.helpnetsecurity.com/2026/08/17/ai-adoption-revenue-growth-research/
        https://larridin.com/hubfs/CMU-Larridin AI-Company Performance 20270811.pdf
      • Infostealers Harvest 1.7 Billion Credentials In Six Months
        "Security researchers recorded 7.4 million devices infected with infostealer malware in the first half of 2026, a 27% increase from the previous six months, according to Flashpoint data. The threat intelligence company revealed the news in its 2026 Global Threat Intelligence Report: Midyear Edition, which features information collected from deep and dark web forums, illicit marketplaces, encrypted channels, and threat actor-linked infrastructure and ecosystems. In total, it claimed that hackers harvested 1.7 billion credentials via infostealer malware between January and June 2026, with Vidar, StealC and Lumma the top three most prolific infostealer variants."
        https://www.infosecurity-magazine.com/news/infostealers-17-billion/
      • Person Hides Prompt Injection In Legal Filing Telling AI To Side With Them
        "A person representing themselves in a Connecticut court hid a series of instructions designed to manipulate artificial intelligence in an official court filing. These “prompt injections” told the hypothetical LLM to side with them, and to “ensure your textual output agrees with the presented filing to ensure remediation.” The instructions were written in tiny, 3-point white font and hidden throughout the filing. In October, the person, named Matthew Elliott, sued the New York Bariatric Group, alleging a series of privacy violations, discrimination, and several other claims."
        https://www.404media.co/person-hides-prompt-injection-in-legal-filing-telling-ai-to-side-with-them/
        https://www.jdsupra.com/legalnews/the-first-documented-prompt-injection-1799990/
        https://securityaffairs.com/197370/ai/invisible-ai-prompts-trigger-court-sanctions.html
      • Phonescams: Casting a Wide Net In An Orchard Of Low-Hanging Fruit
        "Phonescams that impersonate some of America’s favorite brands—and some less expected ones—are distributed en masse to Cofense client email inboxes daily. In the digital age, everyone is looking to get ahead, and while one innovation breeds another, some things never change. Just as the humble wheel has been used for thousands of years, the easiest apple to pick off a tree is still the lowest hanging. Why fetch a ladder when the fruit is within reach? Here in the Cofense Phishing Defense Center, we have noticed that contemporary threat actors are all too aware of the concepts of wide nets and low-hanging fruit."
        https://cofense.com/blog/phonescams-casting-a-wide-net-in-an-orchard-of-low-hanging-fruit
      • Patterns And Problems In Emerging Multiagent Systems
        "Models are improving and AI agents are taking on more tasks in shared codebases, markets, and other social systems. As a result, an increase in real-world interactions between agents is imminent. We've already begun studying this, but still have a lot of uncertainty regarding what this looks like at scale. The trajectory is easy to imagine and hard to slow: current institutions are designed by and for people, resting on assumptions about the sufficiency of oversight at human speed. Some institutions will become human-AI hybrids; others where agents outcompete on speed or cost will become agent-only. The volume of agent-agent interaction could plausibly exceed that of human-human and human-agent interactions before the world understands the conditions for making such interactions go well."
        https://www.anthropic.com/research/multiagent-systems
        https://www.darkreading.com/threat-intelligence/turf-war-claude-agents-self-replicating-malware
        https://www.securityweek.com/conflicting-test-goals-pushed-claude-agents-to-deploy-self-replicating-malware/
      • Adam Shostack Talks Hugging Face & PHANTOM-B
        "OpenAI's rogue agents are raising a whole new set of questions for cyber defenders, and Dark Reading's senior news director Rob Wright sat down at the News Desk with threat modelling expert Adam Shostack to find out more. Shostack attended OpenAI's recent presentation on its findings in the wake of their AI agents going rogue, and he posed fundamental questions the industry will have to reckon with: namely, who is held liable when AI agents do real damage?"
        https://www.darkreading.com/vulnerabilities-threats/adam-shostack-talks-hugging-face-phantom-b

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 7e726480-ef24-4b7b-b7b6-b76eab99d0ab-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 17 August 2026

      Vulnerabilities

      • Chinese Loongson Processors Have Leaky Caches, Researchers Find
        "Researchers from Germany’s Helmholtz Center for Information Security have found processors made by China’s Loongson have leaky caches that attackers could use to seek specific data. Loongson has developed its own LoongArch instruction set architecture (ISA) that blends approaches used by MIPS and RISC-V. On a site called LoongLeakAttack.com, the researchers explain that they found the leaky cache using a fuzzer, then noticed that the LoongArch ISA manual mentions an instruction that leaves 32 bits of a memory register in an “uncertain” state."
        https://www.theregister.com/security/2026/08/13/chinese-loongson-processors-have-leaky-caches-researchers-find/5287137
        https://loongleakattack.com/
      • Unpatched GeoServer Zero-Day Targeted In Active Exploitation Attempts, Can Lead To RCE
        "A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remains unpatched. It was first disclosed on August 12, 2026, at 10:46 UTC, by a researcher named @q1uf3ng on X. "GeoServer jsonArrayContains unauthorized SQL injection, and in the case of the sa [system administrator] database, it's naturally possible to achieve RCE," the researcher said."
        https://thehackernews.com/2026/08/unpatched-geoserver-zero-day-targeted.html
        https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/
        https://securityaffairs.com/197216/hacking/geoserver-zero-day-is-already-being-probed-thats-the-problem.html

      Malware

      • Hackers Exploit MacOS Screen Sharing Flaw To Deploy Monero Miner
        "The Netherlands’ National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. The security issue lies in macOS Screen Sharing, a built-in remote desktop feature that allows remote desktop control over a network, using the VNC protocol over TCP port 5900. Apple fixed CVE-2026-65400 on August 6 in macOS Tahoe 26.6.1 and earlier releases. The flaw allows network-based attackers to gain access without valid credentials."
        https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/
        https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html
        https://securityaffairs.com/197234/uncategorized/macos-screen-sharing-flaw-exploited-to-deploy-monero-miners.html
      • Max Severity SAP Commerce Cloud Flaw Now Targeted In Attacks
        "A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. Commerce Cloud (formerly known as SAP Hybris) is a cloud-based e-commerce platform used by online stores owned by high-profile global brands and large retailers. Tracked as CVE-2026-58231, this critical flaw stems from an improper authorization weakness in the core Data Hub Adapter extension for Commerce Cloud that threat actors without privileges can exploit in low-complexity attacks to execute arbitrary code."
        https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/
        https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html
        https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html
      • ExfilSquad: New Data Extortion Group Leaks Microsoft D365 Data, Likely Linked To Misconfigured Power Pages
        "Fortra Intelligence and Research Experts (FIRE) have developed specialist tooling to support certain customers when faced with ransomware and data extortion claims. We monitor for new disclosures, including public and dark web sources, to provide early alerting to customers and support investigations. As part of this process, we also see activity that is not directly related to customers. When there is a significant interest, and we have new intelligence to share, we aim to share information with the security community to aid understanding of ransomware and extortion actors and campaigns."
        https://www.fortra.com/blog/exfilsquad-data-extortion-group-ransoming-microsoft-d365-data
        https://www.infosecurity-magazine.com/news/exfilsquads-13-organizations/
      • AmnesiaStealer: a Multi-Stage Rust-Based MacOS Infostealer That Hijacks Chromium Browsers
        "Jamf Threat Labs discovers and investigates AmnesiaStealer, a multi-stage Rust-based macOS infostealer spread through a counterfeit GitHub download page that captures the login password, reaches for macOS bypasses Apple has already patched, and can hand the operator live, hidden control of the victim's Chromium browser to steal authenticated sessions."
        https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/
        https://thehackernews.com/2026/08/amnesiastealer-hijacks-chromium.html
        https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/
        https://www.infosecurity-magazine.com/news/macos-infostealer-spread-clickfix/
        https://www.securityweek.com/amnesiastealer-macos-malware-steals-data-controls-browser-sessions/
        https://securityaffairs.com/197190/malware/amnesiastealer-gives-attackers-live-control-of-victims-macos-browsers.html
      • APT Group HoneyMyte Upgrades CoolClient: The Backdoor Gets a Kernel-Level Windows Rootkit
        "CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia. It supports such capabilities as keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and plugin-based extensions. Since its first public disclosure by Sophos in 2022 and subsequent analysis by Trend Micro in 2023, CoolClient has continued to evolve. In 2025, we analyzed a newer variant that introduced clipboard theft and HTTP traffic interception for credential harvesting."
        https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
        https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html
        https://securityaffairs.com/197274/apt/mustang-panda-upgrades-coolclient-with-a-kernel-rootkit.html
      • Return Of The Cookie Monster
        "In Dough No! Revisiting Cookie Theft, we looked at how Chromium’s Application Bound Encryption (ABE) in Windows made cookie theft significantly harder. For operators, this meant they needed to inject into a browser process, utilize remote debugging, or install an extension to steal cookies. This blog post dives deeper how to enable the remote debugging protocol without having to launch it via the --remote-debugger-port argument. With the release of Chrome 136+, Google announced additional protections against stealing cookies via remote debugging. To enable the Chrome DevTools Protocol (CDP) an alternate --user-data-dir needed to be supplied with --remote-debugger-port causing the existing cookies to be abandoned as a new data directory would be used. These changes forced operators to think more carefully about their process context before stealing cookies."
        https://specterops.io/blog/2026/08/13/chrome-devtools-protocol-cookie-theft/
        https://thehackernews.com/2026/08/chrome-devtools-technique-enables.html
      • Fake Zoom Installer Uses .NET Downloader To Deliver Overlord RAT On MacOS
        "Jamf Threat Labs recently identified a campaign using a fake Zoom installer to deliver a configured build of Overlord, an open-source remote access framework, hosted on attacker-controlled infrastructure. The downloader is a macOS ARM64 Mach-O binary named ZoomMeetings, built as a self-contained .NET 10 single-file application with the .NET runtime bundled inside. Rather than the Go or Rust we typically see in macOS malware, this downloader uses .NET, whose cross-platform support means the same codebase also targets Windows. Building macOS malware using the .NET framework is fairly uncommon, so naturally this caught our attention. Our curiosity led to a number of interesting finds that we'll share in this blog post."
        https://www.jamf.com/blog/fake-zoom-installer-delivers-overlord-rat-macos/
      • Large-Scale DDoS Attacks Disrupted Threema Secure Messaging Service
        "Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. ​Organizations using Threema On-Prem did not experience any issues because they rely on their own infrastructure. In a post-mortem report on Friday, the end-to-end encrypted instant messaging service said that the attacks were difficult to defend against because the threat actor constantly changed patterns."
        https://www.bleepingcomputer.com/news/security/large-scale-ddos-attacks-disrupted-threema-secure-messaging-service/
        https://securityaffairs.com/197353/hacking/ddos-attacks-cause-major-threema-outages.html
      • PATCHCORD: New Malware Cluster Targets Afghan Telecom And South Asian Critical Infrastructure
        "Acronis Threat Research Unit (TRU) has identified an ongoing campaign delivering a previously undocumented custom backdoor against Afghan telecom providers and South Asian critical infrastructure organizations. The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools. Infrastructure pivoting uncovered SHEETCORD, a Go-based implant that builds on PATCHCORD's capabilities while abusing Google Sheets for C2 communication. The malware was actively distributed through a domain impersonating India's National Informatics Centre (NIC)."
        https://www.acronis.com/en/tru/posts/patchcord-new-malware-cluster-targets-afghan-telecom-and-south-asian-critical-infrastructure/
        https://securityaffairs.com/197266/intelligence/apt36-suspected-in-patchcord-espionage-campaign-using-google-sheets-c2.html

      Breaches/Hacks/Leaks

      • Shell Investigates 'potential Incident' After Clop Data Theft Claims
        "Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. Shell is a British multinational energy conglomerate and one of the world's top three oil and gas companies, after Chevron and ExxonMobil. It has 85,000 employees in more than 70 countries and operates a massive network of tens of thousands of service and recharge stations that serve over 20 million customers daily. According to a recent post on Clop's dark web data leak site, the allegedly stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans."
        https://www.bleepingcomputer.com/news/security/shell-investigates-potential-incident-after-clop-data-theft-claims/
      • RingCentral Data Breach Exposed Info Of 1.6 Million Accounts
        "The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned. RingCentral is a cloud-based collaboration and communication platform used by over 600,000 businesses for services such as calling, messaging, and voicemail. The company disclosed the incident on July 28, revealing that its systems were compromised following what it described as a "sophisticated social engineering campaign.""
        https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/
        https://haveibeenpwned.com/Breach/RingCentral
        https://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/
      • Scottish Govt Suffers Potentially Widening Data Breach At Prosecutor's Office
        "A contractor has leaked Scottish government employees' personal information, and the full scope of the breach may be far greater than what is currently being reported. On Aug. 13, Scotland's Crown Office and Procurator Fiscal Service (COPFS) — the government's public prosecution service and death investigation authority — disclosed that an unidentified external supplier had experienced a data breach. The breach affected some of its employees' personally identifying information (PII)."
        https://www.darkreading.com/cyberattacks-data-breaches/scottish-govt-data-breach-prosecutors-office
      • 7.3M Chess.com Records Leaked, And The Data Is Real
        "A 15.5 GB file containing 7,337,395 chess.com user records is being handed out free on two data-leak forums. It carries email addresses, usernames, real names, countries, ratings, subscription tiers and internal advertising-audience tags. Ransomnews verified the data against the file itself. It is genuine chess.com data, and it is days old, not a recycled dump. What it is not, on the evidence, is a break-in: every structural signal points to large-scale scraping of a non-public interface rather than a compromise of chess.com’s systems."
        https://ransomnews.com/chess-com-leak-7-million-2026/
        https://securityaffairs.com/197174/breaking-news/chess-com-leak-exposes-7-3-million-users-evidence-points-to-scraping.html
      • LiteLLM Supply Chain Attack: Inside The AI Breach That Exposed 2,500+ Companies
        "New analysis published in August 2026 has overturned the original timeline of the LiteLLM supply chain attack. The well-known 40-minute PyPI window was not the beginning of the exposure. It was the final stage of a five-day collection run that started with the compromise of the Trivy scanner. Record-level data now maps exposure across more than 2,500 organizations and roughly 434,000 captured CI/CD files. SOCRadar’s analysis found that 95% of affected organizations appeared in the dataset before the malicious LiteLLM packages were published on March 24."
        https://socradar.io/blog/litellm-supply-chain-attack/
        https://www.securityweek.com/trivy-not-litellm-behind-the-2500-org-compromise/
      • France Investigates Tax Authority Breach After Hacker Claims 600,000 Victims
        "France’s tax authority has confirmed that hackers breached its information systems and extracted data on individuals and businesses. France’s Economy Ministry said late Thursday that an attacker gained unauthorized access to systems at the Directorate General of Public Finances, or DGFiP, in late June after stealing or misusing someone’s identity. The intrusion allowed the attacker “to view and extract data belonging to individuals and businesses,” according to the ministry."
        https://therecord.media/french-tax-authority-dgfip-confirms-data-breach
        https://securityaffairs.com/197287/cyber-crime/sophisticated-cyberattack-exposes-data-of-678000-french-taxpayers.html
      • Uber Freight Keeps On Trucking After Extortion Crew Breaks In
        "Uber Freight says it is investigating a "data security incident" days after the Helix extortion group listed the company on its data leak site on August 6. Helix claims to have stolen nearly 1 million files from mailboxes, OneDrive accounts, the accounts receivable department, and other repositories. An Uber Freight spokesperson told The Register that the incident was under investigation but had not disrupted the company's daily operations."
        https://www.theregister.com/security/2026/08/12/uber-freight-keeps-on-trucking-after-extortion-crew-breaks-in/5286782
      • SafePal Data Breach Impacts 39,798 Customers, Stolen Info For Sale
        "Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. SafePal says the breach impacts customers who placed orders between March 2, 2025, and April 11, 2026, exposing their names, email addresses, shipping addresses, phone numbers, and purchase information."
        https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-39-798-customers-stolen-info-for-sale/

      General News

      • Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw
        "Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers’ bank accounts. The theft, investigated by the Brazilian and German federal police agencies, occurred over four days in November 2023 and caused losses of around €30 million ($34.6 million). While neither the Brazilian Federal Police nor Germany's BKA named the affected German financial institution, Brazilian media identified it as Commerzbank, a major European financial institution that generates more than €11.1 billion ($12.8 billion) in annual revenue."
        https://www.bleepingcomputer.com/news/security/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw/
        https://therecord.media/investigation-into-banking-hack-leads-to-arrests-germany-brazil
      • Data Analyst Sent To Prison For Stealing Data, Extorting Employer
        "A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. Brightly is a Software-as-a-Service (SaaS) company formerly known as SchoolDude, which was acquired by Siemens in August 2022. Brightly employs over 700 people and provides asset management and maintenance software to more than 12,000 clients worldwide. 27-year-old North Carolina man Cameron Curry (also known as "Loot") was found guilty in March of orchestrating an "extensive cyber extortion scheme" targeting his employer."
        https://www.bleepingcomputer.com/news/security/data-analyst-sent-to-prison-for-stealing-data-extorting-employer/
      • Ransomware Threats In The Americas H1 2026: Dissecting The Regional Attack Patterns And Dominant Actors
        "The Americas carried the heaviest ransomware burden of any region on the planet in the first half of 2026. According to Cyble Research and Intelligence Labs (CRIL), North and South America combined experienced 2,188 documented ransomware attacks between January and June 2026. That single figure — 2,188 attacks — represents more than 57% of the 3,836 ransomware incidents CRIL tracked worldwide, making the Americas the undisputed center of gravity for global ransomware operations."
        https://cyble.com/blog/ransomware-threats-in-america-h1-2026/
      • What Boards Need To Know About Tech Risk
        "Most boardrooms are built to evaluate opportunity, growth initiatives, tech acquisitions, and operational improvements. The discussion centers on a familiar equation: investing in X to generate Y return. That mindset is essential for scaling a business. But it often creates dangerous blind spots in digital infrastructure. Unlike revenue-generating projects, many of the most important technology investments don't produce visible upsides."
        https://www.darkreading.com/cyber-risk/what-boards-must-know-tech-risk
      • The Hardest Part Of Agentic AI May Be Rebuilding The Business
        "Organizations expect AI agents to change how work gets done, driving productivity and growth while allowing employees to focus on higher-value tasks. Few, however, have the processes and workflows needed to realize those benefits, according to Deloitte’s latest research. About half of surveyed leaders say they understand how AI agents will affect their future operating model. Three main challenges limit wider adoption: the lack of a unified and accessible data foundation, limited trust in and governance of AI agents, and the cost and complexity of integration."
        https://www.helpnetsecurity.com/2026/08/14/deloitte-agentic-ai-readiness-gap-report/
      • Weak IAM Affects Up To 98% Of Cloud Environments
        "Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing encryption, exposed services, and logging gaps. CISA now mandates baseline cloud configuration practices for US federal agencies. More than two-thirds of midmarket organizations use multiple cloud providers, each with its own security model, terminology, and configuration settings. The same security issue can manifest differently across AWS, Azure, and Google Cloud, often requiring a different approach to identify and remediate, according to Intruder’s 2026 Cloud Security Index report."
        https://www.helpnetsecurity.com/2026/08/14/intruder-cloud-misconfiguration-trends-report/
      • Black Hat USA 2026: Will Vulnerability Discovery Eventually Decline In The AI Era?
        "The accelerated discovery of previously unknown software vulnerabilities has been making headlines for months. It’s an issue that has even led the US government to create a vulnerability clearing house named Gold Eagle to coordinate research efforts in vulnerability discovery, mitigation and fixes. An indication of the broader pressure facing cyber-defenders can be drawn from the sheer number of patches being delivered in Microsoft’s Patch Tuesday through the last four months: 169 CVEs in April, 118 CVEs in May, 571 CVEs overall in June (including 208 direct Microsoft CVEs) and another 622 vulnerabilities in July that included zero-days under active exploitation."
        https://www.welivesecurity.com/en/business-security/black-hat-usa-2026-vulnerability-discovery-decline-ai-era/
      • North Korean Remote Workers Are Infiltrating Government And Businesses: How To Expose Them Before Hiring
        "Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems companies spend millions trying to protect. That risk is no longer theoretical. The FBI is now investigating a North Korean remote IT worker who reportedly worked for a U.S. federal agency. For CISOs, the priority is clear: spot the warning signs before a fraudulent hire becomes trusted access."
        https://thehackernews.com/2026/08/north-korean-remote-workers-are.html
      • AI Can Find Bugs, But Human Knowledge Still Proves Them
        "Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, explain unfamiliar APIs, and run repetitive testing workflows at impressive speed. That is a real advantage for security teams. It also creates a new kind of pressure, because the industry can now produce more vulnerability-looking output than ever before."
        https://www.sans.org/blog/ai-can-find-bugs-but-human-knowledge-still-proves-them
      • Drop Something? Don’t Worry, Someone Caught It
        "Every day, tens of thousands of domain names expire and become available for registration. Some fade away and are never seen again. Others get a second chance. We refer to these as dropcatch domains: the domain was dropped, became available again, and someone caught it. This isn’t just our name; it’s widely used. There’s even an auction service called DropCatch[.]com. During the first half of 2026, we observed over 50k dropcatch domains a day in the gTLDs alone—when we add in various ccTLDs that number rises to around 65k. That’s an astounding number when you put it next to the total of new registrations every day. For the gTLDs, nearly 20% of all observed registrations are dropcatch. In other words, one of every five newly registered domains had a prior life, sometimes several."
        https://www.infoblox.com/blog/threat-intelligence/drop-something-dont-worry-someone-caught-it/
        https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html
        https://securityaffairs.com/197251/uncategorized/crooks-are-buying-your-expired-domains-and-using-them-to-deliver-malware.html
      • AI Won't Solve Cybersecurity Burnout. Better Leadership Might
        "Cybersecurity has spent years talking about workforce shortages. More recently, AI has entered the conversation as a possible solution. It can help teams analyze alerts, identify threats, automate investigations, and complete routine tasks faster than ever. That shift is already underway. According to SANS workforce research, 74% of cybersecurity teams are changing structures and role assignments because of AI, with entry-level SOC and security analyst roles among the most affected. Yet workloads, complexity and stress continue to rise. The latest ISSA workforce study found that 68% of professionals believe their jobs have become harder over the past two years, and nearly half have considered leaving their current role."
        https://blog.barracuda.com/2026/08/14/ai-won-t-solve-cybersecurity-burnout--better-leadership-might

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) 7b745a34-7080-45b9-8405-28899a9c7f37-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบความพยายามใช้ประโยชน์จากช่องโหว่ SAP Commerce Cloud เสี่ยงรันโค้ดบนระบบ

      พบความพยายามใช้ประโยชน์จากช่องโหว่ SAP Commerce Clo.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 35acf675-b145-44b4-ab65-8d41d42e0cc2-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CTM360 พบแคมเปญ Phishing สมัครงานกว่า 3,000 URL ใช้เทคนิค Browser-in-the-Browser ขโมย Credential

      CTM360 พบแคมเปญ Phishing สมัครงานกว่า 3,000 URL ใช้เทคนิค Bro.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 9548d032-b9a5-41df-b758-4162bdc6eebc-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • พบกลุ่มผู้ไม่หวังดีกว้านซื้อโดเมนที่หมดอายุแล้ว เพื่อใช้เป็นฐานในการโจมตีทางไซเบอร์และแพร่มัลแวร์

      พบกลุ่มผู้ไม่หวังดีกว้านซื้อโดเมนที่หมด.png

      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand df49e788-349b-46f2-ad92-23c2e992b1aa-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • CISA เผยแพร่คำแนะนำด้านระบบควบคุมอุตสาหกรรม (ICS) จำนวน 15 รายการ

      Cybersecurity and Infrastructure Security Agency (CISA) ได้เผยแพร่คำแนะนำเกี่ยวกับระบบควบคุมอุตสาหกรรม (ICS) จำนวน 15 รายการ เมื่อวันที่ 13 สิงหาคม 2569 เพื่อให้ข้อมูลที่ทันเวลาเกี่ยวกับประเด็นด้านความมั่นคงปลอดภัย ช่องโหว่ และการโจมตีที่เกี่ยวข้องกับระบบ ICS โดยมีรายละเอียดดังนี้

      • ICSA-26-225-01 AVEVA Enterprise SCADA
      • ICSA-26-225-02 Haiwell IoT Cloud HMI Gateway
      • ICSA-26-225-03 Johnson Controls Inc. Airwall
      • ICSA-26-225-04 Hitachi Energy APM Edge Product
      • ICSA-26-225-05 ANDRITZ HIPASE-250 and 250 SCALA
      • ICSA-26-225-06 Siemens RUGGEDCOM APE1808
      • ICSA-26-225-07 Siemens License Server (SLS)
      • ICSA-26-225-08 Siemens Desigo DXR and PXC Controllers
      • ICSA-26-225-09 Siemens Siveillance Video
      • ICSA-26-225-10 Siemens Parasolid
      • ICSA-26-225-11 Siemens Simcenter Femap
      • ICSA-26-225-12 Siemens Solid Edge
      • ICSA-26-225-13 Siemens LOGO! Soft Comfort
      • ICSA-26-225-14 Johnson Controls Metasys
      • ICSMA-26-225-01 Flow Neuroscience FL-100

      CISA แนะนำให้ผู้ใช้งานและผู้ดูแลระบบ ตรวจสอบคำแนะนำ ICS ที่เผยแพร่ล่าสุด เพื่อศึกษารายละเอียดทางเทคนิคและแนวทางการลดความเสี่ยง (mitigations)

      อ้างอิง
      https://www.cisa.gov/news-events/ics-advisories
      สามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand 5659c9e0-8038-44d2-9544-47a194eab180-image.png

      โพสต์ใน OT Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT
    • Cyber Threat Intelligence 14 August 2026

      Healthcare Sector

      • Flow Neuroscience FL-100
        "Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to manipulate brain stimulation parameters and override safety limits."

      Industrial Sector

      • Haiwell IoT Cloud HMI Gateway
        "Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges."
      • Hitachi Energy APM Edge Product
        "Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation."
      • Siemens Siveillance Video
        "Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions."
      • AVEVA Enterprise SCADA
        "Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization."
      • Johnson Controls Inc. Airwall
        "Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources."
      • ANDRITZ HIPASE-250 And 250 SCALA
        "Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations."
      • Siemens License Server (SLS)
        "Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version."
      • Siemens Desigo DXR And PXC Controllers
        "A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions."
      • Siemens Parasolid
        "Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions."
      • Siemens Simcenter Femap
        "Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version."
      • Siemens Solid Edge
        "Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions."
      • Siemens LOGO! Soft Comfort
        "Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive project logic and configurations. Siemens has released a new version for LOGO! Soft Comfort and recommends to update to the latest version."
      • Johnson Controls Metasys
        "Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access."

      Vulnerabilities

      • WordPress 7.0.4 Patches Remote Code Execution Vulnerability
        "WordPress on Wednesday announced patches for a high-severity vulnerability that allows authenticated attackers to execute arbitrary code remotely. Tracked as CVE-2026-65640 (CVSS score of 8.8), the security defect can be exploited by attackers with Author-level user or higher permissions via malicious Postscript file uploads. According to WordPress’ advisory, the issue affects only installations that use Imagick and Ghostscript, as it was discovered in Ghostscript’s handling of certain embedded files. Successful exploitation requires that an attacker has file upload rights."
      • Fortinet Patches Authentication Flaws In FortiWeb And FortiManager
        "Fortinet on Wednesday announced patches for eight vulnerabilities across its products, including high-severity authentication bugs in FortiWeb and FortiManager. In FortiWeb, the company resolved an improper authentication issue impacting deployments configured with specific, non-default settings. A remote, unauthenticated attacker could exploit the flaw, tracked as CVE-2026-26035, “to log in to the FortiWeb GUI/CLI with a random username and password,” Fortinet explains."
      • Microsoft Patches LegacyHive Windows Zero-Day Vulnerability
        "Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. The security flaw was disclosed by a security researcher who uses the "Nightmare Eclipse" handle in protest of Microsoft's bug bounty and vulnerability disclosure practices. Nightmare Eclipse published a LegacyHive proof-of-concept (PoC) exploit hours after the July 2026 Patch Tuesday security updates were released, claiming it exploits a security vulnerability in the Windows User Profile Service."

      Malware

      • Armored Likho Expands Its Cyber-Espionage Toolkit
        "In May 2026, we discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals and organizations across various industries in Russia, including major corporations, the public sector, IT, and education. The attackers used a fake app as bait that mimics a service for donations. However, the most interesting part of this campaign isn’t the initial infection method – it’s the malicious implants the attackers use for cyber-espionage. We’ve written previously about recent Armored Likho attacks, but our analysis shows that the campaign discussed below has more in common with the group’s activity from February. That said, the attackers have significantly expanded their arsenal."
      • Akira Hits Safe Mode: Ransomware Rebooting Around EDR
        "Akira has become one of the most prolific ransomware operations and was the most active group we observed in 2025. Its affiliates have settled into a well-worn playbook: get in through an exposed VPN (usually SonicWall), pivot to the domain controller, enumerate Active Directory, stage and exfiltrate data, then detonate all within a few hours. Huntress has documented that playbook in depth: from the active exploitation of SonicWall SSL VPN appliances as an initial-access vector, to a recent case where an affiliate spun up a brand-new virtual machine on the victim's hypervisor specifically to run the encryptor somewhere Huntress wasn't installed."
      • Jewelbug: APT Group Runs Espionage And Crypto Fraud Operations Side By Side
        "A months-long investigation by the Symantec Threat Hunter Team has produced unprecedented visibility into the activities of Jewelbug (aka Earth Alux, REF7707, CL-STA-0049), a China-based APT group that has been breaking into government ministries across Asia and the Middle East while quietly running a cryptocurrency fraud business on the side. The two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel. Jewelbug’s commercial arm is tied to a known registered company in Hunan Province, China. The group has developed five generations of command-and-control (C&C) code and a family of implants spanning browsers, Windows endpoints, Linux servers and network devices, all of it feeding a single database of victims. That toolset serves two missions: espionage attacks against foreign governments and militaries, and for-profit crypto fraud aimed at Chinese-speaking victims."
      • Dissecting The JWR Phishing Framework
        "JWR is a phishing framework capable of harvesting complete payment card data, login credentials, and personally identifiable information (PII) documents and images in real time. The client-side engine of the framework impersonates login, and checkout flows of several payment gateways, including Shopify, PayPal, Apple, Klarna, and banks, while allowing the operator to stealthily control the victim session through an AES-CTR encrypted WebSocket channel. The client engine architecture is divided into a Host Bridge module that relays commands into a phishing inline frame (iframe) and a Vue.js victim application that renders across 44 phishing pages, streams the victim's keystrokes to the actor as they are typed, and carries out more than 40 distinct instructions issued from the command-and-control (C2) console. The data exfiltration schema is a cvvform object that includes fields such as credit card number, CVV, PIN, expiry date, Social Security Number (SSN), passport or ID images, two-factor authentication (2FA) codes, website logins, PayPal credentials, and device fingerprint."
      • Multi-Functional Linux Botnet “Evooo1Bot”
        "FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary. While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities. Telemetry from its command-and-control infrastructure indicates that Evooo1Bot has been actively targeting Internet-facing devices since July 2026, exploiting multiple vulnerabilities across diverse regions. In this article, we provide a detailed analysis of Evooo1Bot’s modular architecture and operational features."
      • How To Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign
        "Organizations increasingly rely on GitHub to develop and store proprietary source code, internal documentation, and other software assets. This makes GitHub Personal Access Tokens (PATs) an attractive target for attackers, as a compromised token can provide access to private repositories and expose secrets such as cloud credentials, API keys, and private keys that may enable further compromise. Recently, the Wiz Customer Incident Response Team (CIRT) investigated a coordinated campaign in which compromised GitHub PATs were used to conduct repository reconnaissance and mass repository exfiltration across multiple organizations. Active from mid-May through early June 2026, the campaign progressed through several distinct stages, from reconnaissance and access validation to large-scale repository cloning and follow-on attempts to leverage exfiltrated credentials."
      • Top 10 Phishing Kits Used By Cybercriminals
        "Phishing kits have turned credential theft into a scalable service by packaging fake login pages, hosting, traffic filtering, victim management, and technical support into ready-made platforms. Advanced services such as Tycoon2FA, EvilProxy, and Sneaky 2FA can also intercept session cookies and bypass MFA methods that are not phishing-resistant, while platforms such as Darcula and Telekopye focus more heavily on smishing and consumer fraud. This article examines ten prominent platforms selected for their documented use, technical influence, current relevance, and value to defenders. It is not a strict ranking, and disrupted services are identified accordingly."

      Breaches/Hacks/Leaks

      • Trezor Discloses Data Breach Affecting Nearly 14,000 Customers
        "Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked. During the incident, the attackers gained access to customers' order data, including their full names, shipping addresses, email addresses, and phone numbers. As the company explained in a Thursday blog post, the resulting data breach affects customers from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10th and August 8th, 2026."
      • Exposed AWS Access Key Linked To Data Breach Affecting 1500+ UK Charities
        "A compromised AWS access key was the likely root cause of the cyber-attack on CRM provider Beacon, which has exposed personal information held by around 1500 UK charities. The software provider said in an August 12 incident update that the access key was potentially exposed in public Javascript build artifacts. This suggests an error was made in the course of software development. Beacon has assessed that the attacker used these valid credentials to access and download all data contained within the CRM platform, including attachment files, thereby impacting its entire 1500-strong customer base of charitable organizations."
      • INC Ransom Targeted 24 Law Firms, But Only 10 Are Listed
        "INC was on an encryption streak against US law firms in March 2026. SOCRadar identified 24 individualized extortion sites, hosted across two IP addresses, that we assess with high confidence are tied to INC Ransom. Each one is built for a specific US law firm, complete with its own countdown timer and highly likely shared with the victim firm’s customers to increase the pressure. Cross-referencing those 24 firms against INC’s known leak site months later, roughly 58% (14 of 24) do not appear there, while 42% (10 of 24) are listed."

      General News

      • Ukraine Shuts Down 94 Fraudulent Call Centers, Seize Millions In Cash
        "Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. The operation occurred this week, and police officers conducted a total of 411 searches following an investigation that involved the National Police, Ukraine's Security Service, the Prosecutor General’s Office, and the German police. According to the Ukrainian police, the fraudsters ran various schemes to obtain money from victims or gain access to their bank accounts."
      • Ransomware Didn’t Slow Down In Q2 2026. It Just Spread Out.
        "Ransomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is more interesting: new research gave us a rare look inside a top tier operation as it was being built, and it revealed just how little it now takes for a small and skilled group to reach the top of the field. Here’s what the quarter actually showed, and what it means for how you defend against it."
      • PQC In Plaintext: Google Cloud’s Post-Quantum Cryptography Roadmap
        "Securing infrastructure and services against a future cryptographically-relevant quantum computer has been a goal for Google for a decade, and we’ve dedicated ourselves to help developers by advancing open standards that can benefit everyone. As post-quantum cryptography (PQC) has matured, we’ve been rolling it out in our infrastructure for internal and customer-facing services. Today, we're sharing our updated Google Cloud roadmap to migrate to PQC by 2029."
      • Germany Moves To Give Spy Agencies Hacking And Sabotage Powers
        "Germany’s cabinet approved legislation Wednesday that would let its intelligence agencies hack foreign systems, sabotage adversaries’ supply chains and feed false information to extremists inside Germany, in the biggest overhaul of the country’s spy laws of the postwar era. Chancellery chief Nina Warken said the new powers could allow the agencies to substitute faulty components into deliveries, use cyber operations to sabotage drone factories or chemical weapons laboratories and disable servers run by hostile state-sponsored hackers and disinformation operators."
      • Trump Taps Cyber Firms To Go On Offensive Against Criminals
        "The Trump administration will allow private companies to launch attacks on cybercrime organizations, according to a presidential memorandum released late on Wednesday. The firms will partner with the Justice and Homeland Security departments on offensive operations and surveillance targeting “transnational cybercrime, fraud, and other predatory schemes against American citizens.” “By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter [Transnational Criminal Organizations] threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” the memorandum said."
      • Apple Sends New ‘Threat Notification’ Alerts Over Mercenary Spyware Attacks
        "You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." Some users on Reddit are reporting that they received these alerts today after Apple sent out a new batch of threat notifications on August 13, but the feature itself is not new."

      อ้างอิง
      Electronic Transactions Development Agency (ETDA) af0a2506-b6c9-422b-817f-717d1773a477-image.png

      โพสต์ใน Cyber Security News
      NCSA_THAICERTN
      NCSA_THAICERT